Skip to content

Commit df38f1f

Browse files
authored
Suspicious user access to multiple resources via sso trigger (demisto#39514)
* Add trigger * RN * Add trigger * RN * RN * after review * RN
1 parent a00f588 commit df38f1f

File tree

3 files changed

+28
-1
lines changed

3 files changed

+28
-1
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
## Cortex Response And Remediation
2+
3+
Documentation and metadata improvements.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
{
2+
"trigger_id": "420e8ea021be42d1f333287a092efcf7",
3+
"playbook_id": "silent-Suspicious user access to multiple resources via SSO",
4+
"suggestion_reason": "Recommended for Valid Accounts alerts involving suspicious user access to multiple resources via SSO.",
5+
"description": "This trigger is responsible for handling Valid Accounts alerts related to suspicious user access to multiple resources via SSO.",
6+
"trigger_name": "silent-Suspicious User access to multiple resources via SSO",
7+
"alerts_filter": {
8+
"filter": {
9+
"AND": [
10+
{
11+
"SEARCH_FIELD": "alert_name",
12+
"SEARCH_TYPE": "EQ",
13+
"SEARCH_VALUE": "Suspicious user access to multiple resources via SSO"
14+
},
15+
{
16+
"SEARCH_FIELD": "alert_type",
17+
"SEARCH_TYPE": "NEQ",
18+
"SEARCH_VALUE": "Correlation"
19+
}
20+
]
21+
}
22+
},
23+
"issilent": true
24+
}

Packs/CortexResponseAndRemediation/pack_metadata.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
"name": "Cortex Response And Remediation",
33
"description": "The Cortex Response & Remediation Pack delivers a powerful collection of automated playbooks designed to streamline incident response and remediation processes. Built to support an Autonomous SOC vision.",
44
"support": "xsoar",
5-
"currentVersion": "1.1.33",
5+
"currentVersion": "1.1.34",
66
"author": "Cortex XSOAR",
77
"url": "https://www.paloaltonetworks.com/cortex",
88
"email": "",

0 commit comments

Comments
 (0)