SafeBreach - Create Incidents per Insight and Associate Indicators
SafeBreach - Breach and Attack Simulation platform Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 5.5.0 and later.
This is a sub-playbook that creates incidents per SafeBreach insight, enriched with all the related indicators and additional SafeBreach insight contextual information. Used in main SafeBreach playbooks, such as "SafeBreach - Process Behavioral Insights Feed" and "SafeBreach - Process Non-Behavioral Insights Feed".
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- SafeBreach_v2
#
Scripts- Set
- SearchIncidentsV2
#
Commands- associateIndicatorToIncident
- safebreach-get-insights
- createNewIncident
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Indicator Query | Indicators matching the indicator query will be used as playbook input | safebreachisbehavioral:T | Optional |
insightIds | List of Insight ids to create incidents for. | Required | |
indicators | List of indicators that to be assigned to created incidents | Required |
#
Playbook OutputsPath | Description | Type |
---|---|---|
incident | Incidents created from SafeBreach Insights | Array |