Malware SIEM Ingestion - Get Incident Data

This playbook handles incident ingestion from the SIEM. The user provides which EDR system to use, the field containing the incident ID or detection ID, and the field indicating whether the ingested item is an incident or detection.

Pack
MalwareInvestigationAndResponse
Tasks
5

Inputs

Outputs