Default (v2.0.18)

Got a unique incident? This Content Pack helps you automate the core steps of enrichment and severity calculation for any kind of incident.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Data Enrichment & Threat Intelligence

Layouts (1)

README

Sometimes you may have an incident, or just some data at hand, that does not fall into any specific category. When you simply create an incident from scratch or just want to get more information about an indicator without performing a full investigation, we recommend using our Default playbook.

This pack provides you with the Default playbook and layout, which help automate the core steps of every investigation.
The Default playbook automatically enriches indicators, parses files, detonates files and URLs, maps affected endpoints and calculates a severity for the incident.
The Default layout is a good match for any incident type, as it dynamically displays mapped or unmapped incident data, file attachments and assets and indicators.

The layout also features remediation buttons as well as a collection of utilities any analyst would love to have at hand.

What does this pack do?

The playbook found in this pack provides a great out-of-the-box solution, yet it can be customized should you want to add additional logic to the default behavior.

For more information, visit our Cortex XSOAR Reference Docs

Default