Darktrace Basic Model Breach Handler
Darktrace Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.6.0 and later.
Handles each fetched Darktrace model breach by gathering additional detail about the activity through enrichment data from Darktrace and XSOAR. Additionally, it offers the ability to take proactive actions from XSOAR to your Darktrace deployment.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Entity Enrichment - Generic v3
#
Integrations- DarktraceMBs
#
Scripts#
Commands- darktrace-get-model-breach
- darktrace-get-model-breach-connections
- darktrace-get-model-breach-comments
- darktrace-post-comment-to-model-breach
- darktrace-acknowledge-model-breach
- closeInvestigation
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.