Incident

Outputs

Incident Data (Array of Objects)

Example:

Usernames

Often used in Each component (loops), Add notes, Add to watch list, etc.

Sources (Array of IPs)

Often used in Each component (loops), Add notes, Add to watch list, Whois IP, Threat Intel

Incident Priority

Can be one of:

  • High

  • Medium

  • Low

Incident Created At

Incident Correlated Values (Array of Objects)

Last updated