Case Investigation - Google SecOps

This playbook investigates a Google SecOps case by retrieving the latest case information, related alerts, and their entities, and updating the case stage. It also calculates severity from IOC scores, updates the incident and case priority accordingly, creates entities in the case from the identified IOCs, and posts a summary comment on the case.

Pack
GoogleChronicleBackstory
Tasks
24

Inputs

Commands used