Incident tasks - Microsoft Defender XDR BEC Playbook for SecOps

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook add Incident Tasks based on Microsoft Defender XDR BEC Playbook for SecOps. This playbook will walk the analyst through four stages of responding to a BEC incident: containment, investigation, remediation and prevention. The step-by-step instructions will help you take the required remedial action to protect information and minimize further risks.

Attribute Value
Type Playbook
Solution SentinelSOARessentials
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 0
microsoftsentinel Managed 0 9
Action parameters (URLs, paths, function IDs)

microsoftsentinel (Managed)

Action Method Endpoint Other
Add_task_to_incident_-_Contain post /Incidents/CreateTask —
Add_task_to_incident_-_Introduction post /Incidents/CreateTask —
Mark_a_task_as_completed_-_Introduction post /Incidents/CompleteTask —
Add_task_to_incident_-Investigation-_Step_1 post /Incidents/CreateTask —
Add_task_to_incident_-Investigation-_Step_2 post /Incidents/CreateTask —
Add_task_to_incident_-Investigation-_Step_3 post /Incidents/CreateTask —
Add_task_to_incident_-Investigation-_Step_4 post /Incidents/CreateTask —
Add_task_to_incident_-_Prevention post /Incidents/CreateTask —
Add_task_to_incident_-_Remediation post /Incidents/CreateTask —

Additional Documentation

📄 Source: Defender_XDR_BEC_Playbook_for_SecOps-Tasks/readme.md

Defender_XDR_BEC_Playbook_for_SecOps-Tasks

author: Benji Kovacevic

This playbook add Incident Tasks based on Microsoft Defender XDR BEC Playbook for SecOps. This playbook will walk the analyst through four stages of responding to a BEC incident: containment, investigation, remediation and prevention. The step-by-step instructions will help you take the required remedial action to protect information and minimize further risks.

Quick Deployment

Deploy to Azure Deploy to Azure Gov

Post-deployment

  1. Assign Microsoft Sentinel Responder role to the managed identity. To do so, choose Identity blade under Settings of the Logic App.
  2. Assign playbook to the automation rule. - https://learn.microsoft.com/azure/sentinel/tutorial-respond-threats-playbook?tabs=LAC
    Conditions
    Incident provider > Equals > Microsoft Defender XDR
    SentinelIncident

Playbook will run if the alert has any of these keywords:

1. BEC

Screenshots

Playbook
playbook screenshot

Microsoft Sentinel Incident Tasks
SentinelIncident


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to SentinelSOARessentials