Agari Message Remediation - Agari Phishing Defense
Investigates Agari policy events by obtaining the original message and attachments from the existing email integrations and remediates in Agari.
- Pack
- AgariPhishingDefense
- Tasks
- 36
Inputs
- APD Global Message ID — Global Message Id obtained from the incident.
- AuthenticateEmail — Whether the authenticity of the email should be verified, using Authenticity Score.
- OnCall — Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later.
- Role — The default role to assign the incident to.
- ResolveIP — Resolve IP addresses to hostnames (DNS).
- AutoRemeditaion — Whether Automatic remediate message or not.
- RemediateAction — Default action for remediation of message.
- UserEnrichmentEnable — Flag for enabling User Enrichment.
- User Id — Id of User.
- APD Internal Message ID — Internal Message Id obtained from the incident.
Commands used
- closeInvestigation
- setIncident