CyphoAssignToMeButton

Assigns the current Incident to the Cortex XSOAR user who clicked the button.

Type
python
Pack
CyphoThreatIntelligence

Source

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401

try:
    current_user_resp = demisto.executeCommand("getUsers", {"current": True})
    current_user = current_user_resp[0].get("Contents", [{}])[0].get("username")

    if not current_user:
        raise ValueError("Could not determine the current user.")

    incident = demisto.incidents()[0]
    current_owner = incident.get("owner")

    if current_owner == current_user:
        demisto.results(f"Incident is already assigned to {current_user}. No changes made.")
    else:
        demisto.executeCommand("setOwner", {"owner": current_user})
        demisto.results(f"Incident ownership changed to {current_user}.")

except Exception as e:
    demisto.error(f"[CyphoAssignToMeButton] Error: {str(e)}")
    demisto.results("Failed to assign the incident to the current user.")

README

Cypho Assign To Me

This automation allows an analyst to assign a Cypho-related incident to themselves directly from Cortex XSOAR with a single button click.

The script synchronizes the assignment action with Cypho, ensuring that the issue owner is updated consistently across both platforms. This guarantees accurate ownership tracking, accountability, and proper analyst attribution throughout the incident lifecycle.

The automation is designed to simplify incident ownership management by eliminating manual assignment steps in Cypho. Once executed, the incident is immediately assigned to the current analyst in XSOAR and reflected accordingly in Cypho.

Script Data


Name Description
Script Type python3
Tags incident-action, button

Inputs


There are no manual inputs for this script.
The automation automatically uses:

Outputs


There are no outputs for this script.
The script performs a background synchronization and updates the issue assignee in Cypho.

✔ Notes