You are creating a playbook to respond to user phishing reports at your company. You configured a UDM query action to find every user who connected to a malicious domain. You need to extract those users from the UDM query and add them as entities in an alert so that the playbook can reset their passwords. You want to minimize SOC analyst effort. What should you do?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion