Check Point - Phishing Takedown

Automates or semi-automates the takedown of high-confidence phishing websites detected by Cyberint. The playbook evaluates the confidence and severity of a Cyberint phishing-website alert, submits a takedown request via the Cyberint Takedown API (automatically or after analyst approval), polls the takedown request until it reaches a terminal status, and annotates the incident and notifies the SOC of the outcome. Requires the Cyberint Takedown integration to be configured.

Pack
Cyberint
Tasks
17

Inputs

Outputs

Commands used