SaaS Security by Palo Alto Networks (v2.1.1)
SaaS Security connects directly to your sanctioned SaaS applications to provide data classification, sharing and permission visibility, and threat detection.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Default data source
- SaaS Security Event Collector
- Categories
- Cloud Security
Incident fields (14)
- Saas Security Asset ID
- Saas Security Asset Name
- Saas Security Asset Owner
- Saas Security Asset Owner Email
- Saas Security Asset URL
- Saas Security Assigned To
- Saas Security Category
- Saas Security Incident Id
- Saas Security Incident Severity Level
- Saas Security Remediation Type
- Saas Security Remove Inherited Sharing
- Saas Security Resolved By
- Saas Security State
- Saas Security Status
Integrations (2)
- SaaS Security Event Collector
- SaaS Security
Layouts (1)
- Saas Security Layout
Modeling rules (1)
- Prisma SAAS Security Modeling Rule
Parsing rules (1)
- Prisma SAAS Security Parsing Rule
README
What does this pack do?
- Provides the SaaS Security integration, which allows Cortex XSOAR to collect incidents from the SaaS Security platform.
- Provides a SaaS Security Incident incident type with dedicated incoming mapper, fields and layout.
- Provides a generic polling playbook that handles the remediation of an asset.
Screenshots
-
SaaS Security Incident Layout:

-
Remediate an Asset:
