Create Lookup Request for IoC Changes workflow
The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by a business rule to run automatically when an IoC is added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.
시작하기 전에
Role required: sn_si.basic
이 태스크 정보
If the IoC is empty, the workflow does not run. Historical scans are retained and viewable in the Security Scan Requests tab and worknotes of the security incident. The existing security incidents are automatically updated.
중요사항:
The Security Incident Response - Create Lookup Request for IoC Changes workflow is migrated to the Flow Designer. The flow gets triggered only when the sn_ti_scanner has at least one record.
The Flow Designer actions include:
- Audit Log Enrichment
- Create IoC Lookup Request activity