Abuse Inbox Management Detect & Respond
SlashNext Phishing Incident Response - Annual Subscription (Direct Subscription) Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.0.0 and later.
When combined with ‘SlashNext Abuse Management Protection’, this playbook fully automates the identification and remediation of phishing emails found in Microsoft 365 user inboxes. Using the indicators of compromise, URL, domain, and IP, found in the original email, it searches and remediates other emails containing the same IOCs.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Abuse Inbox Management Protection
#
Integrations- EWS Mail Sender
- EWS v2
#
ScriptsThis playbook does not use any scripts.
#
Commands- ews-search-mailbox
- send-mail
- ews-move-item
- closeInvestigation
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.