Suspicious Domain Hunting Incident Handling
This playbook process "Suspicious Domain Hunting" incidents generated by the CertStream integration.
- Pack
- SuspiciousDomainHunting
- Tasks
- 32
Inputs
- similarityMaxThreshold — The minimum threshold value for malicious verdict
- similarityMinThreshold — The minimum threshold value for suspicious verdict
- contactEmail — Email address to be used as contact email when sending a takedown request email
Commands used
- closeInvestigation
- domain
- expireIndicators
- rasterize
- setIndicators
- url
- whois