Calculate and assign the incident severity based on the highest returned severity level from the following calculations:
- DBotScores of indicators
- Current incident severity
This playbook uses the following sub-playbooks, integrations, and scripts.
- Calculate Severity Highest DBotScore For Ingress Network Traffic - GreyNoise
- Calculate Severity Highest DBotScore For Egress Network Traffic - GreyNoise
This playbook does not use any integrations.
|Array of all indicators associated with the incident.
|The direction of network traffic event associated with the Incident(Egress/Ingress). If not supplied, Ingress is considered.
|All critical assets involved in the incident.
|Critical endpoints involved in the incident.
|Critical endpoint-groups involved in the incident.
|Critical users involved in the incident.
|Critical user-groups involved in the incident.