Login to view this video
The JNUC session catalog is subject to change. Please remember to check your schedule once on-site.
Soaring with Jamf Protect
Jamf Protect with Jamf Pro allows you to create customized remediation workflows to respond to security threats and malicious activity. With these tools, we can create Security Orchestration, Automation and Response (SOAR) workflows for our Mac endpoints.
This session will explain how to set up Jamf Protect to look for specific malicious activity or behavior on your Mac endpoints and then implement workflows to remediate the situation as well as collect additional forensics data for further analysis.
Key discussion points:
• Configuring Analytics and plans in Jamf Protect.
• Configuring the remediation workflow between Jamf Protect and Jamf Pro.
• Presenting information to the user.
• Example real-world SOAR collection playbooks:
• Endpoint network isolation
• Quarantined file acquisition and removal
• Aftermath - collect additional data from the host and store it in a secure repository
Learning outcomes
• Understand how the integration of Jamf Pro and macOS Security Portal provides remediation capabilities.
• Learn how to keep users informed of the ongoing incident response.
• Learn how to automate detection, containment and recovery actions across macOS endpoints.
• See how Jamf provides security teams with the ability to forensically analyze security events.
The session will include a mixture of high-level theory, setting out how analytics are configured with Jamf Pro policies, as well as providing real-world workflows.
We start by discussing how analytics are configured in Jamf Protect to detect malicious activity and then respond by triggering a Jamf Pro policy to remediate.
The main part of the session is to dig into these workflows.
We will discuss how to classify your workflows with a threat level, thus determining the method of remediation or response. Some workflows may be required to be fully automated with no user interaction, others you may wish to engage the user with either some useful information via alerts using software such as SwiftDialog or even take them to a Self Service Policy.
We will dig into a few useful workflows including handling quarantined items and uploading the quarantined file to a cloud storage solution for further analysis, isolating the Mac endpoints network to prevent it from communicating to other network endpoints and the use of Aftermath to collect further forensic data which you can upload to a cloud storage solution.
Speakers

Senior Education Services Engineer, Jamf

Learning Experience Designer II, Customer Education, Jamf
- Wednesday, Oct 83:00 PM - 3:45 PM MDTMile High Ballroom 3B - Level 4
Session Type: Breakout Session
Products: Jamf Pro, Jamf Protect
Audience: Any
Skill Level: Level 200