Uncover Unknown Malware Using SSDeep (v1.0.3)

Leverages SSDeep hashes to find similarities between indicators and incidents.

Author
Cortex XSOAR
Support
community
URL
https://www.paloaltonetworks.com/cortex
Categories
Forensics & Malware Analysis

Incident fields (1)

Layouts (1)

README

This pack allows you to uncover malware that was previously unknown to you, by comparing its SSDeep hash to other SSDeep hashes.

What does this pack do?

Once the user creates an incident of type Uncover Unknown Malware Using SSDeep and provides an MD5 or SHA256 hash, or a file, the playbook will do the following:

Pack Image

image