Skip to main content

GCP - Enrichment

This Playbook is part of the GCP Enrichment and Remediation Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.8.0 and later.

Given the IP address this playbook enriches GCP and Firewall information.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Google Cloud Compute
  • GCP-IAM

Scripts#

GCPProjectHierarchy

Commands#

  • gcp-compute-aggregated-list-instances-by-ip
  • gcp-compute-list-firewall
  • gcp-iam-project-iam-policy-get
  • gcp-iam-tagbindings-list

Playbook Inputs#


NameDescriptionDefault ValueRequired
GcpIPGCP IP in alertalert.remoteipRequired

Playbook Outputs#


PathDescriptionType
GoogleCloudCompute.InstancesGCP VM Instances information.unknown
GoogleCloudCompute.FirewallsGCP Firewall informationunknown
GCPIAM.PolicyGCP IAM informationunknown
GCPIAM.TagBindingsProject/Folder/Organization level tags.unknown
GCPHierarchyGCP project hierarchy information.unknown

Playbook Image#


GCP - Enrichment