Skip to main content

Dispatch Incident - Vectra Detect

This Playbook is part of the Vectra AI Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

This playbook is called from the Process Incident - Vectra Detect playbook. It will fetch all active detections for the entity under investigation. It will then assign the entity to a user; if an assignment already exists, it will update that assignment and add a note in Vectra.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

This playbook does not use any integrations.

Scripts#

  • DeleteContext

Commands#

  • vectra-assignment-assign
  • vectra-account-note-add
  • vectra-search-assignments
  • vectra-search-detections
  • vectra-host-note-add

Playbook Inputs#


NameDescriptionDefault ValueRequired
user_idUser ID for entity assignment.Optional
entity_typeType of the entity.incident.vectraentitytypeOptional
entity_idID of the entity.incident.accountidOptional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


Dispatch Incident - Vectra Detect