briandelmsft / SentinelAutomationModules

The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel
MIT License
212 stars 58 forks source link

[Feature] Add Incidient Tasks Support - RunPlaybook Module #369

Closed briandelmsft closed 1 year ago

briandelmsft commented 1 year ago

Add incident tasks support to module

briandelmsft commented 1 year ago

@piaudonn what's your opinion of giving an option for a task in the scoring module? I'm leaning towards thinking it's not necessary, the only use I would think it having a task for the analyst to validate that that playbook ran successfully.