This playbook is designed to respond to Initial Access detection incidents—such as unauthorized logins or unusual account behavior. It integrates with SMTP Mail Server, Microsoft Active Directory, ArcSight Intelligence, and ArcSight SOAR. The playbook combines automated enrichment, decision branching, and analyst input to drive proper response actions including severity assignment, notification, labeling, and user disablement.
This playbook is designed to respond to Initial Access detection incidents—such as unauthorized logins or unusual account behavior. It integrates with SMTP Mail Server, Microsoft Active Directory, ArcSight Intelligence, and ArcSight SOAR. The playbook combines automated enrichment, decision branching, and analyst input to drive proper response actions including severity assignment, notification, labeling, and user disablement.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox