Illusive - Data Enrichment
This playbook is used for automatic enrichment of incidents in the organization network, with Illusive's set of forensics and data
- Pack
- IllusiveNetworks
- Tasks
- 19
Inputs
- illusive_incident_id — Illusive incident ID
- fqdn_or_ip — The endpoint's fqdn or IP address
Outputs
- Illusive.Incident.incidentId — The Incident ID
- Illusive.Incident.sourceHostname — The compromised host's name
- Illusive.Incident.sourceIp — The compromised host's IP address
- Illusive.Incident.sourceOperatingSystem — The compromised host's operating system
- Illusive.Incident.lastSeenUser — The user who last reviewed the incident
- Illusive.Incident.deceptionFamilies — The deception families of the deceptions used to trigger the incident
- Illusive.Incident.riskInsights.stepsToCrownJewel — The compromised host's lateral distance from Crown Jewels
- Illusive.Incident.riskInsights.stepsToDomainAdmin — The compromised host's lateral distance from domain admin accounts
- Illusive.Incident.eventsNumber — The number of associated events
- Illusive.Event.eventId — The corresponding event ID
- Illusive.Event.incidentId — The corresponding incident ID
- Illusive.Event.ForensicsAnalyzers — The forensics analyzer
- Illusive.Event.ForensicsTriggeringProcess.commandLine — The triggering process command line
- Illusive.Event.ForensicsTriggeringProcess.connectionsNum — The triggering process active connections
- Illusive.Event.ForensicsTriggeringProcess.md5 — The triggering process md5
- Illusive.Event.ForensicsTriggeringProcess.sha256 — The triggering process sha256
- Illusive.Event.ForensicsTriggeringProcess.name — The triggering process name
- Illusive.Event.ForensicsTriggeringProcess.parent — The parent process of the triggering process
- Illusive.Event.ForensicsTriggeringProcess.path — The triggering process path
- Illusive.Event.ForensicsTriggeringProcess.startTime — The triggering process start time
- Illusive.Incident.incidentTimeUTC — Date and time of the incident
- Illusive.Incident.closed — Whether the incident has been closed
- Illusive.Incident.flagged — Whether the incident has been flagged
- Illusive.Incident.hasForensics — Whether incident has forensics
- Illusive.Incident.incidentTypes — Type of events detected
- Illusive.Incident.policyName — The compromised host's policy
- Illusive.Incident.unread — Whether the incident has been read
- Illusive.Incident.userNotes — The analyst's comments
Commands used
- illusive-get-forensics-analyzers
- illusive-get-forensics-artifacts
- illusive-get-forensics-timeline
- illusive-get-forensics-triggering-process-info
- illusive-get-incident-events
- illusive-get-incidents
- setIncident