Security Operations orchestration activities Release version: Washingtondc Updated February 1, 2024 1 minute to readMany activities are included with Security Operations for use in workflows. Create Enrichment Data records Flow ActionThe Create enrichment data records flow action creates or updates enrichment records to use in the flow.Create Compliance Search ActionThe Create Compliance Search action creates a compliance search for emails in the designated Exchange server(s) using the search queries defined and returns the name of compliance search created.Get IP from CI activityThis workflow activity determines the IPV4 address associated with a configuration item (CI).Get Network Statistics via netstat Flow ActionThe Security Common Orchestration - Get Network Statistics via netstat flow action retrieves the network statistics for an affected resource on a Windows-based system. This flow action can accelerate the investigation and remediation process.Get running processes via WMI activityTheGet Running Processes workflow activity retrieves the running processes of a configuration item on a Windows-based system. This activity can accelerate the investigation and remediation process.Check Compliance Search Status ActionThe Check Compliance Search Status action check the status of created compliance search on exchange server and if the status is completed return the information regarding email search found for the compliance search.Update Task Worknotes activityThe Security Common Orchestration - Update Task Worknotes workflow activity updates the Activity section (work notes) of a task record. This is useful for logging information.Roll up lookup info to security incident activityThe Roll up lookup info to security incident activity can be used with any workflow to gather information from a threat lookup and output a summary of the contents as well as the ID of the originating security incident in task work notes.Write content to record as attachment actionThis action writes the content passed in from an input and creates a designated attachment to a given record.Related conceptsSecurity Operations orchestration workflows
Security Operations orchestration activities Release version: Washingtondc Updated February 1, 2024 1 minute to readMany activities are included with Security Operations for use in workflows. Create Enrichment Data records Flow ActionThe Create enrichment data records flow action creates or updates enrichment records to use in the flow.Create Compliance Search ActionThe Create Compliance Search action creates a compliance search for emails in the designated Exchange server(s) using the search queries defined and returns the name of compliance search created.Get IP from CI activityThis workflow activity determines the IPV4 address associated with a configuration item (CI).Get Network Statistics via netstat Flow ActionThe Security Common Orchestration - Get Network Statistics via netstat flow action retrieves the network statistics for an affected resource on a Windows-based system. This flow action can accelerate the investigation and remediation process.Get running processes via WMI activityTheGet Running Processes workflow activity retrieves the running processes of a configuration item on a Windows-based system. This activity can accelerate the investigation and remediation process.Check Compliance Search Status ActionThe Check Compliance Search Status action check the status of created compliance search on exchange server and if the status is completed return the information regarding email search found for the compliance search.Update Task Worknotes activityThe Security Common Orchestration - Update Task Worknotes workflow activity updates the Activity section (work notes) of a task record. This is useful for logging information.Roll up lookup info to security incident activityThe Roll up lookup info to security incident activity can be used with any workflow to gather information from a threat lookup and output a summary of the contents as well as the ID of the originating security incident in task work notes.Write content to record as attachment actionThis action writes the content passed in from an input and creates a designated attachment to a given record.Related conceptsSecurity Operations orchestration workflows