SOCRadar-Alarm-Sync

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Syncs closed incidents from Microsoft Sentinel back to SOCRadar platform. Uses Synced tag to prevent duplicate syncs. Filters by: SOCRadar tag + Closed status + lastModified. Now with pagination for 1000+ incidents.

Attribute Value
Type Playbook
Solution SOCRadar
Source View on GitHub

Additional Documentation

📄 Source: SOCRadar-Alarm-Sync/readme.md

SOCRadar Alarm Sync

Syncs closed Microsoft Sentinel incidents back to SOCRadar with classification mapping.

Features

Classification Mapping

Microsoft Sentinel Classification SOCRadar Status
FalsePositive FALSE_POSITIVE
BenignPositive MITIGATED
TruePositive RESOLVED
Undetermined RESOLVED

Deployment

Deploy to Azure

You can also install this playbook via Microsoft Sentinel Content Hub.

Prerequisites


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to SOCRadar