Details

This atomic belongs to the Cisco XDR: Investigate atomic group.

Uses the Cisco XDR API to collect information about the given observables from all configured integrations. This atomic supports enriching a single observable or a JSON-formatted list of observables.

Target: Platform APIs

Steps:
[] Generate the observable JSON
[] Request enrichment information from Cisco XDR
[] Check if the request was successful:
[]> If it was, set the output variable
[]> If it wasn't, return an error

More information about this API: https://developer.cisco.com/docs/cisco-xdr/enrich-observables/

About
Authorship
Cisco Managed