Automation Integration
Microsoft Sentinel workbooks provide a powerful way to structure threat hunting workflows, but their true potential is unlocked when integrated with automation. By linking workbooks to alerts and playbooks, analysts can automate triage, response, and remediation processes, reducing manual effort and ensuring consistent handling of threats. This section demonstrates how to connect workbooks to automation mechanisms within Microsoft Sentinel.
Linking Workbooks to Alerts¶
When a workbook is tied to an alert, it automatically triggers the workbook's analysis steps whenever the alert is created. This is ideal for scenarios where initial investigation is required to validate or escalate a potential threat.
Example: Triggering a Workbook via an Alert Rule¶
- Create an alert rule in Microsoft Sentinel that uses a KQL query to detect suspicious activity (e.g., unusual login patterns).
- Link the workbook to the alert rule by specifying the workbook's name and parameters.
KQL Example for Alert Rule:
SecurityEvent
| where EventID == 4624
| where AccountType == "User account"
| where AccountName != "Administrator"
| where SourceIP in (iprange("192.168.0.0/16", "10.0.0.0/8"))
| project TimeGenerated, Computer, AccountName, SourceIP
| summarize count() by Computer, AccountName, SourceIP
| where count_ > 5
Workbook Trigger Configuration:
- In the alert rule, set the Trigger action to "Run workbook".
- Specify the workbook name (e.g., ThreatHuntingWorkbook) and pass relevant parameters (e.g., Computer, AccountName).
This setup ensures the workbook opens automatically when the alert is created, pre-populating context for analysis.
Linking Workbooks to Playbooks¶
Playbooks in Microsoft Sentinel automate response actions (e.g., isolating a host, collecting logs). By embedding playbook calls within workbooks, analysts can execute predefined remediation steps with a single click.
Example: Invoking a Playbook from a Workbook¶
- Define a playbook (e.g.,
Microsoft Defender for Cloud - Remediate Compromised VM) that contains actions like stopping a VM or collecting forensic data. - Add a "Run playbook" action to the workbook.
Workbook Action Example:
{
"action": "Run playbook",
"playbookName": "Microsoft Defender for Cloud - Remediate Compromised VM",
"parameters": {
"vmName": "@{activity('Get_VM_Details').output.vmName}",
"reason": "Suspicious activity detected in workbook"
}
}
This example uses parameters from earlier steps in the workbook to dynamically pass values to the playbook. The playbook then executes its predefined actions, such as isolating the VM or triggering log collection.
Best Practices for Integration¶
- Parameterize inputs: Use dynamic variables from alerts or previous workbook steps to make automation context-aware.
- Validate workflows: Test workbook-playbook integrations in a sandbox environment before deploying to production.
- Monitor outcomes: Track playbook execution results and adjust workflows based on real-world feedback.
Key takeaways¶
- Automate triage: Link workbooks to alerts to streamline initial investigation and reduce manual steps.
- Standardize responses: Use playbooks to enforce consistent remediation actions across threats.
- Leverage context: Pass dynamic parameters from alerts or workbook steps to ensure automation is targeted and efficient.
- Iterate and refine: Continuously validate and improve workflows to adapt to evolving threats.