id: ExtraHop - Ticket Tracking version: -1 name: ExtraHop - Ticket Tracking description: Deprecated. Use the "ExtraHop - Ticket Tracking v2" playbook instead.\ \ Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes. starttaskid: "0" hidden: true tasks: "0": id: "0" taskid: 71394f2c-bc76-4885-8bab-b55ce0094789 type: start task: id: 71394f2c-bc76-4885-8bab-b55ce0094789 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "15" separatecontext: false view: |- { "position": { "x": -10, "y": -460 } } note: false timertriggers: [] ignoreworker: false "1": id: "1" taskid: be00a185-8d20-4e46-8012-4ae44b3687fc type: regular task: id: be00a185-8d20-4e46-8012-4ae44b3687fc version: -1 name: Track the incident status in ExtraHop Reveal(x) description: Link the ExtraHop Detection to the corresponding Demisto Investigation. This uses the ExtraHop ticket tracking functionality to properly display ticket status within ExtraHop. script: '|||extrahop-track-ticket' type: regular iscommand: true brand: "" nexttasks: '#none#': - "12" scriptarguments: detection_id: complex: root: foundIncidents accessor: CustomFields.detectionid incident_close_reason: complex: root: foundIncidents accessor: closeReason incident_id: complex: root: foundIncidents accessor: id incident_owner: complex: root: foundIncidents accessor: owner incident_status: complex: root: foundIncidents accessor: status continueonerror: true separatecontext: false view: |- { "position": { "x": 170, "y": 1110 } } note: false timertriggers: [] ignoreworker: false "2": id: "2" taskid: f4953d89-2219-4d74-8acf-d819728d0ac9 type: title task: id: f4953d89-2219-4d74-8acf-d819728d0ac9 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": -100, "y": 1640 } } note: false timertriggers: [] ignoreworker: false "3": id: "3" taskid: 6f9852cc-7a6e-4d2f-8bef-86fb205e5408 type: regular task: id: 6f9852cc-7a6e-4d2f-8bef-86fb205e5408 version: -1 name: Mark the incident as tracked description: Update the incident to reflect the Detection Ticketed status. script: Builtin|||setIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "4" scriptarguments: addLabels: {} affecteddata: {} affecteddatatype: {} affectedindividualscontactinformation: {} app: {} approximatenumberofaffecteddatasubjects: {} assetid: {} attachmentcount: {} attachmentextension: {} attachmenthash: {} attachmentid: {} attachmentname: {} attachmentsize: {} attachmenttype: {} bugtraq: {} city: {} closeNotes: {} closeReason: {} companyaddress: {} companycity: {} companycountry: {} companyhasinsuranceforthebreach: {} companyname: {} companypostalcode: {} contactaddress: {} contactname: {} country: {} countrywherebusinesshasitsmainestablishment: {} countrywherethebreachtookplace: {} customFields: {} cve: {} cvss: {} dataencryptionstatus: {} datetimeofthebreach: {} deleteEmptyField: {} dest: {} destntdomain: {} details: {} detectionendtime: {} detectionid: {} detectionticketed: simple: "true" detectionupdatetime: {} detectionurl: {} dpoemailaddress: {} duration: {} emailaddress: {} emailbcc: {} emailbody: {} emailbodyformat: {} emailbodyhtml: {} emailcc: {} emailclientname: {} emailfrom: {} emailhtml: {} emailinreplyto: {} emailkeywords: {} emailmessageid: {} emailreceived: {} emailreplyto: {} emailreturnpath: {} emailsenderip: {} emailsize: {} emailsource: {} emailsubject: {} emailto: {} emailtocount: {} emailurlclicked: {} extrahopapplianceid: {} extrahophostname: {} filehash: {} filename: {} filepath: {} id: simple: ${ExtraHop.TicketId} isthedatasubjecttodpia: {} labels: {} likelyimpact: {} maliciouscauseifthecauseisamaliciousattack: {} malwarefamily: {} measurestomitigate: {} name: {} occurred: {} owner: {} participants: {} phase: {} possiblecauseofthebreach: {} postalcode: {} rawparticipants: {} replacePlaybook: {} riskscore: {} roles: {} sectorofaffectedparty: {} severity: {} signature: {} sizenumberofemployees: {} sizeturnover: {} sla: {} slaField: {} src: {} srcntdomain: {} srcuser: {} systems: {} telephoneno: {} type: {} user: {} vendorid: {} vendorproduct: {} vulnerabilitycategory: {} whereisdatahosted: {} separatecontext: false view: |- { "position": { "x": 490, "y": 600 } } note: false timertriggers: [] ignoreworker: false "4": id: "4" taskid: 695438ce-bf6a-43e8-8d73-3b314c1ea1e5 type: regular task: id: 695438ce-bf6a-43e8-8d73-3b314c1ea1e5 version: -1 name: Search for any untracked ExtraHop Detections description: Searches Demisto incidents for any ExtraHop Detections that are untracked. scriptName: SearchIncidentsV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "10" scriptarguments: details: {} fromclosedate: {} fromdate: {} fromduedate: {} id: {} level: {} name: {} notstatus: {} owner: {} page: {} query: simple: type:"ExtraHop Detection" and incident.detectionticketed:F and incident.created:>="1 day ago" reason: {} size: {} sort: {} status: {} toclosedate: {} todate: {} toduedate: {} type: {} separatecontext: false view: |- { "position": { "x": 170, "y": 770 } } note: false timertriggers: [] ignoreworker: false "6": id: "6" taskid: 75eb04ec-c770-4120-8d70-56513ce2201b type: regular task: id: 75eb04ec-c770-4120-8d70-56513ce2201b version: -1 name: Mark the incident as tracked description: Update the incident to reflect the Detection Ticketed status. script: Builtin|||setIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "2" scriptarguments: addLabels: {} affecteddata: {} affecteddatatype: {} affectedindividualscontactinformation: {} app: {} approximatenumberofaffecteddatasubjects: {} assetid: {} attachmentcount: {} attachmentextension: {} attachmenthash: {} attachmentid: {} attachmentname: {} attachmentsize: {} attachmenttype: {} bugtraq: {} city: {} closeNotes: {} closeReason: {} companyaddress: {} companycity: {} companycountry: {} companyhasinsuranceforthebreach: {} companyname: {} companypostalcode: {} contactaddress: {} contactname: {} country: {} countrywherebusinesshasitsmainestablishment: {} countrywherethebreachtookplace: {} customFields: {} cve: {} cvss: {} dataencryptionstatus: {} datetimeofthebreach: {} deleteEmptyField: {} dest: {} destntdomain: {} details: {} detectionendtime: {} detectionid: {} detectionticketed: simple: "true" detectionupdatetime: {} detectionurl: {} dpoemailaddress: {} duration: {} emailaddress: {} emailbcc: {} emailbody: {} emailbodyformat: {} emailbodyhtml: {} emailcc: {} emailclientname: {} emailfrom: {} emailhtml: {} emailinreplyto: {} emailkeywords: {} emailmessageid: {} emailreceived: {} emailreplyto: {} emailreturnpath: {} emailsenderip: {} emailsize: {} emailsource: {} emailsubject: {} emailto: {} emailtocount: {} emailurlclicked: {} extrahopapplianceid: {} extrahophostname: {} filehash: {} filename: {} filepath: {} id: simple: ${ExtraHop.TicketId} isthedatasubjecttodpia: {} labels: {} likelyimpact: {} maliciouscauseifthecauseisamaliciousattack: {} malwarefamily: {} measurestomitigate: {} name: {} occurred: {} owner: {} participants: {} phase: {} possiblecauseofthebreach: {} postalcode: {} rawparticipants: {} replacePlaybook: {} riskscore: {} roles: {} sectorofaffectedparty: {} severity: {} signature: {} sizenumberofemployees: {} sizeturnover: {} sla: {} slaField: {} src: {} srcntdomain: {} srcuser: {} systems: {} telephoneno: {} type: {} user: {} vendorid: {} vendorproduct: {} vulnerabilitycategory: {} whereisdatahosted: {} separatecontext: false view: |- { "position": { "x": 170, "y": 1465 } } note: false timertriggers: [] ignoreworker: false "7": id: "7" taskid: 50b89e52-0733-477b-8929-8b595f704ca4 type: regular task: id: 50b89e52-0733-477b-8929-8b595f704ca4 version: -1 name: Track the incident status in ExtraHop Reveal(x) description: Link the ExtraHop Detection to the corresponding Demisto Investigation. This uses the ExtraHop ticket tracking functionality to properly display ticket status within ExtraHop. script: '|||extrahop-track-ticket' type: regular iscommand: true brand: "" nexttasks: '#none#': - "11" scriptarguments: detection_id: simple: ${incident.detectionid} incident_close_reason: simple: ${incident.closeReason} incident_id: simple: ${incident.id} incident_owner: simple: ${incident.owner} incident_status: simple: ${incident.status} continueonerror: true separatecontext: false view: |- { "position": { "x": 490, "y": 230 } } note: false timertriggers: [] ignoreworker: false "9": id: "9" taskid: 40271f8c-840d-4e71-86c5-57a28bc24aea type: condition task: id: 40271f8c-840d-4e71-86c5-57a28bc24aea version: -1 name: Are the required fields present? description: Checks if the required detection and incident IDs are present. type: condition iscommand: false brand: "" nexttasks: '#default#': - "4" "yes": - "7" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: incident.id iscontext: true - - operator: isNotEmpty left: value: simple: incident.detectionid iscontext: true view: |- { "position": { "x": 170, "y": 50 } } note: false timertriggers: [] ignoreworker: false "10": id: "10" taskid: 76071ff8-9c4d-494d-8b73-aa4368199fb5 type: condition task: id: 76071ff8-9c4d-494d-8b73-aa4368199fb5 version: -1 name: Were there any incidents found? description: Checks if there were any untracked ExtraHop Detections found. type: condition iscommand: false brand: "" nexttasks: '#default#': - "2" "yes": - "1" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: foundIncidents.id iscontext: true view: |- { "position": { "x": 170, "y": 930 } } note: false timertriggers: [] ignoreworker: false "11": id: "11" taskid: e553a569-662c-460e-87f0-f69efaf2901a type: condition task: id: e553a569-662c-460e-87f0-f69efaf2901a version: -1 name: Was the incident successfully tracked? description: Check if the ticket tracking was successful. type: condition iscommand: false brand: "" nexttasks: '#default#': - "4" "yes": - "3" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: ExtraHop.TicketId iscontext: true view: |- { "position": { "x": 490, "y": 390 } } note: false timertriggers: [] ignoreworker: false "12": id: "12" taskid: 624c3b07-31d8-45ca-8f6f-332974515fef type: condition task: id: 624c3b07-31d8-45ca-8f6f-332974515fef version: -1 name: Was the incident successfully tracked? description: Check if the ticket tracking was successful. type: condition iscommand: false brand: "" nexttasks: '#default#': - "2" "yes": - "6" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: ExtraHop.TicketId iscontext: true view: |- { "position": { "x": 170, "y": 1275 } } note: false timertriggers: [] ignoreworker: false "13": id: "13" taskid: 1619242b-d813-4dfb-8801-cd45a61906f3 type: regular task: id: 1619242b-d813-4dfb-8801-cd45a61906f3 version: -1 name: Assign an ExtraHop analyst to the incident description: Assign an analyst randomly from the pool of users with the ExtraHop role. scriptName: AssignAnalystToIncident type: regular iscommand: false brand: "" nexttasks: '#none#': - "9" scriptarguments: assignBy: {} email: {} onCall: complex: root: inputs.OnCall roles: simple: ExtraHop username: {} continueonerror: true separatecontext: false view: |- { "position": { "x": 170, "y": -110 } } note: false timertriggers: [] ignoreworker: false "15": id: "15" taskid: dffb9228-cc49-4adf-88f5-13001f85ba70 type: condition task: id: dffb9228-cc49-4adf-88f5-13001f85ba70 version: -1 name: Is ExtraHop Reveal(x) enabled? description: Checks if there is an active instance of the ExtraHop Reveal(x) integration enabled. scriptName: Exists type: condition iscommand: false brand: "" nexttasks: '#default#': - "2" "yes": - "13" scriptarguments: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: brand iscontext: true right: value: simple: ExtraHop v2 - - operator: isEqualString left: value: simple: state iscontext: true right: value: simple: active separatecontext: false view: |- { "position": { "x": -10, "y": -320 } } note: false timertriggers: [] ignoreworker: false view: |- { "linkLabelsPosition": { "10_1_yes": 0.42, "10_2_#default#": 0.2, "11_3_yes": 0.49, "11_4_#default#": 0.45, "12_2_#default#": 0.31, "12_6_yes": 0.47, "15_13_yes": 0.55, "15_2_#default#": 0.1, "9_4_#default#": 0.31, "9_7_yes": 0.44 }, "paper": { "dimensions": { "height": 2165, "width": 970, "x": -100, "y": -460 } } } inputs: - key: OnCall value: simple: "false" required: false description: Set to true to assign only user that is currently on shift. Requires Cortex XSOAR v5.5 or later. outputs: [] fromversion: 5.0.0 tests: - No test - Deprecated playbook deprecated: true