This Playbook is part of the Flashpoint Pack.#

Compromised Credentials Match playbook uses the details of the compromised credentials ingested from the Flashpoint and authenticates using the Active Directory integration by providing the compromised credentials of the user, expires the credentials if it matches, and sends an email alert about the breach.


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


  • Active Directory Query v2
  • OpenLDAP


  • ad-authenticate
  • ad-expire-password
  • send-mail

Playbook Inputs#

NameDescriptionDefault ValueRequired
usernameThe username of the compromised credentials account.incident.flashpointsourceemailRequired
passwordThe password of the compromised credentials account.incident.flashpointpasswordRequired
sendEmailAsWarningBoolean input whether to send email or not.TrueOptional

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Compromised Credentials Match - Flashpoint