{ "detailsV2": { "tabs": [ { "hidden": false, "id": "summary", "name": "Classic Summary", "type": "summary" }, { "hidden": false, "id": "swtuqptgvs", "name": "Case info", "sections": [ { "displayType": "CARD", "h": 2, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-57f33cc0-97ee-11e9-b8bd-0b00be54d2d3", "isVisible": true, "items": [ { "dropEffect": "move", "endCol": 2, "fieldId": "attachment", "height": 53, "id": "9cd0f990-ac6b-11e9-bb03-dd1b065c10a8", "index": 0, "listId": "swtuqptgvs-49052550-97f0-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Attachments", "static": false, "w": 1, "x": 2, "y": 3 }, { "displayType": "ROW", "h": 3, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "isVisible": true, "items": [ { "endCol": 2, "fieldId": "occurred", "height": 22, "id": "418772e0-a901-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "severity", "height": 22, "id": "45ef12c0-a901-11ec-8585-0dac7af6e9b0", "index": 1, "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "owner", "height": 22, "id": "4b1ac5f0-a901-11ec-8585-0dac7af6e9b0", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailorigin", "height": 22, "id": "b8f3e800-6279-11ec-8fa2-217b8b611613", "index": 3, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "reportedemailfrom", "height": 22, "id": "be942ef0-6279-11ec-8fa2-217b8b611613", "index": 4, "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailto", "height": 22, "id": "c2ce0810-6279-11ec-8fa2-217b8b611613", "index": 5, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailcc", "height": 22, "id": "b6f8e8b0-a901-11ec-8585-0dac7af6e9b0", "index": 6, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "reporteremailaddress", "height": 22, "id": "93c5bbb0-df83-11e9-9d3d-b355b2831118", "index": 7, "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emailbcc", "height": 22, "id": "2bd969b0-879c-11ed-b4ee-6db51deb2f6e", "index": 8, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailsubject", "height": 22, "id": "02f6f6c0-111c-11ee-a4d9-8dbe5c55933f", "index": 9, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "attachmentcount", "height": 22, "id": "86ae8b10-a901-11ec-8585-0dac7af6e9b0", "index": 10, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emailrecipientscount", "height": 22, "id": "77a63970-6279-11ec-8fa2-217b8b611613", "index": 11, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "additionalemailaddresses", "height": 26, "id": "c477b540-d63e-11ee-a660-f13ca793ceb6", "index": 11, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "categories", "height": 22, "id": "5e2287d0-e502-11ed-ba0f-99a713ead7dc", "index": 12, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Case Basic Details", "static": false, "w": 1, "x": 0, "y": 0 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-067d4900-98b4-11e9-97d7-ed26ef9e46c8", "isVisible": true, "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Incident Files", "query": { "categories": [ "attachments" ], "notTags": [ "email_html_image", "url_screenshots" ], "tags": [], "tagsAndOperator": true }, "queryType": "warRoomFilter", "readOnly": true, "static": false, "type": "invTimeline", "w": 2, "x": 0, "y": 14 }, { "displayType": "ROW", "h": 5, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-cc557320-98b7-11e9-b34a-852d068f44fe", "isVisible": true, "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Indicators", "query": "", "queryType": "input", "readOnly": true, "static": false, "type": "indicators", "w": 2, "x": 0, "y": 3 }, { "displayType": "ROW", "h": 3, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-0e149ea0-9d8e-11e9-a715-f7bbe72c84a2", "isVisible": true, "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Email HTML Image", "query": { "tags": [ "email_html_image" ] }, "queryType": "warRoomFilter", "readOnly": true, "static": false, "type": "invTimeline", "w": 1, "x": 1, "y": 0 }, { "h": 3, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-b5924880-df88-11e9-9d3d-b355b2831118", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "URL Screenshots", "query": { "tags": [ "url_screenshots" ] }, "queryType": "warRoomFilter", "static": false, "type": "invTimeline", "w": 1, "x": 2, "y": 0 }, { "description": "", "h": 1, "hideName": true, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-044bccb0-befa-11eb-b351-7bcfe92e5e24", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Related Phishing Campaign", "query": "LinkToPhishingCampaign", "queryType": "script", "static": false, "type": "dynamic", "w": 1, "x": 2, "y": 5 }, { "h": 2, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-e78cf650-a8fd-11ec-927e-2bbbcff3899b", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Work Plan", "static": false, "type": "workplan", "w": 1, "x": 2, "y": 6 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b", "items": [ { "endCol": 2, "fieldId": "reportedemailto", "height": 22, "id": "fdb6d7e0-adbf-11ec-9b0d-458b8734eabf", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "reportedemailmessageid", "height": 22, "id": "b2b6dc90-adbf-11ec-9b0d-458b8734eabf", "index": 1, "listId": "swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emaildeletetype", "height": 22, "id": "d30b3a90-adbf-11ec-9b0d-458b8734eabf", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emaildeletefrombrand", "height": 22, "id": "51e6d7d0-af45-11ec-99c4-cfc9ad59fcf6", "index": 3, "sectionItemType": "field", "startCol": 0 }, { "args": { "delete_from_brand": { "complex": { "accessor": "sourcebrand", "filters": [], "root": "incident", "transformers": [] } }, "delete_type": { "complex": { "accessor": "emaildeletetype", "filters": [], "root": "incident", "transformers": [] } } }, "buttonClass": "error", "dropEffect": "move", "endCol": 2, "fieldId": "", "height": 44, "id": "df048e20-a8fe-11ec-927e-2bbbcff3899b", "index": 4, "listId": "swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b", "name": "Delete email", "scriptId": "DeleteReportedEmail", "sectionItemType": "button", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Response action", "static": false, "w": 1, "x": 2, "y": 8 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-68df82f0-a902-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 2, "fieldId": "emaildeleteresult", "height": 22, "id": "0ef499c0-adc0-11ec-9b0d-458b8734eabf", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emaildeletereason", "height": 22, "id": "10429d90-adc0-11ec-9b0d-458b8734eabf", "index": 1, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Delete Result", "static": false, "w": 1, "x": 2, "y": 10 }, { "columns": [ { "displayed": true, "isDefault": true, "key": "id", "width": 109 }, { "displayed": true, "isDefault": true, "key": "name", "width": 336 }, { "displayed": true, "isDefault": true, "key": "type", "width": 200 }, { "displayed": true, "isDefault": true, "key": "status", "width": 100 }, { "displayed": true, "key": "Reported Email To", "width": 200 }, { "displayed": true, "key": "Reported Email From", "width": 200 }, { "displayed": true, "key": "Reported Email Message ID", "width": 368 }, { "displayed": true, "isDefault": true, "key": "closeNotes", "width": 300 } ], "h": 2, "i": "swtuqptgvs-field-changed-swtuqptgvs-8f724f40-6b37-11ed-b7c0-2904efd8f7fb", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Linked Incidents", "static": false, "type": "linkedIncidents", "w": 3, "x": 0, "y": 16 }, { "description": "Indicators selected to be blocked.", "h": 2, "i": "swtuqptgvs-1a52c090-c187-11ed-a413-1fc9f082fba8", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Selected indicators to block", "query": "tags:\"Blocked Indicator In Systems\"", "queryType": "input", "static": false, "type": "indicators", "w": 1, "x": 2, "y": 14 }, { "description": ":warning: This section contains the original HTML of the email. Links may lead to malicious websites!", "h": 6, "i": "swtuqptgvs-ca48f510-f322-11ed-8c15-d92844a806b0", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Email Body", "query": "DisplayHTMLWithImages", "queryType": "script", "static": false, "type": "dynamic", "w": 2, "x": 0, "y": 8 }, { "displayType": "CARD", "h": 2, "hideName": false, "i": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b", "items": [ { "dropEffect": "move", "endCol": 2, "fieldId": "triagesla", "height": 53, "id": "39e688c0-02e5-11ee-8d4d-65992a7b968b", "index": 1, "listId": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "remediationsla", "height": 53, "id": "37bf6300-02e5-11ee-8d4d-65992a7b968b", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "detectionsla", "height": 53, "id": "361116c0-02e5-11ee-8d4d-65992a7b968b", "index": 0, "listId": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b", "sectionItemType": "field", "startCol": 1 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Incident SLAs", "static": false, "w": 1, "x": 2, "y": 12 } ], "type": "custom" }, { "hidden": false, "id": "fn7ljmkjwi", "name": "Investigation", "sections": [ { "description": "Headers extracted from the original email.", "displayType": "ROW", "h": 5, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-12668f30-a903-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 4, "fieldId": "emailheaders", "height": 106, "id": "1b9a3610-a903-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Headers", "static": false, "w": 2, "x": 0, "y": 0 }, { "description": "Analysis of SPF, DKIM, DMARC and Microsoft anti-spam headers.\n\nFor Microsoft anti-spam headers, please click on each item for the relevant documentation:\n[PCL](https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps?view=exchserver-2019) - Phishing Confidence Level.\n[BCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values?view=o365-worldwide) - Bulk Complaint Level.\n[SCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide) - Spam Confidence Level.\n`Note`: The default value is 0, but it can be changed when the \"Process Microsoft's Email Headers\" playbook runs.", "displayType": "CARD", "h": 3, "hideName": false, "i": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "items": [ { "dropEffect": "move", "endCol": 1, "fieldId": "emailauthenticitycheck", "height": 53, "id": "e81fede0-a905-11ec-8585-0dac7af6e9b0", "index": 0, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 1, "fieldId": "phishingbclscore", "height": 53, "id": "753052e0-a903-11ec-8585-0dac7af6e9b0", "index": 1, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "phishingsclscore", "height": 53, "id": "738f2600-a903-11ec-8585-0dac7af6e9b0", "index": 0, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 1 }, { "dropEffect": "move", "endCol": 2, "fieldId": "phishingpclscore", "height": 53, "id": "779062f0-a903-11ec-8585-0dac7af6e9b0", "index": 2, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 1 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Headers Analysis", "static": false, "w": 1, "x": 2, "y": 0 }, { "description": "Results of machine-learning checks on the email using a pretrained model.", "displayType": "CARD", "h": 3, "hideName": false, "i": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "items": [ { "dropEffect": "move", "endCol": 1, "fieldId": "dbotpredictionprobability", "height": 53, "id": "e9282b90-a904-11ec-8585-0dac7af6e9b0", "index": 0, "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 1, "fieldId": "dbotprediction", "height": 53, "id": "e4e7c2c0-a904-11ec-8585-0dac7af6e9b0", "index": 1, "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "dbottextsuggestionhighlighted", "height": 106, "id": "fa1f2070-a904-11ec-8585-0dac7af6e9b0", "index": 2, "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "ML Prediction For The Email", "static": false, "w": 1, "x": 0, "y": 8 }, { "description": "The category of the email. In case of a phishing email, also shows the phishing sub-type.", "displayType": "ROW", "h": 3, "hideName": false, "i": "swtuqptgvs-4b078f40-a905-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 2, "fieldId": "emailclassification", "height": 22, "id": "6f45aa90-a905-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 4, "fieldId": "phishingsubtype", "height": 22, "id": "79e23040-a905-11ec-8585-0dac7af6e9b0", "index": 2, "sectionItemType": "field", "startCol": 2 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Type Information", "static": false, "w": 1, "x": 2, "y": 6 }, { "displayType": "ROW", "h": 5, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-86ec81a0-a905-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 4, "fieldId": "emailhtml", "height": 44, "id": "b3eb0fa0-a905-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Raw Email HTML", "static": false, "w": 2, "x": 0, "y": 11 }, { "displayType": "ROW", "h": 2, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-8b9776a0-a906-11ec-8585-0dac7af6e9b0", "items": [ { "dropEffect": "move", "endCol": 2, "fieldId": "emailkeywordsfound", "height": 22, "id": "2a056410-fedc-11ed-80a2-5b21992c1654", "index": 0, "listId": "swtuqptgvs-8b9776a0-a906-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "domainsquattingresult", "height": 44, "id": "9aca7460-a906-11ec-8585-0dac7af6e9b0", "index": 1, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Spear Phishing Investigation", "static": false, "w": 1, "x": 2, "y": 3 }, { "description": "Provides machine-learning based detection of phishing URLs (shows only malicious detections).", "h": 3, "i": "swtuqptgvs-d2300fd0-b5a1-11ec-9a46-87b4f35ed7e4", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "ML Prediction for URLs", "query": { "notTags": [], "tags": [ "DBOT_URL_PHISHING_MALICIOUS" ] }, "queryType": "warRoomFilter", "static": false, "type": "invTimeline", "w": 1, "x": 1, "y": 8 }, { "description": "In case a macro code was found in any of the attachments, the source code will appear here.", "displayType": "CARD", "h": 8, "hideName": false, "i": "swtuqptgvs-2b388350-4a26-11ed-9b10-cf167480534f", "items": [ { "endCol": 2, "fieldId": "macrosourcecode", "height": 22, "id": "59b96b90-4a26-11ed-9b10-cf167480534f", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Macro Source Code", "static": false, "w": 1, "x": 2, "y": 9 }, { "description": "In case there were URLs in the email with a score of 3 or above which the user clicked for the email investigated in this incident, they will appear in the **Clicked URLs** table. **Total Malicious URLs Clicks** represents the number of clicks in all emails (other emails as well) associated with any of the malicious URLs found in this email. **Malicious URL Viewed** will be **True** if the click was allowed or the user clicked through, in case it was blocked.", "displayType": "CARD", "h": 3, "hideName": false, "i": "swtuqptgvs-791f4a20-5d1a-11ed-936b-2d907795e2cc", "items": [ { "endCol": 1, "fieldId": "maliciousurlclicked", "height": 53, "id": "c0b24f80-8b4c-11ed-8d12-ef934cb7154e", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 4, "fieldId": "clickedurls", "height": 106, "id": "e4f91d60-8b4c-11ed-8d12-ef934cb7154e", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "maliciousurlviewed", "height": 53, "id": "e9800930-8c09-11ed-bd41-2b7339c8983d", "index": 0, "sectionItemType": "field", "startCol": 1 }, { "endCol": 3, "fieldId": "totalmaliciousurlsclicks", "height": 53, "id": "409da7d0-8b4d-11ed-8d12-ef934cb7154e", "index": 1, "sectionItemType": "field", "startCol": 2 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Malicious Clicked URLs information", "static": false, "w": 2, "x": 0, "y": 5 }, { "description": "", "displayType": "ROW", "h": 1, "hideName": false, "i": "swtuqptgvs-fn7ljmkjwi-swtuqptgvs-fn7ljmkjwi-swtuqptgvs-ed6ea880-fec8-11ed-8c2c-79dd47ae5c19", "items": [ { "endCol": 2, "fieldId": "relatedcampaign", "height": 22, "id": "02a542e0-fec9-11ed-8c2c-79dd47ae5c19", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "relatedreport", "height": 22, "id": "07dc19a0-fec9-11ed-8c2c-79dd47ae5c19", "index": 1, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Threat Intelligence Analysis", "static": false, "w": 1, "x": 2, "y": 5 } ], "type": "custom" }, { "id": "warRoom", "name": "War Room", "type": "warRoom" }, { "id": "workPlan", "name": "Work Plan", "type": "workPlan" }, { "id": "evidenceBoard", "name": "Evidence Board", "type": "evidenceBoard" }, { "id": "relatedIncidents", "name": "Related Incidents", "type": "relatedIncidents" }, { "id": "canvas", "name": "Canvas", "type": "canvas" } ] }, "edit": { "sections": [ { "description": "Trigger the incident based on a phishing email attachment.\n\nPlease fill in:\n1. A name of the incident.\n2. The email address for which you're making the report (optional).\n3. An EML or MSG file representing the phishing email, or containing another EML or MSG file of the phishing email within it.\n\nIf the reporter email address is left blank - user engagement will be skipped in the playbook.", "fields": [ { "fieldId": "incident_name", "isVisible": true }, { "fieldId": "incident_reporteremailaddress", "isVisible": true }, { "fieldId": "incident_attachment", "isVisible": true } ], "isVisible": true, "name": "Add a phishing email", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Optional - details regarding the incident itself (not specific to phishing).", "fields": [ { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_owner", "isVisible": true }, { "fieldId": "incident_type", "isVisible": true }, { "fieldId": "incident_severity", "isVisible": true }, { "fieldId": "incident_playbookid", "isVisible": true }, { "fieldId": "incident_details", "isVisible": true } ], "isVisible": true, "name": "Incident Metadata", "query": null, "queryType": "", "readOnly": false, "type": "" } ] }, "group": "incident", "id": "Phishing Incident v3", "mobile": { "sections": [ { "description": "General information about the incident.", "fields": [ { "fieldId": "incident_type", "isVisible": true }, { "fieldId": "incident_severity", "isVisible": true }, { "fieldId": "incident_owner", "isVisible": true }, { "fieldId": "incident_dbotstatus", "isVisible": true }, { "fieldId": "incident_sourcebrand", "isVisible": true }, { "fieldId": "incident_sourceinstance", "isVisible": true }, { "fieldId": "incident_playbookid", "isVisible": true }, { "fieldId": "incident_phase", "isVisible": true }, { "fieldId": "incident_roles", "isVisible": true } ], "isVisible": true, "name": "Incident Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Information about the phishing email that was received.", "fields": [ { "fieldId": "incident_emailfrom", "isVisible": true }, { "fieldId": "incident_emailto", "isVisible": true }, { "fieldId": "incident_emailcc", "isVisible": true }, { "fieldId": "incident_reporteremailaddress", "isVisible": true }, { "fieldId": "incident_emailsubject", "isVisible": true }, { "fieldId": "incident_emailbody", "isVisible": true }, { "fieldId": "incident_emailhtml", "isVisible": true }, { "fieldId": "incident_emailauthenticitycheck", "isVisible": true }, { "fieldId": "incident_emailinreplyto", "isVisible": true }, { "fieldId": "incident_emailreturnpath", "isVisible": true } ], "isVisible": true, "name": "Email", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Information about file attachments in the phishing email.", "fields": [ { "fieldId": "incident_attachmentname", "isVisible": true }, { "fieldId": "incident_attachmenttype", "isVisible": true }, { "fieldId": "incident_attachmentsize", "isVisible": true } ], "isVisible": true, "name": "Attachments", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Time information about the incident.", "fields": [ { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_dbotcreated", "isVisible": true }, { "fieldId": "incident_dbotduedate", "isVisible": true }, { "fieldId": "incident_dbotmodified", "isVisible": true }, { "fieldId": "incident_dbottotaltime", "isVisible": true }, { "fieldId": "incident_detectionsla", "isVisible": true }, { "fieldId": "incident_remediationsla", "isVisible": true }, { "fieldId": "incident_timetoassignment", "isVisible": true } ], "isVisible": true, "name": "Timeline \u0026 SLA", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_labels", "isVisible": true } ], "isVisible": true, "name": "Labels", "query": null, "queryType": "", "readOnly": true, "type": "labels" } ] }, "name": "Phishing Incident v3", "quickView": { "sections": [ { "description": "Information about the phishing email that was received.", "fields": [ { "fieldId": "incident_emailfrom", "isVisible": true }, { "fieldId": "incident_emailto", "isVisible": true }, { "fieldId": "incident_reporteremailaddress", "isVisible": true }, { "fieldId": "incident_emailsubject", "isVisible": true }, { "fieldId": "incident_emailbody", "isVisible": true }, { "fieldId": "incident_attachmentname", "isVisible": true }, { "fieldId": "incident_attachmenttype", "isVisible": true }, { "fieldId": "incident_attachmentsize", "isVisible": true } ], "isVisible": true, "name": "Email Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_dbotcreated", "isVisible": true }, { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_dbotduedate", "isVisible": true }, { "fieldId": "incident_dbotmodified", "isVisible": true }, { "fieldId": "incident_dbottotaltime", "isVisible": true } ], "isVisible": true, "name": "Timeline Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Information about Service Level Agreements (SLAs).", "fields": [ { "fieldId": "incident_detectionsla", "isVisible": true }, { "fieldId": "incident_remediationsla", "isVisible": true }, { "fieldId": "incident_timetoassignment", "isVisible": true } ], "isVisible": true, "name": "SLA", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_labels", "isVisible": true } ], "isVisible": true, "name": "Labels", "query": null, "queryType": "", "readOnly": true, "type": "labels" } ] }, "system": false, "version": -1, "fromVersion": "6.1.0", "marketplaces": [ "xsoar" ], "description": "" }