- Automation Management
- Automation Management Permissions
- Automation Management Playbooks
- Automation Management Playbook Triggers
- Pre-Built Automation Management Playbooks
- Automation Management Advanced Playbooks
- Automation Management Rule-Based Playbooks
- Filter Automation Management Playbooks
- Find Automation Management Playbooks
- Enable or Disable an Automation Management Playbook
- Reorder an Automation Management Playbook
- Delete an Automation Management Playbook
- Automation Management Services
- Automation Management Actions
- Create an Automation Management Action
- Clone an Automation Management Action
- Edit an Automation Management Action
- Deploy an Automation Management Action
- Preview Automation Management Action Code
- View Automation Management Action Run History
- View Automation Management Action Version History
- View Automation Management Action Audit Log
- Delete an Automation Management Action
- Refresh Automation Management Action List
- Automation Agents
Pre-built services are services that are already configured and enabled by default. They're listed along other services in Automation Management, with Exabeam under the CREATED BY column. There is one pre-built playbook, the threatcenter service.
The threatcenter service integrates Automation Management with Threat Center. It has 10 actions:
No op – Logs the message No operation performed.
Update Alert – Updates the associated Exabeam use cases, tags, priority, and MITRE ATT&CK® tactics and techniques of an alert with a given alert ID.[2]
Update Case – Updates the associated Exabeam use cases, tags, priority, ATT&CK tactics and techniques, stage, closed reason if the stage is changed to Closed, queue, and assignee of a case with a given case ID.
Alert: Send Email – Sends information about an alert with a given alert ID to a list of email addresses.
Alert: Send Webhook – Sends information about an alert with a given alert ID to a list of webhook IDS.
Case: Send Email – Sends information about a case with a given case ID to a list of email addresses.
Case: Send Webhook – Sends information about a case with a given case ID to a list of webhook IDs.
Create Case – Manually creates a case given a case ID and associated Exabeam use cases, tags, priority, ATT&CK tactics and techniques, stage, closed reason if the stage is Closed, queue, and assignee.
Get Case Details – Returns case information, including:
alertCreationTimestamp – The date and time the associated alert was created
alertId – The UUID of the associated alert
approxLogTime – The date and time Search indexes an event
assignee – The assignee assigned to respond to the case
assigneeId – The ID of the person assigned to respond to the case
creationTimestamp – The date and time the case was created
caseId – The UUID of the case
caseNumber – The number assigned to the case
creationBy – Who created the case
stage – The current case stage
closedReason – If the case is closed, the selected pre-defined case closed reason
supportingReason – If the case is closed, the comment added to the pre-defined case closed reason
alertDescription – Case description in either plain text or HTML format. For example Suspicious Activity (plain text) or <strong>Suspicious Activity<strong> (HTML). If HTML formatting is used, it will also be reflected in the Threat Center web interface.
hasAttachments – A boolean value indicating whether the case has attachments.
isDeleted – A boolean value indicating whether the case is deleted.
lastModifiedBy – Who last modified the case.
lastModifiedTimestamp – The date and time the case was last modified.
mitres – The associated MITRE ATT&CK® tactic and technique and their corresponding keys.
alertName – The name of the associated alert.
priority – The case priority: Low, Medium, High, Critical, or Undefined.
riskScore – The case risk score
queue – The queue assigned to respond to the case
status – Whether the case is read or unread
tags – Tags added to the case
useCases – Associated Exabeam use cases
products – The products associated with related detections
vendors – The vendors associated with related detections
srcHosts – The source host names associated with related detections.
srcIps – The source host IP addresses associated with related detections
destHosts – The destination host names associated with related detections
destIps – The destination IP addresses associated with related detections
users – The users associated with related detections
groupedbyKey – The attribute by which detections are grouped
groupedbyValue – The attribute value by which detections are grouped
ingestTimestamp
srcEndpoints – The source host names and IP addresses associated with related detections
destEndpoints – The destination host names and IP addresses associated with related detections
groupingRuleId – The ID of the detection grouping rule used to group related detections
rules – The triggered analytics rules, correlation rules, and Advanced Analytics associated with related detections
Get Alert Details – Returns alert information, including:
creationTimestamp – The date and time the alert was created
alertId – The UUID of the alert
caseId – The UUID of the associated case
approxLogTime – The date and time Search indexes an event
creationBy – Who created the case
alertDescription – Alert description in either plain text or HTML format. For example Suspicious Activity (plain text) or <strong>Suspicious Activity<strong> (HTML). If HTML formatting is used, it will also be reflected in the Threat Center web interface.
lastModifiedBy – Who last modified the alert
lastModifiedTimestamp – The date and time the alert was last modified
mitres – The associated MITRE ATT&CK® tactic and technique and their corresponding keys.
alertName – The name of the alert
priority – The alert priority: Low, Medium, High, Critical, or Undefined
riskScore – The alert risk score
status – Whether the associated case is read or unread
tags – Tags added to the alert
useCases – Associated Exabeam use cases
products – The products associated with related detections
vendors – The vendors associated with related detections
srcHosts – The source host names associated with related detections.
srcIps – The source host IP addresses associated with related detections
destHosts – The destination host names associated with related detections
destIps – The destination IP addresses associated with related detections
users – The users associated with related detections
groupedbyKey – The attribute by which detections are grouped
groupedbyValue – The attribute value by which detections are grouped
ingestTimestamp
srcEndpoints – The source host names and IP addresses associated with related detections
destEndpoints – The destination host names and IP addresses associated with related detections
groupingRuleId – The ID of the detection grouping rule used to group related detections
rules – The triggered analytics rules, correlation rules, and Advanced Analytics associated with related detections
alertStatus – Whether the alert is read or unread
You can't edit or delete pre-built services. If you don't want to use a pre-built service, create your own service.
[2] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.