Has anyone done a playbook for crowdstrike serves stopped? Basically querying splunk for host name, etc? If so can you please share how you have done this?
... View more
How can I create search for temporary users in privileged groups? Domain Admins, Enterprise Admins, Schema Admins, Account Operators, Administrators, Backup Operators, Incoming Forest Trust Builders, Server Operators. I'm struggling
... View more
For "Endpoint - Malicious File Detection in Cloud Application playbook" tickets,how do I include the last six characters of the sha256 hash in the ticket title
... View more
How can I Troubleshoot playbook issue where the wrong raw log is being included in the ticket. For example, where ticket was created for source IP 10.xx.x.xxx and destination IP 10.x.x.x- however the raw log was for source IP 10.35.41.10, and destination IP was 10.1.3.7.
... View more
When parsing the email message body for inclusion in the ticket in Jira, parsing fails on special characters or non-ASCII text. How can I update function in Phantom to properly handle the message body in cases where the error is being thrown.
<error in expanding custom_function_1:custom_function:C1_email>
... View more
How can I enrich the endpoint tickets, where the ticket is for a MacOS host, lookup the host in Jamf and return the following fields: Site, Username, and Full Name. Expected results for 'Site' include "NA - Retail" and "NA - Corp" among others.
... View more