Malware Investigation and Response (v2.0.24)

Accelerate the investigation of your endpoint malware alerts and incidents and trigger containment activities quickly.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Forensics & Malware Analysis

Incident fields (3)

Layouts (1)

Playbooks (3)

Scripts (8)

README

Malware threat is one of the most common cybersecurity challenges facing businesses today. It causes data breaches, hardware failures, and inoperable computers and system networks that can be extremely costly to recover.
Malware investigations require security teams to reconcile data from multiple security products like EDRs, sandboxes, malware analysis tools, and threat intelligence providers.
Manual investigation wastes valuable time when malware may be propagating within an organization.

The Malware Investigation & Response content pack accelerates the investigation process for endpoint malware incidents and alerts by collecting evidence of malicious behaviors from telemetry data available through EDRs and processing malware analysis reports through sandboxes. Incident layouts also include buttons to remediate activities quickly.

The pack closely maps evidence to MITRE ATT&CK to uncover evidence of:

What Does This Pack Do?

Malware Investigation & Response Incident layout

Getting Started / How to Set up the Pack

For better user experience and easier onboarding, use the Deployment Wizard (Cortex XSOAR 6.13) or the Deployment Wizard (Cortex XSOAR 8 Cloud) or Deployment Wizard (Cortex XSOAR 8.7 On-prem) after installing the content pack on the Marketplace page in Cortex XSOAR (Available from version 6.8).

For manual configuration, it is recommended to configure your integration instance to use:

For more information, visit our Cortex XSOAR Developer Docs.

Dependencies & Recommendations

Supported EDRs (Choose at least one):

Supported Sandboxes (Optional):

Supported Case Management (Optional):