Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Utility sub-playbook called by GTIURLScanIncidentEnrichment and GTIURLScanEntityEnrichment. Receives the incident ARM ID, a pre-formatted HTML comment (with GTI URL scan assessment table), and the calling playbook name. Fetches the current incident comment count, enforces a 99-comment limit and a 30 000-character-per-comment limit, posts the comment (or a truncation notice / limit-reached warning that references the GTI_URLScan_CL custom table), and returns a structured HTTP response to the call
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 1 Logic App connector / built-in action:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 3 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Incident | post | /Incidents |
— |
| Add_Comment | post | /Incidents/Comment |
— |
| Add_Limit_Warning | post | /Incidents/Comment |
— |
📄 Source: GTIAddCommentToIncident/readme.md
This playbook is triggered via HTTP request and is designed to be used as a sub-playbook by other GTI playbooks, such as GTIURLScanIncidentEnrichment and GTIURLScanEntityEnrichment. It receives the incident ARM ID, the raw GTI URL scan response object, the scanned URL, and the calling playbook's name. It fetches the current incident comment count, formats the scan results (verdict, severity, threat score, contributing factors, URL details, and context) into an HTML table, enforces a 99-comment and 30,000-character-per-comment limit, and posts the resulting comment to the Microsoft Sentinel incident.
Once deployment is complete, authorize the Microsoft Sentinel connection.
Configure the parent GTI playbooks (GTIURLScanIncidentEnrichment, GTIURLScanEntityEnrichment, etc.) to call this sub-playbook using its HTTP trigger URL.
incidentArmId, scanResponse, urlScanned, and playbookName to this URL.Ensure the playbook has appropriate permissions to add comments to incidents.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊