Automated the incident response process and tracking in MakeMyTrip. Brought down the turn around time for blocking an attack at our infrastructure from an average of 3 hours to just 2 mins. Integrated with multiple data sources to enrich mail notifications of attacks with all the required information. This mail is a single point of view to analyze an incoming attack with details like, whois, reputation check, attack vectors, raw HTTP packets, event count. Just replying with keyword block on this mail automatically blocks the source IP at our perimeter WAF. Metric tracking to log each event with a JIRA ticket and mark it resolved upon action. Reply on Mail action framework to hook-up easily to any type of mail to carry out Automation tasks. Data enrichment and modular functions just plug and play into existing mails to make them more meaningful. Threat intelligence API built to provide a single endpoint to get all available information for a single IP related to reputation, access pattern, attack vectors (if any). Other multiple scripts to help in streamlining the Incident Response
Show less