SpyCloud Malware Information - SpyCloud Enterprise

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This Playbook will be triggered when an spycloud malware incident is created.

Attribute Value
Type Playbook
Solution SpyCloud Enterprise Protection
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 3
spycloud-enterprise-connector Managed 0 1
SpyCloud-Enterprise-Protection Custom 1 0
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_Hosts post /entities/host
Add_comment_to_incident_(V3) post /Incidents/Comment
Update_incident put /Incidents

spycloud-enterprise-connector (Managed)

Action Method Endpoint Other
Get_Compass_Devices_Data get /compass/data/devices/@{encodeURIComponent(variables('infected_machine_id'))}

Additional Documentation

📄 Source: SpyCloud-Malware-Playbook/readme.md

SpyCloud Enterprise Malware Playbook

SpyCloud Enterprise

Table of Contents

  1. Overview
  2. Prerequisites
  3. Deployment
  4. Post Deployment Steps

Overview

This playbook gets triggered when an incident is created from the "SpyCloud Malware Rule" and can perform the following actions

Incident Comments

Prerequisites

Deployment Instructions

Deploy to Azure Deploy to Azure Gov

Post Deployment Instructions

Authorize connections

Once deployment is complete, you will need to authorize each connection:

b.Configurations in Sentinel:


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to SpyCloud Enterprise Protection