Cortex ASM - Tenable.io Enrichment
#
This Playbook is part of the Cortex Attack Surface Management Pack.Supported versions
Supported Cortex XSOAR versions: 6.5.0 and later.
Given the IP address this playbook enriches Tenable.io information relevant to ASM alerts.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
IntegrationsThis playbook does not use any integrations.
#
Scripts- GetTime
- GridFieldSetup
#
Commands- extractIndicators
- tenable-io-get-asset-details
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Indicator Query | Indicators matching the indicator query will be used as playbook input | Optional | |
IPAddress | IP addresses to enrich. | alert.remoteip | Required |
#
Playbook OutputsPath | Description | Type |
---|---|---|
AWS.EC2.Instances | AWS EC2 information. | unknown |
AWS.EC2.SecurityGroups | AWS Security group information. | unknown |
AWS.IAM.Users | AWS IAM information. | unknown |