Rapid7 InsightIDR - Indicators Hunting

This playbook facilitates threat hunting and detection of IOCs within Rapid7 InsightIDR SIEM logs utilizing four sub-playbooks. The sub-playbooks query Rapid7 InsightIDR SIEM for different indicators including files, traffic, HTTP requests, and execution flows indicators. Note that multiple search values should be separated by commas only (without spaces or any special characters). Supported IOCs for this playbook: - MD5 - SHA1 - SHA256 - IP Address - URLDomain - Registry Value - Registry Key - Registry Hives - Command Line - File Name - Process Name - HTTP Request Methods - User Agent - Port Number - File Path - Geolocation - Email Address - CIDR - URI - Ja3 - FileType

Pack
Rapid7_InsightIDR
Tasks
10

Inputs

Outputs