Skip to content

Conversation

@mrangelov-cb
Copy link

Hello,

This is a generic playbook to run on Carbon Black Cloud-ingested alert artifacts (ingested via the recently released VMware Carbon Black Cloud Splunk SOAR app).

It also adds two custom functions to fetch the URLs to pivot to the Alert Triage/Process Analysis pages in CBC that might be useful in other playbooks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant