Skip to main content

AWS - Enrichment

This Playbook is part of the AWS Enrichment and Remediation Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

Given the IP address this playbook enriches EC2 and IAM information.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • AWS - EC2
  • AWS - System Manager

Scripts#

  • Set
  • AWSAccountHierarchy

Commands#

  • aws-ec2-describe-instances
  • aws-ec2-describe-security-groups
  • aws-ec2-describe-regions
  • aws-ec2-get-ipam-discovered-public-addresses
  • aws-ssm-inventory-entry-list
  • aws-ec2-describe-ipam-resource-discoveries

Playbook Inputs#


NameDescriptionDefault ValueRequired
AwsIPAWS IP in alertalert.remoteipRequired
AWSAssumeRoleNameIf assuming roles for AWS, this is the name of the role to assume (should be the same for all organizations).Optional
Indicator QueryIndicators matching the indicator query will be used as playbook input.Optional

Playbook Outputs#


PathDescriptionType
AWS.EC2.InstancesAWS EC2 information.unknown
AWS.EC2.SecurityGroupsAWS Security group information.unknown
AWSHierarchyAWS account hierarchy information.unknown
AWS.SSMAWS SSM information.unknown

Playbook Image#


AWS - Enrichment