Files
splunk-security_content/playbooks/risk_notable_mitigate.yml

22 lines
866 B
YAML

name: Risk Notable Mitigate
id: 050edc96-ff2b-48b0-9f6f-63da3783fd63
version: 1
date: "2021-10-22"
author: Kelby Shelton, Splunk
type: Response
description: This playbook checks for the presence of the Risk Response workbook and updates tasks or leaves generic notes. The risk_notable_verdict playbooks recommends this playbook as a second phase of the investigation. Additionally, this playbook can be used in ad-hoc investigations or incorporated into custom workbooks.
playbook: risk_notable_mitigate
how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack
references:
- https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack
app_list: []
tags:
labels:
- risk_notable
playbook_type: Automation
vpe_type: Modern
platform_tags:
- Risk Notable
product:
- Splunk SOAR