MDE Malware - Incident Enrichment

This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook enriches Microsoft Defender For Endpoint alerts. The enrichment is done on the involved endpoint and Mitre technique ID information, and it sets the 'Malware-Investigation and Response' layout.

Pack
MicrosoftDefenderAdvancedThreatProtection
Tasks
29

Inputs

Outputs

Commands used