Social Engineering Domain Analysis (v1.0.4)

Enrich and compare domains against your organizations registered domain.

Author
Shawn Murphy & Nicholas Ericksen
Support
community
URL
https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/bd-p/Cortex_XSOAR_Discussions
Categories
Data Enrichment & Threat Intelligence

Incident fields (4)

Layouts (1)

README

Social engineering attacks against organizations often rely on domains which are similar to those which are
officially registered for business units.
Determining a potentially malicious domain based on its registration properties and similarity to legitimate domains end users
are expected to interact wtih can be an important step to protecting end users from potential social engineering attacks.

What does this pack do?

The playbooks included in this pack perform analysis of suspicious domains against a specified organizational domain.
A known bad list of registrars can be leveraged to escalate the severity of domain indicators as well as the Levenshtein distance.
Two playbooks are included with this pack:

The Social Engineering Domain Enrichment playbook can be used as a subplaybook in other investigations and an example usage is provided in the
Social Engineering Domain Investigation playbook.

Playbook Image