Enrich Incidents - ShadowByte Aria

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook updates the Incident with the brach details if an account has been compromised.

Attribute Value
Type Playbook
Solution ShadowByte Aria
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 2
ShadowByteAriaConnector Custom 1 1
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Add_comment_to_incident_(V3) post /Incidents/Comment
Entities_-_Get_Accounts post /entities/account

ShadowByteAriaConnector (Custom)

Action Method Endpoint Other
Breach_Search get /v2/breach/search

Additional Documentation

📄 Source: ShadowByte_Aria_Enrich_Incidents/readme.md

Author: ShadowByte

This playbook updates the Incident with the brach details if an account has been compromised.

prerequisites

screenshots:

screenshot1

deploy to Azure


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to ShadowByte Aria