Gem Handle Alert for Root Usage
Gem Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.12.0 and later.
Find all the users who might’ve performed the actions using root (via the source IP), validate it with them using Slack and resolve the alert in case these actions were planned.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Gem
#
Scripts- Set
- IsGreaterThan
- ZipStrings
- GetTime
#
Commands- gem-list-using-entities
- gem-get-alert-details
- gem-update-threat-status
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.