Skip to main content

Rubrik Ransomware Discovery and VM Recovery - Rubrik Polaris

This Playbook is part of the Rubrik Security Cloud Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Use this playbook to recover a virtual machine using the "RubrikPolaris" integration by either exporting or live-mounting a backup snapshot. This playbook also creates tickets on ServiceNow using "ServiceNow v2" integration. Supported integrations:

  • RubrikPolaris
  • ServiceNow v2


This playbook uses the following sub-playbooks, integrations, and scripts.


  • Rubrik Poll Async Result - Rubrik Polaris
  • Rubrik IOC Scan - Rubrik Polaris


  • RubrikPolaris
  • ServiceNow v2


  • http
  • Set
  • PrintErrorEntry
  • SetAndHandleEmpty
  • Print


  • servicenow-create-ticket
  • rubrik-gps-vm-livemount
  • rubrik-gps-vm-export
  • rubrik-gps-vm-datastore-list
  • servicenow-update-ticket
  • rubrik-gps-vm-host-list
  • rubrik-gps-vm-snapshot-create
  • rubrik-polaris-vm-object-metadata-get
  • servicenow-add-comment

Playbook Inputs#

NameDescriptionDefault ValueRequired
ObjectIdObject ID of the incident.incident.rubrikpolarisfidRequired
ClusterIdCluster ID of the incident.incident.rubrikpolariscdmclusteridRequired

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Rubrik Ransomware Discovery and VM Recovery - Rubrik Polaris