This playbook is triggered when suspicious or unauthorized credential access activity is detected. It performs contextual enrichment using ArcSight Intelligence and Microsoft Active Directory (AD), allows for a manual analyst decision, and based on that decision, performs automated actions such as sending notifications, disabling users, and updating the case status in ArcSight SOAR.
This playbook is triggered when suspicious or unauthorized credential access activity is detected. It performs contextual enrichment using ArcSight Intelligence and Microsoft Active Directory (AD), allows for a manual analyst decision, and based on that decision, performs automated actions such as sending notifications, disabling users, and updating the case status in ArcSight SOAR.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox