MDE Malware - Incident Enrichment
This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook enriches Microsoft Defender For Endpoint alerts. The enrichment is done on the involved endpoint and Mitre technique ID information, and it sets the 'Malware-Investigation and Response' layout.
- Pack
- MicrosoftDefenderAdvancedThreatProtection
- Tasks
- 29
Inputs
- DidAlertOriginateFromSIEM — Whether the incident is fetched through a SIEM product.
- AlertID — The Microsoft Defender For Endpoint alert ID.
Outputs
- MITREATTACK — The full MITRE data for the attack pattern.
- AttackPattern — An array of attack patterns name and IDs.
- MicrosoftATP.Alert — Microsoft Defender For Endpoint alert information.
- Endpoint — The endpoint information.
Commands used
- endpoint
- extractIndicators
- file
- microsoft-atp-get-alert-by-id
- setIncident