TIM - ArcSight Add Bad Hash Indicators

This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to an ArcSight Active List. The Active List ID should be defined in the playbook inputs, as well as the field name in the Active list to which to add the indicators.

Pack
ArcSightESM
Tasks
16

Inputs

Commands used