This app implements various incident management and investigative actions
Supported Actions
- test connectivity: Validate the asset configuration for connectivity using supplied configuration
- on poll: Ingest from Preempt
- get user attributes: Gets the attributes of a user
- get user risk: Gets the risk of a user
- watch user: Watch a user
- unwatch user: Stop watching a user
- get incident: Get information about an incident
- update incident: Update the incident state and/or add a comment to the incident
- get user activity: Get user activity from the specified number of hours ago