Nebula has pre-built Playbooks for you to add to your Palo Alto Networks Cortex™ XSOAR console. Add these Playbooks to your console and use them as a template to create a custom Playbook.
This article details each of the Playbooks, and the incident and endpoint parameters available to you.
Add Nebula Playbooks
- Log into your Cortex XSOAR console.
- From the navigation pane, click Playbooks.
- In the search bar, search for Malwarebytes.
- Select one of the following Playbooks:
- Malwarebytes - Isolate Endpoints: This Playbook automates the network, process, and desktop isolation of Nebula endpoints. When you run this playbook on an incident, the playbook first checks if Nebula integration is enabled, then checks and validates the endpoint info. Then the playbook isolates the endpoint based on network, process, and desktop. Each of these three isolation types are verified, and the playbook will run again if any of them fail verification. Note: An active Endpoint Detection and Response subscription is required to run this playbook.
- Malwarebytes - Scan & Remediate Endpoints: This Playbook automates the scan and remediation of Nebula endpoints. When you run this playbook on an incident, the playbook checks the endpoint data such as IP address and hostname, begins a scan, and checks the job status before reporting detection results to Cortex XSOAR.
The following two sections show you where to find local Nebula parameters, and where you can find global parameters you can use for other integrations.
Find incident parameters
- In a new tab, log into Cortex XSOAR.
- In the navigation pane, click Incidents.
- Click the ID of a Nebula incident to expand the incident details.
- At the top-right, click the vertical ellipses drop down menu.
- From the drop down, select Context Data. This slides out the Context Data window.
- In the Context Data menu, click incident to expand the details of this incident.
- Scroll down and click labels to find Nebula parameter values you can use for your Nebula Playbooks.
Find endpoint parameters
Nebula provides endpoint device data which you can use for other integrations. To find this information:
- In the navigation pane, click Incidents.
- Click the ID of a Nebula incident to expand the incident details.
- At the top-right, click the vertical ellipses drop down menu.
- From the drop down, select Context Data. This slides out the Context Data window.
- In the Context Data window, click Endpoint to expand device data for the endpoint.
Return to the table of contents.