XTM Hub by Filigran

Report to IR Case — Automated Promotion

Detection & Response Enablement
A picture of RG9jdW1lbnQ6NzMxNzAzOTYtZDY3NC00NTQ5LThjNmMtMWE4ZmM0NTIxNGZh

Aperçu

Automatically promotes all the details of a report to a Incident Response Case

Overview

This playbook automatically promotes a labelled Report into an Incident Response (IR) Case. When a designated label is applied to a Report, the playbook updates the Report's workflow status, resolves its contents, and wraps them into an IR Case. It is intended for SOC or CTI teams who use Reports as a staging area before escalating to active incident response workflows.


Dependencies

  • A label must exist in the platform to act as the IR promotion trigger.
  • A workflow status named "Moved to IR Case" (or equivalent) must exist for the Report entity type before activation.
  • No connectors or external integrations are required.

How to Use It

  1. Import the playbook JSON file via Automations → Playbooks → Import.
  2. Open the Listen for Labelled Report Updates node and select the label that should trigger IR promotion.
  3. Open the Update Report Workflow Status node and select the workflow status to apply when a Report is promoted.
  4. Save all node configurations and activate the playbook.

Expected Outcome

Once active, any Report updated with the trigger label will be processed automatically.

StepWhat happens
TriggerReport update event detected — trigger label is present
Update Report Workflow StatusReport workflow status updated to "Moved to IR Case"
Resolve Report ContentsAll objects contained in the Report are resolved
Wrap Contents into IR CaseResolved objects are added to an IR Case
Send to KnowledgeIR Case and contents ingested into the platform

Note: The Container Wrapper is configured to add contents to an existing IR Case rather than create a new one.


Trigger Behaviour

The playbook fires on Report update events only, not on creation. This is intentional — the expected workflow is that the trigger label is applied to an existing Report, which fires the update event and starts the playbook.


Manual Enrolment

The playbook supports manual enrolment, allowing it to be run against existing Reports directly from the platform UI without waiting for an update event.

Informations de base

Filigran
Toby Butler
24 août 2026
10+
1

    Nous utilisons des cookies pour assurer le fonctionnement de XTM Hub. Les cookies nécessaires sont toujours activés ; les cookies facultatifs (fonctionnels, d'analyse, de marketing) ne sont utilisés qu'avec votre consentement. Vous pouvez accepter tous les cookies, les refuser tous ou gérer vos préférences à tout moment dans la rubrique « Paramètres des cookies ».