TIM - QRadar Add Bad Hash Indicators
This playbook queries indicators based on a pre-defined query or results from a parent playbook, and adds the resulting indicators to a QRadar Reference Set. The Reference Set name must be defined in the playbook inputs.
- Pack
- QRadar
- Tasks
- 16
Inputs
- QRadarMd5ReferenceSetName — The name of the QRadar Md5 reference set to insert the data in to.
- QRadarSha1ReferenceSetName — The name of the QRadar Sha1 reference set to insert the data in to.
- QRadarSha256ReferenceSetName — The name of the QRadar Sha256 reference set to insert the data in to.
Commands used
- appendIndicatorField
- qradar-update-reference-set-value