HackerView Incident Management V2
This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to track the progress of the investigation. When the remote HackerView ticket status becomes inactive, the playbook automatically closes the local incident via the Close Incident Locally task (closeInvestigation). The HackerView Incident type is configured to run this playbook with autorun enabled, so no analyst prompt is required for that auto-close path.
- Pack
- CTM360-CyberBlindspot
- Tasks
- 18
Inputs
- closeReason — The reason recorded when the playbook closes the local incident after the remote HackerView ticket becomes inactive.
Commands used
- closeInvestigation
- ctm360-hv-incident-details
- ctm360-hv-incident-status-change