This playbook automates the response to incidents involving compromised user credentials. It uses enrichment from ArcSight Intelligence and Microsoft Active Directory (AD) to gather user context, sends notification emails, and allows analysts to manually decide whether the affected user should be disabled.
This playbook automates the response to incidents involving compromised user credentials. It uses enrichment from ArcSight Intelligence and Microsoft Active Directory (AD) to gather user context, sends notification emails, and allows analysts to manually decide whether the affected user should be disabled.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox