Enriching Incidents Using Automation
In the previous chapter, we introduced Microsoft Sentinel automation and its main elements, permissions, and building blocks.
In this chapter, we will work through some hands-on examples. But first, we will guide you on how to enable Microsoft Sentinel to perform these exercises on your own, then we will go through our two hands-on examples – the enrichment of incidents with IP and URL details.
This chapter will go through the following topics:
- Why should you use automation for incident enrichment?
- Creating your own Microsoft Sentinel trail
- VirusTotal playbook – IP enrichment
- VirusTotal playbook – URL enrichment