Featured Playbook: Enhancing XDR Incident Management
Introduction
The new Cortex XDR Lite Incident Handling playbook is a streamlined incident response solution that eliminates manual tasks associated with the enrichment, investigation, and resolution of Cortex XDR incidents ingested into XSOAR. This playbook is easily deployed and requires no additional integrations, making it a valuable addition to your security arsenal. It can significantly reduce the time your analysts spend remediating XDR incidents, allowing them to focus on more critical tasks.
To activate the Cortex XDR Lite Incident Handling playbook, simply fetch a Palo Alto Networks Cortex XDR incident and let the playbook handle the rest. It includes sub-playbooks and tasks that automate the investigation process, making it easier for analysts to identify and resolve threats.
Workflow
The Cortex XDR Lite Incident Handling playbook begins by fetching Cortex XDR incidents from the Palo Alto Networks Cortex XDR – Investigation and Response integration. This triggers the playbook to process each incident individually.
The first step involves retrieving relevant data fields for the specific incident, including a list of alerts comprising multiple events, alerts, and key artifacts. This data provides essential information for the incident investigation process.
Enrichment
Next, the playbook leverages the Entity Enrichment Generic v3 sub-playbook to enhance the retrieved data. This involves enriching all entities associated with the incident using available products within the environment. This enrichment process expands the context and insights available to analysts, enabling them to gain a deeper understanding of the incident.
Investigation
To assist analysts in their investigation, the playbook employs the Command-Line Analysis sub-playbook to scrutinize command line activity and determine if it exhibits malicious or suspicious behavior. This analysis is based on identifying the following characteristics:
- The use of AMSI techniques (Anti-Malware Scan Interface)
- The presence of suspicious parameters
- The execution of malicious tools
- Indications of network activity
- Evidence of suspicious LOLBIN (Living off the land binaries) execution
- Indicators embedded within the command line
The playbook also utilizes the Cortex XDR – Get entity alerts by MITRE tactics sub-playbook to search for XDR-related alerts with a medium severity or higher. This search focuses on MITRE ATT&CK tactics that are indicative of malicious activity performed on the endpoint or by the user. These insights further enhance the playbook’s ability to identify and prioritize potential threats.
Verdict
Based on the comprehensive analysis and investigation conducted by the playbook, the incident severity is determined by analyzing several factors:
- Indicator enrichment data: The playbook assesses the gathered data to identify potential indicators of malicious activity.
- User and host risk levels: The playbook considers the risk levels associated with the user and the endpoint to assess the overall threat posture.
- Command line analysis verdict: The outcome of the command line analysis is factored in to determine if the incident involves suspicious or malicious command-line usage.
- Number of related XDR alerts: The playbook examines the number of XDR alerts related to the incident, focusing on those with a medium severity or higher and mapping them to MITRE ATT&CK tactics.
If the playbook’s analysis does not conclusively determine the incident’s malicious nature, an analyst must review all the gathered evidence and insights presented in the layout to make an informed assessment.
Response Actions
If the playbook determines that the incident is malicious, it will initiate remediation actions. These actions may include isolating the affected endpoint from the network and blocking all indicators associated with the incident. The playbook can perform these actions either manually or automatically using the Block Indicators – Generic v3 sub-playbook. Once the remediation phase is complete, the playbook will close the incident.
If the incident is deemed to be benign, the playbook will simply close the incident without taking any further action.
The Layout
The Cortex XDR Lite Incident Handling playbook includes a comprehensive layout that presents all relevant information about the incident, from its initial detection to the final resolution. It provides a centralized location where analysts can access incident details, analysis findings, and the final verdict, facilitating informed decision-making. Additionally, the layout features convenient remediation buttons that enable quick and efficient manual actions.
The Incident Info tab serves as a central hub for essential information about the incident. It includes details such as the case details, entity information (user and endpoint information), the incident timeline, the assigned analyst, the alerts associated with the incident, whether any tasks require manual input, the reason for incident closure, and buttons for quick actions related to the incident. This consolidated view provides analysts with a holistic understanding of the incident and streamlines the incident resolution process.
The Investigation Results tab serves as a repository for all information gathered during the incident investigation process. It includes the incident verdict, summarizing the findings that led to the classification of the incident as either malicious or benign. Additionally, it presents the investigation results, providing a detailed breakdown of the analysis and evidence that supported the incident verdict. This tab also displays any XDR-related alerts associated with MITRE ATT&CK tactics, highlighting potential malicious activity linked to the user or endpoint. Finally, it lists all the indicators associated with the incident, providing analysts with a concise overview of the potential threats identified.
Conclusion
Managing and responding to Cortex XDR incidents is now more streamlined than ever with the “Cortex XDR Lite – Incident Handling” playbook. This playbook eliminates the need for additional integrations, making it easy to deploy and use. Simply install the Cortex XDR content pack from our Cortex Marketplace, and you’ll be equipped to handle Cortex XDR incidents with ease.







































