Expanse Enrich Cloud Assets
Deprecated. No available replacement. Subplaybook for Handle Expanse Incident playbooks. This Playbook is meant to be used as a subplaybook to enrich Public Cloud Assets (i.e. IP addresses and FQDNs) by: - Searching the corresponding Region and Service by correlating the provided IPs with IP range feeds retrieved from Public Cloud Providers (require TIM and Public Cloud feeds such as AWS Feed integrations to be enabled). - Searching IPs and FQDNs in Prisma Cloud inventory (requires Prisma Cloud).
- Pack
- ExpanseV2
- Tasks
- 13
Inputs
- IP — IP to enrich
- FQDN — FQDN to enrich
- Provider — Cloud Provider
- AWSIndicatorTags — Tags to identify AWS IP Ranges
- GCPIndicatorTags — Tags to identify GCP IP Ranges
- AzureIndicatorTags — Tags to identify Azure IP Ranges
- Update Incident — Flag to check whether to update incident Update means: - Set Expanse Region and Expanse Service to the values found from indicators - Link found indicators to the incident
Outputs
- PrismaCloud.Attribution — Prisma Cloud Asset Attribution
Commands used
- associateIndicatorToIncident
- setIncident