Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
When a high or critical severity mobile threat incident is created in Microsoft Sentinel by Lookout, this playbook enriches the incident with a detailed investigation comment including threat intelligence context, device risk details, and recommended next steps for the analyst.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Lookout |
| Source | View on GitHub |
This playbook uses 1 Logic App connector / built-in action:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 3 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Entities_-_Get_Accounts | post | /entities/account |
— |
| Entities_-_Get_Hosts | post | /entities/host |
— |
| Add_incident_enrichment_comment | post | /Incidents/Comment |
— |
This playbook triggers automatically when Microsoft Sentinel creates an incident from the Lookout - High Severity Mobile Threats Detected (v2) analytic rule. It performs three automated actions:
| Rule | Severity |
|---|---|
| Lookout - High Severity Mobile Threats Detected (v2) | High |
| Lookout - New Threat events found | High |
| Parameter | Required | Description |
|---|---|---|
| PlaybookName | No | Name of the Logic App (default: Lookout-MobileThreat-NotifyAndEnrich) |
| TeamsGroupId | Yes | Microsoft Teams Group (Team) ID for SOC notifications |
| TeamsChannelId | Yes | Microsoft Teams Channel ID for SOC notifications |
Finding your Teams IDs: In Microsoft Teams, right-click the channel → Get link to channel. The URL contains both groupId and the channel ID.
After deployment, navigate to the resource group in the Azure portal and authorize the API connections:
Lookout-MobileThreat-NotifyAndEnrich).Lookout - High Severity Mobile ThreatsLookout-MobileThreat-NotifyAndEnrich| Connection | Auth Method | Permission Required |
|---|---|---|
| Microsoft Sentinel | Managed Identity | Microsoft Sentinel Responder |
| Microsoft Teams | User Account | Channel Post Messages |
| Office 365 | User Account | Send Email |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊