Forum Discussion

SocInABox's avatar
SocInABox
Iron Contributor
Oct 13, 2021

auto assessment playbook with "tag indicators"

Has anyone here done any work on the idea of a playbook to perform triage on Sentinel incidents? eg: If the incident contains a username entity, run these kql queries and create tags depending on t...

Resources