Darkmon - Compromised Employee Auto-Disable

Hourly poll of compromised employees. For each new entry, looks up the user in the configured directory and acts per the DisableMode playbook input: - notify-only : creates incident and notifies; no AD action. [DEFAULT] - approval-required : creates incident, blocks on a manual approval task, then disables on approve. - auto-disable : disables the account immediately, then notifies. Accounts in the 'Darkmon - Auto-Disable Allowlist' list are NEVER auto-disabled.

Pack
Darkmon
Tasks
11

Inputs

Outputs

Commands used