PhishLabs - Populate Indicators
This playbook can be used in a job to populate indicators from PhishLabs, according to a defined period of time.
- Pack
- PhishLabs
- Tasks
- 5
Inputs
- Since — Get indicators within this duration (from now).
- Limit — Maximum number of indicators.
- Remove protocol — Removes the protocol part from indicators, when the rule can be applied.
- Remove query — Removes the query string part from indicators, when the rules can be applied.
- Indicator type — Filter the indicators by indicator type.
Commands used
- closeInvestigation