Skip to main content

Responses are generated using AI and may contain mistakes.

Automation ManagementAutomation Management Guide

Send Case Templated Email Pre-Built Playbook

Automatically send a customized email notification to specific email recipients using the Send Case Templated Email pre-built playbook.

Send Case Templated Email is a partially configured pre-built playbook that is disabled by default. It is partially configured so you can use it as a template and customize it with your own details.

Playbook Logic

The Send Case Templated Email pre-built playbook has the Case created trigger. If the playbook is enabled, the playbook automatically runs when a Threat Center case is created.

The Send Case Tempalted Email pre-built playbook with each step numbered and highlighted in a red rectangle.

1 The playbook uses the Get Case Details action to retrieve the following case information:

  • alertCreationTimestamp – The date and time the associated alert was created

  • alertId – The UUID of the associated alert

  • approxLogTime – The date and time Search indexes an event

  • assignee – The assignee assigned to respond to the case

  • assigneeId – The ID of the person assigned to respond to the case

  • creationTimestamp – The date and time the case was created

  • caseId – The UUID of the case

  • caseNumber – The number assigned to the case

  • creationBy – Who created the case

  • stage – The current case stage

  • closedReason – If the case is closed, the selected pre-defined case closed reason

  • supportingReason – If the case is closed, the comment added to the pre-defined case closed reason

  • alertDescription – Case description in either plain text or HTML format. For example Suspicious Activity (plain text) or <strong>Suspicious Activity<strong> (HTML). If HTML formatting is used, it will also be reflected in the Threat Center web interface.

  • hasAttachments – A boolean value indicating whether the case has attachments.

  • isDeleted – A boolean value indicating whether the case is deleted.

  • lastModifiedBy – Who last modified the case.

  • lastModifiedTimestamp – The date and time the case was last modified.

  • mitres – The associated MITRE ATT&CK® tactic and technique and their corresponding keys.

  • alertName – The name of the associated alert.

  • priority – The case priority: Low, Medium, High, Critical, or Undefined.

  • riskScore – The case risk score

  • queue – The queue assigned to respond to the case

  • status – Whether the case is read or unread

  • tags – Tags added to the case

  • useCases – Associated Exabeam use cases

  • products – The products associated with related detections

  • vendors – The vendors associated with related detections

  • srcHosts – The source host names associated with related detections.

  • srcIps – The source host IP addresses associated with related detections

  • destHosts – The destination host names associated with related detections

  • destIps – The destination IP addresses associated with related detections

  • users – The users associated with related detections

  • groupedbyKey – The attribute by which detections are grouped

  • groupedbyValue – The attribute value by which detections are grouped

  • ingestTimestamp

  • srcEndpoints – The source host names and IP addresses associated with related detections

  • destEndpoints – The destination host names and IP addresses associated with related detections

  • groupingRuleId – The ID of the detection grouping rule used to group related detections

  • rules – The triggered analytics rules, correlation rules, and Advanced Analytics associated with related detections

2 The playbook runs a branch to all. In this branch to all:

  • Nova Summary – The branch calls an Exabeam API to generate a 600 character plain-text summary of the case using the Exabeam Nova Investigation Summary.

  • Case Summary – The branch generates a dictionary of key case attributes:

    • Priority

    • Queue

    • Severity

    • Case number

    • Stage

    • Status

    • Risk score

    • Assignee

    • The date and time the case was created

    • The date and time the associated alert was created

    • The name of the associated alert

    The branch generates display-ready headers for the following attributes:

    • Case number

    • Risk score

    • The date and time the case or associated alert was created

    • The name of the associated alert

    • The case severity, mapped to a color

    • The case URL

    The branch generates a email subject header in the following format: [<Priority>] <Associated alert name or case name>; for example, [Critical] Malware Detected on Endpoint.

  • Entities Summary – The branch generates two formatted HTML tables of Attack Surface Insights entities associated with the case, one for user entities and the other for device entities.

  • Triggered Rules Summary – The branch generates a dictionary of the top 10 unique triggered rules associated with the case and their trigger counts, sorted by severity, then in descending order by trigger count.

3 The playbook runs the Template & Recipients Definition action. The action uses the results from the branch to all to generate a raw HTML string of an email notification.

4 The playbook runs the Recipients list definition action. The action validates a list of email recipients to ensure they follow a valid email format, removes duplicate email addresses from the list, then generates final list of email recipients that also includes the case assignee.

5 The playbook runs the Custom Send Email pre-built threatcenter action. The action uses the list of email recipients, the email subject, and the raw HTML string of the email notification to send an email notification using the Exabeam notification service. It returns a status object indicating whether the email was successfully sent.

Use the Playbook as a Template

The Send Case Templated Email pre-built playbook is partially configured so you can use it as a template and customize it with your own details.

To use the playbook as a template, clone the playbook, then edit the Template & Recipients Definition and Recipients list definition actions.

  1. Clone the playbook.

  2. To create your own email notification HTML structure, edit the Template & Recipients Definition action logic with your own email notification HTML structure.

  3. To define your own list of email recipients, under the Recipients list definition action, navigate to the Step Input tab, then enter each recipient email address under recipientsEmail.