TIM - Process AWS indicators
This playbook handles the tagging of AWS indicators. Specify the tag to apply to these indicators in the playbook inputs. An example tag will be approved_allow. If no inputs are specified, the indicators will be tagged for manual review. The user can specify whether a manual review incident is required.
- Pack
- FeedAWS
- Tasks
- 10
Inputs
- AWSIndicatorTagName — Use this input to define which tag to apply to AWS indicators. An example tag can be allowlist_review. If no tags are specified in the input, the tag allowlist_review will be used.
- OpenIncidentToReviewIndicatorsManually — This input determines if processed indicators that have the allowlist_review tag are reviewed in a new incident. To create an incident, enter any value other than 'No'.
Commands used
- appendIndicatorField
- createNewIncident