This playbook automates the response to potential lateral movement activity within an enterprise environment. It gathers system and user information from Microsoft Active Directory (AD), escalates the case based on an analyst’s decision, notifies stakeholders via email, and disables user accounts if required. It integrates with ArcSight SOAR, Microsoft AD, and SMTP mail services for a comprehensive response.
This playbook automates the response to potential lateral movement activity within an enterprise environment. It gathers system and user information from Microsoft Active Directory (AD), escalates the case based on an analyst’s decision, notifies stakeholders via email, and disables user accounts if required. It integrates with ArcSight SOAR, Microsoft AD, and SMTP mail services for a comprehensive response.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox