Creating Automated Tasks

You can create your own automated tasks. A task consists of the following:

  • Trigger—a starting point of an automated task. An observable in an investigation can be a trigger.

  • Actions—checks and transformations that will be done on a trigger for more detailed analysis. An enrichment in an investigation can be an action.

Each automated task has one trigger and can have up to 20 actions.

To create an automated task:

  1. Navigate to ThreatStream > ManageTask Automation.

  2. Click New in the upper-right corner.

  3. In the Details pane, do the following:

    1. Specify the Name and Description of the automated task.

    2. Select a Visibility setting for the automated task. By default, the automated task is visible only to you. You can expand visibility to all users in your organization (My Organization).

      Note: Anomali recommends setting the Visibility to Me until the automated task is ready to be shared with your organization.
    3. To make the automated task available in investigations, switch User Enabled on.

  4. In the Triggers pane, click Add Trigger, and then in the Edit Trigger dialog box, do the following:
    1. Leave Trigger Type set to Investigation Node.

    2. In Observable Type, select the type of the observables for which the automated task will be available.

      For example, if you set up the Domain observable type as a trigger for the automated tasks, you cannot apply this task in investigations for the other observable types.

    3. Click OK.

  5. In the Actions pane, click Add Actions, and then in the Add Action dialog box, do the following:

    1. Leave Action Type set to Enrichment.

    2. In Enrichment, select the enrichment, which you want to use in the investigation.

    3. In Enrichment Actions, select the action, which you want to apply to the observable under investigation.

      Note: Available actions depend on the observable type that you have selected as a trigger and the enrichments that are active in your organization.
    4. In Observable Type, select one or more observable types that will be the output of the automated task.

    5. Click OK.

      The first action is added, and now you can proceed with adding the next action.

      Note: You can add up to 20 actions in one automated task.
  6. Once you have added all necessary actions, click Save.

Your automated task is created, and it is available in the list of automated tasks on the Manage > Task Automation page.