Cortex XDR - Search and Compare Process Executions - XQL Engine

This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Cortex XDR - XQL Engine" integration to search for the given process executions and compare the command-line argument from the results to the command-line argument received from the playbook input. Note: Under the "Processes" input, the playbook should receive an array that contains the following keys: - value: *process name* - commands: *command-line arguments*

Pack
CortexXDR
Tasks
10

Inputs

Outputs

Commands used