SpyCloud Breach Information - SpyCloud Enterprise

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This Playbook will be triggered when an spycloud breach incident is created.

Attribute Value
Type Playbook
Solution SpyCloud Enterprise Protection
Source View on GitHub

Logic App Connectors

This playbook uses 1 Logic App connector / built-in action:

Connector / Action Type Connections Actions
azuresentinel Managed 1 2
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_Accounts post /entities/account
Add_comment_to_incident_(V3) post /Incidents/Comment

Additional Documentation

📄 Source: SpyCloud-Breach-Playbook/readme.md

SpyCloud Enterprise Breach Playbook

SpyCloud Enterprise

Table of Contents

  1. Overview
  2. Prerequisites
  3. Deployment
  4. Post Deployment Steps

Overview

This playbook gets triggered when an incident is created from the "SpyCloud Breach Rule" and can perform the following actions

Prerequisites

Deployment Instructions

Deploy to Azure Deploy to Azure Gov

Post Deployment Instructions

Authorize connections

Once deployment is complete, you will need to authorize each connection:

b.Configurations in Sentinel:


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to SpyCloud Enterprise Protection