サポートされているプレイブック🔗
注意
各プレイブックには、新しいプレイブックを作成する手順を案内する組み込みのドキュメントがあります。XDRのケーステンプレートまたは設定済みのケースからドキュメントを選択すると、新しいタブで開き、そこで案内に従うことができます。
XDR は、以下を 含むがこれらに限定されない 多数のインテグレーションをサポートしています。
ヒント
最新のプレイブックテンプレート、アクション、コネクターの公開履歴や、既存のテンプレートおよびコネクターの更新情報については、自動化の概要をご覧ください。
| Playbook Title | Description |
|---|---|
| 4me ITSM Alert | XDR アラートに基づいて 4me Problem または Request を作成します |
| 4me ITSM Investigation | XDR Investigation に基づいて 4me Problem または Request を作成します |
| 4me ITSM Investigation Sync | 4me Problem または Request を Security Response Investigation と同期します |
| AD Change Password At Log On | LDAP(S) プロトコルを使用して AD ユーザーのログオン時パスワード変更を行います |
| AD Deactivate Change Password At Log On | LDAP(S) プロトコルを使用して AD ユーザーのログオン時パスワード変更を無効化します |
| AD Disable User | LDAP(S) プロトコルを使用して AD のユーザーアカウントを無効化します |
| AD Enable User | LDAP(S) プロトコルを使用して AD のユーザーアカウントを有効化します |
| AD/LDAP Change Password | LDAP(S) プロトコルを使用して AD/LDAP ユーザーのパスワードを変更します |
| AD/LDAP Look Up User | LDAP(S) プロトコルを使用して AD/LDAP ユーザーを検索します |
| Alert Email Notification | アラートのメール通知を送信します |
| Alert Email Notification with Google Gmail | Google Gmail API を使用してアラートのメール通知を送信します |
| Alert ITSM Sync | ServiceNow Alert を ITSM Incident と同期します |
| Alert SIR Sync | ServiceNow Alert を Security Incident と同期します |
| Amazon Web Services Disable User Access Keys | Amazon Web Services のユーザーアクセスキーを無効化します |
| Amazon Web Services Disable User Login | 特定のユーザーの AWS Console ログインを無効化します |
| Amazon Web Services Disable User MFA Devices | 特定の AWS ユーザーの MFA デバイスを削除します |
| Amazon Web Services Enable User Access Keys | Amazon Web Services のユーザーアクセスキーを有効化します |
| Amazon Web Services Enable User Login | 特定のユーザーに対して、事前定義されたパスワードで AWS Console の新しいログインプロファイルを作成します |
| Amazon Web Services Look Up User | Amazon Web Services ユーザーを検索します |
| Amazon Web Services Update IP Set | AWS WAF で IP アドレスをブロック/ブロック解除します |
| Analyze Email | Email エンティティのエンリッチメントを有効にします |
| Automated Action AD Change Password At Log On | LDAP(S) プロトコルを使用して、アラートに関連するすべてのユーザーのログオン時パスワード変更を自動的に行います |
| Automated Action AD Disable User | LDAP(S) プロトコルを使用して、アラート内のすべてのユーザーを自動的に無効化します |
| Automated Action Isolate Host Red Cloak Endpoint Agent | Automated Action Isolate Host Red Cloak Endpoint Agent |
| Automated Action Isolate Host Taegis Agent | Automated Action Isolate Host Taegis Agent |
| Automated Action Microsoft Entra ID Disable User | Microsoft Graph API を使用して、アラート内のすべてのユーザーを自動的に無効化します |
| Automated Action Microsoft Entra ID Force Password Reset | Microsoft Graph API を使用して、アラート内のすべてのユーザーに対してパスワードリセットを自動的に強制します |
| Azure OpenAI Enrich Investigation | Azure OpenAI を介して Investigation の主な発見事項をエンリッチメントします |
| Block Domain | Block Domain レスポンスアクションを有効にします |
| Block Email Address | Block Email Address レスポンスアクションを有効にします |
| Block File Hash | ファイルハッシュに対する Block File Hash レスポンスアクションを有効にします |
| Block IP | IP アドレスに対する Block IP レスポンスアクションを有効にします |
| Block URL | Block URL レスポンスアクションを有効にします |
| Carbon Black EDR - Block Filehash | Carbon Black EDR (Endpoint Detection and Response) で Filehash をブロックします |
| Carbon Black EDR - Unblock Filehash | Carbon Black EDR (Endpoint Detection and Response) で Filehash のブロックを解除します |
| CB Cloud - Isolate | VMWare Carbon Black Cloud で隔離します |
| CB Cloud - Undo Isolate Host | VMWare Carbon Black Cloud でホストの隔離を解除します |
| Change Password | Change Password レスポンスアクションを有効にします |
| Change Password At Next Login | Change Password At Next Login レスポンスアクションを有効にします |
| Change Password At Next Login Google Workspace Admin SDK API | Google Workspace Admin SDK API を使用して、ユーザーの次回ログイン時パスワード変更を有効にします |
| Change Password Google Workspace Admin SDK API | Google Workspace Admin SDK API を使用して、ユーザーのパスワードを変更します |
| Cisco Meraki Activities | Cisco Meraki でリソースをブロックおよびブロック解除します |
| Comments To Email Notification | Taegis Investigation のコメントを Email で送信します |
| Comments To Mattermost Notification | Taegis Investigation のコメントを Mattermost に送信します |
| Comments To Microsoft Teams Notification | Taegis Investigation のコメントを Microsoft Teams に送信します |
| Comments To Salesforce Slack Notification | Taegis Investigation のコメントを Salesforce Slack に送信します |
| Comments To ServiceNow WorkNote | Taegis Investigation のコメントを ServiceNow WorkNote に送信します |
| Confirm User As Compromised | ユーザーを侵害済みとして確認します |
| Cortex XSOAR Investigation Sync | XDR Investigation を Cortex XSOAR Incident と同期します |
| Create Investigations from Alerts | アラートから XDR Investigation を作成します |
| Create ServiceNow User | ServiceNow ユーザーを作成します |
| CrowdStrike Falcon Endpoint - Isolate | CrowdStrike Falcon Endpoint Protection で隔離します |
| CrowdStrike Falcon Endpoint - Undo Isolate | CrowdStrike Falcon Endpoint Protection でホストの隔離を解除します |
| Deactivate Change Password At Next Login Google Workspace Admin SDK API | Google Workspace Admin SDK API を使用して、ユーザーの次回ログイン時パスワード変更を無効化します |
| Deactivate ServiceNow User | ServiceNow ユーザーを無効化します |
| Detonate URL | URL をデトネートし、結果をエンリッチメントとして提供します |
| Disable User | ユーザーに対する Disable User レスポンスアクションを有効にします |
| Dismiss User As Compromised | ユーザーの侵害済みステータスを却下します |
| Enable User | ユーザーに対する Enable User レスポンスアクションを有効にします |
| Endpoint Tagging | このプレイブックは、任意の数のエンドポイントにタグを追加/削除するために使用できます。 |
| Endpoint Tagging - Multi | 異なる条件で Endpoint Tagging プレイブックを複数回実行できるようにします |
| Enrich Investigation | Investigation のエンリッチメントを有効にします |
| Entity Enrichment Look Up Asset | 資産エンティティのエンリッチメントを有効にします |
| EverBridge Alert Incident | XDR アラートに基づいて EverBridge Incident を作成します |
| EverBridge Investigation Incident | XDR Investigation に基づいて EverBridge Incident を作成します |
| Freshdesk Investigation Sync | Taegis Investigation を Freshdesk Incident と同期します |
| Freshservice Alert Ticket | Taegis Alert に基づいて Freshservice Ticket を作成します |
| Freshservice Investigation Sync | Taegis Investigation を Freshservice Ticket と同期します |
| Freshservice Investigation Ticket | Taegis Investigation に基づいて Freshservice Ticket を作成します |
| Generic Webhook | すべての入力を webhook URL に POST します |
| Halo ITSM Investigation Synch | XDR Investigation を Halo ITSM Incident と同期します |
| Health Event Investigation | Health Event から Taegis Investigation を作成します |
| Initiate Antivirus Scan on Host | ホストでの Antivirus スキャン開始を有効にします |
| Investigation CrowdStrikeFalcon Incident Sync | Investigation を CrowdStrikeFalcon Incident と同期します |
| Investigation Email Notification | Investigation のメール通知を送信します |
| Investigation Email Notification with Google Gmail | Google Gmail API を使用して Investigation のメール通知を送信します |
| Investigation ITSM Sync | ServiceNow Investigation を ITSM Incident に一方向同期します |
| Investigation Service Now MultiTeam Sync | Investigation ServiceNow MultiTeam Sync |
| Investigation SIR Sync | ServiceNow Investigation を Security Incident Response と同期します |
| Investigation SMAX Sync | Taegis Investigation を Microfocus SMAX チケットと同期します |
| Investigation Translate Comments | Investigation のコメントを別の言語に翻訳します |
| Investigation Translate Key Findings | Investigation の主な発見事項を別の言語に翻訳します |
| Investigations Email Report | Taegis Investigation に関するメールレポート |
| Isolate Host | ホストに対する Isolate Host レスポンスアクションを有効にします |
| Isolate Host Automated Action | Isolate Host 自動レスポンスアクション |
| ITSM Incident Vulnerability | XDR 脆弱性に基づいて ServiceNow Incident を作成します |
| Jira Alert Issue | XDR アラートに基づいて Atlassian Jira Issue を作成します |
| Jira Investigation Issue | XDR Investigation に基づいて Atlassian Jira Issue を作成します |
| Jira Investigation Sync | Jira Issue を Security Response Investigation と同期します |
| Jira Vulnerability Issue | XDR 脆弱性に基づいて Atlassian Jira Issue を作成します |
| JupiterOne Investigation AWS Instance Enrichment | JupiterOne の AWS インスタンスコンテキストで Investigation をエンリッチメントします |
| Look Up Asset Vulnerabilities | 資産の脆弱性のエンリッチメントを有効にします |
| Look Up File Hash | File Hash を検索し、結果をエンリッチメントとして提供します |
| Look Up User | ユーザーエンティティのエンリッチメントを有効にします |
| Look Up User Google Workspace Admin SDK API | Google Workspace Admin SDK API を使用してユーザーを検索します |
| ManageEngine ServiceDesk Plus Alert | XDR Alert から ManageEngine Service Desk Plus の Request を作成するために使用されるプレイブック |
| ManageEngine ServiceDesk Plus Investigation Sync | Investigation を ManageEngine Service Desk Plus の Request と同期するために使用されるプレイブック |
| MD ATP - Block Filehash Globally | Microsoft Defender ATP で Filehash をグローバルにブロックします |
| MD ATP - Host Response Action | Microsoft Defender ホストに対してさまざまなレスポンスアクションを実行します |
| MD ATP - Isolate Host | Microsoft Defender ATP でホストを隔離します |
| MD ATP - Single Endpoint Filehash Block | Microsoft Defender ATP で単一エンドポイント上の Filehash をブロックします |
| MD ATP - Undo Isolate Host | Microsoft Defender ATP でホストの隔離を解除します |
| Microsoft Entra ID Disable User | Microsoft Graph API を使用して Microsoft Entra ID ユーザーアカウントを無効化します |
| Microsoft Entra ID Enable User | Microsoft Graph API を使用して Microsoft Entra ID ユーザーアカウントを有効化します |
| Microsoft Entra ID Force Password Reset | Microsoft Graph API を使用して Microsoft Entra ID ユーザーアカウントに対してパスワードリセットを強制します |
| Microsoft Entra ID Look Up User | Microsoft Graph API を使用して Microsoft Entra ID ユーザーを検索します |
| Microsoft Teams Notification | webhook を介して Microsoft Teams 通知を送信します |
| Notifications via Google Workspace Chat | Taegis 通知を Google Workspace Chat webhook に送信します |
| Okta Look Up User | Okta ユーザーを検索します |
| OpenAI Enrich Investigation | OpenAI を介して Investigation の主な発見事項をエンリッチメントします |
| Opsgenie XDR Alert | XDR アラートに基づいて Atlassian Opsgenie Alert または Incident を作成します |
| Opsgenie XDR Investigation | XDR Investigation に基づいて Atlassian Opsgenie Alert または Incident を作成します |
| PagerDuty Alert Event | XDR アラートに基づいて PagerDuty Event を送信します |
| PagerDuty Investigation Event | XDR Investigation に基づいて PagerDuty Event を送信します |
| PagerDuty Investigation Sync | PagerDuty Incident を Security Response Investigation と同期します |
| Palo Alto Networks PAN-OS Block/Unblock | Palo Alto Networks PAN-OS で IP/CIDR または Domain をブロックおよびブロック解除します |
| RC - Isolate | Red Cloak Endpoint Agent で隔離します |
| RC - Undo Isolate Host | Red Cloak Endpoint Agent でホストの隔離を解除します |
| RC Disable Process Disruption | Red Cloak Endpoint Agent で disrupt process (block filehash) ルールを無効化します |
| RC Process Disruption | Red Cloak Endpoint Agent で process disruption (block filehash) を実行します |
| Reactivate User Google Workspace Admin SDK API | Google Workspace Admin SDK API を使用してユーザーを再有効化します |
| Reset MFA Factors | ユーザーに対する Reset MFA Factors レスポンスアクションを有効にします |
| Revoke User Sign-In Sessions | ユーザーに対する Revoke User Sign-In Sessions レスポンスアクションを有効にします |
| Salesforce Slack Notification | Webhook を介して Salesforce Slack 通知を送信します |
| SCADAfence Platform Investigation Enrichment | SCADAfence のアラート/資産詳細で Taegis Investigation をエンリッチメントします |
| Send Notification Message | サポートされているメッセージングプラットフォームに通知メッセージを送信します |
| SentinelOne - Host Response Actions | SentinelOne エージェントに対してさまざまなレスポンスアクションを実行します |
| SentinelOne - Isolate | SentinelOne で隔離します |
| SentinelOne - Undo Isolate Host | SentinelOne でホストの隔離を解除します |
| SentinelOne Threat Mitigation Response Actions | Taegis Alert に対して Threat Mitigation レスポンスアクションを実行します |
| ServiceNow Bidirectional Investigation Sync (Inbound) | Servicenow から提供されたデータに基づいて Taegis Investigation を更新します |
| ServiceNow Bidirectional Investigation Sync (Outbound) | Import Sets を利用して Investigation を Servicenow と同期します |
| Suspend User Google Workspace Admin SDK API | Google Workspace Admin SDK API を使用してユーザーを停止します |
| Sync Alert | サードパーティのアラートを XDR と同期します |
| Taegis Agent - Isolate | Taegis Agent で隔離します |
| Taegis Agent - Restore | Taegis Agent の隔離を解除します |
| Taegis NDR Block | Taegis NDR デバイス上で特定の IP アドレスをブロック (shun) します |
| Taegis NDR Firewall Modification | Taegis NDR ファイアウォール関連のさまざまなアクションを実行します |
| Taegis NDR Unblock | Taegis NDR デバイス上で特定の IP アドレスのブロックを解除 (unshun) します |
| UnBlock Domain | UnBlock Domain レスポンスアクションを有効にします |
| UnBlock Email Address | UnBlock Email Address レスポンスアクションを有効にします |
| UnBlock File Hash | ファイルハッシュに対する UnBlock File Hash レスポンスアクションを有効にします |
| UnBlock IP | IP アドレスに対する UnBlock IP レスポンスアクションを有効にします |
| UnBlock URL | UnBlock URL レスポンスアクションを有効にします |
| UnIsolate Host | ホストに対する UnIsolate Host レスポンスアクションを有効にします |
| Update Investigation with Network Flow Summary | Network Flow Summary で Investigation を更新します |
| Update ServiceNow User | 汎用の ServiceNow ユーザー更新 |
| Update Taegis Investigation | 既存の Taegis Investigation を更新できるようにします |
| xMatters Webhook Alert | Webhook を介して Alert から xMatters イベントをトリガーします |
| xMatters Webhook Investigation | Webhook を介して Investigation から xMatters イベントをトリガーします |
| Zendesk Investigation Sync | XDR Investigation を Zendesk Incident と同期します |