Supported Cortex XSOAR versions: 6.0.0 and later.
Performs indicator extraction and enrichment from the incident content, calculates the severity level, assigns the incident to a particular analyst, notifies SOCRadar platform for the incident response (to mark it as false positive or resolved) and generates investigation summary report just before closing the investigation in the end. This playbook is executed for the SOCRadar Generic incident type.
This playbook uses the following sub-playbooks, integrations, and scripts.
- Entity Enrichment - Generic v3
|AutoEnrich||Auto Enrich input to be used for extracting indicators out of the incident content automatically at the beginning of the playbook. (Options: Yes/No)||Yes||Optional|
There are no outputs for this playbook.