Cloud Enrichment - Generic
## Generic Cloud Enrichment Playbook The **Cloud Enrichment - Generic Playbook** is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments. ### Supported Blocks 1. **Cloud IAM Enrichment - Generic** - Enriches information related to Identity and Access Management (IAM) in the cloud. 2. **Cloud Compute Enrichment - Generic** - Enriches information related to cloud compute resources. The playbook supports a single CSP enrichment at a time.
Common Playbooks · 4 tasks · 9 inputs · 22 outputs
Details
| ID | Cloud Enrichment - Generic |
|---|---|
| From Version | 6.8.0 |
| Tasks | 4 |
README
Generic Cloud Enrichment Playbook
The Cloud Enrichment - Generic Playbook is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments.
Supported Blocks
- Cloud IAM Enrichment - Generic
- Enriches information related to Identity and Access Management (IAM) in the cloud.
- Cloud Compute Enrichment - Generic
- Enriches information related to cloud compute resources.
The playbook supports a single CSP enrichment at a time.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Cloud IAM Enrichment - Generic
- Cloud Compute Enrichment - Generic
Integrations
This playbook does not use any integrations.
Scripts
This playbook does not use any scripts.
Commands
This playbook does not use any commands.
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| cloudProvider | The cloud provider involved. The supported CSPs are AWS, Azure and GCP. |
Optional | |
| instanceName | The instance name. | Optional | |
| instanceID | The instance ID. | Optional | |
| zone | The zone holding the instance. | Optional | |
| region | The region holding the instance. | Optional | |
| azureResourceGroup | The instance’s resource group. | Optional | |
| username | The username involved. | Optional | |
| GCPProjectName | The GCP project name. | Optional | |
| cloudIdentityType | The type of the GCP identity. Can be either Service Account or a user. |
Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| AWS.EC2.Instances | The instances. | unknown |
| AWS.EC2.Instances.NetworkInterfaces | The network interfaces for the instance. | unknown |
| GoogleCloudCompute.Instances | The instances. | unknown |
| GoogleCloudCompute.Instances.networkInterfaces | An array of network configurations for this instance. These specify how interfaces are configured to interact with other network services, such as connecting to the internet. Multiple interfaces are supported per instance. | unknown |
| GoogleCloudCompute.Instances.disks | Array of disks associated with this instance. Persistent disks must be created before you can assign them. | unknown |
| GoogleCloudCompute.Instances.metadata | The metadata key/value pairs assigned to this instance. This includes custom metadata and predefined keys. | unknown |
| GoogleCloudCompute.Instances.scheduling | Sets the scheduling options for this instance. | unknown |
| Azure.Compute | The VMs. | unknown |
| AWS.IAM.Users | AWS AM Users include: UserId Arn CreateDate Path PasswordLastUsed |
unknown |
| AWS.IAM.UserPolicies | AWS IAM - user inline policies. | unknown |
| AWS.IAM.AttachedUserPolicies | AWS IAM - User attached policies. | unknown |
| AWS.IAM.Users.AccessKeys | AWS IAM Users Access Keys include: AccessKeyId Status CreateDate UserName |
unknown |
| AWS.IAM.Users.Groups | AWS IAM - User groups. | unknown |
| GCPIAM | GCP IAM information. | unknown |
| GSuite | GSuite user information. | unknown |
| MSGraphUser | MSGraph user information. | unknown |
| MSGraphGroups | MSGraph groups information. | unknown |
| MSGraphGroup | MSGraph group information. | unknown |
| GSuite.PageToken | Token to specify the next page in the list. | unknown |
| MSGraph.identityProtection | MSGraph identity protection - risky user history. | unknown |
| AWS.IAM.Users.AccessKeys.CreateDate | The date when the access key was created. | unknown |
| AWS.IAM.Users.AccessKeys.UserName | The name of the IAM user that the key is associated with. | unknown |
Playbook Image

Inputs
cloudProvider— The cloud provider involved. The supported CSPs are AWS, Azure and GCP.instanceName— The instance name.instanceID— The instance ID.zone— The zone holding the instance.region— The region holding the instance.azureResourceGroup— The instance's resource group.username— The username involved.GCPProjectName— The GCP project name.cloudIdentityType— The type of the GCP identity. Can be either Service Account or a user.
Outputs
AWS.EC2.Instances— The instances.AWS.EC2.Instances.NetworkInterfaces— The network interfaces for the instance.GoogleCloudCompute.Instances— The instances.GoogleCloudCompute.Instances.networkInterfaces— An array of network configurations for this instance. These specify how interfaces are configured to interact with other network services, such as connecting to the internet. Multiple interfaces are supported per instance.GoogleCloudCompute.Instances.disks— Array of disks associated with this instance. Persistent disks must be created before you can assign them.GoogleCloudCompute.Instances.metadata— The metadata key/value pairs assigned to this instance. This includes custom metadata and predefined keys.GoogleCloudCompute.Instances.scheduling— Sets the scheduling options for this instance.Azure.Compute— The VMs.AWS.IAM.Users— AWS AM Users include: UserId Arn CreateDate Path PasswordLastUsedAWS.IAM.UserPolicies— AWS IAM - user inline policies.AWS.IAM.AttachedUserPolicies— AWS IAM - User attached policies.AWS.IAM.Users.AccessKeys— AWS IAM Users Access Keys include: AccessKeyId Status CreateDate UserNameAWS.IAM.Users.Groups— AWS IAM - User groups.GCPIAM— GCP IAM information.GSuite— GSuite user information.MSGraphUser— MSGraph user information.MSGraphGroups— MSGraph groups information.MSGraphGroup— MSGraph group information.GSuite.PageToken— Token to specify the next page in the list.MSGraph.identityProtection— MSGraph identity protection - risky user history.AWS.IAM.Users.AccessKeys.CreateDate— The date when the access key was created.AWS.IAM.Users.AccessKeys.UserName— The name of the IAM user that the key is associated with.
Flowchart
id: Cloud Enrichment - Generic version: -1 name: Cloud Enrichment - Generic description: |2- ## Generic Cloud Enrichment Playbook The **Cloud Enrichment - Generic Playbook** is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments. ### Supported Blocks 1. **Cloud IAM Enrichment - Generic** - Enriches information related to Identity and Access Management (IAM) in the cloud. 2. **Cloud Compute Enrichment - Generic** - Enriches information related to cloud compute resources. The playbook supports a single CSP enrichment at a time. starttaskid: "0" tasks: "0": id: "0" taskid: 22defffa-e0d3-4818-88f0-f06649899f77 type: start task: id: 22defffa-e0d3-4818-88f0-f06649899f77 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "2" - "7" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 230, "y": 50 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "2": id: "2" taskid: cb7ff971-4a63-4338-8fd0-0e3c6b383627 type: playbook task: id: cb7ff971-4a63-4338-8fd0-0e3c6b383627 version: -1 name: Cloud Compute Enrichment - Generic playbookName: Cloud Compute Enrichment - Generic type: playbook iscommand: false brand: "" description: '' nexttasks: '#none#': - "6" scriptarguments: azureResourceGroup: complex: root: inputs.azureResourceGroup cloudProvider: complex: root: inputs.cloudProvider instanceID: complex: root: inputs.instanceID instanceName: complex: root: inputs.instanceName region: complex: root: inputs.region zone: complex: root: inputs.zone separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 10, "y": 190 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "6": id: "6" taskid: ca18fe4c-e928-4db8-8fb5-a00f434242ba type: title task: id: ca18fe4c-e928-4db8-8fb5-a00f434242ba version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 230, "y": 360 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "7": id: "7" taskid: 6112c304-54e5-4954-85d2-44b1e4e9ab75 type: playbook task: id: 6112c304-54e5-4954-85d2-44b1e4e9ab75 version: -1 name: Cloud IAM Enrichment - Generic description: This playbook is responsible for collecting and enriching data on Identity Access Management (IAM) in cloud environments (AWS, Azure, and GCP). playbookName: Cloud IAM Enrichment - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "6" scriptarguments: GCPProjectName: complex: root: inputs.GCPProjectName cloudIdentityType: complex: root: inputs.cloudIdentityType cloudProvider: complex: root: inputs.cloudProvider username: complex: root: inputs.username separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 450, "y": 190 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 375, "width": 820, "x": 10, "y": 50 } } } inputs: - key: cloudProvider value: {} required: false description: |- The cloud provider involved. The supported CSPs are AWS, Azure and GCP. playbookInputQuery: - key: instanceName value: {} required: false description: The instance name. playbookInputQuery: - key: instanceID value: {} required: false description: The instance ID. playbookInputQuery: - key: zone value: {} required: false description: The zone holding the instance. playbookInputQuery: - key: region value: {} required: false description: The region holding the instance. playbookInputQuery: - key: azureResourceGroup value: {} required: false description: The instance's resource group. playbookInputQuery: - key: username value: {} required: false description: The username involved. playbookInputQuery: - key: GCPProjectName value: {} required: false description: The GCP project name. playbookInputQuery: - key: cloudIdentityType value: {} required: false description: |- The type of the GCP identity. Can be either Service Account or a user. playbookInputQuery: outputs: - contextPath: AWS.EC2.Instances description: The instances. type: unknown - contextPath: AWS.EC2.Instances.NetworkInterfaces description: The network interfaces for the instance. type: unknown - contextPath: GoogleCloudCompute.Instances description: The instances. type: unknown - contextPath: GoogleCloudCompute.Instances.networkInterfaces description: An array of network configurations for this instance. These specify how interfaces are configured to interact with other network services, such as connecting to the internet. Multiple interfaces are supported per instance. - contextPath: GoogleCloudCompute.Instances.disks description: Array of disks associated with this instance. Persistent disks must be created before you can assign them. - contextPath: GoogleCloudCompute.Instances.metadata description: The metadata key/value pairs assigned to this instance. This includes custom metadata and predefined keys. - contextPath: GoogleCloudCompute.Instances.scheduling description: Sets the scheduling options for this instance. - contextPath: Azure.Compute description: The VMs. type: unknown - contextPath: AWS.IAM.Users description: |- AWS AM Users include: UserId Arn CreateDate Path PasswordLastUsed type: unknown - contextPath: AWS.IAM.UserPolicies description: AWS IAM - user inline policies. type: unknown - contextPath: AWS.IAM.AttachedUserPolicies description: AWS IAM - User attached policies. type: unknown - contextPath: AWS.IAM.Users.AccessKeys description: |- AWS IAM Users Access Keys include: AccessKeyId Status CreateDate UserName type: unknown - contextPath: AWS.IAM.Users.Groups description: AWS IAM - User groups. type: unknown - contextPath: GCPIAM description: GCP IAM information. type: unknown - contextPath: GSuite description: GSuite user information. type: unknown - contextPath: MSGraphUser description: MSGraph user information. type: unknown - contextPath: MSGraphGroups description: MSGraph groups information. type: unknown - contextPath: MSGraphGroup description: MSGraph group information. type: unknown - contextPath: GSuite.PageToken description: Token to specify the next page in the list. type: unknown - contextPath: MSGraph.identityProtection description: MSGraph identity protection - risky user history. type: unknown - contextPath: AWS.IAM.Users.AccessKeys.CreateDate description: The date when the access key was created. - contextPath: AWS.IAM.Users.AccessKeys.UserName description: The name of the IAM user that the key is associated with. quiet: false tests: - No tests (auto formatted) fromversion: 6.8.0