This playbook extracts IOCs from the incident details and attached files using regular expressions and then hunts for hashes on endpoints in the organization using available tools.
The playbook supports multiple types of attachments. For the full supported attachments list, refer to "Extract Indicators From File - Generic v2".
- Version History
Extracts IOCs from the incident details and attached files using regular expressions, and then hunts for hashes on endpoints using available tools.
Required Content Packs (2)
Optional Content Packs (0)
All level dependencies (39)
1.0.0 - 4485162 (November 9, 2020)
Cortex XSOARCortex XSIAM
|Created||November 9, 2020|
|Last Release||November 9, 2020|