Retrieve, deduplicate, and enrich alerts from a SIEM, then contact a user via Slack or email to check if they performed an unusual activity. If it appears suspicious, create an incident in PagerDuty and suspend the user's account with this Story.
How it works
Import this story to your tenant, from where you can adapt it to meet your unique needs.
Import