Code42 Security Alert
Retrieves Incydr alert details, assigns the alert to an analyst, and gathers employee and supervisor data from Active Directory, if applicable. Note: this playbook can be used as an alternate default to "Code42 Exfiltration Playbook" when the Code42 Incydr integration is set to "Fetch Incidents".
- Pack
- Code42
- Tasks
- 8
Commands used
- closeInvestigation
- code42-alert-resolve
- setIncident