Dispatch Incident - Vectra XDR
This playbook is called from the Process Incident - Vectra XDR playbook. It will fetch all active detections for the entity under investigation. It will then assign the entity to a user; if an assignment already exists, it will update that assignment and add a note in Vectra.
- Pack
- VectraXDR
- Tasks
- 11
Inputs
- UserID — User ID for entity assignment.
Commands used
- vectra-assignment-list
- vectra-entity-assignment-add
- vectra-entity-assignment-update
- vectra-entity-detection-list
- vectra-entity-note-add