Expanse Enrich Cloud Assets

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Subplaybook for Handle Expanse Incident playbooks. This Playbook is used to enrich Public Cloud Assets by:

  • Searching the corresponding Region and Service from IPRange feeds retrieved from Cloud Providers
  • Searching IPs and FQDNs in Prisma Cloud

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Prisma Cloud - Find Public Cloud Resource by Public IP
  • Prisma Cloud - Find Public Cloud Resource by FQDN
  • Expanse Find Cloud IP Address Region and Service

Integrations

This playbook does not use any integrations.

Scripts

This playbook does not use any scripts.

Commands

  • setIncident
  • associateIndicatorToIncident

Playbook Inputs


NameDescriptionDefault ValueRequired
IPIP to enrichincident.expanseipOptional
FQDNFQDN to enrichincident.expansedomainOptional
ProviderCloud Providerincident.expanseproviderOptional
AWSIndicatorTagsTags to identify AWS IP RangesAWSOptional
GCPIndicatorTagsTags to identify GCP IP RangesGCPOptional
AzureIndicatorTagsTags to identify Azure IP RangesAzureOptional
Update IncidentFlag to check whether to update incident

Update means:
- Set Expanse Region and Expanse Service to the values found from indicators
- Link found indicators to the incident
TrueOptional

Playbook Outputs


PathDescriptionType
PrismaCloud.AttributionPrisma Cloud Asset Attributionunknown

Playbook Image


Expanse Enrich Cloud Assets