XCloud Alert Enrichment
This playbook is responsible for data collection and enrichment. The playbook collects or enriches the following data: - Account enrichment - Network enrichment -Attacker IP -Geolocation -ASN
- Pack
- CloudIncidentResponse
- Tasks
- 11
Inputs
- ResolveIP — Determines whether to convert the IP address to a hostname using a DNS query (True/ False).
- InternalRange — A list of internal IP ranges to check IP addresses against. For IP Enrichment - Generic v2 playbook.
Outputs
- IP — The IP objects
- DBotScore — Indicator, Score, Type, Vendor
- Account — The account object.
- IAM — Generic IAM output.
- UserManagerEmail — The email of the user's manager.
- UserManagerDisplayName — The display name of the user's manager.
- MSGraphUser — The MSGraphUser object.
- MSGraphUserManager.Manager — The MSGrMSGraphUserManageraph Manager object.
- SailPointIdentityNow — The SailPointIdentityNow object.
- SailPointIdentityNow.Account — The IdentityNow account object.
- IdentityIQ — The IdentityIQ object.
- ActiveDirectory.Users — The ActiveDirectory Users object.
Commands used
- ip