Skip to main content

Expanse Enrich Cloud Assets

This Playbook is part of the Expanse v2 Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Subplaybook for Handle Expanse Incident playbooks. This Playbook is used to enrich Public Cloud Assets by:

  • Searching the corresponding Region and Service from IPRange feeds retrieved from Cloud Providers
  • Searching IPs and FQDNs in Prisma Cloud

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • Prisma Cloud - Find Public Cloud Resource by Public IP
  • Prisma Cloud - Find Public Cloud Resource by FQDN
  • Expanse Find Cloud IP Address Region and Service

Integrations#

This playbook does not use any integrations.

Scripts#

This playbook does not use any scripts.

Commands#

  • setIncident
  • associateIndicatorToIncident

Playbook Inputs#


NameDescriptionDefault ValueRequired
IPIP to enrichincident.expanseipOptional
FQDNFQDN to enrichincident.expansedomainOptional
ProviderCloud Providerincident.expanseproviderOptional
AWSIndicatorTagsTags to identify AWS IP RangesAWSOptional
GCPIndicatorTagsTags to identify GCP IP RangesGCPOptional
AzureIndicatorTagsTags to identify Azure IP RangesAzureOptional
Update IncidentFlag to check whether to update incident

Update means:
- Set Expanse Region and Expanse Service to the values found from indicators
- Link found indicators to the incident
TrueOptional

Playbook Outputs#


PathDescriptionType
PrismaCloud.AttributionPrisma Cloud Asset Attributionunknown

Playbook Image#


Expanse Enrich Cloud Assets