Google Threat Intelligence - Add Comment To Incident

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Utility sub-playbook called by GTIURLScanIncidentEnrichment and GTIURLScanEntityEnrichment. Receives the incident ARM ID, a pre-formatted HTML comment (with GTI URL scan assessment table), and the calling playbook name. Fetches the current incident comment count, enforces a 99-comment limit and a 30 000-character-per-comment limit, posts the comment (or a truncation notice / limit-reached warning that references the GTI_URLScan_CL custom table), and returns a structured HTTP response to the call

Attribute Value
Type Playbook
Solution Google Threat Intelligence
Source View on GitHub

Logic App Connectors

This playbook uses 1 Logic App connector / built-in action:

Connector / Action Type Connections Actions
azuresentinel Managed 1 3
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Get_Incident post /Incidents —
Add_Comment post /Incidents/Comment —
Add_Limit_Warning post /Incidents/Comment —

Additional Documentation

📄 Source: GTIAddCommentToIncident/readme.md

Google Threat Intelligence Add Comment To Incident

Summary

This playbook is triggered via HTTP request and is designed to be used as a sub-playbook by other GTI playbooks, such as GTIURLScanIncidentEnrichment and GTIURLScanEntityEnrichment. It receives the incident ARM ID, the raw GTI URL scan response object, the scanned URL, and the calling playbook's name. It fetches the current incident comment count, formats the scan results (verdict, severity, threat score, contributing factors, URL details, and context) into an HTML table, enforces a 99-comment and 30,000-character-per-comment limit, and posts the resulting comment to the Microsoft Sentinel incident.

Prerequisites

  1. This playbook is intended to be called as a sub-playbook by other GTI playbooks.
  2. Ensure the parent playbook(s) (GTIURLScanIncidentEnrichment, GTIURLScanEntityEnrichment, etc.) are deployed and configured.
  3. Ensure you have appropriate permissions to add comments to Microsoft Sentinel incidents.

Deployment Instructions

  1. To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
  2. Fill in the required parameters:
    • PlaybookName: Enter the playbook name here (default: GTIAddCommentToIncident).

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

a. Authorize connections

Once deployment is complete, authorize the Microsoft Sentinel connection.

  1. Go to your logic app → API connections → Select Microsoft Sentinel connection resource.
  2. Go to General → edit API connection.
  3. Click Authorize.
  4. Sign in.
  5. Click Save.

b. Configure Parent Playbooks

Configure the parent GTI playbooks (GTIURLScanIncidentEnrichment, GTIURLScanEntityEnrichment, etc.) to call this sub-playbook using its HTTP trigger URL.

  1. Go to Logic App → your Logic App → Logic app designer.
  2. Copy the HTTP POST URL from the trigger.
  3. Update each parent playbook's "Call comment sub-playbook" action to pass incidentArmId, scanResponse, urlScanned, and playbookName to this URL.

c. Verify Permissions

Ensure the playbook has appropriate permissions to add comments to incidents.

  1. Verify the managed identity has Microsoft Sentinel Responder role or equivalent permissions.
  2. Test the playbook by triggering it from a parent playbook with sample enrichment data.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Google Threat Intelligence