Actions56
- Acquisition Actions
- Asset Actions
- Baseline Actions
- Case Actions
- InterACT Actions
- Organization Actions
- Repository Actions
- Task Actions
- Triage Rule Actions
- User Actions
Triage Rule → Assign Triage Task
AI-generatedOverview
This node operation assigns triage tasks to a specified case using selected triage rules. It is useful in incident response workflows where tasks need to be allocated based on predefined triage rules to streamline case management and investigation processes. For example, security analysts can automate task assignments for cases by specifying triage rule IDs and configuring task options such as enabling the MITRE ATT&CK framework.
Use Case Examples
- Assign triage tasks to a case by providing the case ID and a list of triage rule IDs to automate task distribution.
- Use the task choice option to select between automatic or manual task assignment.
- Filter endpoints by various criteria such as group, IP address, isolation status, and more to refine task assignment scope.
Properties
| Name | Meaning |
|---|---|
| Case ID | ID of the case to assign the triage task to, required for identifying the target case. |
| Triage Rule IDs | Comma-separated list of triage rule IDs to assign, specifying which triage rules to apply for task assignment. |
| Task Choice | Task configuration choice between automatic or manual assignment of tasks. |
| Enable MITRE ATT&CK | Boolean flag to enable or disable the MITRE ATT&CK framework integration for the task assignment. |
| Additional Fields | Optional filters and parameters to refine the task assignment, including endpoint IDs, group filters, IP address, isolation status, issue, managed status, name, online status, organization, platform, policy, tags, version, and search term. |
Output
JSON
assignedTasks- Details of the tasks assigned to the case based on the triage rules and filters applied.
Dependencies
- An API key credential for authenticating with the Binalyze AIR API
Troubleshooting
- Ensure the Case ID and Triage Rule IDs are correctly provided and valid; missing or incorrect IDs will cause assignment failure.
- Verify that the API credentials are correctly configured and have sufficient permissions to assign triage tasks.
- Check that the filters in Additional Fields are correctly formatted; invalid filter values may result in no tasks being assigned or errors.
- Common error messages may include 'Unknown resource' if the resource parameter is incorrect, or API errors related to authentication or invalid parameters.