OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ

Report to IR Case — Automated Promotion

Incident Management
Incident Response & Ticketing
A picture of RG9jdW1lbnQ6NzMxNzAzOTYtZDY3NC00NTQ5LThjNmMtMWE4ZmM0NTIxNGZh

概要

Automatically promotes all the details of a report to a Incident Response Case

Overview

This playbook automatically promotes a labelled Report into an Incident Response (IR) Case. When a designated label is applied to a Report, the playbook updates the Report's workflow status, resolves its contents, and wraps them into an IR Case. It is intended for SOC or CTI teams who use Reports as a staging area before escalating to active incident response workflows.


Dependencies

  • A label must exist in the platform to act as the IR promotion trigger.
  • A workflow status named "Moved to IR Case" (or equivalent) must exist for the Report entity type before activation.
  • No connectors or external integrations are required.

How to Use It

  1. Import the playbook JSON file via Automations → Playbooks → Import.
  2. Open the Listen for Labelled Report Updates node and select the label that should trigger IR promotion.
  3. Open the Update Report Workflow Status node and select the workflow status to apply when a Report is promoted.
  4. Save all node configurations and activate the playbook.

Expected Outcome

Once active, any Report updated with the trigger label will be processed automatically.

StepWhat happens
TriggerReport update event detected — trigger label is present
Update Report Workflow StatusReport workflow status updated to "Moved to IR Case"
Resolve Report ContentsAll objects contained in the Report are resolved
Wrap Contents into IR CaseResolved objects are added to an IR Case
Send to KnowledgeIR Case and contents ingested into the platform

Note: The Container Wrapper is configured to add contents to an existing IR Case rather than create a new one.


Trigger Behaviour

The playbook fires on Report update events only, not on creation. This is intentional — the expected workflow is that the trigger label is applied to an existing Report, which fires the update event and starts the playbook.


Manual Enrolment

The playbook supports manual enrolment, allowing it to be run against existing Reports directly from the platform UI without waiting for an update event.

基本情報

Filigran
Toby Butler
2026年6月19日
10+
1

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。