Azure-Sentinel/Playbooks/Watchlist-InformSubowner-In...
Lior Tamir aad48299ca Update playbook trigger names 2022-02-22 17:02:56 +02:00
..
images Fix Watchlists-InformSubOwner 2020-11-08 18:43:20 +02:00
azuredeploy.json Update playbook trigger names 2022-02-22 17:02:56 +02:00
readme.md Updating Deploy buttons and links part 2 2021-06-16 01:40:49 +00:00

readme.md

Watchlists-InformSubowner-IncidentTrigger

author: Lior Tamir

This playbook levarages Azure Sentinel Watchlists in order to get the relevant subscription owner contact details, and inform about an ASC alert that occured in that subscription. It uses Microsoft Teams and Office 365 Outlook as ways to inform the sub owner.

Note: This playbook utilizes two features currently in Preview.

  • Azure Sentinel Watchlists
  • Azure Sentinel Incident Trigger



Deploy to Azure Deploy to Azure Gov