Prisma Cloud - Network API and Anomaly Incidents

This playbook handles incidents of internet exposed services and detect potential risky configurations that can make your cloud environment vulnerable to attacks, and incidents of unusual network and user activity for all users, and are especially critical for privileged users and assumed roles where detecting unusual activity may indicate the first steps in a potential misuse or account compromise.

Prisma Cloud by Palo Alto Networks · 39 tasks · 20 inputs · 0 outputs

Details

IDPrisma Cloud - Network API and Anomaly Incidents
From Version6.10.0
Tasks39

README

This playbook handles incidents of internet exposed services and detects potential risky configurations that can make your cloud environment vulnerable to attacks, and
incidents of unusual network and user activity for all users, and are especially critical for privileged users and assumed roles where detecting unusual activity may indicate the first steps in a potential misuse or account compromise.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Ticket Management - Generic
  • Cloud Enrichment - Generic
  • Cloud User Investigation - Generic
  • Block IP - Generic v3
  • Cloud Response - Generic

Integrations

  • PrismaCloud v2
  • PrismaCloudV2
  • PrismaCloudIAM
  • RedLock

Scripts

JsonToTable

Commands

  • prisma-cloud-host-finding-list
  • core-list-risky-users
  • setAlert
  • ip
  • cve
  • prisma-cloud-alert-get-details

Playbook Inputs


Name Description Default Value Required
serviceNowShortDescription A short description of the ticket.   Optional
serviceNowImpact The impact for the new ticket. Leave empty for ServiceNow default impact.   Optional
serviceNowUrgency The urgency of the new ticket. Leave empty for ServiceNow default urgency.   Optional
serviceNowSeverity The severity of the new ticket. Leave empty for ServiceNow default severity.   Optional
serviceNowTicketType The ServiceNow ticket type. Options are “incident”, “problem”, “change_request”, “sc_request”, “sc_task”, or “sc_req_item”. Default is “incident”.   Optional
serviceNowCategory The category of the ServiceNow ticket.   Optional
serviceNowAssignmentGroup The group to which to assign the new ticket.   Optional
ZendeskPriority The urgency with which the ticket should be addressed. Allowed values are “urgent”, “high”, “normal”, or “low”.   Optional
ZendeskRequester The user who requested this ticket.   Optional
ZendeskStatus The state of the ticket. Allowed values are “new”, “open”, “pending”, “hold”, “solved”, or “closed”.   Optional
ZendeskSubject The value of the subject field for this ticket.   Optional
ZendeskTags The array of tags applied to this ticket.   Optional
ZendeskType The type of this ticket. Allowed values are “problem”, “incident”, “question”, or “task”.   Optional
ZendeskAssigne The agent currently assigned to the ticket.   Optional
ZendeskCollaborators The users currently CC’ed on the ticket.   Optional
ZenDeskDescription The ticket description.   Optional
CreateTicket Whether to create a ticket in ZenDesk or ServiceNow. Options are True or False. False Optional
StopForRecommendations   True Optional
EarlyContainment   True Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Prisma Cloud - Network API and Anomaly Incidents

Inputs

  • CreateTicket — Whether to create a ticket in ZenDesk or ServiceNow. Insert True or False
  • StopForRecommendations
  • EarlyContainment — Whether to perform early containment.
  • CloudResponse — Whether to perform cloud response.
  • serviceNowShortDescription — A short description of the ticket.
  • serviceNowImpact — The impact for the new ticket. Leave empty for ServiceNow default impact.
  • serviceNowUrgency — The urgency of the new ticket. Leave empty for ServiceNow default urgency.
  • serviceNowSeverity — The severity of the new ticket. Leave empty for ServiceNow default severity.
  • serviceNowTicketType — The ServiceNow ticket type. Options are "incident", "problem", "change_request", "sc_request", "sc_task", or "sc_req_item". Default is "incident".
  • serviceNowCategory — The category of the ServiceNow ticket.
  • serviceNowAssignmentGroup — The group to which to assign the new ticket.
  • ZendeskPriority — The urgency with which the ticket should be addressed. Allowed values are "urgent", "high", "normal", or "low".
  • ZendeskRequester — The user who requested this ticket.
  • ZendeskStatus — The state of the ticket. Allowed values are "new", "open", "pending", "hold", "solved", or "closed".
  • ZendeskSubject — The value of the subject field for this ticket.
  • ZendeskTags — The array of tags applied to this ticket.
  • ZendeskType — The type of this ticket. Allowed values are "problem", "incident", "question", or "task".
  • ZendeskAssigne — The agent currently assigned to the ticket.
  • ZendeskCollaborators — The users currently CC'ed on the ticket.
  • ZenDeskDescription — The ticket description.

Commands used

core-list-risky-users cve ip prisma-cloud-alert-get-details prisma-cloud-host-finding-list setAlert

Flowchart

yes yes yes yes yes yes yes yes yes yes yes Start Start Enrichment Enrichment IP Enrichment - ip IP Enrichment ip Early Containment Early Containment Does IP is malicious? Does IP is malicious? Early Containment enabled? Early Containment enabled? Early Containment Early Containment Containment Complete Containment Complete Investigation Investigation Cloud User Investigation - Generic - Cloud User Investigation - Generic Cloud User Investigation ... Cloud User Investigation - Ge... Cloud Enrichment - Generic - Cloud Enrichment - Generic Cloud Enrichment - Generic Cloud Enrichment - Generic User Investigation User Investigation Vulnerability Enrichment Vulnerability Enrichment Verdict Verdict Does response needed? Does response needed? Remediation Remediation Cloud Response - Generic - Cloud Response - Generic Cloud Response - Generic Cloud Response - Generic Perform Cloud Response? Perform Cloud Response? Pause the playbook to perform policy recommendations? Pause the playbook to per... Pause the playbook to perform policy recommendations Pause the playbook to per... Done Done Block IP - Generic v3 - Block IP - Generic v3 Block IP - Generic v3 Block IP - Generic v3 Ticket Management - Generic - Ticket Management - Generic Ticket Management - Generic Ticket Management - Generic Create a ticket? Create a ticket? Risky User Risky User Check if user is risky by XDR - core-list-risky-users Check if user is risky by... core-list-risky-users Prisma alert enrichment - prisma-cloud-alert-get-details Prisma alert enrichment prisma-cloud-alert-get-details Does Alert Contains IP? Does Alert Contains IP? Host RRN has received from Prisma? Host RRN has received fro... Get host findings - prisma-cloud-host-finding-list Get host findings prisma-cloud-host-finding-list Determine Verdict - setAlert Determine Verdict setAlert Set status to layout - setAlert Set status to layout setAlert Is Part of Alert Rule? Is Part of Alert Rule? Map Alert Rules - JsonToTable Map Alert Rules JsonToTable Get CVE Details - cve Get CVE Details cve Has related CVE? Has related CVE? Has Results? Has Results? Set User Investigation Results - setAlert Set User Investigation Re... setAlert Set status to layout - setAlert Set status to layout setAlert
id: Prisma Cloud - Network API and Anomaly Incidents
version: -1
name: Prisma Cloud - Network API and Anomaly Incidents
description: |-
  This playbook handles incidents of internet exposed services and detect potential risky configurations that can make your cloud environment vulnerable to attacks, and
  incidents of unusual network and user activity for all users, and are especially critical for privileged users and assumed roles where detecting unusual activity may indicate the first steps in a potential misuse or account compromise.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 4f11a4c9-0954-4f33-8c2f-3f0c56f2a5a2
    type: start
    task:
      id: 4f11a4c9-0954-4f33-8c2f-3f0c56f2a5a2
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": -430
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: ae031fc1-70ad-4363-82a6-93475f9024fb
    type: title
    task:
      id: ae031fc1-70ad-4363-82a6-93475f9024fb
      version: -1
      name: Enrichment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "34"
      - "33"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": -300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: 97f6bc4a-c84f-46c9-89c0-9687b97bbfda
    type: regular
    task:
      id: 97f6bc4a-c84f-46c9-89c0-9687b97bbfda
      version: -1
      name: IP Enrichment
      description: Checks the reputation of an IP address.
      script: '|||ip'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      ip:
        simple: ${alert.remoteip}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -40,
          "y": 40
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    fieldMapping:
    - incidentfield: IP Reputation
      output:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: ip
              ignorecase: true
          accessor: Score
    - incidentfield: Source Geolocation
      output:
        simple: ${IP.Geo.Country}
    - incidentfield: ASN
      output:
        simple: ${IP.ASN}
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "3":
    id: "3"
    taskid: aaa5c8f1-f0cf-4946-8e4e-b275ae8947ae
    type: title
    task:
      id: aaa5c8f1-f0cf-4946-8e4e-b275ae8947ae
      version: -1
      name: Early Containment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "4"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: 23f631fe-952d-4904-8bdf-d69285021fa3
    type: condition
    task:
      id: 23f631fe-952d-4904-8bdf-d69285021fa3
      version: -1
      name: Does IP is malicious?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "9"
      "yes":
      - "5"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: DBotScore
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: DBotScore.Type
                      iscontext: true
                    right:
                      value:
                        simple: ip
                    ignorecase: true
                accessor: Score
                transformers:
                - operator: FirstArrayElement
            iscontext: true
          right:
            value:
              simple: "3"
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 520
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "5":
    id: "5"
    taskid: 684ae017-441c-43da-8110-4aa00320909e
    type: condition
    task:
      id: 684ae017-441c-43da-8110-4aa00320909e
      version: -1
      name: Early Containment enabled?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "8"
      "yes":
      - "6"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.EarlyContainment
            iscontext: true
          right:
            value:
              simple: "true"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 30,
          "y": 690
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: 3c1d50e7-8350-4585-86d1-6d000a4db3a8
    type: title
    task:
      id: 3c1d50e7-8350-4585-86d1-6d000a4db3a8
      version: -1
      name: Early Containment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "25"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -260,
          "y": 870
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: f534ab24-4d30-4974-8a22-629c0618a5dd
    type: title
    task:
      id: f534ab24-4d30-4974-8a22-629c0618a5dd
      version: -1
      name: Containment Complete
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "9"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 30,
          "y": 1360
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: 18d1a970-aee6-4ace-8a48-b07c6e6e1a99
    type: title
    task:
      id: 18d1a970-aee6-4ace-8a48-b07c6e6e1a99
      version: -1
      name: Investigation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "12"
      - "13"
      - "28"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1500
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "10":
    id: "10"
    taskid: a14d40f5-2bcc-43f4-8577-750c43d57846
    type: playbook
    task:
      id: a14d40f5-2bcc-43f4-8577-750c43d57846
      version: -1
      name: Cloud User Investigation - Generic
      description: |
        This playbook performs an investigation on a specific user in cloud environments, using queries and logs from Azure Log Analytics, AWS CloudTrail, G Suite Auditor, and GCP Logging.
      playbookName: Cloud User Investigation - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "44"
    scriptarguments:
      AwsTimeSearchFrom:
        simple: "1"
      AzureSearchTime:
        simple: ago(1d)
      GcpTimeSearchFrom:
        simple: "1"
      MfaAttemptThreshold:
        simple: "10"
      Username:
        simple: ${alert.usernames}
      cloudProvider:
        simple: ${alert.cloudprovider.[0]}
      failedLogonThreshold:
        simple: "20"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 30,
          "y": 1770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "11":
    id: "11"
    taskid: 6c232656-52c6-4b24-8918-30776fa31077
    type: playbook
    task:
      id: 6c232656-52c6-4b24-8918-30776fa31077
      version: -1
      name: Cloud Enrichment - Generic
      description: |2-

        ## Generic Cloud Enrichment Playbook

        The **Cloud Enrichment - Generic Playbook** is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments.

        ### Supported Blocks

        1. **Cloud IAM Enrichment - Generic**
           - Enriches information related to Identity and Access Management (IAM) in the cloud.

        2. **Cloud Compute Enrichment - Generic**
           - Enriches information related to cloud compute resources.

        The playbook supports a single CSP enrichment at a time.
      playbookName: Cloud Enrichment - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      cloudProvider:
        simple: ${alert.cloudprovider.[0]}
      instanceID:
        simple: ${PrismaCloud.Alert.resource.id}
      instanceName:
        simple: ${PrismaCloud.Alert.resource.account}
      region:
        simple: ${PrismaCloud.Alert.resource.regionId}
      username:
        simple: ${alert.usernames}
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 450,
          "y": 40
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: a699ec17-49ce-415f-8606-1966eb79ce46
    type: title
    task:
      id: a699ec17-49ce-415f-8606-1966eb79ce46
      version: -1
      name: User Investigation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "10"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 30,
          "y": 1640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: dcaae03d-4ff1-4da5-8cdb-f82bf89d1df7
    type: title
    task:
      id: dcaae03d-4ff1-4da5-8cdb-f82bf89d1df7
      version: -1
      name: Vulnerability Enrichment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "43"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 880,
          "y": 1640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "15":
    id: "15"
    taskid: 74c75a3e-d86c-4cf5-86b4-952537f330a5
    type: title
    task:
      id: 74c75a3e-d86c-4cf5-86b4-952537f330a5
      version: -1
      name: Verdict
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "38"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "16":
    id: "16"
    taskid: bd3672c0-2ab6-4835-8cca-3fdc2b1d2af7
    type: condition
    task:
      id: bd3672c0-2ab6-4835-8cca-3fdc2b1d2af7
      version: -1
      name: Does response needed?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "27"
      "yes":
      - "17"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: alert.verdict
            iscontext: true
          right:
            value:
              simple: malicious
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 900a4aff-dd98-4611-8b66-b6a56945a6fd
    type: title
    task:
      id: 900a4aff-dd98-4611-8b66-b6a56945a6fd
      version: -1
      name: Remediation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "21"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 840,
          "y": 2780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: fd02b167-e582-4040-8a9f-302fe467f7be
    type: playbook
    task:
      id: fd02b167-e582-4040-8a9f-302fe467f7be
      version: -1
      name: Cloud Response - Generic
      description: |-
        This playbook provides response playbooks for:
        - AWS
        - Azure
        - GCP

        The response actions available are:
        - Terminate/Shut down/Power off an instance
        - Delete/Disable a user
        - Delete/Revoke/Disable credentials
        - Block indicators
      playbookName: Cloud Response - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "46"
    scriptarguments:
      cloudProvider:
        simple: ${alert.cloudprovider.[0]}
      sourceIP:
        complex:
          root: DBotScore.Indicator
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: ip
              ignorecase: true
          - - operator: in
              left:
                value:
                  simple: DBotScore.Indicator
                iscontext: true
              right:
                value:
                  simple: alert.remoteip
                iscontext: true
      username:
        simple: ${alert.usernames}
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 840,
          "y": 3090
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: 6c693e4e-ede1-46b2-8edf-2e90906e2664
    type: condition
    task:
      id: 6c693e4e-ede1-46b2-8edf-2e90906e2664
      version: -1
      name: Perform Cloud Response?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "27"
      "yes":
      - "20"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.CloudResponse
            iscontext: true
          right:
            value:
              simple: "true"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 840,
          "y": 2920
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: bb6704b2-b3d8-4473-8e26-32cdeed54c20
    type: condition
    task:
      id: bb6704b2-b3d8-4473-8e26-32cdeed54c20
      version: -1
      name: Pause the playbook to perform policy recommendations?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "24"
      "yes":
      - "23"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.StopForRecommendations
            iscontext: true
          right:
            value:
              simple: "true"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 3770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 8fe0d4e7-caa6-4776-8a20-0337be0dd38a
    type: regular
    task:
      id: 8fe0d4e7-caa6-4776-8a20-0337be0dd38a
      version: -1
      name: Pause the playbook to perform policy recommendations
      type: regular
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "24"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 690,
          "y": 3940
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "24":
    id: "24"
    taskid: c7d45bdf-b5e9-47ea-82f7-cb356e1c1f7f
    type: title
    task:
      id: c7d45bdf-b5e9-47ea-82f7-cb356e1c1f7f
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 4120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "25":
    id: "25"
    taskid: 9640af49-911a-45a8-8624-da033d349dd2
    type: playbook
    task:
      id: 9640af49-911a-45a8-8624-da033d349dd2
      version: -1
      name: Block IP - Generic v3
      description: "This playbook blocks malicious IP addresses using all integrations that are enabled. The direction of the traffic that will be blocked is determined by the XSOAR user (and set by default to outgoing)\nNote the following:\n-  some of those integrations require specific parameters to run, which are based on the playbook inputs. Also, certain integrations use FW rules or appended network objects.\n- Note that the appended network objects should be specified in blocking rules inside the system later on. \n\n\nSupported integrations for this playbook [Network security products such as FW/WAF/IPs/etc.]: \n\n* Check Point Firewall\n* Palo Alto Networks PAN-OS\n* Zscaler\n* FortiGate\n* Aria Packet Intelligence\n* Cisco Firepower \n* Cisco Secure Cloud Analytics\n* Cisco ASA\n* Akamai WAF\n* F5 SilverLine\n* ThreatX\n* Signal Sciences WAF\n* Sophos Firewall\n\n"
      playbookName: Block IP - Generic v3
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "39"
    scriptarguments:
      AutoCommit:
        simple: "No"
      CustomBlockRule:
        simple: "True"
      Folder:
        simple: Shared
      IP:
        complex:
          root: DBotScore.Indicator
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: ip
              ignorecase: true
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          - - operator: in
              left:
                value:
                  simple: DBotScore.Indicator
                iscontext: true
              right:
                value:
                  simple: alert.remoteip
                iscontext: true
      InputEnrichment:
        simple: "False"
      InternalRange:
        complex:
          root: lists
          accessor: PrivateIPs
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2})
              unpack_matches: {}
          - operator: join
            args:
              separator:
                value:
                  simple: ','
      RuleDirection:
        simple: outbound
      RuleName:
        simple: XSIAM - Block IP playbook - ${alert.id}
      UserVerification:
        simple: "True"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -260,
          "y": 1000
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "26":
    id: "26"
    taskid: db3a06dc-6674-445a-8fa5-2d5a8e4da825
    type: playbook
    task:
      id: db3a06dc-6674-445a-8fa5-2d5a8e4da825
      version: -1
      name: Ticket Management - Generic
      description: "`Ticket Management - Generic` allows you to open new tickets or update comments to the existing ticket in the following ticketing systems:\n-ServiceNow \n-Zendesk \nusing the following sub-playbooks:\n-`ServiceNow - Ticket Management`\n-`Zendesk - Ticket Management`"
      playbookName: Ticket Management - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "22"
    scriptarguments:
      ZendeskAssigne:
        simple: ${inputs.ZendeskAssigne}
      ZendeskCollaborators:
        simple: ${inputs.ZendeskCollaborators}
      ZendeskPriority:
        simple: ${inputs.ZendeskPriority}
      ZendeskRequester:
        simple: ${inputs.ZendeskRequester}
      ZendeskStatus:
        simple: ${inputs.ZendeskStatus}
      ZendeskSubject:
        simple: ${inputs.ZendeskSubject}
      ZendeskTags:
        simple: ${inputs.ZendeskTags}
      ZendeskType:
        simple: ${inputs.ZendeskType}
      addCommentPerEndpoint:
        simple: "True"
      description:
        simple: ${inputs.ZenDeskDescription}
      serviceNowAssignmentGroup:
        simple: ${inputs.serviceNowAssignmentGroup}
      serviceNowCategory:
        simple: ${inputs.serviceNowCategory}
      serviceNowImpact:
        simple: ${inputs.serviceNowImpact}
      serviceNowSeverity:
        simple: ${inputs.serviceNowSeverity}
      serviceNowShortDescription:
        simple: ${inputs.serviceNowShortDescription}
      serviceNowTicketType:
        simple: ${inputs.serviceNowTicketType}
      serviceNowUrgency:
        simple: ${inputs.serviceNowUrgency}
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 690,
          "y": 3600
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: cc2d6c1e-9c5b-4322-8df2-33fecac16230
    type: condition
    task:
      id: cc2d6c1e-9c5b-4322-8df2-33fecac16230
      version: -1
      name: Create a ticket?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "22"
      "yes":
      - "26"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.CreateTicket
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 3430
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: 1410b003-f2f9-4bdd-804a-865520e77086
    type: title
    task:
      id: 1410b003-f2f9-4bdd-804a-865520e77086
      version: -1
      name: Risky User
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "29"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "29":
    id: "29"
    taskid: a57b5f12-570d-463f-8e3e-6e20a7dcbb18
    type: regular
    task:
      id: a57b5f12-570d-463f-8e3e-6e20a7dcbb18
      version: -1
      name: Check if user is risky by XDR
      description: Retrieve the risk score of a specific user or list of users with the highest risk score in the environment along with the reason affecting each score.
      script: '|||core-list-risky-users'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      user_id:
        simple: ${alert.usernames}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    fieldMapping:
    - incidentfield: User Risk Level
      output:
        simple: ${Core.RiskyUser.risk_level}
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "33":
    id: "33"
    taskid: d0cf5850-da44-4de5-8a7e-d8fde47fd66c
    type: regular
    task:
      id: d0cf5850-da44-4de5-8a7e-d8fde47fd66c
      version: -1
      name: Prisma alert enrichment
      description: Gets the details of an alert based on the alert ID.
      script: '|||prisma-cloud-alert-get-details'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "35"
      - "40"
      - "11"
    scriptarguments:
      alert_id:
        simple: ${alert.external_id}
      detailed:
        simple: "true"
      using:
        simple: ${alert.sourceInstance}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 900,
          "y": -130
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    fieldMapping:
    - incidentfield: First Seen
      output:
        simple: ${PrismaCloud.Alert.firstSeen}
    - incidentfield: Last Seen
      output:
        simple: ${PrismaCloud.Alert.lastSeen}
    - incidentfield: Alert Rules
      output:
        simple: ${PrismaCloud.Alert.alertRules}
    - incidentfield: Account Name
      output:
        simple: ${PrismaCloud.Alert.resource.account}
    - incidentfield: Account ID
      output:
        simple: ${PrismaCloud.Alert.resource.accountId}
    - incidentfield: Referenced Resource Name
      output:
        simple: ${PrismaCloud.Alert.resource.rrn}
    - incidentfield: Region ID
      output:
        simple: ${PrismaCloud.Alert.resource.regionId}
    - incidentfield: Region
      output:
        simple: ${alert.prisma_region.[0]}
    - incidentfield: Resource Type
      output:
        simple: ${PrismaCloud.Alert.resource.resourceType}
    - incidentfield: System Default Policy
      output:
        simple: ${PrismaCloud.Alert.policy.systemDefault}
    - incidentfield: Resource URL
      output:
        simple: ${PrismaCloud.Alert.resource.url}
    - incidentfield: Last Seen
      output:
        simple: ${PrismaCloud.Alert.lastSeen}
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "34":
    id: "34"
    taskid: aab9ed40-9025-4883-88f0-c2ab4c7234e6
    type: condition
    task:
      id: aab9ed40-9025-4883-88f0-c2ab4c7234e6
      version: -1
      name: Does Alert Contains IP?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "2"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: alert.remoteip
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -50,
          "y": -130
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: 7265dfe6-a8a7-4b86-8066-c118ba872dbe
    type: condition
    task:
      id: 7265dfe6-a8a7-4b86-8066-c118ba872dbe
      version: -1
      name: Host RRN has received from Prisma?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "36"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: PrismaCloud.Alert.resource.rrn
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 900,
          "y": 40
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: 84ddcd55-108f-4bcb-8608-6287ad05bffb
    type: regular
    task:
      id: 84ddcd55-108f-4bcb-8608-6287ad05bffb
      version: -1
      name: Get host findings
      description: Get resource host finding list.
      script: '|||prisma-cloud-host-finding-list'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      all_results:
        simple: "true"
      rrn:
        simple: ${PrismaCloud.Alert.resource.rrn}
      using:
        simple: ${alert.sourceInstance}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 900,
          "y": 220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "38":
    id: "38"
    taskid: 17a38aca-0335-45d3-8b9e-02c7104517d4
    type: regular
    task:
      id: 17a38aca-0335-45d3-8b9e-02c7104517d4
      version: -1
      name: Determine Verdict
      description: commands.local.cmd.set.incident
      script: Builtin|||setAlert
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "16"
    scriptarguments:
      verdict:
        complex:
          root: ${
          accessor: '}'
          transformers:
          - operator: If-Elif
            args:
              conditions:
                value:
                  simple: |-
                    [
                      {
                        "condition": "#{alert.ipreputation} == '2'",
                        "return": "Suspicious"
                      },
                      {
                        "condition": "#{alert.useranomalycount} > '0'",
                        "return": "Suspicious"
                      },
                      {
                        "condition": "#{alert.ipreputation} == '3'",
                        "return": "Malicious"
                      },
                      {
                        "default": 'Undetermined'
                      }
                    ]
              flags:
                value:
                  simple: alert.ipreputation
                iscontext: true
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2410
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "39":
    id: "39"
    taskid: 893a8d8d-ae3a-4d65-8399-128b550d4655
    type: regular
    task:
      id: 893a8d8d-ae3a-4d65-8399-128b550d4655
      version: -1
      name: Set status to layout
      description: commands.local.cmd.set.incident
      script: Builtin|||setAlert
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      ipblockedstatus:
        simple: Executed
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -260,
          "y": 1160
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "40":
    id: "40"
    taskid: 8bab5ef9-fbad-4e40-8750-f235d3e0a15d
    type: condition
    task:
      id: 8bab5ef9-fbad-4e40-8750-f235d3e0a15d
      version: -1
      name: Is Part of Alert Rule?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "41"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: PrismaCloud.Alert.alertRules
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1320,
          "y": 40
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "41":
    id: "41"
    taskid: 436263bc-db35-424b-8cf0-051512df12a2
    type: regular
    task:
      id: 436263bc-db35-424b-8cf0-051512df12a2
      version: -1
      name: Map Alert Rules
      description: Accepts a json object and returns a markdown.
      scriptName: JsonToTable
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      extend-context:
        simple: prismaalertrules=
      value:
        simple: ${PrismaCloud.Alert.alertRules}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1320,
          "y": 220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    fieldMapping:
    - incidentfield: Alert Rules
      output:
        simple: ${prismaalertrules}
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "42":
    id: "42"
    taskid: 3f873b48-5e22-4196-817f-bd02b7a11266
    type: regular
    task:
      id: 3f873b48-5e22-4196-817f-bd02b7a11266
      version: -1
      name: Get CVE Details
      description: Returns CVE information by CVE ID.
      script: '|||cve'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      cve:
        simple: ${CVE.ID}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 880,
          "y": 1930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    fieldMapping:
    - incidentfield: CVSS
      output:
        simple: ${CVE.CVSS.Score}
    - incidentfield: CVE Description
      output:
        simple: ${CVE.Description}
    - incidentfield: CVE Published
      output:
        simple: ${CVE.Published}
    - incidentfield: Vulnerable Product
      output:
        simple: ${CVE.vulnerableproduct}
    - incidentfield: CVE ID
      output:
        simple: ${CVE.ID}
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "43":
    id: "43"
    taskid: 47f296ff-d425-4a5d-8fec-5ec90f8dc250
    type: condition
    task:
      id: 47f296ff-d425-4a5d-8fec-5ec90f8dc250
      version: -1
      name: Has related CVE?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "15"
      "yes":
      - "42"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: CVE
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 880,
          "y": 1770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "44":
    id: "44"
    taskid: 2aec9d38-f06a-4694-869f-60f8daa27e8e
    type: condition
    task:
      id: 2aec9d38-f06a-4694-869f-60f8daa27e8e
      version: -1
      name: Has Results?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "15"
      "yes":
      - "45"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: AwsSuspiciousActivitiesCount
            iscontext: true
          right:
            value: {}
        - operator: isNotEmpty
          left:
            value:
              simple: GcpAnomalousNetworkTraffic
            iscontext: true
        - operator: isEqualString
          left:
            value:
              simple: CountAzureEvents.AzureAnomaliesCount
            iscontext: true
          right:
            value:
              simple: "true"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 30,
          "y": 1930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "45":
    id: "45"
    taskid: 7837fc50-fa9d-489a-89af-977c5c4100b2
    type: regular
    task:
      id: 7837fc50-fa9d-489a-89af-977c5c4100b2
      version: -1
      name: Set User Investigation Results
      description: commands.local.cmd.set.incident
      script: Builtin|||setAlert
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      useranomalycount:
        complex:
          root: CountAzureEvents
          accessor: AzureAnomaliesCount
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: AwsSuspiciousActivitiesCount
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: GcpAnomalousNetworkTraffic
                iscontext: true
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 30,
          "y": 2100
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "46":
    id: "46"
    taskid: 59de8147-06f1-4f75-8c2d-ba383f66db0a
    type: regular
    task:
      id: 59de8147-06f1-4f75-8c2d-ba383f66db0a
      version: -1
      name: Set status to layout
      description: commands.local.cmd.set.incident
      script: Builtin|||setAlert
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "27"
    scriptarguments:
      ipblockedstatus:
        simple: Executed
      userblockstatus:
        simple: Executed
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 840,
          "y": 3250
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "35_3_#default#": 0.1,
      "40_3_#default#": 0.22,
      "4_6_yes": 0.3
    },
    "paper": {
      "dimensions": {
        "height": 4615,
        "width": 1960,
        "x": -260,
        "y": -430
      }
    }
  }
inputs:
- key: CreateTicket
  value:
    simple: "False"
  required: false
  description: Whether to create a ticket in ZenDesk or ServiceNow. Insert True or False
  playbookInputQuery:
- key: StopForRecommendations
  value:
    simple: "True"
  required: false
  description: ""
  playbookInputQuery:
- key: EarlyContainment
  value:
    simple: "True"
  required: false
  description: Whether to perform early containment.
  playbookInputQuery:
- key: CloudResponse
  value:
    simple: "False"
  required: false
  description: Whether to perform cloud response.
  playbookInputQuery:
- key: serviceNowShortDescription
  value: {}
  required: false
  description: A short description of the ticket.
  playbookInputQuery:
- key: serviceNowImpact
  value: {}
  required: false
  description: The impact for the new ticket. Leave empty for ServiceNow default impact.
  playbookInputQuery:
- key: serviceNowUrgency
  value: {}
  required: false
  description: The urgency of the new ticket. Leave empty for ServiceNow default urgency.
  playbookInputQuery:
- key: serviceNowSeverity
  value: {}
  required: false
  description: The severity of the new ticket. Leave empty for ServiceNow default severity.
  playbookInputQuery:
- key: serviceNowTicketType
  value: {}
  required: false
  description: The ServiceNow ticket type. Options are "incident", "problem", "change_request", "sc_request", "sc_task", or "sc_req_item". Default is "incident".
  playbookInputQuery:
- key: serviceNowCategory
  value: {}
  required: false
  description: The category of the ServiceNow ticket.
  playbookInputQuery:
- key: serviceNowAssignmentGroup
  value: {}
  required: false
  description: The group to which to assign the new ticket.
  playbookInputQuery:
- key: ZendeskPriority
  value: {}
  required: false
  description: The urgency with which the ticket should be addressed. Allowed values are "urgent", "high", "normal", or "low".
  playbookInputQuery:
- key: ZendeskRequester
  value: {}
  required: false
  description: The user who requested this ticket.
  playbookInputQuery:
- key: ZendeskStatus
  value: {}
  required: false
  description: The state of the ticket. Allowed values are "new", "open", "pending", "hold", "solved", or "closed".
  playbookInputQuery:
- key: ZendeskSubject
  value: {}
  required: false
  description: The value of the subject field for this ticket.
  playbookInputQuery:
- key: ZendeskTags
  value: {}
  required: false
  description: The array of tags applied to this ticket.
  playbookInputQuery:
- key: ZendeskType
  value: {}
  required: false
  description: The type of this ticket. Allowed values are "problem", "incident", "question", or "task".
  playbookInputQuery:
- key: ZendeskAssigne
  value: {}
  required: false
  description: The agent currently assigned to the ticket.
  playbookInputQuery:
- key: ZendeskCollaborators
  value: {}
  required: false
  description: The users currently CC'ed on the ticket.
  playbookInputQuery:
- key: ZenDeskDescription
  value: {}
  required: false
  description: The ticket description.
  playbookInputQuery:
inputSections:
- inputs:
  - CreateTicket
  - StopForRecommendations
  name: Alert Management
  description: |
    Alert management settings and data,
- inputs:
  - EarlyContainment
  - CloudResponse
  name: Remediation
  description: Remediation settings and data, including containment, eradication, and recovery.
- inputs:
  - serviceNowShortDescription
  - serviceNowImpact
  - serviceNowUrgency
  - serviceNowSeverity
  - serviceNowTicketType
  - serviceNowCategory
  - serviceNowAssignmentGroup
  name: Ticket Management- ServiceNow
  description: Ticket management settings and data for ServiceNow
- inputs:
  - ZendeskPriority
  - ZendeskRequester
  - ZendeskStatus
  - ZendeskSubject
  - ZendeskTags
  - ZendeskType
  - ZendeskAssigne
  - ZendeskCollaborators
  - ZenDeskDescription
  name: Ticket Management - ZenDesk
  description: Ticket management settings and data for ZenDesk
outputSections:
- outputs: []
  name: General (Outputs group)
  description: Generic group for outputs
outputs: []
tests:
- No tests (auto formatted)
marketplaces: ["marketplacev2", "platform"]
fromversion: 6.10.0
supportedModules:
- cloud
- cloud_runtime_security
- xsiam
- edr