Supported Cortex XSOAR versions: 5.5.0 and later.
This is a sub-playbook that creates incidents per SafeBreach insight, enriched with all the related indicators and additional SafeBreach insight contextual information. Used in main SafeBreach playbooks, such as "SafeBreach - Process Behavioral Insights Feed" and "SafeBreach - Process Non-Behavioral Insights Feed".
This playbook uses the following sub-playbooks, integrations, and scripts.
This playbook does not use any sub-playbooks.
|Indicator Query||Indicators matching the indicator query will be used as playbook input||safebreachisbehavioral:T||Optional|
|insightIds||List of Insight ids to create incidents for.||Required|
|indicators||List of indicators that to be assigned to created incidents||Required|
|incident||Incidents created from SafeBreach Insights||Array|