Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook add Incident Tasks based on Microsoft Defender XDR BEC Playbook for SecOps. This playbook will walk the analyst through four stages of responding to a BEC incident: containment, investigation, remediation and prevention. The step-by-step instructions will help you take the required remedial action to protect information and minimize further risks.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | SentinelSOARessentials |
| Source | View on GitHub |
This playbook uses 2 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 0 |
microsoftsentinel |
Managed | 0 | 9 |
microsoftsentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Add_task_to_incident_-_Contain | post | /Incidents/CreateTask |
— |
| Add_task_to_incident_-_Introduction | post | /Incidents/CreateTask |
— |
| Mark_a_task_as_completed_-_Introduction | post | /Incidents/CompleteTask |
— |
| Add_task_to_incident_-Investigation-_Step_1 | post | /Incidents/CreateTask |
— |
| Add_task_to_incident_-Investigation-_Step_2 | post | /Incidents/CreateTask |
— |
| Add_task_to_incident_-Investigation-_Step_3 | post | /Incidents/CreateTask |
— |
| Add_task_to_incident_-Investigation-_Step_4 | post | /Incidents/CreateTask |
— |
| Add_task_to_incident_-_Prevention | post | /Incidents/CreateTask |
— |
| Add_task_to_incident_-_Remediation | post | /Incidents/CreateTask |
— |
📄 Source: Defender_XDR_BEC_Playbook_for_SecOps-Tasks/readme.md
author: Benji Kovacevic
This playbook add Incident Tasks based on Microsoft Defender XDR BEC Playbook for SecOps. This playbook will walk the analyst through four stages of responding to a BEC incident: containment, investigation, remediation and prevention. The step-by-step instructions will help you take the required remedial action to protect information and minimize further risks.

1. BEC
Playbook

Microsoft Sentinel Incident Tasks

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊