CyberBlindspot Incident Management

This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to assist the user in the next course of action (Whether it be closing the incident, initiating the takedown of an online asset or simply waiting for a process on the remote server to end) to take on the incident if any.

CTM360 · 20 tasks · 0 inputs · 0 outputs

Details

IDCyberBlindspot Incident Management
From Version6.10.0
Tasks20

README

This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to assist the user in the next course of action (Whether it be closing the incident, initiating the takedown of an online asset or simply waiting for a process on the remote server to end) to take on the incident if any.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Entity Enrichment - Generic v3

Integrations

  • CTM360_CyberBlindspot

Scripts

  • AssignAnalystToIncident
  • Print

Commands

  • ctm360-cbs-incident-request-takedown
  • ctm360-cbs-incident-details
  • closeInvestigation

Playbook Inputs


There are no inputs for this playbook.

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


CyberBlindspot Incident Management

Commands used

closeInvestigation ctm360-cbs-incident-details ctm360-cbs-incident-request-takedown

Flowchart

yes WIP yes Close and Takedown Allowed Close Incident No Action Close Incident Initiate Takedown of Asset No Action yes Start Start Get Incident Remote Status - ctm360-cbs-incident-details Get Incident Remote Status ctm360-cbs-incident-details Check Remote Status Check Remote Status Check if CyberBlindspot Closed The Incident Check if CyberBlindspot C... Close Incident Locally - closeInvestigation Close Incident Locally closeInvestigation Check if User can Take Action(s) Check if User can Take Ac... Initiate Takedown - ctm360-cbs-incident-request-takedown Initiate Takedown ctm360-cbs-incident-request-t... Check Allowed Action(s) Check Allowed Action(s) Prompt User to Close Incident Prompt User to Close Inci... End of Playbook End of Playbook End of Playbook End of Playbook Shortcut to Close Incident Shortcut to Close Incident Assign Analyst Assign Analyst Assign Analyst - AssignAnalystToIncident Assign Analyst AssignAnalystToIncident Prompt User to Close Incident or Request Takedown of Asset Prompt User to Close Inci... Entity Enrichment - Generic v3 - Entity Enrichment - Generic v3 Entity Enrichment - Gener... Entity Enrichment - Generic v3 Check Mirroring Check Mirroring Check if Incoming Mirroring is Enabled Check if Incoming Mirrori... End of Playbook End of Playbook Inform User Regarding Incident Status On Remote - Print Inform User Regarding Inc... Print
This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to assist the user in the next course of action (Whether it be closing the incident, initiating the takedown of an online asset or simply waiting for a process on the remote server to end) to take on the incident if any.

## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

### Sub-playbooks

Entity Enrichment - Generic v3

### Integrations

CTM360_CyberBlindspot

### Scripts

* AssignAnalystToIncident
* Print

### Commands

* closeInvestigation
* ctm360-cbs-incident-details
* ctm360-cbs-incident-request-takedown

## Playbook Inputs

---
There are no inputs for this playbook.

## Playbook Outputs

---
There are no outputs for this playbook.

## Playbook Image

---

![CyberBlindspot Incident Management V2](../doc_files/CyberBlindspot_Incident_Management_V2.png)