Create PagerDuty incidents for new AxioRank kill chains
A kill chain means AxioRank linked several suspicious agent steps into one attack pattern, which usually warrants an on-call response. This workflow opens a PagerDuty incident for each new kill chain so the on-call responder is paged with the pattern and severity attached. Nothing waits until morning.
- When this happens...New Kill Chain DetectedTriggers when AxioRank correlates a multi step attack pattern on an agent.
- automatically do this!Add Trigger EventTrigger an incident in PagerDuty with this Incident Key.
- Free forever for core features
- 14 day trial for premium features & apps
More things you can do with AxioRank and PagerDuty
Discover other triggers and actions you can use with AxioRank and PagerDuty
- New Agent Quarantined
Triggers when an agent is quarantined by a rule or an operator.
Try ItTriggerInstant - New High Risk Activity
Triggers when AxioRank holds a tool call for approval or detects a kill chain. The catch-all security trigger.
Try ItTriggerInstant - New Inbound Request Flagged
Triggers when inbound agent traffic to a verified property is evaluated.
Try ItTriggerInstant - Approval IDRequired
- DecisionRequired
- Reason
ActionWrite
- New Approval Resolved
Triggers when a held action is approved or denied.
Try ItTriggerInstant - New Hold Awaiting Approval
Triggers when AxioRank holds an action and it is waiting for a human decision.
Try ItTriggerInstant - New Kill Chain Detected
Triggers when AxioRank correlates a multi step attack pattern on an agent.
Try ItTriggerInstant - Incident IDRequired
- ResponseRequired
ActionWrite






