To address this challenge, Sekoia.io has recently released Playbooks on-prem.
In this way, Playbooks on-prem may appeal to companies seeking to synchronize cloud actions with those executed on-premises.
At its core, Playbooks on-prem revolve around a playbook runner that facilitates local execution of different actions.
Let's consider a use case to shed more light on Playbooks on-prem.
Due to the limitation of inbound connections, the playbook can't directly connect to the client environment and take action on-prem.
As a solution, the Sekoia team offers an on-prem playbook runner to be installed within the client's environment.
For the AD use case, the Sekoia team suggests launching a virtual machine with a playbook runner and Docker on the client's environment.
Playbook runner periodically sends requests to the Sekoia SOC platform to check for pending tasks.
On the reception of an automation request, the on-prem agent orchestrates and configures the underlying playbook actions.
After disabling the user, the playbook runner reports to the Sekoia SOC platform.
As soon as the action confirmation is received, the playbook proceeds to the next task and dispatches it to the playbook runner.
The encrypted communication channel between a playbook runner and the Sekoia SOC platform is a cornerstone here.
Playbooks on-prem: prerequisites and installation guidelines.
As there is no inbound communication between the local environment and the Sekoia SOC platform, you'll need to establish an outbound communication channel between the playbook runner installed within your domain and our platform.
Kickstart the installation process by creating a playbook runner.
Optionally, you can assign a name to the playbook runner for easy identification.
Check out our public documentation for more details on how to install Playbooks on-prem.
All the reports generated by the installed playbook runners will be available on the Sekoia SOC platform.
Playbooks on-prem are a versatile solution for running actions within a local environment.
Last but not least, this automation implies simplicity and flexibility, and our team is always ready to support clients on their way to installing, configuring, and leveraging Playbooks on-prem.
This Cyber News was published on blog.sekoia.io. Publication date: Thu, 22 Feb 2024 20:43:06 +0000