Trend Micro CAS - Indicators Hunting

In this playbook, the 'trendmicro-cas-email-sweep' command is used to automatically hunt for and detect IOCs within email messages protected by Cloud App Security (CAS). Note that multiple search values should be separated by commas only (without spaces or any special characters). Supported IOCs for this playbook: - IP Addresses - CIDR - File Name - File Type - SHA1 - URL - Domain - Email Addresses Separate searches are conducted for each type of indicator in the playbook.

Pack
TrendMicroCAS
Tasks
42

Inputs

Outputs

Commands used