Incident tasks - Microsoft Defender XDR BEC Playbook for SecOps

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook add Incident Tasks based on Microsoft Defender XDR BEC Playbook for SecOps. This playbook will walk the analyst through four stages of responding to a BEC incident: containment, investigation, remediation and prevention. The step-by-step instructions will help you take the required remedial action to protect information and minimize further risks.

Attribute Value
Type Playbook
Solution SentinelSOARessentials
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 0
microsoftsentinel Managed 0 9
Action parameters (URLs, paths, function IDs)

microsoftsentinel (Managed)

Action Method Endpoint Other
Add_task_to_incident_-_Contain post /Incidents/CreateTask
Add_task_to_incident_-_Introduction post /Incidents/CreateTask
Mark_a_task_as_completed_-_Introduction post /Incidents/CompleteTask
Add_task_to_incident_-Investigation-_Step_1 post /Incidents/CreateTask
Add_task_to_incident_-Investigation-_Step_2 post /Incidents/CreateTask
Add_task_to_incident_-Investigation-_Step_3 post /Incidents/CreateTask
Add_task_to_incident_-Investigation-_Step_4 post /Incidents/CreateTask
Add_task_to_incident_-_Prevention post /Incidents/CreateTask
Add_task_to_incident_-_Remediation post /Incidents/CreateTask

Additional Documentation

📄 Source: Defender_XDR_BEC_Playbook_for_SecOps-Tasks/readme.md

Defender_XDR_BEC_Playbook_for_SecOps-Tasks

author: Benji Kovacevic

This playbook add Incident Tasks based on Microsoft Defender XDR BEC Playbook for SecOps. This playbook will walk the analyst through four stages of responding to a BEC incident: containment, investigation, remediation and prevention. The step-by-step instructions will help you take the required remedial action to protect information and minimize further risks.

Quick Deployment

Deploy to Azure Deploy to Azure Gov

Post-deployment

  1. Assign Microsoft Sentinel Responder role to the managed identity. To do so, choose Identity blade under Settings of the Logic App.
  2. Assign playbook to the automation rule. - https://learn.microsoft.com/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC
    Conditions
    Incident provider > Equals > Microsoft Defender XDR
    SentinelIncident

Playbook will run if the alert has any of these keywords:

1. BEC

Screenshots

Playbook
playbook screenshot

Microsoft Sentinel Incident Tasks
SentinelIncident


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to SentinelSOARessentials