Skip to main content

SafeBreach - Create Incidents per Insight and Associate Indicators

This Playbook is part of the SafeBreach - Breach and Attack Simulation platform Pack.#

Deprecated

No available replacement.

Deprecated. No available replacement.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • SafeBreach_v2

Scripts#

  • Set
  • Sleep
  • SearchIncidentsV2

Commands#

  • associateIndicatorToIncident
  • createNewIncident
  • safebreach-get-insights

Playbook Inputs#


NameDescriptionDefault ValueRequired
Indicator QueryIndicators matching the indicator query will be used as playbook inputsafebreachisbehavioral:TOptional
insightIdsList of Insight ids to create incidents for.Required
indicatorsList of indicators that to be assigned to created incidentsRequired

Playbook Outputs#


PathDescriptionType
incidentIncidents created from SafeBreach InsightsArray