Category: Security · View source ↗
Security
Identity Alert History Check
On a new identity or EDR alert, look back 90 days for prior alerts of the same type for the same user and client, check for a reported trip on unexpected-country alerts, and post the history as an internal note.
Runs as: AgentBeta Paste this prompt into a Flow’s New Super Magic Agent action and it runs unattended on a matching ticket event. You can also run it yourself in Super Magic while you prove it out.
Connectors: Thread
Role: Security & Compliance Owner, Technician
Outcome: Faster Resolution & Response, Risk & Compliance
When to use: An identity or EDR alert arrives (“Unexpected country: Denmark by jane@client.com”, “Unexpected VPN: <provider>”, “Critical incident on host”) and the analyst’s first question is whether this has happened before, or whether the user told you they were travelling.
Run it: on one ticket · or as a Flow (when a ticket is created from your ITDR or EDR vendor, such as Huntress, Blackpoint or SentinelOne).
Was this page helpful?