Send Investigation Summary Reports

This playbook iterates over closed incidents, generates a summary report for each closed incident, and emails the reports to specified users.

Common Playbooks · 7 tasks · 4 inputs · 0 outputs

Details

IDSend Investigation Summary Reports
From Version5.0.0
Tasks7

README

Iterates over closed incidents, generates a summary report for each closed incident, and emails the reports to specified users.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

  • Builtin

Scripts

  • SearchIncidentsV2
  • GenerateSummaryReports
  • Exists

Commands

  • send-mail
  • setIncident

Playbook Inputs


Name Description Default Value Required
MailTo The email address to mail the report to. None Required
ReportName The reports to generate. Investigation Summary Optional
ReportType The type of report. pdf Optional
IncidentSearchQuery The query used to search for incidents. Default query will search for all incidents closed within the last hour. -category:job status:closed closed:>=”1 hour ago” Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Send_Investigation_Summary_Reports

Inputs

  • MailTo — Email address to mail the report to.
  • ReportName — Reports to generate.
  • ReportType — Type of report
  • IncidentSearchQuery — Query used to search for incidents. Default query will search for all incidents closed within the last hour.

Commands used

send-mail setIncident

Flowchart

yes Start Start Find Closed Incidents - SearchIncidentsV2 Find Closed Incidents SearchIncidentsV2 Generate Summary Report - GenerateSummaryReports Generate Summary Report GenerateSummaryReports Email Reports - send-mail Email Reports send-mail Set Report Done Label - setIncident Set Report Done Label setIncident Complete Complete Are there relevant closed incidents? - Exists Are there relevant closed... Exists
id: Send Investigation Summary Reports
version: -1
name: Send Investigation Summary Reports
description: 'This playbook iterates over closed incidents, generates a summary report for each closed incident, and emails the reports to specified users. '
starttaskid: "0"
fromversion: "5.0.0"
marketplaces:
- xsoar
- marketplacev2
- platform
tasks:
  "0":
    id: "0"
    taskid: efefff28-b722-4f90-86cf-da4636ecf7f6
    type: start
    task:
      id: efefff28-b722-4f90-86cf-da4636ecf7f6
      version: -1
      name: ""
      description: ""
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 450,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "3":
    id: "3"
    taskid: 22f91f1b-ad02-4439-85de-444c9cc9165c
    type: regular
    task:
      id: 22f91f1b-ad02-4439-85de-444c9cc9165c
      version: -1
      name: Find Closed Incidents
      description: Searches Demisto incidents to identify closed incidents.
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      details: {}
      fromclosedate: {}
      fromdate: {}
      fromduedate: {}
      id: {}
      level: {}
      name: {}
      notstatus: {}
      owner: {}
      page: {}
      query:
        simple: ${inputs.IncidentSearchQuery}
      reason: {}
      size: {}
      sort: {}
      status: {}
      toclosedate: {}
      todate: {}
      toduedate: {}
      type: {}
    reputationcalc: 1
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 450,
          "y": 190
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "4":
    id: "4"
    taskid: b28d0033-ac09-4d02-84fc-c6d363d80f51
    type: regular
    task:
      id: b28d0033-ac09-4d02-84fc-c6d363d80f51
      version: -1
      name: Generate Summary Report
      description: Generates report summaries for the passed incidents.
      scriptName: GenerateSummaryReports
      type: regular
      iscommand: false
      brand: Builtin
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      ids:
        simple: ${foundIncidents(!val.labels || val.labels.filter(function(v) { return  v.type == 'ReportSent'}).length == 0).id}
      name:
        simple: ${inputs.ReportName}
      type:
        simple: ${inputs.ReportType}
    reputationcalc: 1
    separatecontext: false
    skipunavailable: true
    view: |-
      {
        "position": {
          "x": 900,
          "y": 560
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "5":
    id: "5"
    taskid: d7525c1a-713e-446c-89d3-f43963155023
    type: regular
    task:
      id: d7525c1a-713e-446c-89d3-f43963155023
      version: -1
      name: Email Reports
      description: Send an email
      script: '|||send-mail'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "6"
    scriptarguments:
      attachCIDs: {}
      attachIDs:
        simple: ${InfoFile.EntryID}
      attachNames: {}
      bcc: {}
      body:
        simple: Please find attached summary reports for recently closed incidents.
      cc: {}
      htmlBody: {}
      replyTo: {}
      subject:
        simple: Demisto Incident Summary Report
      templateParams: {}
      to:
        simple: ${inputs.MailTo}
      transientFile: {}
      transientFileCID: {}
      transientFileContent: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 900,
          "y": 770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "6":
    id: "6"
    taskid: 93763170-619f-46dc-8b98-4036b015019d
    type: regular
    task:
      id: 93763170-619f-46dc-8b98-4036b015019d
      version: -1
      name: Set Report Done Label
      description: commands.local.cmd.set.incident
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      addLabels:
        simple: '[{"ReportSent":"true"}]'
      affecteddata: {}
      affecteddatatype: {}
      affectedindividualscontactinformation: {}
      app: {}
      approximatenumberofaffecteddatasubjects: {}
      assetid: {}
      attachmentcount: {}
      attachmentextension: {}
      attachmenthash: {}
      attachmentid: {}
      attachmentname: {}
      attachmentsize: {}
      attachmenttype: {}
      bugtraq: {}
      city: {}
      closeNotes: {}
      closeReason: {}
      companyaddress: {}
      companycity: {}
      companycountry: {}
      companyhasinsuranceforthebreach: {}
      companyname: {}
      companypostalcode: {}
      contactaddress: {}
      contactname: {}
      country: {}
      countrywherebusinesshasitsmainestablishment: {}
      countrywherethebreachtookplace: {}
      customFields: {}
      cve: {}
      cvss: {}
      dataencryptionstatus: {}
      datetimeofthebreach: {}
      deleteEmptyField: {}
      dest: {}
      destntdomain: {}
      details: {}
      dpoemailaddress: {}
      duration: {}
      emailaddress: {}
      emailbcc: {}
      emailbody: {}
      emailbodyformat: {}
      emailbodyhtml: {}
      emailcc: {}
      emailclientname: {}
      emailfrom: {}
      emailinreplyto: {}
      emailkeywords: {}
      emailmessageid: {}
      emailreceived: {}
      emailreplyto: {}
      emailreturnpath: {}
      emailsenderip: {}
      emailsize: {}
      emailsource: {}
      emailsubject: {}
      emailto: {}
      emailtocount: {}
      emailurlclicked: {}
      filehash: {}
      filename: {}
      filepath: {}
      id:
        simple: ${foundIncidents.id}
      isthedatasubjecttodpia: {}
      labels: {}
      likelyimpact: {}
      maliciouscauseifthecauseisamaliciousattack: {}
      malwarefamily: {}
      measurestomitigate: {}
      name: {}
      occurred: {}
      owner: {}
      phase: {}
      possiblecauseofthebreach: {}
      postalcode: {}
      replacePlaybook: {}
      roles: {}
      sectorofaffectedparty: {}
      severity: {}
      signature: {}
      sizenumberofemployees: {}
      sizeturnover: {}
      sla: {}
      slaField: {}
      src: {}
      srcntdomain: {}
      srcuser: {}
      systems: {}
      telephoneno: {}
      type: {}
      user: {}
      vendorid: {}
      vendorproduct: {}
      vulnerabilitycategory: {}
      whereisdatahosted: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 900,
          "y": 1000
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "8":
    id: "8"
    taskid: a5d10443-87fb-403d-893a-05723bbc93c5
    type: title
    task:
      id: a5d10443-87fb-403d-893a-05723bbc93c5
      version: -1
      name: Complete
      description: ""
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 460,
          "y": 1180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "9":
    id: "9"
    taskid: 58e69d68-ff03-4356-8b8f-d61f60346c81
    type: condition
    task:
      id: 58e69d68-ff03-4356-8b8f-d61f60346c81
      version: -1
      name: Are there relevant closed incidents?
      description: Checks if there are any incidents without the ReportSent label. Note that the same DT of this task is used in the "Generate Summary Report" task.
      scriptName: Exists
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "8"
      "yes":
      - "4"
    scriptarguments:
      value:
        simple: ${foundIncidents(!val.labels || val.labels.filter(function(v) { return  v.type == 'ReportSent'}).length == 0).id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 450,
          "y": 365
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1195,
        "width": 830,
        "x": 450,
        "y": 50
      }
    }
  }
inputs:
- key: MailTo
  value:
    simple:
  required: true
  description: Email address to mail the report to.
- key: ReportName
  value:
    simple: Investigation Summary
  required: false
  description: Reports to generate.
- key: ReportType
  value:
    simple: pdf
  required: false
  description: Type of report
- key: IncidentSearchQuery
  value:
    simple: -category:job status:closed closed:>="1 hour ago"
  required: false
  description: Query used to search for incidents. Default query will search for all incidents closed within the last hour.
outputs: []
tests:
- Send Investigation Summary Reports - Test