Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will be triggered when any automation rule is attached or manually invoked. This will fetch associated IPs, Host(Domains) and SHAs from incident and make associated API calls to retrieve Censys data and enrich incident with additional information as Incident comment.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Censys |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CensysCertificate_CL 🔶 |
? | ✓ | ? |
CensysHost_CL 🔶 |
? | ✓ | ? |
CensysWebProperty_CL 🔶 |
? | ✓ | ? |
This playbook uses 6 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azureloganalyticsdatacollector |
Managed | 1 | 3 |
azuresentinel |
Managed | 1 | 0 |
keyvault |
Managed | 1 | 0 |
keyvault-1 |
Managed | 0 | 1 |
http |
Built-in | 0 | 3 |
workflow |
Built-in | 0 | 1 |
azureloganalyticsdatacollector (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Ingest_Censys_Host_Data | post | /api/logs |
— |
| Ingest_Censys_Certificate_Data | post | /api/logs |
— |
| Ingest_Censys_Web_Property_Data | post | /api/logs |
— |
keyvault-1 (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Censys_API_Token | get | /secrets/@{encodeURIComponent('Censys-Access-Token')}/value |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| HTTP_Call_to_Fetch_Host_Data | POST | @{variables('base_url')}/@{variables('api_version')}/global/asset/host |
— |
| HTTP_Call_to_Fetch_Certificates_Data | POST | @{variables('base_url')}/@{variables('api_version')}/global/asset/certificate |
— |
| HTTP_Call_to_Fetch_WebProperty_Data | POST | @{variables('base_url')}/@{variables('api_version')}/global/asset/webproperty |
— |
workflow (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| CensysIncidentEnrichment | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/',resourceGroup().name,'/providers/Microsoft.Logic/workflows/',trim(parameters('IncidentEnrichmentPlaybookName')))]triggerName= When_an_HTTP_request_is_received |
📄 Source: CensysIncidentEnrichment/readme.md
This playbook will be triggered when any automation rule is attached or manually invoked. This will fetch associated IPs, Host(Domains) and SHAs from incident and make associated API calls to retrieve Censys data and enrich incident with additional information as Incident comment.
Once deployment is complete, authorize each connection.
Add access policy for the playbook's managed identity to read secrets from Key Vault.
Assign Microsoft Sentinel Responder role to the playbook's managed identity.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊