ChronicleAsset Investigation - Chronicle

This playbook receives indicators from its parent playbook, performs enrichment and investigation for each one of them, provides an opportunity to isolate and block the hostname or IP address associated with the current indicator, and gives out a list of isolated and blocked entities. This playbook also lists the events fetched for the asset identifier information associated with the indicator.

Pack
GoogleChronicleBackstory
Tasks
13

Inputs

Outputs

Commands used