Digital Guardian Demo Playbook
This playbook will show how to handle an exfiltration event through Digital Guardian by emailing a user's manager and adding the user to a DG Watchlist.
- Pack
- DigitalGuardian
- Tasks
- 15
Inputs
- User Name — User Name to check
- Watchlist Name — The name of the DG watchlist to add the user to.
- Incident Match — The incident name should contain this string in order for the playbook to handle the event. The default is DLP1008 which is a USB Exfiltration event.
- Notify Manager — Notify User's Manager
Commands used
- closeInvestigation
- digitalguardian-add-watchlist-entry
- send-mail