import demistomock as demisto # noqa: F401
from CommonServerPython import * # noqa: F401
incidentflowdata = """
Incident Playbooks (Ingestion)
- Cortex XDR Incident
- Prisma Saas Alert
- Prisma Cloud Alert
- Okta Alert
\
- WinEvent Alert
- Linux Alert
- Proofpoint Alert
- G-Suite Alert
\
- GCP Alert
- Support Requests
- NGFW Alert
- Abuse Reports
\
- Onboarding/Offboarding
- Expanse Alert
- Monitoring Alert
- Password Spray \
Alert
\
Analysis Playbooks (Enrichment)
- Upon \
Trigger
- Calculate Severity
- Start SLA Timers
- Notification
- Gather Details
- User \
Enrichment
- Host Enrichment
- URL Enrichment
- Domain Enrichment
- Email Address Enrichment
- File Enrichment
- IP Enrichment
- Related email \
search
- Related log search
- Forensic capture
- Kill sessions
- Ask user a question
\
Containment Subplaybooks (Analyst/User \
Actions)
- Lock AD user account
- Lock AD service account
- EDL Block (IP/Domain/URL)
- PAN-DB re-categorization
- Block email sender
- Quarantine email
- Quarantine \
files
- Quarantine device
- Disable project
\
Eradication Playbooks
- Re-image request
- Password Reset
- Search and destroy
- External website takedown
- Revoke physical badge access
\
Post-Incident Metrics
- Metrics incl. effort
- Lessons Learned
- Timeline
"""
demisto.executeCommand("createList", {"listName": "XSOARIncidentFlow", "listData": incidentflowdata})