IP Enrichment - Internal - Generic v2
Enrich Internal IP addresses using one or more integrations. - Resolve IP address to hostname (DNS) - Separate internal and external IP addresses - Get host information for IP addresses.
- Pack
- CommonPlaybooks
- Tasks
- 11
Inputs
- IP — The IP address to enrich.
- InternalRange — A comma-separated list of IP address ranges (in CIDR notation). Use this list to check if an IP address is found within a set of IP address ranges. For example: "172.16.0.0/12,10.0.0.0/8,192.168.0.0/16" (without quotes).
- ResolveIP — Whether to convert the IP address to a hostname using a DNS query (True/False). The default value is true.
- ExecutedFromParent — Whether to execute common logic, like the classification of IP addresses to ranges and resolving, in the the main (IP Enrichment - Generic v2) enrichment playbook, instead of in the sub-playbooks. Possible values are: True, False. Setting this to True will execute the relevant commands in the main playbook instead of executing them in both sub-playbooks. Set this to True in the parent playbook if you are using the parent playbook, as opposed to using the sub-playbooks directly in your playbooks, as this will improve the performance of the playbook and reduce the overfall size of the incident.
- Hostnames — Hostnames to enrich. If the ExecutedFromParent playbook is set to True in the IP - Enrichment - Generic v2 playbook, and an internal IP resolves to an endpoint hostname that you want to enrich, the hostnames defined here will be used.
Outputs
- IP — The IP objects.
- DBotScore — Indicator, Score, Type and Vendor.
- Endpoint — The endpoint's object.
- Endpoint.Hostname — The hostname to enrich.
- Endpoint.OS — Endpoint operating system.
- Endpoint.IP — A list of endpoint IP addresses.
- Endpoint.MAC — A list of endpoint MAC addresses.
- Endpoint.Domain — Endpoint domain name.
- Endpoint.ID — The endpoint ID.
- Endpoint.Status — The endpoint status.
- Endpoint.IsIsolated — The endpoint isolation status.
- Endpoint.MACAddress — The endpoint MAC address.
- Endpoint.Vendor — The integration name of the endpoint vendor.
- Endpoint.Relationships — The endpoint relationships of the endpoint that was enriched.
- Endpoint.Processor — The model of the processor.
- Endpoint.Processors — The number of processors.
- Endpoint.Memory — Memory on this endpoint.
- Endpoint.Model — The model of the machine or device.
- Endpoint.BIOSVersion — The endpoint's BIOS version.
- Endpoint.OSVersion — The endpoint's operation system version.
- Endpoint.DHCPServer — The DHCP server of the endpoint.
- Endpoint.Groups — Groups for which the computer is listed as a member.
- ExtraHop.Device.Macaddr — The MAC Address of the device.
- ExtraHop.Device.DeviceClass — The class of the device.
- ExtraHop.Device.UserModTime — The time of the most recent update, expressed in milliseconds since the epoch.
- ExtraHop.Device.AutoRole — The role automatically detected by the ExtraHop.
- ExtraHop.Device.ParentId — The ID of the parent device.
- ExtraHop.Device.Vendor — The device vendor.
- ExtraHop.Device.Analysis — The level of analysis preformed on the device.
- ExtraHop.Device.DiscoveryId — The UUID given by the Discover appliance.
- ExtraHop.Device.DefaultName — The default name of the device.
- ExtraHop.Device.DisplayName — The display name of device.
- ExtraHop.Device.OnWatchlist — Whether the device is on the advanced analysis allow list.
- ExtraHop.Device.ModTime — The time of the most recent update, expressed in milliseconds since the epoch.
- ExtraHop.Device.IsL3 — Indicates whether the device is a Layer 3 device.
- ExtraHop.Device.Role — The role of the device.
- ExtraHop.Device.DiscoverTime — The time that the device was discovered.
- ExtraHop.Device.Id — The ID of the device.
- ExtraHop.Device.Ipaddr4 — The IPv4 address of the device.
- ExtraHop.Device.Vlanid — The ID of VLan.
- ExtraHop.Device.Ipaddr6 — The IPv6 address of the device.
- ExtraHop.Device.NodeId — The Node ID of the Discover appliance.
- ExtraHop.Device.Description — A user customizable description of the device.
- ExtraHop.Device.DnsName — The DNS name associated with the device.
- ExtraHop.Device.DhcpName — The DHCP name associated with the device.
- ExtraHop.Device.CdpName — The Cisco Discovery Protocol name associated with the device.
- ExtraHop.Device.NetbiosName — The NetBIOS name associated with the device.
- ExtraHop.Device.Url — Link to the device details page in ExtraHop.
- McAfee.ePO.Endpoint — The endpoint that was enriched.
- ActiveDirectory.ComputersPageCookie — An opaque string received in a paged search, used for requesting subsequent entries.
- ActiveDirectory.Computers — The information about the hostname that was enriched using Active Directory.
- ActiveDirectory.Computers.dn — The computer distinguished name.
- ActiveDirectory.Computers.memberOf — Groups for which the computer is listed.
- ActiveDirectory.Computers.name — The computer name.
- CrowdStrike.Device — The information about the endpoint.
- CarbonBlackEDR.Sensor.systemvolume_total_size — The size, in bytes, of the system volume of the endpoint on which the sensor is installed. installed.
- CarbonBlackEDR.Sensor.emet_telemetry_path — The path of the EMET telemetry associated with the sensor.
- CarbonBlackEDR.Sensor.os_environment_display_string — Human-readable string of the installed OS.
- CarbonBlackEDR.Sensor.emet_version — The EMET version associated with the sensor.
- CarbonBlackEDR.Sensor.emet_dump_flags — The flags of the EMET dump associated with the sensor.
- CarbonBlackEDR.Sensor.clock_delta — The clock delta associated with the sensor.
- CarbonBlackEDR.Sensor.supports_cblr — Whether the sensor supports Carbon Black Live Response (CbLR).
- CarbonBlackEDR.Sensor.sensor_uptime — The uptime of the process.
- CarbonBlackEDR.Sensor.last_update — When the sensor was last updated.
- CarbonBlackEDR.Sensor.physical_memory_size — The size in bytes of physical memory.
- CarbonBlackEDR.Sensor.build_id — The sensor version installed on this endpoint. From the /api/builds/ endpoint.
- CarbonBlackEDR.Sensor.uptime — Endpoint uptime in seconds.
- CarbonBlackEDR.Sensor.is_isolating — Boolean representing sensor-reported isolation status.
- CarbonBlackEDR.Sensor.event_log_flush_time — If event_log_flush_time is set, the server will instruct the sensor to immediately send all data before this date, ignoring all other throttling mechanisms. To force a host current, set this value to a value far in the future. When the sensor has finished sending its queued data, this value will be null.
- CarbonBlackEDR.Sensor.computer_dns_name — The DNS name of the endpoint on which the sensor is installed.
- CarbonBlackEDR.Sensor.emet_report_setting — The report setting of the EMET associated with the sensor.
- CarbonBlackEDR.Sensor.id — The ID of this sensor.
- CarbonBlackEDR.Sensor.emet_process_count — The number of EMET processes associated with the sensor.
- CarbonBlackEDR.Sensor.emet_is_gpo — Whether the EMET is a GPO.
- CarbonBlackEDR.Sensor.power_state — The sensor power state.
- CarbonBlackEDR.Sensor.network_isolation_enabled — Boolean representing the network isolation request status.
- CarbonBlackEDR.Sensor.systemvolume_free_size — The amount of free bytes on the system volume.
- CarbonBlackEDR.Sensor.status — The sensor status.
- CarbonBlackEDR.Sensor.num_eventlog_bytes — The number of event log bytes.
- CarbonBlackEDR.Sensor.sensor_health_message — Human-readable string indicating the sensor’s self-reported status.
- CarbonBlackEDR.Sensor.build_version_string — Human-readable string of the sensor version.
- CarbonBlackEDR.Sensor.computer_sid — Machine SID of this host.
- CarbonBlackEDR.Sensor.next_checkin_time — Next expected communication from this computer in server-local time and zone.
- CarbonBlackEDR.Sensor.node_id — The node ID associated with the sensor.
- CarbonBlackEDR.Sensor.cookie — The cookie associated with the sensor.
- CarbonBlackEDR.Sensor.emet_exploit_action — The EMET exploit action associated with the sensor.
- CarbonBlackEDR.Sensor.computer_name — NetBIOS name of this computer.
- CarbonBlackEDR.Sensor.license_expiration — When the license of the sensor expires.
- CarbonBlackEDR.Sensor.supports_isolation — Whether the sensor supports isolation.
- CarbonBlackEDR.Sensor.parity_host_id — The ID of the parity host associated with the sensor.
- CarbonBlackEDR.Sensor.supports_2nd_gen_modloads — Whether the sensor support modload of 2nd generation.
- CarbonBlackEDR.Sensor.network_adapters — A pipe-delimited list of IP,MAC pairs for each network interface.
- CarbonBlackEDR.Sensor.sensor_health_status — Self-reported health score, from 0 to 100. Higher numbers indicate a better health status.
- CarbonBlackEDR.Sensor.registration_time — Time this sensor was originally registered in server-local time and zone.
- CarbonBlackEDR.Sensor.restart_queued — Whether a restart of the sensor is queued.
- CarbonBlackEDR.Sensor.notes — The notes associated with the sensor.
- CarbonBlackEDR.Sensor.num_storefiles_bytes — Number of storefiles bytes associated with the sensor.
- CarbonBlackEDR.Sensor.os_environment_id — The ID of the OS environment of the sensor.
- CarbonBlackEDR.Sensor.shard_id — The ID of the shard associated with the sensor.
- CarbonBlackEDR.Sensor.boot_id — A sequential counter of boots since the sensor was installed.
- CarbonBlackEDR.Sensor.last_checkin_time — Last communication with this computer in server-local time and zone.
- CarbonBlackEDR.Sensor.os_type — The operating system type of the computer.
- CarbonBlackEDR.Sensor.group_id — The sensor group ID this sensor is assigned to.
- CarbonBlackEDR.Sensor.uninstall — When set, indicates that the sensor will be directed to uninstall on next check-in.
- PaloAltoNetworksXDR.Endpoint.endpoint_id — The endpoint ID.
- PaloAltoNetworksXDR.Endpoint.endpoint_name — The endpoint name.
- PaloAltoNetworksXDR.Endpoint.endpoint_type — The endpoint type.
- PaloAltoNetworksXDR.Endpoint.endpoint_status — The status of the endpoint.
- PaloAltoNetworksXDR.Endpoint.os_type — The endpoint OS type.
- PaloAltoNetworksXDR.Endpoint.ip — A list of IP addresses.
- PaloAltoNetworksXDR.Endpoint.users — A list of users.
- PaloAltoNetworksXDR.Endpoint.domain — The endpoint domain.
- PaloAltoNetworksXDR.Endpoint.alias — The endpoint's aliases.
- PaloAltoNetworksXDR.Endpoint.first_seen — First seen date/time in Epoch (milliseconds).
- PaloAltoNetworksXDR.Endpoint.last_seen — Last seen date/time in Epoch (milliseconds).
- PaloAltoNetworksXDR.Endpoint.content_version — Content version.
- PaloAltoNetworksXDR.Endpoint.installation_package — Installation package.
- PaloAltoNetworksXDR.Endpoint.active_directory — Active directory.
- PaloAltoNetworksXDR.Endpoint.install_date — Install date in Epoch (milliseconds).
- PaloAltoNetworksXDR.Endpoint.endpoint_version — Endpoint version.
- PaloAltoNetworksXDR.Endpoint.is_isolated — Whether the endpoint is isolated.
- PaloAltoNetworksXDR.Endpoint.group_name — The name of the group to which the endpoint belongs.
- PaloAltoNetworksXDR.Endpoint.count — Number of endpoints returned.
- Account.Username — The username in the relevant system.
- Account.Domain — The domain of the account.
- PaloAltoNetworksXDR.RiskyHost.type — Form of identification element.
- PaloAltoNetworksXDR.RiskyHost.id — Identification value of the type field.
- PaloAltoNetworksXDR.RiskyHost.score — The score assigned to the host.
- PaloAltoNetworksXDR.RiskyHost.reasons — The endpoint risk objects.
- PaloAltoNetworksXDR.RiskyHost.reasons.date created — Date when the incident was created.
- PaloAltoNetworksXDR.RiskyHost.reasons.description — Description of the incident.
- PaloAltoNetworksXDR.RiskyHost.reasons.severity — The severity of the incident.
- PaloAltoNetworksXDR.RiskyHost.reasons.status — The incident status.
- PaloAltoNetworksXDR.RiskyHost.reasons.points — The score.
- Core.Endpoint.endpoint_id — The endpoint ID.
- Core.Endpoint.endpoint_name — The endpoint name.
- Core.Endpoint.endpoint_type — The endpoint type.
- Core.Endpoint.endpoint_status — The status of the endpoint.
- Core.Endpoint.os_type — The endpoint OS type.
- Core.Endpoint.ip — A list of IP addresses.
- Core.Endpoint.users — A list of users.
- Core.Endpoint.domain — The endpoint domain.
- Core.Endpoint.alias — The endpoint's aliases.
- Core.Endpoint.first_seen — First seen date/time in Epoch (milliseconds).
- Core.Endpoint.last_seen — Last seen date/time in Epoch (milliseconds).
- Core.Endpoint.content_version — Content version.
- Core.Endpoint.installation_package — Installation package.
- Core.Endpoint.active_directory — Active directory.
- Core.Endpoint.install_date — Install date in Epoch (milliseconds).
- Core.Endpoint.endpoint_version — Endpoint version.
- Core.Endpoint.is_isolated — Whether the endpoint is isolated.
- Core.Endpoint.group_name — The name of the group to which the endpoint belongs.
- Core.RiskyHost.type — Form of identification element.
- Core.RiskyHost.id — Identification value of the type field.
- Core.RiskyHost.score — The score assigned to the host.
- Core.RiskyHost.reasons — The reasons for the risk level.
- Core.RiskyHost.reasons.date created — Date when the incident was created.
- Core.RiskyHost.reasons.description — Description of the incident.
- Core.RiskyHost.reasons.severity — The severity of the incident.
- Core.RiskyHost.reasons.status — The incident status.
- Core.RiskyHost.reasons.points — The score.
- IP.Address — The IP address.
- IP.InRange — Is the IP in the input ranges? (could be 'yes' or 'no).