Slack - General Failed Logins v2.1
Investigates a failed login event. The playbook interacts with the user via the Slack integration, checks whether the logins were a result of the user's attempts or an attack, raises the severity, and expires the user's password according to the user's replies.
- Pack
- Slack
- Tasks
- 11
Inputs
- UsernameOrEmail — The username or the email address of the user who failed to login.
Commands used
- ad-expire-password
- closeInvestigation
- send-notification
- setIncident