Skip to main content

Create Intezer Case from Trigger Alert - Workflow Template

Receives alerts from Intezer Trigger and creates a case via a field mapper. It adds Quick Actions notes and an Initial Runbook.

Updated over 3 months ago

The "Create Intezer Case from Trigger Alert" workflow automates the incident response for initial triage alerts. Initiated by Intezer Trigger, the workflow swiftly creates a Torq case enriched with predefined custom fields and observables derived from a comprehensive JSON alert analysis. This is achieved via a nested workflow that meticulously processes the raw alert data, ultimately offering a structured case format for more efficient handling. Based on alert recommendations, relevant quick actions are selected to enhance the case, while a key note is added summarizing the alert insights. The workflow also leverages AI to concisely synthesize triage data and seamlessly attaches an initial runbook, providing clear guidance for the next steps in the case management process.

Trigger

Use Cases

Case Management

Workflow Breakdown

  1. Workflow will trigger for 'initial_triage' alerts.

  2. Creates a case, populating it with custom fields and observables via a nested workflow that processes the raw JSON alert.

  3. Defines wich quick action should be added to the case based on alert recommendations.

  4. Adds alert note as a key note for the case.

  5. Uses AI Task to summarize triage data.

  6. Attaches an Initial Runbook to the case

Vendors

Utils, Torq Cases

Tips

  • Define Quick Action workflows to be associated with the case based on alert recommendations.

Did this answer your question?