Expanse Enrich Cloud Assets
Cortex Xpanse by Palo Alto Networks Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.0.0 and later.
Subplaybook for Handle Expanse Incident playbooks. This Playbook is used to enrich Public Cloud Assets by:
- Searching the corresponding Region and Service from IPRange feeds retrieved from Cloud Providers
- Searching IPs and FQDNs in Prisma Cloud
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Prisma Cloud - Find Public Cloud Resource by Public IP
- Prisma Cloud - Find Public Cloud Resource by FQDN
- Expanse Find Cloud IP Address Region and Service
#
IntegrationsThis playbook does not use any integrations.
#
ScriptsThis playbook does not use any scripts.
#
Commands- setIncident
- associateIndicatorToIncident
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
IP | IP to enrich | incident.expanseip | Optional |
FQDN | FQDN to enrich | incident.expansedomain | Optional |
Provider | Cloud Provider | incident.expanseprovider | Optional |
AWSIndicatorTags | Tags to identify AWS IP Ranges | AWS | Optional |
GCPIndicatorTags | Tags to identify GCP IP Ranges | GCP | Optional |
AzureIndicatorTags | Tags to identify Azure IP Ranges | Azure | Optional |
Update Incident | Flag to check whether to update incident Update means: - Set Expanse Region and Expanse Service to the values found from indicators - Link found indicators to the incident | True | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
PrismaCloud.Attribution | Prisma Cloud Asset Attribution | unknown |