SafeNet Trusted Access - Add to Unusual Activity Group
This playbook adds the user to a group that was created to identify unusual activity. SafeNet Trusted Access policies can be configured to take this into account and provide stronger protection when handling access events from users who are members of the group. The user is added to this group for a configurable period of time.
- Pack
- SafeNet_Trusted_Access
- Tasks
- 24
Inputs
- UserName — Username of the user.
- UnusualActivityGroup — Name of the Unusual Activity Group.
- InstanceName — Name of the SafeNet Trusted Access integration instance.
- Time — Amount of time for which the user will remain in the Unusual Activity Group.
Commands used
- closeInvestigation
- setIncident
- sta-add-user-group
- sta-get-group-info
- sta-get-user-info
- sta-remove-user-group
- sta-user-exist-group
- sta-validate-tenant