A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change results in two critical issues:
• Rate limits being hit on integrated reputation services
• Incidents associated with hundreds of indicators
Given the settings below, what would prevent the issues in this use case?
Incident Type: AD-Analysis –
Extract Indicators on Incident Creation: Use System Default (None)
Extract Indicators on Field Change: Inline
Task 1: ad-get-user –
Mark results as note: False –
Indicator Extract Mode: Inline –
Quiet Mode: False –
Task 2: ad-disable-account –
Mark results as note: True –
Indicator Extract Mode: None –
Quiet Mode: True –
Task 3: servicenow-update-ticket –
Mark results as note: False –
Indicator Extract Mode: Use System Default
Quiet Mode: False
Submit