Skip to main content

Cortex ASM - Tenable.io Enrichment

This Playbook is part of the Cortex Attack Surface Management Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

Given the IP address this playbook enriches Tenable.io information relevant to ASM alerts.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

This playbook does not use any integrations.

Scripts#

  • GetTime
  • GridFieldSetup

Commands#

  • extractIndicators
  • tenable-io-get-asset-details

Playbook Inputs#


NameDescriptionDefault ValueRequired
Indicator QueryIndicators matching the indicator query will be used as playbook inputOptional
IPAddressIP addresses to enrich.alert.remoteipRequired

Playbook Outputs#


PathDescriptionType
AWS.EC2.InstancesAWS EC2 information.unknown
AWS.EC2.SecurityGroupsAWS Security group information.unknown
AWS.IAM.UsersAWS IAM information.unknown

Playbook Image#


Cortex ASM - Tenable.io Enrichment