Use the following steps to set up the User Deleting Bash History playbook.
Before you begin
Make sure you have installed Security Operations Spoke (sn_sec_spoke).
Role required:
sn_si.admin
flow_designer
Procedure
Login as a user with sn_si.user and flow_designer roles.
Navigate to All > Flow Designer and select the User Deleting .bash_history - Cloud playbook.
Optional: Create a copy of the User Deleting .bash_history - Cloud playbook flow and make the necessary modifications.
If you plan to customize or make specific changes to the flow, then you must create a copy of the playbook's flow. Select the icon and select Copy flow.
Figure 1. User Deleting Bash History - Cloud playbook
Activate the playbooks.
Activate the main flow to use the playbook available in the base system.
Activate the copied flows after making the required changes.
Set a Trigger Condition for the playbook.
This playbook is triggered and associated with the security incident when the Category is Insider Breach.
Figure 2. User Deleting Bash History - Cloud playbook trigger condition