Block Domain - Generic Deprecated

Deprecated. Use 'Block Domain - Generic v2' instead. This playbook blocks malicious Domains using all integrations that are enabled. Supported integrations for this playbook: * Zscaler * Symantec Messaging Gateway * FireEye EX * Trend Micro Apex One * Proofpoint Threat Response

Common Playbooks · 7 tasks · 2 inputs · 0 outputs

Details

IDBlock Domain - Generic
From Version5.5.0
Tasks7

README

Deprecated. Use ‘Block Domain - Generic v2’ instead. This playbook blocks malicious Domains using all integrations that are enabled.

Supported integrations for this playbook:

  • Zscaler
  • Symantec Messaging Gateway
  • FireEye EX
  • Trend Micro Apex One
  • Proofpoint Threat Response

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Block Domain - FireEye Email Security
  • Block Domain - Proofpoint Threat Response
  • Block Domain - Zscaler
  • Block Domain - Trend Micro Apex One
  • Block Domain - Symantec Messaging Gateway

Integrations

This playbook does not use any integrations.

Scripts

This playbook does not use any scripts.

Commands

This playbook does not use any commands.

Playbook Inputs


Name Description Default Value Required
Domain The Domain to block.   Optional
DomainBlackListID The Domain List ID to add the Domain to.
product: Proofpoint Threat Response
  Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Block Domain - Generic

Inputs

  • Domain — The Domain to block.
  • DomainBlackListID — The Domain List ID to add the Domain to. product: Proofpoint Threat Response

Flowchart

Start Start Block Domain - Symantec Messaging Gateway - Block Domain - Symantec Messaging Gateway Block Domain - Symantec M... Block Domain - Symantec Messa... Block Domain - FireEye Email Security - Block Domain - FireEye Email Security Block Domain - FireEye Em... Block Domain - FireEye Email ... Block Domain - Zscaler - Block Domain - Zscaler Block Domain - Zscaler Block Domain - Zscaler Done Done Block Domain - Trend Micro Apex One - Block Domain - Trend Micro Apex One Block Domain - Trend Micr... Block Domain - Trend Micro Ap... Block Domain - Proofpoint Threat Response - Block Domain - Proofpoint Threat Response Block Domain - Proofpoint... Block Domain - Proofpoint Thr...
This playbook blocks malicious Domains using all integrations that are enabled.

Supported integrations for this playbook:
* Zscaler
* Symantec Messaging Gateway
* FireEye EX
* Trend Micro Apex One
* Proofpoint Threat Response
* Cisco Stealthwatch Cloud


## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

### Sub-playbooks

* Block Domain - Zscaler
* Block Domain - Proofpoint Threat Response
* Block Domain - Symantec Messaging Gateway
* Block Domain - External Dynamic List
* Block Domain - Trend Micro Apex One
* Block Domain - FireEye Email Security
* Block Domain - Cisco Stealthwatch

### Integrations

This playbook does not use any integrations.

### Scripts

This playbook does not use any scripts.

### Commands

This playbook does not use any commands.

## Playbook Inputs

---

| **Name** | **Description** | **Default Value** | **Required** |
| --- | --- | --- | --- |
| Domain | The Domain to block. |  | Optional |
| DomainBlackListID | The Domain List ID to add the Domain to.<br/>product: Proofpoint Threat Response |  | Optional |
| Tag | Tag to assign a domain to the External Dynamic List.<br/>sub-playbook: Block Domain - External Dynamic List |  | Optional |
| Expiration | The UTC expiration date and time of the suspicious object, for example: 2020-01-25T09:00:00Z.<br/>Products: <br/>Trend Micro Apex One<br/>Proofpoint Threat Response |  | Optional |

## Playbook Outputs

---
There are no outputs for this playbook.

## Playbook Image

---

![Block Domain - Generic v2](../doc_files/Block_Domain_-_Generic_v2.png)