Autofocus - Hunting And Threat Detection

Deprecated. No available replacement. The playbook queries the PANW Autofocus session and samples log data for file and traffic indicators, such as SHA256, SHA1, MD5, IP addresses, URLs, and domains. A simple search mode queries Autofocus based on the indicators specified in the playbook inputs. Advanced queries can also use with multiple query parameters, but require all field names, parameters, and operators (JSON format) to be specified. We recommended using the Autofocus UI to create an advanced query, exporting it, and pasting it into the relevant playbook inputs. Note that multiple search values should be separated by commas only (without spaces or any special characters).

Pack
AutoFocus
Tasks
5

Inputs

Outputs