|
ASM
|
Cortex ASM - ASM Alert
|
1 |
Cortex Attack Surface Management
|
6.10.0 |
|
AWS CloudTrail Misconfiguration
|
Prisma Cloud Remediation - AWS CloudTrail Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
AWS EC2 Instance Misconfiguration
|
Prisma Cloud Remediation - AWS EC2 Instance Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
AWS IAM Policy Misconfiguration
|
Prisma Cloud Remediation - AWS IAM Policy Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
Alibaba ActionTrail - Multiple Unauthorized Action Attempts Detected By a User Alerts
|
Alibaba ActionTrail - multiple unauthorized action_attempts detected by a user
|
1 |
Alibaba Action Trail
|
|
|
Allow Access by Trusted Services
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Assign Managed Identity to Function App
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Assign Managed Identity to Web App
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Azure AKS Misconfiguration
|
Prisma Cloud Remediation - Azure AKS Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
Azure Network Misconfiguration
|
Prisma Cloud Remediation - Azure Network Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
Azure SQL Misconfiguration
|
Prisma Cloud Remediation - Azure SQL Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
Azure Storage Misconfiguration
|
Prisma Cloud Remediation - Azure Storage Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
Cloud Data Exfiltration
|
Cloud Data Exfiltration Response
|
1 |
Cloud Incident Response
|
|
|
Cloud IAM User Access Investigation
|
Cloud IAM User Access Investigation
|
0 |
Cloud Incident Response
|
|
|
Cloud Token Theft
|
Cloud Token Theft Response
|
0 |
Cloud Incident Response
|
|
|
Cortex Exposure Management
|
Cortex VM - Vulnerability Issue
|
4 |
Cortex Vulnerability Management
|
6.10.0 |
|
Cortex Exposure Management AWS Virtual Machine Remediation
|
Cortex EM - AWS VM Exposure Remediation
|
5 |
Cortex Exposure Management
|
6.10.0 |
|
Cortex Exposure Management Azure Virtual Machine Remediation
|
Cortex EM - Azure VM Exposure Remediation
|
5 |
Cortex Exposure Management
|
6.10.0 |
|
Cortex Exposure Management Enrichment
|
Cortex EM - Exposure Issue
|
5 |
Cortex Exposure Management
|
6.10.0 |
|
Cortex Exposure Management GCP Virtual Machine Remediation
|
Cortex EM - GCP VM Exposure Remediation
|
5 |
Cortex Exposure Management
|
6.10.0 |
|
Disable Network Access to Storage Account
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Disable Public & Private Access to VM Disk
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Disable Public Access on RDS
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Disable Remote Debugging on Azure App
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Disable Storage Account Cross Tenant Replication
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
DropBox - Massive Scale Operations on Files Response
|
DropBox - Massive scale operations on files
|
0 |
Dropbox
|
|
|
Enable Automatic Backup for RDS dB
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable Azure App Service Auth
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable CloudTrail Log Validation
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable CloudTrail Logging
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable Copy Tags on RDS Snapshot
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable Deletion Protection on RDS
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable GCP Bucket Versioning
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable GKE Cluster Intra-node Visibility
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable IAM Authentication on RDS
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable IAM Authentication on RDS Cluster
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable Master Authorized Networks on GKE
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable RDS Auto Upgrade
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable RDS Cluster Deletion Protection
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable S3 Versioning
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Enable Soft Delete on Blob
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
GCP Compute Engine Misconfiguration
|
Prisma Cloud Remediation - GCP Compute Engine Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
GCP Kubernetes Engine Misconfiguration
|
Prisma Cloud Remediation - GCP Kubernetes Engine Misconfiguration v2
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
IOC Alert
|
IOC Alert
|
1 |
Core
|
|
|
Identity Analytics Alerts
|
Identity Analytics - Alert Handling
|
1 |
Core
|
6.10.0 |
|
Impossible Traveler
|
Impossible Traveler Response
|
1 |
Core
|
|
|
Large Upload Alert
|
Large Upload Alert
|
2 |
Core
|
6.10.0 |
|
Make GCP Bucket Private
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Malware detected by Microsoft Defender for Endpoint
|
Microsoft Defender for Endpoint - Malware Detected
|
2 |
Microsoft Defender for Endpoint
|
|
|
NGFW Scanning Alerts
|
NGFW Scan
|
2 |
Core
|
|
|
Phishing Playbook Trigger
|
Phishing - Generic v3
|
1 |
Phishing
|
|
|
Possible External RDP Brute-Force
|
Possible External RDP Brute-Force
|
1 |
Core
|
|
|
Prisma Cloud - VM Alert Prioritization
|
Prisma Cloud - VM Alert Prioritization
|
1 |
Prisma Cloud by Palo Alto Networks
|
|
|
Prisma Cloud Compute - Audit Alert v3 Trigger
|
Prisma Cloud Compute - Audit Alert v3
|
1 |
Prisma Cloud Compute by Palo Alto Networks
|
6.10.0 |
|
Prisma Cloud Compute - Compliance Alert v2 Trigger
|
Prisma Cloud Compute - Compliance Alert v2
|
1 |
Prisma Cloud Compute by Palo Alto Networks
|
6.10.0 |
|
Prisma Cloud Network API and Anomaly alerts
|
Prisma Cloud - Network API and Anomaly Incidents
|
2 |
Prisma Cloud by Palo Alto Networks
|
6.10.0 |
|
Ransomware Response
|
Ransomware Response
|
0 |
Core
|
|
|
Remediation playbook for AWS EC2 misconfigurations
|
AWS EC2 Instance Misconfiguration - Remediate and Notify
|
1 |
Cloud Security Posture Management Playbooks
|
|
|
Remediation playbook for AWS IAM Password Policy Misconfiguration
|
AWS IAM Password Policies Misconfiguration - Remediate and Notify
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Remediation playbook for AWS S3 Bucket Publicly accessible
|
AWS S3 Bucket Publicly Accessible - Remediate and Notify
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Remote PsExec with LOLBIN command execution alert
|
Remote PsExec with LOLBIN command execution alert
|
1 |
Core
|
6.10.0 |
|
Remove GCP Bucket AllAuthenticatedUser Access
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Remove GCP Bucket AllUsers Access
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set AMI to Private
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Function App HTTP Version to 2.0
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Function App Min TLS Version
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set GCP Bucket Access to Uniform
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set RDS Cluster Snapshot to Private
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set RDS Snapshot to Private
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Secure Transport for MySQL
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Snapshot to Private
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Storage Account to HTTPS only
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Web App Min TLS Version
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Set Webapp HTTP Version to 2.0
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
T1036 - Masquerading
|
T1036 - Masquerading
|
0 |
Core
|
|
|
T1059 - Command and Scripting Interpreter
|
T1059 - Command and Scripting Interpreter
|
0 |
Core
|
|
|
Trigger - AWS Network Exposure
|
AWS Network Exposure - Auto-remediate
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Trigger - AWS Public Access Misconfiguration
|
AWS Public Access Misconfiguration - Auto-remediate
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Trigger - Azure Network Exposure
|
Azure Network Exposure - Auto-remediate
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Trigger - Azure Public Access Misconfiguration
|
Azure Public Access Misconfiguration - Auto-remediate
|
0 |
Cloud Security Posture Management Playbooks
|
8.11.0 |
|
Trigger - GCP Network Exposure
|
GCP Network Exposure - Auto-remediate
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
Trigger - GCP Public Access Misconfiguration
|
GCP Public Access Misconfiguration - Auto-remediate
|
0 |
Cloud Security Posture Management Playbooks
|
8.11.0 |
|
Update Azure Monitor Log Retention Period
|
—
|
0 |
Cloud Security Posture Management Playbooks
|
|
|
WildFire and Wildfire Post detection
|
WildFire Malware
|
1 |
Core
|
|
|
XCloud Cryptojacking
|
XCloud Cryptojacking
|
1 |
Cloud Incident Response
|
|