TIM - Process Indicators Against Approved Hash List
This playbook checks if file hash indicators exist in a Cortex XSOAR list. If the indicators exist in the list, they are tagged as approved_hash.
- Pack
- TIM_Processing
- Tasks
- 10
Inputs
- ApprovedHashList — A Cortex XSOAR list containing approved hash values. Hash indicators that appear in the list are tagged as approved.
Outputs
- HashesInApprovedList — File hashes that are found in the approved_hash list.
- HashesNotInApprovedList — File hashes that are not found in the approved_hash list.
Commands used
- appendIndicatorField