← Files CrowdStrike Falcon FusionARCHIVED FILE

skills/authoring/examples/identity-response/identity-detection-auto-resolution.yaml

2.97 KB · Oct 5, 2026 · 18:32 UTC

↓ Download file

# Example: Identity Detection Auto-Resolution (Recent Password Change)
# Category: identity-response
# Source: CrowdStrike Content Library

name: Identity Detection Auto-Resolution - Recent Password Change
description: 'This workflow automatically resolves Identity Protection Password Brute Force detections when the involved user has recently changed their password within 30 minutes of the detection trigger time. The logic assumes that recent password changes indicate legitimate user activity, making the alert a likely false positive.


  Note: The 30-minute time window can be customized based on your organization''s needs'
trigger:
  next:
    - detection_name_includes_password_brute_force_attack_active_d
  name: Detection > Identity Detection
  event: Investigatable/IDP
  type: Signal
  version_constraint: ~0
actions:
  add_comment_to_alert_d0f89df5:
    id: 7b77cb5d5ff2651cc51c7c4c610d54d1
    name: Add comment to detection
    version_constraint: ~0
    properties:
      _fields:
        - ${get_user_identity_context_36d2cf6c.EntityName}
        - ${get_user_identity_context_36d2cf6c.PasswordChange}
      comment: 'Detection auto-resolved: user changed password shortly before detection triggered'
      investigatable_id: ${Trigger.Category.Investigatable.InvestigatableID}
  get_user_identity_context_36d2cf6c:
    id: 19c7e2af0a24f468be7797fe180c8329
    name: Get user identity context
    version_constraint: ~1
    next:
      - cs_timestamp_parse_data_trigger_category_investigatable_prod
    properties:
      continue_if_entity_not_found: false
      entity_sid: ${Trigger.Category.Investigatable.Product.IDP.SourceAccountObjectSid}
      username: ${Trigger.Category.Investigatable.Product.IDP.SourceAccountName}
  set_alert_status_0e01213e:
    id: beb56cc40d334583671ca91e6e390056
    name: Set detection status
    next:
      - add_comment_to_alert_d0f89df5
    properties:
      investigatable_id: ${Trigger.Category.Investigatable.InvestigatableID}
      status: closed
conditions:
  cs_timestamp_parse_data_trigger_category_investigatable_prod:
    next:
      - set_alert_status_0e01213e
    cel_expression: cs.timestamp.parse(data['Trigger.Category.Investigatable.Product.IDP.EndTime'], 'RFC3339') - cs.timestamp.parse(data['get_user_identity_context_36d2cf6c.PasswordChange'], 'RFC3339') < duration('30m')
    display:
      - cs.timestamp.parse(data[&#39;Trigger.Category.Investigatable.Product.IDP.EndTime&#39;], &#39;RFC3339&#39;) - cs.timestamp.parse(data[&#39;activity_36d2cf6c-0585-4be2-8713-03ec9642dc92.PasswordChange&#39;], &#39;RFC3339&#39;) &lt; duration(&#39;30m&#39;)
  detection_name_includes_password_brute_force_attack_active_d:
    next:
      - get_user_identity_context_36d2cf6c
    expression: Trigger.Category.Investigatable.Product.IDP.DetectName:['Password Brute Force attack (Active Directory)','Password Brute Force attack (web-based)']
    display:
      - Detection name includes Password Brute Force attack (Active Directory), Password Brute Force attack (web-based)

SHA-256: 9975a817164985568dca78c582e7b75046f5abfef23b66e735f4b56d3b0c7952