| [[Deprecated]] Add Dynatrace Application Security Attack Source IP Address to Threat Intelligence |
Dynatrace |
1 |
1 |
| [Deprecated] Intel 471 Malware Intelligence to Graph Security |
Intel471 |
1 |
2 |
| Add URL - Netskope |
๐ Standalone |
1 |
1 |
| Armis Update Alert Status |
Armis |
1 |
1 |
| AS-Add-Domains-to-Zscaler-URL-Category |
๐ Standalone |
1 |
2 |
| AS-Add-Machine-Logon-Users-to-Incident |
๐ Standalone |
1 |
1 |
| AS-Blob-Storage-Add-Domains-to-Zscaler-URL-Category |
๐ Standalone |
1 |
2 |
| AS-Block-GitHub-User |
๐ Standalone |
1 |
1 |
| AS-Block-Hash-in-Defender |
๐ Standalone |
1 |
1 |
| AS-Checkmarx-Audit-Ingestion |
๐ Standalone |
0 |
1 |
| AS-Checkmarx-SAST-Ingestion |
๐ Standalone |
1 |
1 |
| AS-Clear-Okta-Network-Zone-List |
๐ Standalone |
1 |
1 |
| AS-Create-Opsgenie-Incident |
๐ Standalone |
1 |
1 |
| AS-CrowdstrikeAlerts-Integration |
๐ Standalone |
1 |
1 |
| AS-Datadog-Events-Integration |
๐ Standalone |
1 |
2 |
| AS-Delete-App-Registration |
๐ Standalone |
1 |
1 |
| AS-Disable-Microsoft-Entra-ID-User-From-Entity |
๐ Standalone |
1 |
1 |
| AS-Edgescan-Integration-Assets |
๐ Standalone |
1 |
1 |
| AS-Edgescan-Integration-Hosts |
๐ Standalone |
1 |
1 |
| AS-Edgescan-Integration-Vulnerabilities |
๐ Standalone |
1 |
1 |
| AS-Enable-Microsoft-Entra-ID-User-From-Entity |
๐ Standalone |
1 |
1 |
| AS-Incident-Response-Approval-Email |
๐ Standalone |
1 |
1 |
| AS-Incident-Spiderfoot-Scan |
๐ Standalone |
1 |
1 |
| AS-IP-Blocklist |
๐ Standalone |
1 |
1 |
| AS-IP-Blocklist-HTTP |
๐ Standalone |
1 |
1 |
| AS-IP-Blocklist-HTTP |
๐ Standalone |
1 |
1 |
| AS-IP-Blocklist-Remove-IPs |
๐ Standalone |
1 |
1 |
| AS-Make-GitHub-Repository-Private |
๐ Standalone |
1 |
1 |
| AS-MDE-Isolate-Machine |
๐ Standalone |
1 |
1 |
| AS-MDE-Unisolate-Machine |
๐ Standalone |
1 |
1 |
| AS-Microsoft-DCR-Log-Ingestion |
๐ Standalone |
1 |
2 |
| AS-Microsoft-Entra-ID-Revoke-User-Sessions-HTTP |
๐ Standalone |
1 |
1 |
| AS-Microsoft-Entra-ID-Revoke-User-Sessions-HTTP |
๐ Standalone |
1 |
1 |
| AS-MuleSoft-Integration |
๐ Standalone |
1 |
1 |
| AS-Okta-NetworkZoneUpdate |
๐ Standalone |
1 |
1 |
| AS-Okta-NetworkZoneUpdate-HTTP |
๐ Standalone |
1 |
1 |
| AS-Okta-Terminate-User-Sessions-HTTP |
๐ Standalone |
1 |
1 |
| AS-Remove-Domains-from-Zscaler-URL-Category |
๐ Standalone |
1 |
2 |
| AS-Revoke-Entra-ID-User-Session-From-Entity |
๐ Standalone |
1 |
1 |
| AS-Revoke-Entra-ID-User-Session-From-Incident |
๐ Standalone |
1 |
1 |
| AS-Sign-Out-Google-User |
๐ Standalone |
1 |
1 |
| AS-Terminate-Okta-User-Sessions-From-Entity |
๐ Standalone |
1 |
1 |
| AS-Update-Okta-Network-Zone-From-Entity |
๐ Standalone |
1 |
1 |
| Block IP & URL on ThreatX-WAF cloud |
ThreatXCloud |
0 |
1 |
| Block Risky/Compromised User From Entrust |
Entrust identity as Service |
0 |
1 |
| Censys Ad-Hoc IOC Lookup |
Censys |
1 |
0 |
| Censys Alert Enrichment |
Censys |
1 |
1 |
| Censys Alert Rescan |
Censys |
1 |
1 |
| Censys Entity Enrichment - Certificate |
Censys |
1 |
1 |
| Censys Entity Enrichment - Host |
Censys |
1 |
1 |
| Censys Entity Enrichment - Web Property |
Censys |
1 |
1 |
| Censys Host History |
Censys |
1 |
1 |
| Censys Incident Enrichment |
Censys |
1 |
0 |
| Censys Related Infrastructure |
Censys |
1 |
1 |
| Censys Rescan |
Censys |
1 |
1 |
| CiscoUmbrella-AddIpToDestinationList |
CiscoUmbrella |
1 |
2 |
| CiscoUmbrella-AssignPolicyToIdentity |
CiscoUmbrella |
1 |
2 |
| CiscoUmbrella-GetDomainInfo |
CiscoUmbrella |
1 |
2 |
| Close Cohesity Helios Incident |
CohesitySecurity |
1 |
1 |
| Commvault Disable Data Aging Logic App Playbook |
Commvault Security IQ |
1 |
2 |
| Commvault Disable SAML Provider Logic App Playbook |
Commvault Security IQ |
1 |
2 |
| Commvault Disable User Logic App Playbook |
Commvault Security IQ |
1 |
2 |
| Crowdstrike API authentication |
CrowdStrike Falcon Endpoint Protection |
0 |
2 |
| Cybersixgill-Alert-Status-Update |
Cybersixgill-Actionable-Alerts |
1 |
3 |
| Cyjax Ad Hoc Enrichment |
Cyjax |
1 |
1 |
| Cyjax Data Breaches |
Cyjax |
1 |
1 |
| Cyjax Domain Monitor |
Cyjax |
1 |
1 |
| Cyjax Incident Enrichment |
Cyjax |
1 |
1 |
| DataminrPulseAlertEnrichment |
Dataminr Pulse |
1 |
3 |
| Delete-Cybersixgill-Alert |
Cybersixgill-Actionable-Alerts |
1 |
3 |
| Druva Quarantine Playbook for Enterprise Workload |
DruvaDataSecurityCloud |
1 |
2 |
| Druva Quarantine Playbook for inSync Workloads |
DruvaDataSecurityCloud |
1 |
2 |
| Druva Quarantine Playbook for Shared Drive |
DruvaDataSecurityCloud |
1 |
2 |
| Druva Quarantine Playbook for Sharepoint |
DruvaDataSecurityCloud |
1 |
2 |
| Druva Quarantine Using Resource id |
DruvaDataSecurityCloud |
1 |
2 |
| Enrich Dynatrace Application Security Attack Incident |
Dynatrace |
1 |
1 |
| Enrich Dynatrace Application Security Attack with related Microsoft Defender XDR insights |
Dynatrace |
1 |
1 |
| Enrich Dynatrace Application Security Attack with related Microsoft Sentinel Security Alerts |
Dynatrace |
1 |
1 |
| Enrich file hash entities - Intezer Analyze |
๐ Standalone |
1 |
1 |
| Fetch IP Details From Entrust |
Entrust identity as Service |
0 |
1 |
| Fetch IP Details From Entrust - Entity |
Entrust identity as Service |
0 |
1 |
| Fetch Security Posture from Prisma Cloud |
PaloAltoPrismaCloud |
0 |
1 |
| Fetch Threat Intel from ThreatX |
ThreatXCloud |
0 |
1 |
| Fetch User Details From Entrust |
Entrust identity as Service |
0 |
1 |
| Get-AD4IoTDeviceCVEs - Alert |
๐ Standalone |
1 |
1 |
| Get-AD4IoTDeviceCVEs - Incident |
IoTOTThreatMonitoringwithDefenderforIoT |
1 |
1 |
| Get-AD4IoTDeviceCVEs - Incident |
๐ Standalone |
1 |
1 |
| Get-MachineData-EDR-SOAR-ActionsOnMachine |
๐ GitHub Only |
1 |
1 |
| Get-MDATPVulnerabilities |
๐ GitHub Only |
1 |
1 |
| Ingest Microsoft Defender XDR insights into Dynatrace |
Dynatrace |
1 |
1 |
| Ingest Microsoft Sentinel Security Alerts into Dynatrace |
Dynatrace |
1 |
1 |
| Intel 471 Malware Intelligence to Sentinel |
Intel471 |
1 |
2 |
| MTI Threat Actor Lookup |
๐ Standalone |
1 |
1 |
| NetApp Ransomware Resilience Authentication Playbook |
NetApp Ransomware Resilience |
1 |
3 |
| O365 - Block Malware file extensions |
Microsoft Defender for Office 365 |
0 |
1 |
| O365 - Block Sender Entity Trigger |
Microsoft Defender for Office 365 |
0 |
1 |
| O365 - Block Spam Domain |
Microsoft Defender for Office 365 |
0 |
1 |
| O365 - Block Suspicious Sender |
Microsoft Defender for Office 365 |
0 |
1 |
| O365 - Delete All Malicious Inbox Rule |
Microsoft Defender for Office 365 |
0 |
1 |
| Pure Storage FlashBlade File System Snapshot |
Pure Storage |
1 |
2 |
| Pure Storage Protection Group Snapshot |
Pure Storage |
1 |
2 |
| Pure Storage User Deletion |
Pure Storage |
1 |
1 |
| Pure Storage Volume Snapshot |
Pure Storage |
1 |
2 |
| Query Azure Resource Graph with HTTP input and output |
๐ Standalone |
1 |
2 |
| Remediate assets on prisma cloud |
PaloAltoPrismaCloud |
0 |
1 |
| Restore From Last Cohesity Snapshot |
CohesitySecurity |
1 |
1 |
| ReversingLabs-CheckQuota |
ReversingLabs |
1 |
1 |
| Rubrik Advanced Threat Hunt |
RubrikSecurityCloud |
1 |
2 |
| Rubrik Anomaly Analysis |
RubrikSecurityCloud |
1 |
0 |
| Rubrik Data Object Discovery |
RubrikSecurityCloud |
1 |
0 |
| Rubrik File Object Context Analysis |
RubrikSecurityCloud |
1 |
2 |
| Rubrik IOC Scan |
RubrikSecurityCloud |
1 |
0 |
| Rubrik Poll Async Result |
RubrikSecurityCloud |
1 |
0 |
| Rubrik Ransomware Discovery and File Recovery |
RubrikSecurityCloud |
1 |
0 |
| Rubrik Ransomware Discovery and VM Recovery |
RubrikSecurityCloud |
1 |
0 |
| Rubrik Turbo Threat Hunt |
RubrikSecurityCloud |
1 |
2 |
| Rubrik Update Anomaly Status Via Incident |
RubrikSecurityCloud |
1 |
2 |
| Rubrik User Intelligence Analysis |
RubrikSecurityCloud |
1 |
2 |
| RubrikWorkloadAnalysis |
RubrikSecurityCloud |
1 |
2 |
| spur_alert |
๐ Standalone |
1 |
0 |
| spur_alert |
๐ Standalone |
1 |
0 |
| Sync Jira from Sentinel - Create incident |
AtlassianJiraAudit |
1 |
1 |
| Sync Jira to Sentinel - Assigned User |
AtlassianJiraAudit |
1 |
1 |
| Tanium-ComplyFindings |
Tanium |
1 |
1 |
| Tanium-GeneralHostInfo |
Tanium |
1 |
1 |
| Tanium-ListSecurityPatches |
Tanium |
1 |
1 |
| Tanium-MSDefenderHealth |
Tanium |
1 |
1 |
| Tanium-QuarantineHosts |
Tanium |
1 |
1 |
| Tanium-ResolveThreatResponseAlert |
Tanium |
1 |
1 |
| Tanium-SCCMClientHealth |
Tanium |
1 |
1 |
| Tanium-UnquarantineHosts |
Tanium |
1 |
1 |
| Update-Watchlist-With-NamedLocations |
๐ GitHub Only |
0 |
1 |
| Vectra Add Note To Entity |
Vectra XDR |
1 |
2 |
| Vectra Add Tag To Entity |
Vectra XDR |
1 |
2 |
| Vectra Add Tag To Entity All Detections |
Vectra XDR |
1 |
3 |
| Vectra Add Tag To Entity Selected Detections |
Vectra XDR |
1 |
3 |
| Vectra Assign Dynamic User To Entity |
Vectra XDR |
1 |
0 |
| Vectra Assign Static User To Entity |
Vectra XDR |
1 |
4 |
| Vectra Close Detections |
Vectra XDR |
1 |
3 |
| Vectra Decorate Incident Based On Tag |
Vectra XDR |
1 |
0 |
| Vectra Decorate Incident Based On Tags And Notify |
Vectra XDR |
1 |
0 |
| Vectra Download Pcap File To Storage |
Vectra XDR |
1 |
3 |
| Vectra Dynamic Assign Member To Group |
Vectra XDR |
1 |
0 |
| Vectra Dynamic Resolve Assignment |
Vectra XDR |
1 |
0 |
| Vectra Generate Access Token |
Vectra XDR |
1 |
3 |
| Vectra Mark Detections As Fixed |
Vectra XDR |
1 |
3 |
| Vectra Open Closed Detections |
Vectra XDR |
1 |
2 |
| Vectra Operate On Entity Source IP |
Vectra XDR |
1 |
1 |
| Vectra Static Assign Member To Group |
Vectra XDR |
1 |
0 |
| Vectra Static Resolve Assignment |
Vectra XDR |
1 |
4 |
| Vectra Update Incident Based on Tag And Notify |
Vectra XDR |
1 |
0 |