Azure-Sentinel/Playbooks/Get-SOCActions
NikTripathi ba27997850
Merge pull request #4182 from rinure-msft/patch-2
Update readme.md
2022-04-04 11:11:56 +05:30
..
azuredeploy.json Update playbook trigger names 2022-02-22 17:02:56 +02:00
readme.md Update readme.md 2022-03-31 15:20:52 -06:00

readme.md

Get-SOCActions

author: Rin Ure

This playbook will provide users with Recommended SOC Actions using a .csv file that they upload into a WatchList and give it the the Alias of "SocRA". This also contains steps an Analyst should consider taking when an Analytic Detection has not been onboarded to the WatchList .csv file.

Deploy to Azure

Deploy to Azure Gov