Hi Kyle,
I'm not sure if this is the best way to do it, but I'll share how we did it...
If you are using an integration/code, you can use the following API call:
confirm = self.rest_client().get("/types/actioninvocation/fields/field_api_name")
Then you can write an if statement based on the value of the variable (in this case confirm):
if confirm:
else:
I do not know if there is a way to get those fields in the in-product scripting although I would LOVE to know if it was possible.
Hope this helps!
Adina
------------------------------
Adina Bodkins
------------------------------
Original Message:
Sent: Tue February 04, 2020 12:40 PM
From: Kyle Cisco
Subject: Confirm Manual Actions
All,
Thanks for the suggestions! I ended up trying the Rule activity fields and created a "confirm Escalation" select field.
While it does provide a nice popup to have the analyst confirm an action, even if they select "No", the action still executes.
If there is a way to reference those fields in a script or workflow that would be great! Otherwise, I think Brendon's HTML block solution should suffice.
Thanks all!
Kyle
------------------------------
Kyle Cisco
Original Message:
Sent: Mon February 03, 2020 12:46 PM
From: Brenden Glynn
Subject: Confirm Manual Actions
You could also add a HTML Block in the Activity Field section of the Rule, with a description of what you're asking the user to do, in the case confirm that they wish to trigger the action.
------------------------------
Brenden Glynn
CISSP, GCIH
Incident Response Business Consultant
IBM Resilient
Original Message:
Sent: Mon February 03, 2020 09:00 AM
From: Adina Bodkins
Subject: Confirm Manual Actions
Hi Kyle,
We had a similar scenario and the way we dealt with it was by creating activity fields that asked the analyst a Yes or No question (Did you confirm that this is the right machine? It's not affecting business or whatnot). Then when the analyst would hit the manual action button they would get a pop up with these questions that they would have to answer before hitting submit.
In our code we didn't end up doing anything with the answers to the questions, it was more for the analyst to make sure that they hadn't made a mistake but technically you can have additional controls in place if needed based on their answer.
You can find the activity fields underneath the destinations box in a manual rule. You'll have to click the link to show the activity fields, then it's just drag and drop.
Hope this helps!
Adina
------------------------------
Adina Bodkins
Original Message:
Sent: Fri January 31, 2020 10:03 AM
From: Kyle Cisco
Subject: Confirm Manual Actions
Hi Resilient Community,
Anyone know of a way to present a confirmation to an analyst before performing a manual action? We have a number of menu action items, some of which are escalation buttons. We have seen they can be misclicked by accident. Granted in this situation that's not a huge deal, however if the button was designed to do much more, such as a network block, or a device quarantine, it can have higher ramifications. A confirmation prompt with a tooltip would be useful in these situations.
Thanks,
------------------------------
Kyle Cisco
------------------------------