This playbook receives indicators from its parent playbook, performs enrichment and investigation for each one of them, provides an opportunity to isolate and block the hostname or IP address associated with the current indicator, and gives out a list of isolated and blocked entities. This playbook also lists the events fetched for the asset identifier information associated with the indicator.
This playbook uses the following sub-playbooks, integrations, and scripts.
List Device Events - Chronicle Hostname And IP Address Investigation And Remediation - Chronicle
This playbook does not use any integrations.
|The value of the ChronicleAsset indicator.
|The support email address for the chronicle asset.
|Autoblock the detected suspicious IP Address(es). You can manually set this as 'Yes' or 'No' here or you can set it into a 'Chronicle Auto Block Entities' custom incident field.
|Skip the isolation of entities. You can manually set this as 'Yes' or 'No' here or you can set it into a 'Chronicle Skip Entity Isolation' custom incident field.
|List of the isolated entities.
|List of potentially blocked IP addresses.