Phishing - Search Related Incidents (Defender 365)

This playbook should only be used as a sub-playbook inside the "Phishing - Handle Microsoft 365 Defender Results" playbook. It searches through existing Cortex XSOAR incidents based on retrieved email message IDs and returns data only for emails that are not found in existing incidents.

Pack
Phishing
Tasks
8

Inputs

Outputs