Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook takes a host from a Microsoft Sentinel incident and adds it to protection. The playbook is configured to add the machine to protection(learning). If you want to have it go straight to protection, remove the protectAt property in the action.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | ZeroNetworks |
| Source | View on GitHub |
📄 Source: ZeroNetworksSegment-AddAssettoProtection/readme.md
This playbook takes a host from a Microsoft Sentinel incident and adds it to protection. The playbook is configured to add the machine to protection(learning). If you want to have it go straight to protection, remove the protectAt property in the action.
When a new Microsoft Sentinel incident is created, this playbook gets triggered and performs below actions 1. For the hosts in the incident, each host is added to protection (learning). 2. A comment is added to Microsoft Sentinel incident.
Playbook overview:

Once deployment is complete, you will need to authorize each connection. 1. Click the Microsoft Sentinel connection resource 2. Click edit API connection 3. Click Authorize 4. Sign in 5. Click Save 6. Repeat steps for other connections such as Zero Networks
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊