SlashNext Phishing Incident Investigation Playbook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Enhance your security with threat hunting and incident investigation using this playbook. Scan with world’s largest, real-time phishing intelligence database for accurate, definitive binary verdicts on suspicious URLs and download phishing forensics including webpage screenshots, HTML and text. The playbook shall perform the analysis of all URL entities attached to an existing incident using SlashNext Logic Apps Connector and add threat information to each malicious incident.

Attribute Value
Type Playbook
Solution SlashNext
Source View on GitHub

Additional Documentation

📄 Source: SlashNextPhishingIncidentInvestigation/readme.md

drawing

Overview

Enhance your security with threat hunting and incident investigation using this playbook. Scan with world’s largest, real-time phishing intelligence database for accurate, definitive binary verdicts on suspicious URLs and download phishing forensics including webpage screenshots, HTML and text. The playbook shall perform the analysis of all URL entities attached to an existing incident using SlashNext Logic Apps Connector and add threat information to each malicious incident.

SlashNext Phishing Incident Investigation Playbook

Prerequisites

SlashNext Logic Apps Connector supports Basic authentication, while creating connection you will be asked to provide API key. To acquire SlashNext API key, please contact us at support@slashnext.com or visit SlashNext.com

Deployment Instructions

Deploy with Incident Trigger (recommended) - After deployment, attach this playbook to an automation rule so it runs when the incident is created.

Learn more about automation rules

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

a. Authorize Connection

Once deployment is complete, authorize SlashNext Logic Apps Connector connection.

  1. Click on the SlashNext connection resource
  2. Click Edit API connection
  3. Enter API key acquired from SlashNext
  4. Click Save

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Playbooks · Back to SlashNext