MDR Escalation Process - Vectra XDR
This playbook retrieves the MDR ticket number associated with the given entity by parsing its notes. It then collects the entity's active detections, performs a detection assessment, and sends the results to the designated recipient via email.
- Pack
- VectraXDR
- Tasks
- 17
Inputs
- entity_id — The ID of the entity.
- entity_type — The type of the entity.
- recipient_email — The recipient email address for MDR escalation process.
- detection_assessment_limit — The number of the active detection to be assessed.
Commands used
- send-mail
- vectra-entity-detection-list
- vectra-entity-note-list