ExtraHop - Ticket Tracking Deprecated Hidden

Deprecated. Use the "ExtraHop - Ticket Tracking v2" playbook instead.\ \ Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.

Deprecated Content (Deprecated) · 13 tasks · 1 input · 0 outputs

Details

IDExtraHop - Ticket Tracking
From Version5.0.0
Tasks13

README

Deprecated. Use the “ExtraHop - Ticket Tracking v2” playbook instead.
Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

  • SearchIncidentsV2
  • Exists
  • AssignAnalystToIncident

Commands

  • extrahop-track-ticket
  • setIncident

Playbook Inputs


Name Description Default Value Required
OnCall Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later. false Optional

Playbook Outputs


There are no outputs for this playbook.

Inputs

  • OnCall — Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later.

Commands used

extrahop-track-ticket setIncident

Flowchart

yes yes yes yes yes Start Start Track the incident status in ExtraHop Reveal(x) - extrahop-track-ticket Track the incident status... extrahop-track-ticket Done Done Mark the incident as tracked - setIncident Mark the incident as tracked setIncident Search for any untracked ExtraHop Detections - SearchIncidentsV2 Search for any untracked ... SearchIncidentsV2 Mark the incident as tracked - setIncident Mark the incident as tracked setIncident Track the incident status in ExtraHop Reveal(x) - extrahop-track-ticket Track the incident status... extrahop-track-ticket Are the required fields present? Are the required fields p... Were there any incidents found? Were there any incidents ... Was the incident successfully tracked? Was the incident successf... Was the incident successfully tracked? Was the incident successf... Assign an ExtraHop analyst to the incident - AssignAnalystToIncident Assign an ExtraHop analys... AssignAnalystToIncident Is ExtraHop Reveal(x) enabled? - Exists Is ExtraHop Reveal(x) ena... Exists
id: ExtraHop - Ticket Tracking
version: -1
name: ExtraHop - Ticket Tracking
description: Deprecated. Use the "ExtraHop - Ticket Tracking v2" playbook instead.\
  \ Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.
starttaskid: "0"
hidden: true
tasks:
  "0":
    id: "0"
    taskid: 71394f2c-bc76-4885-8bab-b55ce0094789
    type: start
    task:
      id: 71394f2c-bc76-4885-8bab-b55ce0094789
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "15"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -10,
          "y": -460
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "1":
    id: "1"
    taskid: be00a185-8d20-4e46-8012-4ae44b3687fc
    type: regular
    task:
      id: be00a185-8d20-4e46-8012-4ae44b3687fc
      version: -1
      name: Track the incident status in ExtraHop Reveal(x)
      description: Link the ExtraHop Detection to the corresponding Demisto Investigation.  This uses the ExtraHop ticket tracking functionality to properly display ticket status within ExtraHop.
      script: '|||extrahop-track-ticket'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "12"
    scriptarguments:
      detection_id:
        complex:
          root: foundIncidents
          accessor: CustomFields.detectionid
      incident_close_reason:
        complex:
          root: foundIncidents
          accessor: closeReason
      incident_id:
        complex:
          root: foundIncidents
          accessor: id
      incident_owner:
        complex:
          root: foundIncidents
          accessor: owner
      incident_status:
        complex:
          root: foundIncidents
          accessor: status
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 170,
          "y": 1110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "2":
    id: "2"
    taskid: f4953d89-2219-4d74-8acf-d819728d0ac9
    type: title
    task:
      id: f4953d89-2219-4d74-8acf-d819728d0ac9
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -100,
          "y": 1640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "3":
    id: "3"
    taskid: 6f9852cc-7a6e-4d2f-8bef-86fb205e5408
    type: regular
    task:
      id: 6f9852cc-7a6e-4d2f-8bef-86fb205e5408
      version: -1
      name: Mark the incident as tracked
      description: Update the incident to reflect the Detection Ticketed status.
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      addLabels: {}
      affecteddata: {}
      affecteddatatype: {}
      affectedindividualscontactinformation: {}
      app: {}
      approximatenumberofaffecteddatasubjects: {}
      assetid: {}
      attachmentcount: {}
      attachmentextension: {}
      attachmenthash: {}
      attachmentid: {}
      attachmentname: {}
      attachmentsize: {}
      attachmenttype: {}
      bugtraq: {}
      city: {}
      closeNotes: {}
      closeReason: {}
      companyaddress: {}
      companycity: {}
      companycountry: {}
      companyhasinsuranceforthebreach: {}
      companyname: {}
      companypostalcode: {}
      contactaddress: {}
      contactname: {}
      country: {}
      countrywherebusinesshasitsmainestablishment: {}
      countrywherethebreachtookplace: {}
      customFields: {}
      cve: {}
      cvss: {}
      dataencryptionstatus: {}
      datetimeofthebreach: {}
      deleteEmptyField: {}
      dest: {}
      destntdomain: {}
      details: {}
      detectionendtime: {}
      detectionid: {}
      detectionticketed:
        simple: "true"
      detectionupdatetime: {}
      detectionurl: {}
      dpoemailaddress: {}
      duration: {}
      emailaddress: {}
      emailbcc: {}
      emailbody: {}
      emailbodyformat: {}
      emailbodyhtml: {}
      emailcc: {}
      emailclientname: {}
      emailfrom: {}
      emailhtml: {}
      emailinreplyto: {}
      emailkeywords: {}
      emailmessageid: {}
      emailreceived: {}
      emailreplyto: {}
      emailreturnpath: {}
      emailsenderip: {}
      emailsize: {}
      emailsource: {}
      emailsubject: {}
      emailto: {}
      emailtocount: {}
      emailurlclicked: {}
      extrahopapplianceid: {}
      extrahophostname: {}
      filehash: {}
      filename: {}
      filepath: {}
      id:
        simple: ${ExtraHop.TicketId}
      isthedatasubjecttodpia: {}
      labels: {}
      likelyimpact: {}
      maliciouscauseifthecauseisamaliciousattack: {}
      malwarefamily: {}
      measurestomitigate: {}
      name: {}
      occurred: {}
      owner: {}
      participants: {}
      phase: {}
      possiblecauseofthebreach: {}
      postalcode: {}
      rawparticipants: {}
      replacePlaybook: {}
      riskscore: {}
      roles: {}
      sectorofaffectedparty: {}
      severity: {}
      signature: {}
      sizenumberofemployees: {}
      sizeturnover: {}
      sla: {}
      slaField: {}
      src: {}
      srcntdomain: {}
      srcuser: {}
      systems: {}
      telephoneno: {}
      type: {}
      user: {}
      vendorid: {}
      vendorproduct: {}
      vulnerabilitycategory: {}
      whereisdatahosted: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 490,
          "y": 600
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "4":
    id: "4"
    taskid: 695438ce-bf6a-43e8-8d73-3b314c1ea1e5
    type: regular
    task:
      id: 695438ce-bf6a-43e8-8d73-3b314c1ea1e5
      version: -1
      name: Search for any untracked ExtraHop Detections
      description: Searches Demisto incidents for any ExtraHop Detections that are untracked.
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "10"
    scriptarguments:
      details: {}
      fromclosedate: {}
      fromdate: {}
      fromduedate: {}
      id: {}
      level: {}
      name: {}
      notstatus: {}
      owner: {}
      page: {}
      query:
        simple: type:"ExtraHop Detection" and incident.detectionticketed:F and incident.created:>="1 day ago"
      reason: {}
      size: {}
      sort: {}
      status: {}
      toclosedate: {}
      todate: {}
      toduedate: {}
      type: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 170,
          "y": 770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "6":
    id: "6"
    taskid: 75eb04ec-c770-4120-8d70-56513ce2201b
    type: regular
    task:
      id: 75eb04ec-c770-4120-8d70-56513ce2201b
      version: -1
      name: Mark the incident as tracked
      description: Update the incident to reflect the Detection Ticketed status.
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "2"
    scriptarguments:
      addLabels: {}
      affecteddata: {}
      affecteddatatype: {}
      affectedindividualscontactinformation: {}
      app: {}
      approximatenumberofaffecteddatasubjects: {}
      assetid: {}
      attachmentcount: {}
      attachmentextension: {}
      attachmenthash: {}
      attachmentid: {}
      attachmentname: {}
      attachmentsize: {}
      attachmenttype: {}
      bugtraq: {}
      city: {}
      closeNotes: {}
      closeReason: {}
      companyaddress: {}
      companycity: {}
      companycountry: {}
      companyhasinsuranceforthebreach: {}
      companyname: {}
      companypostalcode: {}
      contactaddress: {}
      contactname: {}
      country: {}
      countrywherebusinesshasitsmainestablishment: {}
      countrywherethebreachtookplace: {}
      customFields: {}
      cve: {}
      cvss: {}
      dataencryptionstatus: {}
      datetimeofthebreach: {}
      deleteEmptyField: {}
      dest: {}
      destntdomain: {}
      details: {}
      detectionendtime: {}
      detectionid: {}
      detectionticketed:
        simple: "true"
      detectionupdatetime: {}
      detectionurl: {}
      dpoemailaddress: {}
      duration: {}
      emailaddress: {}
      emailbcc: {}
      emailbody: {}
      emailbodyformat: {}
      emailbodyhtml: {}
      emailcc: {}
      emailclientname: {}
      emailfrom: {}
      emailhtml: {}
      emailinreplyto: {}
      emailkeywords: {}
      emailmessageid: {}
      emailreceived: {}
      emailreplyto: {}
      emailreturnpath: {}
      emailsenderip: {}
      emailsize: {}
      emailsource: {}
      emailsubject: {}
      emailto: {}
      emailtocount: {}
      emailurlclicked: {}
      extrahopapplianceid: {}
      extrahophostname: {}
      filehash: {}
      filename: {}
      filepath: {}
      id:
        simple: ${ExtraHop.TicketId}
      isthedatasubjecttodpia: {}
      labels: {}
      likelyimpact: {}
      maliciouscauseifthecauseisamaliciousattack: {}
      malwarefamily: {}
      measurestomitigate: {}
      name: {}
      occurred: {}
      owner: {}
      participants: {}
      phase: {}
      possiblecauseofthebreach: {}
      postalcode: {}
      rawparticipants: {}
      replacePlaybook: {}
      riskscore: {}
      roles: {}
      sectorofaffectedparty: {}
      severity: {}
      signature: {}
      sizenumberofemployees: {}
      sizeturnover: {}
      sla: {}
      slaField: {}
      src: {}
      srcntdomain: {}
      srcuser: {}
      systems: {}
      telephoneno: {}
      type: {}
      user: {}
      vendorid: {}
      vendorproduct: {}
      vulnerabilitycategory: {}
      whereisdatahosted: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 170,
          "y": 1465
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "7":
    id: "7"
    taskid: 50b89e52-0733-477b-8929-8b595f704ca4
    type: regular
    task:
      id: 50b89e52-0733-477b-8929-8b595f704ca4
      version: -1
      name: Track the incident status in ExtraHop Reveal(x)
      description: Link the ExtraHop Detection to the corresponding Demisto Investigation.  This uses the ExtraHop ticket tracking functionality to properly display ticket status within ExtraHop.
      script: '|||extrahop-track-ticket'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "11"
    scriptarguments:
      detection_id:
        simple: ${incident.detectionid}
      incident_close_reason:
        simple: ${incident.closeReason}
      incident_id:
        simple: ${incident.id}
      incident_owner:
        simple: ${incident.owner}
      incident_status:
        simple: ${incident.status}
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 490,
          "y": 230
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "9":
    id: "9"
    taskid: 40271f8c-840d-4e71-86c5-57a28bc24aea
    type: condition
    task:
      id: 40271f8c-840d-4e71-86c5-57a28bc24aea
      version: -1
      name: Are the required fields present?
      description: Checks if the required detection and incident IDs are present.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "4"
      "yes":
      - "7"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: incident.id
            iscontext: true
      - - operator: isNotEmpty
          left:
            value:
              simple: incident.detectionid
            iscontext: true
    view: |-
      {
        "position": {
          "x": 170,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "10":
    id: "10"
    taskid: 76071ff8-9c4d-494d-8b73-aa4368199fb5
    type: condition
    task:
      id: 76071ff8-9c4d-494d-8b73-aa4368199fb5
      version: -1
      name: Were there any incidents found?
      description: Checks if there were any untracked ExtraHop Detections found.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "2"
      "yes":
      - "1"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: foundIncidents.id
            iscontext: true
    view: |-
      {
        "position": {
          "x": 170,
          "y": 930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "11":
    id: "11"
    taskid: e553a569-662c-460e-87f0-f69efaf2901a
    type: condition
    task:
      id: e553a569-662c-460e-87f0-f69efaf2901a
      version: -1
      name: Was the incident successfully tracked?
      description: Check if the ticket tracking was successful.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "4"
      "yes":
      - "3"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: ExtraHop.TicketId
            iscontext: true
    view: |-
      {
        "position": {
          "x": 490,
          "y": 390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "12":
    id: "12"
    taskid: 624c3b07-31d8-45ca-8f6f-332974515fef
    type: condition
    task:
      id: 624c3b07-31d8-45ca-8f6f-332974515fef
      version: -1
      name: Was the incident successfully tracked?
      description: Check if the ticket tracking was successful.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "2"
      "yes":
      - "6"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: ExtraHop.TicketId
            iscontext: true
    view: |-
      {
        "position": {
          "x": 170,
          "y": 1275
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "13":
    id: "13"
    taskid: 1619242b-d813-4dfb-8801-cd45a61906f3
    type: regular
    task:
      id: 1619242b-d813-4dfb-8801-cd45a61906f3
      version: -1
      name: Assign an ExtraHop analyst to the incident
      description: Assign an analyst randomly from the pool of users with the ExtraHop role.
      scriptName: AssignAnalystToIncident
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      assignBy: {}
      email: {}
      onCall:
        complex:
          root: inputs.OnCall
      roles:
        simple: ExtraHop
      username: {}
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 170,
          "y": -110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "15":
    id: "15"
    taskid: dffb9228-cc49-4adf-88f5-13001f85ba70
    type: condition
    task:
      id: dffb9228-cc49-4adf-88f5-13001f85ba70
      version: -1
      name: Is ExtraHop Reveal(x) enabled?
      description: Checks if there is an active instance of the ExtraHop Reveal(x) integration enabled.
      scriptName: Exists
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "2"
      "yes":
      - "13"
    scriptarguments:
      value:
        complex:
          root: modules
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: brand
                iscontext: true
              right:
                value:
                  simple: ExtraHop v2
          - - operator: isEqualString
              left:
                value:
                  simple: state
                iscontext: true
              right:
                value:
                  simple: active
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -10,
          "y": -320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
view: |-
  {
    "linkLabelsPosition": {
      "10_1_yes": 0.42,
      "10_2_#default#": 0.2,
      "11_3_yes": 0.49,
      "11_4_#default#": 0.45,
      "12_2_#default#": 0.31,
      "12_6_yes": 0.47,
      "15_13_yes": 0.55,
      "15_2_#default#": 0.1,
      "9_4_#default#": 0.31,
      "9_7_yes": 0.44
    },
    "paper": {
      "dimensions": {
        "height": 2165,
        "width": 970,
        "x": -100,
        "y": -460
      }
    }
  }
inputs:
- key: OnCall
  value:
    simple: "false"
  required: false
  description: Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later.
outputs: []
fromversion: 5.0.0
tests:
- No test - Deprecated playbook
deprecated: true