Cloud Enrichment - Generic

## Generic Cloud Enrichment Playbook The **Cloud Enrichment - Generic Playbook** is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments. ### Supported Blocks 1. **Cloud IAM Enrichment - Generic** - Enriches information related to Identity and Access Management (IAM) in the cloud. 2. **Cloud Compute Enrichment - Generic** - Enriches information related to cloud compute resources. The playbook supports a single CSP enrichment at a time.

Common Playbooks · 4 tasks · 9 inputs · 22 outputs

Details

IDCloud Enrichment - Generic
From Version6.8.0
Tasks4

README

Generic Cloud Enrichment Playbook

The Cloud Enrichment - Generic Playbook is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments.

Supported Blocks

  1. Cloud IAM Enrichment - Generic
    • Enriches information related to Identity and Access Management (IAM) in the cloud.
  2. Cloud Compute Enrichment - Generic
    • Enriches information related to cloud compute resources.

The playbook supports a single CSP enrichment at a time.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Cloud IAM Enrichment - Generic
  • Cloud Compute Enrichment - Generic

Integrations

This playbook does not use any integrations.

Scripts

This playbook does not use any scripts.

Commands

This playbook does not use any commands.

Playbook Inputs


Name Description Default Value Required
cloudProvider The cloud provider involved.
The supported CSPs are AWS, Azure and GCP.
  Optional
instanceName The instance name.   Optional
instanceID The instance ID.   Optional
zone The zone holding the instance.   Optional
region The region holding the instance.   Optional
azureResourceGroup The instance’s resource group.   Optional
username The username involved.   Optional
GCPProjectName The GCP project name.   Optional
cloudIdentityType The type of the GCP identity.
Can be either Service Account or a user.
  Optional

Playbook Outputs


Path Description Type
AWS.EC2.Instances The instances. unknown
AWS.EC2.Instances.NetworkInterfaces The network interfaces for the instance. unknown
GoogleCloudCompute.Instances The instances. unknown
GoogleCloudCompute.Instances.networkInterfaces An array of network configurations for this instance. These specify how interfaces are configured to interact with other network services, such as connecting to the internet. Multiple interfaces are supported per instance. unknown
GoogleCloudCompute.Instances.disks Array of disks associated with this instance. Persistent disks must be created before you can assign them. unknown
GoogleCloudCompute.Instances.metadata The metadata key/value pairs assigned to this instance. This includes custom metadata and predefined keys. unknown
GoogleCloudCompute.Instances.scheduling Sets the scheduling options for this instance. unknown
Azure.Compute The VMs. unknown
AWS.IAM.Users AWS AM Users include:
UserId
Arn
CreateDate
Path
PasswordLastUsed
unknown
AWS.IAM.UserPolicies AWS IAM - user inline policies. unknown
AWS.IAM.AttachedUserPolicies AWS IAM - User attached policies. unknown
AWS.IAM.Users.AccessKeys AWS IAM Users Access Keys include:
AccessKeyId
Status
CreateDate
UserName
unknown
AWS.IAM.Users.Groups AWS IAM - User groups. unknown
GCPIAM GCP IAM information. unknown
GSuite GSuite user information. unknown
MSGraphUser MSGraph user information. unknown
MSGraphGroups MSGraph groups information. unknown
MSGraphGroup MSGraph group information. unknown
GSuite.PageToken Token to specify the next page in the list. unknown
MSGraph.identityProtection MSGraph identity protection - risky user history. unknown
AWS.IAM.Users.AccessKeys.CreateDate The date when the access key was created. unknown
AWS.IAM.Users.AccessKeys.UserName The name of the IAM user that the key is associated with. unknown

Playbook Image


Cloud Enrichment - Generic

Inputs

  • cloudProvider — The cloud provider involved. The supported CSPs are AWS, Azure and GCP.
  • instanceName — The instance name.
  • instanceID — The instance ID.
  • zone — The zone holding the instance.
  • region — The region holding the instance.
  • azureResourceGroup — The instance's resource group.
  • username — The username involved.
  • GCPProjectName — The GCP project name.
  • cloudIdentityType — The type of the GCP identity. Can be either Service Account or a user.

Outputs

  • AWS.EC2.Instances — The instances.
  • AWS.EC2.Instances.NetworkInterfaces — The network interfaces for the instance.
  • GoogleCloudCompute.Instances — The instances.
  • GoogleCloudCompute.Instances.networkInterfaces — An array of network configurations for this instance. These specify how interfaces are configured to interact with other network services, such as connecting to the internet. Multiple interfaces are supported per instance.
  • GoogleCloudCompute.Instances.disks — Array of disks associated with this instance. Persistent disks must be created before you can assign them.
  • GoogleCloudCompute.Instances.metadata — The metadata key/value pairs assigned to this instance. This includes custom metadata and predefined keys.
  • GoogleCloudCompute.Instances.scheduling — Sets the scheduling options for this instance.
  • Azure.Compute — The VMs.
  • AWS.IAM.Users — AWS AM Users include: UserId Arn CreateDate Path PasswordLastUsed
  • AWS.IAM.UserPolicies — AWS IAM - user inline policies.
  • AWS.IAM.AttachedUserPolicies — AWS IAM - User attached policies.
  • AWS.IAM.Users.AccessKeys — AWS IAM Users Access Keys include: AccessKeyId Status CreateDate UserName
  • AWS.IAM.Users.Groups — AWS IAM - User groups.
  • GCPIAM — GCP IAM information.
  • GSuite — GSuite user information.
  • MSGraphUser — MSGraph user information.
  • MSGraphGroups — MSGraph groups information.
  • MSGraphGroup — MSGraph group information.
  • GSuite.PageToken — Token to specify the next page in the list.
  • MSGraph.identityProtection — MSGraph identity protection - risky user history.
  • AWS.IAM.Users.AccessKeys.CreateDate — The date when the access key was created.
  • AWS.IAM.Users.AccessKeys.UserName — The name of the IAM user that the key is associated with.

Flowchart

Start Start Cloud Compute Enrichment - Generic - Cloud Compute Enrichment - Generic Cloud Compute Enrichment ... Cloud Compute Enrichment - Ge... Done Done Cloud IAM Enrichment - Generic - Cloud IAM Enrichment - Generic Cloud IAM Enrichment - Ge... Cloud IAM Enrichment - Generic
id: Cloud Enrichment - Generic
version: -1
name: Cloud Enrichment - Generic
description: |2-

  ## Generic Cloud Enrichment Playbook

  The **Cloud Enrichment - Generic Playbook** is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments.

  ### Supported Blocks

  1. **Cloud IAM Enrichment - Generic**
     - Enriches information related to Identity and Access Management (IAM) in the cloud.

  2. **Cloud Compute Enrichment - Generic**
     - Enriches information related to cloud compute resources.

  The playbook supports a single CSP enrichment at a time.

starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 22defffa-e0d3-4818-88f0-f06649899f77
    type: start
    task:
      id: 22defffa-e0d3-4818-88f0-f06649899f77
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "2"
      - "7"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 230,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: cb7ff971-4a63-4338-8fd0-0e3c6b383627
    type: playbook
    task:
      id: cb7ff971-4a63-4338-8fd0-0e3c6b383627
      version: -1
      name: Cloud Compute Enrichment - Generic
      playbookName: Cloud Compute Enrichment - Generic
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "6"
    scriptarguments:
      azureResourceGroup:
        complex:
          root: inputs.azureResourceGroup
      cloudProvider:
        complex:
          root: inputs.cloudProvider
      instanceID:
        complex:
          root: inputs.instanceID
      instanceName:
        complex:
          root: inputs.instanceName
      region:
        complex:
          root: inputs.region
      zone:
        complex:
          root: inputs.zone
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 10,
          "y": 190
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: ca18fe4c-e928-4db8-8fb5-a00f434242ba
    type: title
    task:
      id: ca18fe4c-e928-4db8-8fb5-a00f434242ba
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 230,
          "y": 360
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: 6112c304-54e5-4954-85d2-44b1e4e9ab75
    type: playbook
    task:
      id: 6112c304-54e5-4954-85d2-44b1e4e9ab75
      version: -1
      name: Cloud IAM Enrichment - Generic
      description: This playbook is responsible for collecting and enriching data on Identity Access Management (IAM) in cloud environments (AWS, Azure, and GCP).
      playbookName: Cloud IAM Enrichment - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "6"
    scriptarguments:
      GCPProjectName:
        complex:
          root: inputs.GCPProjectName
      cloudIdentityType:
        complex:
          root: inputs.cloudIdentityType
      cloudProvider:
        complex:
          root: inputs.cloudProvider
      username:
        complex:
          root: inputs.username
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 450,
          "y": 190
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 375,
        "width": 820,
        "x": 10,
        "y": 50
      }
    }
  }
inputs:
- key: cloudProvider
  value: {}
  required: false
  description: |-
    The cloud provider involved.
    The supported CSPs are AWS, Azure and GCP.
  playbookInputQuery:
- key: instanceName
  value: {}
  required: false
  description: The instance name.
  playbookInputQuery:
- key: instanceID
  value: {}
  required: false
  description: The instance ID.
  playbookInputQuery:
- key: zone
  value: {}
  required: false
  description: The zone holding the instance.
  playbookInputQuery:
- key: region
  value: {}
  required: false
  description: The region holding the instance.
  playbookInputQuery:
- key: azureResourceGroup
  value: {}
  required: false
  description: The instance's resource group.
  playbookInputQuery:
- key: username
  value: {}
  required: false
  description: The username involved.
  playbookInputQuery:
- key: GCPProjectName
  value: {}
  required: false
  description: The GCP project name.
  playbookInputQuery:
- key: cloudIdentityType
  value: {}
  required: false
  description: |-
    The type of the GCP identity.
    Can be either Service Account or a user.
  playbookInputQuery:
outputs:
- contextPath: AWS.EC2.Instances
  description: The instances.
  type: unknown
- contextPath: AWS.EC2.Instances.NetworkInterfaces
  description: The network interfaces for the instance.
  type: unknown
- contextPath: GoogleCloudCompute.Instances
  description: The instances.
  type: unknown
- contextPath: GoogleCloudCompute.Instances.networkInterfaces
  description: An array of network configurations for this instance. These specify how interfaces are configured to interact with other network services, such as connecting to the internet. Multiple interfaces are supported per instance.
- contextPath: GoogleCloudCompute.Instances.disks
  description: Array of disks associated with this instance. Persistent disks must be created before you can assign them.
- contextPath: GoogleCloudCompute.Instances.metadata
  description: The metadata key/value pairs assigned to this instance. This includes custom metadata and predefined keys.
- contextPath: GoogleCloudCompute.Instances.scheduling
  description: Sets the scheduling options for this instance.
- contextPath: Azure.Compute
  description: The VMs.
  type: unknown
- contextPath: AWS.IAM.Users
  description: |-
    AWS AM Users include:
    UserId
    Arn
    CreateDate
    Path
    PasswordLastUsed
  type: unknown
- contextPath: AWS.IAM.UserPolicies
  description: AWS IAM - user inline policies.
  type: unknown
- contextPath: AWS.IAM.AttachedUserPolicies
  description: AWS IAM - User attached policies.
  type: unknown
- contextPath: AWS.IAM.Users.AccessKeys
  description: |-
    AWS IAM Users Access Keys include:
    AccessKeyId
    Status
    CreateDate
    UserName
  type: unknown
- contextPath: AWS.IAM.Users.Groups
  description: AWS IAM - User groups.
  type: unknown
- contextPath: GCPIAM
  description: GCP IAM information.
  type: unknown
- contextPath: GSuite
  description: GSuite user information.
  type: unknown
- contextPath: MSGraphUser
  description: MSGraph user information.
  type: unknown
- contextPath: MSGraphGroups
  description: MSGraph groups information.
  type: unknown
- contextPath: MSGraphGroup
  description: MSGraph group information.
  type: unknown
- contextPath: GSuite.PageToken
  description: Token to specify the next page in the list.
  type: unknown
- contextPath: MSGraph.identityProtection
  description: MSGraph identity protection - risky user history.
  type: unknown
- contextPath: AWS.IAM.Users.AccessKeys.CreateDate
  description: The date when the access key was created.
- contextPath: AWS.IAM.Users.AccessKeys.UserName
  description: The name of the IAM user that the key is associated with.
quiet: false
tests:
- No tests (auto formatted)
fromversion: 6.8.0