Skip to main content

Rubrik Ransomware Discovery and File Recovery - Rubrik Polaris

This Playbook is part of the Rubrik Security Cloud Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This playbook performs an IOC Scan based on the provided inputs, search the recoverable snapshot and performs recovery on the searched recoverable snapshot. This playbook also creates tickets on ServiceNow using "ServiceNow v2" integration. Supported integrations:

  • RubrikPolaris
  • ServiceNow v2


This playbook uses the following sub-playbooks, integrations, and scripts.


  • Rubrik IOC Scan - Rubrik Polaris
  • Rubrik Poll Async Result - Rubrik Polaris
  • Block File - Generic v2


  • RubrikPolaris
  • ServiceNow v2


  • http
  • PrintErrorEntry
  • Print
  • Set


  • servicenow-update-ticket
  • rubrik-gps-vm-recover-files
  • rubrik-polaris-vm-object-snapshot-list
  • servicenow-add-comment
  • rubrik-gps-vm-snapshot-create
  • servicenow-create-ticket

Playbook Inputs#

NameDescriptionDefault ValueRequired
ObjectIdObject ID of the incident.incident.rubrikpolarisfidRequired
ClusterIdCluster ID of the incident.incident.rubrikcdmclusteridRequired

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Rubrik Ransomware Discovery and File Recovery - Rubrik Polaris