Call from SOC analyst when bulk isolating hosts org-wide
J
Josh O'Mealey
We would like for the SOC analyst that performs an org-wide host isolation action to then call each number listed on the "Incident Notification Contacts" list at least once to speak to someone that can let the SOC analyst know if something unique might be happening in the customer environment that could warrant having the SOC analyst fully or partially roll back the org-wide host isolation. It would also be good for the SOC analyst to give the organization contact a quick run-down of what they saw in the environment in case the org contact hasn't seen any details about new incidents being entered into the Huntress platform yet.
M
Mike Farwell
This is a great idea!