Skip to main content

Threat CenterThreat Center Guide

Manually Send Case or Alert Information to Email

Manually send an email containing case or alert information directly from the case or alert to people who can't access Threat Center.

Email people who can't access Threat Center, like non-SOC staff in your organization, to exchange questions, instructions, and feedback about an investigation.

The email contains:

  • The person or playbook that sent the email

  • The case or alert ID

  • The date and time the case or alert was last updated

  • The field by which related detections are grouped

  • The case or alert URL

  • A summary of the case or alert, including the number of related detections, triggered rules, MITRE ATT&CK® tactics and techniques, users, endpoints; and the case or alert risk score[8]

  • A more detailed summary of the case or alert, including a list of related users, endpoints, tags, ATT&CK tactics and techniques, Exabeam use cases; the case or alert severity; and, for cases, the case stage, the case closed reason if the case stage is Closed, queue, and assignee.

  • The entire threat timeline.

To automatically send case or alert information to email under specific situations and conditions you specify, create an Automation Management playbook where an action is Send all threat details via email.

  1. In a case or alert, click Automations, then select Send email.

    threatcenter-automations-sendemail.png
  2. Select or enter the email addresses to which you'll send case or alert information.

  3. Click Send. This action is recorded in the case or alert history.




[8] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.