Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook allows blocking an IP outbound from protected assets in Zero Networks Segment.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | ZeroNetworks |
| Source | View on GitHub |
📄 Source: ZeroNetworksSegment-AddBlockOutboundRule/readme.md
This playbook allows blocking an IP outbound from protected assets in Zero Networks Segment.
When a new Sentinel incident is created, this playbook gets triggered and performs below actions 1. For the IPs, we add them to a new outbound block rule in Segment. 2. A comment is added to Microsoft Sentinel incident.
Playbook overview:

Once deployment is complete, you will need to authorize each connection. 1. Click the Microsoft Sentinel connection resource 2. Click edit API connection 3. Click Authorize 4. Sign in 5. Click Save 6. Repeat steps for other connections such as Zero Networks
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊