Skip to main content

Azure Enrichment and Remediation

Download With Dependencies

Playbooks using multiple Azure content packs for enrichment and remediation purposes

What does this pack do?

The pack contains Azure playbooks and scripts that conduct enrichment and/or remediation and can use multiple other Azure
content packs.

There are multiple Azure content packs for multiple Azure products (Compute, MSGraphUsers, etc). The intent was so that
users can install and use only the packs they need. However, if an Azure playbook uses multiple pack integrations (such
as Compute and MSGraphUsers), they can't reside in one of the current packs because they include content from multiple integrations. This pack was created as a place to put Azure playbooks that use Azure integrations from multiple packs with a focus on enrichment and remediation.

Scripts

AzureFindAvailableNSGPriorities

This script takes in a list of numbers that represent Azure priorities for NSG rules, a target priority number, and a number of available priorities to return available priorities from the provided list.

Playbooks

Users are only able to run playbooks in v6.5.0 or higher as it requires commands to execute the task.
This content pack includes the following playbook:

Azure - Enrichment

Azure - Enrichment

Azure - Network Security Group Remediation

Azure - Network Security Group Remediation

Azure - User Investigation

Azure - User Investigation

Cloud Credentials Rotation - Azure

Cloud Credentials Rotation - Azure

Cloud Response - Azure

Cloud Response - Azure

What does this pack do?

The pack contains Azure playbooks and scripts that conduct enrichment and/or remediation and can use multiple other Azure
content packs.

There are multiple Azure content packs for multiple Azure products (Compute, MSGraphUsers, etc). The intent was so that
users can install and use only the packs they need. However, if an Azure playbook uses multiple pack integrations (such
as Compute and MSGraphUsers), they can't reside in one of the current packs because they include content from multiple integrations. This pack was created as a place to put Azure playbooks that use Azure integrations from multiple packs with a focus on enrichment and remediation.

Scripts

AzureFindAvailableNSGPriorities

This script takes in a list of numbers that represent Azure priorities for NSG rules, a target priority number, and a number of available priorities to return available priorities from the provided list.

Playbooks

Users are only able to run playbooks in v6.5.0 or higher as it requires commands to execute the task.
This content pack includes the following playbook:

Azure - Enrichment

Azure - Enrichment

Azure - Network Security Group Remediation

Azure - Network Security Group Remediation

Azure - User Investigation

Azure - User Investigation

Cloud Credentials Rotation - Azure

Cloud Credentials Rotation - Azure

Cloud Response - Azure

Cloud Response - Azure

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedDecember 2, 2022
Last ReleaseSeptember 23, 2024
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise. For more information, see the Marketplace documentation.