Send Vulnerabilities to SoftPro Medusa
Focus
Focus
IoT Security

Send Vulnerabilities to SoftPro Medusa

Table of Contents

Send Vulnerabilities to SoftPro Medusa

Manually send vulnerabilities from IoT Security through Cortex XSOAR to SoftPro Medusa to make work orders.
Where Can I Use This?What Do I Need?
  • IoT Security (Managed by IoT Security)
  • IoT Security subscription for an advanced IoT Security product (Enterprise Plus, Industrial OT, or Medical)
One of the following Cortex XSOAR setups:
  • An IoT Security Third-party Integration Add-on license that includes a cohosted, limited-featured Cortex XSOAR instance
    AND
    A Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
From the IoT Security portal, you can send vulnerability instances to SoftPro Medusa. Before forwarding the vulnerability to SoftPro Medusa, Cortex XSOAR converts it into a security incident, which SoftPro Medusa receives. From there, a SoftPro Medusa user can create a work order for a network security analyst to investigate.
When sending vulnerability instances to SoftPro Medusa, you can choose to send:
  • A vulnerability from a Device Details page
  • A vulnerability instance from a Vulnerability Details page
If a vulnerability affects multiple devices, then IoT Security sends a single ticket that includes all affected devices, instead of sending a separate ticket for each affected device.
After you send a vulnerability to SoftPro Medusa, you can view the ticket on your SoftPro Medusa instance.
  1. Log in to the IoT Security portal and send a vulnerability instance to SoftPro Medusa.
    • From the Device Details page:
      Navigate to AssetsDevices and select the device with a vulnerability that you want to send to SoftPro Medusa. On the Device Details page, click on the Vulnerabilities tab, select the vulnerability that you want to send, and select ActionsSend to...SoftPro Medusa.
    • From the Vulnerability Details page:
      Navigate to VulnerabilitiesVulnerability OverviewAll Vulnerabilities and select the vulnerability that you want to send to SoftPro Medusa. On the Vulnerability Details page, under Impact ViewActive Instances select the check boxes for the vulnerability instances that you want to send to SoftPro Medusa. After you have chosen the instances, select MoreSend to...SoftPro Medusa.
  2. In the Send to SoftPro Medusa pop-up that appears, fill in the following fields:
    • Priority: Enter a priority number that your SoftPro Medusa system analyst can use to correlate with the priority numbering system in SoftPro Medusa.
    • Add Comments: Add any additional comments that would help with the risk mitigation workflow.
  3. Send the vulnerability to SoftPro Medusa.
    After you click Send, a link to the Cortex XSOAR playbook appears at the bottom of the pop-up. The link opens a new tab or window to see the Cortex XSOAR playbook for this action.
  4. To confirm that the vulnerability successfully reached SoftPro Medusa, click the link to the Cortex XSOAR playbook for this action.
    For the link in IoT Security to open the corresponding work plan in Cortex XSOAR, you must already be logged in to your cloud Cortex XSOAR instance before clicking on the link. If you have an on-premises Cortex XSOAR, you need to search the incidents on your Cortex XSOAR to find the work plan.
    Follow the path through the playbook to see if the action completed successfully, or to triage where the action may have failed.