CTF 2 - Classify an incident - RDP Brute force

Classify an RDP Brute Force Incident - Run this playbook and follow the questions.

Capture The Flag - 02 · 23 tasks · 0 inputs · 0 outputs

Details

IDCTF 2 - Classify an incident - RDP Brute force
From Version8.2.0
Tasks23

README

Classify an RDP Brute Force Incident - Run this playbook and follow the questions.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

  • DeleteContext
  • CTF_2_BF

Commands

This playbook does not use any commands.

Playbook Inputs


There are no inputs for this playbook.

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


CTF 2 - Classify an incident - RDP Brute force

Flowchart

Start Start Find the XDR RDP Brute Force incident Find the XDR RDP Brute Fo... Check your answer #6 - CTF_2_BF Check your answer #6 CTF_2_BF No More Questions No More Questions Nicely done! Let's do this! Nicely done! Let's do this! Are any errors in the playbook? Are any errors in the pla... Check your answer #1 - CTF_2_BF Check your answer #1 CTF_2_BF Analyze the Incident Indicators Analyze the Incident Indi... Check your answer #2 - CTF_2_BF Check your answer #2 CTF_2_BF Check your answer #3 - CTF_2_BF Check your answer #3 CTF_2_BF Check if the indicator is associated with a campaign Check if the indicator is... Check your answer #4 - CTF_2_BF Check your answer #4 CTF_2_BF Campaign and report Campaign and report TIM and Auto-extract TIM and Auto-extract Related Incidents Related Incidents Classify this incident! Classify this incident! Post classification actions Post classification actions Investigate the incident Investigate the incident Check your answer #5 - CTF_2_BF Check your answer #5 CTF_2_BF Done Done Check the tag associated with the malicious indicator Check the tag associated ... Check your answer #7 - CTF_2_BF Check your answer #7 CTF_2_BF Delete Context - DeleteContext Delete Context DeleteContext
id: CTF 2 - Classify an incident - RDP Brute force
version: -1
contentitemexportablefields:
  contentitemfields: {}
name: CTF 2 - Classify an incident - RDP Brute force
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 2bd4aecf-6329-4c67-86cd-58ca954c6e16
    type: start
    task:
      id: 2bd4aecf-6329-4c67-86cd-58ca954c6e16
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "39"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": -290
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 906e556e-c6da-4f0c-8778-a845c37bea90
    type: regular
    task:
      id: 906e556e-c6da-4f0c-8778-a845c37bea90
      version: -1
      name: Find the XDR RDP Brute Force incident
      description: "Welcome to the second CTF challenge! \nIn this section, we are going to analyze the XDR RDP Brute Force incident from an analyst's perspective.\n\nTo complete the challenge, please complete all the tasks in this playbook.\nIn order to complete the tasks you will need to find the XDR RDP Brute Force incident in your environment (You can use the following query to search for this incident -> `name:\"XDR Incident 413 - 'Possible external RDP Brute-Force' generated by XDR Analytics detected on host dc1env12apc05 involving user env12\\administrator\"`). \n*Note*: do not change anything in the incident itself, since multiple students are working on the same one. \n\nOnce you find the relevant incident, complete this task and proceed.\n\nAs it was mentioned before, SLA for the answers will start once you mark this task as completed.\n___\n![myfile](https://raw.githubusercontent.com/demisto/content/10b88c87c2954c3b97108b3c07596fcf3cf128b7/Packs/ctf01/doc_files/C.gif)\n___\n"
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "34"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 10
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: c591b287-7bd4-4606-8b58-43ca0114d204
    type: regular
    task:
      id: c591b287-7bd4-4606-8b58-43ca0114d204
      version: -1
      name: 'Check your answer #6'
      description: |-
        Question #6:
        Classify this Incident
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "33"
    scriptarguments:
      question_ID:
        simple: "06"
      secret:
        complex:
          root: Classification.Answers
          accessor: "0"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 1965
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: 0499f25a-c2d2-4e42-8fc3-2ab1114b3900
    type: title
    task:
      id: 0499f25a-c2d2-4e42-8fc3-2ab1114b3900
      version: -1
      name: No More Questions
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "8"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 2590
        }
      }
    note: false
    timertriggers:
    - fieldname: ctf02
      action: stop
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: b7f452b8-b4b1-4560-8224-c6f1a0ede173
    type: regular
    task:
      id: b7f452b8-b4b1-4560-8224-c6f1a0ede173
      version: -1
      name: Nicely done! Let's do this!
      description: "Great Job! You have finished the entire CTF Challenge.\nHope you enjoyed the challenge and gained some knowledge on the system.\nSee you on the next challenge :) \n___\n![myfile](https://raw.githubusercontent.com/demisto/content/9e0946e3f76ed1862c6e40ea79ab85a9449d7102/Packs/ctf01/doc_files/I.gif)\n___\n"
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "36"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 2745
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: 49eda76d-b816-4f0c-873f-3c0dfbe81248
    type: collection
    task:
      id: 49eda76d-b816-4f0c-873f-3c0dfbe81248
      version: -1
      name: Are any errors in the playbook?
      description: Are any errors in the playbook?
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 340
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: Check if there are any errors in the playbook?
        required: false
        gridcolumns: []
        defaultrows: []
        type: singleSelect
        options: []
        optionsarg:
        - simple: "Yes"
        - simple: "No"
        fieldassociated: ""
        placeholder: ""
        tooltip: You can check the Work Plan entries or the Incident overview section
        readonly: false
      title: Check if there are any errors in the playbook?
      description: "Sometimes playbooks are stopped due to an issue whether it's because of the integration or missing information.  No matter what - the playbook should always run without errors so all the reliable information will be populated to the analyst properly.\n\n **Did you know?**\nError handling helps you:\n- Manage automation errors when tasks run in a playbook.\n- Configure how important tasks handle errors.\nto read more [Cortex XSOAR 6.X](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Handle-Errors-in-a-Playbook) or [Cortex XSOAR 8 Cloud](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Configure-script-error-handling-in-a-playbook) or [Cortex XSOAR 8.7 On-prem](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Configure-script-error-handling-in-a-playbook)\n___\n![myfile](https://raw.githubusercontent.com/demisto/content/10b88c87c2954c3b97108b3c07596fcf3cf128b7/Packs/ctf01/doc_files/G.gif)\n___\n"
      sender: ""
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "14":
    id: "14"
    taskid: e4fd6e15-1902-4610-8a56-d16ba0bb1fd5
    type: regular
    task:
      id: e4fd6e15-1902-4610-8a56-d16ba0bb1fd5
      version: -1
      name: 'Check your answer #1'
      description: |-
        Question #1:
        Are there any playbook errors?
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "23"
    scriptarguments:
      question_ID:
        simple: "01"
      secret:
        complex:
          root: Check if there are any errors in the playbook?.Answers
          accessor: "0"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 520
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "15":
    id: "15"
    taskid: 5b28b492-d786-4788-8eaa-91e61aa9b023
    type: collection
    task:
      id: 5b28b492-d786-4788-8eaa-91e61aa9b023
      version: -1
      name: Analyze the Incident Indicators
      description: Analyze the Incident Indicators
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "16"
      - "17"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 835
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: What is the type of the malicious indicator?
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg:
        - simple: "Yes"
        - simple: "No"
        fieldassociated: ""
        placeholder: ""
        tooltip: Check out the "Investigation" tab and find the "Indicators" section
        readonly: false
      - id: "1"
        label: ""
        labelarg:
          simple: How many relationships does the malicious indicator have?
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg: []
        fieldassociated: ""
        placeholder: ""
        tooltip: You can see the relationships numbers in the on the relevant indicator . Remember that existing indicators are highlighted  with link.
        readonly: false
      title: Check the various indicators that are extracted from the incident
      description: "Indicators are our first way to determine if the incident is malicious or not even before we deep dive into the details. \nWe need you to analyze the indicators within the XDR RDP brute force incident and help us to make the right call!\n\n**Did you know?**\n\nIf you have a Cortex XSOAR Threat Intelligence Management (TIM) license, it is possible to create predefined relationships between indicators to describe how they relate to each other. This enables the SOC analyst to do a more efficient incident analysis based on the indicators associated to the incident.\nTo read more [Cortex XSOAR 6.13](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.13/Cortex-XSOAR-Threat-Intel-Management-Guide/Indicator-Relationships) or [Cortex XSOAR 8 Cloud](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Threat-Intel-Management-Guide/Indicator-Relationships) or [Cortex XSOAR 8.7 On-prem](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Manage-indicator-relationships)"
      sender: ""
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "16":
    id: "16"
    taskid: da0e26b8-3acd-4ddd-8336-2fbb9339f26e
    type: regular
    task:
      id: da0e26b8-3acd-4ddd-8336-2fbb9339f26e
      version: -1
      name: 'Check your answer #2'
      description: "Question #2:\nWhat is the type of the malicious indicator? "
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "22"
    scriptarguments:
      question_ID:
        simple: "02"
      secret:
        complex:
          root: Check the various indicators that are extracted from the incident.Answers
          accessor: "0"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 210,
          "y": 1010
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 818d59f0-29d3-4257-84bf-8ee191cf7425
    type: regular
    task:
      id: 818d59f0-29d3-4257-84bf-8ee191cf7425
      version: -1
      name: 'Check your answer #3'
      description: |-
        Question #3:
        How many relationships does the malicious indicator have?
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "22"
    scriptarguments:
      question_ID:
        simple: "03"
      secret:
        complex:
          root: Check the various indicators that are extracted from the incident.Answers
          accessor: "1"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 1010
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: 30d26ae3-a2a2-4744-860b-8b797754b206
    type: collection
    task:
      id: 30d26ae3-a2a2-4744-860b-8b797754b206
      version: -1
      name: Check if the indicator is associated with a campaign
      description: Check if the indicator is associated with a campaign
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "21"
      - "35"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 1315
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: |-
            Based on the Campaign's Report Description, what was the year when a banking trojan malware associated with this campaign was first seen?
            To answer - search for the report indicator type associated with that campaign
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg:
        - simple: "Yes"
        - simple: "No"
        fieldassociated: ""
        placeholder: ""
        tooltip: 'Check the description of the campaign''s  report '
        readonly: false
      - id: "1"
        label: ""
        labelarg:
          simple: How many indicators are associated with the campaign?
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg: []
        fieldassociated: ""
        placeholder: ""
        tooltip: You can do that by searching the campaign name in the Threat Intel Tab and check how many relationships it has.
        readonly: false
      title: Threat Campaign
      description: |-
        Based on what we have found, this malicious indicator is also associated with a well-known campaign as indicated in a threat report from Unit-42.
        And now, let’s dive into other indicators.

        **Did you know?**
        Unit 42 Intel provides threat intelligence from multiple Palo Alto Networks services.
        Using Unit 42 Intel data, you can investigate indicators and their behaviors, and use that knowledge to better safeguard your network from malicious activity. [Check out the UNIT 42 Intel pack](https://cortex.marketplace.pan.dev/marketplace/details/Unit42Intel/).
        [Click here to read more.](https://cortex.marketplace.pan.dev/marketplace/details/Unit42Intel/)

      sender: ""
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: 1d0237e7-a9ad-4683-81d7-c5b8c23cc6c0
    type: regular
    task:
      id: 1d0237e7-a9ad-4683-81d7-c5b8c23cc6c0
      version: -1
      name: 'Check your answer #4'
      description: |-
        Question #4:
        Based on the Campaign's Report, what was the year when this campaign was first seen?
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "27"
    scriptarguments:
      question_ID:
        simple: "04"
      secret:
        complex:
          root: Threat Campaign.Answers
          accessor: "0"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 230,
          "y": 1495
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: 7e5d148a-3484-4309-8ea4-e46dc935f76b
    type: title
    task:
      id: 7e5d148a-3484-4309-8ea4-e46dc935f76b
      version: -1
      name: Campaign and report
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "20"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 1190
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 44da2012-d4ff-4b1e-8f54-a21294e249ab
    type: title
    task:
      id: 44da2012-d4ff-4b1e-8f54-a21294e249ab
      version: -1
      name: TIM and Auto-extract
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "15"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: 70d59eaf-9851-4372-885a-292e9ca7f430
    type: title
    task:
      id: 70d59eaf-9851-4372-885a-292e9ca7f430
      version: -1
      name: Related Incidents
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "32"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 1670
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "32":
    id: "32"
    taskid: 06b6424a-932d-4103-802e-da444608984d
    type: collection
    task:
      id: 06b6424a-932d-4103-802e-da444608984d
      version: -1
      name: Classify this incident!
      description: Classify this incident!
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "4"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 1800
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: Classify this Incident
        required: false
        gridcolumns: []
        defaultrows: []
        type: singleSelect
        options: []
        optionsarg:
        - simple: True Positive
        - simple: False Positive
        fieldassociated: ""
        placeholder: ""
        tooltip: Look at the RDP Brute Force Tab
        readonly: false
      title: Classification
      description: "This playbook can classify this incident for you. So what's it going to be? True Or False Positive? \n\nYou can go over the collected data from the playbook and the information provided in the layout, you should have all the information to accomplish this mission.\n\n**Did you know?**\nCortex XSOAR can \n- Get faster closure and false positive detection with automated playbooks.\n- Leverage historical cross-correlation for duplicate detection.\n- Combine analyst knowledge with a collaboration window for joint investigations.\nThe result is that customers can cut weekly alert volume by 95%, increase analyst productivity, and reduce organizational risks.\n[Click here to read more.](https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/cortex-xsoar-esri-case-study/ta-p/329087)\n___\n![myfile](https://raw.githubusercontent.com/demisto/content/10b88c87c2954c3b97108b3c07596fcf3cf128b7/Packs/ctf01/doc_files/H.gif)\n___\n"
      sender: Your SOC team
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "33":
    id: "33"
    taskid: deb05f1a-58b2-48f3-827b-a6b0acc8ad9a
    type: title
    task:
      id: deb05f1a-58b2-48f3-827b-a6b0acc8ad9a
      version: -1
      name: Post classification actions
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "37"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 2130
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "34":
    id: "34"
    taskid: 9096ef81-9d7f-4e9e-862c-fa8ebcf60606
    type: title
    task:
      id: 9096ef81-9d7f-4e9e-862c-fa8ebcf60606
      version: -1
      name: Investigate the incident
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "13"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 190
        }
      }
    note: false
    timertriggers:
    - fieldname: ctf02
      action: start
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: 1e9e6d56-7636-4df2-8e72-23d3bca7335a
    type: regular
    task:
      id: 1e9e6d56-7636-4df2-8e72-23d3bca7335a
      version: -1
      name: 'Check your answer #5'
      description: |-
        Question #5:
        How many indicators are associated with the campaign?
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "27"
    scriptarguments:
      question_ID:
        simple: "05"
      secret:
        complex:
          root: Threat Campaign.Answers
          accessor: "1"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 680,
          "y": 1495
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: 7c43443b-65f3-4d0d-881b-2a4737f85e8e
    type: title
    task:
      id: 7c43443b-65f3-4d0d-881b-2a4737f85e8e
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 2920
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "37":
    id: "37"
    taskid: f1962682-823e-4c9c-8de5-9664e9689ac6
    type: collection
    task:
      id: f1962682-823e-4c9c-8de5-9664e9689ac6
      version: -1
      name: Check the tag associated with the malicious indicator
      description: Check the tag associated with the malicious indicator
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "38"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 2265
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: What is the malicious indicator tag in our investigation?
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg:
        - simple: "Yes"
        - simple: "No"
        fieldassociated: ""
        placeholder: ""
        tooltip: You can check indicators information from the incident's indicator quick view or through the Threat Intel section.
        readonly: false
      title: Check the tag associated with the malicious indicator
      description: |-
        Great!

        Now, we have classified the incident as true positive, we would like to verify that we blocked the malicious indicator. Let’s export this indicator to an External Dynamic List (EDL) using the Export Dynamic Lists integration.

        The EDL integration utilizes the TIM query to populate indicators to an external dynamic list. For example, a TIM query can use a dedicated tag for blocking (such as "Bad" or "BlockMe").

      sender: Your SOC team
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "38":
    id: "38"
    taskid: ad47b1e6-f810-4afa-8c14-6b1c71b2e5e5
    type: regular
    task:
      id: ad47b1e6-f810-4afa-8c14-6b1c71b2e5e5
      version: -1
      name: 'Check your answer #7'
      description: |-
        Question #7:
        What is the malicious indicator tag in our investigation?
      scriptName: CTF_2_BF
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    scriptarguments:
      question_ID:
        simple: "07"
      secret:
        complex:
          root: Check the tag associated with the malicious indicator.Answers
          accessor: "0"
          transformers:
          - operator: LastArrayElement
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 460,
          "y": 2425
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "39":
    id: "39"
    taskid: 71663406-c22e-4381-8aa7-cbf2fbb38645
    type: regular
    task:
      id: 71663406-c22e-4381-8aa7-cbf2fbb38645
      version: -1
      name: Delete Context
      description: precaution task for re-running the playbook without deleting context.
      scriptName: DeleteContext
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "1"
    scriptarguments:
      all:
        simple: "yes"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": -150
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
system: true
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 3605,
        "width": 850,
        "x": 210,
        "y": -290
      }
    }
  }
inputs: []
outputs: []
tests:
- No tests (auto formatted)
fromversion: 8.2.0
description: 'Classify an RDP Brute Force Incident - Run this playbook and follow the questions.'