Impossible Traveler Response

This playbook handles impossible traveler alerts. An Impossible Traveler event occurs when multiple login attempts seen for a user from multiple remote countries in a short period of time, which shouldn't be possible. This may indicate the account is compromised. **Attacker's Goals:** Gain user-account credentials. **Investigative Actions:** Investigate the IP addresses and identities involved in the detected activity using: * Impossible Traveler - Enrichment playbook * CalculateGeoDistance automation **Response Actions** The playbook's first response actions are based on the data available within the alert. In that phase, the playbook will execute: * Manual block indicators if the IP address found malicious * Manual disable user * Manual clear of the user’s sessions (Okta) When the playbook continues, after validating the activity with the user’s manager, another phase of response actions is being executed, which includes: * Auto block indicators **External Resources:** [Impossible traveler alert](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Impossible-traveler-SSO)

Pack
Core
Tasks
26

Inputs

Outputs

Commands used