Cortex XDR - XCloud Cryptojacking

Investigates a Cortex XDR incident containing a Cloud Cryptojacking related alert. The playbook supports AWS, Azure, and GCP and executes the following: - Cloud enrichment: - Collects info about the involved resources - Collects info about the involved identities - Collects info about the involved IPs - Verdict decision tree - Verdict handling: - Handle False Positives - Handle True Positives - Cloud Response - Generic sub-playbook. - Notifies the SOC if a malicious verdict was found

Pack
CloudIncidentResponse
Tasks
23

Inputs

Commands used