IRP Playbooks
  • Initial page
  • Output Types
    • Number (Num)
    • Arrays
    • Objects
    • HR (Human Readable)
  • Components
    • Notifications
      • Send SMS
    • Start Playbook (Required)
      • Incident
    • Investigation
      • SearchEvents
      • SearchLogs
      • SearchWatchList
      • SearchIncidentData
    • Incident Response
      • AbuseEmail
    • Mange Incident
      • AddNote
      • Resolve
      • Escalate
      • AddToWatchList
    • Enrichements
      • Virustotal
      • ThreatIntel
      • WhoisURL
      • GeoIP
      • DomainAvailability
    • Filters
      • Each
    • Controls
      • PublicIp
  • Version
    • Changelog
Powered by GitBook
On this page
  • Outputs
  1. Components
  2. Start Playbook (Required)

Incident

PreviousStart Playbook (Required)NextInvestigation

Last updated 4 years ago

Outputs

  • Incident ID

  • Incident Name

  • Appliance ID

  • Appliance Name

  • Total Incident Data

  • Incident Description

  • Incident Category

  • Incident OS

  • Incident Security Layer

  • Incident Status

  • Incident Events Count (Num)

  • Raw Output

Incident Data (Array of Objects)

Example:

Usernames

["root", "john", "mike"]

Sources (Array of IPs)

[168.26.26.26, 123.15.15.15, 45.55.68.3]

Incident Priority

Can be one of:

  • High

  • Medium

  • Low

Incident Created At

2020-09-30T07:16:00.262+00:00

Incident Correlated Values (Array of Objects)

[{"qk":"src","counts":2,"value":"185.132.53.115"}]

Often used in (loops), , , etc.

Often used in (loops), , , ,

Each component
Add notes
Add to watch list
Each component
Add notes
Add to watch list
Whois IP
Threat Intel
Incident Data (Array)
Usernames (Array)
Sources (Array of IPs)
Incident Priority
Incident Created At
Incident Correlated Values (Array of Objects)