Process Incident - Vectra XDR

This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook.

Vectra XDR · 8 tasks · 0 inputs · 0 outputs

Details

IDProcess Incident - Vectra XDR
From Version6.8.0
Tasks8

README

This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Dispatch Incident - Vectra XDR
  • Add Note - Vectra XDR

Integrations

  • VectraXDR

Scripts

  • VectraXDRAddNotesInLayout
  • DeleteContext

Commands

  • vectra-user-list

Playbook Inputs


There are no inputs for this playbook.

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Process Incident - Vectra XDR

Commands used

vectra-user-list

Flowchart

Start Start Done Done Get the Vectra UserID to assign the current entity. Get the Vectra UserID to ... Delete the context of GetUserID - DeleteContext Delete the context of Get... DeleteContext List Available Users for Assignment - vectra-user-list List Available Users for ... vectra-user-list Dispatch Incident - Vectra XDR - Dispatch Incident - Vectra XDR Dispatch Incident - Vectr... Dispatch Incident - Vectra XDR Add Note - Vectra XDR - Add Note - Vectra XDR Add Note - Vectra XDR Add Note - Vectra XDR Add entity notes to the layout. - VectraXDRAddNotesInLayout Add entity notes to the l... VectraXDRAddNotesInLayout
id: Process Incident - Vectra XDR
version: -1
name: Process Incident - Vectra XDR
description: This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 3c98d2d3-b434-4946-8366-b4dfddb80a29
    type: start
    task:
      id: 3c98d2d3-b434-4946-8366-b4dfddb80a29
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "12"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: eb0627e1-fd16-48a9-8a73-b06a5d0d0cfa
    type: title
    task:
      id: eb0627e1-fd16-48a9-8a73-b06a5d0d0cfa
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1245
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: 4b15e9c2-436f-41e3-8d2e-cd60c9ecc09c
    type: collection
    task:
      id: 4b15e9c2-436f-41e3-8d2e-cd60c9ecc09c
      version: -1
      name: Get the Vectra UserID to assign the current entity.
      description: Provide the Vectra User ID to assign the current entity in Vectra.
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "11"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: Provide the Vectra User ID to assign the current entity in Vectra.
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: 'Enter the Vectra User ID to assign the current entity: '
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg: []
        fieldassociated: ""
        placeholder: ""
        tooltip: ""
        readonly: false
      title: GetUserID
      description: ""
      sender: ""
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: e2d22193-588a-4dc0-88d8-abde5bce3375
    type: regular
    task:
      id: e2d22193-588a-4dc0-88d8-abde5bce3375
      version: -1
      name: Delete the context of GetUserID
      description: |-
        Delete field from context.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: DeleteContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      key:
        simple: GetUserID
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: 344ff522-06bc-4a6a-847e-850c73d4f655
    type: regular
    task:
      id: 344ff522-06bc-4a6a-847e-850c73d4f655
      version: -1
      name: List Available Users for Assignment
      description: Returns a list of users.
      script: '|||vectra-user-list'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "10":
    id: "10"
    taskid: 0cc1a518-e1e9-4773-851d-41cf98477437
    type: playbook
    task:
      id: 0cc1a518-e1e9-4773-851d-41cf98477437
      version: -1
      name: Dispatch Incident - Vectra XDR
      playbookName: Dispatch Incident - Vectra XDR
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      UserID:
        complex:
          root: GetUserID.Answers
          accessor: "0"
          transformers:
          - operator: LastArrayElement
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "11":
    id: "11"
    taskid: 67172383-99f8-454c-88af-0eff8ceba2d9
    type: playbook
    task:
      id: 67172383-99f8-454c-88af-0eff8ceba2d9
      version: -1
      name: Add Note - Vectra XDR
      playbookName: Add Note - Vectra XDR
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "10"
    separatecontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 895
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: 819e40bf-1a4d-4892-82dd-04b1739b76f0
    type: regular
    task:
      id: 819e40bf-1a4d-4892-82dd-04b1739b76f0
      version: -1
      name: Add entity notes to the layout.
      description: This script allows to add Entity notes in the layout.
      scriptName: VectraXDRAddNotesInLayout
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 50,
          "y": 195
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1260,
        "width": 380,
        "x": 50,
        "y": 50
      }
    }
  }
inputs: []
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.8.0