Illusive-Retrieve-Incident
Illusive Networks Pack.#
This Playbook is part of theThis playbook is used for retrieving an extensive view over a detected incident by retrieving the incident details and a forensics timeline if and when forensics have been successfully collected.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- IllusiveNetworks
#
Scripts#
Commands- illusive-get-forensics-timeline
- illusive-get-incidents
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
incident_id | The desired incident ID to retrieve. | 3 | Required |
start_date | The starting date of the forensics timeline. | Optional | |
end_date | The last date of the forensics timeline. | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
Illusive.Forensics.Evidence.details | The forensics evidence details | unknown |
Illusive.Forensics.Evidence.eventId | The event ID | unknown |
Illusive.Forensics.Evidence.id | The forensics evidence ID | unknown |
Illusive.Forensics.Evidence.source | The Evidence source | unknown |
Illusive.Forensics.Evidence.starred | Whether the forensics evidence has been starred | unknown |
Illusive.Forensics.Evidence.time | Date and time of the forensics evidence | unknown |
Illusive.Forensics.Evidence.title | The forensics evidence description | unknown |
Illusive.Forensics.IncidentId | The Incident Id | unknown |