Skip to main content

GCP - Enrichment

This Playbook is part of the GCP Enrichment and Remediation Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

Given the IP address this playbook enriches GCP and Firewall information.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • GCP-IAM
  • Google Cloud Compute

Scripts#

This playbook does not use any scripts.

Commands#

  • gcp-compute-aggregated-list-instances-by-ip
  • gcp-compute-list-firewall
  • gcp-iam-project-iam-policy-get

Playbook Inputs#


NameDescriptionDefault ValueRequired
GcpIPGCP IP in alertalert.remoteipRequired

Playbook Outputs#


PathDescriptionType
GoogleCloudCompute.InstancesGCP VM Instances information.unknown
GoogleCloudCompute.FirewallsGCP Firewall informationunknown
GCPIAM.PolicyGCP IAM informationunknown

Playbook Image#


GCP - Enrichment