Access Investigation - QRadar
IBM QRadar Pack.#
This Playbook is part of theDeprecated
No available replacement.
Investigates an Access incident by gathering user and IP address information. The playbook then interacts with the user that triggered the incident to confirm whether or not they initiated the access action.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Access Investigation - Generic
- QRadar - Get offense correlations v2
#
Integrations- Builtin
#
ScriptsThis playbook does not use any scripts.
#
Commands- setIncident
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.