← Files CrowdStrike Falcon FusionARCHIVED FILE
skills/authoring/examples/identity-response/identity-detection-auto-resolution.yaml
2.97 KB · Oct 5, 2026 · 18:32 UTC
# Example: Identity Detection Auto-Resolution (Recent Password Change)
# Category: identity-response
# Source: CrowdStrike Content Library
name: Identity Detection Auto-Resolution - Recent Password Change
description: 'This workflow automatically resolves Identity Protection Password Brute Force detections when the involved user has recently changed their password within 30 minutes of the detection trigger time. The logic assumes that recent password changes indicate legitimate user activity, making the alert a likely false positive.
Note: The 30-minute time window can be customized based on your organization''s needs'
trigger:
next:
- detection_name_includes_password_brute_force_attack_active_d
name: Detection > Identity Detection
event: Investigatable/IDP
type: Signal
version_constraint: ~0
actions:
add_comment_to_alert_d0f89df5:
id: 7b77cb5d5ff2651cc51c7c4c610d54d1
name: Add comment to detection
version_constraint: ~0
properties:
_fields:
- ${get_user_identity_context_36d2cf6c.EntityName}
- ${get_user_identity_context_36d2cf6c.PasswordChange}
comment: 'Detection auto-resolved: user changed password shortly before detection triggered'
investigatable_id: ${Trigger.Category.Investigatable.InvestigatableID}
get_user_identity_context_36d2cf6c:
id: 19c7e2af0a24f468be7797fe180c8329
name: Get user identity context
version_constraint: ~1
next:
- cs_timestamp_parse_data_trigger_category_investigatable_prod
properties:
continue_if_entity_not_found: false
entity_sid: ${Trigger.Category.Investigatable.Product.IDP.SourceAccountObjectSid}
username: ${Trigger.Category.Investigatable.Product.IDP.SourceAccountName}
set_alert_status_0e01213e:
id: beb56cc40d334583671ca91e6e390056
name: Set detection status
next:
- add_comment_to_alert_d0f89df5
properties:
investigatable_id: ${Trigger.Category.Investigatable.InvestigatableID}
status: closed
conditions:
cs_timestamp_parse_data_trigger_category_investigatable_prod:
next:
- set_alert_status_0e01213e
cel_expression: cs.timestamp.parse(data['Trigger.Category.Investigatable.Product.IDP.EndTime'], 'RFC3339') - cs.timestamp.parse(data['get_user_identity_context_36d2cf6c.PasswordChange'], 'RFC3339') < duration('30m')
display:
- cs.timestamp.parse(data['Trigger.Category.Investigatable.Product.IDP.EndTime'], 'RFC3339') - cs.timestamp.parse(data['activity_36d2cf6c-0585-4be2-8713-03ec9642dc92.PasswordChange'], 'RFC3339') < duration('30m')
detection_name_includes_password_brute_force_attack_active_d:
next:
- get_user_identity_context_36d2cf6c
expression: Trigger.Category.Investigatable.Product.IDP.DetectName:['Password Brute Force attack (Active Directory)','Password Brute Force attack (web-based)']
display:
- Detection name includes Password Brute Force attack (Active Directory), Password Brute Force attack (web-based)
SHA-256: 9975a817164985568dca78c582e7b75046f5abfef23b66e735f4b56d3b0c7952