NGFW Internal Scan
This playbook investigates a scan where the source is an internal IP address. An attacker might initiate an internal scan for discovery, lateral movement and more. **Attacker's Goals:** An attacker can leverage a scan for open ports and vulnerable systems on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services. **Investigative Actions:** * Endpoint Investigation Plan playbook **Response Actions** The playbook's response actions are based on the Endpoint Investigation Plan playbook results. In that phase, the playbook will execute: * Auto endpoint isolation * Manual block indicators * Manual file quarantine
Core · 16 tasks · 23 inputs · 0 outputs
Details
| ID | NGFW Internal Scan |
|---|---|
| From Version | 6.6.0 |
| Tasks | 16 |
README
This playbook investigates a scan where the source is an internal IP address.
An attacker might initiate an internal scan for discovery, lateral movement and more.
Attacker’s Goals:
An attacker can leverage a scan for open ports and vulnerable systems on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services.
Investigative Actions:
- Endpoint Investigation Plan playbook
Response Actions
The playbook’s response actions are based on the Endpoint Investigation Plan playbook results. In that phase, the playbook will execute:
- Auto endpoint isolation
- Manual block indicators
- Manual file quarantine
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Account Enrichment - Generic v2.1
- Containment Plan
- Endpoint Enrichment - Generic v2.1
- Endpoint Investigation Plan
- Ticket Management - Generic
Integrations
This playbook does not use any integrations.
Scripts
This playbook does not use any scripts.
Commands
- closeInvestigation
- setParentIncidentFields
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| scannerIP | The scanner IP address | alert.hostip | Optional |
| AutoCloseAlert | Whether to close the alert automatically or manually, after an analyst’s review. | false | Optional |
| AutoContainment | Whether to execute automatically or manually the containment plan tasks: * Block indicators * Quarantine file * Disable user |
Optional | |
| HostAutoContainment | Whether to execute endpoint isolation automatically or manually. | Optional | |
| ShouldOpenTicket | Whether to open a ticket automatically in a ticketing system. (True/False). | False | Optional |
| serviceNowShortDescription | A short description of the ticket. | XSIAM Incident ID - ${parentIncidentFields.incident_id} | Optional |
| serviceNowImpact | The impact for the new ticket. Leave empty for ServiceNow default impact. | Optional | |
| serviceNowUrgency | The urgency of the new ticket. Leave empty for ServiceNow default urgency. | Optional | |
| serviceNowSeverity | The severity of the new ticket. Leave empty for ServiceNow default severity. | Optional | |
| serviceNowTicketType | The ServiceNow ticket type. Options are “incident”, “problem”, “change_request”, “sc_request”, “sc_task”, or “sc_req_item”. Default is “incident”. | Optional | |
| serviceNowCategory | The category of the ServiceNow ticket. | Optional | |
| serviceNowAssignmentGroup | The group to which to assign the new ticket. | Optional | |
| ZendeskPriority | The urgency with which the ticket should be addressed. Allowed values are “urgent”, “high”, “normal”, or “low”. | Optional | |
| ZendeskRequester | The user who requested this ticket. | Optional | |
| ZendeskStatus | The state of the ticket. Allowed values are “new”, “open”, “pending”, “hold”, “solved”, or “closed”. | Optional | |
| ZendeskSubject | The value of the subject field for this ticket. | XSIAM Incident ID - ${parentIncidentFields.incident_id} | Optional |
| ZendeskTags | The array of tags applied to this ticket. | Optional | |
| ZendeskType | The type of this ticket. Allowed values are “problem”, “incident”, “question”, or “task”. | Optional | |
| ZendeskAssigne | The agent currently assigned to the ticket. | Optional | |
| ZendeskCollaborators | The users currently CC’ed on the ticket. | Optional | |
| description | The ticket description. | ${parentIncidentFields.description}. ${parentIncidentFields.xdr_url} | Optional |
| addCommentPerEndpoint | Whether to append a new comment to the ticket for each endpoint in the incident. Possible values: True/False. | True | Optional |
| CommentToAdd | Comment for the ticket. | ${alert.name}. Alert ID: ${alert.id} | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
scannerIP— The scanner IP addressAutoCloseAlert— Whether to close the alert automatically or manually, after an analyst's review.AutoContainment— Whether to execute automatically or manually the containment plan tasks: * Block indicators * Quarantine file * Disable userHostAutoContainment— Whether to execute endpoint isolation automatically or manually.ShouldOpenTicket— Whether to open a ticket automatically in a ticketing system. (True/False).serviceNowShortDescription— A short description of the ticket.serviceNowImpact— The impact for the new ticket. Leave empty for ServiceNow default impact.serviceNowUrgency— The urgency of the new ticket. Leave empty for ServiceNow default urgency.serviceNowSeverity— The severity of the new ticket. Leave empty for ServiceNow default severity.serviceNowTicketType— The ServiceNow ticket type. Options are "incident", "problem", "change_request", "sc_request", "sc_task", or "sc_req_item". Default is "incident".serviceNowCategory— The category of the ServiceNow ticket.serviceNowAssignmentGroup— The group to which to assign the new ticket.ZendeskPriority— The urgency with which the ticket should be addressed. Allowed values are "urgent", "high", "normal", or "low".ZendeskRequester— The user who requested this ticket.ZendeskStatus— The state of the ticket. Allowed values are "new", "open", "pending", "hold", "solved", or "closed".ZendeskSubject— The value of the subject field for this ticket.ZendeskTags— The array of tags applied to this ticket.ZendeskType— The type of this ticket. Allowed values are "problem", "incident", "question", or "task".ZendeskAssigne— The agent currently assigned to the ticket.ZendeskCollaborators— The users currently CC'ed on the ticket.description— The ticket description.addCommentPerEndpoint— Whether to append a new comment to the ticket for each endpoint in the incident. Possible values: True/False.CommentToAdd— Comment for the ticket.
Commands used
closeInvestigation
setParentIncidentFields
Flowchart
id: NGFW Internal Scan version: -1 name: NGFW Internal Scan description: | This playbook investigates a scan where the source is an internal IP address. An attacker might initiate an internal scan for discovery, lateral movement and more. **Attacker's Goals:** An attacker can leverage a scan for open ports and vulnerable systems on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services. **Investigative Actions:** * Endpoint Investigation Plan playbook **Response Actions** The playbook's response actions are based on the Endpoint Investigation Plan playbook results. In that phase, the playbook will execute: * Auto endpoint isolation * Manual block indicators * Manual file quarantine starttaskid: "0" tasks: "0": id: "0" taskid: 3ecd7ed7-c821-46c1-8a4e-dc6250b266ec type: start task: id: 3ecd7ed7-c821-46c1-8a4e-dc6250b266ec version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "7" separatecontext: false view: |- { "position": { "x": 440, "y": -140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "1": id: "1" taskid: 87c1a8ec-c2f2-4b91-8721-f44652f1634c type: playbook task: id: 87c1a8ec-c2f2-4b91-8721-f44652f1634c version: -1 name: Account Enrichment - Generic v2.1 description: |- Enrich accounts using one or more integrations. Supported integrations: - Active Directory playbookName: Account Enrichment - Generic v2.1 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "8" scriptarguments: Username: complex: root: alert accessor: username transformers: - operator: uniq separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 200, "y": 180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "7": id: "7" taskid: 8ed375b2-b63e-47b1-8f39-6d90c4bb0dcc type: title task: id: 8ed375b2-b63e-47b1-8f39-6d90c4bb0dcc version: -1 name: Enrichment type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "1" - "28" separatecontext: false view: |- { "position": { "x": 440, "y": 30 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "8": id: "8" taskid: f17016e4-9d9f-4d47-8621-87f10e27c144 type: title task: id: f17016e4-9d9f-4d47-8621-87f10e27c144 version: -1 name: Investigation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "24" separatecontext: false view: |- { "position": { "x": 440, "y": 360 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "11": id: "11" taskid: f84429f7-dd8d-4b8f-8746-e4f0e34f46e9 type: title task: id: f84429f7-dd8d-4b8f-8746-e4f0e34f46e9 version: -1 name: Remediation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "12" separatecontext: false view: |- { "position": { "x": 60, "y": 1340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "12": id: "12" taskid: 7dfb9c5d-5ad6-4bdd-881f-bfce33da263c type: playbook task: id: 7dfb9c5d-5ad6-4bdd-881f-bfce33da263c version: -1 name: Containment Plan description: |- This playbook handles all the containment actions available with Cortex XSIAM. The playbook allows to contain the alert with one of the following tasks: * Isolate endpoint * Disable account * Quarantine file * Block indicators * Clear user session (currently, the playbook supports only Okta) The playbook inputs allows you to manipulate the execution flow. Review the inputs description. playbookName: Containment Plan type: playbook iscommand: false brand: "" nexttasks: '#none#': - "18" scriptarguments: AutoContainment: complex: root: inputs.AutoContainment BlockIndicators: simple: "False" ClearUserSessions: simple: "False" EndpointID: complex: root: alert accessor: agentid FileContainment: simple: "False" FileHash: complex: root: foundIncidents.CustomFields filters: - - operator: isNotEqualString left: value: simple: foundIncidents.CustomFields.initiatorpath iscontext: true right: value: simple: c:\windows\explorer.exe ignorecase: true accessor: initiatorsha256 FilePath: complex: root: foundIncidents.CustomFields.initiatorpath filters: - - operator: isNotEqualString left: value: simple: foundIncidents.CustomFields.initiatorpath iscontext: true right: value: simple: c:\windows\explorer.exe ignorecase: true FileRemediation: simple: Quarantine HostAutoContainment: complex: root: inputs.HostAutoContainment IAMUserDomain: simple: '@xsoar.com' UserContainment: simple: "False" separatecontext: false loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 60, "y": 1480 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "15": id: "15" taskid: adea3df5-fc34-4ca3-83f5-ca3a7e60cec4 type: condition task: id: adea3df5-fc34-4ca3-83f5-ca3a7e60cec4 version: -1 name: Was other activity found for the scanning host? description: Checks if any other activity was found for the scanning host. type: condition iscommand: false brand: "" nexttasks: '#default#': - "18" "yes": - "25" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: foundincidents iscontext: true right: value: {} view: |- { "position": { "x": 440, "y": 660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "18": id: "18" taskid: 14a8536b-2d4e-4124-8712-39d147e4c6d0 type: condition task: id: 14a8536b-2d4e-4124-8712-39d147e4c6d0 version: -1 name: Should close the alert? description: Whether to close the alert automatically or continue with the investigation. type: condition iscommand: false brand: "" nexttasks: '#default#': - "19" "Yes": - "23" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.AutoCloseAlert iscontext: true right: value: simple: "true" ignorecase: true view: |- { "position": { "x": 440, "y": 1650 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "19": id: "19" taskid: cdde9f89-b5ae-4db0-85e0-bbcebbb4fd1a type: regular task: id: cdde9f89-b5ae-4db0-85e0-bbcebbb4fd1a version: -1 name: Continue with the investigation description: The AutoCloseAlert input is false, hence, a manual decision whether to close it or investigate further is needed. type: regular iscommand: false brand: "" nexttasks: '#none#': - "23" separatecontext: false view: |- { "position": { "x": 60, "y": 1820 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "20": id: "20" taskid: 8bb3b16b-4a01-4e95-81c3-95dafe8c3231 type: title task: id: 8bb3b16b-4a01-4e95-81c3-95dafe8c3231 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": 440, "y": 2180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "23": id: "23" taskid: 2c8a152f-e2e3-4c40-89a7-0eb0be8bc68d type: regular task: id: 2c8a152f-e2e3-4c40-89a7-0eb0be8bc68d version: -1 name: Close alert description: commands.local.cmd.close.inv script: Builtin|||closeInvestigation type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "20" separatecontext: false view: |- { "position": { "x": 440, "y": 2000 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "24": id: "24" taskid: 9f808ed4-3737-4536-8bb2-276ed2c9e330 type: playbook task: id: 9f808ed4-3737-4536-8bb2-276ed2c9e330 version: -1 name: Endpoint Investigation Plan description: |- This playbook handles all the endpoint investigation actions available with Cortex XSIAM. The playbook enables you to investigate and hunt for more information using one of the following tasks: * Pre-defined MITRE Tactics * Host fields (Host ID) * Attacker fields (Attacker IP, External host) * MITRE techniques * File hash (currently, the playbook supports only SHA256) The playbook inputs enable you to manipulate the execution flow. Review the inputs description. playbookName: Endpoint Investigation Plan type: playbook iscommand: false brand: "" nexttasks: '#none#': - "15" scriptarguments: HuntAttacker: simple: "True" HuntCnCTechniques: simple: "False" HuntCollectionTechniques: simple: "False" HuntDefenseEvasionTechniques: simple: "False" HuntDiscoveryTechniques: simple: "False" HuntExecutionTechniques: simple: "False" HuntImpactTechniques: simple: "False" HuntInitialAccessTechniques: simple: "False" HuntLateralMovementTechniques: simple: "False" HuntPersistenceTechniques: simple: "False" HuntPrivilegeEscalationTechniques: simple: "False" HuntReconnaissanceTechniques: simple: "False" agentID: simple: '*' attackerRemoteIP: complex: root: inputs.scannerIP separatecontext: false loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 440, "y": 490 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "25": id: "25" taskid: 6dbec345-05c5-4203-8c12-1b2ab81410d8 type: regular task: id: 6dbec345-05c5-4203-8c12-1b2ab81410d8 version: -1 name: Set Alert Severity to High description: commands.local.cmd.set.parent.alert.field script: Builtin|||setParentIncidentFields type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "26" scriptarguments: manual_severity: simple: high separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 60, "y": 835 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 2 isoversize: false isautoswitchedtoquietmode: false "26": id: "26" taskid: 3e3cd67a-5288-4489-8697-11ddbd6c6c5f type: condition task: id: 3e3cd67a-5288-4489-8697-11ddbd6c6c5f version: -1 name: Should open a ticket automatically in a ticketing system? description: Checks whether to open a ticket automatically in a ticketing system. type: condition iscommand: false brand: "" nexttasks: '#default#': - "11" "yes": - "27" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.ShouldOpenTicket iscontext: true right: value: simple: "True" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 60, "y": 1000 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "27": id: "27" taskid: 9c16cf70-885d-4b45-8333-5722e50f131a type: playbook task: id: 9c16cf70-885d-4b45-8333-5722e50f131a version: -1 name: Ticket Management - Generic description: "`Ticket Management - Generic` allows you to open new tickets or update comments to the existing ticket in the following ticketing systems:\n-ServiceNow \n-Zendesk \nusing the following sub-playbooks:\n-`ServiceNow - Ticket Management`\n-`Zendesk - Ticket Management`\n" playbookName: Ticket Management - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "11" scriptarguments: CommentToAdd: complex: root: inputs.CommentToAdd ZendeskAssigne: complex: root: inputs.ZendeskAssigne ZendeskCollaborators: complex: root: inputs.ZendeskCollaborators ZendeskPriority: complex: root: inputs.ZendeskPriority ZendeskRequester: complex: root: inputs.ZendeskRequester ZendeskStatus: complex: root: inputs.ZendeskStatus ZendeskSubject: complex: root: inputs.ZendeskSubject ZendeskTags: complex: root: inputs.ZendeskTags ZendeskType: complex: root: inputs.ZendeskType addCommentPerEndpoint: complex: root: inputs.addCommentPerEndpoint description: complex: root: inputs.description serviceNowAssignmentGroup: complex: root: inputs.serviceNowAssignmentGroup serviceNowCategory: complex: root: inputs.serviceNowCategory serviceNowImpact: complex: root: inputs.serviceNowImpact serviceNowSeverity: complex: root: inputs.serviceNowSeverity serviceNowShortDescription: complex: root: inputs.serviceNowShortDescription serviceNowTicketType: complex: root: inputs.serviceNowTicketType serviceNowUrgency: complex: root: inputs.serviceNowUrgency separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -200, "y": 1170 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "28": id: "28" taskid: 42116819-eaab-4919-830d-3d86bcfb2bb5 type: playbook task: id: 42116819-eaab-4919-830d-3d86bcfb2bb5 version: -1 name: Endpoint Enrichment - Generic v2.1 description: |- Enrich an endpoint by hostname using one or more integrations. Supported integrations: - Active Directory Query v2 - McAfee ePO v2 - VMware Carbon Black EDR v2 - Cylance Protect v2 - CrowdStrike Falcon - ExtraHop Reveal(x) - Cortex XDR / Core (endpoint enrichment, reputation and risk) - Endpoint reputation using !endpoint command playbookName: Endpoint Enrichment - Generic v2.1 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "8" scriptarguments: IPAddress: complex: root: inputs.scannerIP transformers: - operator: uniq UseReputationCommand: simple: "False" separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 680, "y": 180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": { "18_19_#default#": 0.4 }, "paper": { "dimensions": { "height": 2385, "width": 1260, "x": -200, "y": -140 } } } inputs: - key: scannerIP value: complex: root: alert accessor: hostip required: false description: The scanner IP address playbookInputQuery: - key: AutoCloseAlert value: simple: "false" required: false description: Whether to close the alert automatically or manually, after an analyst's review. playbookInputQuery: - key: AutoContainment value: {} required: false description: |- Whether to execute automatically or manually the containment plan tasks: * Block indicators * Quarantine file * Disable user playbookInputQuery: - key: HostAutoContainment value: {} required: false description: Whether to execute endpoint isolation automatically or manually. playbookInputQuery: - key: ShouldOpenTicket value: simple: "False" required: false description: Whether to open a ticket automatically in a ticketing system. (True/False). playbookInputQuery: - key: serviceNowShortDescription value: simple: XSIAM Incident ID - ${parentIncidentFields.incident_id} required: false description: A short description of the ticket. playbookInputQuery: - key: serviceNowImpact value: {} required: false description: The impact for the new ticket. Leave empty for ServiceNow default impact. playbookInputQuery: - key: serviceNowUrgency value: {} required: false description: The urgency of the new ticket. Leave empty for ServiceNow default urgency. playbookInputQuery: - key: serviceNowSeverity value: {} required: false description: The severity of the new ticket. Leave empty for ServiceNow default severity. playbookInputQuery: - key: serviceNowTicketType value: {} required: false description: The ServiceNow ticket type. Options are "incident", "problem", "change_request", "sc_request", "sc_task", or "sc_req_item". Default is "incident". playbookInputQuery: - key: serviceNowCategory value: {} required: false description: The category of the ServiceNow ticket. playbookInputQuery: - key: serviceNowAssignmentGroup value: {} required: false description: The group to which to assign the new ticket. playbookInputQuery: - key: ZendeskPriority value: {} required: false description: The urgency with which the ticket should be addressed. Allowed values are "urgent", "high", "normal", or "low". playbookInputQuery: - key: ZendeskRequester value: {} required: false description: The user who requested this ticket. playbookInputQuery: - key: ZendeskStatus value: {} required: false description: The state of the ticket. Allowed values are "new", "open", "pending", "hold", "solved", or "closed". playbookInputQuery: - key: ZendeskSubject value: simple: XSIAM Incident ID - ${parentIncidentFields.incident_id} required: false description: The value of the subject field for this ticket. playbookInputQuery: - key: ZendeskTags value: {} required: false description: The array of tags applied to this ticket. playbookInputQuery: - key: ZendeskType value: {} required: false description: The type of this ticket. Allowed values are "problem", "incident", "question", or "task". playbookInputQuery: - key: ZendeskAssigne value: {} required: false description: The agent currently assigned to the ticket. playbookInputQuery: - key: ZendeskCollaborators value: {} required: false description: The users currently CC'ed on the ticket. playbookInputQuery: - key: description value: simple: ${parentIncidentFields.description}. ${parentIncidentFields.xdr_url} required: false description: The ticket description. playbookInputQuery: - key: addCommentPerEndpoint value: simple: "True" required: false description: 'Whether to append a new comment to the ticket for each endpoint in the incident. Possible values: True/False.' playbookInputQuery: - key: CommentToAdd value: simple: '${alert.name}. Alert ID: ${alert.id}' required: false description: Comment for the ticket. playbookInputQuery: inputSections: - inputs: - AutoCloseAlert name: Alert Management description: Alert management settings and data, including escalation processes, and user engagements. - inputs: - scannerIP name: Investigation description: Investigation settings and data, including any deep dive alert investigation and verdict determination. - inputs: - AutoContainment - HostAutoContainment name: Remediation description: Remediation settings and data, including containment, eradication, and recovery. - inputs: - ShouldOpenTicket - serviceNowShortDescription - serviceNowImpact - serviceNowUrgency - serviceNowSeverity - serviceNowTicketType - serviceNowCategory - serviceNowAssignmentGroup - ZendeskPriority - ZendeskRequester - ZendeskStatus - ZendeskSubject - ZendeskTags - ZendeskType - ZendeskAssigne - ZendeskCollaborators - description - addCommentPerEndpoint - CommentToAdd name: Ticket Management description: Ticket management settings and data. outputSections: - outputs: [] name: General (Outputs group) description: Generic group for outputs outputs: [] tests: - No tests (auto formatted) marketplaces: - marketplacev2 - platform fromversion: 6.6.0 supportedModules: - agentix - cloud - cloud_posture - cloud_runtime_security - edr - xsiam