Files
splunk-security_content/playbooks/Related_Tickets_Search_Dispatch.yml
2026-05-19 11:12:49 -07:00

22 lines
904 B
YAML

name: Related Tickets Search Dispatch
id: fc0edc96-ab1f-48b9-9b4d-63da61bafe74
version: 2
creation_date: '2023-02-27'
modification_date: '2026-05-19'
author: Patrick Bareiss, Splunk
type: Investigation
description: "Detects available indicators and routes them to dispatch related ticket search playbooks. The output of the analysis will update any artifacts, tasks, and indicator tags."
playbook: Related_Tickets_Search_Dispatch
how_to_implement: This playbook looks for artifacts and then dispatches the community Related Tickets playbooks. This playbook takes the output of those playbooks and nicely formats them into notes and tags indicators with their results.
references:
- https://d3fend.mitre.org/technique/d3f:IdentifierReputationAnalysis/
app_list: []
platform_tags: []
playbook_type: Automation
vpe_type: Modern
playbook_fields: []
product:
- Splunk SOAR
use_cases:
- Enrichment