Impossible Traveler - Enrichment
This playbook get as an input all of the involved IP addresses and identities from the Impossible Traveler playbook alert, and enriches them based on the following: * Geo location * Active Directory * IP enrichment e.g. VirusTotal, AbuseIPDB, etc.
- Pack
- Core
- Tasks
- 17
Inputs
- sourceip — The source IP to iterate over.
- username — The username to iterate over.
- domain — The organization domain.
Outputs
- ActiveDirectory.Users.manager — The manager of the user.
- IP — The IP enrichment results.
- IP.Geo — The IP geo information.
- IP.Malicious — The IP verdict.
- AbuseIPDB.IP — The IP information retrieved from AbuseIPDB.
- AbuseIPDB.IP.Geo — The IP geo information.
- DBotScore — The DBotScore
- AbuseIPDB.IP.Malicious — The IP verdict.
- Account — The account object.
- ActiveDirectory.Users — The AD users.
- MSGraphUser — The user information retrieved from MSGraphUser
- MSGraphUserManager.Manager — The user's manager information retrieved from MSGraphUser.
Commands used
- ip