3CXDesktopApp Supply Chain Attack [3CXDesktopApp_Supply_Chain_Attack] — ### 3CXDesktopApp Supply Chain Attack
#### Executive Summary
On March 29, 2023, CrowdStrike [released a blog](https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/) discussing a supply chain attack involving a software-based phone application called [3CXDesktopApp](https://www.3cx.com/).
As of March 30, the 3CXDesktopApp installer hosted on the developer’s website will install the application with two malicious libraries included. The malicious libraries will ultimately run shellcode to load a backdoor on the system that allows actors to install additional malware on the victim machine.
Between March 9-30, 2023, we observed activity at 127 Cortex XDR customers that involved the 3CXDesktopApp process attempting to run shellcode, which was blocked by the XDR Agent’s In-process Shellcode Protection Module. Due to blocking the shellcode, we were unable to obtain the secondary payload used in this attack, so we cannot determine its capabilities or any post-exploitation activities carried out by the threat actor.
#### Affected Products
According to 3CX’s announcement, the supply chain attack involved 3CX’s Electron Windows App shipped in Update 7, version numbers 18.12.407 & 18.12.416 and Electron Mac App version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416.
#### Playbook Flow
**This playbook should be triggered manually or can be configured as a job.**
Please create a new incident and choose the 3CXDesktopApp Supply Chain Attack playbook and Rapid Breach Response incident type.
**The playbook includes the following tasks:**
**Hunting:**
- Cortex XDR
- XQL hunting queries
- Advanced SIEM queries
- Splunk
- QRadar
- Elasticsearch
- Azure Log Analytics
- Indicators hunting
**References:**
[Threat Brief: 3CXDesktopApp Supply Chain Attack](https://unit42.paloaltonetworks.com/3cxdesktopapp-supply-chain-attack/)
[CrowdStrike Falcon Platform Detects and Prevents Active Intrusion Campaign Targeting 3CXDesktopApp Customers](https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
ASM Issue Incident Response - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook initiates the response for ASM Issues in XSOAR when an incident is investigated. For medium, high, or critical severity, it creates a ServiceNow ticket using the "ServiceNow v2" integration; otherwise, the incident is assigned to an analyst. The ticket is enriched with GTI ASM Issue details, including entity name, status, confidence, tags, UUID, collection info, and other relevant incident information.
AWS - User Investigation [AWS-Enrichment-Remediation] — This playbook performs an investigation on a specific user in AWS environments, using queries and logs from AWS CloudTrail to locate the following activities performed by the user:
- Failed login attempt
- Suspicious activities
- API access denied
- Administrative user activities
- Security rules and policies changes
- Access keys and access token activities
- Script-based user agent usage
- User role changes activities
- MFA device changes activities
AWS IAM - User enrichment [AWS-IAM] — Enrich AWS IAM user information from AWS Identity and Access Management.
- List user access keys
- Get user information
AWS IAM User Access Investigation [Core] — Deprecated. Use `Cloud IAM User Access Investigation` instead. Investigate and respond to Cortex XSIAM alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment.
The following alerts are supported for AWS environments.
- Penetration testing tool attempt
- Penetration testing tool activity
- Suspicious API call from a Tor exit node
This is a beta playbook, which lets you implement and test pre-release software. Although AWS is supported, we are working towards multi-cloud support. As the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We encourage feedback on the quality and usability of the content to help us identify and fix issues, so we can continually improve the content.
AWS IAM User Access Investigation - Remediation [Core] — Deprecated. Use `Cloud IAM User Access Investigation` instead. Respond to Cortex XDR Cloud alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment.
The following alerts are supported for AWS environments.
- Penetration testing tool attempt
- Penetration testing tool activity
- Suspicious API call from a Tor exit node
This is a beta playbook, which lets you implement and test pre-release software. Although AWS is supported, we are working towards multi-cloud support. As the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We encourage your feedback on the quality and usability of the content to help us identify and fix issues, so we can continually improve the content.
Access Investigation - Generic - NIST [NIST] — This playbook investigates an access incident by gathering user and IP information, and handling the incident based on the stages in "Handling an incident - Computer Security Incident Handling Guide" by NIST.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Used Sub-playbooks:
- IP Enrichment - Generic v2
- Account Enrichment - Generic v2.1
- Block IP - Generic v3
- NIST - Lessons Learned
Access Investigation - QRadar [QRadar] — Deprecated. No available replacement. This playbook uses the QRadar integration to investigate an access incident by gathering user and IP information.
The playbook then interacts with the user that triggered the incident to confirm whether or not they initiated the access action.
Account Enrichment [DeprecatedContent] — Deprecated. Use the "Account Enrichment - Generic v2.1" playbook instead.\ \ Enrich the accounts under the Account context key with details from relevant integrations such as AD.
Account Enrichment - Generic [DeprecatedContent] — Deprecated. Use "Account Enrichment - Generic v2.1" playbook instead.\ \ Enrich Accounts using one or more integrations
Account Enrichment - Generic v2 [DeprecatedContent] — Deprecated. Use "Account Enrichment - Generic v2.1" playbook instead.\ \ Enrich accounts using one or more integrations. Supported integrations - - Active Directory
Account Enrichment - Generic v2.1 [CommonPlaybooks] — Enrich accounts using one or more integrations.
Supported integrations:
- Active Directory
- Microsoft Graph User
- SailPoint IdentityNow
- SailPoint IdentityIQ
- PingOne
- Okta
- AWS IAM
- Cortex XDR (account enrichment and reputation)
Also, the playbook supports the generic command 'iam-get-user' (implemented in IAM integrations). For more information, visit https://xsoar.pan.dev/docs/integrations/iam-integrations.
Acquire And Analyze Host Forensics [WindowsForensics] — This playbook enables gathering forensic data from a host and analyzing the acquired data by using the relevant forensics automations.
Active Directory Investigation [Active_Directory_Query] — Active Directory Investigation playbook provides tools and guidance to investigate changes and manipulation in Active Directory containers, ACLs, Schema, and objects.
This playbook uses a 3rd party tool provided by Microsoft to scan the Active Directory access list, trees, and objects.
Additional investigative information is provided for manual investigation.
Add Employees to Departing Employee Watchlist [Code42] — Loops through stand-down tickets provided by the Departing Employee Auto-Add playbook and adds employees to the Departing Employee watchlist in Code42 Incydr.
Add Employees to New Hire Watchlist [Code42] — Loops through stand-up tickets provided by the New Hire Auto-Add playbook and adds employees to the New Hire watchlist in Code42 Incydr.
Add Note - Vectra Detect [Vectra_AI] — This playbook will add a note in Vectra for an entity based on its type.
Add Note - Vectra XDR [VectraXDR] — This playbook will add a note in Vectra for an entity based on its type.
Add Unknown Indicators To Inventory - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — Adds the unknown indicators or updates/removes the indicators identified as a known asset in the RiskIQ Digital Footprint inventory according to the user inputs for each asset. To select the indicators you want to add, go to playbook inputs, choose "from indicators" and set your query. For example reputation:None etc. The purpose of the playbook is to check if the indicators with the unknown reputation are known assets. The default playbook query is "reputation:None". In case indicators with different reputations are to be added to the inventory, the query must be edited accordingly. This playbook cannot be run in quiet mode. This playbook needs to be used with caution as it might use up the integration’s API license when running for large amounts of indicators.
Supported integration:
- RiskIQ Digital Footprint
Agari Message Remediation - Agari Phishing Defense [AgariPhishingDefense] — Investigates Agari policy events by obtaining the original message and attachments from the existing email integrations and remediates in Agari.
Akamai WAF - Activate Network Lists [Akamai_WAF] — Activates network lists in Staging or Production on Akamai WAF. The playbook finishes running when the network list is active on the requested enviorment.
Allow IP - Okta Zone [Okta] — Sync a list of IP addresses to the Okta Network Zone with the given ID.
Existing IPs in the Okta Zone which are not in the input list will be removed and the indicator will be untagged in Cortex XSOAR.
IDs can be retrieved using !okta-list-zones. This playbook supports CIDR notation only (1.1.1.1/32) and not range notation (1.1.1.1-1.1.1.1)
Arcanna-Generic-Investigation [Arcanna] — Playbook takes incident data and sends it to Arcanna.Ai for ML inference and automated decision. Once decision is retrieved, manual input ( in this case )
from analyst is added in as feedback and sent back to Arcanna.ai. Once Feedback is provided in the final steps of the playbook, an automated AI Training
is triggered and finally the full record, that contains all Arcanna.ai added metadata, is retrieved back into the context
Archer initiate incident [ArcherRSA] — Deprecated. Use the `archer-get-file` command directly instead. initiate Archer incident
Arcsight - Get events related to the Case [ArcSightESM] — Get the Case's Arcsight ResourceID from the FetchID field, or the "ID" label. If neither is there, ask user for the ID.
Use the resource ID to get full data for the case, the correlated/aggregate events underneath it, and all base events underneath them.
Asimily Asset Info Enrich [Asimily_Insight] — Default playbook for Asimily Anomaly and CVE incidents. It enriches incidents by running asimily-get-asset-details to fetch related asset information.
Assess Wiz Issues [Wiz] — Example basic Playbook to assess Wiz Issues
Assign Active Incidents to Next Shift [ShiftManagement-AssignToNextShift] — This playbook reassigns Active Incidents to the current users on call, requires shift management to be setup. Can be run as a job a few minutes after the scheduled shift change time.
Update the playbook input with a different search query if required. Will also branch if there are no Incidents that match the query, and no users on call.
Search results are the default 100 Incidents returned by the query.
Assign Active Incidents to Next Shift V2 [ShiftManagement] — This playbook reassigns Active Incidents to the current users on call. It requires shift management to be set up. The playbook can be run as a job a few minutes after the scheduled shift change time.
You can update the playbook input with a different search query, if required. Will branch if there are no incidents that match the query and no users on call.
Cases will not be assigned to users that defined OOO (by OutOfOffice automation).
Auto Add Assets - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — This playbook automatically adds the provided asset(s) to the RiskIQ Digital Footprint inventory according to the values provided. Use this playbook as a sub playbook and loop over each asset in the asset list in order to add multiple assets.
Supported integration:
- RiskIQ Digital Footprint
Auto Update Or Remove Assets - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — This playbook automatically updates or removes the provided asset(s) from the RiskIQ Digital Footprint inventory according to the values provided. Use this playbook as a sub playbook and loop over each asset in the asset list in order to update or remove multiple assets.
Supported integration:
- RiskIQ Digital Footprint
AutoFocusPolling [AutoFocus] — Use this playbook as a sub-playbook to query PANW Autofocus Threat intelligence system. This sub-playbook is the same as the generic polling sub-playbook besides that it provides outputs in the playbook. The reason for that is that in Autofocus its impossible to query the results of the same query more than once so the outputs have to be in the polling context.
This playbook implements polling by continuously running the command in Step \#2 until the operation completes.
The remote action should have the following structure:
1. Initiate the operation.
2. Poll to check if the operation completed.
3. (optional) Get the results of the operation.
Autofocus - File Indicators Hunting [AutoFocus] — Deprecated. No available replacement. The playbook queries the PANW Autofocus session and samples log data for file indicators such as MD5, SHA256, and SHA1 hashes.
A simple search mode is used to query Autofocus based on the file indicators specified in the playbook inputs. Advanced search mode queries can also be used with multiple query parameters, but require all field names, parameters, and operators (JSON format) to be specified.
We recommended using the Autofocus UI to create an advanced query, exporting it, and pasting it into the relevant playbook inputs.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Autofocus - Hunting And Threat Detection [AutoFocus] — Deprecated. No available replacement. The playbook queries the PANW Autofocus session and samples log data for file and traffic indicators, such as SHA256, SHA1, MD5, IP addresses, URLs, and domains.
A simple search mode queries Autofocus based on the indicators specified in the playbook inputs. Advanced queries can also use with multiple query parameters, but require all field names, parameters, and operators (JSON format) to be specified.
We recommended using the Autofocus UI to create an advanced query, exporting it, and pasting it into the relevant playbook inputs.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Autofocus - Traffic Indicators Hunting [AutoFocus] — Deprecated. No available replacement. The playbook queries the PANW Autofocus session and samples log data for traffic indicators such as URLs, IP addresses, and domains.
A simple search mode queries Autofocus based on the traffic indicators specified in the playbook inputs. Advanced search mode queries can also be used with multiple query parameters, but require all field names, parameters, and operators (JSON format) to be specified.
We recommended using the Autofocus UI to create an advanced query, exporting it, and pasting it into the relevant playbook inputs.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Autofocus Query Samples, Sessions and Tags [AutoFocus] — Deprecated. No available replacement. This playbook is used for querying the PANW threat intelligence Autofocus system. The playbook accepts indicators such as IP's, hashes, domains to run basic queries or mode advanced queries that can leverage several query parameters. In order to run the more advanced queries its recommended to use the Autofocus UI https://autofocus.paloaltonetworks.com/#/dashboard/organization to created a query and than use the export search button. The result can be used as a playbook input.
The playbook supports searching both the Samples API and the sessions API.
Azure - User Investigation [Azure-Enrichment-Remediation] — This playbook performs an investigation on a specific user in Azure environments, using queries and logs from Azure Log Analytics to locate the following activities performed by the user:
- Script-based user agent usage
- Administrative user activities
- Security rules and policies changes
- Failed login attempt
- MFA failed login attempt
- Login attempt from an uncommon country
- Anomalies activities
- Risky users
- Uncommon high volume of actions
- Action uncommonly performed by the user
Azure Configuration Analysis [MicrosoftPolicyAndCompliance] — Deprecated. Use 'Office 365 and Azure Configuration Analysis' instead. This playbook helps you collect, review, and find misconfigurations with the Azure environment.
Azure Hunting playbook [MicrosoftPolicyAndCompliance] — Deprecated. Use 'Office 365 and Azure Hunting' instead. This playbook enables you to collect and investigate suspicious security events from Azure AD environment.
BeyondTrust Retrieve Credentials [BeyondTrust_Password_Safe] — Playbook for retrieving credentials for BeyondTrust Password Safe
Block Account - Generic [CommonPlaybooks] — Deprecated. Use 'Block Account - Generic v2' instead. This playbook blocks malicious usernames using all integrations that you have enabled.
Supported integrations for this playbook:
* Active Directory
* PAN-OS - This requires PAN-OS 9.1 or higher.
Block Account - Generic v2 [CommonPlaybooks] — This playbook blocks malicious usernames using all integrations that you have enabled.
Supported integrations for this playbook:
* Active Directory
* PAN-OS - This requires PAN-OS 9.1 or higher.
* SailPoint
* PingOne
* AWS IAM
* Clarizen IAM
* Envoy IAM
* ExceedLMS IAM
* Okta
* Microsoft Graph User (Entra ID Users)
* Google Workspace Admin
* Slack IAM
* ServiceNow IAM
* Prisma Cloud IAM
* Zoom IAM
* Atlassian IAM
* GitHub IAM.
Block Domain - External Dynamic List [EDL] — This playbook blocks domains using External Dynamic Link.
The playbook adds a tag to the inputs domain indicators. the tagged domains can be publish as External Dynamic list that can be added to blocklist using products like Panorama by Palo Alto Networks.
For Panorama - You can block the tagged domains by creating EDL(in Panorama) with the XSOAR EDL Url, and assign it to Anti-Spyware profile under "DNS Signature Policies"
Block Domain - FireEye Email Security [FireEyeEX] — This playbook blocks domains using FireEye Email Security.
The playbook checks whether the FireEye Email Security integration is enabled, whether the Domain input has been provided and if so, blocks the domain.
Block Domain - Generic [CommonPlaybooks] — Deprecated. Use 'Block Domain - Generic v2' instead. This playbook blocks malicious Domains using all integrations that are enabled.
Supported integrations for this playbook:
* Zscaler
* Symantec Messaging Gateway
* FireEye EX
* Trend Micro Apex One
* Proofpoint Threat Response
Block Domain - Generic v2 [CommonPlaybooks] — This playbook blocks malicious Domains using all integrations that are enabled.
Supported integrations for this playbook:
* Zscaler
* Symantec Messaging Gateway
* FireEye EX
* Trend Micro Apex One
* Proofpoint Threat Response
* Cisco Stealthwatch Cloud
Block Domain - Proofpoint Threat Response [ProofpointThreatResponse] — This playbook blocks domains using Proofpoint Threat Response.
The playbook checks whether the Proofpoint Threat Response integration is enabled, whether the Domain input has been provided and if so, blocks the domain.
Block Domain - Symantec Messaging Gateway [Symantec_Messaging_Gateway] — This playbook blocks domains using Symantec Messaging Gateway.
The playbook checks whether the Symantec Messaging Gateway integration is enabled, whether the Domain input has been provided and if so, blocks the domain.
Block Domain - Trend Micro Apex One [TrendMicroApex] — This playbook blocks domains using TrendAI™ Apex One.
The playbook checks whether the TrendAI™ Apex One integration is enabled, whether the Domain input has been provided and if so, blocks the domain.
Block Domain - Zscaler [Zscaler] — This playbook blocks domains using Zscaler.
The playbook checks whether the Zscaler integration is enabled, whether the Domain input has been provided and if so, blocks the domain.
Block Email - Generic [CommonPlaybooks] — Deprecated. Use 'Block Email - Generic v2' instead. This playbook will block emails at your mail relay integration.
Block Email - Generic v2 [CommonPlaybooks] — This playbook will block emails at your mail relay integration.
Supported integrations for this playbook:
* Mimecast
* FireEye Email Security (EX)
* Cisco Email Security
* Symantec Email Security
Block Endpoint - Carbon Black Response [Carbon_Black_Enterprise_Response] — Deprecated. Use the `Block Endpoint - Carbon Black Response V2.1` playbook instead. Carbon Black Response - isolate an endpoint, given a hostname.
Block Endpoint - Carbon Black Response V2 [Carbon_Black_Enterprise_Response] — Deprecated. Use the `Block Endpoint - Carbon Black Response V2.1` playbook instead. Carbon Black Response - isolates an endpoint for a given hostname.
Block File - Carbon Black Response [Carbon_Black_Enterprise_Response] — This playbook receives an MD5 hash and adds it to the block list in Carbon Black Enterprise Response. Files with that MD5 hash are blocked from execution on the managed endpoints. If the hash is already on the block list, no action is taken on the MD5.
The playbook uses the integration ''VMware Carbon Black EDR v2".
Block File - Cybereason [Cybereason] — This playbook accepts an MD5 hash and blocks the file using the Cybereason integration.
Block File - Cylance Protect v2 [Cylance_Protect] — This playbook accepts a SHA256 hash and adds the hash to the Global Quarantine list using the Cylance Protect v2 integration.
Block File - Generic [DeprecatedContent] — Deprecated. Use "Block File - Generic v2" playbook instead. A generic playbook for blocking files from running on endpoints. This playbook currently supports Carbon Black Enterprise Response.
Block File - Generic v2 [CommonPlaybooks] — This playbook is used to block files from running on endpoints.
This playbook supports the following integrations:
- Palo Alto Networks Traps
- Palo Alto Networks Cortex XDR
- Cybereason
- Carbon Black Enterprise Response
- Cylance Protect v2
- Crowdstrike Falcon
- Microsoft Defender for Endpoint.
Block IP - Generic [DeprecatedContent] — Deprecated. Use "Block IP - Generic v2" playbook instead. This playbook blocks malicious IPs using all integrations that you have enabled.
Supported integrations for this playbook:
* Check Point Firewall
* Palo Alto Networks Minemeld
* Palo Alto Networks Panorama
* Zscaler
Block IP - Generic v2 [CommonPlaybooks] — Deprecated. Use the `Block IP - Generic v3` playbook instead.
This playbook blocks malicious IPs using all integrations that are enabled.
Supported integrations for this playbook:
* Check Point Firewall
* Palo Alto Networks Minemeld
* Palo Alto Networks PAN-OS
* Zscaler
* FortiGate
Block IP - Generic v3 [CommonPlaybooks] — This playbook blocks malicious IP addresses using all integrations that are enabled. The direction of the traffic that will be blocked is determined by the XSOAR user (and set by default to outgoing)
Note the following:
- some of those integrations require specific parameters to run, which are based on the playbook inputs. Also, certain integrations use FW rules or appended network objects.
- Note that the appended network objects should be specified in blocking rules inside the system later on.
Supported integrations for this playbook [Network security products such as FW/WAF/IPs/etc.]:
* Check Point Firewall
* Palo Alto Networks PAN-OS
* Zscaler
* FortiGate
* Aria Packet Intelligence
* Cisco Firepower
* Cisco Secure Cloud Analytics
* Cisco ASA
* Akamai WAF
* F5 SilverLine
* ThreatX
* Signal Sciences WAF
* Sophos Firewall.
Block Indicator - Infoblox Cloud [InfobloxBloxOne] — This playbook blocks the given IP or domain by adding it to the given block type custom list of the Infoblox Cloud platform. If prompted it also removes the provided indicators from given allow list.
Block Indicator - Infoblox NIOS [Infoblox] — This playbook blocks the given Indicator by creating or updating RP Zone rule in Infoblox NIOS platform.
Block Indicators - Generic [DeprecatedContent] — Deprecated. We recommend using the 'Block Indicators - Generic v2' playbook instead.
This playbook blocks malicious indicators using all integrations that are enabled.
Supported integrations for this playbook:
* Active Directory
* Check Point Firewall
* Palo Alto Networks Minemeld
* Palo Alto Networks Panorama
* Zscaler
* Carbon Black Enterprise Response
Block Indicators - Generic v2 [CommonPlaybooks] — Deprecated. Use the `Block Indicators - Generic V3` playbook instead.
This playbook blocks malicious Indicators using all integrations that are enabled, using the following sub-playbooks:
- Block URL - Generic
- Block Account - Generic
- Block IP - Generic v2
- Block File - Generic v2
- Block Email - Generic
- Block Domain - Generic
Block Indicators - Generic v3 [CommonPlaybooks] — This playbook blocks malicious indicators using all integrations that are enabled, using the following sub-playbooks:
- Block URL - Generic v2
- Block Account - Generic v2
- Block IP - Generic v3
- Block File - Generic v2
- Block Email - Generic v2
- Block Domain - Generic v2.
Block URL - Generic v2 [CommonPlaybooks] — This playbook blocks malicious URLs using all integrations that are enabled.
Supported integrations for this playbook:
* Palo Alto Networks PAN-OS
* Zscaler
* Sophos
* Forcepoint
* Checkpoint
* Netcraft.
BreachRx - Create Incident and get Active Tasks [BreachRx] — This Playbook creates a privacy Incident on the BreachRx platform, and pulls in all tasks from that created privacy Incident into the Cortex XSOAR Incident.
Bring Asset Data Back - Infoblox NIOS [Infoblox] — This playbook brings asset data from XSOAR to Infoblox by creating the host record using the Infoblox NIOS integration.
Brute Force Investigation - Generic - SANS [SANS] — This playbook investigates a "Brute Force" incident by gathering user and IP information, and calculating the incident severity based on the gathered information and information received from the user. It then performs remediation.
This is done based on the phases for handling an incident as they are described in the SANS Institute ‘Incident Handler’s Handbook’ by Patrick Kral.
https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901
The playbook handles the following use-cases:
* Brute Force IP Detected - A detection of source IPs that are exceeding a high threshold of rejected and/or invalid logins.
* Brute Force Increase Percentage - A detection of large increase percentages in various brute force statistics over different periods of time.
* Brute Force Potentially Compromised Accounts - A detection of accounts that have shown high amount of failed logins with one successful login.
Used Sub-playbooks:
- IP Enrichment - Generic v2
- Account Enrichment - Generic v2.1
- Calculate Severity - Critical Assets v2
- Isolate Endpoint - Generic v2
- Block Indicators - Generic v3
- SANS - Lessons Learned
***Disclaimer: This playbook does not ensure compliance to SANS regulations.
C2SEC-Domain Scan [C2sec] — Launches a C2sec scan by domain name and waits for the scan to finish by polling its status in pre-defined intervals.
CCTV Motion Detected [UnifiVideoNVR] — A playbook that runs ComputerVision on CCTV events
CTIX - Delete Flagged Indicators [CTIX] — Deletes indicators ingested from Cyware Intel Exchange (CTIX v3) that are flagged as deprecated, revoked, false positive, reviewed, or whitelisted, by running the CTIXDeleteFlaggedIndicators script. All delete flags default to false - enable the ones you want via the playbook inputs. Intended to run on a schedule via the bundled 'CTIX - Delete Flagged Indicators' job.
CVE Enrichment - Generic [CVESearch] — Deprecated. Use "CVE Enrichment - Generic v2" playbook instead. Enrich CVE using one or more integrations.
CVE Enrichment - Generic v2 [CommonPlaybooks] — This playbook performs CVE Enrichment using the following integrations:
- VulnDB
- CVE Search
- IBM X-Force Exchange
CVE Exposure - RiskSense [RiskSense] — Block IPs and apply the tag to assets that are vulnerable to the specified CVE.
CVE Ticket Creation - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook creates a ServiceNow ticket using the "ServiceNow v2" integration based on enriched CVE data, leveraging the CVE exploitation state, risk rating, and CVSS score.
CVE-2021-22893 - Pulse Connect Secure RCE [MajorBreachesInvestigationandResponse] — On April 20th, a new Remote Code Execution vulnerability in Pulse Connect Secure was disclosed.
The reference number for the vulnerability is CVE-2021-22893 with the CVSS Score of 10.0.
This playbook should be trigger manually and includes the following tasks:
* Enrich related known CVEs and Malware Hashes used by the suspected APT actor.
* Search for unpatched endpoints vulnerable to the exploits.
* Search network facing system using Expanse for relevant issues.
* Indicators and known webshells hunting using SIEM products.
* Block indicators automatically or manually.
* Provide different mitigations that has been publicly published such as:
* Patches
* Workarounds
* Yara and Snort Rules
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
More information:
[Exploitation of Pulse Connect Secure Vulnerabilities](https://us-cert.cisa.gov/ncas/alerts/aa21-110a)
CVE-2021-34527 | CVE-2021-1675 - PrintNightmare [MajorBreachesInvestigationandResponse] — **The playbook can be triggered manually or automatically by setting up a reoccurring job.**
Microsoft has released a security update in June 2021 Patch Tuesday for CVE-2021-1675, a Local Privilege Escalation vulnerability in the Print Spooler Service. Later that month, researchers found another method to exploit the Print Spooler service remotely, which raised the severity of the vulnerability due to the fact that the new method allows Remote Code Execution, a new ID was given to the critical vulnerability - CVE-2021-34527.
Microsoft patched the vulnerability in June but an exploit POC and complete technical analysis were made publicly available online.
**Update 7.8.2021 - Microsoft has released an emergency patch for the PrintNightmare. A reference for the patch can be found in "Install Microsoft spooler service patches" task.
This playbook includes the following tasks:
- Manual actions to mitigate the exploit
- Search Vulnerable Devices using the CVE
- Query SIEM, FW, XDR to detect malicious activity and compromised hosts
- Run Dedicated Detection and Response playbook for Cortex XDR
More details on the vulnerabilities:
[CVE-2021-1675 LPE](https://nvd.nist.gov/vuln/detail/CVE-2021-1675)
[CVE-2021-34527 RCE](https://nvd.nist.gov/vuln/detail/CVE-2021-34527)
** Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2021-40444 - MSHTML RCE [CVE_2021_40444] — CVE-2021-4044 refers to the MSHTML engine, that has been found vulnerable to arbitrary code execution by a specially crafted Microsoft Office document or rich text format file.
Mitigations:
* Microsoft official patch addressing CVE-2021-40444
* Several workarounds suggested by Microsoft.
Researchers have validated this attack triggered in Windows Explorer with “Preview Mode” enabled, even in just a rich-text format RTF file (not an Office file and without ActiveX). This indicates it can be exploited even without opening the file and this invalidates Microsoft’s workaround mitigation mentioned above.
This playbook should be trigger manually and includes the following tasks:
* Collect related known indicators from several sources.
* Indicators, Files and Process creation patterns hunting using PAN-OS, Cortex XDR and SIEM products.
* Block indicators automatically or manually.
* Provide workarounds and detection capabilities.
* Microsoft official CVE-2021-40444 patch.
More information:
[Microsoft MSHTML Remote Code Execution Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2021-44228 - Log4j RCE [CVE_2021_44228] — Critical RCE Vulnerability: log4j - CVE-2021-44228
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform.
On Dec. 14 2021, another vulnerability was discovered related to the log4j 0-day exploit known as CVE-2021-45046.
On Dec 18 2021, yet another vulnerability was discovered related to the log4j 0-day exploit known as CVE-2021-45105 that allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3.
On Dec 28 2021, another RCE vulnerability was published for Apache Log4j2, versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4).
In order to exploit this vulnerability, an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
**Affected Version**
Apache Log4j 2.x <= 2.17.0
This playbook should be triggered manually or can be configured as a job.
Please create a new incident and choose the **CVE-2021-44228 - Log4j RCE** playbook and **Rapid Breach Response** incident type.
**The playbook includes the following tasks:**
* Collect related known indicators from several sources.
* Indicators and exploitation patterns hunting using PAN-OS, Cortex XDR and SIEM products.
*Search for possible vulnerable servers using Xpanse and Prisma Cloud.
* Block indicators automatically or manually.
**Mitigations:**
* Apache official CVE-2021-44228 patch.
* Unit42 recommended mitigations.
* Detection Rules.
* Snort
* Suricata
* Sigma
* Yara
* Zeek Intel
More information:
[Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228)](https://unit42.paloaltonetworks.com/apache-log4j-vulnerability-cve-2021-44228/)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2022-26134 - Confluence RCE [CVE_2022_26134] — Atlassian has been made aware of the current active exploitation of a critical severity unauthenticated remote code execution vulnerability in Confluence Data Center and Server. The OGNL injection vulnerability allows an unauthenticated user to execute arbitrary code on a Confluence Server or Data Center instance.
**All** versions of Confluence Server and Data Center prior to the fixed versions listed above are affected by this vulnerability.
Atlassian has released the following versions to address this issue:
**Released versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, and 7.18.1 which contain a fix for this issue.**
This playbook includes the following tasks:
* Collect detection rules.
* Exploitation patterns & IoCs hunting using PANW Next-Generation Firewalls and 3rd party SIEM products.
* Cortex Xpanse policies coverage.
* Provides Atlassian workarounds and patched versions.
**More information:**
[Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022-26134)
](https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/)
[Confluence Security Advisory 2022-06-02](https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html)
**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2022-30190 - MSDT RCE [CVE_2022_30190] — On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec).
The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word.
On **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**.
This playbook includes the following tasks:
* Collect detection rules.
* Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.
* Cortex XDR BIOCs coverage.
* Provides Microsoft workarounds and detection capabilities.
**More information:**
[Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability
](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/)
**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2022-3786 & CVE-2022-3602 - OpenSSL X.509 Buffer Overflows [CVE_2022_3786_and_CVE_2022_3602_-_OpenSSL_X.509_Buffer_Overflows] — On November 1, OpenSSL released a [security advisory](https://www.openssl.org/news/secadv/20221101.txt) describing two high severity vulnerabilities within the OpenSSL library, CVE-2022-3786 and CVE-2022-3602. OpenSSL versions from 3.0.0 - 3.0.6 are vulnerable, with 3.0.7 containing the patch for both vulnerabilities. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
The vulnerability described in CVE-2022-3602 allows an attacker to obtain a 4-byte overflow on the stack by crafting a malicious email address within the attacker-controlled certificate. The overflow will result in a crash (most likely scenario) or potentially remote code execution (much less likely). In CVE-2022-3786, an attacker can achieve a stack overflow of arbitrary length by crafting a malicious email address within the attacker-controlled certificate.
Both vulnerabilities are “triggered through X.509 certificate verification, specifically, name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.”
**The playbook includes the following tasks:**
* Hunting for active processes running OpenSSL vulnerable versions using:
* Cortex XDR
* Splunk
* Azure Sentinel
* Cortex Xpanse
* Prisma
* PANOS
**Mitigations:**
* OpenSSL official patch
More information:
[Unit42 Threat Brief: CVE-2022-3786 and CVE-2022-3602: OpenSSL X.509 Buffer Overflows](https://unit42.paloaltonetworks.com/openssl-vulnerabilities/)
[NCSC-NL - OpenSSL overview Scanning software](https://github.com/NCSC-NL/OpenSSL-2022/tree/main/scanning)
Note: This is a beta playbook that lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2022-41040 & CVE-2022-41082 - ProxyNotShell [CVE_2022_41040_and_CVE_2022_41082_-_ProxyNotShell] — **UPDATE**
A new method for bypassing ProxyNotShell mitigations was found after being seen exploited in the wild by the Play ransomware gang.
While the original exploit took advantage of the Autodiscover endpoint, the new exploit is using the OWA endpoint leading to SSRF.
The OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA).
This playbook introduces several updates in response to the new discovery:
- Hunting:
- Detecting possibly successful exploitation of the OWA SSRF vulnerability.
- Mitigations:
- IIS URL Rewrite rule for the modified exploitation URI path.
- Remediation:
- Block Indicators - Generic v3 playbook.
Microsoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker.
Currently, Microsoft is aware of limited targeted attacks using these two vulnerabilities. In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability.
This playbook includes the following tasks:
* Collect detection rules, indicators and mitigation tools.
* Exploitation patterns hunting using Cortex XDR - XQL Engine.
* Exploitation patterns hunting using 3rd party SIEM products:
* Azure Sentinel
* Splunk
* QRadar
* Elasticsearch
* Indicators hunting using:
* PAN-OS
* Splunk
* QRadar
* Provides Microsoft mitigation and detection capabilities.
**More information:**
[Threat Brief: OWASSRF Vulnerability Exploitation](https://unit42.paloaltonetworks.com/threat-brief-OWASSRF/)
[Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)](https://unit42.paloaltonetworks.com/proxynotshell-cve-2022-41040-cve-2022-41082/)
**References:**
[OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations](https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/)
[Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082](https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/)
[Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server](https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/)
[WARNING: NEW ATTACK CAMPAIGN UTILIZED A NEW 0-DAY RCE VULNERABILITY ON MICROSOFT EXCHANGE SERVER](https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html)
[ProxyNotShell— the story of the claimed zero days in Microsoft Exchange](https://doublepulsar.com/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9)
**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2023-23397 - Microsoft Outlook EoP [CVE_2023_23397_-_Microsoft_Outlook_EoP] — ### CVE-2023-23397 - Critical Elevation of Privilege vulnerability in Microsoft Outlook
#### Summary
Microsoft Threat Intelligence discovered limited, targeted abuse of a vulnerability in Microsoft Outlook for Windows that allows for new technology LAN manager (NTLM) credential theft. Microsoft has released CVE-2023-23397 to address the critical elevation of privilege (EoP) vulnerability affecting Microsoft Outlook for Windows. We strongly recommend all customers update Microsoft Outlook for Windows to remain secure.
#### Affected Products
All supported versions of Microsoft Outlook for Windows are affected. Other versions of Microsoft Outlook such as Android, iOS, Mac, as well as Outlook on the web and other M365 services are not affected.
#### Technical Details
CVE-2023-23397 is a critical EoP vulnerability in Microsoft Outlook that is triggered when an attacker sends a message with an extended MAPI property with a UNC path to an SMB (TCP 445) share on a threat actor-controlled server. No user interaction is required.
The threat actor is using a connection to the remote SMB server sends the user’s NTLM negotiation message, which the attacker can then relay for authentication against other systems that support NTLM authentication.
**This playbook should be triggered manually or can be configured as a job.**
Please create a new incident and choose the CVE-2023-23397 - Microsoft Outlook EoP playbook and Rapid Breach Response incident type.
**The playbook includes the following tasks:**
**Hunting:**
- Panorama Threat IDs
- Cortex XDR
- XQL hunting query
- BTP hunting
- Microsoft PowerShell hunting script
- Advanced SIEM hunting queries
- Indicators hunting
- Endpoint by CVE hunting
**Mitigations:**
- Cortex XDR Advanced API Monitoring
- Microsoft official CVE-2023-23397 patch
- Microsoft workarounds
- Detection Rules
- Yara
**References:**
[Microsoft Mitigates Outlook Elevation of Privilege Vulnerability](https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/)
[CVE-2023-23397 Audit & Eradication Script](https://github.com/microsoft/CSS-Exchange/blob/a4c096e8b6e6eddeba2f42910f165681ed64adf7/docs/Security/CVE-2023-23397.md)
[Neo23x0 Yara Rules](https://github.com/Neo23x0/signature-base/blob/master/yara/expl_outlook_cve_2023_23397.yar)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2023-34362 - MOVEit Transfer SQL Injection [CVE_2023_34362_-_MOVEit_SQLI] — ### CVE-2023-34362 - Critical SQL Injection vulnerability in MOVEit Transfer.
#### Summary
A critical vulnerability has been identified in MOVEit Transfer, a managed file transfer solution. The vulnerability affects versions prior to the latest release and involves improper input validation. Exploiting this vulnerability can lead to remote execution of arbitrary code, potentially resulting in unauthorized access and compromise of sensitive data.
To mitigate the risk associated with this vulnerability, it is crucial for users to update to the latest version of MOVEit Transfer that includes necessary security patches.
#### Affected Products
| Affected Version | Fixed Version | Documentation |
|-------------------------------|---------------------------|-------------------------------------|
| MOVEit Transfer 2023.0.0 (15.0) | MOVEit Transfer 2023.0.1 | [MOVEit 2023 Upgrade Documentation](https://docs.ipswitch.com/MOVEit/2023/Upgrade/) |
| MOVEit Transfer 2022.1.x (14.1) | MOVEit Transfer 2022.1.5 | [MOVEit 2022 Upgrade Documentation](https://docs.ipswitch.com/MOVEit/2022/Upgrade/) |
| MOVEit Transfer 2022.0.x (14.0) | MOVEit Transfer 2022.0.4 | [MOVEit 2022 Upgrade Documentation](https://docs.ipswitch.com/MOVEit/2022/Upgrade/) |
| MOVEit Transfer 2021.1.x (13.1) | MOVEit Transfer 2021.1.4 | [MOVEit 2021 Upgrade Documentation](https://docs.ipswitch.com/MOVEit/2021/Upgrade/) |
| MOVEit Transfer 2021.0.x (13.0) | MOVEit Transfer 2021.0.6 | [MOVEit 2021 Upgrade Documentation](https://docs.ipswitch.com/MOVEit/2021/Upgrade/) |
| MOVEit Transfer 2020.1.x (12.1) | Special Patch Available | See [KB 000234559](https://docs.ipswitch.com/MOVEit/2020/234559.htm) |
| MOVEit Transfer 2020.0.x (12.0) or older | MUST upgrade to a supported version | See [MOVEit Transfer Upgrade and Migration Guide](https://docs.ipswitch.com/MOVEit/Transfer2021/UpgradeGuide/) |
**This playbook should be triggered manually or can be configured as a job.**
Please create a new incident and choose the CVE-2023-34362 - MOVEit SQL Injection playbook and Rapid Breach Response incident type.
**The playbook includes the following tasks:**
**IoCs Collection**
- Blog IoCs download
- Yara Rules download
- Sigma rules download
**Hunting:**
- Cortex XDR XQL exploitation patterns hunting
- Cortex Xpanse external facing instances hunting
- Advanced SIEM exploitation patterns hunting
- Indicators hunting
The hunting queries are searching for the following activities:
- ASPX file creation by w3wp.exe
- IIS compiling binaries via the csc.exe on behalf of the MOVEit
- Detects get requests to specific exploitation related files
**Mitigations:**
- Progress official CVE-2023-34362 patch
- Progress mitigation measures
- Detection Rules
- Yara
- Sigma
**References:**
[CVE-2023-34362: MOVEit Transfer SQL Injection Vulnerability Threat Brief](https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/)
[MOVEit Transfer Critical Vulnerability (May 2023)](https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2023-36884 - Microsoft Office and Windows HTML RCE [CVE_2023_36884_-_Microsoft_Office_and_Windows_RCE] — ## CVE-2023-36884 - Microsoft Office and Windows HTML RCE
**Summary:**
Microsoft recently detected a sophisticated phishing campaign orchestrated by a threat actor called Storm-0978. The targets of this campaign were defense and government organizations in Europe and North America. The attackers exploited the previously undisclosed CVE-2023-36884, introduced in July's recent Patch Tuesday release.
CVE-2023-36884 is affecting both Office and Windows. This zero-day vulnerability enables remote code execution through specially crafted Microsoft Office documents.
**This playbook should be triggered manually or can be configured as a job.**
Please create a new incident and choose the CVE-2023-36884 - Office and Windows HTML RCE playbook and Rapid Breach Response incident type.
**The playbook includes the following tasks:**
**IoCs Collection**
- Unit42 IoCs download
**Hunting:**
- PANW Hunting:
- Cortex XDR XQL exploitation patterns hunting
- Panorama Threat IDs hunting
- Advanced SIEM exploitation patterns hunting
- Indicators hunting
- Endpoints by CVE hunting
The hunting queries are searching for the following activities:
- Detects a Microsoft Office file drops a file called 'file001.url'.
- Suspicious New Instance Of An Office COM Object
- Change PowerShell Policies to an Insecure Level
`Please note that the threat hunting queries are related to the behavior identified as part of the exploitation patterns and may result in false positive detections.`
**Mitigations:**
- Microsoft mitigation measures
**References:**
[CVE-2023-36884 - Microsoft Office and Windows HTML Remote Code Execution: Threat Brief](https://unit42.paloaltonetworks.com/cve-2023-36884-rce/)
[Storm-0978 attacks reveal financial and espionage motives
](https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/)
CVE-2024-47575 - FortiManager Authentication Bypass [CVE_2024_47575] — CVE-2024-47575, also known as **FortiJump**, is a critical zero-day vulnerability affecting **FortiManager**, a centralized management platform for Fortinet devices. The vulnerability arises due to missing authentication checks in specific FortiManager REST API endpoints. An unauthenticated attacker with network access to the FortiManager device can exploit this flaw to execute arbitrary code or commands, potentially leading to complete system compromise.
---
## Affected Versions
| FortiManager Version | Status |
|------------------------|--------------------|
| **7.2.0 to 7.2.3** | Affected |
| **7.0.0 to 7.0.7** | Affected |
| **6.4.0 to 6.4.11** | Affected |
| **6.2.x and earlier** | Potentially Affected |
| **7.2.4 and above** | **Patched** |
| **7.0.8 and above** | **Patched** |
| **6.4.12 and above** | **Patched** |
*Note:*
Old FortiAnalyzer models 1000E, 1000F, 2000E, 3000E, 3000F, 3000G, 3500E, 3500F, 3500G, 3700F, 3700G, 3900E with the following feature enabled (FortiManager on FortiAnalyzer):
config system global
set fmg-status enable
end
And at least one interface with the fgfm service enabled is also impacted by this vulnerability.
---
## Playbook Flow
1. Create, Tag, and Block Indicators
2. Hunt **Automatically** for Suspicious Behavior Related to the exploitation flow using XQL
**Note: The 'fortinet_fortimanager_raw' dataset must be available for the XQL queries completion.**
3. Provide Mitigations and Workarounds
---
**References**:
- [Fortinet PSIRT Advisory FG-IR-24-423](https://www.fortiguard.com/psirt/FG-IR-24-423)
---
By following this playbook, organizations can effectively respond to and mitigate the risks associated with **CVE-2024-47575 (FortiJump)**.
CVE-2024-6387 - OpenSSH RegreSSHion RCE [CVE_2024_6387_-_OpenSSH_RCE_RegreSSHion] — RegreSSHion Vulnerability (CVE-2024-6387)
On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, known as RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote code execution (RCE) with root privileges. This vulnerability has been rated High severity (CVSS 8.1).
#### Impacted Versions
The vulnerability impacts the following OpenSSH server versions:
- OpenSSH versions between 8.5p1 and 9.8p1
- OpenSSH versions earlier than 4.4p1, if they have not been backport-patched against CVE-2006-5051 or patched against CVE-2008-4109
#### Unaffected Versions
The SSH features in PAN-OS are not affected by CVE-2024-6387.
### The playbook includes the following tasks:
**Collect, Extract and Enrich Indicators**
* Collect known indicators from Unit42 blog
**Threat Hunting**
* Searches vulnerable endpoints using Prisma Cloud and Cortex XDR - XQL queries
**Mitigations:**
* OpenSSH official CVE-2024-6387 patch
* Unit42 recommended mitigations
**This playbook should be triggered manually or can be configured as a job.**
Please create a new incident and choose the CVE-2024-6387 - OpenSSH RegreSSHion RCE playbook and Rapid Breach Response incident type.
Reference:
[Threat Brief: CVE-2024-6387 OpenSSH RegreSSHion Vulnerability
](https://unit42.paloaltonetworks.com/threat-brief-cve-2024-6387-openssh/).
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Calculate Severity - Cortex XDR Risky Assets [CortexXDR] — Calculates a severity for the incident based on the involvement of risky users or risky hosts in the incident, as determined by the Cortex XDR ITDR module.
Calculate Severity - Critical Assets v2 [CommonPlaybooks] — Determines if a critical assest is associated with the invesigation. The playbook returns a severity level of "Critical" if at least one critical asset is associated with the investigation.
Critical assets refer to: users, user groups, endpoints and endpoint groups.
Calculate Severity - Critical assets [DeprecatedContent] — Deprecated. Use Calculate Severity - Critical Assets v2 playbook instead. Determines if a critical assest is associated with the invesigation. The playbook returns a severity level of \"Critical\" if a critical asset is associated with the investigation.\n\nThis playbook verifies if a user account or an endpoint is part of a critical list or a critical AD group.
Calculate Severity - Generic [DeprecatedContent] — Deprecated. Use "Calculate Severity - Generic v2" playbook instead. Calculates and assign the incident severity based on the highest returned severity level from the following severity calculations:
* Indicators DBotScore - Calculates the incident severity level according to the highest indicator DBotScore.
* Critical assets - Determines if a critical assest is associated with the invesigation.
* 3rd-party integrations - Calculates the incident severity level according to the methodology of a 3rd-party integration.
NOTE: the new severity level overwrites the previous severity level even if the previous severity level was more severe.
Calculate Severity - Generic v2 [CommonPlaybooks] — Calculate and assign the incident severity based on the highest returned severity level from the following calculations:
- DBotScores of indicators
- Critical assets
- Email authenticity
- Current incident severity
- Microsoft Headers
- Risky users (XDR)
- Risky hosts (XDR).
Calculate Severity - Standard [CommonPlaybooks] — Calculates and sets the incident severity based on the combination of the current incident severity, and the severity returned from the Calculate Severity By Highest DBotScore playbook.
Caldera Operation [MitreCaldera] — This playbook is used to create a new Operation in Mitre Caldera.
California - Breach Notification [BreachNotification-US] — This playbook helps an analyst determine if the breached data meets the criteria for breach notification according to California law, and, if necessary, follows through with the notification procedures.
DISCLAIMER: Please consult with your legal team before implementing this playbook.
**Source:** http://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82.
Carbon Black Rapid IOC Hunting [DeprecatedContent] — Deprecated. Use "Search Endpoints By Hash - Carbon Black Response V2" playbook instead. Hunt for malicious indicators using Carbon Black
Carbon Black Response - Unisolate Endpoint [Carbon_Black_Enterprise_Response] — This playbook unisolates sensors according to the sensor ID that is provided in the playbook input.
Case Investigation - Google SecOps [GoogleChronicleBackstory] — This playbook investigates a Google SecOps case by retrieving the latest case information, related alerts, and their entities, and updating the case stage. It also calculates severity from IOC scores, updates the incident and case priority accordingly, creates entities in the case from the identified IOCs, and posts a summary comment on the case.
Case Management - Generic [CaseManagement-Generic] — This playbook executes when no other playbook is associated with an incident. It enriches indicators in an incident using one or more integrations.
Change Management [Change_Management] — If you are using PAN-OS/Panorama firewall and Jira or ServiceNow as a ticketing system this playbook is a perfect match for your change management for Firewall process.
This playbook can be triggered by 2 different options - a fetch from ServiceNow or Jira - and will help you manage and automate your change management process.
Check IP Address For Whitelisting - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — Checks if the provided IP Address should be added to allow list and excluded or not. Use this playbook as a sub-playbook to loop over multiple IP Addresses to check if they should be added to allow list and excluded.
Check Indicators For Unknown Assets - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — This playbook receives indicators from its parent playbook and checks if the indicator is an unknown or a known asset in the RiskIQ Digital Footprint inventory and gives out a list of the unknown as well as known assets. This playbook cannot be run in quiet mode. This playbook needs to be used with caution as it might use up the integration’s API license when running for large amounts of indicators.
Supported integration:
- RiskIQ Digital Footprint
Check Point - Credential Leak Validation and Response [Cyberint] — Validates and responds to leaked employee or customer credentials reported by Cyberint Argos.
The playbook looks up leaked credentials for the configured company domain (or, when no domain is configured, uses the exposed credentials embedded in the triggering Cyberint alert), escalates the incident when exposed credentials are found, and drives an automated or semi-automated remediation flow (reset sessions, force password reset, or disable the account in the identity provider), followed by user and SOC notification.
Identity-provider validation and remediation steps are modeled as manual tasks so the playbook works out of the box; connect them to your Active Directory, Microsoft Entra ID or Okta integration to fully automate the response.
Check Point - IOC Enrichment and Triage [Cyberint] — Enriches IOC entities (IP, domain, URL, file hash) found in an incident with Cyberint threat intelligence, then applies triage decision logic.
The playbook routes each indicator to the matching Cyberint IOC enrichment endpoint, appends the returned maliciousness score and detected activities to the incident, and escalates the incident severity when a malicious indicator is found.
Requires the Check Point EM Feed (Cyberint Feed) integration to be configured.
Check Point - Phishing Takedown [Cyberint] — Automates or semi-automates the takedown of high-confidence phishing websites detected by Cyberint.
The playbook evaluates the confidence and severity of a Cyberint phishing-website alert, submits a takedown request via the Cyberint Takedown API (automatically or after analyst approval), polls the takedown request until it reaches a terminal status, and annotates the incident and notifies the SOC of the outcome.
Requires the Cyberint Takedown integration to be configured.
Check Point - Vulnerability Exploitation Monitoring [Cyberint] — Enriches CVEs from a vulnerability-management incident with Cyberint vulnerability intelligence and prioritizes them based on real-world exploitation.
For each CVE the playbook retrieves the Cyberint CVE score, CVSS, EPSS, CWE and active-exploitation evidence. When a CVE exceeds the configured risk thresholds or is being actively exploited, the incident is escalated and a patch-remediation ticket is opened; otherwise the CVE is tagged as monitored.
Connect the remediation task to your ticketing system and CMDB to fully automate risk-based vulnerability management.
Check WebEx Feed [CiscoWebExFeed] — Deprecated. No available replacement.
ChronicleAsset Investigation - Chronicle [GoogleChronicleBackstory] — This playbook receives indicators from its parent playbook, performs enrichment and investigation for each one of them, provides an opportunity to isolate and block the hostname or IP address associated with the current indicator, and gives out a list of isolated and blocked entities. This playbook also lists the events fetched for the asset identifier information associated with the indicator.
ChronicleAssets Investigation And Remediation - Chronicle [GoogleChronicleBackstory] — Performs enrichment and investigation of the ChronicleAsset type of indicators, provides an opportunity to remediate in case any of the ChronicleAsset information i.e., hostname or IP address is found to be malicious or suspicious, and sends out an email containing the list of isolated and potentially blocked entities. To select the indicators you want to add, go to playbook inputs, choose "from indicators" and set your query. For example, type:ChronicleAsset etc. The default playbook query is "type:ChronicleAsset". In case indicators with different query parameters are to be investigated, the query must be edited accordingly. This playbook needs to be used with caution as it might use up the integration’s API license when running large amounts of indicators.
Cloaked Ursa Diplomatic Phishing Campaign [CloakedUrsaPhishingCampaign] — ## Cloaked Ursa: Targeting Diplomatic Missions with Phishing Lures
**Summary:**
Cloaked Ursa, a hacking group associated with Russia's Foreign Intelligence Service, has been persistently targeting diplomatic missions globally. Using phishing tactics, Their initial access attempts over the past two years have predominantly used phishing lures with a theme of diplomatic operations such as the following:
- Notes verbale (semiformal government-to-government diplomatic communications)
- Embassies’ operating status updates
- Schedules for diplomats
- Invitations to embassy events
Recently, Unit42 researchers observed a shift in their strategy, with a focus on targeting diplomats themselves. In Kyiv alone, at least 22 out of over 80 foreign missions were targeted.
**This playbook should be triggered manually or can be configured as a job.**
Please create a new incident and choose the Cloaked Ursa (APT29) Diplomatic Phishing Campaign playbook and Rapid Breach Response incident type.
**The playbook includes the following tasks:**
**IoCs Collection**
- Blog IoCs download
**Hunting:**
- Cortex XDR XQL exploitation patterns hunting
- Advanced SIEM exploitation patterns hunting
- Indicators hunting
The hunting queries are searching for the following activities:
- Related LNK files execution command line
- Dropped file names
**Mitigations:**
- Unit42 mitigation measures
**References:**
[Diplomats Beware: Cloaked Ursa Phishing With a Twist](https://unit42.paloaltonetworks.com/cloaked-ursa-phishing/)
Close Duplicate XSOAR Incidents - Vectra Detect [Vectra_AI] — This playbook is called from the Close All Duplicate XSOAR Incidents - Vectra Detect playbook. It will close the duplicate incidents in XSOAR and resolve its assignment in Vectra.
Close Related XSOAR and Incydr Incidents [Code42] — Checks for open XSOAR incidents associated with Incydr alerts and passes them to the Check Incydr Status and Close XSOAR Incident playbook.
Cloud Compute Enrichment - Generic [CommonPlaybooks] — This playbook provides a generic enrichment of AWS, GCP, and Azure compute resources.
Cloud Credentials Rotation - AWS [AWS-Enrichment-Remediation] — ## **AWS Credentials Rotation Playbook**
### **Identity Remediation**
Secure compromised accounts by taking swift action:
- **Reset Password**: Resets the user password to halt any unauthorized access.
- **Access Key Deactivation**: Deactivate any suspicious or known-compromised access keys.
- **Combo Action**: In some cases, you may want to reset both the password and deactivate the access key for absolute security.
### **Role Remediation**
If a role is suspected to be compromised:
- **Deny Policy Implementation**: Attach a deny-all policy to the compromised role, thus preventing it from performing any further actions.
- **Role Cloning**: Before outright remediation, clone the role. This ensures that you have a backup with the same permissions, making transition smoother.
Cloud Credentials Rotation - Azure [Azure-Enrichment-Remediation] — ## **Azure Credentials Rotation Playbook**
### **IAM Remediation**
Protect your identity and access management:
- **Reset Password**: Resets the user password to halt any unauthorized access.
- **Revoke Session**: Terminates current active sessions to ensure the malicious actor is locked out.
- **Combo Action**: Resets the password and terminates all active sessions.
### **Service Principal Remediation**
Guard your applications:
- **Password Regeneration**: Generate a new password for the service principal, making sure the old one becomes obsolete.
Cloud Credentials Rotation - GCP [GCP-Enrichment-Remediation] — ## **GCP Credentials Rotation Playbook**
### **IAM Remediation**
For compromised service accounts:
- **Access Key Disabling**: Immediately disable the compromised service account access key.
- **New Key Generation**: After ensuring the old key is disabled, generate a new access key.
### **GSuite Admin Remediation**
Admin accounts are crucial:
- **Reset Password**: Resets the user password to halt any unauthorized access.
- **Revoke Access Token**: Revoke any suspicious or unauthorized access tokens.
- **Combo Action**: Reset the password and revoke access tokens to ensure complete safety.
Cloud Credentials Rotation - Generic [CommonPlaybooks] — ## **Cloud Credentials Rotation - Generic**
This comprehensive playbook combines the remediation steps from AWS, Azure, and GCP sub-playbooks into a single, cohesive guide. Regardless of which Cloud Service Provider (CSP) you're working with, this playbook will direct you to the relevant steps, ensuring swift and effective response.
The primary objective is to offer an efficient way to address compromised credentials across different cloud platforms. By consolidating the key steps from AWS, Azure, and GCP, it minimizes the time spent searching for platform-specific procedures and accelerates the remediation process, ensuring the highest level of security for your cloud environments.
## **Integrations for Each Sub-Playbook**
In order to seamlessly execute the actions mentioned in each sub-playbook, specific integrations are essential. These integrations facilitate the automated tasks and processes that the playbook carries out. Here are the required integrations for each sub-playbook:
### **AWS Sub-Playbook:**
1. [**AWS - IAM**](https://xsoar.pan.dev/docs/reference/integrations/aws---iam): Used to manage AWS Identity and Access Management.
2. [**AWS - EC2**](https://xsoar.pan.dev/docs/reference/integrations/aws---ec2): Essential for managing Amazon Elastic Compute Cloud (EC2) instances.
### **GCP Sub-Playbook:**
1. [**Google Workspace Admin**](https://xsoar.pan.dev/docs/reference/integrations/g-suite-admin): Manages users, groups, and other entities within Google Workspace.
2. [**GCP-IAM**](https://xsoar.pan.dev/docs/reference/integrations/gcp-iam): Ensures management and control of GCP's Identity and Access Management.
### **Azure Sub-Playbook:**
1. [**Microsoft Graph Users**](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-user): Manages users and related entities in Microsoft Graph.
2. [**Microsoft Graph Applications**](https://xsoar.pan.dev/docs/reference/integrations/microsoft-graph-applications): Manages applications within Microsoft Graph.
Cloud Data Exfiltration Response [CloudIncidentResponse] — ## Cloud Data Exfiltration Response
The Cloud Data Exfiltration Response playbook is designed to address data exfiltration activity alerts in the cloud environment. This playbook is intended for handling "An identity performed a suspicious download of multiple cloud storage object" alert.
The playbook supports AWS, GCP, and Azure and executes the following:
- Enrichment involved assets.
- Determines the appropriate verdict based on the data collected from the enrichment.
- Cloud Persistence Threat Hunting:
- Conducts threat hunting activities to identify any cloud persistence techniques
- Verdict Handling:
- Handles false positives identified during the investigation
- Handles true positives by initiating appropriate response actions
Cloud Enrichment - Generic [CommonPlaybooks] —
## Generic Cloud Enrichment Playbook
The **Cloud Enrichment - Generic Playbook** is designed to unify all the relevant playbooks concerning the enrichment of information in the cloud. It provides a standardized approach to enriching information in cloud environments.
### Supported Blocks
1. **Cloud IAM Enrichment - Generic**
- Enriches information related to Identity and Access Management (IAM) in the cloud.
2. **Cloud Compute Enrichment - Generic**
- Enriches information related to cloud compute resources.
The playbook supports a single CSP enrichment at a time.
Cloud IAM Enrichment - Generic [CommonPlaybooks] — This playbook is responsible for collecting and enriching data on Identity Access Management (IAM) in cloud environments (AWS, Azure, and GCP).
Cloud IAM User Access Investigation [CloudIncidentResponse] — Investigate and respond to Cortex XSIAM alerts where a Cloud IAM user access key is used suspiciously to access the cloud environment.
The following alerts are supported for AWS, Azure, and GCP environments.
Penetration testing tool attempt
Penetration testing tool activity
Suspicious API call from a Tor exit node
Cloud Response - AWS [AWS-Enrichment-Remediation] — This playbook provides response actions to AWS. The following are available for execution automatically/manually:
- Resource remediation:
- Terminate the instance
- Stop the instance
- Identity remediation:
- Delete the user
- Revoke the user's credentials
- Access key remediation:
- Disable the access key
- Delete the access key
- Block indicators.
Cloud Response - Azure [Azure-Enrichment-Remediation] — This playbook provides response actions to Azure. The following are available for execution automatically/manually:
- Resource remediation
- Delete the instance
- Power off the instance
- Identity remediation:
- Disable the user
- Delete the user
- Block indicators.
Cloud Response - GCP [GCP-Enrichment-Remediation] — This playbook provides response actions to GCP. The following are available for execution automatically/manually:
- Resource remediation:
- Delete the instance
- Stop the instance
- Identity remediation:
- Disable the user
- Delete the user
- Access key remediation:
- Disable the access key
- Delete the access key
- Block indicators.
Cloud Response - Generic [CommonPlaybooks] — This playbook provides response playbooks for:
- AWS
- Azure
- GCP
The response actions available are:
- Terminate/Shut down/Power off an instance
- Delete/Disable a user
- Delete/Revoke/Disable credentials
- Block indicators
Cloud Threat Hunting - Persistence [CloudIncidentResponse] — ---
## Cloud Threat Hunting - Persistence Playbook
The playbook is responsible for hunting persistence activity in the cloud. It supports AWS, GCP, and Azure - one at a time.
### Hunting Queries
The playbook executes hunting queries for each provider related to each of the following:
1. IAM
2. Compute Resources
3. Compute Functions
### Indicator Extraction
If relevant events are found during the search, indicators will be extracted using the `ExtractIndicators-CloudLogging` script.
---
Cloud Token Theft - Set Verdict [CloudIncidentResponse] — ---
## Cloud Token Theft - Set Verdict Playbook
The playbook is built from a decision tree whose ultimate goal is to decide whether the observed activity is malicious.
### Event Search
The playbook searches for events based on the attacker's IP address within the last two hours.
### Tests Performed
The following tests are performed on the observed activity:
1. **Malicious IP Check**: Determines if the IP address is malicious.
2. **CSP ASN Check**: Checks if the activity was performed from an Autonomous System Number (ASN) belonging to one of the Cloud Service Providers (CSPs).
3. **IP and ASN History Check**: Verifies if the IP address and ASN have been previously observed.
4. **Region Check**: Determines if the API call was made from outside the recognized region.
5. **Anomalous State Check**: Checks if the API call was made from an anomalous state.
6. **Alert Check**: Looks for any related alerts around the event, including:
- Possible cloud instance metadata service (IMDS) abuse.
- Impossible Traveler by cloud identity.
---
Cloud Token Theft Response [CloudIncidentResponse] — ---
## Cloud Token Theft Response Playbook
The **Cloud Token Theft Response Playbook** provides a structured and comprehensive flow to effectively respond to and mitigate alerts involving the theft of cloud tokens. The playbook supports AWS, GCP, and Azure and executes the following:
**Cloud Enrichment:**
- Enriches the involved resources
- Enriches the involved identities
- Enriches the involved IPs
**Verdict Decision Tree:**
- Determines the appropriate verdict based on the investigation findings
**Early Containment using the Cloud Response - Generic Playbook:**
- Implements early containment measures to prevent further impact
**Cloud Persistence Threat Hunting:**
- Conducts threat hunting activities to identify any cloud persistence techniques
**Enriching and Responding to Hunting Findings:**
- Performs additional enrichment and responds to the findings from threat hunting
**Verdict Handling:**
- Handles false positives identified during the investigation
- Handles true positives by initiating appropriate response actions
---
Cloud User Investigation - Generic [CommonPlaybooks] — This playbook performs an investigation on a specific user in cloud environments, using queries and logs from Azure Log Analytics, AWS CloudTrail, G Suite Auditor, and GCP Logging.
Cluster Report Categorization - Cofense Triage v3 [CofenseTriage] — Cluster Report Categorization playbook is used to retrieve the reports of specific clusters and perform the categorization of reports.
Code42 Add Departing Employee From Ticketing System v2 [Code42] — Parses a Ticket Summary containing a username='username' and optionally a departure='date' and adds the user to the Code42 Departing Employee list. This playbook uses Jira out-of-the-box, but you can swap it with a different Ticketing system and achieve the same result. For example, to use Zendesk, change the command `jira-get-issue` to be `zendesk-ticket-details` and use the `id` parameter for `issueId`. Change the output (what gets parsed) to be either the Subject or the Description from Zendesk.
Code42 Copy File To Ticketing System v2 [Code42] — Downloads a file from Code42 and attaches it to a ticketing system. This playbook uses Jira out-of-the-box, but you can swap it with a different Ticketing system and achieve the same result. For example, to use ServiceNow, change the command `jira-issue-upload-file` to be `servicenow-upload-file` and use the `id` parameter for `issueId` and `file_id` for `entryId`.
Code42 Exfiltration Playbook [Code42] — The Code42 Exfiltration playbook acts on Code42 Security Alerts, retrieves file event data, and allows security teams to remediate file exfiltration events by revoking access rights to cloud files or containing endpoints.
Code42 File Download [Code42] — This playbook downloads a file via Code42 by either MD5 or SHA256 hash.
Code42 File Search [Code42] — This playbook searches for files via Code42 security events by either MD5 or SHA256 hash. The data is output to the Code42.SecurityData context for use.
Code42 File Search v2 [Code42] — This playbook searches for files via Code42 security events by either MD5 or SHA256 hash. The data is output to the Code42.FileEvents context for use.
Code42 Security Alert [Code42] — Retrieves Incydr alert details, assigns the alert to an analyst, and gathers employee and supervisor data from Active Directory, if applicable. Note: this playbook can be used as an alternate default to "Code42 Exfiltration Playbook" when the Code42 Incydr integration is set to "Fetch Incidents".
Code42 Suspicious Activity Review v2 [Code42] — Detects suspicious activities of a user and allows a recipient to assess the results. Afterward, the playbook takes action on the user such as adding them to legal hold.
Codecov Breach - Bash Uploader [MajorBreachesInvestigationandResponse] — This playbook includes the following tasks:
- Search for the Security Notice email sent from Codecov.
- Collect indicators to be used in your threat hunting process.
- Query network logs to detect related activity.
- Search for the use of Codecov bash uploader in GitHub repositories
- Query Panorama to search for logs with related anti-spyware signatures
- Data Exfiltration Traffic Detection
- Malicious Modified Shell Script Detection
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
More information:
[Codecov Security Notice](https://about.codecov.io/security-update/)
Command-Line Analysis [CommonPlaybooks] — This playbook takes a command line from the alert and performs the following actions:
- Checks for base64 string and decodes if exists
- Extracts and enriches indicators from the command line
- Checks specific arguments for malicious usage
At the end of the playbook, it sets a possible verdict for the command line, based on the finding:
1. Indicators found in the command line
2. Found AMSI techniques
3. Found suspicious parameters
4. Usage of malicious tools
5. Indication of network activity
6. Indication of suspicious LOLBIN execution
7. Suspicious path and arguments in the command line
Note: To run this playbook with a list of command lines, set this playbook to run in a loop. To do so, navigate to 'Loop' and check "For Each Input".
Compare Process Execution Arguments To LOLBAS Patterns [FeedLOLBAS] — This playbook takes a process name and determines its presence in the LOLBAS repository. It then proceeds to compare the incident command line against known patterns of malicious commands listed in TIM by using LOLBAS feed integration. The playbook outputs results when the similarity between the analyzed command line and the malicious patterns is greater than or equal to the preconfigured StringSimilarity threshold. The playbook offers the flexibility to adjust this threshold through the use of the dedicated playbook input, 'StringSimilarityThreshold'.
Compromised Credentials Match - Flashpoint [Flashpoint] — The Compromised Credentials Match playbook uses the details of the compromised credentials ingested from Flashpoint Ignite and authenticates using the Active Directory integration by providing the compromised credentials of the user. It then expires the credentials if it matches, and sends an email alert about the breach.
Supported integrations:
- Flashpoint
- OpenLDAP
- Active Directory Query v2
Configuration Setup [ContentManagement] — Playbook for the configuration incident type.
Containment Plan [CommonPlaybooks] — This playbook handles the main containment actions available with Cortex XSIAM, including the following sub-playbooks:
* Containment Plan - Isolate endpoint
* Containment Plan - Disable account
* Containment Plan - Quarantine file
* Containment Plan - Block indicators
* Containment Plan - Clear user session (currently, the playbook supports only Okta)
Note: The playbook inputs enable manipulating the execution flow. Read the input descriptions for details.
Containment Plan - Block Indicators [CommonPlaybooks] — ## Containment Plan - Block Indicators
This playbook is a sub-playbook within the containment plan playbook.
### Indicator Blocking
The playbook block indicators by two methods:
1. It adds the malicious hashes into the XSIAM hash block list
2. It utilizes the sub-playbook "Block Indicators - Generic v3"
Containment Plan - Clear User Sessions [CommonPlaybooks] — ## Containment Plan - Clear User Sessions
This playbook is a sub-playbook within the containment plan playbook.
The playbook uses the 'Okta v2' and 'MSGraph User' integrations to clear user sessions.
Containment Plan - Disable Account [CommonPlaybooks] — ## Containment Plan - Disable Account
This playbook is a sub-playbook within the containment plan playbook.
The playbook disables users by utilizing the sub-playbook "Block Account - Generic v2"
Containment Plan - Isolate Device [CommonPlaybooks] — ## Containment Plan - Isolate Device
This playbook is a sub-playbook within the containment plan playbook.
The playbook isolates devices using core commands.
Containment Plan - Quarantine File [CommonPlaybooks] — ## Containment Plan - Quarantine File
This playbook is a sub-playbook within the containment plan playbook.
The playbook quarantines files using core commands.
Content Update Check [XSOARContentUpdateNotifications] — Deprecated. Use "Content Update Manager" playbook instead. This playbook will check to see if there are any content updates available for installed packs and notify users via e-mail or Slack.
Content Update Manager [XSOARContentUpdateNotifications] — This playbook checks for any available content updates for selected installed content packs and notifies users via e-mail or Slack.
It also contains an auto-update flow that lets users decide via playbook inputs or communication tasks if they want to trigger an auto-update process to install all updates that were found.
This playbook can be used as a Cortex XSOAR job to help users track marketplace pack updates and install them regularly.
Context Polling - DT [CommonPlaybooks] — This playbook polls a context value until a specific condition, defined by a DT expression, is met.
Context Polling - Generic [CommonPlaybooks] — This playbook polls a context key to check if a specific value exists.
Convert file hash to corresponding hashes [CommonPlaybooks] — The playbook enables you to get all of the corresponding file hashes for a file even if there is only one hash type available.
For example, if we have only the SHA256 hash, the playbook will get the SHA1 and MD5 hashes as long as the
original searched hash is recognized by any our the threat intelligence integrations.
Cortex XDR - AWS IAM user access investigation [CortexXDR] — Deprecated. Use `Cortex XDR - Cloud IAM User Access Investigation` instead. Investigate and respond to Cortex XDR Cloud alerts where an AWS IAM user`s access key is used suspiciously to access the cloud environment.
The following alerts are supported for AWS environments.
- Penetration testing tool attempt
- Penetration testing tool activity
- Suspicious API call from a Tor exit node
This is a beta playbook, which lets you implement and test pre-release software. At the moment we support AWS but are working towards multi-cloud support. Since the playbook is beta, it might contain bugs. Updates to the playbook during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the content to help us identify issues, fix them, and continually improve.
Cortex XDR - Block File [CortexXDR] — Use this playbook to add files to Cortex XDR block list with a given file SHA256 playbook input.
Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer [CVE_2025_31324] — This playbook should be triggered manually or can be configured as a job.
Please create a new incident and choose the Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer playbook and Rapid Breach Response incident type.
CVE-2025-31324 is a critical zero-day vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. The vulnerability arises from missing authorization checks, allowing unauthenticated attackers to upload malicious executable binaries. Exploitation of this flaw can lead to full remote code execution (RCE) on affected systems, posing a significant risk to confidentiality, integrity, and availability.
## CVE-2025-31324 - SAP NetWeaver RCE Vulnerability
## Vulnerability Overview
- **Component Affected**: SAP NetWeaver Visual Composer Metadata Uploader
- **Endpoint**: `/developmentserver/metadatauploader`
- **CVE ID**: CVE-2025-31324
- **CVSS Score**: 10.0 (Critical)
- **Exploitability**: Unauthenticated remote attackers can exploit this without user interaction
This flaw allows unauthenticated attackers to upload arbitrary files (e.g., JSP web shells), enabling remote code execution with the same privileges as the SAP application server process.
[Source: Unit42 - Palo Alto Networks](https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/)
## Mitigation and Recommendations
- **Apply Patch**: SAP Note #3594142 (released April 24, 2025)
- **Disable Visual Composer** if not in use
- **Restrict Access** to the vulnerable endpoint
- **Monitor for IoCs** in `/irj/servlet_jsp/irj/root/` and suspicious traffic
## Conclusion
CVE-2025-31324 is actively exploited and is critically severe. Organizations should patch immediately, monitor for compromise, and disable or restrict vulnerable components.
[View official CVE details on NIST](https://nvd.nist.gov/vuln/detail/CVE-2025-31324)
## Playbook Triggers
- Manually
- "CVE Exploitation - 986328356" Agent rule
## Playbook Flow
- Collects IoCs from Unit42 blog.
- Downloads Sigma rules.
- Search for CVE Exploitation alerts.
- Directory enumeration to identify if there are already any suspicious files that might indicate a webshell.
- Using XQL, identify potential SAP NetWeaver instances in your environment.
- Using XQL, check if there are events that point to any potential webshells downloaded in the directories.
- Hunt the IoCs using Panorama and 3rd party SIEM.
- Remediate using "Block Indicators - Generic v3" playbook.
- Provides Mitigation recommendations.
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Cortex XDR - CVE-2025-49704 and CVE-2025-49706 and CVE-2025-53770 and CVE-2025-53771 - Microsoft SharePoint ToolShell vulnerability chain [Microsoft_SharePoint_ToolShell_Vulnerability] — This playbook should be triggered manually or can be configured as a job.
CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 are a set of vulnerabilities that impact Microsoft SharePoint. CVE-2025-49704 and CVE-2025-49706, or CVE-2025-53770 and CVE-2025-53771, may be chained together, allowing unauthenticated threat actors to access functionality that is normally restricted, to run arbitrary commands on vulnerable instances of Microsoft SharePoint.
### Vulnerability Overview
* **Platform Affected**: Microsoft SharePoint Server 2016 / 2019 / Subscription Edition
* **CVE IDs**:
* CVE-2025-49706 – Improper authentication in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
* CVE-2025-49704 – Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
* CVE-2025-53770 – Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
* CVE-2025-53771 – Improper limitation of a pathname to a restricted directory (path traversal) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
* **CVSS Scores**: 7.1, 8.8, 9.8 ,7.1
* **Impact**:When chained together, they allow an attacker to run arbitrary commands on vulnerable instances of Microsoft SharePoint.
These flaws enable an attacker to:
- Spoof authentication
- Bypass security boundaries
- Gain remote execution
### Mitigation & Recommendations
* Apply Patches Immediately:
* [CVE-2025-49706](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706)
* [CVE-2025-49704](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49704)
* [CVE-2025-53770](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770)
* [CVE-2025-53771](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53771)
* Harden SharePoint diagnostic/debug endpoints
* Rotate SharePoint Server ASP.NET machine keys
* Check IIS logs for suspicious activity
* Disable/Isolate unnecessary SharePoint services or endpoints (at least until those servers are patched)
---
### References
* [CVE-2025-49706 - NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-49706)
* [CVE-2025-49704 - NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-49704)
* [CVE-2025-53770 - NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-53770)
* [CVE-2025-53771 - NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-53771)
* [Microsoft Security Update – July 2025](https://msrc.microsoft.com/update-guide/)
* [Unit42 Blog](https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/)
---
### How to trigger the playbook
Triggered via:
- Cortex XDR alerts: `"CVE Exploitation - 685768089"` or `"CVE Exploitation - 818854253"` or `"CVE Exploitation - 903162508"`
- Manual creation of an alert with this playbook.
---
### Playbook Flow
1. Run XQL Queries to detect possible affected servers running Microsoft SharePoint.
2. Search for downloaded or created webshell files using XQL (especially for the known file name artifacts).
3. Run XQL on network events and XDR .net events to determine if there was any usage of the CVEs in the organization.
4. Check for malicious activity on the possible affected hosts for post-exploitation activities (such as running PowerShell encoded commands on the hosts) via additional alerts on the same host.
5. Retrieve IOCs from the Unit42 blog, hunt for those IOCs with XQL, and block malicious indicators.
6. Instruct the analyst on relevant response actions and mitigation steps.
---
**Note:**
This is a beta playbook. Updates to the pack during the beta phase might include non-backward-compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Cortex XDR - CVE-2025-59287 - Microsoft WSUS Remote Code Execution [CVE_2025-59287_-_Microsoft_WSUS_RCE] — CVE-2025-59287 - Microsoft WSUS Remote Code Execution
## Vulnerability Overview
- **Vulnerability Name**: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
- **CVE ID**: CVE-2025-59287
- **CVSS Score**: 9.8 (Critical)
An unauthenticated remote code execution (RCE) vulnerability has been identified in Microsoft Windows Server Update Services (WSUS).
[Source: Unit42 - Palo Alto Networks](https://unit42.paloaltonetworks.com/microsoft-cve-2025-59287/)
## Mitigation and Recommendations
- **Apply Patch**
- **Restrict Access** to the vulnerable serves
- **Monitor for IoCs and suspicious traffic**
## Conclusion
CVE‑2025‑59287 is a critical, remotely exploitable vulnerability in WSUS that allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges.
[View official CVE details on NIST](https://nvd.nist.gov/vuln/detail/CVE-2025-59287)
## Playbook Triggers
- Manually
## Playbook Flow
1. Uses XQL to identify WSUS servers in your environment.
2. Collects IOCs from the Unit42 blog.
3. Uses XQL to detect any suspicious command lines indicative of exploitation of this vulnerability.
4. Investigates the command lines to identify malicious indicators related to the vulnerability.
5. Uses XQL to hunt for malicious IOCs.
6. Isolates compromised WSUS servers.
7. Blocks malicious indicators using the "Block Indicators - Generic v3" playbook.
8. Provides mitigation recommendations.
Cortex XDR - Cloud Data Exfiltration Response [CloudIncidentResponse] — ## Data Exfiltration Response
The Data Exfiltration Response playbook is designed to address data exfiltration activity alerts in the cloud environment. This playbook is intended for handling "An identity performed a suspicious download of multiple cloud storage object" alert.
The playbook supports AWS, GCP, and Azure and executes the following:
- Enrichment involved assets.
- Determines the appropriate verdict based on the data collected from the enrichment phase.
- Cloud Persistence Threat Hunting:
- Conducts threat hunting activities to identify any cloud persistence techniques
- Verdict Handling:
- Handles false positives identified during the investigation
- Handles true positives by initiating appropriate response actions
Cortex XDR - Cloud Enrichment [CloudIncidentResponse] — This playbook is responsible for collecting data from Cortex XDR detector and enriching data for further usage and building the layout.
The playbook collects or enriches the following data:
- Resource enrichment
- Previous activity seen in the specified region or project
- Account enrichment
- Network enrichment
- Attacker IP
- Geolocation
- ASN
Cortex XDR - Cloud IAM User Access Investigation [CloudIncidentResponse] — Investigate and respond to Cortex XDR Cloud alerts where a Cloud IAM user`s access key is used suspiciously to access the cloud environment.
The following alerts are supported for AWS, Azure, and GCP environments.
- Penetration testing tool attempt
- Penetration testing tool activity
- Suspicious API call from a Tor exit node
Cortex XDR - Display Risky Assets [CortexXDR] — This playbooks displays risky users and risky hosts, as detected by Cortex XDR's ITDR module. The data is displayed in incident fields in Cortex XDR incidents.
Cortex XDR - Endpoint Investigation [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response. This playbook handles all the endpoint investigation actions available with Cortex XSOAR, including the following tasks:
* Pre-defined MITRE Tactics
* Host fields (Host ID)
* Attacker fields (Attacker IP, External host)
* MITRE techniques
* File hash (currently, the playbook supports only SHA256)
Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.
Cortex XDR - Execute commands [CortexXDR] — Deprecated. Use the `xdr-script-commands-execute` command instead. Initiates a new script execution of shell commands.
Cortex XDR - Execute snippet code script [CortexXDR] — Deprecated. Use the `xdr-snippet-code-script-execute` command instead. Initiates a new endpoint script execution action using the provided snippet code and retrieves the file results.
Cortex XDR - False Positive Incident Handling [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles false-positive incident closures for Cortex XDR - Malware investigation.
Cortex XDR - First SSO Access [CortexXDR] — Deprecated. Use `Cortex XDR - Identity Analytics` instead.
Investigates a Cortex XDR incident containing First SSO access from ASN in organization
or First successful SSO connection from a country in organization.
The playbook executes the following:
- IP and User Enrichment.
- User Investigation - Using 'User Investigation - Generic' sub-playbook.
- Set alert's verdict - Using 'Cortex XDR - First SSO access - Set Verdict' sub-playbook.
- Response based on the verdict.
The playbook is used as a sub-playbook in ‘Cortex XDR Incident Handling - v3’.
Cortex XDR - First SSO Access - Set Verdict [CortexXDR] — Deprecated. Use `Cortex XDR - Identity Analytics` instead.
This playbook determines the alert’s verdict based on the results of multiple checks.
By default, if at least two of the checks' results are true, the verdict is set to malicious.
else if only one check's results are true, the verdict is set to suspicious.
If none of the conditions is true, the verdict is set to non-malicious.
It is possible to change the threshold value of the inputs to change the sensitivity of the verdict.
Cortex XDR - Get File Path from alerts by hash [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook assists in retrieving file paths from the Cortex XDR incident by hash.
Cortex XDR - Get entity alerts by MITRE tactics [CortexXDR] — This playbook is part of the Cortex XDR by Palo Alto Networks’ pack. This playbook searches alerts related to specific entities from Cortex XDR, on a given timeframe, based on MITRE tactics.
Note: The playbook's inputs enable manipulating the execution flow. Read the input descriptions for details.
Cortex XDR - Get entity alerts by MITRE tactics CTF [ctf01] — This playbook is part of the Cortex XDR by Palo Alto Networks’ pack. This playbook searches alerts related to specific entities from Cortex XDR, on a given timeframe, based on MITRE tactics.
Note: The playbook's inputs enable manipulating the execution flow. Read the input descriptions for details.
Cortex XDR - Identity Analytics [CortexXDR] — The `Cortex XDR - Identity Analytics` playbook is designed to handle Cortex XDR Identity Analytics alerts and executes the following:
Analysis:
- Enriches the IP address and the account, providing additional context and information about these indicators.
Verdict:
- Determines the appropriate verdict based on the data collected from the enrichment phase.
Investigation:
- Checks for related Cortex XDR alerts to the user by Mitre tactics to identify malicious activity.
- Checks for specific arguments for malicious usage from Okta using the 'Okta User Investigation' sub-playbook.
- Checks for specific arguments for malicious usage from Azure using the 'Azure User Investigation' sub-playbook.
Verdict Handling:
- Handles malicious alerts by initiating appropriate response actions, including blocking malicious IP addresses and revoking or clearing user's sessions.
- Handles non-malicious alerts identified during the investigation.
The playbook is used as a sub-playbook in ‘Cortex XDR Alerts Handling v2’.
Cortex XDR - Isolate Endpoint [CortexXDR] — This playbook accepts an XDR endpoint ID and isolates it using the 'Palo Alto Networks Cortex XDR - Investigation and Response' integration.
Cortex XDR - Malicious Pod Response - Agent [CloudIncidentResponse] — This playbook ensures a swift and effective response to malicious activities within Kubernetes environments, leveraging cloud-native tools to maintain cluster security and integrity.
The playbook is designed to handle agent-generated alerts due to malicious activities within Kubernetes (K8S) pods, such as mining activities, which require immediate action. The playbook also addresses scenarios where the malicious pod is killed, but the malicious K8S workload repeatedly creates new pods.
### Key Features:
AWS Function Integration: This utilizes an AWS Lambda function that can manage resources and facilitate rapid response actions within an Amazon EKS cluster without the need for third-party tools such as Kubectl.
The Lambda function can initiate the following response actions:
- Pod Termination: The playbook includes steps to safely terminate the affected pod within the K8S environment.
- Workload Suspension: If necessary, the playbook can be escalated to suspend the entire workload associated with the mining activity.
Once the Lambda function execution is completed, the playbook deletes all of the created objects to ensure undesirable usage.
### Workflow:
1. Alert Detection: The playbook begins with the monitoring agent detecting a mining alert within a Kubernetes pod.
2. Alert Validation: Validates the alert to ensure it is not a false positive.
3. Response Decision:
- Pod Termination: If the mining activity is isolated to a single pod, the AWS Lambda function is invoked to terminate the affected pod within the K8S environment.
- Workload Suspension: If the mining activity is widespread or poses a significant threat, the AWS Lambda function suspends the entire workload within the K8S environment.
4. Cleanup: This action initiates the complete removal of all objects created for the Lambda execution for security and hardening purposes.
### Required Integration
#### AWS IAM (Identity and Access Management)
- [AWS IAM API Documentation](https://docs.aws.amazon.com/IAM/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS IAM Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSIAM/)
#### AWS EC2 (Elastic Compute Cloud)
- [AWS EC2 API Documentation](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS EC2 Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSEC2/)
#### AWS EKS (Elastic Kubernetes Service)
- [AWS EKS API Documentation](https://docs.aws.amazon.com/eks/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS EKS Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSEKS/)
#### AWS Lambda
- [AWS Lambda API Documentation](https://docs.aws.amazon.com/lambda/latest/dg/API_Reference.html)
- [Cortex XSOAR AWS Lambda Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSLambda/).
Cortex XDR - Possible External RDP Brute-Force [CortexXDR] — This playbook investigates a “Possible External RDP Brute Force” XDR Alert by gathering user, IP, and hostname information, and investigating if the following suspicious elements exists:
- "IP Reputation" - Dbot Score is 2-3
- "Source geolocation" - RDP Connection made from rare geo-location
- Related to campaign - IP address is related to campaign, based on TIM module
- Hunting results - the hunt for indicators related to the source IP and the related campaign returned results
- XDR Alert search - XDR Alerts that related to the same username and endpoint, and to the MITRE tactics that comes after "Credential Access", were found.
- Risky User - The user that was identified in the attack was given a medium or high score by XDR's ITDR module.
- Risky Host - The destination host that was identified in the attack was given a medium or high score by XDR's ITDR module.
Set verdict method:
* Critical Element - The "Critical Element" input allows you to select a specific element that, if identified as suspicious, the investigation's final verdict will be deemed a "True Positive".
* Final Verdict - Each suspicious element is being added to an array called "Suspicious Elements", which is used to count potential security threats. The array size will be compared to a final threshold. If the size is greater than or equal to the threshold, the investigation's final verdict will be deemed a "True Positive".
* User Engagement - The "UserEngagementThreshold" input allows you to set the number of suspicious elements that trigger user engagement. When this threshold is met, an email will be sent to the user and their manager asking for authorization of RDP activity. If the RDP activity is not authorized by the user, the investigation's final verdict will be deemed a "True Positive".
Cortex XDR - Possible External RDP Brute-Force - Set Verdict [CortexXDR] — This playbook creating an array called "Suspicious Elements", which is used to count potential security threats. The following elements can be added to the array:
- "IP Reputation" - DBot Score is 2-3
- "Source geolocation" - RDP Connection made from rare geo-location
- Related to campaign - IP address is related to campaign, based on TIM module
- Hunting results - the hunt for indicators related to the source IP and the related campaign returned results
- XDR Alert search - XDR Alerts that related to the same username and endpoint, and to the MITRE tactics that comes after "Credential Access", were found.
- Risky User - one or more risky users are involved in the incident, as identified by the Cortex XDR - IR integration's ITDR module.
- Risky Host - one or more risky hosts are involved in the incident, as identified by the Cortex XDR - IR integration's ITDR module.
The array will then be outputted and its size will be compared to a final threshold. If the size is greater than or equal to the threshold, the investigation's final verdict will be deemed a "True Positive."
Cortex XDR - Possible External RDP Brute-Force CTF [ctf01] — This playbook investigates a “Possible External RDP Brute Force” XDR Alert by gathering user, IP, and hostname information, and investigating if the following suspicious elements exists:
- "IP Reputation" - Dbot Score is 2-3
- "Source geolocation" - RDP Connection made from rare geo-location
- Related to campaign - IP address is related to campaign, based on TIM module
- Hunting results - the hunt for indicators related to the source IP and the related campaign returned results
- XDR Alert search - XDR Alerts that related to the same username and endpoint, and to the MITRE tactics that comes after "Credential Access", were found.
Set verdict method:
* Critical Element - The "Critical Element" input allows you to select a specific element that, if identified as suspicious, the investigation's final verdict will be deemed a "True Positive".
* Final Verdict - Each suspicious element is being added to an array called "Suspicious Elements", which is used to count potential security threats. The array size will be compared to a final threshold. If the size is greater than or equal to the threshold, the investigation's final verdict will be deemed a "True Positive".
* User Engagement - The "UserEngagementThreshold" input allows you to set the number of suspicious elements that trigger user engagement. When this threshold is met, an email will be sent to the user and their manager asking for authorization of RDP activity. If the RDP activity is not authorized by the user, the investigation's final verdict will be deemed a "True Positive".
Cortex XDR - PrintNightmare Detection and Response [CortexXDR] — The playbook targets specific PrintNightmare rules written by Cortex XDR for both vulnerabilities:
[CVE-2021-1675 LPE](https://nvd.nist.gov/vuln/detail/CVE-2021-1675)
[CVE-2021-34527 RCE](https://nvd.nist.gov/vuln/detail/CVE-2021-34527)
This playbook includes the following tasks:
- Containment of files, endpoints, users and IP Addresses
- Enrichment of indicators
- Data acquisition of system info and files using Cortex XDR
- Eradicating compromised user credentials
** Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Cortex XDR - Retrieve File by sha256 [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
The playbook facilitates the process of retrieving files from the investigated devices, unzipping the retrieved files, and loading them into the War Room.
This playbook consists of the following steps:
Initially, the sub-playbook 'Cortex XDR - Get File Path from alerts by hash' examines the SHA256 file hashes and retrieves the file paths associated with each hash.
As soon as the SHA256 hashes, file paths, and endpoint IDs are obtained, the playbook attempts to retrieve the files from all the investigated devices.
Once the file retrieval automation has been completed successfully, the playbook will unzip the files and load them into the War Room.
Note: When retrieving multiple files, ensure that the SHA256 input is set to run in a loop.
Cortex XDR - Run script [CortexXDR] — Deprecated. Use the `xdr-script-run` command instead. Initiates a new endpoint script execution action using a provided script unique id from Cortex XDR script library.
Cortex XDR - Search And Block Software - XQL Engine [CortexXDR] — This playbook will search a file or process activity of a software by a given image file name using Cortex XDR XQL Engine. The analyst can then choose the files to block.
Cortex XDR - Search and Compare Process Executions - XDR Alerts [CortexXDR] — This playbook is a generic playbook that receives a process name and command-line argument. It uses the "Cortex XDR IR" integration to search for the given process executions inside Cortex XDR alerts and compares the command-line argument from the results to the command-line argument received from the playbook input.
Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*.
Cortex XDR - Search and Compare Process Executions - XQL Engine [CortexXDR] — This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Cortex XDR - XQL Engine" integration to search for the given process executions and compare the command-line argument from the results to the command-line argument received from the playbook input.
Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
Cortex XDR - True Positive Incident Handling [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles a true-positive incident closure for Cortex XDR - Malware Investigation.
Cortex XDR - Unisolate Endpoint [CortexXDR] — This playbook unisolates endpoints according to the endpoint ID that is provided in the playbook input.
Cortex XDR - XCloud Cryptojacking [CloudIncidentResponse] — Investigates a Cortex XDR incident containing a Cloud Cryptojacking related alert.
The playbook supports AWS, Azure, and GCP and executes the following:
- Cloud enrichment:
- Collects info about the involved resources
- Collects info about the involved identities
- Collects info about the involved IPs
- Verdict decision tree
- Verdict handling:
- Handle False Positives
- Handle True Positives
- Cloud Response - Generic sub-playbook.
- Notifies the SOC if a malicious verdict was found
Cortex XDR - XCloud Cryptojacking - Set Verdict [CloudIncidentResponse] — This playbook sets the alert's verdict as malicious if one of the following conditions is true:
1. If the source IP address is malicious
2. If the incident includes both "Unusual allocation of multiple cloud compute resources" AND "Cloud identity reached a throttling API rate" (medium/high severity)
3. If the incident includes both "Unusual allocation of multiple cloud compute resources" AND "Suspicious heavy allocation of compute resources - possible mining activity"
4. If the incident includes "Unusual allocation of multiple cloud compute resources" with medium/high severity, the source ASN isn't known, and the source IP isn't known as well.
5. If the incident includes both "Unusual allocation of multiple cloud compute resources" AND "A cloud compute instance was created in a dormant region"
If none of the conditions is true, the playbook will wait for an analyst's decision.
Cortex XDR - XCloud Token Theft - Set Verdict [CloudIncidentResponse] — ---
## Cloud Token Theft - Set Verdict Playbook
The playbook is built from a decision tree whose ultimate goal is to decide whether the observed activity is malicious.
### Event Search
The playbook searches for events based on the attacker's IP address within the last two hours.
### Tests Performed
The following tests are performed on the observed activity:
1. **Malicious IP Check**: Determines if the IP address is malicious.
2. **CSP ASN Check**: Checks if the activity was performed from an Autonomous System Number (ASN) belonging to one of the Cloud Service Providers (CSPs).
3. **IP and ASN History Check**: Verifies if the IP address and ASN have been previously observed.
4. **Region Check**: Determines if the API call was made from outside the recognized region.
5. **Anomalous State Check**: Checks if the API call was made from an anomalous state.
6. **Alert Check**: Looks for any related alerts around the event, including:
- Possible cloud instance metadata service (IMDS) abuse.
- Impossible Traveler by cloud identity.
---
Cortex XDR - XCloud Token Theft Response [CloudIncidentResponse] — ---
## Cloud Token Theft Response Playbook
The **Cloud Token Theft Response Playbook** provides a structured and comprehensive flow to effectively respond to and mitigate alerts involving the theft of cloud tokens. The playbook supports AWS, GCP, and Azure and executes the following:
**Cloud Enrichment:**
- Enriches the involved resources.
- Enriches the involved identities.
- Enriches the involved IPs.
**Verdict Decision Tree:**
- Determines the appropriate verdict based on the investigation findings.
**Early Containment using the Cloud Response - Generic Playbook:**
- Implements early containment measures to prevent further impact.
**Cloud Persistence Threat Hunting:**
- Conducts threat hunting activities to identify any cloud persistence techniques.
**Enriching and Responding to Hunting Findings:**
- Performs additional enrichment and responds to the findings from threat hunting.
**Verdict Handling:**
- Handles false positives identified during the investigation.
- Handles true positives by initiating appropriate response actions.
---
Cortex XDR - check file existence [CortexXDR] — Deprecated. Use `xdr-file-exist-script-execute` command instead. Initiates a new endpoint script execution to check if the file exists and retrieve the results.
Cortex XDR - delete file [CortexXDR] — Deprecated. Use the `xdr-file-delete-script-execute` command instead. Initiates a new endpoint script execution to delete the specified file and retrieve the results.
Cortex XDR - kill process [CortexXDR] — Deprecated. Use the `xdr-kill-process-script-execute` command instead. Initiates a new endpoint script execution kill process and retrieves the results.
Cortex XDR Alerts Handling CTF [ctf01] — This playbook is used to loop over every alert in a Cortex XDR incident.
Supported alert categories:
- Malware
- Port Scan.
Cortex XDR IOCs - Disable expired IOCs in XDR [CortexXDR] — This is a *sub-playbook* of "Cortex XDR IOCs - Push new IOCs to XDR (Main)". This playbook disables indicators in Cortex XDR after they expire from Cortex XSOAR using a loop and querying on the "xdr_pushed" tag.
Cortex XDR IOCs - Push new IOCs to XDR [CortexXDR] — This is a *sub-playbook* of "Cortex XDR IOCs - Push new IOCs to XDR - Main" and should not be run on its own. This sub-playbook retrieves IOCs according to the users query input (passed from the main playbook) and pushes them into Cortex XDR, and marks them as "xdr_pushed" or "xdr_not_processed" for further processing.
Cortex XDR IOCs - Push new IOCs to XDR (Main) [CortexXDR] — This is the *main* playbook for Cortex XDR IOCs sync. The playbook will "sync" IOCs into Cortex XDR by pushing new IOCs in and disabling expired IOCs. The playbook utilizes Cortex XSOAR tags and loops in order to find IOCs using a query provided by the user. The playbook will iterate over the IOCs pushing them in batches into Cortex XDR. In the second phase, the playbook will disable expired IOCs that were previously pushed into Cortex XDR. We recommend running this playbook as a job a twice a day after disabling the integration sync function.
Cortex XDR Lite - Incident Handling [CortexXDR] — The Cortex XDR Lite - Incident Handling playbook is triggered by fetching a Palo Alto Networks Cortex XDR incident and executes the following:
Analysis:
- Enriches all the indicators from XDR incidents and alerts, providing additional context and information about these indicators.
Investigation:
- Checks for related XDR alerts to the user and the endpoint by Mitre tactics to identify malicious activity.
- Checks for specific arguments for malicious usage from the command line.
Verdict:
- Determines the incident's verdict by considering indicator enrichment results, user and host risk levels, command line analysis, and the number of related XDR alerts (medium severity or higher) to the user and the endpoint by Mitre tactics.
Verdict Handling:
- Handles malicious incidents by initiating appropriate response actions, including blocking malicious indicators, isolating endpoints, and disabling user accounts.
To utilize this playbook as the default for handling XDR incidents, the classifier should be empty, and the selected incident type should be `Cortex XDR - Lite`.
The selected Mapper (incoming) should be `XDR - Incoming Mapper`, and the selected Mapper (outgoing) should be Cortex `XDR - Outgoing Mapper`.
Cortex XDR Malware - Incident Enrichment [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook enriches the Cortex XDR incident. The enrichment is done on the involved endpoint and Mitre technique ID information, and sets the 'Malware-Investigation and Response' layout.
Cortex XDR Malware - Investigation And Response [CortexXDR] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook investigates Cortex XDR malware incidents. It uses:
- Cortex XDR insights
- Command Line Analysis
- Dedup
- Sandbox hash search and detonation
- Cortex XDR enrichment
- Incident Handling (True/False Positive).
Cortex XDR Remote PsExec with LOLBIN command execution alert [CortexXDR] — The "Remote PsExec-like LOLBIN Command Execution" playbook is designed to address and respond to alerts indicating suspicious activities related to remote PsExec-like LOLBIN command execution from an unsigned non-standard source.
The playbook aims to efficiently:
- Get the alert data and check if the execution is blocked. If not will terminate the process (manually by default).
- Enrich any entities and indicators from the alert and find any related campaigns.
- Perform command analysis to provide insights and a verdict for the executed command.
- Perform further endpoint investigation using Cortex XDR.
- Checks for any malicious verdicts found to raise the severity of the alert.
- Perform automatic/manual remediation response by blocking any malicious indicators found.
The playbook is designed to run as a sub-playbook in "Cortex XDR Incident Handling - v3 & Cortex XDR Alerts Handling".
It depends on the data from the parent playbooks and cannot be used as a standalone version.
Cortex XDR device control violations [CortexXDR] — Queries Cortex XDR for device control violations for the specified hosts, IP address, or XDR endpoint ID. It then communicates via email with the involved users to understand the nature of the incident and if the user connected the device.
All the collected data will be displayed in the XDR device control incident layout.
This playbook can also be associated with Cortex XDR device control violation job to periodically query and investigate XDR device control violations. In this configuration, the playbook will only communicate with the involved users.
Cortex XDR disconnected endpoints [CortexXDR] — A Job to periodically query disconnected Cortex XDR endpoints with a provided last seen time range playbook input.
The Collected data, if found will be generated to a CSV report, including a detailed list of the disconnected endpoints.
The report will be sent to the recipient's provided email addresses in the playbook input.
The playbook includes an incident type with a dedicated layout to visualize the collected data.
To set the job correctly, you will need to.
1. Create a new recurring job.
2. Set the recurring schedule.
3. Add a name.
4. Set type to Cortex XDR disconnected endpoints.
5. Set this playbook as the job playbook.
https://xsoar.pan.dev/docs/incidents/incident-jobs
The scheduled run time and the timestamp relative date should be identical,
If the job is recurring every 7 days, the time range should be 7 days as well.
Cortex XDR incident handling v3 CTF [ctf01] — This playbook is triggered by fetching a Palo Alto Networks Cortex XDR incident.
The playbook syncs and updates new XDR alerts that construct the incident and triggers a sub-playbook to handle each alert by type.
Then, the playbook performs enrichment on the incident’s indicators and hunts for related IOCs.
Based on the severity, it lets the analyst decide whether to continue to the remediation stage or close the investigation as a false positive.
After the remediation, if there are no new alerts, the playbook stops the alert sync and closes the XDR incident and investigation. For performing the bidirectional sync, the playbook uses the incoming and outgoing mirroring feature added in XSOAR version 6.0.0. After the Calculate Severity - Generic v2 sub-playbook’s run, Cortex XSOAR will be treated as the single source of truth for the severity field, and it will sync only from Cortex XSOAR to XDR, so manual changes for the severity field in XDR will not update in the XSOAR incident.
Courses of Action - Collection [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1005 - Data from Local System
- Kill Chain phase:
- Collection
MITRE ATT&CK Description:
The adversary is attempting to gather data of interest to accomplish their goal.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary’s objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Command and Control [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0011: command and control
MITRE ATT&CK Description:
The adversary is trying to communicate with compromised systems to control them.
Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Credential Access [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0006: Credential Access
MITRE ATT&CK Description:
The adversary is trying to steal account names and passwords.
Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Defense Evasion [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0005: Defense Evasion
MITRE ATT&CK Description:
The adversary is trying to avoid being detected.
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Discovery [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0007: Discovery
MITRE ATT&CK Description:
The adversary is trying to figure out your environment.
Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what’s around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Execution [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0002: Execution
MITRE ATT&CK Description:
The adversary is trying to run malicious code.
Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Exfiltration [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0010: Exfiltration
MITRE ATT&CK Description:
The adversary is trying to steal data.
Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Impact [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0040: Impact
MITRE ATT&CK Description:
The adversary is trying to manipulate, interrupt, or destroy your systems and data.
Impact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries’ goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Initial Access [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0001: Initial Access
MITRE ATT&CK Description:
The adversary is trying to get into your network.
Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Lateral Movement [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0008: Lateral Movement
MITRE ATT&CK Description:
The adversary is trying to move through your environment.
Lateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target and subsequently gaining access to it. Reaching their objective often involves pivoting through multiple systems and accounts to gain. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Persistence [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0003: Persistence
MITRE ATT&CK Description:
The adversary is trying to maintain their foothold.
Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Courses of Action - Privilege Escalation [MITRECoA] — This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0004: Privilege Escalation
MITRE ATT&CK Description:
The adversary is trying to gain higher-level permissions.
Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include: • SYSTEM/root level• local administrator• user account with admin-like access • user accounts with access to specific system or perform specific functionThese techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Create Jira Issue [Jira] — Create Jira issue allows you to open new issues.
When creating the issue, you can decide to update based on on the issue's state, which will wait for the issue to resolve or close with StatePolling.
Alternatively, you can select to mirror the Jira issue and incident fields. To apply either of these options, set the SyncTicket value in the playbook inputs to one of the following options:
1. StatePolling
2. Mirror
3. Leave Blank to use none
When creating Jira issues through XSOAR, using the mirroring function, make sure that you exclude those issues when fetching incidents. To exclude these issues, tag the relevant issues with a dedicated label and exclude that label from the JQL query (Labels!=).
Create ServiceNow Ticket [ServiceNow] — Create ServiceNow Ticket allows you to open new tickets as a task from a parent playbook.
When creating the ticket, you can decide to update based on on the ticket's state, which will wait for the ticket to resolve or close with StatePolling.
Alternatively, you can select to mirror the ServiceNow ticket and incident fields. To apply either of these options, set the SyncTicket value in the playbook inputs to one of the following options:
1. StatePolling
2. Mirror
3. Leave Blank to use none.
Create list for PTH [CertStream] — This playbook help analysts creating a new list of domains to monitor using CertStream integration.
CrowdStrike Falcon - False Positive Incident Handling [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles a CrowdStrike case or detection that was determined to be a false positive by the analyst. Actions include unisolating the host, allowing the indicator by the EDR, and tagging it.
CrowdStrike Falcon - Get Detections by Case [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook enables getting CrowdStrike Falcon detection (alerts) details based on the CrowdStrike case ID.
CrowdStrike Falcon - Get Endpoint Forensics Data [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook extracts data from the host using RTR commands. For example, commands for getting a list of running processes and network connections.
CrowdStrike Falcon - Retrieve File [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook retrieves and unzips files from CrowdStrike Falcon and returns a list of the files that were and were not retrieved.
CrowdStrike Falcon - SIEM ingestion Get Incident Data [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles incident ingestion from a SIEM.
The user provides the field for the incident ID or detection ID and the field indicating whether the ingested item is an incident or detection. This playbook enables changing the severity scale in Cortex XSOAR as well as fetching CrowdStrike detections based on the CrowdStrike incident type.
CrowdStrike Falcon - Search Endpoints By Hash [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook searches across the organization for other endpoints associated with a specific SHA256/MD5/SHA1 hash.
CrowdStrike Falcon - Search Endpoints By Indicators [CrowdStrikeFalcon] — This playbooks searches for different indicators (IP,IPV6,File hashes,Domain) in the crowdstrike falcon console. The output will be all the endpoints found associated with provided indicators. Provided agent id as an input will be excluded from the returned list.
CrowdStrike Falcon - T1059 - Command and Scripting Interpreter [CrowdStrikeFalcon] — This playbook handles command and scripting interpreter alerts based on the MITRE T1059 technique.
An attacker might abuse command and script interpreters to execute commands, scripts, or binaries.
The playbook executes the following stages:
**Analysis**
- Initiates the CommandLineAnalysiss script which will determine if the command lines have any suspicious artifacts that might indicate malicious behavior.
- Enriches any indicators found during the command lines analysis phase.
**Investigative Actions:**
- In case malicious indicators were found, the playbook will initiate a check against CrowdStrike Falcon to identify if any other endpoint has been associated with the same indicators.
- If there are any, the playbook will update the layout and create a new incident for further investigation.
**Remediation:**
- Terminate the process if the CrowdStike Falcon agent doesn't block it.
- If the process failed or the parent process command line was suspicious as well, a manual action will be provided to the analyst to choose how to proceed further:
- Terminate the parent process
- Isolate the endpoint
**Closure Steps:**
- Handle malicious alerts by closing the alert as True Positive.
- Handle non-malicious alerts by closing the alert as False Positive.
CrowdStrike Falcon - True Positive Incident Handling [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles a CrowdStrike case or detection that was determined to be a true positive by the analyst. Actions include isolating the host, blocking the indicator by the EDR, and tagging it.
CrowdStrike Falcon Malware - Incident Enrichment [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook enables enriching CrowdStrike Falcon incidents by pivoting to their detections as well as mapping all the relevant data to the Cortex XSOAR incident fields.
CrowdStrike Falcon Malware - Investigation and Response [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles a CrowdStrike Falcon malware investigation, including:
- Extracting and displaying MITRE data from the EDR and sandboxes
- Deduplicating similar incidents
- Searching for hashes in an alert in a sandbox to provide their relevant information. If the hashes are not found, retrieving them from the endpoint and detonating them in the sandbox.
- Verifying the actions taken by the EDR
- Analyzing the command line
- Searching for relevant hashes in additional hosts in the organization
- Retrieving data about the host, including process list and network connections
- Performing containment and mitigation actions as part of handling false/true positives
- Setting the relevant layouts.
CrowdStrike Falcon Malware - Verify Containment Actions [CrowdStrikeFalcon] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook verifies and sets the policy actions applied by CrowdStrike Falcon.
CrowdStrike Rapid IOC Hunting [DeprecatedContent] — Deprecated. Use "CrowdStrike Rapid IOC Hunting v2" playbook instead. Hunt for endpoint activity involving hash and domain IOCs, using Crowdstrike Falcon Host.\nAlso use AnalystEmail label to determine where to send an email alert if something is found.
Crowdstrike Falcon - Isolate Endpoint [CrowdStrikeFalcon] — This playbook will auto isolate endpoints by the device ID that was provided in the playbook.
Crowdstrike Falcon - Unisolate Endpoint [CrowdStrikeFalcon] — This playbook unisolates devices according to the device ID that is provided in the playbook input.
CyberBlindspot Incident Management [CTM360-CyberBlindspot] — This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to assist the user in the next course of action (Whether it be closing the incident, initiating the takedown of an online asset or simply waiting for a process on the remote server to end) to take on the incident if any.
CyberBlindspot Incident Management V2 [CTM360-CyberBlindspot] — This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to assist the user in the next course of action (Whether it be closing the incident, initiating the takedown of an online asset or simply waiting for a process on the remote server to end) to take on the incident if any.
CyberBlindspot Incident Management V3 [CTM360-CyberBlindspot] — This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to assist the user in the next course of action (Whether it be closing the incident, initiating the takedown of an online asset or simply waiting for a process on the remote server to end) to take on the incident if any.
Cybereason - Download Close File [Cybereason] — This playbook aborts a file download operation which is in progress based on the Malop ID and username provided.
Cybereason - Download File [Cybereason] — This playbook downloads a file from Cybereason platform, based on the Malop ID and username provided.
Cyble Intel Alert [CybleEvents] — This is a playbook which will handle the alerts coming from the Cyble Events service
D2 - Endpoint data collection [D2] — Uses Demisto's d2 agent to collect data from an endpoint for IR purposes.
Input:
* Hostname (default: ${Endpoint.Hostname})
* OS (default: windows)
* Credentials (default: Admin)
* Path (default: None)
DBot Create Phishing Classifier [DeprecatedContent] — Deprecated. Use "DBot Create Phishing Classifier V2" playbook instead. Create a phishing classifier using machine learning technique, based on email content
DBot Create Phishing Classifier Job [DeprecatedContent] — Deprecated. Use "DBot Create Phishing Classifier V2" playbook instead. Train the phishing machine learning model. This playbook should be used as job, to run repeatedly, for example every week.
DBot Create Phishing Classifier V2 From File [ML] — Create a phishing classifier using machine learning. The classifier is based on incidents files extracted from email content.
DBot Create Phishing Classifier V2 Job [ML] — Train the phishing machine learning model. This playbook should be used as job, to run repeatedly, for example every week.
DLP - Get Approval [Palo_Alto_Networks_Enterprise_DLP] — Get an approver response for an exemption request from a user.
DLP - Get User Feedback [Palo_Alto_Networks_Enterprise_DLP] — Get the user feedback on a blocked file, whether it is false or true positive and if an exemption is needed.
DLP - Get User Feedback via Email [Palo_Alto_Networks_Enterprise_DLP] — Get the user feedback via email on a blocked file, whether it is false or true positive and if an exemption is needed.
DLP - User Message App Check [Palo_Alto_Networks_Enterprise_DLP] — Check if the given message app exists and is configured and retrieve the user details from it.
DNSDB - Hostname from IP [DNSDB] — A playbook that uses DNSDB to retrieve all hostnames seen for a given IP around the time of observation.
DNSDB - IPs from Hostname [DNSDB] — A playbook that uses DNSDB to retrieve all IPs seen for a given hostname around the time of observation.
DNSDB - Related Hostnames from Hostname [DNSDB] — A playbook that “pivots” in DNSDB to retrieve a limited number of other hostnames seen on the same IPs as the target hostname.
DSPM Jira Ticket Creation [DSPM] — This playbook automates the process of creating and managing Jira issues for DSPM-related risks detected in XSOAR incidents. It creates a Jira ticket with risk details, checks for errors, updates incident details, and sends a Slack notification with ticket information. This streamlines risk tracking and notification.
DSPM Multi-Cloud Risk Remediation [DSPM] — The playbook ensures efficient incident resolution and compliance with security policies by guiding the user through decision points based on incident type, such as empty storage assets or assets open to the world. It concludes by updating the incident status and closing the playbook upon resolution.
DSPM Re-run incident [DSPM] — The "DSPM Re-run Incident" playbook is designed to automatically re-run DSPM incidents. It starts by executing the RerunDSPMIncidents task, which reinitiates the incidents for further investigation or processing. After completing this task, the playbook proceeds to close the current incident using the closeInvestigation script. This playbook ensures that DSPM incidents can be efficiently retried and closed upon completion.
DSPM Remediation for Empty storage asset [DSPM] — This playbook is designed to remediate risks associated with empty storage assets across AWS, Azure, and GCP environments. It identifies the cloud provider for the asset and proceeds to delete the storage container or bucket accordingly. Additionally, it sends notifications via Slack to inform stakeholders about the status of the remediation process.
DSPM Remediation for Sensitive asset open to world [DSPM] — The DSPM Remediation playbook for Sensitive Asset Open to World is designed to handle incidents where sensitive assets are exposed to the public, with specific focus on remediating this vulnerability across several cloud providers(for example AWS).
DSPM Send Slack Notification to User [DSPM] — "Send Slack Notification to User" playbook is designed to notify a user via Slack and handle their response. It begins by sending a Slack notification to a specified email using the SlackBlockBuilder script. Afterward, it waits for the user's response until a predefined time, as configured in Prisma Cloud DSPM. Once the response is received, it is inserted into the incident's context. If there is an error in generating the Slack block, the incident is added for a re-run. Finally, the playbook extracts the user's response from the Slack block state for further processing.
DSPM Valid User Response [DSPM] — The DSPM Valid User Response playbook is designed to assess and manage user responses to DSPM-identified risks. It checks the user’s selected action (e.g., creating a Jira ticket or remediating specific risk types) and initiates the appropriate remediation or notification workflows. If no user response is received, the playbook logs the incident for future action, ensuring comprehensive tracking and response handling for DSPM incidents.
DSPM notify user in case of error [DSPM] — The DSPM Notify User in Case of Error playbook is designed to handle errors in DSPM incidents by notifying users and managing Slack notifications.
DTM Alert Incident Response - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook initiates the response for DTM Alerts in XSOAR when an incident is investigated. For medium or higher severity, it creates a ServiceNow ticket using the "ServiceNow v2" integration; otherwise, the incident is assigned to an analyst. The ticket is enriched with GTI DTM Alert details, including alert type, status, monitor information, summary, AI Doc summary, and tags.
Darkmon - Block IOC [Darkmon] — Analyst-facing wrapper around Darkmon - Generic Block Indicator. Lets analysts paste an IOC into a War Room form and trigger a provider-routed block action.
Darkmon - Brand-Targeted NRD Watch [Darkmon] — Daily sweep of newly-registered domains. Each candidate's root label is compared against the brand list via DarkmonLevenshtein; matches with distance <= 2 (configurable) open a 'Darkmon Typosquatting Threat' incident.
Darkmon - Compromised Account Response [Darkmon] — Incident-type playbook for 'Darkmon Compromised Credential' (and similar). Identifies the user via the configured directory, suspends, forces a password reset, revokes active sessions, and notifies SOC + the user.
Darkmon - Compromised Credentials Sweep [Darkmon] — Polls Darkmon for compromised credentials, filters to the customer's email/web domains, dedupes via state list, and creates a 'Darkmon Compromised Credential' incident per new account. Triggered on a 4-hour Job.
Darkmon - Compromised Employee Auto-Disable [Darkmon] — Hourly poll of compromised employees. For each new entry, looks up the user
in the configured directory and acts per the DisableMode playbook input:
- notify-only : creates incident and notifies; no AD action. [DEFAULT]
- approval-required : creates incident, blocks on a manual approval task,
then disables on approve.
- auto-disable : disables the account immediately, then notifies.
Accounts in the 'Darkmon - Auto-Disable Allowlist' list are NEVER auto-disabled.
Darkmon - Critical CVE Pipeline [Darkmon] — Daily filter of new CVEs (CVSS >= 9) against the customer's tech-stack tags. Matches open a 'Darkmon Critical CVE' incident per match and ticket via Generic Notify.
Darkmon - EDR Alert Enrichment [Darkmon] — Designed to be invoked from CrowdStrike / SentinelOne / Defender alert playbooks. Takes the alert's IOCs, enriches each via Darkmon, and if any are scored Bad, escalates incident severity and notifies the SOC. Endpoint containment is left to the EDR-specific playbook.
Darkmon - Email Deep Dive [Darkmon] — Analyst-driven full Darkmon profile for a single email address. Runs board-protection check, all three boardemails categories, and global search. Outputs a unified summary into the incident War Room.
Darkmon - Enrich Domain [Darkmon] — Sub-playbook that calls the Darkmon !domain command and returns DBotScore + Common.Domain for the input Domain indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Darkmon - Enrich Email [Darkmon] — Sub-playbook that calls the Darkmon !email command and returns DBotScore + Common.Account.Email for the input Email indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Darkmon - Enrich File [Darkmon] — Sub-playbook that calls the Darkmon !file command and returns DBotScore + Common.File for the input File indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Darkmon - Enrich IP [Darkmon] — Sub-playbook that calls the Darkmon !ip command and returns DBotScore + Common.IP for the input IP indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Darkmon - Enrich URL [Darkmon] — Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Darkmon - Generic Block Indicator [Darkmon] — Provider-agnostic indicator-block dispatcher. Reads the 'Darkmon - Block Provider' List for the configured block target (panos | fortinet | umbrella | cloudflare) and routes to the matching command. Falls back to logging the block intent in the War Room when no provider is configured.
Darkmon - Generic Notify [Darkmon] — Provider-agnostic notification dispatcher. Reads "Darkmon - Notification Provider" List for the configured target (slack | teams | email | servicenow | jira) and routes to the matching command.
Darkmon - Generic User Action [Darkmon] — Provider-agnostic user-action dispatcher (disable, reset password, revoke sessions). Reads "Darkmon - Identity Provider" List for the configured directory (ad | okta | azuread) and routes to the matching command.
Darkmon - Phishing Email Triage [Darkmon] — Extracts URLs/IPs/file-hashes from a reported phishing email, enriches each via the Darkmon - Enrich * sub-playbooks, and if any indicator is scored Bad (DBotScore=3) calls Generic Block Indicator on it. Notifies the reporter and the SOC at the end.
Darkmon - Ransomware Mentions Watch [Darkmon] — Every 6 hours, polls ransomware mentions for the customer organisation. New entries open a critical 'Darkmon Ransomware Mention' incident and notify the CISO via Generic Notify.
Darkmon - Ransomware Victim Response [Darkmon] — Triggered when our company surfaces in a Darkmon ransomware mention. Verifies the match, opens a war-room channel via Generic Notify, pages the CISO, and prints next-step guidance for the customer's IR runbook.
Darkmon - VIP Email Monitor [Darkmon] — Hourly poll of board-protected emails. For each protected email, checks accounts/combo-lists/public-breaches and opens a 'Darkmon VIP Email Leak' incident per new entry.
DeDup incidents [DeprecatedContent] — Deprecated. Check for duplicate incidents for the current incident, and close it if any duplicate has found.
DeDup incidents - ML [DeprecatedContent] — Deprecated. Check for duplicate incidents for the current incident, and close it if any duplicate has been found by machine-learning find duplicates automation.
Dedup - Generic [DeprecatedContent] — Deprecated. Use "Dedup - Generic v2" playbook instead. This playbook identifies duplicate incidents using one of the supported methods.
Dedup - Generic v2 [CommonPlaybooks] — Deprecated. Use the Dedup Generic v3 playbook instead. This playbook identifies duplicate incidents using one of the supported methods.
Dedup - Generic v3 [CommonPlaybooks] — Deprecated. Use the `Dedup - Generic v4` playbook instead. This playbook identifies duplicate incidents using one of the supported methods.
Select one of the following methods to identify duplicate incidents in Cortex XSOAR.
- ml: Machine learning model, which is trained mostly on phishing incidents.
-rules: Rules help identify duplicate incidents when the logic is well defined, for example, the same label or custom fields.
-text: Statistics algorithm that compares text, which is generally useful for phishing incidents.
For each method, the playbook will search for the oldest similar incident. when there is a match for a similar incident the playbook will close the current incident and will link it to the older incident.
Dedup - Generic v4 [CommonPlaybooks] — This playbook identifies duplicate incidents using the Cortex XSOAR machine learning method (script).
In this playbook, you can choose fields and/or indicators to be compared against other incidents in the Cortex XSOAR database.
Note: To identify similar incidents you *must* properly define the playbook inputs.
Delete Custom Content [ContentManagement] — This playbook deletes custom content from the system. It deletes Playbooks, Scripts, Layouts, Classifiers, Mappers, Incident Types and Incident Fields.
Departing Employee Auto-Add [Code42] — Queries stand-down tickets from a ticketing system and passes relevant employee data to the Add Employees to Departing Employee Watchlist playbook. Intended to be run as a scheduled job.
Departing Employee Clean-Up [Code42] — Queries the Departing Employee watchlist in Code42 Incydr and passes relevant employee data to the Remove Employees from Departing Employee Watchlist playbook. Intended to be run as a scheduled job.
Detonate File - BitDam [BitDam] — Detonates one or more files using BitDam integration.
Returns verdict to the War Room and file reputations to the context data.
Supported file types are mainly PDF & microsoft office software/
Detonate File - FireEye AX [fireeye] — Detonate one or more files using the FireEye AX integration. This playbook returns relevant reports to the War Room and file reputations to the context data. The detonation supports the following file types - PE32, EXE, DLL, JAR, JS, PDF, DOC, DOCX, RTF, XLS, PPT, PPTX, XML, ZIP, VBN, SEP, XZ, GZ, BZ2, TAR, MHTML, SWF, LNK, URL, MSI, JTD, JTT, JTDC, JTTC, HWP, HWT, HWPX, BAT, HTA, PS1, VBS, WSF, JSE, VBE, CHM, JPG, JPEG, GIF, PNG, XLSX
Detonate File - FireEye Detection on Demand [FireEye-Detection-on-Demand] — Detonate one or more files using the FireEye Detection on Demand integration. This playbook returns relevant reports to the War Room and file reputations to the context data.
Detonate File - FortiSandbox [FortiSandbox] — Main playbook to upload submissions to FortiSandbox, poll for verdict. Deprecated. Use `fortisandbox-submission-file-upload` instead. and retrieve report
Detonate File - Generic [CommonPlaybooks] — Detonate files through one or more active integrations that support file detonation.
Supported integrations:
- SecneurX Analysis
- ANY.RUN Cloud Sandbox
- McAfee Advanced Threat Defense
- WildFire
- Lastline
- Cuckoo Sandbox
- Cisco Secure Malware Analytics (ThreatGrid)
- JoeSecurity
- CrowdStrike Falcon Sandbox
- FireEye AX
- VMRay Analyzer
- Polygon
- CrowdStrike Falcon Intelligence Sandbox
- OPSWAT Filescan.
Detonate File - JoeSecurity V2 [JoeSecurity] — The Detonate File using Joe Sandbox Process is designed to streamline and enhance the security assessment of files. This automated system accepts a user-submitted file, sends it for in-depth analysis using Joe Sandbox technology, and returns comprehensive results as attachments to the user. The process is designed to be swift, efficient, and secure, providing users with valuable insights into potential threats and vulnerabilities within their files.
Detonate File - ThreatGrid v2 [ThreatGrid] — Detonate one or more files using the ThreatGrid integration. This playbook returns relevant reports to the War Room and file reputations to the context data. The detonation supports the following file types - EXE, DLL, JAR, JS, PDF, DOC, DOCX, RTF, XLS, PPT, PPTX, XML, ZIP, VBN, SEP, XZ, GZ, BZ2, TAR, MHTML, SWF, LNK, URL, MSI, JTD, JTT, JTDC, JTTC, HWP, HWT, HWPX, BAT, HTA, PS1, VBS, WSF, JSE, VBE, CHM
Detonate File - ThreatStream [Anomali_ThreatStream] — Detonate one or more files using the Anomali ThreatStream v2 integration. This playbook returns relevant reports to the War Room, and file reputations to the context data.
Detonate File - Trend Micro Deep Discovery Analyzer Beta [TrendMicroDDA] — Detonates a File using the TrendAI™ Deep Discovery™ Analyzer sandbox.
Deep Discovery Analyzer(version 6.0.0) supports the following File Types:
bat, cell, chm, class, cmd, dll, doc, docx, exe, gul, hta, htm, html, hwp, hwpx, jar, js, jse, jtd, lnk, mov, pdf, ppt, pptx, ps1, pub, rtf, slk, svg, swf, vbe, vbs,
wsf, xls, xlsx, xml
Detonate URL - Generic [CommonPlaybooks] — Deprecated. Use Detonate URL - Generic v1.5 playbook instead. Detonate URL through active integrations that support URL detonation.
Detonate URL - ThreatStream [Anomali_ThreatStream] — Detonates one or more URLs using the Anomali ThreatStream sandbox integration.
Returns relevant reports to the War Room and URL reputations to the context data.
Detonate and Analyze File - Generic [CommonPlaybooks] — This playbook uploads, detonates, and analyzes files for supported sandboxes. Currently supported sandboxes are Falcon Intelligence Sandbox, JoeSecurity, and Wildfire.
Digital Defense FrontlineVM - PAN-OS block assets [Digital_Defense_FrontlineVM] — This playbook will pull Panorama queried threat logs and check for any correlating assets that are found to have a minimum of high level vulnerabilities. If so, it will block the the IP using Panorama's PAN-OS - Block IP and URL - External Dynamic List playbook.
Digital Defense FrontlineVM - Scan Asset Not Recently Scanned [Digital_Defense_FrontlineVM] — This playbook will pull the IP address from the details value of an incident and check if that asset has been scanned within the past 60 days. If not then it will prompt to perform a scan on the asset.
Digital Guardian Demo Playbook [DigitalGuardian] — This playbook will show how to handle an exfiltration event through Digital Guardian by emailing a user's manager and adding the user to a DG Watchlist.
Dispatch Incident - Vectra Detect [Vectra_AI] — This playbook is called from the Process Incident - Vectra Detect playbook. It will fetch all active detections for the entity under investigation. It will then assign the entity to a user; if an assignment already exists, it will update that assignment and add a note in Vectra.
Dispatch Incident - Vectra XDR [VectraXDR] — This playbook is called from the Process Incident - Vectra XDR playbook. It will fetch all active detections for the entity under investigation. It will then assign the entity to a user; if an assignment already exists, it will update that assignment and add a note in Vectra.
Domain Enrichment - Generic [DeprecatedContent] — Deprecated. Use "Domain Enrichment - Generic v2" playbook instead. Enrich Domain using one or more integrations.
Domain enrichment includes:
* Domain reputation
* Threat information
Domain Enrichment - Generic v2 [CommonPlaybooks] — Enrich domains using one or more integrations.
Domain enrichment includes:
* Threat information
* Domain reputation using !domain command
Domain Enrichment - Infoblox Cloud [InfobloxBloxOne] — This playbook enriches domains or hosts with the dossier, TIDE and asset data using Infoblox Threat Defense with DDI integration.
Doppel Screenshot Preview [Doppel] — Previews the Doppel Screenshot URL to an actual image in the Incident War Room
EDL Monitor- Email EDL content [EDLMonitor] — You can use the playbook (or a cloned copy) with a job to check the EDL on a schedule.
ETD Email Reclassification And Remediation [ETDXsoarConnector] — Allows analysts to review Cisco ETD emails, reclassify message verdicts, and perform remediation actions.
Email Address Enrichment - Generic [DeprecatedContent] — Deprecated. Use "Email Address Enrichment - Generic v2.1" playbook instead. Get email address reputation using one or more integrations
Email Address Enrichment - Generic v2 [DeprecatedContent] — Deprecated. Use "Email Address Enrichment - Generic v2.1" playbook instead. Enrich email addresses. Email address enrichment involves:
- Getting information from Active Directory for internal addresses
- Getting the domain-squatting reputation for external addresses
Email Address Enrichment - Generic v2.1 [CommonPlaybooks] — Enrich email addresses.
- Get information from Active Directory for internal addresses
- Get the domain-squatting reputation for external addresses
- Email address reputation using !email command.
Email Collection by Enriched Domain - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook accepts a domain as input, filters the email list to identify addresses containing the specified domain, and outputs the extracted email addresses for further processing.
Email Headers Check - Generic [CommonPlaybooks] — This playbook executes one sub-playbook and one automation to check the email headers:
- **Process Microsoft's Anti-Spam Headers** - This playbook stores the SCL, BCL and PCL scores if they exist to the relevant incident fields (Phishing SCL Score, Phishing PCL Score, Phishing BCL Score).
- **CheckEmailAuthenticity** - This automation checks email authenticity based on its SPF, DMARC, and DKIM.
Endpoint Enrichment - Generic [DeprecatedContent] — Deprecated. Use "Endpoint Enrichment - Generic v2.1" playbook instead. Enrich an Endpoint Hostname using one or more integrations
Endpoint Enrichment - Generic v2 [DeprecatedContent] — Deprecated. Use "Endpoint Enrichment - Generic v2.1" playbook instead. Enrich an endpoint by hostname using one or more integrations.
Currently, the following integrations are supported:
- Active Directory
- McAfee ePolicy Orchestrator
- Carbon Black Enterprise Response
- Cylance Protect
- CrowdStrike Falcon Host
Endpoint Enrichment - Generic v2.1 [CommonPlaybooks] — Enrich an endpoint by hostname using one or more integrations.
Supported integrations:
- Active Directory Query v2
- McAfee ePO v2
- VMware Carbon Black EDR v2
- Cylance Protect v2
- CrowdStrike Falcon
- ExtraHop Reveal(x)
- Cortex XDR / Core (endpoint enrichment, reputation and risk)
- Endpoint reputation using !endpoint command.
Endpoint Investigation Plan [CommonPlaybooks] — This playbook handles all the endpoint investigation actions by performing the following tasks on every alert associated with the incident:
* Pre-defined MITRE Tactics
* Host fields (Host ID)
* Attacker fields (Attacker IP, External host)
* MITRE techniques
* File hash (currently, the playbook supports only SHA256)
Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.
Endpoint Malware Investigation - Generic [Malware] — Deprecated. Use 'Malware Investigation & Response Incident handler' instead. (From the 'Malware Investigation And Response Pack')
This playbook is triggered by a malware incident from an 'Endpoint' type integration. The playbook performs enrichment, detonation, and hunting within the organization, and remediation on the malware.
Used sub-playbooks:
- Endpoint Enrichment - Generic v2.1
- Retrieve File from Endpoint - Generic
- Detonate File - Generic
- File Enrichment - Generic v2
- Calculate Severity - Generic v2
- Isolate Endpoint - Generic
- Block Indicators - Generic v2
Endpoint Malware Investigation - Generic V2 [Malware] — Deprecated. Use 'Malware Investigation & Response Incident handler' instead. (From the 'Malware Investigation And Response Pack')
This playbook provides a framework for handling malware investigation through all essential steps. The playbook consists of 7 stages. Each stage contains the relevant playbook or tasks.
This playbook auto extracts indicators from incidents using indicator extraction rules of the malware incident type.
To use Illusive integration in the `Forensics - Generic` playbook, note that you will be able to set the forensic timeline by editing the `Forensics - Generic` playbook inputs.
Endpoint data collection [DeprecatedContent] — Deprecated. Generic playbook to collect data from endpoints for IR purposes. Will use whichever integrations are configured and available.
Enrich Custom IOCs - Dataminr Pulse [DataminrPulse] — This playbook will enrich the Dataminr Pulse ReGenAI Incident's IOCs using custom reputation commands.
Enrich DXL with ATD verdict [DeprecatedContent] — Deprecated. Use "Enrich DXL with ATD verdict v2" playbook instead. Example of using McAfee ATD and pushing any malicious verdicts over DXL.
Detonates a file in ATD and if malicious - push its MD5, SHA1 and SHA256 hashes to McAfee DXL.
Enrich DXL with ATD verdict v2 [McAfee_DXL] — Uses McAfee ATD to push any malicious verdicts over DXL.
Detonates a file in ATD and if malicious, pushes its MD5, SHA1 and SHA256 hashes to McAfee DXL.
Enrich Incident With Asset Details - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — Enriches the incident with asset details, and enriches the asset with the incident URL on the RiskIQ Digital Footprint platform. This playbook also sends an email containing the owner's information to the primary or secondary contact of the asset and provides the user with an opportunity to update or remove the asset.
Supported integration:
- RiskIQ Digital Footprint
Enrich McAfee DXL using 3rd party sandbox [DeprecatedContent] — Deprecated. Use "Enrich McAfee DXL using 3rd party sandbox v2" playbook instead. Example of bridging DXL to a third party sandbox.
Detonate a file in Wildfire and if malicious - push its MD5, SHA1 and SHA256 hashes to McAfee DXL.
Enrich McAfee DXL using 3rd party sandbox v2 [McAfee_DXL] — Example of bridging DXL to a third party sandbox.
Detonate a file in 3rd party sandbox and if malicious, push its MD5, SHA1 and SHA256 hashes to McAfee DXL.
Enrich ThinkstCanary Events [ThinkstCanary] — Enrich events that are received as part of a ThinkstCanary incident.
Enrichment Playbook [DeprecatedContent] — Deprecated. We recommend using Entity Enrichment - Generic playbook instead. Enrich data with reputation. Data is expected to be found in the standard locations like File, URL, IP.
Enrichment for Verdict [CommonPlaybooks] — This playbook checks prior alert closing reasons and performs enrichment and prevalence checks on different IOC types. It then returns the information needed to establish the alert's verdict.
Entity Enrichment - Generic [DeprecatedContent] — Deprecated. Use "Entity Enrichment - Generic v3" playbook instead. Enrich entities using one or more integrations
Eradication Plan [CommonPlaybooks] — This playbook handles all the eradication actions available with Cortex XSIAM, including the following sub-playbooks:
* Eradication Plan - Reset user password
* Eradication Plan - Delete file
* Eradication Plan - Kill process (currently, the playbook supports terminating a process by name)
Note: The playbook inputs enable manipulating the execution flow. Read the input descriptions for details.
Eradication Plan - Delete File [CommonPlaybooks] — This playbook is one of the sub-playbooks in the eradication plan.
This playbook executes actions of file deletion, which is a crucial step in the eradication process.
Eradication Plan - Reset Password [CommonPlaybooks] — This playbook is one of the sub-playbooks in the eradication plan.
The playbook executes actions to reset the user's passwords, which is a crucial step in the eradication process.
Eradication Plan - Terminate Process [CommonPlaybooks] — This playbook is one of the sub-playbooks in the eradication plan.
This playbook handles the termination of the processes as a crucial step in the eradication action.
The playbook executes actions of process termination, which is a crucial step in the eradication process.
The process termination can be performed based on either the process ID or the process name.
Exchange 2016 Search and Delete [Exchange2016_Compliance] — Run a compliance search in Exchange Server 2016, and delete the results.
Expanse Attribution [ExpanseV2] — Deprecated. No available replacement.
Subplaybook for Handle Expanse Incident playbooks. Given an Expanse Issue IP, Issue Provider, Issue Domain,
Issue Port and Issue Protocol hunts for internal activity related to the detected service.
The playbook looks for logs on Splunk, Cortex Data Lake, Panorama, and ServiceNow CMDB.
Returns a list of potential owner BUs, owner Users, Device and Notes.
Expanse Enrich Cloud Assets [ExpanseV2] — Deprecated. No available replacement.
Subplaybook for Handle Expanse Incident playbooks.
This Playbook is meant to be used as a subplaybook to enrich Public Cloud Assets (i.e. IP addresses and FQDNs) by:
- Searching the corresponding Region and Service by correlating the provided IPs with IP range feeds retrieved from Public Cloud Providers (require TIM and Public Cloud feeds such as AWS Feed integrations to be enabled).
- Searching IPs and FQDNs in Prisma Cloud inventory (requires Prisma Cloud).
Expanse Find Cloud IP Address Region and Service [ExpanseV2] — Deprecated. No available replacement. > Sub-playbook for Expanse Enrich Cloud Assets sub-playbook. This playbook is used to find the corresponding Public Cloud Region (i.e. AWS us-east-1) and Service (i.e. AWS EC2) for a provided IP Address. It works by correlating the provided IP address with the IP Range Indicators (CIDRs) that can be collected from Public Cloud feeds (i.e. AWS Feed) in XSOAR. CIDR Indicators must be tagged properly using the corresponding tags (i.e. AWS for AWS Feed): tags can be configured in the Feed Integrations and must match the ones provided in the inputs of this playbook. Correlation is done based on the longest match (i.e. smaller CIDR such as /20 range wins over a bigger one such as /16).
Expanse Load-Create List [ExpanseV2] — Deprecated. No available replacement.
Sub-playbook to support Expanse Handle Incident playbook.
Loads a list to be used in the Expanse playbook.
Creates the list if it does not exist.
Expanse Unmanaged Cloud [ExpanseV2] — Deprecated. No available replacement.
Subplaybook for bringing rogue cloud accounts under management.
Expanse VM Enrich [ExpanseV2] — Deprecated. No available replacement.
This Playbook is used to verify that all assets found by Expanse are being scanned by a vulnerability management tool by:
- Searching the IP and / or domain of the identified Expanse asset in the vulnerability management tool
This playbook expects an incident with an IP or a Domain to exist in the context.
Expire Inactive Detections - Vectra RUX [VectraRUX] — This playbook identifies incidents with inactive detections and updates their investigation status to "expired".
ExtraHop - CVE-2019-0708 (BlueKeep) [ExtraHop] — This server received a Remote Desktop Protocol (RDP) connection request that is consistent with a known vulnerability, also known as BlueKeep, in older versions of Microsoft Windows. This vulnerability allows an unauthenticated attacker to remotely run arbitrary code on an RDP server. The attacker can then tamper with data or install malware that could propagate to other Windows devices across the network. Investigate to determine if this server is hosting a version affected by CVE-2019-0708: Windows 7, Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008.
MITIGATION OPTIONS
- Disable Remote Desktop Services if they are not required
- Implement Network Level Authentication (NLA) on systems running supported versions of Windows 7, Windows Server 2008, and Windows Server 2008 R2
- Configure firewalls to block traffic on TCP port 3389
ExtraHop - Default [ExtraHop] — Default playbook to run for all ExtraHop Detection incidents. This playbook handles ticket tracking as well as triggering specific playbooks based on the name of the ExtraHop Detection.
ExtraHop - Get Peers by Host [ExtraHop] — Given a host, the playbook will retrieve the peer network devices that communicated with that host in a given time range. In addition to a list of peers and protocols (sorted by bytes) the playbook returns a link to the ExtraHop Live Activity Map to visualize the peer relationships.
ExtraHop - Ticket Tracking [DeprecatedContent] — Deprecated. Use the "ExtraHop - Ticket Tracking v2" playbook instead.\ \ Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.
ExtraHop - Ticket Tracking v2 [ExtraHop] — Links the Demisto incident back to the ExtraHop detection that created it for ticket tracking purposes.
Extract Indicators - Generic [DeprecatedContent] — Deprecated. We recommend using extractIndicators command instead.
Extract indicators from input data.
Extract Indicators From File - Generic [DeprecatedContent] — Deprecated. Use the "Extract Indicators From File - Generic v2" playbook instead.\
\ Extracts indicators from a file.
Supported file types:
- PDF
- TXT
- HTM, HTML
- DOC, DOCX
Extract Indicators From File - Generic v2 [CommonPlaybooks] — This playbook extracts indicators from a file.
Supported file types:
- CSV
- PDF
- TXT
- HTM, HTML
- DOC, DOCX
- PPT
- PPTX
- RTF
- XLS
- XLSX
- XML
- XLSM
- DOCM
- PPTM
- DOTM
- XLSB
- DOT
- PPSM
- PNG
- JPG/JPEG
- GIF (when Image OCR is enabled).
In addition, the playbook supports QR codes.
The playbook does not support encrypted / password-protected files such as XLSB. Such files will be skipped.
Extract and Enrich Expanse Indicators [ExpanseV2] — Deprecated. No available replacement.
Subplaybook for Handle Expanse Incident playbooks.
Extract and Enrich Indicators (CIDRs, IPs, Certificates, Domains and DomainGlobs) from Expanse Incidents.
Enrichment is performed via enrichIndicators command and generic playbooks.
Returns the enriched indicators.
Failed Login Playbook - Slack v2 [DeprecatedContent] — Deprecated. Use the Slack - General Failed Logins v2.1 playbook. When there are three failed login attempts to Demisto that originate from the same user ID, a direct message is sent to the user on Slack requesting that they confirm the activity. If the reply is "no", then the incident severity is set to "high". If the reply is "yes", then another direct message is sent to the user asking if they require a password reset in AD.
Field Polling - Generic [CommonPlaybooks] — This playbook polls a field to check if a specific value exists.
Fighting Ursa Luring Targets With Car For Sale [Unit42_Threat_Brief_-_Fighting_Ursa] — A Russian threat actor we track as Fighting Ursa advertised a car for sale as a lure to distribute HeadLace backdoor malware. The campaign likely targeted diplomats and began as early as March 2024. Fighting Ursa (aka APT28, Fancy Bear and Sofacy) has been associated with Russian military intelligence and classified as an advanced persistent threat (APT).
Diplomatic-car-for-sale phishing lure themes have been used by Russian threat actors for years. These lures tend to resonate with diplomats and get targets to click on the malicious content.
Unit 42 has previously observed other threat groups using this tactic. For example, in 2023, a different Russian threat group, Cloaked Ursa, repurposed an advertisement for a BMW for sale to target diplomatic missions within Ukraine. This campaign is not directly connected to the Fighting Ursa campaign described here. However, the similarity in tactics points to known behaviors of Fighting Ursa. The Fighting Ursa group is known for repurposing successful tactics – even continuously exploiting known vulnerabilities for 20 months after their cover was already blown.
The details of the March 2024 campaign, which we attribute to Fighting Ursa with a medium to high level of confidence, indicate the group targeted diplomats and relied on public and free services to host various stages of the attack. This article examines the infection chain from the attack.
Palo Alto Networks customers are better protected from the threats discussed in this article through our Network Security solutions, such as Advanced WildFire and Advanced URL Filtering, as well as our Cortex line of products.
If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team.
File Enrichment - Generic [DeprecatedContent] — Deprecated. Use "File Enrichment - Generic v2" playbook instead. Enrich a file using one or more integrations.
File enrichment includes:
* File history
* Threat information
* File reputation
File Enrichment - Generic v2 [CommonPlaybooks] — Enrich a file using one or more integrations.
- Provide threat information
- Determine file reputation using the !file command
File Private Scanning - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook submits a file for private scanning, retrieves and evaluates the analysis verdict, and automatically creates a ServiceNow ticket using the "ServiceNow v2" integration when the file is determined to be malicious.
File Reputation [CommonPlaybooks] — This playbook checks the file reputation and sets the verdict as a new context key.
The verdict is composed by 3 main components:
* VirusTotal detection rate
* Digital certificate signers
* NSRL DB
Note: a user can provide a list of trusted signers of his own using the playbook inputs
FireEye HX - Execution Flow Indicators Hunting [FireEyeHX] — This playbook queries FireEye Endpoint Security (HX) for execution flow indicators, including processes name, registry keys, registry values, and applications.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
FireEye HX - File Indicators Hunting [FireEyeHX] — This playbook queries FireEye Endpoint Security (HX) for file indicators, including MD5 hashes, SHA256 hashes, SHA1 hashes, file names, file paths, and file types.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
FireEye HX - Indicators Hunting [FireEyeHX] — This playbook facilitates threat hunting and detection of IOCs within FireEye Endpoint Security (HX) utilizing three sub-playbooks. The sub-playbooks query FireEye HX for different indicators including files, traffic, and execution flow indicators.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Supported IOCs for this playbook:
- MD5
- SHA1
- SHA256
- IP Address
- URLDomain
- Registry Value
- Registry Key
- File Name
- Process Name
- Port Number
- File Path
- FileType
FireEye HX - Isolate Endpoint [FireEyeHX] — This playbook will auto isolate endpoints by the endpoint ID that was provided in the playbook.
FireEye HX - Traffic Indicators Hunting [FireEyeHX] — This playbook queries FireEye Endpoint Security (HX) for traffic indicators, including IP addresses, URLs, domains, and ports.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
FireEye HX - Unisolate Endpoint [FireEyeHX] — This playbook unisolates endpoints according to the hostname/endpoint ID that is provided by the playbook input.
FireEye Helix Archive Search [FireEyeHelix] — Create an archive search in FireEye Helix, and fetch the results as events.
FireEye Red Team Tools Investigation and Response [MajorBreachesInvestigationandResponse] — This playbook does the following:
Collect indicators to aid in your threat hunting process.
- Retrieve IOCs of FireEye red team tools.
- Discover IOCs of associated activity related to the infection.
- Generate an indicator list to block indicators with SUNBURST tags.
Hunt for the indicators
- Search endpoints with the FireEye red team tools CVEs.
- Search endpoint logs for FireEye red team tools hashes.
- Search and link previous incidents with the FireEye hashes.
If compromised hosts are found, fire off sub-playbooks to isolate/quarantine infected hosts/endpoints and await further actions from the security team.
FireMon Pre Change Assessment [FireMonSecurityManager] — Validates and Return Pre Changes Assessment on Rules added as Requirement.
Forensics Tools Analysis [WindowsForensics] — This playbook allows the user to analyze forensic evidence acquired from a host, such as registry files and PCAP files.
FortiSandbox - Loop For Job Verdict [FortiSandbox] — Playbook used to retrieve the verdict for a specific job id for a sample. Deprecated. Use `fortisandbox-submission-file-upload` instead. submitted to FortiSandbox
FortiSandbox - Loop for Job Submissions [FortiSandbox] — Playbook used to retrieve job id for submissions of fortisandbox using. Deprecated. Use `fortisandbox-submission-file-upload` instead. the submission id.
FortiSandbox - Upload Multiple Files [FortiSandbox] — Playbook used to upload files to FortiSandbox. Deprecated. Use `fortisandbox-submission-file-upload` instead.
Function Deployment - AWS [AWS-Enrichment-Remediation] — This playbook automates the deployment of an AWS Lambda function to manage resources within an Amazon EKS cluster. It ensures that all necessary configurations are created, updated, and verified.
### Setup
- **Describe EKS Cluster**: Gather essential details of the EKS cluster.
- **Create IAM Role**: Set up a new IAM role for the Lambda function.
- **Create and Attach Policy**: Define and attach a policy to the IAM role to grant necessary permissions.
### Authentication Mode Check
- **Verify Authentication Mode**: Ensure the current authentication mode allows API access.
- **If not**: Update the cluster authentication mode to permit API access.
### Access Entry Configuration
- **Create Access Entry**: Establish a new access entry in the EKS cluster.
- **Associate Access Policy**: Link the access policy with the created access entry.
- **Update Access Entry**: Apply the latest configurations to the access entry.
### VPC and Security Group Setup
- **Describe VPCs**: Identify the appropriate VPC for the Lambda function.
- **Create Security Group**: Define a security group to manage Lambda function traffic.
- **Set Ingress Rules**: Configure ingress rules for the security group.
### VPC Endpoint Creation
- **Create VPC Endpoint for eks-auth**: Establish a VPC endpoint for EKS authentication.
- **Check for Errors**: Verify if there are any errors during the creation of the VPC endpoint.
- **If errors**: Handle and log them.
- **Verify VPC Endpoint Existence**: Ensure the VPC endpoint already exists.
- **If exists**: Proceed with the next steps.
### Lambda Function Deployment
- **Download Kubernetes Library**: Fetch the necessary Kubernetes library.
- **Publish AWS Lambda Layer**: Publish a new layer version for the AWS Lambda function.
- **Create Lambda Code**: Develop the Lambda function code.
- **Zip Lambda Code**: Compress the Lambda function code for deployment.
- **Create AWS Lambda Function**: Deploy the Lambda function using the zipped code.
### Resolution
- **Final Verification**: Ensure all operations have been successfully completed.
- **Completion**: Confirm the deployment process is finished, ensuring robust management of EKS authentication through AWS Lambda.
This playbook provides a comprehensive, automated approach to deploying an AWS Lambda function for managing resources within an EKS cluster, efficiently handling all configurations and potential errors.
### Required Integration
#### AWS IAM (Identity and Access Management)
- [AWS IAM API Documentation](https://docs.aws.amazon.com/IAM/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS IAM Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSIAM/)
#### AWS EC2 (Elastic Compute Cloud)
- [AWS EC2 API Documentation](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS EC2 Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSEC2/)
#### AWS EKS (Elastic Kubernetes Service)
- [AWS EKS API Documentation](https://docs.aws.amazon.com/eks/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS EKS Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSEKS/)
#### AWS Lambda
- [AWS Lambda API Documentation](https://docs.aws.amazon.com/lambda/latest/dg/API_Reference.html)
- [Cortex XSOAR AWS Lambda Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSLambda/).
Function Removal - AWS [AWS-Enrichment-Remediation] — This playbook automates the removal of an AWS Lambda function and its associated resources used for managing resources within an Amazon EKS cluster. It ensures all related roles, policies, and security configurations are properly detached and deleted.
### Resource Detachment and Deletion
- **Get the Lambda Role**: Retrieve the IAM role associated with the Lambda function.
- **Detach Policy from Lambda Role**: Remove the policy attached to the Lambda role.
- **Delete IAM Role**: Delete the IAM role that was used for the Lambda function.
- **Delete Lambda Policy**: Remove the policy specifically created for the Lambda function.
- **Delete Security Group**: Delete the security group that was managing the Lambda function's traffic.
### Access Entry Check
- **Check if Access Entry was Created**: Verify if the access entry for the EKS cluster was created.
- **If YES**: Proceed to delete additional resources.
- **If NO**: Skip the deletion of additional resources.
### Additional Resource Deletion
- **Delete Kubernetes Layer**: Remove the Kubernetes layer that was used by the Lambda function.
- **Delete Lambda Function**: Delete the Lambda function itself, ensuring all related code and configurations are removed.
### Resolution
- **Final Cleanup**: Ensure all specified resources have been deleted successfully.
- **Completion**: Confirm that the removal process is complete, providing a clean environment free from the previously deployed Lambda function and its configurations.
This playbook provides a comprehensive, automated approach to removing an AWS Lambda function and its related resources, ensuring all configurations and dependencies are properly managed and deleted.
### Required Integration
#### AWS IAM (Identity and Access Management)
- [AWS IAM API Documentation](https://docs.aws.amazon.com/IAM/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS IAM Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSIAM/)
#### AWS EC2 (Elastic Compute Cloud)
- [AWS EC2 API Documentation](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Welcome.html)
- [Cortex XSOAR AWS EC2 Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSEC2/)
#### AWS Lambda
- [AWS Lambda API Documentation](https://docs.aws.amazon.com/lambda/latest/dg/API_Reference.html)
- [Cortex XSOAR AWS Lambda Integration](https://cortex.marketplace.pan.dev/marketplace/details/AWSLambda/).
GCP - User Investigation [GCP-Enrichment-Remediation] — This playbook performs an investigation on a specific user in GCP environments, using queries and logs from G Suite Auditor, and GCP Logging to locate the following activities performed by the user:
- Failed login attempt
- Suspicious API usage by the user
- Anomalous network traffic by the user
- Unusual and suspicious login attempt
- User's password leaked
GDPR Breach Notification [GDPR] — This playbook triggers by a GDPR breach incident, and then performs the required tasks that are detailed in GDPR Article 33.
The General Data Protection Regulation (the GDPR) is a regulation in EU law on data protection and privacy of individuals. The GDPR introduces the requirement for a personal data breach to be notified to the competent national supervisory authority and in certain cases, to communicate the breach to the individuals whose personal data have been affected by the breach.
***Disclaimer: This playbook does not ensure compliance to the GDPR regulation. Before using this playbook, we advise consulting with the relevant authority, and adjusting it to the organization's needs.
GRACase [Gurucul] — Playbook for fetching cases assosiated to high risk users.
GenericPolling [CommonPlaybooks] — Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete.
This playbook implements polling by continuously running the command in Step \#2 until the operation completes.
The remote action should have the following structure:
1. Initiate the operation.
2. Poll to check if the operation completed.
3. (optional) Get the results of the operation.
NOTE: This playbook should be run only when the playbook's context is using the "Private to sub-playbook" option.
Get Cloud Account Owner - Generic [CommonPlaybooks] — Retrieves the owners of a cloud account based on account ID.
Current supported platforms:
- GCP
- Prisma Cloud.
Get Code42 Employee Information [Code42] — Receives usernames from a Code42 Incydr alert and queries Active Directory for employee and supervisor information, if applicable.
Get Email From Email Gateway - FireEye [FireEyeEX] — This playbook retrieves a specified EML/MSG file directly from FireEye Email Security or Central Management.
Get Email From Email Gateway - Generic [CommonPlaybooks] — This playbook retrieves a specified EML/MSG file directly from the email security gateway product.
Get File Sample By Hash - Cylance Protect v2 [Cylance_Protect] — This playbook returns a file sample to the War Room given the file's SHA256 hash, using Cylance Protect v2 integration.
Get File Sample By Hash - Generic [DeprecatedContent] — Deprecated. Use "Get File Sample By Hash - Generic v2" playbook instead. Returns to the war-room a file sample correlating from a hash using one or more products
Get File Sample By Hash - Generic v2 [CommonPlaybooks] — Deprecated. Use `Get File Sample By Hash - Generic v3` instead. This playbook returns a file sample correlating to a hash in the war-room using the following sub-playbooks:
- Get File Sample By Hash - Carbon Black Enterprise Response
- Get File Sample By Hash - Cylance Protect v2
Get File Sample By Hash - Generic v3 [CommonPlaybooks] — This playbook returns a file sample correlating to a hash in the War Room using the following sub-playbooks:
- Get binary file by MD5 hash from Carbon Black telemetry data - VMware Carbon Black EDR v2.
- Get the threat (file) associated with a specific SHA256 hash - Cylance Protect v2.
- Get the file associated with a specific MD5 or SHA256 hash - Code42.
Get File Sample From Path - D2 [D2] — Returns a file sample to the war-room from a path on an endpoint using Demisto Dissolvable Agent (D2)
Input:
* Credentials - credentials to use when trying to deploy Demisto Dissolvable Agent (D2) (default: Admin)
* ${Endpoint.Hostname} - deploy agent on target endpoint
* ${File.Path} - file's path to collect
Get File Sample From Path - Generic [CommonPlaybooks] — Deprecated. Use `Get File Sample From Path - Generic V3` instead. Returns a file sample to the war-room from a path on an endpoint using one or more integrations
inputs:
* UseD2 - if "True", use Demisto Dissolvable Agent (D2) to return the file (default: False)
Get File Sample From Path - Generic V2 [CommonPlaybooks] — Deprecated. Use `Get File Sample From Path - Generic V3` instead.
This playbook returns a file sample correlating to a path into the War Room using the following sub-playbooks:
inputs:
1) Get File Sample From Path - D2.
2) Get File Sample From Path - VMware Carbon Black EDR (Live Response API).
Get File Sample From Path - Generic V3 [CommonPlaybooks] — This playbook returns a file sample from a specified path and host that you input in the following playbooks:
- PS Remote Get File Sample From Path
- Get File Sample From Path - VMware Carbon Black EDR (Live Response API)
- CrowdStrike Falcon - Retrieve File
- MDE - Retrieve File
- Cortex XDR - Retrieve File V2
Get File Sample From Path - VMware Carbon Black EDR - Live Response API [Carbon_Black_Enterprise_Live_Response] — This playbook retrieves a file from a path on an endpoint using VMware Carbon Black EDR (Live Response API).
Make sure to provide the Carbon Black sensor ID of the endpoint from which you want to retrieve the file.
Get Mails By Folder Pathes [DeprecatedContent] — Deprecated. Use the "Get Mails By Folder Paths" playbook instead.
Get Mails By Folder Paths [MicrosoftExchangeOnline] — Get emails from specific folders and pre-process them using EWS.
Get Original Email - EWS v2 [MicrosoftExchangeOnPremise] — This v2 playbook retrieves the original email in a thread as an EML file (and not an email object as in the previous version) by using the EWS v2 or EWSO365 integration.
It also reduces the number of tasks to perform the fetch action.
Note: You must have the necessary eDiscovery permissions in the EWS integration to execute a global search.
Get Original Email - Generic v2 [Phishing] — This v2 playbook is used inside the phishing flow. The inputs in this version do not use labels and also allow the user to supply an email brand.
Note: You must have the necessary permissions in your email service to execute a global search.
To retrieve the email files directly from the email service providers, use one of the provided inputs (Agari Phishing Defense customers should also use the following):
- EWS: eDiscovery
- Gmail: Google Apps Domain-Wide Delegation of Authority
- MSGraph: As described in the [message-get API](https://docs.microsoft.com/en-us/graph/api/message-get) and the [user-list-messages API](https://docs.microsoft.com/en-us/graph/api/user-list-messages)
- EmailSecurityGateway retrieves EML files from:
* FireEye EX
* FireEye CM
* Proofpoint Protection Server
* Mimecast
Get Original Email - Gmail v2 [Gmail] — This v2 playbook uses the reporter's email headers to retrieve the original email. This decreases the number of tasks to retrieve the original email.
Use this playbook to retrieve the original email using the Gmail integration, including headers and attachments.
Note: You must have the necessary Google Apps Domain-Wide Delegation of Authority permissions in your Gmail service to execute global search.
Get Original Email - Microsoft Graph Mail [MicrosoftGraphMail] — This playbook retrieves the original email using the Microsoft Graph Mail integration.
Note: You must have the necessary permissions in the Microsoft Graph Mail integration as described in the [message-get API](https://docs.microsoft.com/en-us/graph/api/message-get) and the [user-list-messages API](https://docs.microsoft.com/en-us/graph/api/user-list-messages)
Get User Devices - Generic [CommonPlaybooks] — This playbook retrieves information on all of the associated user devices.
In order to get a generic output, the following information on all of the retrieved devices will be saved under the `UserDevices` context key:
- Name
- Serial Number
- ID
- Model
- MAC Address
- OS
- Integration
Note that not all of the supported integrations will be able to retrieve this information.
In order to get the full list of supported integrations, read the following sub-playbooks descriptions:
- Get User Devices by Username - Generic
- Get User Devices by Email Address - Generic
Get User Devices by Email Address - Generic [CommonPlaybooks] — This playbook retrieves information on all of the associated user devices, based on the user email.
In order to get a generic output, the following information on all of the retrieved devices will be saved under the `UserDevices` context key:
- Name
- Serial Number
- ID
- Model
- MAC Address
- OS
- Integration
Note that not all of the supported integrations will be able to retrieve this information.
Supported integrations:
- jamf v2
- Google Workspace (Gsuite)
- ServiceNow v2
- Active Directory Query v2
- Microsoft Graph API (In order to get devices details, provide the permissions as mentioned here: https://learn.microsoft.com/en-us/graph/api/user-list-owneddevices?view=graph-rest-1.0&tabs=http )
Get User Devices by Username - Generic [CommonPlaybooks] — This playbook retrieves information on all of the associated user devices, based on the user's username.
In order to get a generic output, the following information on all of the retrieved devices will be saved under the `UserDevices` context key:
- Name
- Serial Number
- ID
- Model
- MAC Address
- OS
- Integration
Note that not all of the supported integrations will be able to retrieve this information.
Supported integrations:
- jamf v2
- Microsoft Defender for Endpoint
- Cortex XDR IR
- ServiceNow v2
- Google Workspace (Gsuite)
- Active Directory Query v2.
Get endpoint details - Generic [CommonPlaybooks] — Deprecated. Use the `Endpoint Enrichment - Generic v2.1` playbook instead.
This playbook uses the generic command !endpoint to retrieve details on a specific endpoint.
This command currently supports the following integrations:
- Palo Alto Networks Cortex XDR - Investigation and Response.
- CrowdStrike Falcon.
Get entity alerts by MITRE tactics [Core] — This playbook searches XDR alerts related to specific entities, on a given timeframe, based on MITRE tactics.
Note: The playbook's inputs enable manipulating the execution flow. Read the input descriptions for details.
Get host forensics - Generic [CommonPlaybooks] — This playbook retrieves forensics from hosts for the following integrations:
- Illusive Networks
- Microsoft Defender For Endpoint.
Get prevalence for IOCs [CommonPlaybooks] — The playbook queries the analytics module to receive the prevalence of an IOC.
Supported IOC:
- Process by SHA256
- Process by file name
- IP
- Domain
- CMD
- Registry (require key and value)
Google Dorking File Processing [GoogleDorking] — This playbook processes files fetched by the Google Dorking integration.
The SOC will track the file owner and classify the exposed data and users in order to contained the leaked data.
Google Vault - Search Drive [GoogleVault] — This is a playbook for performing Google Vault search in Drive accounts and display the results.
Google Vault - Search Groups [GoogleVault] — This is a playbook for performing Google Vault search in Groups and display the results.
Google Vault - Search Mail [GoogleVault] — This is a playbook for performing Google Vault search in Mail accounts and display the results.
HAFNIUM - Exchange 0-day exploits [MajorBreachesInvestigationandResponse] — This playbook includes the following tasks:
Collect indicators to be used in your threat hunting process Retrieve IOCs related to HAFNIUM and the exploited exchange 0-day vulnerabilities Discover IOCs related to the attack Query firewall logs to detect malicious network activity Search endpoint logs for malicious hashes to detect compromised hosts (Available from Cortex XSOAR 5.5.0). Block indicators Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. Read more about the attack on our Unit42 blog: https://unit42.paloaltonetworks.com/microsoft-exchange-server-vulnerabilities/ Sources: https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
HIPAA - Breach Notification [HIPAA-BreachNotification] — USA Health Insurance Portability and Accountability Act of 1996 (HIPAA) covers organizations that use, store, or process Private Health Information (PHI).
The HIPAA Breach Notification Rule requires companies that deal with health information to disclose cybersecurity breaches; the disclosure will include notification to individuals, to the media, and the Secretary of Health and Human Services.
This playbook is triggered by a HIPAA breach notification incident and follows through with the notification procedures.
DISCLAIMER: Please consult with your legal team before implementing this playbook.
** Source: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
HackerView Incident Management [CTM360-CyberBlindspot] — This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to track the progress of the investigation.
HackerView Incident Management V2 [CTM360-CyberBlindspot] — This playbook runs the incidents through indicator enrichment, then based on the mirroring settings, it can communicate with the remote server to track the progress of the investigation.
When the remote HackerView ticket status becomes inactive, the playbook automatically closes the local incident via the Close Incident Locally task (closeInvestigation). The HackerView Incident type is configured to run this playbook with autorun enabled, so no analyst prompt is required for that auto-close path.
Handle Darktrace Model Breach [Darktrace] — Deprecated. Use Darktrace Basic Model Breach Handler and Darktrace Basic AI Analyst Event Handler instead.
Handle Expanse Incident [ExpanseV2] — Deprecated. No available replacement.
Main Playbook to Handle Expanse Incidents.
There are several phases:
1. Enrichment: all the related information from the incident is extracted, and related indicators (IP, CIDR, Domain, DomainGlob, Certificate) are created and enriched.
2. Validation: the found IP and FQDN are correlated with the information available in other products:
- Firewall logs from Strata Logging Service, Panorama, and Splunk.
- User information from Active Directory.
- Public IP address from AWS/GCP/Azure public IP feeds to identify the Public Cloud region and service (i.e., us-west-1 on AWS EC2).
- IP and FQDN from Prisma Cloud inventory.
3. Shadow IT check: based on the information found, the playbook can suggest whether the discovered issue corresponds to an asset that is known to the InfoSec team (i.e., there are firewall logs present, or the asset is protected by Prisma Cloud, or is part of an IP range associated to the company).
4. Attribution: based on the information collected above, the analyst is prompted to assign this issue to an Organization Unit, which is a group within the company with a specific owner. The analyst can choose from existing Organization Units (stored in an XSOAR list) or define a new one.
5. Response: depending on the issue type, several remediation actions can be automatically and manually performed, such as:
- Tagging the asset in Expanse with a specific Organization Unit tag.
- Blocking the service on PAN-OS (if a firewall is deployed in front of the service).
- Creating a new Shadow IT issue (if the asset is detected to be Shadow IT and the analyst confirms it)
- Adding the service to a Vulnerability Management system
- Linking the incident to a related Prisma Cloud alert for the asset (if the asset is found under Prisma Cloud inventory)
- Bringing rogue cloud accounts under management
Handle Expanse Incident - Attribution Only [ExpanseV2] — Deprecated. No available replacement.
Shorter version of Handle Expanse Incident playbook with only the Attribution part.
There are several phases:
1. Enrichment: all the related information from the incident is extracted and related Indicators (of types IP, CIDR, Domain, DomainGlob, Certificate) are created and enriched.
2. Validation: the found IP and FQDN are correlated with the information available in other products:
- Firewall logs from Strata Logging Service, Panorama and Splunk
- User information from Active Directory
- Public IP address from AWS/GCP/Azure public IP feeds to identify the Public Cloud region and Service (i.e. us-west-1 on AWS EC2)
- IP and FQDN from Prisma Cloud inventory
3. Shadow IT check: based on the information found, the playbook can suggest whether the discovered issue corresponds to an asset that is known to the InfoSec team (i.e. there are firewall logs present, or the asset is protected by Prisma Cloud, or is part of an IP range associated to the Company).
4. Attribution: based on the information collected above, the Analyst is prompted to assign this issue to an Organization Unit, that is a group within the Company with a specific owner. The Analyst can choose from existing Organization Units (stored in an XSOAR list) or define a new one.
Handle False Positive Alerts [CommonPlaybooks] — This playbook handles false positive alerts.
It creates an alert exclusion or alert exception, or adds a file to an allow list based on the alert fields and playbook inputs.
Handle Hello World Alert [HelloWorld] — This is a playbook which will handle the alerts coming from the Hello World service
Handle Shadow IT Incident [ShadowIT] — This Playbook is used to handle a Shadow IT incident. A Shadow IT incident occurs when a resource attributed to the organization that is not sanctioned by IT nor protected by the InfoSec team is found.
This playbook handles the incident by helping the analyst to find the owner of the resource based on existing evidence. The playbook also marks the service indicators (IP or FQDN) with a Shadow IT tag. The possible owner and their manager are notified and onboarding of the asset on Prisma Cloud is triggered through a manual process.
HelloWorld Scan [HelloWorld] — Deprecated. No available replacement.
Hostname And IP Address Investigation And Remediation - Chronicle [GoogleChronicleBackstory] — This playbook receives ChronicleAsset type of indicators from its parent playbook "ChronicleAsset Investigation - Chronicle", performs enrichment and investigation for each one of them, provides an opportunity to isolate and block the hostname or IP address associated with the current indicator, and provides a list of isolated and blocked entities.
Hunt Extracted Hashes [DeprecatedContent] — Deprecated. Use the Hunt Extracted Hashes V2 playbook instead. This playbook extracts IOCs from the incident details and attached\ \ files using regular expressions and then hunts for hashes on endpoints in the organization\ \ using available tools.\nThe playbook supports multiple types of attachments. For\ \ the full supported attachments list, refer to \"Extract Indicators From\ \ File - Generic v2\".
Hunt Extracted Hashes V2 [Hunting] — This playbook extracts IOCs from the incident details and attached files using regular expressions and then hunts for hashes on endpoints in the organization using available tools.
The playbook supports multiple types of attachments. For the full supported attachments list, refer to "Extract Indicators From File - Generic v2".
Hunt for bad IOCs [DeprecatedContent] — Deprecated. Use the Search Endpoints By Hash playbook. Assume that malicious IOCs are in the right place in the context and start hunting using available tools.
Hunting C&C Communication Playbook [DeprecatedContent] — Deprecated. A playbook to use the latest Threat Intelligence to hunt across your infrastructure and look for malicious C&C communications.
Hurukai - Hunt IOCs [HarfangLabEDR] — This playbook allows is triggered by the Hurukai - Process Indicators - Manual Review playbook. It allows to search for IOC sightings in the HarfangLab EDR and tag sighted IOCs accordingly for manual review. All IOCs are tagged in order to be further inserted into a HarfangLab EDR IOC source.
Hurukai - Process Indicators - Manual Review [HarfangLabEDR] — This playbook tags indicators ingested by feeds that require manual approval. The playbook is triggered due to a job. The indicators are tagged as requiring a manual review. The playbook optionally concludes with creating a new incident that includes all of the indicators that the analyst must review.
To enable the playbook, the indicator query needs to be configured. An example query is a list of the feeds whose ingested indicators should be manually reviewed. For example, sourceBrands:"Feed A" or sourceBrands:"Feed B".
IOC Alert [Core] — IOCs provide the ability to alert on known malicious objects on endpoints across the organization.
**Analysis Actions:**
The playbook will use several enrichment sources to determine the IOC verdict. Additionally, will use the Analytics module to run a prevalence check for the IOC.
**Response Actions:**
The playbook's first response action is a containment plan that is based on the playbook input. In that phase, the playbook will execute endpoint isolation
**Investigative Actions:**
When the playbook executes, it checks for additional abnormal activity using the Endpoint Investigation Plan playbook that can indicate the endpoint might be compromised.
**Remediation Actions:**
In case results are found within the investigation phase, the playbook will execute remediation actions that include containment and eradication.
This phase will execute the following containment actions:
* File quarantine
* Endpoint isolation
And the following eradication actions:
* Manual process termination
* Manual file deletion.
IOC Curated Enrichment - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook provides IOC curated enrichment using Google Threat Intelligence data, including malware families, campaigns, and threat actors, and displays the results in the War Room for investigation.
IOC Enrichment and Blocking - Google SecOps [GoogleChronicleBackstory] — This playbook enriches IOCs using the enrichment commands (IP, Email, Domain, URL, and File) and blocks the malicious IOCs based on DBot Score.
IOC Enrichment and Blocking - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook enriches IOCs using the GTI enrichment commands (IP, Domain, URL, and File) and blocks the IOCs based on GTI assessment parameters such as Threat Score, Severity, and Verdict.
IP Enrichment - External - Generic v2 [CommonPlaybooks] — Enrich IP addresses using one or more integrations.
- Resolve IP addresses to hostnames (DNS).
- Provide threat information.
- IP address reputation using !ip command.
- Separate internal and external addresses.
IP Enrichment - Generic [DeprecatedContent] — Deprecated. Enrich IP using one or more integrations.
IP enrichment includes:
* Resolve IP to Hostname (DNS)
* Threat information
* Separate internal and external addresses
* IP reputation
* For internal addresses, get host information
IP Enrichment - Generic v2 [CommonPlaybooks] — Enrich IP addresses using one or more integrations.
- Resolve IP addresses to hostnames (DNS)
- Provide threat information
- Determine IP address reputation using the !ip command
- Separate internal and external IP addresses
- For internal IP addresses, get host information.
When executing this playbook through IP Enrichment - Generic v2, IP classification and resolution will be handled by the main playbook, improving performance.
IP Enrichment - Infoblox Cloud [InfobloxBloxOne] — This playbook enriches IP addresses with the dossier, TIDE and asset data using Infoblox Threat Defense with DDI integration.
IP Enrichment - Internal - Generic v2 [CommonPlaybooks] — Enrich Internal IP addresses using one or more integrations.
- Resolve IP address to hostname (DNS)
- Separate internal and external IP addresses
- Get host information for IP addresses.
IP Lookup - Infoblox NIOS [Infoblox] — This playbook looks up IP addresses using Infoblox NIOS integration.
IP Whitelist And Exclusion - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — Adds the IP Address(es) to allow list after checking if it should be added to allow list according to the user inputs provided. This playbook also adds these IP Address indicators to the exclusion list and tags it with the "RiskIQ Whitelisted IP Address" tag.
IQ-HUB Automation [Confluera] — This playbook is used to retrieve real-time detections and progressions data generated by events on different systems present in the network.
Identity Analytics - Alert Handling [Core] — The `Identity Analytics - Alert Handling` playbook is designed to handle Identity Analytics alerts and executes the following:
Analysis:
- Enriches the Indicators and the account, providing additional context and information about these indicators.
Verdict:
- Determines the appropriate verdict based on the data collected from the enrichment phase.
Investigation:
- Checks for related XDR alerts to the user by Mitre tactics to identify malicious activity.
- Checks for specific arguments for malicious usage from Okta using the 'Okta User Investigation' sub-playbook.
- Checks for specific arguments for malicious usage from Azure using the 'Azure User Investigation' sub-playbook.
Verdict Handling:
- Handles malicious alerts by initiating appropriate response actions, including blocking malicious IP and revoking or clearing user's sessions.
- Handles non-malicious alerts identified during the investigation.
Illinois - Breach Notification [BreachNotification-US] — This playbook helps an analyst determine if the breached data meets the criteria for breach notification according to Illinois law, and, if necessary, follows through with the notification procedures.
DISCLAIMER: Please consult with your legal team before implementing this playbook.
**Source:** http://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=2702&ChapAct=815%C2%A0ILCS%C2%A0530/&ChapterID=67&ChapterName=BUSINESS+TRANSACTIONS&ActName=Personal+Information+Protection+Act.
https://www.mintz.com/newsletter/2007/PrivSec-DataBreachLaws-02-07/state_data_breach_matrix.pdf
Illuminate Integration Demonstration [illuminate] — Deprecated. No available replacement. A quick demonstration of the various illuminate enrichment commands.
Illusive - Data Enrichment [IllusiveNetworks] — This playbook is used for automatic enrichment of incidents in the organization network, with Illusive's set of forensics and data
Illusive - Incident Escalation [IllusiveNetworks] — This playbook is used for creating an automatic analysis of the Illusive's incident details, in order to end up with a certain score or a set of insights that will enable automatic decisions and actions.
Illusive-Collect-Forensics-On-Demand [IllusiveNetworks] — This playbook is used to collect forensics on-demand on any compromised host and retrieve the forensics timeline upon successful collection.
Illusive-Retrieve-Incident [IllusiveNetworks] — This playbook is used for retrieving an extensive view over a detected incident by retrieving the incident details and a forensics timeline if and when forensics have been successfully collected.
Impossible Traveler - Enrichment [Core] — This playbook get as an input all of the involved IP addresses and identities from the Impossible Traveler playbook alert, and enriches them based on the following:
* Geo location
* Active Directory
* IP enrichment e.g. VirusTotal, AbuseIPDB, etc.
Impossible Traveler Response [Core] — This playbook handles impossible traveler alerts.
An Impossible Traveler event occurs when multiple login attempts seen for a user from multiple remote countries in a short period of time, which shouldn't be possible. This may indicate the account is compromised.
**Attacker's Goals:**
Gain user-account credentials.
**Investigative Actions:**
Investigate the IP addresses and identities involved in the detected activity using:
* Impossible Traveler - Enrichment playbook
* CalculateGeoDistance automation
**Response Actions**
The playbook's first response actions are based on the data available within the alert. In that phase, the playbook will execute:
* Manual block indicators if the IP address found malicious
* Manual disable user
* Manual clear of the user’s sessions (Okta)
When the playbook continues, after validating the activity with the user’s manager, another phase of response actions is being executed, which includes:
* Auto block indicators
**External Resources:**
[Impossible traveler alert](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Impossible-traveler-SSO)
Incident Enrichment [DeprecatedContent] — Deprecated. We recommend using Default playbook instead. Enrich data with reputation from the incident. Data is extracted to the standard locations like File, URL, IP.
Incident Enrichment - XM Cyber [XMCyber] — This playbook enriches the incident using the hostname indicators and user data and increases the severity based on the calculated risk score and pushes breach points of the identified entities to XM Cyber.
Incident Response - Infoblox Cloud [InfobloxBloxOne] — This playbook is used to initiate the incident response. This playbook runs when an incident is selected for investigation. It will change the state from pending to active and it will list the available indicators, events, assets, and comments from Infoblox corresponding to the incident. If incident severity is found to be higher than or equivalent to medium, it will create a ServiceNow incident otherwise the given incident will be assigned to an analyst.
Indicator Enrichment - Censys [Censys] — This playbook enriches the IP addresses, domains, and SHA256 file hashes indicators with Censys threat intelligence data.
Indicator Enrichment - Infoblox Cloud [InfobloxBloxOne] — This playbook enriches IP addresses, MAC addresses, domains and URLs with the dossier, DHCP lease, TIDE and asset data using Infoblox Threat Defense with DDI integration.
Indicator Pivoting - DomainTools Iris [DomainTools_Iris] — Pivots are used to gather data that share a common attribute with a domain. For instance, pivoting on an IP Address will give you back all domains related to that IP address.
Integration Troubleshooting [Troubleshoot] — Troubleshoot a problem with either an integration's configuration or with running a command.
Integrations and Incidents Health Check - Running Scripts [IntegrationsAndIncidentsHealthCheck] — This playbook is triggered by a 'JOB - Integrations and Playbooks Health' playbook and is responsible for running failed integrations and failed incidents scripts. The playbook may run separately from the main playbook to run health tests on enabled integrations and open incidents.
Intezer - Analyze Uploaded file [Intezer] — Upload a file to Intezer Analyze to analyze and enrich the file reputation. (up to 150 MB)
Intezer - Analyze by hash [Intezer] — Analyze the given file hash on Intezer Analyze and enrich the file reputation. Supports SHA256, SHA1, and MD5.
Investigate On Bad Domain Matches - Chronicle [GoogleChronicleBackstory] — Use this playbook to investigate and remediate Bad IOC domain matches with recent activity found in the enterprise, as well as notify the SOC lead and network team about the matches.
Supported Integrations:
- Chronicle
- Google SecOps
- Whois
- Mail Sender (New)
- Palo Alto Networks PAN-OS
- Palo Alto Networks AutoFocus v2
Isolate Endpoint - Generic [CommonPlaybooks] — Deprecated. Use the "Isolate Endpoint - Generic V2" playbook instead.
Isolate Endpoint - Generic V2 [CommonPlaybooks] — This playbook isolates a given endpoint using various endpoint product integrations.
Make sure to provide valid playbook inputs for the integration you are using.
Issue Exception Approval [Core] — This playbook manages communication for the approval of a requested issue exception.
Ivanti Critical Vulnerabilities [IvantiCriticalVulnerabilities] — Ivanti has recently disclosed four critical vulnerabilities in their VPN devices, identified as CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, and CVE-2024-21893, with active exploitation reported. These security flaws impact all supported versions of Ivanti Connect Secure and Ivanti Policy Secure gateways, including versions 9.x and 22.x, and Ivanti Neurons for ZTA.
#### Disclosed Vulnerabilities
* CVE-2023-46805, a high-severity vulnerability, allows attackers to bypass authentication checks in the web component, granting access to restricted resources without credentials.
* CVE-2024-21887, of critical severity, enables command injection through specially crafted requests by authenticated administrators, leading to arbitrary command execution.
* CVE-2024-21888, another critical vulnerability, permits privilege escalation within the web component, enabling users to gain administrative rights.
* CVE-2024-21893 exposes a server-side request forgery (SSRF) vulnerability within the SAML component, allowing unauthorized access to specific restricted resources.
The combination of these vulnerabilities, particularly CVE-2023-46805 and CVE-2024-21887, facilitates attackers to execute commands on the compromised system sans authentication, posing a significant security risk. Organizations utilizing affected Ivanti products are urged to apply mitigations and patches to safeguard their systems against potential exploits.
**This playbook should be triggered manually or can be configured as a job.**
**IoCs Collection**
- Unit42 IoCs download
**Hunting**
- PANW Hunting:
- Panorama Threat IDs hunting
- Cortex Xpanse issues hunting
- Indicators hunting
- Endpoints by CVE hunting
**Mitigations**
Ivanti recommended workaround and patch.
**References**
[Unit42 Threat Brief: Multiple Ivanti Vulnerabilities](https://unit42.paloaltonetworks.com/threat-brief-ivanti-cve-2023-46805-cve-2024-21887/#ivanti-2024-addit-resources)
[CVE-2023-46805 (Authentication Bypass) & CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways](https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
JOB - Cortex XDR query endpoint device control violations [CortexXDR] — A job to periodically query Cortex XDR device control violations by a given timestamp in a relative date playbook input.
The collected data, if found, will be generated for a new incident.
You can configure the created new incident type in the playbook input and use the XDR Device Control Violations incident type to associate it with the response playbook.
The job includes an incident type with a dedicated layout to visualize the collected data.
To configure the job correctly:
1. Create a new recurring job.
2. Configure the recurring schedule.
3. Add a name.
4. Configure the type to XDR Device Control Violations.
5. Configure this playbook as the job playbook.
The scheduled run time and the timestamp relative date should be identical.
If the job recurs every 7 days, the timestamp should be 7 days as well.
JOB - Integrations and Incidents Health Check [IntegrationsAndIncidentsHealthCheck] — You should run this playbook as a scheduled job. The playbook checks the health of all enabled integrations and open incidents.
JOB - Integrations and Incidents Health Check - Lists handling [IntegrationsAndIncidentsHealthCheck] — This playbook is triggered by a 'JOB - Integrations and Playbooks Health' playbook and is responsible for creating or updating related XSOAR lists.
JOB - Popular News [PopularCybersecurityNews] — Playbook can be run ad-hoc or as a Job to fetch results from Popular News sites
JOB - XSOAR - Export Selected Custom Content [XSOAR-SimpleDevToProd] — This playbook is intended to be run as an adhoc job to quickly create a custom content bundle with only selected items from the servers custom content.
Then you can import this new zip on the other XSOAR server.
Create a Job with the Type “XSOAR Dev to Prod”, and select this playbook to get started. For more information on Jobs: https://xsoar.pan.dev/docs/incidents/incident-jobs
JOB - XSOAR - Simple Dev to Prod [XSOAR-SimpleDevToProd] — This playbook is intended to be run as an adhoc job to quickly create a custom content bundle with only selected items from the servers custom content. You can import this new zip on the other XSOAR server, or push it to production using the Core REST API integration.
Please ensure to read the setup instructions for this pack carefully.
Create a Job with the Type “XSOAR Dev to Prod”, and select this playbook to get started. For more information on Jobs: https://xsoar.pan.dev/docs/incidents/incident-jobs
Jira Change Management [Change_Management] — If you are using PAN-OS/Panorama firewall and Jira as a ticketing system, this playbook will be a perfect match for your change management for firewall process.
This playbook is triggered by afetch from Jira and will help you manage and automate your change management process.
Jira Ticket State Polling [Jira] — Use Jira Incident State Polling as a sub-playbook when required to pause the execution of a master playbook until the Jira ticket state is either resolved or closed.
This playbook implements polling by continuously running the jira-get-issue command until the state is either resolved or closed.
Kaseya VSA 0-day - REvil Ransomware Supply Chain Attack [MajorBreachesInvestigationandResponse] — On July 2nd, Kaseya company has experienced an attack against the VSA (Virtual System/Server Administrator) product. Kaseya customers pointed out a ransomware outbreak in their environments.
Further investigation revealed that REvil group exploited VSA zero-day vulnerabilities for authentication bypass and arbitrary command execution. This allowed the attacker to deploy ransomware on Kaseya customers' endpoints.
This playbook should be trigger manually and includes the following tasks:
* Collect related known indicators from several sources.
* Indicators, PS commands, Registry changes and known HTTP requests hunting using PAN-OS, Cortex XDR and SIEM products.
* Splunk advanced queries can be modified through the playbook inputs.
* QRadar query is done using Reference Set and "QRadar Indicator Hunting V2" playbook
* Search for internet facing Kaseya VSA servers using Xpanse.
* Block indicators automatically or manually.
* Provide advanced hunting and detection capabilities.
* Mitigation using Kaseya On-Premises and SaaS patch.
More information:
[Kaseya Incident Overview & Technical Details](https://helpdesk.kaseya.com/hc/en-gb/articles/4403584098961)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Kenna - Search and Handle Asset Vulnerabilities [Kenna] — This playbook accepts an asset, then searches for vulnerabilities on that asset using the Kenna integration. If a vulnerability exists, it looks for relevant patches, lets the analyst deploy them and then generates an investigation summary report.
LSASS Credential Dumpin [LSASSCredentialDumping] — This playbook is focused on detecting Credential Dumping attack as researched by Accenture Security analysts and engineers.
Large Upload Alert [Core] — The playbook investigates Cortex XDR alerts involving large upload alerts.
The playbook consists of the following procedures:
- Searches for similar previous alerts that were closed as false positives.
- Enrichment and investigation of the initiator and destination hostname and IP address.
- Enrichment and investigation of the initiator user, process, file, or command if it exists.
- Detection of related indicators and analysis of the relationship between the detected indicators.
- Utilize the detected indicators to conduct threat hunting.
- Blocks detected malicious indicators.
- Endpoint isolation.
This playbook supports the following Cortex XDR alert names:
- Large Upload (Generic)
- Large Upload (SMTP)
- Large Upload (FTP)
- Large Upload (HTTPS)
List Device Events - Chronicle [GoogleChronicleBackstory] — This playbook receives ChronicleAsset identifier information and provides a list of events related to each one of them.
Supported integration:
- Chronicle
- Google SecOps.
Local Analysis alert Investigation [Core] — When an unknown executable, DLL, or macro attempts to run on a Windows or Mac endpoint, the Cortex XDR agent uses local analysis to determine if it is likely to be malware. Local analysis uses a static set of pattern-matching rules that inspect multiple file features and attributes, and a statistical model that was developed with machine learning on WildFire threat intelligence.
**Investigative Actions:**
Investigate the executed process image and verify if it is malicious using:
* XDR trusted signers
* VT trusted signers
* VT detection rate
* NSRL DB
**Response Actions**
The playbook's first response action is a containment plan that is based on the initial data provided within the alert. In that phase, the playbook will execute:
* Auto block indicators
* Auto file quarantine
* Manual endpoint isolation
When the playbook executes, it checks for additional activity using the Endpoint Investigation Plan playbook, and another phase, which includes containment and eradication, is executed.
This phase will execute the following containment actions:
* Manual block indicators
* Manual file quarantine
* Auto endpoint isolation
And the following eradication actions:
* Manual process termination
* Manual file deletion
* Manual reset of the user’s password
External resources:
[Malware Protection Flow](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/File-Analysis-and-Protection-Flow)
LogRhythmRestV2 - Search query [LogRhythmRest] — This playbook used generic polling to get query results using the command: lr-execute-search-query.
Logrhythm - Search query [LogRhythmRest] — This playbook used generic polling to gets query result using the command: lr-execute-search-query
Logrhythm Alarm Handling [LogRhythmRest] — This playbook is triggered by fetching a LogRhythm alarm incident.
The playbook executes the commands: lr-alarms-list, lr-alarm-summary and lr-users-list to get more useful data for the alarm.
Lost / Stolen Device Playbook [Lost_Stolen_Device] — This manual playbook handles an incident for a lost or stolen device. It guides the analyst through various steps to validate the type of device and its contents, and the required steps for response and remediation. Initial incident details should be the name of the reporting person or ID of the SIEM alert/incident, and description of the lost device.
MAC Enrichment - Infoblox Cloud [InfobloxBloxOne] — This playbook enriches MAC addresses with DHCP lease information using Infoblox Threat Defense with DDI integration.
MAR - Endpoint data collection [McAfee-MAR] — Use McAfee Active Response to collect data from an endpoint for IR purposes (requires ePO as well).
Input:
* Hostname (Default: ${Endpoint.Hostname})
MDE - False Positive Incident Handling [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles closing false positive incidents for Microsoft Defender for Endpoint.
MDE - Host Advanced Hunting [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook uses the Microsoft Defender For Endpoint Advanced Hunting feature based on the provided inputs.
MDE - Host Advanced Hunting For Network Activity [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook uses the Microsoft Defender For Endpoint Advanced Hunting feature to hunt for host network activity.
MDE - Host Advanced Hunting For Persistence [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook uses the Microsoft Defender For Endpoint Advanced Hunting feature to hunt for host persistence evidence.
MDE - Host Advanced Hunting For Powershell Executions [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook uses the Microsoft Defender For Endpoint Advanced Hunting feature to hunt for host PowerShell executions.
MDE - Pro-Active Actions [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook supports investigation actions for the analyst, including:
- Running a full AV scan for a specific endpoint
- Requesting an investigation package (a zip file containing forensic data with a size of ~ 15MB) from an endpoint.
- Requesting to run automatic investigation on an endpoint.
MDE - Retrieve File [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the ‘Malware Investigation And Response’ pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook uses the Live Response feature to retrieve a file from an endpoint. The playbook supports a supplied machine id as an input. Otherwise, it will take the Device ID incident field.
The playbook supports only one element to be retrieved for each task (if needed more then one - use the playbook loop feature).
MDE - Search And Block Software [MicrosoftDefenderAdvancedThreatProtection] — This playbook will search a file or process activity of a software by a given image file name using Microsoft Defender For Endpoint. The analyst can then choose the files to block.
MDE - Search and Compare Process Executions [MicrosoftDefenderAdvancedThreatProtection] — This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Microsoft Defender For Endpoint" integration to search for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input.
Note: Under the "Processes", input the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
MDE - True Positive Incident Handling [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This Playbook handles closing a true positive incident for Microsoft Defender for Endpoint.
MDE Malware - Incident Enrichment [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook enriches Microsoft Defender For Endpoint alerts. The enrichment is done on the involved endpoint and Mitre technique ID information, and it sets the 'Malware-Investigation and Response' layout.
MDE Malware - Investigation and Response [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook investigates Microsoft Defender For Endpoint malware alerts. It uses - Microsoft Defender For Endpoint Advanced Hunting - Command Line Analysis - Deduplication - Sandbox hash search and detonation - Proactive investigation actions (AV scan, investigation package collection, running automated investigation on an endpoint) - Microsoft Defender For Endpoint alert enrichment - Incident handling (true/false positive)
MDE SIEM ingestion - Get Incident Data [MicrosoftDefenderAdvancedThreatProtection] — This playbook is part of the 'Malware Investigation And Response' pack. For more information, refer to https://xsoar.pan.dev/docs/reference/packs/malware-investigation-and-response.
This playbook handles incident ingestion from a SIEM. The user provides the incident fields containing the alert ID. This playbook also enables changing the severity according to a user-defined scale to override the default assigned severity.
MDR Escalation Process - Vectra XDR [VectraXDR] — This playbook retrieves the MDR ticket number associated with the given entity by parsing its notes. It then collects the entity's active detections, performs a detection assessment, and sends the results to the designated recipient via email.
MITRE ATT&CK - Courses of Action [MITRECoA] — This is the parent playbook, which contains all phases and remediates MITRE ATT&CK techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. The playbook utilizes several other MITRE ATT&CK remediation playbooks.
The playbook follows the MITRE ATT&CK kill chain phases and takes action to protect the organization from the inputted techniques, displaying and implementing security policy recommendations for Palo Alto Networks products.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Possible playbook triggers:
- The playbook can be triggered by a feed integration fetching indicators that contain MITRE ATT&CK techniques as “Feed Related Indicators”, using the "MITRE ATT&CK - Courses of Action - Job" playbook.
- The playbook can be triggered manually for specific MITRE ATT&CK techniques using the ‘techniqueByIncident’ playbook input.
- An incident that contains MITRE ATT&CK technique IDs using the ‘techniqueByIncident’ playbook input.
MITRE ATT&CK - Courses of Action Trigger Job [MITRECoA] — This is a wrapper playbook for the "MITRE ATT&CK - Courses of Action" use-case.
Possible playbook triggers:
- Through a job, by a feed integration fetching indicators that contain MITRE ATT&CK techniques as “Feed Related Indicators”, or with custom inputs.
- Through an incident, using custom playbook inputs.
Once triggered, the playbook will create a new incident from type "MITRE ATT&CK CoA". The incident will trigger the playbook "MITRE ATT&CK - Courses of Action",
which contains all phases and remediates MITRE ATT&CK techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
MITRE ATT&CK CoA - T1003 - OS Credential Dumping [MITRECoA] — This playbook Remediates the OS Credential Dumping technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1003: OS Credential Dumping
Kill Chain phases:
- Defense Evasion
MITRE ATT&CK Description:
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software. Credentials can then be used to perform Lateral Movement and to access restricted information.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1005 - Data from Local System [MITRECoA] — This playbook Remediates the Data from Local System technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1005: Data from Local System
Kill Chain phases:
- Collection
MITRE ATT&CK Description:
Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a Command and Scripting Interpreter, such as cmd, which has functionality to interact with the file system to gather information. Some adversaries may also use Automated Collection on the local system.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1021.001 - Remote Desktop Protocol [MITRECoA] — This playbook Remediates the Remote Desktop Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1021.001: Remote Desktop Protocol
Kill Chain phases:
- Lateral Movement
MITRE ATT&CK Description:
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).
Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features technique for Persistence.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1027 - Obfuscated Files or Information [MITRECoA] — This playbook Remediates the Obfuscated Files or Information technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1027: Obfuscated Files or Information
Kill Chain phases:
- Defense Evasion
MITRE ATT&CK Description:
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1041 - Exfiltration Over C2 Channel [MITRECoA] — This playbook Remediates the Exfiltration Over C2 Channel technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1041: Exfiltration Over C2 Channel
Kill Chain phases:
- Exfiltration
MITRE ATT&CK Description:
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1048 - Exfiltration Over Alternative Protocol [MITRECoA] — This playbook Remediates the Exfiltration Over Alternative Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1048: Exfiltration Over Alternative Protocol
Kill Chain phases:
- Exfiltration
MITRE ATT&CK Description:
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Different protocol channels could also include Web services such as cloud storage. Adversaries may also opt to encrypt and/or obfuscate these alternate channels.
Exfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1057 - Process Discovery [MITRECoA] — This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1057: Process Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter [MITRECoA] — This playbook Remediates the Command and Scripting Interpreter technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1059: Command and Scripting Interpreter
Kill Chain phases:
- Execution
MITRE ATT&CK Description:
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript/JScript and Visual Basic.
Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1059.001 - PowerShell [MITRECoA] — This playbook Remediates the Command and Scripting Interpreter technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1059.001: Command and Scripting Interpreter: PowerShell
Kill Chain phases:
- Execution
MITRE ATT&CK Description:
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. [1] Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
PowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1068 - Exploitation for Privilege Escalation [MITRECoA] — This playbook Remediates the Exploitation for Privilege Escalation technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1068: Exploitation for Privilege Escalation
Kill Chain phases:
- Privilege Escalation
MITRE ATT&CK Description:
Adversaries may exploit software vulnerabilities in an attempt to collect elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
When initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This may be a necessary step for an adversary compromising a endpoint system that has been properly configured and limits other privilege escalation methods.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1071 - Application Layer Protocol [MITRECoA] — This playbook Remediates the Application Layer Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1071: Application Layer Protocol
Kill Chain phases:
- Command And Control
MITRE ATT&CK Description:
Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, or DNS. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1078 - Valid Accounts [MITRECoA] — This playbook Remediates the Valid Accounts technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1078: Valid Accounts
Kill Chain phases:
- Defense Evasion
- Persistence
- Privilege Escalation
- Initial Access
MITRE ATT&CK Description:
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1082 - System Information Discovery [MITRECoA] — This playbook Remediates the System Information Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1082: System Information Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Tools such as Systeminfo can be used to gather detailed system information. A breakdown of system data can also be gathered through the macOS systemsetup command, but it requires administrative privileges.
Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1083 - File and Directory Discovery [MITRECoA] — This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1083: File and Directory Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1105 - Ingress tool transfer [MITRECoA] — This playbook Remediates the Ingress tool transfer technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1105: Ingress tool transfer
Kill Chain phases:
- Command And Control
MITRE ATT&CK Description:
Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. Files can also be copied over on Mac and Linux with native tools like scp, rsync, and sftp.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1110 - Brute Force [MITRECoA] — This playbook Remediates the Brute Force technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1110 : Brute Force
Kill Chain phases:
- Credential Access
MITRE ATT&CK Description:
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1133 - External Remote Services [MITRECoA] — This playbook Remediates the External Remote Services technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1133: External Remote Services
Kill Chain phases:
- Persistence
- Initial Access
MITRE ATT&CK Description:
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1135 - Network Share Discovery [MITRECoA] — This playbook Remediates the Network Share Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1135: Network Share Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
File sharing over a Windows network occurs over the SMB protocol. [1] [2] Net can be used to query a remote system for available shared drives using the net view \remotesystem command. It can also be used to query shared drives on the local system using net share.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1189 - Drive-by Compromise [MITRECoA] — This playbook Remediates the Drive-by Compromise technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1189: Drive-by Compromise
Kill Chain phases:
- Initial Access
MITRE ATT&CK Description:
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. With this technique, the user's web browser is typically targeted for exploitation, but adversaries may also use compromised websites for non-exploitation behavior such as acquiring Application Access Token.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1199 - Trusted Relationship [MITRECoA] — This playbook Remediates the Trusted Relationship technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1199: Trusted Relationship
Kill Chain phases:
- Initial Access
MITRE ATT&CK Description:
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship exploits an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Organizations often grant elevated access to second or third-party external providers in order to allow them to manage internal systems as well as cloud-based environments. Some examples of these relationships include IT services contractors, managed security providers, infrastructure contractors (e.g. HVAC, elevators, physical security). The third-party provider's access may be intended to be limited to the infrastructure being maintained, but may exist on the same network as the rest of the enterprise. As such, Valid Accounts used by the other party for access to internal network systems may be compromised and used.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1204 - User Execution [MITRECoA] — This playbook Remediates the User Execution technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1204: User Execution
Kill Chain phases:
- Execution
MITRE ATT&CK Description:
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.
While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1486 - Data Encrypted for Impact [MITRECoA] — This playbook Remediates the Data Encrypted for Impact technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1486: Data Encrypted for Impact
Kill Chain phases:
- Impact
MITRE ATT&CK Description:
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.[1][2][3][4] In the case of ransomware, it is typical that common user files like Office documents, PDFs, images, videos, audio, text, and source code files will be encrypted. In some cases, adversaries may encrypt critical system files, disk partitions, and the MBR.
To maximize impact on the target organization, malware designed for encrypting data may have worm-like features to propagate across a network by leveraging other attack techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1518 - Software Discovery [MITRECoA] — This playbook Remediates the Software Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1518: Software Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to Exploitation for Privilege Escalation.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1543.003 - Windows Service [MITRECoA] — This playbook Remediates the Windows Service technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1543.003: Create or Modify System Process: Windows Service
Kill Chain phases:
- Persistence
- Privilege Escalation
MITRE ATT&CK Description:
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions.[1] Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry. Service configurations can be modified using utilities such as sc.exe and Reg.
Adversaries may install a new service or modify an existing service by using system utilities to interact with services, by directly modifying the Registry, or by using custom tools to interact with the Windows API. Adversaries may configure services to execute at startup in order to persist on a system.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1547 - Boot or Logon Autostart Execution [MITRECoA] — This playbook Remediates the Boot or Logon Autostart Execution technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1547: Boot or Logon Autostart Execution
Kill Chain phases:
- Persistence
- Privilege Escalation
MITRE ATT&CK Description:
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon.[1][2][3][4][5] These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
Since some boot or logon autostart programs run with higher privileges, an adversary may leverage these to elevate privileges.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1547.001 - Registry Run Keys Startup Folder [MITRECoA] — This playbook Remediates the Registry Run Keys / Startup Folder technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1547.001: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Kill Chain phases:
- Persistence
- Privilege Escalation
MITRE ATT&CK Description:
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. [1] These programs will be executed under the context of the user and will have the account's associated permissions level.
Placing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is C:\Users[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup. The startup folder path for all users is C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1560.001 - Archive via Utility [MITRECoA] — This playbook Remediates the Data Encrypted technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1560.001: Archive Collected Data: Archive via Utility
Kill Chain phases:
- Exfiltration
MITRE ATT&CK Description:
An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities. Many utilities exist that can archive data, including 7-Zip[1], WinRAR[2], and WinZip[3]. Most utilities include functionality to encrypt and/or compress data.
Some 3rd party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1562.001 - Disable or Modify Tools [MITRECoA] — This playbook Remediates the Disable or Modify Tools technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1562.001: Impair Defenses: Disable or Modify Tools
Kill Chain phases:
- Defense Evasion
MITRE ATT&CK Description:
Adversaries may disable security tools to avoid possible detection of their tools and activities. This can take the form of killing security software or event logging processes, deleting Registry keys so that tools do not start at run time, or other methods to interfere with security tools scanning or reporting information.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1564.004 - NTFS File Attributes [MITRECoA] — This playbook Remediates the NTFS File Attributes technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1564.004: NTFS File Attributes
Kill Chain phases:
- Defense Evasion
MITRE ATT&CK Description:
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. [1] Within MFT entries are file attributes, [2] such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).
Adversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1566 - Phishing [MITRECoA] — This playbook Remediates the Phishing technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1566: Phishing
Kill Chain phases:
- Initial Access
MITRE ATT&CK Description:
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems or to gather credentials for use of Valid Accounts. Phishing may also be conducted via third-party services, like social media platforms.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1566.001 - Spear-Phishing Attachment [MITRECoA] — This playbook Remediates the Spear-Phishing Attachment technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1566.001: Spear-Phishing Attachment
Kill Chain phases:
- Initial Access
MITRE ATT&CK Description:
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1569.002 - Service Execution [MITRECoA] — This playbook Remediates the Service Execution technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1569.002: System Services: Service Execution
Kill Chain phases:
- Execution
MITRE ATT&CK Description:
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services.[1] The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net.
PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API.[2]
Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK CoA - T1573.002 - Asymmetric Cryptography [MITRECoA] — This playbook Remediates the Standard Cryptographic Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- 1573.002: Encrypted Channel: Asymmetric Cryptography
Kill Chain phases:
- Command And Control
MITRE ATT&CK Description:
Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private. Due to how the keys are generated, the sender encrypts data with the receiver’s public key and the receiver decrypts the data with their private key. This ensures that only the intended recipient can read the encrypted data. Common public key encryption algorithms include RSA and ElGamal.
For efficiency, may protocols (including SSL/TLS) use symmetric cryptography once a connection is established, but use asymmetric cryptography to establish or transmit a key. As such, these protocols are classified as Asymmetric Cryptography.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Malcore alert related file [Gatewatcher-AionIQ] — This playbook fetch a malcore alert from a GCenter, retrieve the associated suspicious file and checks the SHA256 reputation using VirusTotal integration.
Malware Investigation & Response Incident Handler [MalwareInvestigationAndResponse] — This playbook is triggered by a malware incident from an endpoint integration. It performs enrichment, detonation, and hunting within the organization, and remediation on the malware.
The playbook also covers the SIEM ingestion flow in which the fetching integration is the SIEM and EDR integrations grab all additional data.
Currently supported EDR integrations are XDR, CrowdStrike Falcon, and Microsoft Defender for Endpoint.
Currently supported SIEM integrations are QRadar and Splunk.
Malware Investigation - Generic [DeprecatedContent] — Deprecated. Use "Endpoint Malware Investigation - Generic" playbook instead. Investigate a malware using one or more integrations
Malware Investigation - Generic - Setup [DeprecatedContent] — Deprecated. Verify file sample and hostname information for the "Malware Investigation - Generic" playbook.
If the file sample or hostname are missing, the playbook will attempt to retrieve them using one or more integrations
Malware Investigation - Manual [Malware] — Deprecated. Use 'Malware Investigation & Response Incident handler' instead. (From the 'Malware Investigation And Response Pack')
Master playbook for investigating suspected malware presence on an endpoint.
Labels:
- System: the hostname for the endpoint being investigated
Malware Playbook - Manual [DeprecatedContent] — Deprecated. Use "Malware Investigation - Manual" playbook instead. Master playbook for investigating suspected malware presence on an endpoint.
Labels:
- System: the hostname for the endpoint being investigated
Malware SIEM Ingestion - Get Incident Data [MalwareInvestigationAndResponse] — This playbook handles incident ingestion from the SIEM.
The user provides which EDR system to use, the field containing the incident ID or detection ID, and the field indicating whether the ingested item is an incident or detection.
McAfee ePO Endpoint Compliance Playbook [DeprecatedContent] — Deprecated. Use "McAfee ePO Endpoint Compliance Playbook v2" playbook instead. Discover endpoints that are not using the latest McAfee AV Signatures
McAfee ePO Endpoint Connectivity Diagnostics Playbook [DeprecatedContent] — Deprecated. Use "McAfee ePO Endpoint Connectivity Diagnostics Playbook V2" playbook instead. Perform a check on ePO endpoints to see if any endpoints are unmanaged or lost connectivity with ePO and take steps to return to valid state.
McAfee ePO Repository Compliance Playbook [DeprecatedContent] — Deprecated. Use "McAfee ePO Repository Compliance Playbook v2" playbook instead. Ensures that ePO servers are updated to the latest McAfee published AV signatures (DAT file version).
Message Quarantine - Cofense Vision [CofenseVision] — This playbook allows users to quarantine various messages that meet their specified criteria.
Microsoft 365 Defender - Emails Indicators Hunt [Microsoft365Defender] — This playbook retrieves email data based on the "URLDomain", "SHA256" and "IPAddress" inputs.
SHA256 - Emails with attachments matching the "SHA256" input are retrieved.
URLDomain - If the "URLDomain" value is found as a substring of URL(s) in the body of the email, the email is retrieved.
IPAddress - Emails with "SenderIPv4"/SenderIPv6" or URLs (in the body) matching the "IPAddress" input are retrieved.
Microsoft 365 Defender - Get Email URL Clicks [Microsoft365Defender] — This playbook retrieves email data based on the `URLDomain` and `MessageID` inputs. It uses the Microsoft 365 Defender's Advanced Hunting to search only for URL click events based on the playbook inputs and enriches it with the full email data.
**URLDomain** - If the “URLDomain” value is found as a substring of the URL(s) in the body of the email, the email is retrieved.
**MessageID** - The message ID of the email from which the URL was clicked. Note that this can be either of the following 2 values:
- The value of the header "Message-ID".
- The internal ID of the message within Microsoft's products (e.g., NetworkMessageId).
Can be a single MessageID or an array of MessageIDs to search.
Microsoft 365 Defender - Threat Hunting Generic [Microsoft365Defender] — This playbook retrieves email data based on the `URLDomain`, `SHA256`, `IPAddress`. and `MessageID` inputs. The output is a unified object with all of the retrieved emails based on the following sub-playbooks outputs:
- **Microsoft 365 Defender - Get Email URL clicks**:
Retrieves data based on URL click events.
- **Microsoft 365 Defender - Emails Indicators Hunt**:
Retrieves data based on several different email events.
Read the playbook's descriptions in order to get the full details.
Microsoft Defender For Endpoint - Isolate Endpoint [MicrosoftDefenderAdvancedThreatProtection] — This playbook accepts an endpoint ID, IP, or host name and isolates it using the Microsoft Defender For Endpoint integration.
Microsoft Defender For Endpoint - Unisolate Endpoint [MicrosoftDefenderAdvancedThreatProtection] — This playbook accepts an endpoint ID, IP, or host name and unisolates it using the Microsoft Defender For Endpoint integration.
Microsoft Defender for Endpoint - Malware Detected [MicrosoftDefenderAdvancedThreatProtection] — This playbook investigates “Malware detected by Microsoft Defender for Endpoint” by gathering Hash and User information and performing remediation based on the information gathered and received from the enrichment.
Used Sub-playbooks:
* Enrichment for Verdict
To link this playbook to the relevant alerts automatically, we recommend using the following filters when configuring the playbook triggers: Alert Source = Correlation AND Alert Name = Malware detected by Microsoft Defender for Endpoint
Mirror Jira Ticket [Jira] — Mirror Jira Ticket is designed to serve as a sub-playbook, which enables ticket mirroring with Jira.
Mirror ServiceNow Ticket [ServiceNow] — Mirror ServiceNow Ticket is designed to serve as a sub-playbook, which enables ticket mirroring with ServiceNow.
It enables you to manage ServiceNow tickets in Cortex xSOAR while data is continuously synced between ServiceNow and Cortex xSOAR, including ServiceNow schema, fields, comments, work notes, and attachments.
To enable OOTB mirroring, use the ServiceNow Create ticket - common mappers for incoming and outgoing mirroring.
FieldPolling - You can the FieldPolling value to true if you only want to be informed when the ticket is resolved or closed. If FieldPolling is set to true, the FieldPolling Playbook will poll for the state(ServiceNow State field) of the ServiceNow ticket until it marks as either resolved or closed.
In Addition to the playbook, we recommend that you use the included layout for ServiceNow Ticket, which helps visualize ServiceNow ticket information in Cortex xSOAR.
You can add the new layout as a tab to existing layouts using the Edit Layout page.
NCSC CAF Assessment [NCSCCyberAsssessmentFramework] — This playbook executes automatically as part of the NCSC Assessment Incident Type. It will send the relevant questions (via e-mail) to each participant and generate the assessment results.
NGFW Internal Scan [Core] — This playbook investigates a scan where the source is an internal IP address.
An attacker might initiate an internal scan for discovery, lateral movement and more.
**Attacker's Goals:**
An attacker can leverage a scan for open ports and vulnerable systems on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services.
**Investigative Actions:**
* Endpoint Investigation Plan playbook
**Response Actions**
The playbook's response actions are based on the Endpoint Investigation Plan playbook results. In that phase, the playbook will execute:
* Auto endpoint isolation
* Manual block indicators
* Manual file quarantine
NGFW Scan [Core] — This playbook handles external and internal scanning alerts.
**Attacker's Goals:**
Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation. Methods to acquire this information include port scans and vulnerability scans using tools that are brought onto a system.
**Investigative Actions:**
Investigate the scanner IP address using:
* IP enrichment:
* NGFW Internal Scan playbook
* Endpoint Investigation Plan playbook
* Entity enrichment
**Response Actions**
The playbook's response actions are based on the initial data provided within the alert. In that phase, the playbook will execute:
* Automatically block IP address
* Report IP address (If configured as true in the playbook inputs)
When the playbook executes, it checks for additional activity using the Endpoint Investigation Plan playbook, and another phase, which includes the Containment Plan playbook, is executed.
This phase will execute the following containment actions:
* Automatically isolate involved endpoint
* Manual block indicators
* Manual file quarantine
* Manual disable user
**External resources:**
[Mitre technique T1046 - Network Service Scanning](https://attack.mitre.org/techniques/T1046/)
[Port Scan](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Port-Scan)
NIST - Handling an Incident Template [NIST] — This playbook contains the phases to handling an incident as described in the 'Handling an Incident' section of NIST - Computer Security Incident Handling Guide.
Handling an incident - Computer Security Incident Handling Guide
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
NIST - Lessons Learned [NIST] — This playbook assists in processing an incident after it occurs and facilitates the lessons learned stage.
NMAP - Banner Check [Nmap] — Sub-playbook that performs an Nmap scan and compares the results against a regular expression to determine a match. This could be used to look for OpenSSH versions or other OS information found in the banner.
NMAP - Single Port Scan [Nmap] — Sub-playbook that conducts a single port Nmap scan and returns the results to the parent playbook.
NOBELIUM - wide scale APT29 spear-phishing [MajorBreachesInvestigationandResponse] — On May 27, 2021, Microsoft reported a wide scale spear phishing campaign attributed to APT29, the same threat actor responsible for the SolarWinds campaign named SolarStorm. This attack had a wide range of targets for an APT spear phishing campaign with 3,000 email accounts targeted within 150 organizations.
https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/
This playbook includes the following tasks:
- Collect IOCs to be used in your threat hunting process
- Query FW, SIEMs, EDR, XDR to detect malicious hashes, network activity and compromised hosts
- Block known indicators
** Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
NSA - 5 Security Vulnerabilities Under Active Nation-State Attack [ExpanseV2] — Deprecated. No available replacement. Russian Foreign Intelligence Service (SVR) actors (also known as APT29, Cozy Bear, and The Dukes) frequently use publicly known vulnerabilities to conduct widespread scanning and exploitation.
This playbook should be trigger manually and includes the following tasks:
- Enrich related known CVEs reported in the US agencies alert.
- Search for unpatched endpoints vulnerable to the exploits.
- Search for vulnerable assets facing the internet using Expanse.
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
More information:
[Cyber Security Advisory] (https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF)
NetOps - Firewall Version and Content Upgrade [PAN-OS] — Network operations playbook that updates the version and content of the firewall. You must have Superuser permissions to update the PAN-OS version.
NetOps - Upgrade PAN-OS Firewall Device [PAN-OS] — Network operations playbook that upgrades the firewall. You must have Superuser permissions to update the PAN-OS version. Note: This playbook should only be used for minor version upgrades. Major version upgrades will not work due to a change in the API key.
New Hire Auto-Add [Code42] — Queries stand-up tickets from a ticketing system and passes relevant employee data to the Add Employees to New Hire Watchlist playbook.
New Hire Clean-Up [Code42] — Queries the New Hire watchlist in Code42 Incydr and passes relevant employee data to the Remove Employees from New Hire Watchlist playbook.
New York - Breach Notification [BreachNotification-US] — This playbook helps an analyst determine if the breached data meets the criteria for breach notification according to New York State law, and, if necessary, follows through with the notification procedures.
DISCLAIMER: Please consult with your legal team before implementing this playbook.
**Sources:**
https://ag.ny.gov/internet/data-breach
https://www.dos.ny.gov/consumerprotection/pdf/infosecbreach03.pdf
https://www.nysenate.gov/legislation/laws/GBS/899-AA
Nexpose - Create and Download Report [Rapid7_Nexpose] — Use this playbook as a sub-playbook to configure a report and download it.
This playbook implements polling by continuously running the `nexpose-get-report-status` command until the operation completes.
The remote action should have the following structure:
1. Initiate the operation - insert the type of the report (sites, scan, or assets) and it's additional arguments if required.
2. Poll to check if the operation completed.
3. Get the results of the operation.
O365 - Security And Compliance - Search [MicrosoftExchangeOnline] — Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead.
This playbook performs the following steps:
1. Creates a compliance search.
2. Starts a compliance search.
3. Waits for the compliance search to complete.
4. Gets the results of the compliance search as an output.
5. Gets the preview results, if specified.
O365 - Security And Compliance - Search Action - Delete [MicrosoftExchangeOnline] — Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead.
This playbook performs the following steps:
1. Creates a new compliance search action Purge - Hard or Soft.
2. Waits for the compliance search action to complete.
3. Retrieves the delete search action.
O365 - Security And Compliance - Search Action - Preview [MicrosoftExchangeOnline] — Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead.
This playbook perform:
1. Creates a new compliance search action - Preview (Base on created compliance search).
2. Waits for the preview action to complete.
3. Retrieves the preview results.
O365 - Security And Compliance - Search And Delete [MicrosoftExchangeOnline] — Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead.
This playbook performs the following steps:
1. Creates a compliance search.
2. Starts a compliance search.
3. Waits for the compliance search to complete.
4. Gets the results of the compliance search.
5. Gets the preview results, if specified.
6. Deletes the search results (Hard/Soft).
Office 365 Search and Delete [MicrosoftExchangeOnline] — Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead. This playbook runs a ComplianceSearch on Office 365 and delete the results.
Office 365 and Azure Hunting [Office365AndAzureAuditLog] — This playbook enables you to collect and investigate suspicious security events from Azure AD environment.
Okta - User Investigation [Okta] — This playbook performs an investigation on a specific user, using queries and logs from Okta.
PAN-OS - Add Domains EDL To Anti-Spyware [PAN-OS] — This playbook add domains EDL to Panorama Anti-Spyware. It assigns External Dynamic List URLs that contain domains to block to Panorama Anti-Spyware. You can create an External Dynamic List (EDL) and add domains to it using the Cortex XSOAR pack called "Generic Export Indicators Service".
We recommend using this playbook as a one-time job. Once EDL is created and assigned to anti-spyware, domains can be blocked by adding them to the EDL.
PAN-OS - Add Static Routes [PAN-OS] — This playbook accepts a PAN-OS static route configuration and creates it in the PAN-OS instance.
PAN-OS - Apply Security Profile to Policy Rule [MITRECoA] — This playbook is used to apply a PAN-OS security profile to a policy rule.
The playbook performs the following tasks:
- Accepts a rule name to apply the security profile to.
- Applies the security profile to the rule if the rule exists. If not, creates the rule and applies.
- Commits the configuration.
PAN-OS - Block Destination Service [PAN-OS] — This playbook blocks a destination IP and service (TCP or UDP port) by creating a rule for a specific device group on PAN-OS.
PAN-OS - Block IP [PAN-OS] — This playbook blocks IP addresses with 2 optional actions:
- Block IP addresses using Static Address Groups in Palo Alto Networks Panorama or Firewall. The playbook receives malicious IP addresses and an address group name as inputs, verifies that the addresses are not already a part of the address group, adds them and commits the configuration.
- Utilize the Dynamic Address Group (DAG) capability of PAN-OS. DAG enables analysts to create a rule one time, where the group is the source/destination, and adds IP addresses dynamically without the need to commit the configuration every time.
The playbook checks if the given tag already exists. If the tag exists, then the IP address is added to the tag.
If the tag does not exist, a new address group is created with the given tag and a matching rule, and the configuration is committed.
PAN-OS - Block IP - Custom Block Rule [PAN-OS] — This playbook blocks IP addresses using Custom Block Rules in Palo Alto Networks Panorama or Firewall.
The playbook receives malicious IP addresses as inputs, creates a custom bi-directional rule to block them, and commits the configuration.
PAN-OS - Block IP - Static Address Group [PAN-OS] — This playbook blocks IP addresses using Static Address Groups in Palo Alto Networks Panorama or Firewall.
The playbook receives malicious IP addresses and an address group name as inputs, verifies that the addresses are not already a part of the address group, adds them and commits the configuration.
***Note - The playbook does not block the address group communication using a policy block rule. This step will be taken once outside of the playbook.
PAN-OS - Block IP and URL - External Dynamic List [DeprecatedContent] — Deprecated. Use "PAN-OS - Block IP and URL - External Dynamic List v2" playbook instead. This playbook blocks IP addresses and URLs using Palo Alto Networks Panorama or Firewall External Dynamic Lists.
It checks if the EDL configuration is in place with the 'PAN-OS EDL Setup' sub-playbook (otherwise the list will be configured), and adds the input IPs and URLs to the relevant lists.
PAN-OS - Block IPs From EDL - Custom Block Rule [PAN-OS] — This playbook blocks IP addresses from External Dynamic List using Custom Block Rules in Palo Alto Networks Panorama or Firewall. The playbook receives EDL name as input, creates a custom "from" directional rule to block, and commits the configuration.
PAN-OS - Block URL - Custom URL Category [PAN-OS] — This playbook blocks URLs using Palo Alto Networks Panorama or Firewall through Custom URL Categories.
The playbook checks whether the input URL category already exists, and if the URLs are a part of this category. Otherwise, it will create the category, block the URLs, and commit the configuration.
PAN-OS - Block all unknown and unauthorized applications [MITRECoA] — This playbook is used to find and remove all rules that allow unauthorized applications communication as any.
The playbook performs the following tasks:
- Lists PAN-OS policy rules.
- Checks for a rule that allows applications as any.
- Deletes the rule based on user approval.
- Commits the configuration.
PAN-OS - Enforce Anti-Spyware Best Practices Profile [MITRECoA] — This playbook enforces the Anti-Spyware Best Practices Profile as defined by Palo Alto Networks BPA.
The playbook performs the following tasks:
- Check for DNS Security license (If license is not activated, the playbook refers users to their Palo Alto Networks account manager for further instructions).
- Get the existing profile information.
- Get the best practices profile information.
- Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take).
- Create best practices profile.
- Apply profile to policy rules on PAN-OS firewall or Panorama.
PAN-OS - Enforce Anti-Virus Best Practices Profile [MITRECoA] — This playbook enforces the Anti-Virus Best Practices Profile as defined by Palo Alto Networks BPA.
The playbook performs the following tasks:
- Check for Threat Prevention license (If license is not activated, the playbook refers users to their Palo Alto Networks account manager for further instructions).
- Get the existing profile information.
- Get the best practices profile information.
- Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take).
- Create best practices profile.
- Apply profile to policy rules on PAN-OS firewall or Panorama.
PAN-OS - Enforce File Blocking Best Practices Profile [MITRECoA] — This playbook enforces the File Blocking Best Practices Profile as defined by Palo Alto Networks BPA.
The playbook performs the following tasks:
- Get the existing profile information.
- Get the best practices profile information.
- Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take).
- Create best practices profile.
- Apply profile to policy rules on PAN-OS firewall or Panorama.
PAN-OS - Enforce URL Filtering Best Practices Profile [MITRECoA] — This playbook enforces the URL Filtering Best Practices Profile as defined by Palo Alto Networks BPA.
The playbook performs the following tasks:
- Check for URL Filtering license (If license is not activated, the playbook refers users to their Palo Alto Networks account manager for further instructions).
- Get the existing profile information.
- Get the best practices profile information.
- Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take).
- Create best practices profile.
- Apply profile to policy rules on PAN-OS firewall or Panorama.
PAN-OS - Enforce Vulnerability Protection Best Practices Profile [MITRECoA] — This playbook enforces the Vulnerability Protection Best Practices Profile as defined by Palo Alto Networks BPA.
The playbook performs the following tasks:
- Check for Threat Prevention license (If license is not activated, the playbook refers users to their Palo Alto Networks account manager for further instructions).
- Get the existing profile information.
- Get the best practices profile information.
- Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take).
- Create best practices profile.
- Apply profile to policy rules on PAN-OS firewall or Panorama.
PAN-OS - Enforce WildFire Best Practices Profile [MITRECoA] — This playbook enforces the WildFire Best Practices Profile as defined by Palo Alto Networks BPA.
The playbook performs the following tasks:
- Check for WildFire license (If license is not activated, the playbook refers users to their Palo Alto Networks account manager for further instructions).
- Get the existing profile information.
- Get the best practices profile information.
- Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take).
- Create best practices profile.
- Apply profile to policy rules on PAN-OS firewall or Panorama.
PAN-OS DAG Configuration [PAN-OS] — This playbook utilizes the Dynamic Address Group (DAG) capability of PAN-OS.
DAG enables analysts to create a rule one time, where the group is the source/destination, and adds IP addresses dynamically without the need to commit the configuration every time.
The playbook checks if the given tag already exists. If the tag exists, then the IP address is added to the tag.
If the tag does not exist, a new address group is created with the given tag and a matching rule, and the configuration is committed.
PAN-OS EDL Service Configuration [EDL] — Deprecated. No available replacement. This single-run playbook enables Cortex XSOAR's built-in External Dynamic List (EDL) as a service for system indicators, and configures PAN-OS EDL Objects and the respective firewall policy rules.
The EDLs will continuously update for each indicator that matches the query syntax input in the playbook
(to validate to which indicators the query applied, you need to enter the query syntax from the indicator tab at the top of the playbook inputs window as well).
If both the IP and URL indicator types exist in the query, it sorts the indicators into two EDLs, IP and URL. If only one indicator type exists in the query, only one EDL is created.
The playbook then creates EDL objects directing to the indicator lists and firewall policy rules in PAN-OS.
- It is recommended to configure a dedicated EDL Service instance for the usage of this playbook.
- If necessary to edit or update the EDL query after this playbook run, use the panorama-edit-edl command and panorama integration to update the URL containing the indicator query syntax.
PAN-OS EDL Setup [DeprecatedContent] — Deprecated. Use PAN-OS EDL Setup v3 playbook instead. Configures an external dynamic list in PAN-OS.\nIn the event that the file exists on the web server, it will sync it to demisto. Then it will create an EDL object and a matching rule.
PAN-OS EDL Setup v2 [DeprecatedContent] — Deprecated. Use "PAN-OS EDL Setup v3" playbook instead. Configures an external dynamic list in PAN-OS.
In the event that the file exists on the web server, it will sync it to demisto. Then it will create an EDL object and a matching rule.
PAN-OS EDL Setup v3 [PaloAltoNetworks_PAN_OS_EDL_Management] — Deprecated. Use Generic Export Indicators Service instead.
PAN-OS Log Forwarding Setup And Configuration [PAN-OS] — This playbook sets up and maintains log forwarding for the Panorama rulebase.
It can be run when setting up a new instance, or as a periodic job to enforce log forwarding policy.
You can either update all rules and override previous profiles, or update only rules that do not have a log forwarding profile configured.
PAN-OS Query Logs For Indicators [PAN-OS] — This playbook queries the following PAN-OS log types: traffic, threat, url, data-filtering and wildfire. The playbook accepts inputs such as IP. hash, and url.
PAN-OS create or edit policy [Change_Management] — This playbook will automate the process of creating or editing a policy.
The first task in the playbook checks if there is a security policy that matches the playbook inputs. If there is no security policy that matches, a new policy will be created. If there is a security policy that matches, the user will be able to modify the existing policy or create a new hardened policy.
PAN-OS edit policy [Change_Management] — This playbook guides the user in the process of editing an existing policy. The playbook sends a data collection form to retrieve the relevant parameters for editing the existing rule.
PANW Device Security Incident Handling with ServiceNow [PaloAltoNetworks_DeviceSecurity] — This playbook creates a ServiceNow ticket after the incident is enriched by Palo Alto Networks Device Security portal (previously Zingbox Cloud).
PANW Device Security ServiceNow Tickets Check [PaloAltoNetworks_DeviceSecurity] — This playbook checks the ServiceNow ticket status for Palo Alto Networks Device Security (previously Zingbox) alerts or vulnerabilities and automatically closes the Cortex XSOAR incident when the related ServiceNow ticket is closed. Designed to run as a recurring job.
PANW IoT Incident Handling with ServiceNow [PaloAltoNetworks_IoT] — This playbook creates a ServiceNow ticket after the incident is enriched by Palo Alto Networks IoT security portal (previously Zingbox Cloud).
PANW IoT ServiceNow Tickets Check [PaloAltoNetworks_IoT] — This playbook should be used in a recurring Job to check the ServiceNow ticket status for the Palo Alto Networks IoT (previously Zingbox) alerts or vulnerabilties.
PCAP Analysis [PcapAnalysis] — This playbook leverages all of the PCAP miner and PCAP file extractor sub playbook capabilities, including: * Search for specific values in a PCAP file * Parse and enrich detected indicators such as IP addresses, URLs, email addresses and domains found by the search . * Carve (extract) files found in the http, smb and other protocols and perform enrichment and detonation.
PCAP File Carving [PcapAnalysis] — This playbook is used to carve (extract) files from within PCAP files and perform enrichment and detonation of the extracted files. Supported PCAP file types are pcap, cap, pcapng. The playbook can handle one PCAP file per incident. Additional inputs allow the user to provide the WPA password for decrypting 802.11 (wireless) traffic and adding an RSA certificate to decrypt SSL traffic. Additional options enable you to filter the files to extract according to the file extension or the actual file type (MIME), and limit the amount of files to extract. Another feature enables you to specify a filter to create a new smaller PCAP file. To display the results within the relevant incident fields, the playbook needs to run in a PCAP Analysis incident type. For handling of PCAP files larger than 30 MB, refer to the PcapMinerV2 documentation.
PCAP Parsing And Indicator Enrichment [PcapAnalysis] — This playbook is used to parse and extract indicators within PCAP files and perform enrichment on the detected indicators. Supported file types are pcap, cap, pcapng. The playbook can handle one PCAP file per incident. The user inputs which indicator types are to be enriched including, email, URLs, IP addresses. The user can specify in the inputs which indicators are internal or that will be treated as internal (not enriched). The user can also specify a specific regex pattern to search for. Another option is to specify the protocol types to be printed to context for data extraction. Additional inputs allow the user to provide the WPA password for decrypting 802.11 (wireless) traffic and add an RSA certificate to decrypt SSL traffic. To display the results within the relevant incident fields, the playbook needs to run in a PCAP Analysis incident type. For handling of PCAP files larger than 30 MB, refer to the PcapMinerV2 documentation.
PCAP Search [PcapAnalysis] — This playbook is used to parse and search within PCAP files. Supported file types are pcap, cap, pcapng. The playbook can handle one PCAP file per incident. The user inputs which objects the playbook should search for in the PCAP. The values to search are IP addresses, CIDR ranges, and TCP or UDP ports or protocols. In the event that more than one input type was specified, specify in the QueryOperator input (such as IP addresses and TCP ports) if the PCAP filter query will use an AND or an OR operator between the inputs. Another option is to use advanced filters just like in Wireshark to use refined filters or for objects not specified in other inputs. Additional inputs allow the user to provide the WPA password for decrypting 802.11 (wireless) traffic and adding an RSA certificate to decrypt SSL traffic. To display the results within the relevant incident fields, the playbook needs to run in a PCAP Analysis incident type. For handling of PCAP files larger than 30 MB, refer to the PcapMinerV2 documentation.
PII Check - Breach Notification [BreachNotification-US] — The playbook checks for all various types of PII, however, each state determines what is considered PII, and which PII requires notification.
DISCLAIMER: Please consult with your legal team before implementing this playbook.
**Sources:
http://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82
https://www.nysenate.gov/legislation/laws/GBS/899-AA
and more for each state.
PS Remote Get File Sample From Path [WindowsForensics] — This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire a file as forensic evidence for further analysis.
PS-Remote Acquire Host Forensics [WindowsForensics] — This playbook allows the user to gather multiple forensic data from a Windows endpoint including network traffic, MFT (Master File Table), and registry export by using the PS Remote automation which enables connecting to a Windows host without the need to install any 3rd-party tools using just native Windows management tools.
PS-Remote Get MFT [WindowsForensics] — This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the MFT (Master File Table) as forensic evidence for further analysis.
PS-Remote Get Network Traffic [WindowsForensics] — This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host. It then connectst to the Netsh tool to create an ETL file which is the equivalent of a Wireshark PCAP file by using the PS-Remote integration. After receiving the resultant ETL, XSOAR will be able to convert the ETL to a PCAP file to be parsed and enriched later. Review the Microsoft documentation for how to use ETL filters (https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj129382(v=ws.11)#using-filters-to-limit-etl-trace-file-details).
PS-Remote Get Registry [WindowsForensics] — This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the registry as forensic evidence for further analysis. The capture can be for the entire registry or for a specific hive or path.
Panorama Query Logs [PAN-OS] — Query Panorama Logs of types: traffic, threat, url, data-filtering and wildfire.
PanoramaCommitConfiguration [DeprecatedContent] — Deprecated. - Use PAN-OS Commit Configuration instead.\nIf specified as Panorama, will also push the Policies to the specified Device Group in the instance. (please use pan-os-commit-configuration instead)
PanoramaQueryTrafficLogs [DeprecatedContent] — Deprecated. Use "PAN-OS Query Logs For Indicators" playbook instead. Queries traffic logs in a PAN-OS Panorama or Firewall device.
Pentera Filter And Create Incident [Pcysys] — Sub-playbook to select specific entries from the Pentera action report and create incidents for each of the selected entries
Pentera Run Scan and Create Incidents [Pcysys] — This playbook will run a pentera task given the Pentera task name. It will generate the full action report that contains all the actions that Pentera made during the scan, and will create incidents according to the filters in the Pentera Filter and Create incidents playbook.
PhishLabs - Populate Indicators [PhishLabs] — This playbook can be used in a job to populate indicators from PhishLabs, according to a defined period of time.
PhishLabs - Whitelist false positives [PhishLabs] — This playbook can be used in a job to add to the allow list indicators from PhishLabs that were classified as false positives, according to a defined period of time.
Phishing - Create New Incident [Phishing] — This playbook take arguments which will be used to create a new phishing incident. It is needed for scenarios such as creating several incidents based on values stored in the context. In such scenarios, the playbook can be looped.
Phishing - Get Original Email Loop [Phishing] — When the "Get Original Email - Generic v2" playbook is looped, there is no actual way to distinguish which retrieved file is related to which Message-ID. In order to solve this issue, this playbook will be looped instead and will output the "FileAssociation" key with the File-MessageID association.
Phishing - Handle Microsoft 365 Defender Results [Phishing] — This playbook is used to handle the results from the "Microsoft 365 Defender - Threat Hunting Generic" playbook inside a phishing incident. It performs the following actions:
1) Set the relevant incident fields based on the results, such as "Clicked URLs", "Malicious URL Viewed", and "Malicious URL Clicked".
2) In case the relevant playbook inputs were configured, it will create new incidents for each email returned in the results of the "Microsoft 365 Defender - Threat Hunting Generic" playbook. First, it will try to retrieve the original emails' files and then it will create an incident for each retrieved email.
3) Link the newly created incidents to the main originating incident.
Note that this playbook should only be used inside a phishing incident and not as a main playbook.
Phishing - Indicators Hunting [Phishing] — Hunt indicators related to phishing with available integrations and then handle the results. Handling the results will include setting relevant incident fields which will be displayed in the layout and optionally, opening new incidents according to the findings.
Current integration in this playbook:
- Microsoft 365 Defender (using "Advanced Hunting")
Note that this playbook should be used as a sub-playbook inside a phishing incident and not as a main playbook.
Phishing - Search Related Incidents (Defender 365) [Phishing] — This playbook should only be used as a sub-playbook inside the "Phishing - Handle Microsoft 365 Defender Results" playbook.
It searches through existing Cortex XSOAR incidents based on retrieved email message IDs and returns data only for emails that are not found in existing incidents.
Phishing Alerts - Check Severity [PhishingAlerts] — This playbook calculates and assigns the incident severity based on the highest returned severity level from the following calculations:
- Email security alert action
- DBotScores of indicators
- Critical assets
- Email authenticity
- Current incident severity
- Microsoft Headers
Phishing Alerts Investigation [PhishingAlerts] — This playbook investigates and remediates potential phishing incidents produced by either an email security gateway or a SIEM product. It retrieves original email files from the email security gateway or email service provider and generates a response based on the initial severity, hunting results, and the existence of similar phishing incidents in XSOAR.
No action is taken without an initial approval given by the analyst using the playbook inputs.
Phishing Investigation - Generic [DeprecatedContent] — Deprecated. Use "Phishing Investigation - Generic v2" playbook instead. Use this playbook to investigate and remediate a potential phishing incident. The playbook simultaneously engages with the user that triggered the incident, while investigating the incident itself.
The final remediation tasks are always decided by a human analyst.
Phishing Playbook - Automated [DeprecatedContent] — Deprecated. We recommend using Phishing investigation - Generic playbook instead.
This is an automated playbook to investigate suspected Phishing attempts.
It picks up the required information from the incident metadata as created by the mail listener.
Labels:
- Email/from: Email address of the user targeted by the suspected phishing attempt, who reported the email by forwarding it
- Email: the to recipients
- Email/cc: the cc recipients
- Email/format: the format of the email - text / html / etc.
- Email/html: the html body
- Email/text: the text body
- Email/subject: subject of the email
- Email/attachments: list of attachments
- Email/headers: the headers for the email
Phishing Playbook - Manual [Phishing] — Master playbook for phishing incidents. This playbook is a manual playbook.
Phishing Triage and Response - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook extracts email addresses from phishing alerts, enriches their associated domains using the GTI domain enrichment command, and evaluates the GTI Threat Score, severity, and verdict. Based on these enrichment results, the playbook automatically blocks the malicious or high-risk email addresses to prevent further compromise.
PhishingDemo-Onboarding [OnboardingIntegration] — This playbook is part of the on-boarding experience, and focuses on phishing scenarios. To use this playbook, you'll need to enable the `on-boarding` integration and configure incidents of type `Phishing`. For more information, refer to the on-boarding walkthroughs in the help section.
Policy Optimizer - Add Applications to Policy Rules [PANOSPolicyOptimizer] — This playbook edits rules with unused applications or rules that are port based, and adds an application to the rule. It is used in PAN-OS - Policy Optimizer playbooks and includes communication tasks to get a rule name and the application to edit from the user.
Policy Optimizer - Generic [PANOSPolicyOptimizer] — This playbook is triggered by the Policy Optimizer incident type, and can execute any of the following sub-playbooks:
- Policy Optimizer - Manage Unused Rules
- Policy Optimizer - Manage Rules with Unused Applications
- Policy Optimizer - Manage Port Based Rules
Policy Optimizer - Manage Port Based Rules [PANOSPolicyOptimizer] — This playbook migrates port-based rules to application-based allow rules to reduce the attack surface and safely enable applications on your network.
Policy Optimizer - Manage Rules with Unused Applications [PANOSPolicyOptimizer] — This playbook helps identify and remove unused applications from security policy rules. If you have application-based security policy rules that allow a large number of applications, you can remove unused applications (applications never seen on the rules) from those rules to allow only applications actually seen in the rule’s traffic. This strengthens your security posture by reducing the attack surface.
Policy Optimizer - Manage Unused Rules [PANOSPolicyOptimizer] — This playbook helps identify and remove unused rules that do not pass traffic in your environment.
Possible External RDP Brute-Force [Core] — This playbook investigates a “Possible External RDP Brute Force” XDR Alert by gathering user, IP, and hostname information, and investigating if the following suspicious elements exists:
- "IP Reputation" - DBot Score is 2-3
- "Source geolocation" - RDP Connection made from rare geo-location
- Related to campaign - IP address is related to campaign, based on TIM module
- Hunting results - the hunt for indicators related to the source IP and the related campaign returned results
- XDR Alert search - XDR Alerts that related to the same username and endpoint, and to the MITRE tactics that comes after "Credential Access", were found.
- Risky User - The user that was identified in the attack was given a medium or high score by the Core integration's ITDR module.
- Risky Host - The destination host that was identified in the attack was given a medium or high score by the Core integration's ITDR module.
Set verdict method:
* Critical Element - The "Critical Element" input allows you to select a specific element that, if identified as suspicious, the investigation's final verdict will be deemed a "True Positive".
* Final Verdict - Each suspicious element is being added to an array called "Suspicious Elements", which is used to count potential security threats. The array size will be compared to a final threshold. If the size is greater than or equal to the threshold, the investigation's final verdict will be deemed a "True Positive".
* User Engagement - The "UserEngagementThreshold" input allows you to set the number of suspicious elements that trigger user engagement. When this threshold is met, an email will be sent to the user and their manager asking for authorization of RDP activity. If the RDP activity is not authorized by the user, the investigation's final verdict will be deemed a "True Positive".
Possible External RDP Brute-Force - Set Verdict [Core] — This playbook creating an array called "Suspicious Elements", which is used to count potential security threats. The following elements can be added to the array:
- "IP Reputation" - DBot Score is 2-3
- "Source geolocation" - RDP Connection made from rare geo-location
- Related to campaign - IP address is related to campaign, based on TIM module
- Hunting results - the hunt for indicators related to the source IP and the related campaign returned results
- XDR Alert search - XDR Alerts that related to the same username and endpoint, and to the MITRE tactics that comes after "Credential Access", were found.
- Risky User - one or more risky users are involved in the incident, as identified by the Cortex Core - IR integration's ITDR module.
- Risky Host - one or more risky hosts are involved in the incident, as identified by the Cortex Core - IR integration's ITDR module.
The array will then be outputted and its size will be compared to a final threshold. If the size is greater than or equal to the threshold, the investigation's final verdict will be deemed a "True Positive."
Post Intrusion Ransomware Investigation [Ransomware] — Provides the first step in the investigation of ransomware attacks.
The playbook requires the ransom note and an example of an encrypted file (<1MB) to try to identify the ransomware and find a recovery tool via the online database.
You will be guided with further investigation steps throughout the playbook, some of the key features are:
- Encrypted file owner investigation
- Endpoint forensic investigation
- Active Directory investigation
- Timeline of the breach investigation
- Indicator and account enrichment
Playbook settings and mapping:
For the full operation of the playbook, the following data should be mapped to the relevant incident fields.
Username - Usernames (common incident field)
Hostname - Hostnames (common incident field)
Prepare your CTF [ctf01] — This playbook aims to assit in configuring you env for the Capture The Flag (CTF) game.
Prisma Access - Logout User [PrismaAccess] — This playbook forces logout of a specific user and computer from Prisma Access.
Prisma Access - Connection Health Check [PrismaAccess] — Use the Prisma Access integration to run SSH CLI commands and query the connection states for all tunnels. If any tunnels are down - the playbook escalates to a manual task for remediation and provides recommendations on next steps in the task description. The playbook can be run as a job, or triggered from an incoming event to confirm an initial suspicion (such as a tunnel log from Cortex Data Lake) to validate that the issue still exists.
Prisma Cloud - Find AWS Resource by FQDN [PrismaCloud] — Deprecated. Use Prisma Cloud - Find AWS Resource by FQDN v2 instead.
Find AWS resources by FQDN using Prisma Cloud inventory.
Supported services: EC2, Application Load Balancer, ECS, Route53, CloudFront, S3, API Gateway.
Prisma Cloud - Find AWS Resource by FQDN v2 [PrismaCloud] — Find AWS resources by FQDN using Prisma Cloud inventory.
Supported services: EC2, Application Load Balancer, ECS, Route53, CloudFront, S3, API Gateway.
Prisma Cloud - Find AWS Resource by Public IP [PrismaCloud] — Deprecated. Use Prisma Cloud - Find AWS Resource by Public IP v2 instead.
Find AWS resources by Public IP using Prisma Cloud inventory.
Supported services: EC2, Network Load Balancer, ECS, Route53.
Prisma Cloud - Find Azure Resource by FQDN [PrismaCloud] — Deprecated. Use Prisma Cloud - Find Azure Resource by FQDN v2 instead.
Find Azure resources by FQDN using Prisma Cloud inventory.
Supported services: Azure VM, Azure Load Balancer, Azure Application Gateway, AKS, Azure Web Apps, Azure Storage.
Prisma Cloud - Find Azure Resource by FQDN v2 [PrismaCloud] — Find Azure resources by FQDN using Prisma Cloud inventory.
Supported services: Azure VM, Azure Load Balancer, Azure Application Gateway, AKS, Azure Web Apps, Azure Storage.
Prisma Cloud - Find Azure Resource by Public IP [PrismaCloud] — Deprecated. Use Prisma Cloud - Find Azure Resource by Public IP v2 instead.
Find Azure resources by Public IP using Prisma Cloud inventory.
Supported services: Azure VM, Azure Load Balancer, Azure Application Gateway, Azure Web Apps.
Prisma Cloud - Find Azure Resource by Public IP v2 [PrismaCloud] — Find Azure resources by Public IP using Prisma Cloud inventory.
Supported services: Azure VM, Azure Load Balancer, Azure Application Gateway, Azure Web Apps.
Prisma Cloud - Find GCP Resource by FQDN [PrismaCloud] — Deprecated. Use Prisma Cloud - Find GCP Resource by FQDN v2 instead.
Find GCP resources by FQDN using Prisma Cloud inventory.
Supported services: Cloud DNS.
Prisma Cloud - Find GCP Resource by Public IP [PrismaCloud] — Deprecated. Use Prisma Cloud - Find GCP Resource by Public IP v2 instead.
Find GCP resources by Public IP using Prisma Cloud inventory.
Supported services: GCE, Load Balancing, GKE.
Prisma Cloud - Network API and Anomaly Incidents [PrismaCloud] — This playbook handles incidents of internet exposed services and detect potential risky configurations that can make your cloud environment vulnerable to attacks, and
incidents of unusual network and user activity for all users, and are especially critical for privileged users and assumed roles where detecting unusual activity may indicate the first steps in a potential misuse or account compromise.
Prisma Cloud - VM Alert Prioritization [PrismaCloud] — This playbook handles incidents related to dozens of Prisma Cloud public VM alerts.
It determines the severity of the ingested alert based on data returned from Cortex XSOAR commands interacting with the Prisma Cloud API and creates new issues in either Slack or Jira, with all of the relevant information.
The playbook updates the Cortex XSOAR incident’s layout with information the analyst can use to investigate the alert. It also extracts and enriches indicators using existing configured integrations and then closes the investigation.
The flow of this playbook is as following:
1) Check the CSP type.
2) Check whether there's a public IP associated to the instance. In case there is, it will continue to other steps, if not, it will set the severity of the incident to "Low" and will close the incident.
3) Check if there are any vulnerabilities or findings related to the instance.
4) Check if there are any IAM permissions associated to the instance.
5) Set the incident severity based on the results:
- Low - No public IP was found.
- Medium - Public IP was found, other checks didn't return results.
- High - Public IP was found and also one of the other checks returned results.
- Critical - Public IP was found and both of the other checks returned results.
6) Notifications and ticketing with 3rd party systems.
7) Close the incident.
This playbook will run when a new incident is created with the **Prisma Cloud - VM Alert Prioritization** incident type which also includes a dedicated layout.
Prisma Cloud Correlate Alerts [PrismaCloud] — Deprecated. Use Prisma Cloud Correlate Alerts v2 instead. Search alerts in Prisma Cloud for a specific asset ID and, if present in XSOAR, link them.
Prisma Cloud Correlate Alerts v2 [PrismaCloud] — Search alerts in Prisma Cloud for a specific asset ID and, if present in Cortex XSOAR, link them.
Prisma Cloud Remediation - AWS CloudTrail Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - AWS CloudTrail Misconfiguration v2 instead.
This playbook remediates Prisma Cloud AWS CloudTrail alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- AWS CloudTrail Trail Log Validation Is Not Enabled In All Regions
- AWS CloudTrail is not enabled in all regions
- AWS CloudTrail Trail Is Not Integrated With CloudWatch Logs
- AWS CloudTrail is not enabled on the account
Prisma Cloud Remediation - AWS CloudTrail Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud AWS CloudTrail alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- AWS CloudTrail Trail Log Validation Is Not Enabled In All Regions
- AWS CloudTrail is not enabled in all regions
- AWS CloudTrail Trail Is Not Integrated With CloudWatch Logs
- AWS CloudTrail is not enabled on the account.
Prisma Cloud Remediation - AWS CloudTrail Trail Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud AWS CloudTrail alerts.
Prisma Cloud policies remediated:
- AWS CloudTrail Trail Log Validation Is Not Enabled In All Regions
- AWS CloudTrail is not enabled in all regions.
Prisma Cloud Remediation - AWS CloudTrail is not Enabled on the Account [PrismaCloud] — AWS Cloudtrail is a service which provides event history of your AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. To remediate Prisma Cloud Alert "CloudTrail is not enabled on the account", this playbook creates an S3 bucket to host Cloudtrail logs and enable Cloudtrail (includes all region events and global service events).
Prisma Cloud Remediation - AWS EC2 Instance Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - AWS EC2 Instance Misconfiguration v2 instead.
This playbook remediates Prisma Cloud AWS EC2 alerts. It calls the following sub-playbooks to perform the remediation:
- AWS Default Security Group Does Not Restrict All Traffic
- AWS Security Groups Allow Internet Traffic
- AWS Security Groups With Inbound Rule Overly Permissive To All Traffic
- AWS Security Groups allow internet traffic from internet to FTP-Data port (20)
- AWS Security Groups allow internet traffic from internet to FTP port (21)
- AWS Security Groups allow internet traffic to SSH port (22)
- AWS Security Group allows all traffic on SSH port (22)
- AWS Security Groups allow internet traffic from internet to Telnet port (23)
- AWS Security Groups allow internet traffic from internet to SMTP port (25)
- AWS Security Groups allow internet traffic from internet to DNS port (53)
- AWS Security Groups allow internet traffic from internet to Windows RPC port (135)
- AWS Security Groups allow internet traffic from internet to NetBIOS port (137)
- AWS Security Groups allow internet traffic from internet to NetBIOS port (138)
- AWS Security Groups allow internet traffic from internet to CIFS port (445)
- AWS Security Groups allow internet traffic from internet to SQLServer port (1433)
- AWS Security Groups allow internet traffic from internet to SQLServer port (1434)
- AWS Security Groups allow internet traffic from internet to MYSQL port (3306)
- AWS Security Groups allow internet traffic from internet to RDP port (3389)
- AWS Security Groups allow internet traffic from internet to MSQL port (4333)
- AWS Security Groups allow internet traffic from internet to PostgreSQL port (5432)
- AWS Security Groups allow internet traffic from internet to VNC Listener port (5500)
- AWS Security Groups allow internet traffic from internet to VNC Server port (5900)
Prisma Cloud Remediation - AWS EC2 Instance Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud AWS EC2 alerts. It calls the following sub-playbooks to perform the remediation:
- AWS Default Security Group Does Not Restrict All Traffic (policy id: 2378dbf4-b104-4bda-9b05-7417affbba3f)
- AWS Security Group allows all traffic on SSH port (22) (policy id: 617b9138-584b-4e8e-ad15-7fbabafbed1a)
- AWS Security Groups allow internet traffic from internet to RDP port (3389) (policy id: b82f90ce-ed8b-4b49-970c-2268b0a6c2e5).
Prisma Cloud Remediation - AWS EC2 Security Group Misconfiguration [PrismaCloud] — This playbook remediates the Prisma Cloud AWS EC2 alerts generated by the following policies:
- AWS Default Security Group Does Not Restrict All Traffic
- AWS Security Group allows all traffic on SSH port (22).
Prisma Cloud Remediation - AWS IAM Password Policy Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud AWS IAM password policy alerts.
Prisma Cloud policies remediated:
- AWS IAM password policy allows password reuse
- AWS IAM password policy does not expire in 90 days
- AWS IAM password policy does not have a lowercase character
- AWS IAM password policy does not have a minimum of 14 characters
- AWS IAM password policy does not have a number
- AWS IAM password policy does not have a symbol
- AWS IAM password policy does not have a uppercase character
- AWS IAM password policy does not have password expiration period
- AWS IAM Password policy is insecure
Prisma Cloud Remediation - AWS IAM Policy Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - AWS IAM Policy Misconfiguration v2 instead. This playbook remediates Prisma Cloud AWS IAM policy alerts. It uses sub-playbooks that perform the remediation steps.
Prisma Cloud Remediation - AWS Inactive Users For More Than 30 Days [PrismaCloud] — To increase the security of your AWS account, it is recommended to find and remove IAM user credentials (passwords, access keys) that have not been used within a specified period of time.
To remediate Prisma Cloud Alert Inactive users for more than 30 days, this playbook deactivates the user by disabling the access keys (marking them as inactive) as well as resetting the user console password.
Prisma Cloud Remediation - Azure AKS Cluster Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud Azure AKS cluster alerts.
Prisma Cloud policies remediated:
- Azure AKS cluster monitoring not enabled
- Azure AKS cluster HTTP application routing enabled
Prisma Cloud Remediation - Azure AKS Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - Azure AKS Misconfiguration v2 instead.
This playbook remediates Prisma Cloud Azure AKS alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure AKS cluster monitoring not enabled
- Azure AKS cluster HTTP application routing enabled
Prisma Cloud Remediation - Azure AKS Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud Azure AKS alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure AKS cluster monitoring not enabled
- Azure AKS cluster HTTP application routing enabled
Prisma Cloud Remediation - Azure Network Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - Azure Network Misconfiguration v2 instead.
This playbook remediates Prisma Cloud Azure Network alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on any protocol
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on TCP protocol
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on UDP protocol
- Azure Network Security Group (NSG) allows SSH traffic from internet on port 22
- Azure Network Security Group (NSG) allows traffic from internet on port 3389
- Azure Network Security Group allows DNS (TCP Port 53)
- Azure Network Security Group allows FTP (TCP Port 21)
- Azure Network Security Group allows FTP-Data (TCP Port 20)
- Azure Network Security Group allows MSQL (TCP Port 4333)
- Azure Network Security Group allows MySQL (TCP Port 3306)
- Azure Network Security Group allows Windows RPC (TCP Port 135)
- Azure Network Security Group allows Windows SMB (TCP Port 445)
- Azure Network Security Group allows PostgreSQL (TCP Port 5432)
- Azure Network Security Group allows SMTP (TCP Port 25)
- Azure Network Security Group allows SqlServer (TCP Port 1433)
- Azure Network Security Group allows Telnet (TCP Port 23)
- Azure Network Security Group allows VNC Listener (TCP Port 5500)
- Azure Network Security Group allows all traffic on ICMP (Ping)
- Azure Network Security Group allows CIFS (UDP Port 445)
- Azure Network Security Group allows NetBIOS (UDP Port 137)
- Azure Network Security Group allows NetBIOS (UDP Port 138)
- Azure Network Security Group allows SQLServer (UDP Port 1434)
- Azure Network Security Group allows DNS (UDP Port 53)
Prisma Cloud Remediation - Azure Network Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud Azure Network alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on any protocol
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on TCP protocol
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on UDP protocol
- Azure Network Security Group (NSG) allows SSH traffic from internet on port 22
- Azure Network Security Group (NSG) allows traffic from internet on port 3389
- Azure Network Security Group allows DNS (TCP Port 53)
- Azure Network Security Group allows FTP (TCP Port 21)
- Azure Network Security Group allows FTP-Data (TCP Port 20)
- Azure Network Security Group allows MSQL (TCP Port 4333)
- Azure Network Security Group allows MySQL (TCP Port 3306)
- Azure Network Security Group allows Windows RPC (TCP Port 135)
- Azure Network Security Group allows Windows SMB (TCP Port 445)
- Azure Network Security Group allows PostgreSQL (TCP Port 5432)
- Azure Network Security Group allows SMTP (TCP Port 25)
- Azure Network Security Group allows SqlServer (TCP Port 1433)
- Azure Network Security Group allows Telnet (TCP Port 23)
- Azure Network Security Group allows VNC Listener (TCP Port 5500)
- Azure Network Security Group allows all traffic on ICMP (Ping)
- Azure Network Security Group allows CIFS (UDP Port 445)
- Azure Network Security Group allows NetBIOS (UDP Port 137)
- Azure Network Security Group allows NetBIOS (UDP Port 138)
- Azure Network Security Group allows SQLServer (UDP Port 1434)
- Azure Network Security Group allows DNS (UDP Port 53).
Prisma Cloud Remediation - Azure Network Security Group Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud Azure Network security group alerts.
Prisma Cloud policies remediated:
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on any protocol
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on TCP protocol
- Azure Network Security Group (NSG) having Inbound rule overly permissive to allow all traffic from any source on UDP protocol
- Azure Network Security Group (NSG) allows SSH traffic from internet on port 22
- Azure Network Security Group (NSG) allows traffic from internet on port 3389
- Azure Network Security Group allows DNS (TCP Port 53)
- Azure Network Security Group allows FTP (TCP Port 21)
- Azure Network Security Group allows FTP-Data (TCP Port 20)
- Azure Network Security Group allows MSQL (TCP Port 4333)
- Azure Network Security Group allows MySQL (TCP Port 3306)
- Azure Network Security Group allows Windows RPC (TCP Port 135)
- Azure Network Security Group allows Windows SMB (TCP Port 445)
- Azure Network Security Group allows PostgreSQL (TCP Port 5432)
- Azure Network Security Group allows SMTP (TCP Port 25)
- Azure Network Security Group allows SqlServer (TCP Port 1433)
- Azure Network Security Group allows Telnet (TCP Port 23)
- Azure Network Security Group allows VNC Listener (TCP Port 5500)
- Azure Network Security Group allows all traffic on ICMP (Ping)
- Azure Network Security Group allows CIFS (UDP Port 445)
- Azure Network Security Group allows NetBIOS (UDP Port 137)
- Azure Network Security Group allows NetBIOS (UDP Port 138)
- Azure Network Security Group allows SQLServer (UDP Port 1434)
- Azure Network Security Group allows DNS (UDP Port 53)
Prisma Cloud Remediation - Azure SQL Database Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud Azure SQL database alerts.
Prisma Cloud policies remediated:
- Azure SQL database auditing is disabled
- Azure SQL Database with Auditing Retention less than 90 days
- Azure Threat Detection on SQL databases is set to Off
- Azure SQL Database with Threat Retention less than or equals to 90 days
Prisma Cloud Remediation - Azure SQL Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - Azure SQL Misconfiguration v2 instead.
This playbook remediates Prisma Cloud Azure SQL alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure SQL database auditing is disabled
- Azure SQL Database with Auditing Retention less than 90 days
- Azure Threat Detection on SQL databases is set to Off
- Azure SQL Database with Threat Retention less than or equals to 90 days
Prisma Cloud Remediation - Azure SQL Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud Azure SQL alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure SQL database auditing is disabled
- Azure SQL Database with Auditing Retention less than 90 days
- Azure Threat Detection on SQL databases is set to Off
- Azure SQL Database with Threat Retention less than or equals to 90 days
Prisma Cloud Remediation - Azure Storage Blob Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud Azure Storage blob alerts.
Prisma Cloud policies remediated:
- Azure storage account has a blob container with public access
- Azure storage account logging for blobs is disabled
Prisma Cloud Remediation - Azure Storage Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - Azure Storage Misconfiguration v2 instead.
This playbook remediates Prisma Cloud Azure Storage alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure storage account has a blob container with public access
- Azure storage account logging for blobs is disabled
- Azure Storage Accounts without Secure transfer enabled
- Azure storage account logging for queues is disabled
- Azure storage account logging for tables is disabled #95
Prisma Cloud Remediation - Azure Storage Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud Azure Storage alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- Azure storage account has a blob container with public access
- Azure storage account logging for blobs is disabled
- Azure Storage Accounts without Secure transfer enabled
- Azure storage account logging for queues is disabled
- Azure storage account logging for tables is disabled
Prisma Cloud Remediation - GCP Compute Engine Instance Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud GCP Compute Engine VM Instance alerts.
Prisma Cloud policies remediated:
- GCP VM instances have serial port access enabled
- GCP VM instances have block project-wide SSH keys feature disabled
- GCP VM instances without any custom metadata information
Prisma Cloud Remediation - GCP Compute Engine Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - GCP Compute Engine Misconfiguration v2 instead.
This playbook remediates Prisma Cloud GCP Compute Engine alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- GCP VM instances have serial port access enabled
- GCP VM instances have block project-wide SSH keys feature disabled
- GCP VM instances without any custom metadata information
Prisma Cloud Remediation - GCP Compute Engine Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud GCP Compute Engine alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- GCP VM instances have serial port access enabled
- GCP VM instances have block project-wide SSH keys feature disabled
- GCP VM instances without any custom metadata information.
Prisma Cloud Remediation - GCP Kubernetes Engine Cluster Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud GCP Kubernetes Engine Cluster alerts.
Prisma Cloud policies remediated:
* GCP Kubernetes Engine Clusters Basic Authentication is set to Enabled
* GCP Kubernetes Engine Clusters have HTTP load balancing disabled
* GCP Kubernetes Engine Clusters have Legacy Authorization enabled
* GCP Kubernetes Engine Clusters have Master authorized networks disabled
* GCP Kubernetes Engine Clusters have Network policy disabled
* GCP Kubernetes Engine Clusters have Stackdriver Logging disabled
* GCP Kubernetes Engine Clusters have Stackdriver Monitoring disabled
* GCP Kubernetes Engine Clusters have binary authorization disabled
* GCP Kubernetes Engine Clusters web UI/Dashboard is set to Enabled
* GCP Kubernetes cluster intra-node visibility disabled
Prisma Cloud Remediation - GCP Kubernetes Engine Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - GCP Kubernetes Engine Misconfiguration v2 instead.
This playbook remediates Prisma Cloud GCP Kubernetes Engine alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
* GCP Kubernetes Engine Clusters Basic Authentication is set to Enabled
* GCP Kubernetes Engine Clusters have HTTP load balancing disabled
* GCP Kubernetes Engine Clusters have Legacy Authorization enabled
* GCP Kubernetes Engine Clusters have Master authorized networks disabled
* GCP Kubernetes Engine Clusters have Network policy disabled
* GCP Kubernetes Engine Clusters have Stackdriver Logging disabled
* GCP Kubernetes Engine Clusters have Stackdriver Monitoring disabled
* GCP Kubernetes Engine Clusters have binary authorization disabled
* GCP Kubernetes Engine Clusters web UI/Dashboard is set to Enabled
* GCP Kubernetes cluster intra-node visibility disabled
Prisma Cloud Remediation - GCP Kubernetes Engine Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud GCP Kubernetes Engine alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
* GCP Kubernetes Engine Clusters Basic Authentication is set to Enabled
* GCP Kubernetes Engine Clusters have HTTP load balancing disabled
* GCP Kubernetes Engine Clusters have Legacy Authorization enabled
* GCP Kubernetes Engine Clusters have Master authorized networks disabled
* GCP Kubernetes Engine Clusters have Network policy disabled
* GCP Kubernetes Engine Clusters have Stackdriver Logging disabled
* GCP Kubernetes Engine Clusters have Stackdriver Monitoring disabled
* GCP Kubernetes Engine Clusters have binary authorization disabled
* GCP Kubernetes Engine Clusters web UI/Dashboard is set to Enabled
* GCP Kubernetes cluster intra-node visibility disabled.
Prisma Cloud Remediation - GCP VPC Network Firewall Misconfiguration [PrismaCloud] — This playbook remediates the following Prisma Cloud GCP VPC Network Firewall alerts.
Prisma Cloud policies remediated:
- GCP Firewall rule allows internet traffic to FTP port (21)
- GCP Firewall rule allows internet traffic to HTTP port (80)
- GCP Firewall rule allows internet traffic to MongoDB port (27017)
- GCP Firewall rule allows internet traffic to MySQL DB port (3306)
- GCP Firewall rule allows internet traffic to Oracle DB port (1521)
- GCP Firewall rule allows internet traffic to PostgreSQL port (5432)
- GCP Firewall rule allows internet traffic to RDP port (3389)
- GCP Firewall rule allows internet traffic to SSH port (22)
- GCP Firewall rule allows internet traffic to Telnet port (23)
- GCP Firewall rule allows internet traffic to DNS port (53)
- GCP Firewall rule allows internet traffic to Microsoft-DS port (445)
- GCP Firewall rule allows internet traffic to NetBIOS-SSN port (139)
- GCP Firewall rule allows internet traffic to POP3 port (110)
- GCP Firewall rule allows internet traffic to SMTP port (25)
- GCP Default Firewall rule should not have any rules (except http and https)
- GCP Firewall with Inbound rule overly permissive to All Traffic
Prisma Cloud Remediation - GCP VPC Network Misconfiguration [PrismaCloud] — Deprecated. Use Prisma Cloud Remediation - GCP VPC Network Misconfiguration v2 instead.
This playbook remediates Prisma Cloud GCP VPC Network alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- GCP project is using the default network
- GCP Firewall rule allows internet traffic to FTP port (21)
- GCP Firewall rule allows internet traffic to HTTP port (80)
- GCP Firewall rule allows internet traffic to MongoDB port (27017)
- GCP Firewall rule allows internet traffic to MySQL DB port (3306)
- GCP Firewall rule allows internet traffic to Oracle DB port (1521)
- GCP Firewall rule allows internet traffic to PostgreSQL port (5432)
- GCP Firewall rule allows internet traffic to RDP port (3389)
- GCP Firewall rule allows internet traffic to SSH port (22)
- GCP Firewall rule allows internet traffic to Telnet port (23)
- GCP Firewall rule allows internet traffic to DNS port (53)
- GCP Firewall rule allows internet traffic to Microsoft-DS port (445)
- GCP Firewall rule allows internet traffic to NetBIOS-SSN port (139)
- GCP Firewall rule allows internet traffic to POP3 port (110)
- GCP Firewall rule allows internet traffic to SMTP port (25)
- GCP Default Firewall rule should not have any rules (except http and https)
- GCP Firewall with Inbound rule overly permissive to All Traffic
Prisma Cloud Remediation - GCP VPC Network Misconfiguration v2 [PrismaCloud] — This playbook remediates Prisma Cloud GCP VPC Network alerts. It calls sub-playbooks that perform the actual remediation steps.
Remediation:
- GCP project is using the default network
- GCP Firewall rule allows internet traffic to FTP port (21)
- GCP Firewall rule allows internet traffic to HTTP port (80)
- GCP Firewall rule allows internet traffic to MongoDB port (27017)
- GCP Firewall rule allows internet traffic to MySQL DB port (3306)
- GCP Firewall rule allows internet traffic to Oracle DB port (1521)
- GCP Firewall rule allows internet traffic to PostgreSQL port (5432)
- GCP Firewall rule allows internet traffic to RDP port (3389)
- GCP Firewall rule allows internet traffic to SSH port (22)
- GCP Firewall rule allows internet traffic to Telnet port (23)
- GCP Firewall rule allows internet traffic to DNS port (53)
- GCP Firewall rule allows internet traffic to Microsoft-DS port (445)
- GCP Firewall rule allows internet traffic to NetBIOS-SSN port (139)
- GCP Firewall rule allows internet traffic to POP3 port (110)
- GCP Firewall rule allows internet traffic to SMTP port (25)
- GCP Default Firewall rule should not have any rules (except http and https)
- GCP Firewall with Inbound rule overly permissive to All Traffic
Prisma SASE - Block IP [PrismaAccess] — This playbook assists in blocking communication with the provided IPs in the Prisma SASE policy.
If a group name is provided, the IPs will be added to the mentioned static address group (there should be a rule associated with the group name to block communication with that group).
And if the group name is not provided, a new group will be created with a dedicated rule to block communication with those IPs.
Prisma SASE - Block URL [PrismaAccess] — The playbook will handle the operation of blocking a URL within the organization.
If a category is provided, the URL will be added to the list.
If not, a new URL category will be created, and a new security rule that blocks that category.
Prisma SASE - Create Address Object [PrismaAccess] — This playbook creates new address objects in the Prisma SASE Object section. Those objects can be used later on in other objects such as Security Rules.
Prisma SASE - Create a security pre-rule for EDL [PrismaAccess] — This playbook helps to create a security rule to block indicators from an EDL. This playbook should run only once to setup the EDL object and its rule.
Prisma SASE - Quarantine a SentinelOne Host With Active Threat [PrismaAccess] — ## Goal
This playbook is designed to automatically quarantine a SentinelOne host in response to a new threat incident trigger using Prisma SASE.
## Playbook Flow
- **Trigger**: The playbook activates upon the creation of a new SentinelOne Threat incident.
- **Process**:
1. Retrieves the Host ID from Cortex Data Lake.
2. Loads detailed information about the agent.
3. If the Host ID is found and the agent is not decommissioned, it initiates quarantine through Prisma SASE.
## Dependencies and Configuration
- This playbook requires being set as the default in the SentinelOne instance configuration.
- It specifically responds to events categorized as 'Threats'.
- Ensure that the Prisma SASE, Cortex Data Lake and SentinelOne integrations are properly configured and operational for seamless execution of this playbook.
Proactive Threat Hunting [ProactiveThreatHunting] — This playbook is the main playbook of the 'Proactive Threat Hunting' pack. It automatically runs during a new hunting session and guides the threat hunter through the session based on the selected hunting method. The available hunting methods are:
- SDO Hunt: Constructs the hunting hypothesis based on SDO indicators (Campaign, Malware, Intrusion Set).
- Freestyle Hunt: Allows the threat hunter to provide their own queries and IOCs for hunting.
Proactive Threat Hunting - Block Account [ProactiveThreatHunting] — This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of blocking a user specified by the analyst.
Proactive Threat Hunting - Block Indicators [ProactiveThreatHunting] — This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of blocking indicators specified by the analyst.
Proactive Threat Hunting - Endpoint Isolation [ProactiveThreatHunting] — This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of isolating a host specified by the analyst.
Proactive Threat Hunting - Entity Enrichment [ProactiveThreatHunting] — This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of enriching information on hosts and users specified by the analyst.
Proactive Threat Hunting - Execute Query [ProactiveThreatHunting] — This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of executing a query that will be provided by the analyst. The playbook supports executing a query using the following integrations:
- Cortex XDR XQL Engine
- Microsoft Defender For Endpoint
Proactive Threat Hunting - Quarantine File [ProactiveThreatHunting] — This playbook will be executed from the “Proactive Threat Hunting” layout button with the objective of quarantining a file specified by the analyst. The following integration is supported:
- Cortex XDR IR
Proactive Threat Hunting - SDO Threat Hunting [ProactiveThreatHunting] — This playbook will be executed when the analyst chooses to perform SDO hunting.
The playbook receives an SDO type indicator and executes the following steps:
- Searches IOCs related to the SDO indicator - IPs, Hashes, Domains, URLs.
- Hunts for the found IOCs using the "Threat Hunting - Generic" sub-playbook.
- Searches attack patterns that are related to the SDO indicator.
- Searches LOLBAS tools that are related to the found attack patterns.
- Hunts for LOLBin executions command-line arguments that are similar to LOLBAS malicious commands patterns.
Process Email [DeprecatedContent] — Deprecated. We recommend using Process Email - Generic playbook instead. Add email details into the relevant context entities and handle the case where you have attached original emails.
Process Email - Add custom fields [DeprecatedContent] — Deprecated. We recommend using Process Email - Generic playbook instead. Process email - Add email data to a phishing incident's custom fields
Process Incident - Vectra Detect [Vectra_AI] — This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra Detect playbook.
Process Incident - Vectra XDR [VectraXDR] — This playbook is used to initiate the processing of an incident. This playbook runs when a pending incident is selected for investigation. It will change the state from pending to active and it will list the available users in Vectra and request the user ID to use for assignment. Once the data collection is complete, it will call the Dispatch Incident - Vectra XDR playbook.
Proofpoint TAP - Event Enrichment [ProofpointTAP] — This playbook enriches Proofpoint Targeted Attack Protection (TAP) incidents with forensic evidence.
By utilizing the 'proofpoint-get-forensics' command, the playbook retrieves forensic evidence based on the campaign ID and threat ID detected in the Proofpoint TAP incidents.
QRadar - Get Offense Logs [QRadar] — Works for QRadar integration version 3, v1 and v2 are deprecated.
Note: You can use the integration to fetch the events with the offense however it will fetch the events according to the specified limit defined in the instance settings. By using this playbook you can define an additional search to query a larger number of logs.
Default playbook inputs use the QRadar incident fields such as idoffense, starttime. These fields can be replaced but need to point to relevant offense ID and starttime fields.
QRadar - Get offense correlations [DeprecatedContent] — Deprecated. Use the `QRadar - Get offense correlations v2` instead.\"\nRun on a QRadar offense to get more information\n\n* Get all correlations relevant to the offense\n* Get all logs relevant to the correlations (not done by default, set "GetCorrelationLogs\" to \"True\")\n\nInputs-\n* GetCorrelationLogs (default - False)\n* MaxLogsCount (default - 20)
QRadar - Get offense correlations v2 [QRadar] — Deprecated. Use the "QRadar - Get Offense Logs" playbook instead.
Run on a QRadar offense to get more information:
* Get all correlations relevant to the offense
* Get all logs relevant to the correlations (not done by default - set "GetCorrelationLogs" to "True")
Inputs:
* GetCorrelationLogs (default: False)
* MaxLogsCount (default: 20)
QRadar Build Query and Search [QRadar] — The QRadar Build Query and Search playbook creates an AQL query for the QRadar SIEM using the QRadarCreateAQLQuery automation queries. Complex queries take into consideration several inputs and allow including or excluding each of the values as well as performing a full or partial search. Each of the values can be searched across several fields.
The playbook supports 3 separate conditions to be evaluated.
For example, in the first condition, inputs will evaluate several user names that may or may not exist in several fields. The second input, can for example, evaluate for IP addresses in several fields that may or may not exist in several fields, and a third value can search for an event ID that may or may not exist in several fields. The results of all of the inputs will create an AQL query that covers all of the inputs combining all of the different conditions.
Each of the inputs is validated so in case the inputs are not set correctly, the user can review and run them again.
Also, populated inputs will be combined, meaning by populating the first and second values the resulting AQL query will be a combination of all of the values and not 3 separate searches. In addition, make sure to populate the inputs in order according to the indexed fields in QRadar (indexed fields should be provided before non indexed ones).
QRadar Generic [QRadar] — The QRadar Generic playbook is executed for the QRadar Generic incident type. It performs all the common parts of the investigation, including notifying the SOC, enriching data for indicators and users, calculating severity, assigning incidents, and notifying the SIEM admin about false positives.
QRadar Get Hunting Results [QRadar] — This playbook is used to sort the QRadar search results to display the IP addresses, assets, and usernames that the search provided. In addition, the results allow you to differentiate between internal and external IP addresses as well as query the QRadar assets API in order to get the assets details from the IP addresses. You can provide the QRadar fields names and the organizations' IP ranges in order to properly sort the data. The end result of the playbook will be the internal and external IP addresses detected as well as the assets and users.
QRadar Indicator Hunting [QRadar] — Deprecated. Use the "QRadar Indicator Hunting V2" playbook instead.
QRadar Indicator Hunting V2 [QRadar] — The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls.
QRadarCorrelationLog [QRadar] — Deprecated. Use the "QRadar - Get Offense Logs"\ \ playbook instead. This playbook retrieves the correlation logs of multiple QIDs.
QRadarFullSearch [QRadar] — Deprecated.Use the following command instead `qradar-search-retrieve-results`.
This playbook runs a QRadar query and return its results to the context.
Query Cisco Stealthwatch Flows [CiscoStealthwatch] — This playbook runs a query on Cisco Stealthwatch flows and return its results to the context.
Query using Sigma rules [Sigma] — An example playbook on how to query Sigma rules from within TIM and query a SIEM/EDR.
RDP Bitmap Cache - Detect and Hunt [RDPCacheHunting] — ## Playbook: Automated Collection and Forensic Analysis of RDP Sessions Cache Data
This playbook automates the collection and forensic analysis of RDP sessions cache data. It involves the following steps:
### Step 1: Collect Cache Files and Convert to Image
The first step is to collect the cache files from RDP sessions and convert them into an image format.
### Step 2: Extract Readable Text from the Image
Once the cache files are converted into an image, the playbook extracts readable text from the image to facilitate analysis.
### Step 3: Build Indicators of Compromise (IOCs) from Text
In this step, the extracted text is used to build indicators of compromise (IOCs) for further investigation and threat hunting.
### Step 4: Enrich Extracted Indicators for Further Hunting
Finally, the playbook enriches the extracted indicators by adding additional context and information, enhancing their usefulness for further hunting and analysis.
> Note: It is important to customize and adapt this playbook to fit specific use cases and environments. Additionally, ensure compliance with legal and privacy requirements when collecting and analyzing data.
Feel free to modify and enhance this playbook according to your requirements.
Ransomware Advanced Analysis [Core] — This playbook detects the ransomware type and searches for available decryptors.
The playbook uses the ID-Ransomware service, which allows you to detect the ransomware using multiple methods.
Ransomware Enrich and Contain [Core] — This playbook is responsible for ransomware alert data enrichment and response.
The playbook executes the following:
1.Checks if the initiator is a remote attacker and allows isolating the remote host, if possible.
2.Retrieves the WildFire sandbox report and extract the indicators within it.
* The playbook tries to retrieve the report, but if there is no report available, the playbook tries to fetch the ransomware file for detonation.
3.Hunts for the ransomware alert indicators from the alert table, searches for endpoints that have been seen with them, and allows containing the identified endpoints.
Ransomware Exposure - RiskSense [RiskSense] — The ransomware exposure playbook reveals an organization's exposure to the specific vulnerabilities that are being exploited to launch ransomware attacks.
Ransomware Playbook - Manual [Ransomware] — Master playbook for ransomware incidents. This playbook is a manual playbook.
Ransomware Response [Core] — This playbook handles ransomware alerts based on the Cortex XDR Traps module signature 'Suspicious File Modification'
**Attacker’s Goals:**
An attacker is attempting to encrypt the victim files for either extortion or destruction purposes.
**Investigative Actions:**
Investigate the executed process image and verify if it is malicious using:
XDR trusted signers
VT trusted signers
VT detection rate
NSRL DB
**Response Actions:**
The playbook’s first response action is a remediation plan which includes two sub-playbooks, **Containment Plan** and **Eradication Plan**, which is based on the initial data provided within the alert. In that phase, the playbooks will execute:
Auto endpoint isolation
Auto block indicators
Auto file quarantine
Auto user disable
Auto process termination
Next, the playbook executes an enrichment and response phase which includes two sub-playbooks, **Ransomware Enrich and Contain** & **Account Enrichment - Generic v2.1**.
The Ransomware Enrich and Contain playbook does the following:
1.Checks if the initiator is a remote attacker and allows isolating the remote host, if possible.
2.Retrieves the WildFire sandbox report and extracts the indicators within it. * The playbook tries to retrieve the report, but if there is no report available, the playbook tries to fetch the ransomware file for detonation.
3.Hunts for the ransomware alert indicators from the alert table, searches for endpoints that have been seen with them, and allows containing the identified endpoints.
Next, an advanced analysis playbook, which is currently done mostly manually, will be executed. This sub-playbook, **Ransomware Advanced Analysis** allows the analyst to upload the ransomware note and for the ransomware identification. Using the **ID-Ransomware** service, the analyst will be able to get the ransomware type and the decryptor if available.
When the playbook executes, it checks for additional activity using the Endpoint Investigation Plan playbook, and another phase, which includes the Containment Plan sub-playbook, is executed.
**This phase will execute the following containment actions:**
Manual block indicators
Manual file quarantine
Auto endpoint isolation
Finally, the recovery phase is executed. If the analysts decides to continue with the investigation rather than recover and close the alert, a manual task with **CISA** official ransomware investigation checklist is provided for further investigation.
**External resources:**
[MITRE Technique T1486](https://attack.mitre.org/techniques/T1486/)
[CISA Ransomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide)
Rapid Breach Response - Set Incident Info [MajorBreachesInvestigationandResponse] — This playbook is responsible for setting up the Rapid Breach Response Incident Info tab in the layout.
Rapid IOC Hunting Playbook [DeprecatedContent] — Deprecated. Use the Hunt File Hash playbook instead. Playbook to quickly react to discovery of new IOCs. Receive a list of IOCs as attached text / csv files, extract IOCs using regular expressions and hunt rapidly across the infrastructure using various integrations. Also supports attaching multiple files.
Rapid7 InsightIDR - Execution Flow Indicators Hunting [Rapid7_InsightIDR] — This playbook queries Rapid7 InsightIDR SIEM for execution flow indicators, including registry values, registry keys, registry hives, commands, processes name, and applications.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Rapid7 InsightIDR - File Indicators Hunting [Rapid7_InsightIDR] — This playbook queries Rapid7 InsightIDR SIEM for file indicators, including MD5 hashes, SHA256 hashes, SHA1 hashes, file names, file types, and file paths.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Rapid7 InsightIDR - HTTP Requests Indicators Hunting [Rapid7_InsightIDR] — This playbook queries Rapid7 InsightIDR SIEM for indicators associated with HTTP requests, including HTTP request methods, user agents, URIs, and Ja3.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Rapid7 InsightIDR - Indicators Hunting [Rapid7_InsightIDR] — This playbook facilitates threat hunting and detection of IOCs within Rapid7 InsightIDR SIEM logs utilizing four sub-playbooks. The sub-playbooks query Rapid7 InsightIDR SIEM for different indicators including files, traffic, HTTP requests, and execution flows indicators.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Supported IOCs for this playbook:
- MD5
- SHA1
- SHA256
- IP Address
- URLDomain
- Registry Value
- Registry Key
- Registry Hives
- Command Line
- File Name
- Process Name
- HTTP Request Methods
- User Agent
- Port Number
- File Path
- Geolocation
- Email Address
- CIDR
- URI
- Ja3
- FileType
Rapid7 InsightIDR - Traffic Indicators Hunting [Rapid7_InsightIDR] — This playbook queries Rapid7 InsightIDR SIEM for traffic indicators, including URLs, domains, ports, IP addresses, IP ranges (CIDR), email addresses, and geolocations.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Recorded Future - Identity Exposure [IdentityRecordedFuture] — This playbook was developed as a template response when an Identity Exposure Playbook Alert has been triggered.
Recorded Future - Threat Actor Search [RecordedFuture] — Template playbook to initiate an Automated Threat Hunt based on the Threat Map in Recorded Future. The Playbook fetches links related to the Threat Actors part of the Threat Map from Recorded Future and launches a hunt in the SIEM for any detections within the environment.
Recorded Future Domain Abuse [RecordedFuture] — This playbook was developed as a template to handle the ingestion of Recorded Future Domain Abuse playbook alerts.
Recorded Future Entity Enrichment [RecordedFuture] — Template playbook to incorporate Recorded Future enrichment for IPs, Hashes, Domains, URLs into your current workflows. Playbook also shows how to look up available 'Links' data for IOCs.
Recorded Future External Usecase [IdentityRecordedFuture] — Deprecated. Use Recorded Future - Identity Exposure instead. Implements an external usecase for Recorded Future Identity Data
Recorded Future Identity - Create Incident (sub) [IdentityRecordedFuture] — Deprecated. Use Recorded Future - Identity Exposure instead. This playbook was developed as a sub-playbook to generate incidents for each exposed identity found in the Recorded Future Identity - Lookup Identities (parent) playbook.
Recorded Future Identity - Identity Found (incident) [IdentityRecordedFuture] — Deprecated. Use Recorded Future - Identity Exposure instead. This playbook was developed as a template response when an Identity has been found and a Recorded Future Identity Incident has been created.
Recorded Future Identity - Lookup Identities (parent) [IdentityRecordedFuture] — Deprecated. Use Recorded Future - Identity Exposure instead. This playbook was developed as a template to look up exposed identities and generate incidents if they exist; it can be used within a job.
Recorded Future Leaked Credential Alert Handling [RecordedFuture] — Template playbook showing suggested steps to triage leaked credential alerts. Classifier/Mapper are available to ingest Recorded Future Leaked Credential Alerts.
Recorded Future Playbook Alert Details [RecordedFuture] — A default playbook to fetch details of Playbook alert that does not yet have mapping made by Recorded Future
Recorded Future Sandbox [RecordedFuture] — Template playbook utilizing Hatching.io to sandbox a given file and generate an analysis report. Indicators from the given report are then extracted and enriched with Recorded Future data.
Recorded Future Threat Assessment [RecordedFuture] — Threat Assessment using the Recorded Future SOAR Triage API and the context Phishing.
Recorded Future Typosquat Alert Handling [RecordedFuture] — Template playbook showing suggested steps to triage typo squat alerts. Classifier/Mapper are available to ingest Recorded Future Typo squat Alerts.
Recorded Future Vulnerability [RecordedFuture] — This playbook was developed as a template to handle the ingestion of Recorded Future Cyber Vulnerability playbook alerts.
Recorded Future Vulnerability Alert Handling [RecordedFuture] — Template playbook showing suggested steps to triage new critical vulnerability alerts. Playbook include New and Critical CVEs. Classifier/Mapper are available to ingest Recorded Future New, Critical or Pre NVD Vulnerability Alerts.
Recorded Future Workforce Usecase [IdentityRecordedFuture] — Deprecated. Use Recorded Future - Identity Exposure instead. Implements an workforce usecase for Recorded Future Identity Data
Recovery Plan [CommonPlaybooks] — This playbook handles all the recovery actions available with Cortex XSIAM, including the following tasks:
* Unisolate endpoint
* Restore quarantined file
Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.
Registry Parse Data Analysis [WindowsForensics] — This playbook leverages the RegistryParse automation to perform registry analysis and extract forensic artifacts. The automation includes common registry objects to extract which are useful for analyzing registry, or a user provides registry path to parse.
Remote PsExec with LOLBIN command execution alert [Core] — The "Remote PsExec-like LOLBIN Command Execution" playbook is designed to address and respond to alerts indicating suspicious activities related to remote PsExec-like LOLBIN command execution from an unsigned non-standard source.
The playbook aims to efficiently:
- Check if the execution is blocked. If not will terminate the process (Manually by default).
- Enrich any entities and indicators from the alert and find any related campaigns.
- Perform command analysis to provide insights and verdict for the executed command.
- Perform further endpoint investigation using XDR.
- Checks for any malicious verdict found to raise the severity of the alert.
- Perform Automatic/Manual remediation response by blocking any malicious indicators found.
The playbook is designed to run as a sub-playbook in ‘Cortex XDR Incident Handling - v3 & Cortex XDR Alerts Handling’.
It depends on the data from the parent playbooks and can not be used as a standalone version.
Remove Employees from New Hire Watchlist [Code42] — Loops through New Hire watchlist entries from Code42 Incydr and removes employees based on specified criteria.
Report Categorization - Cofense Triage v3 [CofenseTriage] — Report Categorization playbook investigates reports that are unprocessed or uncategorized on Cofense Triage as incident alerts in XSOAR and categorizes them based on the severity of the incident.
Residents Notification - Breach Notification [BreachNotification-US] — This playbook is triggered by a breach notification playbook and is responsible for the resident notification process.
Retrieve Alert Attachments - Rapid7 ThreatCommand [IntSight] — This playbook is used by default for the Rapid7 ThreatCommand alerts being ingested as XSOAR incidents. This playbook retrieves attachments (CSV file and images) using the Alert ID incident field.
Retrieve Alerts For IOCs - Dataminr Pulse [DataminrPulse] — This playbook is used to fetch alerts from Dataminr Pulse, which will be based on the given input text. First, it will extract indicators from the input text, then it will use extracted indicators to retrieve alerts from Dataminr Pulse. After that, it will store related alerts in the context.
Retrieve Email Data - Agari Phishing Defense [AgariPhishingDefense] — Retrieve Email Data from one of the Integrations of Gmail, Mail Listener v2, EWS O365, Microsoft Graph Mail.
Retrieve File from Endpoint - Generic [CommonPlaybooks] — Deprecated. Use `Retrieve File from Endpoint - Generic V3` instead.
This playbook retrieves a file sample from an endpoint using the following playbooks:
- Get File Sample From Path - Generic
- Get File Sample By Hash - Generic v2
Retrieve File from Endpoint - Generic V2 [CommonPlaybooks] — Deprecated. Use `Retrieve File from Endpoint - Generic V3` instead.
'This playbook retrieves a file sample from an endpoint using the following playbooks:'
- Get File Sample From Path - Generic v2.
- Get File Sample By Hash - Generic v3.
Retrieve File from Endpoint - Generic V3 [CommonPlaybooks] — 'This playbook retrieves a file sample from an endpoint using the following playbooks:'
- Get File Sample From Path - Generic v2.
- Get File Sample By Hash - Generic v3.
Retrieve Related Alerts - Dataminr Pulse [DataminrPulse] — This playbook is used to fetch related alerts for Dataminr Pulse. The information required to fetch related alerts will be used from the incident s alert ID for which the playbook is going to run. After that, it will store them in the context.
RiskIQAsset Basic Information Enrichment - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — This playbook receives indicators from its parent playbook and enriches the basic information and the detected CVEs for the "RiskIQAsset" type of indicators. This playbook needs to be used with caution as it might use up the integrations' API license when running for large amounts of indicators.
Supported Integrations:
- RiskIQ Digital Footprint
- VulnDB
- CVE Search
- IBM X-Force
RiskIQAsset Enrichment - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — Enriches the "RiskIQAsset" type of indicators with basic information and CVEs detected for the asset, performs a vulnerability scan for "Host" and "IP Address" type of assets, and enriches received information in the context as well as provides the user to add to allow list a list of "IP Address" type of assets. This playbook also enriches the detected CVEs. To select the indicators you want to enrich, go to playbook inputs, choose "from indicators" and set your query. For example type:RiskIQAsset etc. The default playbook query is "type:RiskIQAsset". In case indicators with specific "riskiqassettype" are to be enriched, the query must be edited accordingly. This playbook needs to be used with caution as it might use up the integrations' API license when running for large amounts of indicators.
Supported integrations:
- RiskIQ Digital Footprint
- Tenable.io
- Google Cloud Compute
- AWS - EC2
- Okta v2
Rubrik Anomaly Incident Response - Rubrik Polaris [RubrikPolaris] — This playbook will investigate an anomaly incident ingested by the integration "RubrikPolaris", enrich its data, and perform a remediation according to the incident's object type.
Rubrik DSPM Violation Remediation - Rubrik Security Cloud [RubrikPolaris] — This playbook remediates DSPM violations by retrieving violation details and affected file information, downloading the affected file details and remediation logs as CSV files, quarantining the affected files and updating the violation status.
Rubrik File Context Analysis - Rubrik Polaris [RubrikPolaris] — This playbook fetches file context information for the provided file, folder, or file share name and the object ID to get the policy hits.
Rubrik Fileset Ransomware Discovery - Rubrik Polaris [RubrikPolaris] — This playbook performs IOC Scan on fileset object. It also creates tickets on ServiceNow using "ServiceNow v2" integration.
Supported integrations:
- RubrikPolaris
- ServiceNow v2
Rubrik IOC Scan - Rubrik Polaris [RubrikPolaris] — This playbook starts an IOC Scan with the provided IOC values. It can be looped until recoverable snapshots are obtained or the limit to loop is reached.
Rubrik IOC Scan v2 - Rubrik Polaris [RubrikPolaris] — This playbook starts an advance IOC Scan with the provided IOC values and shows the results upon completion.
Rubrik Object Context Analysis - Rubrik Polaris [RubrikPolaris] — This playbook will investigate based on the object type from the Rubrik Anomaly incident to retrieve the policy hits of the files related to the object.
Rubrik Polaris - Anomaly Analysis [RubrikPolaris] — Monitor the progress of a Rubrik Radar anomaly event and use Rubrik Sonar to check for data classification hits.
Rubrik Quarantine Files General [RubrikPolaris] — This playbook quarantines files using the Microsoft Graph Search (O365 File Management) integration.
Rubrik Quarantine Files using MS Graph Search [RubrikPolaris] — This playbook quarantines files using the Microsoft Graph Search (O365 File Management) integration by downloading them, uploading them to a quarantine folder and deleting them from their original location.
Rubrik Ransomware Discovery and File Recovery - Rubrik Polaris [RubrikPolaris] — This playbook performs an IOC Scan based on the provided inputs, search the recoverable snapshot and performs recovery on the searched recoverable snapshot. This playbook also creates tickets on ServiceNow using "ServiceNow v2" integration.
Supported integrations:
- RubrikPolaris
- ServiceNow v2
Rubrik Ransomware Discovery and VM Recovery - Rubrik Polaris [RubrikPolaris] — Use this playbook to recover a virtual machine using the "RubrikPolaris" integration by either exporting or live-mounting a backup snapshot. This playbook also creates tickets on ServiceNow using "ServiceNow v2" integration.
Supported integrations:
- RubrikPolaris
- ServiceNow v2
Rubrik Retrieve Anomaly Result - Rubrik Security Cloud [RubrikPolaris] — This playbook retrieves the list of anomaly files for the provided snapshot ID (or activity series ID) and generates the downloadable links for the file path(s).
Rubrik Retrieve User Access Information - Rubrik Polaris [RubrikPolaris] — This playbook retrieves User Intelligence information for the provided username or email, which includes the user's risk level and the types of analyzer hits.
Rubrik Turbo IOC Scan - Rubrik Polaris [RubrikPolaris] — This playbook starts a Turbo IOC scan with the specified IOC values and shows the results upon completion.
Rubrik Update Anomaly Status- Rubrik Security Cloud [RubrikPolaris] — This playbook updates status of the Anomaly Detection snapshot for the provided anomaly ID (or activity series ID) and workload ID (or Object ID).
Rubrik User Access Analysis - Rubrik Polaris [RubrikPolaris] — This playbook fetches User Intelligence information for the provided username or email, and then increases the incident severity based on the user risk levels.
Rubrik Workload Analysis - Rubrik Security Cloud [RubrikPolaris] — This playbook fetches workload information for the provided IPs or domains/hostnames, and then increases the XSOAR incident severity based on the workload risk levels and threat information.
SANS - Incident Handler's Handbook Template [SANS] — This playbook contains the phases for handling an incident as they are described in the SANS Institute ‘Incident Handler's Handbook’ by Patrick Kral.
https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901
***Disclaimer: This playbook does not ensure compliance to SANS regulations.
SANS - Incident Handlers Checklist [SANS] — This playbook follows the "Incident Handler's Checklist" described in the SANS Institute ‘Incident Handler’s Handbook’ by Patrick Kral.
https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901
***Disclaimer: This playbook does not ensure compliance to SANS regulations.
SANS - Lessons Learned [SANS] — This playbook assists in post-processing an incident and facilitates the lessons learned stage, as presented by SANS Institute ‘Incident Handler’s Handbook’ by Patrick Kral.
https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901
***Disclaimer: This playbook does not ensure compliance to SANS regulations.
SIEM - Search for Failed logins [CommonPlaybooks] — This playbook searches for failed logon on a specific user by querying logs from different sources.
Supported Integrations:
-Splunk
-QRadar
-Azure Log Analytics.
SOCRadar Incident [SOCRadar] — Performs indicator extraction and enrichment from the incident content, calculates the severity level, assigns the incident to a particular analyst, notifies SOCRadar platform for the incident response (to mark it as false positive or resolved) and generates investigation summary report just before closing the investigation in the end. This playbook is executed for the SOCRadar Generic incident type.
SSL_Certificate_Verification [SSLCertificates] — Demo playbook - takes list of addresses from an XSOAR list, process the status of each SSL certificate, and generate war room and email summary outputs.
SafeNet Trusted Access - Add to Unusual Activity Group [SafeNet_Trusted_Access] — This playbook adds the user to a group that was created to identify unusual activity. SafeNet Trusted Access policies can be configured to take this into account and provide stronger protection when handling access events from users who are members of the group. The user is added to this group for a configurable period of time.
SafeNet Trusted Access - Terminate User SSO Sessions [SafeNet_Trusted_Access] — This playbook terminates user SSO sessions so that upon the next login attempt following the unlocking of the account, authentication is required.
Scan Assets - Nexpose [Rapid7_Nexpose] — Deprecated. Use the "Scan Site - Nexpose" playbook instead.
Scan Site - Nexpose [Rapid7_Nexpose] — Starts a Nexpose scan by site id and waits for the scan to finish by polling its status in pre-defined intervals.
Schedule Task and Poll [ScheduleTaskAndPoll] — This playbook will schedule a specified command and monitor for completion by looking for output in context. Make the playbook context shared globally if you have a command that returns to Context automatically and you have a specific key to monitor. The key monitored must be a single field value and not an array.
Search And Block Software - Generic [CommonPlaybooks] — This playbook will search a file or process activity of a software by a given image file name. The analyst can then choose the files to block.
The following integrations are supported:
- Cortex XDR XQL Engine
- Microsoft Defender For Endpoint
Search And Delete Emails - EWS [MicrosoftExchangeOnPremise] — This playbook searches EWS to identify and delete emails with similar attributes of a malicious email.
Search And Delete Emails - Generic [CommonPlaybooks] — Deprecated. Use `Search And Delete Emails - Generic v2` instead. This playbook searches and delete emails with similar attributes of a malicious email.
Search And Delete Emails - Generic v2 [CommonPlaybooks] — This playbook searches and deletes emails with similar attributes of a malicious email using one of the following integrations: * EWS * Microsoft Graph Security * Gmail * Agari Phishing Defense.
Search And Delete Emails - Gmail [Gmail] — This playbook searches Gmail to identify and delete emails with similar attributes to the malicious email.
Search And Delete Emails - Microsoft Graph Security [MicrosoftGraphSecurity] — This playbook performs the following steps:
1. Checks that the Microsoft Graph integration is available and active.
2. Lists existing eDiscovery cases and finds the specified case, or creates it if missing.
3. Composes the KQL content query based on the mailbox scope (recipientsOnly, allTenantMailboxes, or other).
4. Creates a new eDiscovery search with the composed query, or reuses an existing search based on the force input.
5. Runs an estimate statistics operation to count emails matching the query.
6. Waits for the estimate operation to complete and checks whether any emails were found.
7. Optionally previews the results (statistics summary or full export), based on the preview input.
8. Purges the matching emails (Hard delete / Soft delete / manual analyst approval).
9. Cleans up the eDiscovery search based on the cleanup input.
Search Endpoints By Hash - Carbon Black Response [DeprecatedContent] — Deprecated. Use the Search Search Endpoints By Hash - Carbon Black Response V2 playbook instead. Hunt for malicious indicators using Carbon Black.
Search Endpoints By Hash - Generic [DeprecatedContent] — Deprecated. Use the Search Endpoints By Hash - Generic V2 playbook instead. Hunt using available tools
Search Endpoints By Hash - TIE [McAfee-TIE] — Hunt for sightings of MD5, SHA1 and/or SHA256 hashes on endpoints, using McAfee TIE (requires ePO as well).
Input:
* Hash (default, takes all deferent hashes from context)
Output:
* All agents that files with "Hash" has been executed on (TIE)
* Enrich Agents info from ePO
Search For Hash In Sandbox - Generic [CommonPlaybooks] — This playbook searches for a specific hash in the supported sandboxes. If the hash is known, the playbook provides a detailed analysis of the sandbox report. Currently, supported sandboxes are Falcon Intelligence Sandbox, Wildfire and Joe Sandbox.
Search LOLBAS Tools By Name [FeedLOLBAS] — This playbook searches for LOLBAS tools by their name, and returns the tool command from LOLBAS.
Search all mailboxes - Gmail with polling [Gmail] — This playbook searches Gmail records for all Google users, designed for large companies with over 2500 Google users.
Search and Compare Process Executions - Generic [CommonPlaybooks] — This playbook is a generic playbook that receives a process name and a command-line argument. It searches for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input. The playbook supports searching process executions using the following integrations:
- Cortex XDR XQL Engine
- Cortex XDR IR(Search executions inside XDR alerts)
- Microsoft Defender For Endpoint
Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
Send Indicators - Cofense Triage v3 [CofenseTriage] — Send Indicators playbook is used to create or update threat indicators in Cofense Triage that have been identified as malicious or suspicious by the analysis.
Send Investigation Summary Reports [CommonPlaybooks] — This playbook iterates over closed incidents, generates a summary report for each closed incident, and emails the reports to specified users.
Send Investigation Summary Reports Job [CommonPlaybooks] — You should run this playbook as a scheduled job, whicn should run at an interval of once every 15 minutes. This playbook functions by calling the sub-playbook: "Send Investigation Summary Reports", and closes the incident. By default, the playbook will search all incidents closed within the last hour. If you want to run the playbook more frequently, you should adjust the search query of the child playbook: "Send Investigation Summary". Reports.
ServiceNow - Ticket Management [ServiceNow] — `ServiceNow - Ticket Management` allows you to open a new ticket or comment on an existing ticket.
ServiceNow CMDB Search [ServiceNow] — Subplaybook for finding CI records in ServiceNow CMDB.
ServiceNow Change Management [Change_Management] — If you are using a PAN-OS/Panorama firewall and ServiceNow as a ticketing system this playbook is a perfect match for your change management for firewall process.
This playbook is triggered by a fetch from ServiceNow and will help you manage and automate your change management process.
ServiceNow Ticket State Polling [ServiceNow] — Use ServiceNow Incident State Polling as a sub-playbook when required to pause the execution of a master playbook until the ServiceNow ticket state is either resolved or closed.
This playbook implements polling by continuously running the servicenow-get-ticket command until the state is either resolved or closed.
Set Team Members [TeamManagement] — This playbook will accept a CSV of usernames and / or a CSV of role names (of which to enumerate for usernames) to add to the incidents team members.
The playbook will determine the existing owner and ensure that they are replaced as the owner once complete.
Set up a Shift handover meeting [ShiftManagement] — This playbook is used to create an online meeting for shift handover. Currently, this playbook supports Zoom.
Shift handover [ShiftManagement] — This playbook is used to set up shift handover meetings with all the accompanying processes such as creating an online meeting, creating a notification in a integrated chat app (for example Slack), creating a SOC manager briefing, and creating a display of the active incidents, team members who are on-call, and team members who are out of the office.
By modifying the playbook inputs you can decide whether to activate the Assign Active Incidents to Next Shift and whether a user who is out of the office will be taken into consideration.
Slack - General Failed Logins v2.1 [Slack] — Investigates a failed login event. The playbook interacts with the user via the Slack integration, checks whether the logins were a result of the user's attempts or an attack, raises the severity, and expires the user's password according to the user's replies.
SolarStorm Activity Behavior Hunting playbook [MajorBreachesInvestigationandResponse] — This manual playbook should be used as a sub-playbook in the 'SolarStorm and SUNBURST Hunting and Response' playbook and it helps you hunt for suspicious behavior related to SolarStorm activity.
Sources:
- https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
- https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/3/
- https://www.splunk.com/en_us/blog/security/sunburst-backdoor-detections-in-splunk.html
SolarStorm and SUNBURST Hunting and Response Playbook [MajorBreachesInvestigationandResponse] — This playbook does the following:
- Collect indicators to aid in your threat hunting process.
- Retrieve IOCs of SUNBURST (a trojanized version of the SolarWinds Orion plugin).
- Retrieve C2 domains and URLs associated with Sunburst.
- Discover IOCs of associated activity related to the infection.
- Generate an indicator list to block indicators with SUNBURST tags.
- Hunt for the SUNBURST backdoor
- Query firewall logs to detect network activity.
- Search endpoint logs for Sunburst hashes to detect presence on hosts.
If compromised hosts are found:
- Notify security team to review and trigger remediation response actions.
- Run sub-playbooks to isolate/quarantine infected hosts/endpoints and await further actions from the security team.
Sources:
https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/3/
https://www.splunk.com/en_us/blog/security/sunburst-backdoor-detections-in-splunk.html
Spear Phishing Investigation [Phishing] — The "Spear Phishing Investigation" playbook is designed to detect patterns that indicates a spear phishing attempt by the attacker.
SpecterOpsBHE [SpecterOpsBHE] — Deprecated. Use the SpecterOpsBloodHoundEnterprise playbook instead. Automated playbook that enriches BloodHound Enterprise attack path incidents with object information and validates attack path existence between security principals.
SpecterOpsBloodHoundEnterprise [SpecterOpsBloodHoundEnterprise] — Automated playbook that enriches BloodHound Enterprise attack path incidents with object information and validates attack path existence between security principals.
Splunk Generic [SplunkPy] — This is a generic playbook to be executed for the Splunk Notable Generic incident type. The playbook performs all the common parts of the investigation, including notifying the SOC, enriching the data for indicators and users, calculating the severity, assigning the incident, notifying the SIEM admin for false positives and more.
Splunk Indicator Hunting [SplunkPy] — This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators.
Spring Core and Cloud Function SpEL RCEs [SpringRCEs] — On March 29, 2022, information about a 0-day vulnerability in the popular Java library Spring Core appeared on Twitter.
Spring Framework is an extremely popular framework used by Java developers to build modern applications. If you rely on the Java stack, it is very likely that your development teams use Spring. In some cases, a single specially crafted request is enough to exploit the vulnerability.
Later, it was discovered that these are two separate vulnerabilities, one in Spring Core and the other in Spring Cloud Function:
**CVE-2022-22965 - RCE in "Spring Core" is a severe vulnerability, aka Spring4Shell**
**CVE-2022-22963 - RCE in "Spring Cloud Function SpEL"**
**CVE-2022-22947 - RCE in "Spring Cloud Gateway"**
**Spring Core vulnerability requirements:**
* JDK 9 or higher
* Apache Tomcat as the Servlet container
* Packaged as WAR
* spring-webmvc or spring-webflux dependency
* Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions
**Spring Cloud Function unaffected versions:**
* 3.1.7
* 3.2.3
**This playbook will provide you with a first response kit which includes:**
* Hunting
* Panorama
* Prisma Cloud Compute
* XDR XQL queries - set the playbook input **RunXQLHuntingQueries** to 'True' if you would like the XQL to be executed via the playbook.
* XDR Alerts - Search for new incidents including one or more of Spring RCEs dedicated Cortex XDR signatures
* Remediation
* Mitigations
**Note:** You can execute this playbook using the Incidents view by creating a new incident or by using a dedicated job to schedule the playbook execution.
**Additional resources:**
[Spring Framework RCE](https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement)
[CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild
](https://unit42.paloaltonetworks.com/cve-2022-22965-springshell/)
SpyCloud - Breach Investigation [SpyCloudEnterpriseProtection] — SpyCloud Breach playbook gets executed on the occurrence of the incident SpyCloud Breach Data type.
SpyCloud - Malware Incident Enrichment [SpyCloudEnterpriseProtection] — SpyCloud Malware Playbook executes the spycloud-compass-device-data command when any incident of the SpyCloud Malware Data type is created, and sets the corresponding incident field.
Suspicious Domain Hunting Incident Handling [SuspiciousDomainHunting] — This playbook process "Suspicious Domain Hunting" incidents generated by the CertStream integration.
Symantec block Email [Symantec_Messaging_Gateway] — This playbook will block email address at your email gateway.
T1036 - Masquerading [Core] — This playbook handles masquerading alerts based on the MITRE T1036 technique.
An attacker might leverage Microsoft Windows well-known image names to run malicious processes without being caught.
**Attacker's Goals:**
An attacker is attempting to masquerade as standard windows images by using a trusted name to execute malicious code.
**Investigative Actions:**
Investigate the executed process image and verify if it is malicious using:
* XDR trusted signers
* VT trusted signers
* VT detection rate
* NSRL DB
**Response Actions**
The playbook's first response action is a containment plan which is based on the initial data provided within the alert. In that phase, the playbook will execute:
* Auto block indicators
* Auto file quarantine
* Manual endpoint isolation
When the playbook executes, it checks for additional activity using the Endpoint Investigation Plan playbook, and another phase, which includes containment and eradication, is executed.
This phase will execute the following containment actions:
* Manual block indicators
* Manual file quarantine
* Auto endpoint isolation
And the following eradication actions:
* Manual process termination
* Manual file deletion
* Manual reset of the user’s password
External resources:
[MITRE Technique T1036](https://attack.mitre.org/techniques/T1036/)
[Possible Microsoft process masquerading](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Possible-Microsoft-process-masquerading)
T1059 - Command and Scripting Interpreter [Core] — This playbook handles command and scripting interpreter alerts based on the MITRE T1059 technique.
An attacker might abuse command and script interpreters to execute commands, scripts, or binaries.
Most systems come with some kind of built-in command line interface and scripting capabilities. For example, macOS and Linux distributions include some form of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
**Attacker's Goals:**
An attacker can abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in initial access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. An attacker may also execute commands through interactive terminals/shells, as well as utilize various remote services to achieve remote execution.
**Analysis**
Due to the nature of this technique and the usage of built-in command line interfaces, the first step of the playbook is to analyze the command line.
The command line analysis does the following:
- Checks and decodes base64
- Extracts and enriches indicators from the command line
- Checks specific arguments for malicious usage
**Investigative Actions:**
The playbook checks for additional activity using the 'Endpoint Investigation Plan' playbook and utilizes the power of insight alerts.
**Response Actions**
After analyzing the data, the playbook's first response action is to contain the threat based on the initial data provided within the alert. In this phase, the playbook will:
* Isolate the endpoint based on playbook inputs.
When the playbook proceeds, it checks for additional activity using the 'Endpoint Investigation Plan' playbook. It then continues with the next stage, which includes, containment and eradication.
This phase executes the following containment actions:
* Automatically isolates the endpoint
It then continues with the following eradication actions:
* process termination
TIE - IOC Hunt [McAfee-TIE] — Hunt for sightings of MD5, SHA1 and/or SHA256 hashes on endpoints, using McAfee TIE (requires ePO as well).
Input:
* Hash (default, takes all deferent hashes from context)
Output:
* All agents that files with "Hash" has been executed on (TIE)
* Enrich Agents info from ePO
TIM - Add All Indicator Types To SIEM [TIM_SIEM] — This playbook runs sub playbooks that send indicators to your SIEM. To select the indicators you want to add, go to playbook inputs, choose “from indicators” and set your query. For example tags:approved_black, approved_white etc. The purpose of the playbook is to send to SIEM only indicators that have been processed and tagged accordingly after an automatic or manual review process. The default playbook query is"
(type:ip or type:file or type:Domain or type:URL) -tags:pending_review and (tags:approved_black or tags:approved_white or tags:approved_watchlist)"
In case more indicator types need to be sent to the SIEM, the query must be edited accordingly.
TIM - Add Bad Hash Indicators To SIEM [TIM_SIEM] — This playbook recives indicators from its parent playbook
and provides the indicators as inputs for the sub-playbooks that push the indicators
to the SIEM.
TIM - Add Domain Indicators To SIEM [TIM_SIEM] — This playbook receives indicators from its parent playbook and provides the indicators as inputs for the sub-playbooks that push the indicators to the SIEM.
TIM - Add IP Indicators To SIEM [TIM_SIEM] — TIM playbook - This playbook receives indicators from its parent playbook
and provides the indicators as inputs for the sub-playbooks that push the indicators
to your SIEM.
TIM - Add Url Indicators To SIEM [TIM_SIEM] — TIM playbook - This playbook receives indicators from its parent playbook
and provides the indicators as inputs for the sub-playbooks that push the indicators
to your SIEM.
TIM - ArcSight Add Bad Hash Indicators [ArcSightESM] — This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to an ArcSight Active List. The Active List ID should be defined in the playbook inputs, as well as the field name in the Active list to which to add the indicators.
TIM - ArcSight Add Domain Indicators [ArcSightESM] — This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to an ArcSight Active List. The Active List ID should also be defined in the playbook inputs, as well as the field name in the Active list to add to.
TIM - ArcSight Add IP Indicators [ArcSightESM] — This playbook receives indicators from its parent playbook and provides the indicators as inputs for the sub-playbooks that push the indicators to SIEM.
TIM - ArcSight Add Url Indicators [ArcSightESM] — This playbook queries indicators based on a pre-defined
query or results from a parent playbook and adds the resulting indicators to an ArcSight
Active List. The Active List ID should also be defined in the playbook inputs as well as the field name in the Active list to add to.
TIM - Indicator Auto Processing [TIM_Processing] — This playbook uses several sub playbooks to process and tag indicators, which is used to identify indicators that shouldn't be added to block list. For example IP indicators that belong to business partners or important hashes we wish to not process. Additional sub playbooks can be added for improving the business logic and tagging according to the user's needs. This playbook doesn't have its own indicator query as it processes indicators provided by the parent playbook query. To enable the playbook, provide the relevant list names in the sub playbook indicators, such as the ApprovedHashList, OrganizationsExternalIPListName, BusinessPartnersIPListName, etc. Also be sure to append the results of additional sub playbooks to Set indicators to Process Indicators for the additional playbooks results to be in the outputs.
TIM - Indicator Relationships Analysis [TIM_Processing] — This playbook is designed to assist with a security investigation by providing an analysis of indicator relationships. The following information is included:
- Indicators of compromise (IOCs) related to the investigation.
- Attack patterns related to the investigation.
- Campaigns related to the investigation.
- IOCs associated with the identified campaigns.
- Reports containing details on the identified campaigns.
TIM - Indicators Exclusion By Related Incidents [TIM_Processing] — This playbooks allows you to exclude indicators according to the number of incidents the indicator is related to. The indicator query is "investigationsCount:>=X" where X is the number of related incidents to the indicator that you set. Excluded indicators are located in the Cortex XSOAR exclusion list and are removed from all of their related incidents and future ones. The purpose of excluding these indicators is to reduce the amount internal and common indicators appearing in many incidents and showing only relevant indicators. Creating exclusions can also accelerate performance.
TIM - Intel Tracking [TIMCampaignTracking] — Track threat actors and campaigns by uploading threat intelligence in the form of briefs and IOCs. Add notes and find IOCs in related incidents.
TIM - Process AWS indicators [FeedAWS] — This playbook handles the tagging of AWS indicators. Specify the tag to apply to these indicators in the playbook inputs. An example tag will be approved_allow. If no inputs are specified, the indicators will be tagged for manual review. The user can specify whether a manual review incident is required.
TIM - Process Azure indicators [FeedAzure] — This playbook handles the tagging of Azure indicators. Specify the tag to apply to these indicators in the playbook inputs. An example tag will be approved_allow. If no inputs are specified, the indicators will be tagged for manual review. The user can specify whether a manual review incident is required.
TIM - Process CIDR Indicators By Size [TIM_Processing] — This playbook processes CIDR indicators of both IPV4 and IPV6. By specifying in the inputs the maximum number of hosts allowed per CIDR, the playbook tags any CIDR that exceeds the number as pending_review. If the maximum CIDR size is not specified in the inputs, the playbook does not run.
TIM - Process Domain Age With Whois [Whois] — This playbook compares the domain creation time against a provided time value such as one month ago. The period can be configured within the playbook inputs MinimumAgeOfDomainMonths or MinimumAgeOfDomainHours. The playbook calculates the timestamp for the relevant period and compares it to the domain creation time value provided by Whois. The domains are outputted accordingly if they were created before or after the compared time, respectively.
TIM - Process Domain Registrant With Whois [Whois] — This playbook compares the domain registrant against the Cortex XSOAR list of approved registrants provided in the inputs. A registrant is the company or entity that owns the domain.
TIM - Process Domains With Whois [Whois] — This playbook uses several sub playbooks to process and tag indicators based on the results of the Whois tool.
TIM - Process Indicators - Fully Automated [TIM_Processing] — This playbook tags indicators ingested from high reliability feeds. The playbook is triggered due to a Cortex XSOAR job. The indicators are tagged as approved_allow, approved_block, approved_watchlist. The tagged indicators will be ready for consumption for 3rd party systems such as SIEM, EDR etc.
TIM - Process Indicators - Manual Review [TIM_Processing] — This playbook tags indicators ingested by feeds that require manual approval. The playbook is triggered due to a job. The indicators are tagged as requiring a manual review. The playbook optionally concludes with creating a new incident that includes all of the indicators that the analyst must review.
To enable the playbook, the indicator query needs to be configured. An example query is a list of the feeds whose ingested indicators should be manually reviewed. For example, sourceBrands:"Feed A" or sourceBrands:"Feed B".
TIM - Process Indicators Against Approved Hash List [TIM_Processing] — This playbook checks if file hash indicators exist in a Cortex XSOAR list. If the indicators exist in the list, they are tagged as approved_hash.
TIM - Process Indicators Against Business Partners IP List [TIM_Processing] — This playbook processes indicators to check if they exist in a Cortex XSOAR list containing business partner IP addresses, and tags the indicators accordingly.
TIM - Process Indicators Against Business Partners URL List [TIM_Processing] — This playbook processes indicators to check if they exist in a Cortex XSOAR list containing business partner urls, and tags the indicators accordingly. To enable the playbook, provide a Cortex XSOAR list name containing business partner urls.
TIM - Process Indicators Against Organizations External IP List [TIM_Processing] — This playbook processes indicators to check if they exist in a Cortex XSOAR list containing the organizational External IP addresses or CIDR, and tags the indicators accordingly.
TIM - Process Office365 indicators [FeedOffice365] — This playbook handles the tagging of Office365 indicators. Specify the tag to apply to these indicators in the playbook inputs. An example tag will be approved_allow. If no inputs are specified, the indicators will be tagged for manual review. The user can specify whether a manual review incident is required.
TIM - QRadar Add Bad Hash Indicators [QRadar] — This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
TIM - QRadar Add Domain Indicators [QRadar] — This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
TIM - QRadar Add IP Indicators [QRadar] — This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
TIM - QRadar Add Url Indicators [QRadar] — This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
TIM - Review Indicators Manually [TIM_Processing] — This playbook helps analysts manage the manual process of reviewing indicators. The playbook indicator query is set to search for indicators that have the 'pending review' tag. The playbook's layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags 'such as, 'approved_block', 'approved_allow', etc. Once the analyst completes their review, the playbook can optionally send an email with a list of changes done by the analyst which haven't been approved. Once complete, the playbook removes the 'pending review' tag from the indicators.
TIM - Review Indicators Manually For Allowlisting [TIM_Processing] — This playbook helps analysts manage the manual process of adding indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query is set to search for indicators that have the 'allowlist_review' tag. The playbooks layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags such as, 'approved_block', 'approved_allow', etc. Once the analyst completes the review, the playbook can optionally send an email with a list of changes done by the analyst which haven't been approved. Once complete, the playbook removes the 'allowlist review' tag from the indicators.
TIM - Run Enrichment For All Indicator Types [TIM_Processing] — This playbook performs enrichment on indicators
based on playbook query, as specified in the playbook
inputs. This playbook needs to be used with caution as it might use up the user
enrichment integration's API license when running enrichment for large amounts of
indicators. Example queries can be "tags:example_tag" for indicators with a specific tag. For a specific feed name"
the query will be "sourceBrands:example_feed". For a specifc reputation the query will be "reputation:None" etc.
TIM - Run Enrichment For Domain Indicators [TIM_Processing] — This playbook processes indicators by enriching indicators based on the indicator feed's reputation, as specified in the playbook inputs. This playbook needs to be used with caution as it might use up the user enrichment integration's API license when running enrichment for large amounts of indicators.
TIM - Run Enrichment For Hash Indicators [TIM_Processing] — This playbook processes indicators by enriching indicators
based on the indicator feed's reputation, as specified in the playbook
inputs. This playbook needs to be used with caution as it might use up the user
enrichment integration's API license when running enrichment for large amounts of
indicators.
TIM - Run Enrichment For IP Indicators [TIM_Processing] — This playbook processes indicators by enriching indicators
based on the indicator feed's reputation, as specified in the playbook
inputs. This playbook needs to be used with caution as it might use up the user
enrichment integration's API license when running enrichment for large amounts of
indicators.
TIM - Run Enrichment For Url Indicators [TIM_Processing] — This playbook processes indicators by enriching indicators
based on the indicator feed's reputation, as specified in the playbook
inputs. This playbook needs to be used with caution as it might use up the user
enrichment integration's API license when running enrichment for large amounts of
indicators.
TIM - Update Indicators Organizational External IP Tag [TIM_Processing] — This playbook checks if an indicator with a tag of organizational_external_ip has been updated and keeps/removes the tag according to the check results.
Tanium - Ask Question [Tanium] — This playbook used generic polling to gets question result.
Threat Hunting - Chronicle [GoogleChronicleBackstory] — Use this playbook to investigate and remediate suspicious IOC domain matches with recent activity found in the enterprise. This playbook also creates indicators for the entities fetched, as well as investigating and enriching them.
Supported Integrations:
- Chronicle
- Google SecOps
- Whois
Threat Hunting - Generic [CommonPlaybooks] — This playbook enables threat hunting for IOCs in your enterprise. It currently supports the following integrations:
- Splunk
- Qradar
- Pan-os
- Cortex Data Lake
- Autofocus
- Microsoft 365 Defender
Ticket Management - Generic [CommonPlaybooks] — `Ticket Management - Generic` allows you to open new tickets or update comments to the existing ticket in the following ticketing systems:
-ServiceNow
-Zendesk
using the following sub-playbooks:
-`ServiceNow - Ticket Management`
-`Zendesk - Ticket Management`
Trellix Email Security Cloud - Indicators Hunting [FireEyeETP] — This playbook queries Trellix Email Security - Cloud for indicators such as domains, IP addresses, sender and recipient email addresses.
Separate searches are conducted for each type of indicator in the playbook.
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Trello - Generic [Trello] — A generic extract and enrichment playbook for incidents based on Trello Card data.
Trello Set Severity [Trello] — Updates the Severity of a trello card by setting, and creating if required, a Trello Label.
Trend Micro CAS - Indicators Hunting [TrendMicroCAS] — In this playbook, the 'trendmicro-cas-email-sweep' command is used to automatically hunt for and detect IOCs within email messages protected by Cloud App Security (CAS).
Note that multiple search values should be separated by commas only (without spaces or any special characters).
Supported IOCs for this playbook:
- IP Addresses
- CIDR
- File Name
- File Type
- SHA1
- URL
- Domain
- Email Addresses
Separate searches are conducted for each type of indicator in the playbook.
Tufin - Enrich IP Address(es) [Tufin] — Enrich a single IP using SecureTrack. Returns information such as the associated zones, network objects and policies for the address, and if the address is network device.
Tufin - Enrich Source & Destination IP Information [Tufin] — Enrich source and destination IP information using SecureTrack. Returns information such as the associated zones, network objects and policies for the addresses, if the addresses are network devices, and a topology map from source to destination.
Tufin - Get Network Device Info by IP Address [Tufin] — Use a device's IP address to gather information about the device, including basic device information, USP zone(s), and policies related to the device.
Tufin - Investigate Network Alert [Tufin] — Example Playbook utilizing the Tufin integration to enrich a network alert and perform containment, if needed.
Requires the following incident details: Source IP, Destination IP, Destination Ports
URL Enrichment - Generic [DeprecatedContent] — Deprecated. Use "URL Enrichment - Generic v2" playbook instead. Enrich URL using one or more integrations.
URL enrichment includes:
* Verify URL SSL
* Threat information
* URL reputaiton
* Take URL screenshot
URL Enrichment - Generic v2 [CommonPlaybooks] — Enrich URLs using one or more integrations.
URL enrichment includes:
* SSL verification for URLs.
* Threat information.
* Providing of URL screenshots.
* URL Reputation using !url.
URL Enrichment - Infoblox Cloud [InfobloxBloxOne] — This playbook enriches URL with the dossier and TIDE data using Infoblox Threat Defense with DDI integration.
URL Private Scanning - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook performs private URL scanning and analyses the URL based on GTI assessment parameters such as Threat Score, Verdict, and Severity. Based on these parameters, the playbook blocks the URL.
URL Scan - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook scans URLs using GTI private scanning and evaluates the results against GTI assessment parameters, including Threat Score, Severity, and Verdict. URLs that meet the defined high-risk criteria are returned for further action.
US - Breach Notification [BreachNotification-US] — This playbook is triggered by a breach notification incident and then proceeds to the breach notification playbook for the relevant state.
DISCLAIMER: Please consult with your legal team before implementing this playbook.
Unblock Indicator - Infoblox Cloud [InfobloxBloxOne] — This playbook unblocks the given IP or domain by adding it to the given allow type custom list of the Infoblox Cloud platform.
Unblock Indicator - Infoblox NIOS [Infoblox] — This playbook unblocks the given Indicator by deleting its RP Zone rule from Infoblox NIOS platform.
Unisolate Endpoint - Generic [CommonPlaybooks] — This playbook unisolates endpoints according to the endpoint ID or host name provided in the playbook.
It currently supports the following integrations:
- Carbon Black Response
- Cortex XDR
- Crowdstrike Falcon
- FireEye HX
- Cybereason
- Microsoft Defender For Endpoint.
Unzip File [CommonPlaybooks] — This playbook checks whether a file has an extension that supports unzipping, and unzips the file.
Update Incident Status And Fetch Attachments - Securonix [Securonix] — This playbook fetches the attachments for the incident. Also, it updates the state of the Securonix incident based on the configuration provided in integration configuration.
Update Live Briefs - Dataminr Pulse [DataminrPulse] — This playbook will update the previously fetched Dataminr Pulse ReGenAI incidents with the latest briefs.
Update Or Remove Assets - RiskIQ Digital Footprint [RiskIQDigitalFootprint] — Using various user inputs, this playbook checks if the user wants to update or remove an asset, and performs the respective actions.
Supported integration:
- RiskIQ Digital Footprint
User Investigation - Generic [CommonPlaybooks] — This playbook performs an investigation on a specific user, using queries and logs from SIEM, Identity management systems, XDR, and firewalls.
Supported Integrations:
-Okta
-Splunk
-QRadar
-Azure Log Analytics
-PAN-OS
-XDR / Core By Palo Alto Networks.
Vulnerability Enrichment and Ticket Creation - Google Threat Intelligence [GoogleThreatIntelligence] — This playbook enriches CVE information using the Google Threat Intelligence enrichment command and determines the appropriate action for each CVE based on key risk factors. For every extracted CVE, the playbook evaluates the Exploitation State, Risk Rating, and CVSS scores to decide whether to create a ServiceNow ticket using the "ServiceNow v2" integration or route the incident for analyst review.
Vulnerability Handling - Nexpose [Rapid7_Nexpose] — Manage vulnerability remediation using Nexpose data, and optionally enrich data with 3rd-party tools.
Before you run this playbook, run the "Vulnerability Management - Nexpose (Job)" playbook.
Vulnerability Handling - Qualys [DeprecatedContent] — Deprecated. Manage vulnerability remediation using Qualys data, and optionally enrich data with 3rd-party tools.
Before you run this playbook, run the "Vulnerability Management - Qualys (Job)" playbook.
Vulnerability Management - Nexpose (Job) [Rapid7_Nexpose] — Deprecated. No available replacement. Manage assets vulnerabilities using Nexpose.
This playbook runs as a job, and by default creates incidents of type "Vulnerability" based on assets and vulnerabilities.
The incidents are created by querying Nexpose for the input assets vulnerability list.
You can define the minimum severity (minSeverity) that incidents are created for.
Duplicate incidents are not created for the same asset ID and the Nexpose ID.
This playbook is a part of a series of playbooks for Nexpose vulnerability management and remediation.
For this series of playbooks to run successfully, create a Job and do the following:
1. Assign this playbook to the Job
2. Enter the relevant assets' hostnames in the playbook inputs (comma separated list).
3. Associate the "Vulnerability" type incident to the "Vulnerability Handling - Nexpose" playbook.
Vulnerability Management - Qualys (Job) [qualys] — Deprecated. Use the `Vulnerability Management - Qualys (Job) - V2` playbook instead.
Use the latest Qualys report to manage vulnerabilities.
This playbook runs as a job, and by default creates incidents of type "Vulnerability" based on assets and vulnerabilities.
The incidents are created from the latest version of the report determined by the report timestamp.
You can define the minimum severity (minSeverity) that incidents are created for.
Duplicate incidents are not created for the same asset ID and QID.
This playbook is a part of a series of playbooks for Qualys vulnerability management and remediation.
For this series of playbooks to run successfully, create a Job and do the following:
1. Assign this playbook to the Job
2. Enter the Qualys XML report name into the "Details" field
3. Associate the "Vulnerability" type incident to the "Vulnerability Handling - Qualys" playbook.
Vulnerability Management - Qualys (Job) - V2 [qualys] — Use the latest Qualys report to manage vulnerabilities.
This playbook runs as a job, and by default creates incidents of type "Vulnerability" based on assets and vulnerabilities.
The incidents are created from the latest version of the report determined by the report timestamp.
You can define the minimum severity (minSeverity) that incidents are created for.
Duplicate incidents are not created for the same asset ID and QID.
This playbook is a part of a series of playbooks for Qualys vulnerability management and remediation.
For this series of playbooks to run successfully, create a Job and do the following:
1. Assign this playbook to the Job
2. Enter the Qualys XML report name into the "Details" field
3. Associate the "Vulnerability" type incident to the "Vulnerability Handling - Qualys" playbook.
Wait Until Datetime [CommonPlaybooks] — Pauses execution until the date and time that was specified in the plabyook input is reached.
Wait Until Windows Host Online [Ansible_Powered_Integrations] — Deprecated. Use "Wait Until Windows Host Online v2" playbook from the Ansible Microsoft Windows Pack instead.
Wait Until Windows Host Online v2 [AnsibleMicrosoftWindows] — Pauses execution until the Windows host responds to a ping over WinRM.
WhisperGate and HermeticWiper & CVE-2021-32648 [WhisperGateCVE-2021-32648] — - On January 14th, 2022, reports began on a malware operation dubbed "WhisperGate" targeting multiple -organizations in Ukraine.
- On February 23, 2022, a new wiper malware known as "HermeticWiper" was disclosed by several cybersecurity researchers. The new wiper "HermeticWiper" was also being used against organizations in Ukraine.
CVE-2021-32648 vulnerability has a CVSS score of 9.1 and was found in octobercms, which is a CMS platform based on the Laravel PHP Framework.
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
The issue has been patched in Build 472 and v1.1.5.
**The playbook includes the following tasks:**
- Collect related known indicators from Unit 42, CISA and Malware News blog.
- Search for possible vulnerable servers using Xpanse.
- Indicators and exploitation patterns hunting using PAN-OS, Cortex XDR and SIEM products.
- Block indicators automatically or manually.
**Mitigations:**
* October CMS security recommendations
* Deploy YARA detection Rules.
More information:
[UNIT42 Blog - Ongoing Russia and Ukraine Cyber Conflict](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)
[Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon and Website Defacement](https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/)
[Microsoft Blog](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/)
[CVE-2021-32648 NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-32648#vulnCurrentDescriptionTitle)
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
WildFire Malware [Core] — This playbook handles WildFire Malware alerts.
It performs enrichment on the different alert entities and establishes a verdict.
For a possible true positive alert, the playbook performs further investigation for related IOCs and executes a containment plan.
Wildfire Detonate and Analyze File [Palo_Alto_Networks_WildFire] — This playbook uploads, detonates, and analyzes files for the Wildfire sandbox.
Windows Application Deployment [Ansible_Powered_Integrations] — Deprecated. Use "Windows Application Deployment v2" playbook from the Ansible Microsoft Windows Pack instead.
Windows Application Deployment v2 [AnsibleMicrosoftWindows] — This playbook helps an operator install Windows applications to workstations using the Chocolatey package manager.
XCloud Alert Enrichment [CloudIncidentResponse] — This playbook is responsible for data collection and enrichment.
The playbook collects or enriches the following data:
- Account enrichment
- Network enrichment
-Attacker IP
-Geolocation
-ASN
XCloud Cryptojacking [CloudIncidentResponse] — Investigates a Cortex XDR incident containing Cloud Cryptojacking related alert.
The playbook supports AWS, Azure, and GCP and executes the following:
- Cloud enrichment:
-Collects info about the involved resources
-Collects info about the involved identities
-Collects info about the involved IPs
- Verdict decision tree
- Verdict handling:
-Handle False Positives
-Handle True Positives
-Cloud Response - Generic sub-playbook.
- Notifies the SOC if a malicious verdict was found
XCloud Cryptojacking - Set Verdict [CloudIncidentResponse] — This playbook sets the alert's verdict as malicious if one of the following conditions is true:
1. If the source IP address is malicious
2. If the incident includes both "Unusual allocation of multiple cloud compute resources" AND "Cloud identity reached a throttling API rate" (medium/high severity)
3. If the incident includes both "Unusual allocation of multiple cloud compute resources" AND "Suspicious heavy allocation of compute resources - possible mining activity"
4. If the incident includes "Unusual allocation of multiple cloud compute resources" with medium/high severity, the source ASN isn't known, and the source IP isn't known as well.
5. If the incident includes both "Unusual allocation of multiple cloud compute resources" AND "A cloud compute instance was created in a dormant region"
If none of the conditions is true, the playbook will wait for an analyst's decision.
Xpanse Incident Handling - Generic [ExpanseV2] — Deprecated. Use Xpanse - Alert Handler playbook instead.
A generic playbook for handling Xpanse issues.
The logic behind this playbook is to work with an internal exclusions list which will help the analyst to get to a decision or, if configured, close incidents automatically.
The phases of this playbook are:
1) Check if assets (IP, Domain or Certificate) associated with the issue are excluded in the exclusions list and optionally, close the incident automatically.
2) Optionally, enrich indicators and calculate the severity of the issue, using sub-playbooks.
3) Optionally, allow the analyst to add associated assets (IP, Domain or Certificate) to the exclusions list.
4) Tag associated assets.
5) Update the status of the issue.
YARA - File Scan [Yara] — A playbook to run YARA scan against uploaded file.
To run the playbook, provide the YARA rule content and the entry ID of the file you intend to scan.
ZTAP Alert [ZeroTrustAnalyticsPlatform] — This playbok is triggered by fetching escalated ZTAP Alerts.
The playbook fetches newly escalated alerts.
Then, the playbook performs enrichment on the incident's indicators.
Lastly, it adds comments/logs as Evidence.
Zendesk - Ticket Management [Zendesk] — `Zendesk - Ticket Management` allows you to open a new ticket or comment on an existing ticket.
panorama_content_update_test [PAN-OS] — This playbook pulls Panorama content update file from shared SMB folder, uploads it to the Panorama server and installs it. It also uploads the content file to SCP folder for future use of the Panorama Device Deployment content updates engine which can be scheduled to pull the files automatically from SCP server.
This playbook should run in "Air Gap internal network" and works together with "Air Gap - Panorama Content Update Sender - External" playbook that runs in "Air Gap external network".
This playbook should be run as part of a Job in the internal network.
Playbook inputs:
panorama_admin_email - email address of the panorama admin for sending the output of the update.
smbshare - the SMB share of the content update folder. Example: Folder
scpwildfire - scp folder for wildfire content update file. Example: /home/demisto/Folder/wildfire
scpcontents - scp folder for contents (antivirus and apps) content update file. Example: /home/demisto/Folder/contents
scpantivirus - scp folder for Anti-Virus content update file. Example: /home/demisto/Folder/antivirus
smbpath - SMB path to the content files files. Example: Content
xsoar-data-collection-response-tracking [XsoarWebserver] — This playbook tracks the user responses and resends the emails to recipients who have not responded
xsoarwebserver-email-acknowledgement [XsoarWebserver] — Playbook to demonstrate the features of XSOAR-Web-Server. It sends an html email to a set of users up to 2 times. The email can contain multiple html links, that the users can click and the response will be available in the context. This playbook sets up the webserver to handle http get requests
xsoarwebserver-email-data-collection [XsoarWebserver] — Playbook to demonstrate the features of XSOAR-Web-Server. It sends an html email to a set of users up to 2 times. The email can contain multiple html links, that the users can click and the response will be available in the context