Skip to main content

DarkmonCreateIncidents

This Script is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

Creates one XSOAR incident per item using a name_template and field_map (comma-separated 'field=path' pairs).

Script Data#


NameDescription
Script Typepython3
Tagsdarkmon
Cortex XSOAR Version6.5.0

Used In#


This script is used in the following playbooks and scripts.

  • Darkmon - Compromised Credentials Sweep
  • Darkmon - Ransomware Mentions Watch
  • Darkmon - Brand-Targeted NRD Watch
  • Darkmon - Critical CVE Pipeline
  • Darkmon - Compromised Employee Auto-Disable

Inputs#


Argument NameDescription
itemsItems to process.
id_fieldField name to use as the dedup key.
seen_listName of the XSOAR List storing already-seen IDs.
domain_filter_listOptional - list of customer domains to filter username matches.
domain_match_fieldField on each item to match against domain_filter_list.
allowlistOptional list of usernames/DNs that must NEVER be actioned.
allowlist_match_fieldField to match against the allowlist.
incident_typeIncident type for newly created incidents.
severitySeverity (1=Low, 2=Medium, 3=High, 4=Critical).
name_templateIncident name template (supports ${field} interpolation).
field_mapComma-separated 'fieldCli=sourcePath' pairs.
emailsEmail addresses to fan out per VIP fetch.
domains
brands_list
max_distance
min_cvss
tech_stack_list

Outputs#


PathDescriptionType
NewAccountsunknown
CreatedIncidentsunknown
Countnumber
Typosquatsunknown
FilteredCVEsunknown
VIPCreatednumber