Extract and Enrich Expanse Indicators
Deprecated. No available replacement. Subplaybook for Handle Expanse Incident playbooks. Extract and Enrich Indicators (CIDRs, IPs, Certificates, Domains and DomainGlobs) from Expanse Incidents. Enrichment is performed via enrichIndicators command and generic playbooks. Returns the enriched indicators.
- Pack
- ExpanseV2
- Tasks
- 37
Inputs
- Expanse Assets — Expanse Assets to Extract and Enrich.
- Create Indicators — Create Indicators for types that are not handled by AutoExtract, such as Certificates, Domains and DomainGlobs.
- Expanse IP — IP from the Expanse Incident.
Outputs
- Expanse.Certificate — Expanse Certificate Information
- Expanse.IPRange — Expanse IP Range
- Domain — The domain objects.
- DBotScore — Indicator, Score, Type, and Vendor.
- IP — The IP objects
- Endpoint — The Endpoint's object
- Expanse.Domain — Expanse Domain
- DomainDNSDetails — Domain DNS Details
Commands used
- createNewIndicator
- enrichIndicators
- expanse-get-certificate
- expanse-get-domain
- expanse-get-iprange