Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/netapp.azure-sentinel-solution-netapprrs-c5332052-bf87-49ed-a159-5c1d1dc073c7/image0_NlogovioletAzure.png

NetApp Ransomware Resilience for Microsoft Sentinel

by NetApp

NetApp Sentinel SOAR playbook automates response to alerts to limit data loss and contain attacks.

The NetApp Sentinel SOAR playbook enables users to limit data loss and contain the attack at the data layer from within their Microsoft Sentinel SOAR.

Used in conjunction with NetApp Ransomware Resilience, the NetApp Sentinel SOAR playbook orchestrates predefined actions on ONTAP including:

• Generating immutable, indelible snapshots to create unalterable recovery points.

• Blocking suspicious users or IP addresses from accessing data volumes.

• Taking compromised data volumes offline logically, moving the data out of harm's way to prevent further infection.

This targeted containment strategy isolates only affected data volumes or user accounts during an attack, avoiding full network shutdowns and keeping operations running.

All actions taken by the NetApp SOAR playbooks can be customized and configured based on the organization’s security policies and processes and can include multiple conditions. They can be triggered manually or automatically.

Beyond creating a cohesive, closed-loop defense-in-depth strategy, the NetApp Sentinel SOAR playbook helps eliminates the manual effort required to protect ONTAP data under active attack—all without requiring deep storage expertise. Moreover, using the NetApp Sentinel SOAR playbook to respond to cyber threats can help improve security team metrics like MTTC.

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies