Cortex XDR Lite - Incident Handling

The Cortex XDR Lite - Incident Handling playbook is triggered by fetching a Palo Alto Networks Cortex XDR incident and executes the following: Analysis: - Enriches all the indicators from XDR incidents and alerts, providing additional context and information about these indicators. Investigation: - Checks for related XDR alerts to the user and the endpoint by Mitre tactics to identify malicious activity. - Checks for specific arguments for malicious usage from the command line. Verdict: - Determines the incident's verdict by considering indicator enrichment results, user and host risk levels, command line analysis, and the number of related XDR alerts (medium severity or higher) to the user and the endpoint by Mitre tactics. Verdict Handling: - Handles malicious incidents by initiating appropriate response actions, including blocking malicious indicators, isolating endpoints, and disabling user accounts. To utilize this playbook as the default for handling XDR incidents, the classifier should be empty, and the selected incident type should be `Cortex XDR - Lite`. The selected Mapper (incoming) should be `XDR - Incoming Mapper`, and the selected Mapper (outgoing) should be Cortex `XDR - Outgoing Mapper`.

Pack
CortexXDR
Tasks
32

Inputs

Commands used