Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up

Report to IR Case — Automated Promotion

Incident Management
Incident Response & Ticketing
A picture of RG9jdW1lbnQ6NzMxNzAzOTYtZDY3NC00NTQ5LThjNmMtMWE4ZmM0NTIxNGZh

Overview

Automatically promotes all the details of a report to a Incident Response Case

Overview

This playbook automatically promotes a labelled Report into an Incident Response (IR) Case. When a designated label is applied to a Report, the playbook updates the Report's workflow status, resolves its contents, and wraps them into an IR Case. It is intended for SOC or CTI teams who use Reports as a staging area before escalating to active incident response workflows.


Dependencies

  • A label must exist in the platform to act as the IR promotion trigger.
  • A workflow status named "Moved to IR Case" (or equivalent) must exist for the Report entity type before activation.
  • No connectors or external integrations are required.

How to Use It

  1. Import the playbook JSON file via Automations → Playbooks → Import.
  2. Open the Listen for Labelled Report Updates node and select the label that should trigger IR promotion.
  3. Open the Update Report Workflow Status node and select the workflow status to apply when a Report is promoted.
  4. Save all node configurations and activate the playbook.

Expected Outcome

Once active, any Report updated with the trigger label will be processed automatically.

StepWhat happens
TriggerReport update event detected — trigger label is present
Update Report Workflow StatusReport workflow status updated to "Moved to IR Case"
Resolve Report ContentsAll objects contained in the Report are resolved
Wrap Contents into IR CaseResolved objects are added to an IR Case
Send to KnowledgeIR Case and contents ingested into the platform

Note: The Container Wrapper is configured to add contents to an existing IR Case rather than create a new one.


Trigger Behaviour

The playbook fires on Report update events only, not on creation. This is intentional — the expected workflow is that the trigger label is applied to an existing Report, which fires the update event and starts the playbook.


Manual Enrolment

The playbook supports manual enrolment, allowing it to be run against existing Reports directly from the platform UI without waiting for an update event.

Basic information

Filigran
Toby Butler
June 19, 2026
10+
1

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".