コンテンツにスキップ

サポートされているプレイブック🔗

注意

各プレイブックには、新しいプレイブックを作成する手順を案内する組み込みのドキュメントがあります。XDRのケーステンプレートまたは設定済みのケースからドキュメントを選択すると、新しいタブで開き、そこで案内に従うことができます。

XDR は、以下を 含むがこれらに限定されない 多数のインテグレーションをサポートしています。

ヒント

最新のプレイブックテンプレート、アクション、コネクターの公開履歴や、既存のテンプレートおよびコネクターの更新情報については、自動化の概要をご覧ください。

Playbook Title Description
4me ITSM Alert XDR アラートに基づいて 4me Problem または Request を作成します
4me ITSM Investigation XDR Investigation に基づいて 4me Problem または Request を作成します
4me ITSM Investigation Sync 4me Problem または Request を Security Response Investigation と同期します
AD Change Password At Log On LDAP(S) プロトコルを使用して AD ユーザーのログオン時パスワード変更を行います
AD Deactivate Change Password At Log On LDAP(S) プロトコルを使用して AD ユーザーのログオン時パスワード変更を無効化します
AD Disable User LDAP(S) プロトコルを使用して AD のユーザーアカウントを無効化します
AD Enable User LDAP(S) プロトコルを使用して AD のユーザーアカウントを有効化します
AD/LDAP Change Password LDAP(S) プロトコルを使用して AD/LDAP ユーザーのパスワードを変更します
AD/LDAP Look Up User LDAP(S) プロトコルを使用して AD/LDAP ユーザーを検索します
Alert Email Notification アラートのメール通知を送信します
Alert Email Notification with Google Gmail Google Gmail API を使用してアラートのメール通知を送信します
Alert ITSM Sync ServiceNow Alert を ITSM Incident と同期します
Alert SIR Sync ServiceNow Alert を Security Incident と同期します
Amazon Web Services Disable User Access Keys Amazon Web Services のユーザーアクセスキーを無効化します
Amazon Web Services Disable User Login 特定のユーザーの AWS Console ログインを無効化します
Amazon Web Services Disable User MFA Devices 特定の AWS ユーザーの MFA デバイスを削除します
Amazon Web Services Enable User Access Keys Amazon Web Services のユーザーアクセスキーを有効化します
Amazon Web Services Enable User Login 特定のユーザーに対して、事前定義されたパスワードで AWS Console の新しいログインプロファイルを作成します
Amazon Web Services Look Up User Amazon Web Services ユーザーを検索します
Amazon Web Services Update IP Set AWS WAF で IP アドレスをブロック/ブロック解除します
Analyze Email Email エンティティのエンリッチメントを有効にします
Automated Action AD Change Password At Log On LDAP(S) プロトコルを使用して、アラートに関連するすべてのユーザーのログオン時パスワード変更を自動的に行います
Automated Action AD Disable User LDAP(S) プロトコルを使用して、アラート内のすべてのユーザーを自動的に無効化します
Automated Action Isolate Host Red Cloak Endpoint Agent Automated Action Isolate Host Red Cloak Endpoint Agent
Automated Action Isolate Host Taegis Agent Automated Action Isolate Host Taegis Agent
Automated Action Microsoft Entra ID Disable User Microsoft Graph API を使用して、アラート内のすべてのユーザーを自動的に無効化します
Automated Action Microsoft Entra ID Force Password Reset Microsoft Graph API を使用して、アラート内のすべてのユーザーに対してパスワードリセットを自動的に強制します
Azure OpenAI Enrich Investigation Azure OpenAI を介して Investigation の主な発見事項をエンリッチメントします
Block Domain Block Domain レスポンスアクションを有効にします
Block Email Address Block Email Address レスポンスアクションを有効にします
Block File Hash ファイルハッシュに対する Block File Hash レスポンスアクションを有効にします
Block IP IP アドレスに対する Block IP レスポンスアクションを有効にします
Block URL Block URL レスポンスアクションを有効にします
Carbon Black EDR - Block Filehash Carbon Black EDR (Endpoint Detection and Response) で Filehash をブロックします
Carbon Black EDR - Unblock Filehash Carbon Black EDR (Endpoint Detection and Response) で Filehash のブロックを解除します
CB Cloud - Isolate VMWare Carbon Black Cloud で隔離します
CB Cloud - Undo Isolate Host VMWare Carbon Black Cloud でホストの隔離を解除します
Change Password Change Password レスポンスアクションを有効にします
Change Password At Next Login Change Password At Next Login レスポンスアクションを有効にします
Change Password At Next Login Google Workspace Admin SDK API Google Workspace Admin SDK API を使用して、ユーザーの次回ログイン時パスワード変更を有効にします
Change Password Google Workspace Admin SDK API Google Workspace Admin SDK API を使用して、ユーザーのパスワードを変更します
Cisco Meraki Activities Cisco Meraki でリソースをブロックおよびブロック解除します
Comments To Email Notification Taegis Investigation のコメントを Email で送信します
Comments To Mattermost Notification Taegis Investigation のコメントを Mattermost に送信します
Comments To Microsoft Teams Notification Taegis Investigation のコメントを Microsoft Teams に送信します
Comments To Salesforce Slack Notification Taegis Investigation のコメントを Salesforce Slack に送信します
Comments To ServiceNow WorkNote Taegis Investigation のコメントを ServiceNow WorkNote に送信します
Confirm User As Compromised ユーザーを侵害済みとして確認します
Cortex XSOAR Investigation Sync XDR Investigation を Cortex XSOAR Incident と同期します
Create Investigations from Alerts アラートから XDR Investigation を作成します
Create ServiceNow User ServiceNow ユーザーを作成します
CrowdStrike Falcon Endpoint - Isolate CrowdStrike Falcon Endpoint Protection で隔離します
CrowdStrike Falcon Endpoint - Undo Isolate CrowdStrike Falcon Endpoint Protection でホストの隔離を解除します
Deactivate Change Password At Next Login Google Workspace Admin SDK API Google Workspace Admin SDK API を使用して、ユーザーの次回ログイン時パスワード変更を無効化します
Deactivate ServiceNow User ServiceNow ユーザーを無効化します
Detonate URL URL をデトネートし、結果をエンリッチメントとして提供します
Disable User ユーザーに対する Disable User レスポンスアクションを有効にします
Dismiss User As Compromised ユーザーの侵害済みステータスを却下します
Enable User ユーザーに対する Enable User レスポンスアクションを有効にします
Endpoint Tagging このプレイブックは、任意の数のエンドポイントにタグを追加/削除するために使用できます。
Endpoint Tagging - Multi 異なる条件で Endpoint Tagging プレイブックを複数回実行できるようにします
Enrich Investigation Investigation のエンリッチメントを有効にします
Entity Enrichment Look Up Asset 資産エンティティのエンリッチメントを有効にします
EverBridge Alert Incident XDR アラートに基づいて EverBridge Incident を作成します
EverBridge Investigation Incident XDR Investigation に基づいて EverBridge Incident を作成します
Freshdesk Investigation Sync Taegis Investigation を Freshdesk Incident と同期します
Freshservice Alert Ticket Taegis Alert に基づいて Freshservice Ticket を作成します
Freshservice Investigation Sync Taegis Investigation を Freshservice Ticket と同期します
Freshservice Investigation Ticket Taegis Investigation に基づいて Freshservice Ticket を作成します
Generic Webhook すべての入力を webhook URL に POST します
Halo ITSM Investigation Synch XDR Investigation を Halo ITSM Incident と同期します
Health Event Investigation Health Event から Taegis Investigation を作成します
Initiate Antivirus Scan on Host ホストでの Antivirus スキャン開始を有効にします
Investigation CrowdStrikeFalcon Incident Sync Investigation を CrowdStrikeFalcon Incident と同期します
Investigation Email Notification Investigation のメール通知を送信します
Investigation Email Notification with Google Gmail Google Gmail API を使用して Investigation のメール通知を送信します
Investigation ITSM Sync ServiceNow Investigation を ITSM Incident に一方向同期します
Investigation Service Now MultiTeam Sync Investigation ServiceNow MultiTeam Sync
Investigation SIR Sync ServiceNow Investigation を Security Incident Response と同期します
Investigation SMAX Sync Taegis Investigation を Microfocus SMAX チケットと同期します
Investigation Translate Comments Investigation のコメントを別の言語に翻訳します
Investigation Translate Key Findings Investigation の主な発見事項を別の言語に翻訳します
Investigations Email Report Taegis Investigation に関するメールレポート
Isolate Host ホストに対する Isolate Host レスポンスアクションを有効にします
Isolate Host Automated Action Isolate Host 自動レスポンスアクション
ITSM Incident Vulnerability XDR 脆弱性に基づいて ServiceNow Incident を作成します
Jira Alert Issue XDR アラートに基づいて Atlassian Jira Issue を作成します
Jira Investigation Issue XDR Investigation に基づいて Atlassian Jira Issue を作成します
Jira Investigation Sync Jira Issue を Security Response Investigation と同期します
Jira Vulnerability Issue XDR 脆弱性に基づいて Atlassian Jira Issue を作成します
JupiterOne Investigation AWS Instance Enrichment JupiterOne の AWS インスタンスコンテキストで Investigation をエンリッチメントします
Look Up Asset Vulnerabilities 資産の脆弱性のエンリッチメントを有効にします
Look Up File Hash File Hash を検索し、結果をエンリッチメントとして提供します
Look Up User ユーザーエンティティのエンリッチメントを有効にします
Look Up User Google Workspace Admin SDK API Google Workspace Admin SDK API を使用してユーザーを検索します
ManageEngine ServiceDesk Plus Alert XDR Alert から ManageEngine Service Desk Plus の Request を作成するために使用されるプレイブック
ManageEngine ServiceDesk Plus Investigation Sync Investigation を ManageEngine Service Desk Plus の Request と同期するために使用されるプレイブック
MD ATP - Block Filehash Globally Microsoft Defender ATP で Filehash をグローバルにブロックします
MD ATP - Host Response Action Microsoft Defender ホストに対してさまざまなレスポンスアクションを実行します
MD ATP - Isolate Host Microsoft Defender ATP でホストを隔離します
MD ATP - Single Endpoint Filehash Block Microsoft Defender ATP で単一エンドポイント上の Filehash をブロックします
MD ATP - Undo Isolate Host Microsoft Defender ATP でホストの隔離を解除します
Microsoft Entra ID Disable User Microsoft Graph API を使用して Microsoft Entra ID ユーザーアカウントを無効化します
Microsoft Entra ID Enable User Microsoft Graph API を使用して Microsoft Entra ID ユーザーアカウントを有効化します
Microsoft Entra ID Force Password Reset Microsoft Graph API を使用して Microsoft Entra ID ユーザーアカウントに対してパスワードリセットを強制します
Microsoft Entra ID Look Up User Microsoft Graph API を使用して Microsoft Entra ID ユーザーを検索します
Microsoft Teams Notification webhook を介して Microsoft Teams 通知を送信します
Notifications via Google Workspace Chat Taegis 通知を Google Workspace Chat webhook に送信します
Okta Look Up User Okta ユーザーを検索します
OpenAI Enrich Investigation OpenAI を介して Investigation の主な発見事項をエンリッチメントします
Opsgenie XDR Alert XDR アラートに基づいて Atlassian Opsgenie Alert または Incident を作成します
Opsgenie XDR Investigation XDR Investigation に基づいて Atlassian Opsgenie Alert または Incident を作成します
PagerDuty Alert Event XDR アラートに基づいて PagerDuty Event を送信します
PagerDuty Investigation Event XDR Investigation に基づいて PagerDuty Event を送信します
PagerDuty Investigation Sync PagerDuty Incident を Security Response Investigation と同期します
Palo Alto Networks PAN-OS Block/Unblock Palo Alto Networks PAN-OS で IP/CIDR または Domain をブロックおよびブロック解除します
RC - Isolate Red Cloak Endpoint Agent で隔離します
RC - Undo Isolate Host Red Cloak Endpoint Agent でホストの隔離を解除します
RC Disable Process Disruption Red Cloak Endpoint Agent で disrupt process (block filehash) ルールを無効化します
RC Process Disruption Red Cloak Endpoint Agent で process disruption (block filehash) を実行します
Reactivate User Google Workspace Admin SDK API Google Workspace Admin SDK API を使用してユーザーを再有効化します
Reset MFA Factors ユーザーに対する Reset MFA Factors レスポンスアクションを有効にします
Revoke User Sign-In Sessions ユーザーに対する Revoke User Sign-In Sessions レスポンスアクションを有効にします
Salesforce Slack Notification Webhook を介して Salesforce Slack 通知を送信します
SCADAfence Platform Investigation Enrichment SCADAfence のアラート/資産詳細で Taegis Investigation をエンリッチメントします
Send Notification Message サポートされているメッセージングプラットフォームに通知メッセージを送信します
SentinelOne - Host Response Actions SentinelOne エージェントに対してさまざまなレスポンスアクションを実行します
SentinelOne - Isolate SentinelOne で隔離します
SentinelOne - Undo Isolate Host SentinelOne でホストの隔離を解除します
SentinelOne Threat Mitigation Response Actions Taegis Alert に対して Threat Mitigation レスポンスアクションを実行します
ServiceNow Bidirectional Investigation Sync (Inbound) Servicenow から提供されたデータに基づいて Taegis Investigation を更新します
ServiceNow Bidirectional Investigation Sync (Outbound) Import Sets を利用して Investigation を Servicenow と同期します
Suspend User Google Workspace Admin SDK API Google Workspace Admin SDK API を使用してユーザーを停止します
Sync Alert サードパーティのアラートを XDR と同期します
Taegis Agent - Isolate Taegis Agent で隔離します
Taegis Agent - Restore Taegis Agent の隔離を解除します
Taegis NDR Block Taegis NDR デバイス上で特定の IP アドレスをブロック (shun) します
Taegis NDR Firewall Modification Taegis NDR ファイアウォール関連のさまざまなアクションを実行します
Taegis NDR Unblock Taegis NDR デバイス上で特定の IP アドレスのブロックを解除 (unshun) します
UnBlock Domain UnBlock Domain レスポンスアクションを有効にします
UnBlock Email Address UnBlock Email Address レスポンスアクションを有効にします
UnBlock File Hash ファイルハッシュに対する UnBlock File Hash レスポンスアクションを有効にします
UnBlock IP IP アドレスに対する UnBlock IP レスポンスアクションを有効にします
UnBlock URL UnBlock URL レスポンスアクションを有効にします
UnIsolate Host ホストに対する UnIsolate Host レスポンスアクションを有効にします
Update Investigation with Network Flow Summary Network Flow Summary で Investigation を更新します
Update ServiceNow User 汎用の ServiceNow ユーザー更新
Update Taegis Investigation 既存の Taegis Investigation を更新できるようにします
xMatters Webhook Alert Webhook を介して Alert から xMatters イベントをトリガーします
xMatters Webhook Investigation Webhook を介して Investigation から xMatters イベントをトリガーします
Zendesk Investigation Sync XDR Investigation を Zendesk Incident と同期します