DSPM Multi-Cloud Risk Remediation

The playbook ensures efficient incident resolution and compliance with security policies by guiding the user through decision points based on incident type, such as empty storage assets or assets open to the world. It concludes by updating the incident status and closing the playbook upon resolution.

DSPM · 38 tasks · 3 inputs · 0 outputs

Details

IDDSPM Multi-Cloud Risk Remediation
From Version6.10.0
Tasks38

README

The playbook ensures efficient incident resolution and compliance with security policies by guiding the user through decision points based on incident type, such as empty storage assets or assets open to the world. It concludes by updating the incident status and closing the playbook upon resolution.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • DSPM Valid User Response
  • Send slack notificaton to user
  • Invalid response sending notification to user again
  • DSPM notify user in case of error

Integrations

This playbook does not use any integrations.

Scripts

  • DSPMCreateSimpleSlackMessageBlock
  • DSPMCheckAndSetErrorEntries
  • IsIntegrationAvailable
  • DSPMIncidentList
  • DSPMExtractRiskDetails
  • DeleteContext
  • DSPMCreateRiskSlackBlocks
  • isError
  • SlackBlockBuilder

Commands

  • createList
  • setList
  • getList
  • addToList
  • closeInvestigation
  • core-api-post

Playbook Inputs


Name Description Default Value Required
defaultSlackUserName In the event that the risk asset tag is absent, the risk notice will be sent to this Slack user email address. dummy@mail.com Required
slackMessageLifetime Lifetime for slack notification (in seconds) 300 Optional
rerunTime Incident re-run time (in hours) 24 Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


DSPM Multi-Cloud Risk Remediation

Inputs

  • defaultSlackUserName — In the event that the risk asset tag is absent, the risk notice will be sent to this Slack user email address.
  • slackMessageLifetime — Lifetime for slack notification (in seconds)
  • rerunTime — Incident re-run time (in hours)

Commands used

addToList closeInvestigation core-api-post createList getList setList

Flowchart

no yes no yes Invalid response Valid response no yes Invalid response Valid response #error# no yes #error# #error# add Start Start Closed current Incident playbook - closeInvestigation Closed current Incident ... closeInvestigation Get DSPM risk details - DSPMExtractRiskDetails Get DSPM risk details DSPMExtractRiskDetails Create a Slackblock list to send a user notification displaying risk information. - DSPMCreateRiskSlackBlocks Create a Slackblock list ... DSPMCreateRiskSlackBlocks Removing ${block_list_name} list from XSOAR LIST - core-api-post Removing ${block_list_nam... core-api-post Error while retrieving DSPM risk details? - DSPMCheckAndSetErrorEntries Error while retrieving DS... DSPMCheckAndSetErrorEntries Errors occurred when developing the Slack block list for the incident ID : ${incident.id} - DSPMCheckAndSetErrorEntries Errors occurred when deve... DSPMCheckAndSetErrorEntries closeInvestigation - closeInvestigation closeInvestigation closeInvestigation DSPM notify user in case of error - DSPM notify user in case of error DSPM notify user in case ... DSPM notify user in case of e... Delete incident from INCIDENT LIST - DSPMIncidentList Delete incident from INCI... DSPMIncidentList Check if the user action is invalid? Check if the user action ... Is there any error occurred in DSPM Invalid Response playbook? - isError Is there any error occurr... isError Create Slack block sending notification to user. - DSPMCreateSimpleSlackMessageBlock Create Slack block sendin... DSPMCreateSimpleSlackMessageB... Identify User-Selected Action Identify User-Selected Ac... DSPM Valid User Response - DSPM Valid User Response DSPM Valid User Response DSPM Valid User Response Sending notification to ${userSlackEmail} - SlackBlockBuilder Sending notification to $... SlackBlockBuilder Done Done Check list exists for Incident ID : ${incident.id} - getList Check list exists for Inc... getList Create new XSOAR list for Incident ID : ${incident.id} - createList Create new XSOAR list for... createList Save the customised slack block to the new XSOAR list. - createList Save the customised slack... createList Save the above slack block to the XSOAR list. - setList Save the above slack bloc... setList DSPM Send Slack Notification to User - DSPM Send Slack Notification to User DSPM Send Slack Notificat... DSPM Send Slack Notification ... DSPM Send Slack Notification to User - DSPM Send Slack Notification to User DSPM Send Slack Notificat... DSPM Send Slack Notification ... Notify user about error Notify user about error Create slack block message to send user Create slack block messag... Send slack notification to user Send slack notification t... Remediate Risk or Create Jira ticket Remediate Risk or Create ... Send an invalid response notification to the user and resend the remediation notification form to the user Send an invalid response ... Is Slack Integration available? - IsIntegrationAvailable Is Slack Integration avai... IsIntegrationAvailable Get DSPM Incident List - getList Get DSPM Incident List getList Create DSPM Incident list - createList Create DSPM Incident list createList Add incident for re-run - DSPMIncidentList Add incident for re-run DSPMIncidentList Get DSPM Incident List - getList Get DSPM Incident List getList Check incident list status? Check incident list status? Add incident in DSPM Incident list - addToList Add incident in DSPM Inc... addToList Clear previous all context data! - DeleteContext Clear previous all contex... DeleteContext Deleting slack block from context data after saving into xsoar list. - DeleteContext Deleting slack block from... DeleteContext Deleting slack block from context after saving into xsoar list. - DeleteContext Deleting slack block from... DeleteContext
id: DSPM Multi-Cloud Risk Remediation
version: -1
name: DSPM Multi-Cloud Risk Remediation
description: The playbook ensures efficient incident resolution and compliance with security policies by guiding the user through decision points based on incident type, such as empty storage assets or assets open to the world. It concludes by updating the incident status and closing the playbook upon resolution.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: bf838bc6-fd32-4cfb-8907-d8ab44600b88
    type: start
    task:
      id: bf838bc6-fd32-4cfb-8907-d8ab44600b88
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "91"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 705,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: d71509bd-4b68-4fd5-847a-750dad4f305a
    type: regular
    task:
      id: d71509bd-4b68-4fd5-847a-750dad4f305a
      version: -1
      name: Closed current  Incident playbook
      description: commands.local.cmd.close.inv
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "69"
    scriptarguments:
      closeReason:
        simple: Resolved
      id:
        simple: ${incident.id}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 5180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "25":
    id: "25"
    taskid: 99a6d2c6-22ed-4591-8e5d-4caf2802a1d7
    type: regular
    task:
      id: 99a6d2c6-22ed-4591-8e5d-4caf2802a1d7
      version: -1
      name: Get DSPM risk details
      scriptName: DSPMExtractRiskDetails
      type: regular
      iscommand: false
      brand: ""
      description: "This script extracts risk details from an incident object"
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      defaultSlackUser:
        simple: ${inputs.defaultSlackUserName}
      incident_object:
        simple: ${incident}
    results:
    - userSlackEmail
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 817.5,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: 58e1b935-b074-468b-894c-7e6e67c78d5d
    type: regular
    task:
      id: 58e1b935-b074-468b-894c-7e6e67c78d5d
      version: -1
      name: Create a Slackblock list to send a user notification displaying risk information.
      description: This XSOAR automation script generates a Slack message block to notify users of risks detected by a Data Security Posture Management (DSPM) tool. The Slack block is dynamically constructed based on the details of the security incident and includes options for users to take specific actions, such as creating a Jira ticket or remediating the risk.
      scriptName: DSPMCreateRiskSlackBlocks
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "72"
    scriptarguments:
      dspm_incident:
        simple: ${incident_object}
      dspmIncident:
        simple: ${incident_object}
      incidentLink:
        simple: ${demistoUrls.investigation}
      list_of_project:
        simple: ${projects_list}
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 1040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: 04f04a2c-48d4-45de-84bc-278fb5cf6abc
    type: regular
    task:
      id: 04f04a2c-48d4-45de-84bc-278fb5cf6abc
      version: -1
      name: Removing ${block_list_name} list from XSOAR LIST
      description: send HTTP POST request.
      script: '|||core-api-post'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "83"
    scriptarguments:
      body:
        simple: '{"id":"slack block of Incident ID : ${incident.id}"}'
      uri:
        simple: /lists/delete
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 4655
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: a3fa951e-294b-4dd2-8186-eb09df490d17
    type: condition
    task:
      id: a3fa951e-294b-4dd2-8186-eb09df490d17
      version: -1
      name: Error while retrieving DSPM risk details?
      description: This script checks for error entries based on provided entry IDs and returns "yes" if any errors are found or "no" if no errors are present. If errors are detected, it sets the error messages in the XSOAR context.
      scriptName: DSPMCheckAndSetErrorEntries
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "77"
      "yes":
      - "76"
    scriptarguments:
      entry_id:
        simple: ${lastCompletedTaskEntries}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 817.5,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: 3aa32a75-bc46-4852-8f17-df11598270d5
    type: condition
    task:
      id: 3aa32a75-bc46-4852-8f17-df11598270d5
      version: -1
      name: 'Errors occurred when developing the Slack block list for the incident ID : ${incident.id}'
      description: This script checks for error entries based on provided entry IDs and returns "yes" if any errors are found or "no" if no errors are present. If errors are detected, it sets the error messages in the XSOAR context.
      scriptName: DSPMCheckAndSetErrorEntries
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "78"
      "yes":
      - "76"
    scriptarguments:
      entry_id:
        simple: ${lastCompletedTaskEntries}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 1565
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "38":
    id: "38"
    taskid: b99382b5-a6ec-49a5-865f-378c34948474
    type: regular
    task:
      id: b99382b5-a6ec-49a5-865f-378c34948474
      version: -1
      name: closeInvestigation
      description: Close the current incident
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "69"
    scriptarguments:
      closeNotes:
        simple: Closing the playbook before sending notification to user.
      closeReason:
        simple: Unable to create custom slack block for this incident.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1175,
          "y": 2060
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "51":
    id: "51"
    taskid: e2fe1e30-6db6-49a0-8968-c199fd25a849
    type: playbook
    task:
      id: e2fe1e30-6db6-49a0-8968-c199fd25a849
      version: -1
      name: DSPM notify user in case of error
      description: The DSPM Notify User in Case of Error playbook is designed to handle errors in DSPM incidents by notifying users and managing Slack notifications.
      playbookName: DSPM notify user in case of error
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "38"
    scriptarguments:
      rerunTime:
        simple: ${inputs.rerunTime}
    separatecontext: false
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1175,
          "y": 1885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "60":
    id: "60"
    taskid: 8aa1b623-74a2-4653-8207-da31101c0e77
    type: regular
    task:
      id: 8aa1b623-74a2-4653-8207-da31101c0e77
      version: -1
      name: Delete incident from INCIDENT LIST
      scriptName: DSPMIncidentList
      type: regular
      iscommand: false
      brand: ""
      description: "Delete incident from INCIDENT LIST"
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      action:
        simple: delete
      incident_data:
        simple: ${incident_object}
      incident_list:
        simple: ${lists.INCIDENT_LIST2}
      rerun_time:
        simple: ${inputs.rerunTime}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 735,
          "y": 5005
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "61":
    id: "61"
    taskid: 568e1c3d-4b36-42d4-8f6f-4ec55e38da80
    type: condition
    task:
      id: 568e1c3d-4b36-42d4-8f6f-4ec55e38da80
      version: -1
      name: Check if the user action is invalid?
      type: condition
      iscommand: false
      brand: ""
      description: "Check if the user action is invalid?"
    nexttasks:
      Invalid response:
      - "80"
      Valid response:
      - "79"
    separatecontext: false
    conditions:
    - label: Invalid response
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: invalid_response
    - label: Valid response
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: jira
        - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: no_response
        - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: remediate
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 2060
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "63":
    id: "63"
    taskid: 88493bf0-afee-4721-8ace-a08465534d89
    type: condition
    task:
      id: 88493bf0-afee-4721-8ace-a08465534d89
      version: -1
      name: Is there any error occurred in DSPM Invalid Response playbook?
      description: Check whether given entry/entries returned an error. Use ${lastCompletedTaskEntries} to check the previous task entries. If array is provided, will return yes if one of the entries returned an error.
      scriptName: isError
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "66"
      "yes":
      - "28"
    scriptarguments:
      entryId:
        simple: ${lastCompletedTaskEntries}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 490,
          "y": 2555
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "64":
    id: "64"
    taskid: e82596dc-9e18-43e5-884f-70d56c62425d
    type: regular
    task:
      id: e82596dc-9e18-43e5-884f-70d56c62425d
      version: -1
      name: Create Slack block sending notification to user.
      description: This automation script overwrites the value of a specified list and sends a Slack notification to inform the user that they failed to respond to an incident notification in a timely manner. The notification includes a message indicating the end of the incident playbook and an invitation to reopen the incident if necessary.
      scriptName: DSPMCreateSimpleSlackMessageBlock
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "73"
    scriptarguments:
      incident_id:
        simple: ${incident_object.incidentId}
      incidentLink:
        simple: ${demistoUrls.investigation}
      list_name:
        simple: ${block_list_name}
      message:
        simple: "You have provided invalid response to ${incident_object.incidentId} \n Incident notification. We will resend the notification for Incident ${incident_object.incidentId} respond with valid details when slack message lifetime expires.\nRegards."
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 3255
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "66":
    id: "66"
    taskid: 157e00b4-c609-4d71-8dea-ce1c237a6fb4
    type: condition
    task:
      id: 157e00b4-c609-4d71-8dea-ce1c237a6fb4
      version: -1
      name: Identify User-Selected Action
      type: condition
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      Invalid response:
      - "70"
      Valid response:
      - "79"
    separatecontext: false
    conditions:
    - label: Invalid response
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: invalid_response
    - label: Valid response
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: jira
        - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: remediate
        - operator: isEqualString
          left:
            value:
              simple: User.Action
            iscontext: true
          right:
            value:
              simple: no_response
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 377.5,
          "y": 2730
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "67":
    id: "67"
    taskid: 4bf94281-0377-4806-8f0d-4180c101083d
    type: playbook
    task:
      id: 4bf94281-0377-4806-8f0d-4180c101083d
      version: -1
      name: DSPM Valid User Response
      playbookName: DSPM Valid User Response
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      rerunTime:
        simple: ${inputs.rerunTime}
    separatecontext: false
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 3080
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "68":
    id: "68"
    taskid: f4a07585-b29b-433c-8c6d-9960361c67f8
    type: regular
    task:
      id: f4a07585-b29b-433c-8c6d-9960361c67f8
      version: -1
      name: Sending notification to ${userSlackEmail}
      description: SlackBlockBuilder will format a given Slack block into a format readable by the SlackV3 integration. The script will also send the block to the given destination. Make sure to mark **Trust any certificate** and fill the **XSOAR API Key integration** parameters if you want to get a response to the incident context.
      scriptName: SlackBlockBuilder
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "88"
    scriptarguments:
      list_name:
        simple: 'slack block of Incident ID : ${incident.id}'
      user:
        simple: ${userSlackEmail}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 3780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "69":
    id: "69"
    taskid: d8e1a41e-082d-4466-8273-60432fe78b66
    type: title
    task:
      id: d8e1a41e-082d-4466-8273-60432fe78b66
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 377.5,
          "y": 5355
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "70":
    id: "70"
    taskid: a13704ca-44b5-47ed-8490-6edff334fb74
    type: regular
    task:
      id: a13704ca-44b5-47ed-8490-6edff334fb74
      version: -1
      name: 'Check list exists for Incident ID : ${incident.id}'
      description: commands.local.cmd.list.get
      script: Builtin|||getList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#error#':
      - "71"
      '#none#':
      - "64"
    scriptarguments:
      listName:
        simple: 'slack block of Incident ID : ${incident.id}'
    separatecontext: false
    continueonerror: true
    continueonerrortype: errorPath
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 2905
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "71":
    id: "71"
    taskid: f2f60e7f-ae65-464a-89b6-c48f00dec79c
    type: regular
    task:
      id: f2f60e7f-ae65-464a-89b6-c48f00dec79c
      version: -1
      name: 'Create new XSOAR list for Incident ID : ${incident.id}'
      description: commands.local.cmd.list.create
      script: Builtin|||createList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "64"
    scriptarguments:
      listData:
        simple: '{}'
      listName:
        simple: 'slack block of Incident ID : ${incident.id}'
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 3080
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "72":
    id: "72"
    taskid: 6285650a-9c2c-49a2-81e2-fefba069c667
    type: regular
    task:
      id: 6285650a-9c2c-49a2-81e2-fefba069c667
      version: -1
      name: Save the customised slack block to the new XSOAR list.
      description: commands.local.cmd.list.create
      script: Builtin|||createList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "92"
    scriptarguments:
      listData:
        simple: ${slackBlock.block}
      listName:
        simple: 'slack block of Incident ID : ${incident.id}'
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 1215
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "73":
    id: "73"
    taskid: b70e6dec-5de1-4e94-8e06-828222ab2880
    type: regular
    task:
      id: b70e6dec-5de1-4e94-8e06-828222ab2880
      version: -1
      name: Save the above slack block to the XSOAR list.
      description: Set data in list
      script: Builtin|||setList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "93"
    scriptarguments:
      listData:
        simple: ${slackBlock}
      listName:
        simple: 'slack block of Incident ID : ${incident.id}'
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 3430
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "74":
    id: "74"
    taskid: 29ed342a-8e51-4b16-87d0-2799f1738668
    type: playbook
    task:
      id: 29ed342a-8e51-4b16-87d0-2799f1738668
      version: -1
      name: DSPM Send Slack Notification to User
      description: "The 'Send Slack Notification to User' playbook is designed to notify a user via Slack and handle their response. It begins by sending a Slack notification to a specified email using the SlackBlockBuilder script. Afterwards, it waits for the user's response until a predefined time, as configured in Prisma Cloud DSPM. Once the response is received, it is inserted into the incident's context. If there is an error in generating the Slack block, the incident is added for a re-run. Finally, the playbook extracts the user's response from the Slack block state for further processing."
      playbookName: DSPM Send Slack Notification to User
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "61"
    scriptarguments:
      flowPath:
        simple: slack
      incident_object:
        simple: ${incident_object}
      rerunTime:
        simple: ${inputs.rerunTime}
      slackMessageLifetime:
        simple: ${inputs.slackMessageLifetime}
      slackUserEmail:
        simple: ${userSlackEmail}
    separatecontext: false
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 1885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "75":
    id: "75"
    taskid: d7fcd3f0-c218-42b8-8a75-9b362fe64e02
    type: playbook
    task:
      id: d7fcd3f0-c218-42b8-8a75-9b362fe64e02
      version: -1
      name: DSPM Send Slack Notification to User
      description: '"Send Slack Notification to User" playbook is designed to notify a user via Slack and handle their response. It begins by sending a Slack notification to a specified email using the SlackBlockBuilder script. Afterward, it waits for the user''s response until a predefined time, as configured in Prisma Cloud DSPM. Once the response is received, it is inserted into the incident''s context. If there is an error in generating the Slack block, the incident is added for a re-run. Finally, the playbook extracts the user''s response from the Slack block state for further processing.'
      playbookName: DSPM Send Slack Notification to User
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "63"
    scriptarguments:
      flowPath:
        simple: invalid
      rerunTime:
        simple: ${inputs.rerunTime}
      slackMessageLifetime:
        simple: ${inputs.slackMessageLifetime}
    separatecontext: false
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 490,
          "y": 2380
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "76":
    id: "76"
    taskid: cf916f68-6081-4b43-8d5f-a26ca7050906
    type: title
    task:
      id: cf916f68-6081-4b43-8d5f-a26ca7050906
      version: -1
      name: Notify user about error
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "51"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1175,
          "y": 1740
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "77":
    id: "77"
    taskid: d04888d1-e8d3-4c6b-8ec8-84d6093e9009
    type: title
    task:
      id: d04888d1-e8d3-4c6b-8ec8-84d6093e9009
      version: -1
      name: Create slack block message to send user
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "27"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 895
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "78":
    id: "78"
    taskid: 462037c4-c62d-4fc4-876c-58c0ebf4457f
    type: title
    task:
      id: 462037c4-c62d-4fc4-876c-58c0ebf4457f
      version: -1
      name: Send slack notification to user
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "74"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 1740
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "79":
    id: "79"
    taskid: d6233707-2284-4f46-8afb-f6cb73d1b4f5
    type: title
    task:
      id: d6233707-2284-4f46-8afb-f6cb73d1b4f5
      version: -1
      name: Remediate Risk or Create Jira ticket
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "67"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 2920
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "80":
    id: "80"
    taskid: e3a47e3c-b10c-4ce1-8796-9a21c8db208a
    type: title
    task:
      id: e3a47e3c-b10c-4ce1-8796-9a21c8db208a
      version: -1
      name: Send an invalid response notification to the user and resend the remediation notification form to the user
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "75"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 490,
          "y": 2235
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "81":
    id: "81"
    taskid: ce05f4a4-1133-4f7e-8146-833311d11a37
    type: condition
    task:
      id: ce05f4a4-1133-4f7e-8146-833311d11a37
      version: -1
      name: Is Slack Integration available?
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'.
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "69"
      "yes":
      - "25"
    scriptarguments:
      brandname:
        simple: SlackV3
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 705,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "83":
    id: "83"
    taskid: e91dcfef-7133-48b6-8cfb-17bdb7fc66f5
    type: regular
    task:
      id: e91dcfef-7133-48b6-8cfb-17bdb7fc66f5
      version: -1
      name: Get DSPM Incident List
      description: commands.local.cmd.list.get
      script: Builtin|||getList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#error#':
      - "86"
      '#none#':
      - "60"
    scriptarguments:
      listName:
        simple: INCIDENT_LIST2
    separatecontext: false
    continueonerror: true
    continueonerrortype: errorPath
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 4830
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "86":
    id: "86"
    taskid: 10bb4f92-de2d-4d0b-8e80-9e493fab3e0a
    type: regular
    task:
      id: 10bb4f92-de2d-4d0b-8e80-9e493fab3e0a
      version: -1
      name: Create DSPM Incident list
      description: commands.local.cmd.list.create
      script: Builtin|||createList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      listData:
        simple: '{"incident_id":"${incident.id}","incident_created":"${incident_object.incidentCreated}"}'
      listName:
        simple: INCIDENT_LIST2
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 5005
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "87":
    id: "87"
    taskid: 2b4c293d-2c3d-4808-82e3-20f91e13a861
    type: regular
    task:
      id: 2b4c293d-2c3d-4808-82e3-20f91e13a861
      version: -1
      name: Add incident for re-run
      scriptName: DSPMIncidentList
      type: regular
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      '#none#':
      - "89"
    scriptarguments:
      action:
        simple: add
      incident_data:
        simple: ${incident_object}
      incident_list:
        simple: ${lists.INCIDENT_LIST2}
      rerun_time:
        simple: ${inputs.rerunTime}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 275,
          "y": 4130
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "88":
    id: "88"
    taskid: 58baf0b8-e634-49da-8e7a-0231de4684ee
    type: regular
    task:
      id: 58baf0b8-e634-49da-8e7a-0231de4684ee
      version: -1
      name: Get DSPM Incident List
      description: commands.local.cmd.list.get
      script: Builtin|||getList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#error#':
      - "86"
      '#none#':
      - "87"
    scriptarguments:
      listName:
        simple: INCIDENT_LIST2
    separatecontext: false
    continueonerror: true
    continueonerrortype: errorPath
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 3955
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "89":
    id: "89"
    taskid: 48de7094-b3ee-494d-8414-1b8b481efb3b
    type: condition
    task:
      id: 48de7094-b3ee-494d-8414-1b8b481efb3b
      version: -1
      name: Check incident list status?
      type: condition
      iscommand: false
      brand: ""
      description: "Check incident list status?"
    nexttasks:
      add:
      - "90"
    separatecontext: false
    conditions:
    - label: add
      condition:
      - - operator: containsGeneral
          left:
            value:
              simple: listStatus
            iscontext: true
          right:
            value:
              simple: Successfully added incident data
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 275,
          "y": 4305
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "90":
    id: "90"
    taskid: 500631a5-55c3-467b-86ad-9ec62e9322fc
    type: regular
    task:
      id: 500631a5-55c3-467b-86ad-9ec62e9322fc
      version: -1
      name: Add incident in  DSPM Incident list
      description: commands.local.cmd.list.add
      script: Builtin|||addToList
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      listData:
        simple: '{"incident_id":"${incident.id}","incident_created":"${incident_object.incidentCreated}"}'
      listName:
        simple: INCIDENT_LIST2
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 275,
          "y": 4480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "91":
    id: "91"
    taskid: a6285598-9d17-49de-8396-f558dbe9a762
    type: regular
    task:
      id: a6285598-9d17-49de-8396-f558dbe9a762
      version: -1
      name: Clear previous all context data!
      description: |-
        Delete field from context.

        This automation script runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Scripts
      scriptName: DeleteContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "81"
    scriptarguments:
      all:
        simple: "yes"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 705,
          "y": 195
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "92":
    id: "92"
    taskid: 3d0214d6-d890-4347-82e6-35837383ec44
    type: regular
    task:
      id: 3d0214d6-d890-4347-82e6-35837383ec44
      version: -1
      name: Deleting slack block from context data after saving into xsoar list.
      description: |-
        Delete field from context.

        This automation script runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Scripts
      scriptName: DeleteContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "36"
    scriptarguments:
      key:
        simple: slackBlock
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 1390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "93":
    id: "93"
    taskid: a2e83278-ef34-4dbd-8bed-48033906e034
    type: regular
    task:
      id: a2e83278-ef34-4dbd-8bed-48033906e034
      version: -1
      name: Deleting slack block from context after saving into xsoar list.
      description: |-
        Delete field from context.

        This automation script runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Scripts
      scriptName: DeleteContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "68"
    scriptarguments:
      key:
        simple: slackBlock
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 3605
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 5370,
        "width": 1505,
        "x": 50,
        "y": 50
      }
    }
  }
inputs:
- key: defaultSlackUserName
  value:
    simple: dummy@mail.com
  required: true
  description: In the event that the risk asset tag is absent, the risk notice will be sent to this Slack user email address.
  playbookInputQuery:
- key: slackMessageLifetime
  value:
    simple: "300"
  required: false
  description: Lifetime for slack notification (in seconds)
  playbookInputQuery:
- key: rerunTime
  value:
    simple: "24"
  required: false
  description: Incident re-run time (in hours)
  playbookInputQuery:
inputSections:
- inputs:
  - defaultSlackUserName
  - slackMessageLifetime
  - rerunTime
  name: General (Inputs group)
  description: Generic group for inputs
outputSections:
- outputs: []
  name: General (Outputs group)
  description: Generic group for outputs
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.10.0