JoeSandbox URL Analyis

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Submits a url or set of urls associated with an incident to JoeSandbox for Analyis.

Attribute Value
Type Playbook
Solution JoeSandbox
Source View on GitHub

Additional Documentation

📄 Source: JoeSandbox-Submit-Url-Sentinel-Incident/readme.md

JoeSandbox URL Analysis Playbook

Table of Contents

  1. Overview
  2. Deploy Playbook
  3. Authentication
  4. Prerequisites
  5. Deployment
  6. Post Deployment Steps

Overview

When a new Azure Sentinel Incident is created, this playbook gets triggered and performs the following actions:

Incident Comments

Deploy to Azure Deploy to Azure

url_playbook

Fields Description
Subscription Select the appropriate Azure Subscription
Resource Group Select the appropriate Resource Group
Region Based on Resource Group this will be uto populated
Playbook Name Please provide a playbook name, if needed
Workspace ID Please provide Log Analytics Workspace ID
Function App Name Please provide the JoeSandbox enrichment function app name

Authentication

Authentication methods this connector supports: - API Key authentication

Prerequisites for using and deploying playbook

Deployment instructions

Post-Deployment instructions.

b. Configurations in Sentinel:


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to JoeSandbox