CTF 2 - Classify an incident - RDP Brute force
Classify an RDP Brute Force Incident - Run this playbook and follow the questions.
Capture The Flag - 02 · 23 tasks · 0 inputs · 0 outputs
Details
| ID | CTF 2 - Classify an incident - RDP Brute force |
|---|---|
| From Version | 8.2.0 |
| Tasks | 23 |
README
Classify an RDP Brute Force Incident - Run this playbook and follow the questions.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
- DeleteContext
- CTF_2_BF
Commands
This playbook does not use any commands.
Playbook Inputs
There are no inputs for this playbook.
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Flowchart
id: CTF 2 - Classify an incident - RDP Brute force version: -1 contentitemexportablefields: contentitemfields: {} name: CTF 2 - Classify an incident - RDP Brute force starttaskid: "0" tasks: "0": id: "0" taskid: 2bd4aecf-6329-4c67-86cd-58ca954c6e16 type: start task: id: 2bd4aecf-6329-4c67-86cd-58ca954c6e16 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "39" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": -290 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "1": id: "1" taskid: 906e556e-c6da-4f0c-8778-a845c37bea90 type: regular task: id: 906e556e-c6da-4f0c-8778-a845c37bea90 version: -1 name: Find the XDR RDP Brute Force incident description: "Welcome to the second CTF challenge! \nIn this section, we are going to analyze the XDR RDP Brute Force incident from an analyst's perspective.\n\nTo complete the challenge, please complete all the tasks in this playbook.\nIn order to complete the tasks you will need to find the XDR RDP Brute Force incident in your environment (You can use the following query to search for this incident -> `name:\"XDR Incident 413 - 'Possible external RDP Brute-Force' generated by XDR Analytics detected on host dc1env12apc05 involving user env12\\administrator\"`). \n*Note*: do not change anything in the incident itself, since multiple students are working on the same one. \n\nOnce you find the relevant incident, complete this task and proceed.\n\nAs it was mentioned before, SLA for the answers will start once you mark this task as completed.\n___\n\n___\n" type: regular iscommand: false brand: "" nexttasks: '#none#': - "34" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 10 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "4": id: "4" taskid: c591b287-7bd4-4606-8b58-43ca0114d204 type: regular task: id: c591b287-7bd4-4606-8b58-43ca0114d204 version: -1 name: 'Check your answer #6' description: |- Question #6: Classify this Incident scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "33" scriptarguments: question_ID: simple: "06" secret: complex: root: Classification.Answers accessor: "0" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 1965 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "7": id: "7" taskid: 0499f25a-c2d2-4e42-8fc3-2ab1114b3900 type: title task: id: 0499f25a-c2d2-4e42-8fc3-2ab1114b3900 version: -1 name: No More Questions type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "8" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 2590 } } note: false timertriggers: - fieldname: ctf02 action: stop ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "8": id: "8" taskid: b7f452b8-b4b1-4560-8224-c6f1a0ede173 type: regular task: id: b7f452b8-b4b1-4560-8224-c6f1a0ede173 version: -1 name: Nicely done! Let's do this! description: "Great Job! You have finished the entire CTF Challenge.\nHope you enjoyed the challenge and gained some knowledge on the system.\nSee you on the next challenge :) \n___\n\n___\n" type: regular iscommand: false brand: "" nexttasks: '#none#': - "36" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 2745 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "13": id: "13" taskid: 49eda76d-b816-4f0c-873f-3c0dfbe81248 type: collection task: id: 49eda76d-b816-4f0c-873f-3c0dfbe81248 version: -1 name: Are any errors in the playbook? description: Are any errors in the playbook? type: collection iscommand: false brand: "" nexttasks: '#none#': - "14" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 340 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false form: questions: - id: "0" label: "" labelarg: simple: Check if there are any errors in the playbook? required: false gridcolumns: [] defaultrows: [] type: singleSelect options: [] optionsarg: - simple: "Yes" - simple: "No" fieldassociated: "" placeholder: "" tooltip: You can check the Work Plan entries or the Incident overview section readonly: false title: Check if there are any errors in the playbook? description: "Sometimes playbooks are stopped due to an issue whether it's because of the integration or missing information. No matter what - the playbook should always run without errors so all the reliable information will be populated to the analyst properly.\n\n **Did you know?**\nError handling helps you:\n- Manage automation errors when tasks run in a playbook.\n- Configure how important tasks handle errors.\nto read more [Cortex XSOAR 6.X](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Handle-Errors-in-a-Playbook) or [Cortex XSOAR 8 Cloud](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Configure-script-error-handling-in-a-playbook) or [Cortex XSOAR 8.7 On-prem](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Configure-script-error-handling-in-a-playbook)\n___\n\n___\n" sender: "" expired: false totalanswers: 0 skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "14": id: "14" taskid: e4fd6e15-1902-4610-8a56-d16ba0bb1fd5 type: regular task: id: e4fd6e15-1902-4610-8a56-d16ba0bb1fd5 version: -1 name: 'Check your answer #1' description: |- Question #1: Are there any playbook errors? scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "23" scriptarguments: question_ID: simple: "01" secret: complex: root: Check if there are any errors in the playbook?.Answers accessor: "0" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 520 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "15": id: "15" taskid: 5b28b492-d786-4788-8eaa-91e61aa9b023 type: collection task: id: 5b28b492-d786-4788-8eaa-91e61aa9b023 version: -1 name: Analyze the Incident Indicators description: Analyze the Incident Indicators type: collection iscommand: false brand: "" nexttasks: '#none#': - "16" - "17" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 835 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false form: questions: - id: "0" label: "" labelarg: simple: What is the type of the malicious indicator? required: false gridcolumns: [] defaultrows: [] type: shortText options: [] optionsarg: - simple: "Yes" - simple: "No" fieldassociated: "" placeholder: "" tooltip: Check out the "Investigation" tab and find the "Indicators" section readonly: false - id: "1" label: "" labelarg: simple: How many relationships does the malicious indicator have? required: false gridcolumns: [] defaultrows: [] type: shortText options: [] optionsarg: [] fieldassociated: "" placeholder: "" tooltip: You can see the relationships numbers in the on the relevant indicator . Remember that existing indicators are highlighted with link. readonly: false title: Check the various indicators that are extracted from the incident description: "Indicators are our first way to determine if the incident is malicious or not even before we deep dive into the details. \nWe need you to analyze the indicators within the XDR RDP brute force incident and help us to make the right call!\n\n**Did you know?**\n\nIf you have a Cortex XSOAR Threat Intelligence Management (TIM) license, it is possible to create predefined relationships between indicators to describe how they relate to each other. This enables the SOC analyst to do a more efficient incident analysis based on the indicators associated to the incident.\nTo read more [Cortex XSOAR 6.13](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.13/Cortex-XSOAR-Threat-Intel-Management-Guide/Indicator-Relationships) or [Cortex XSOAR 8 Cloud](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Threat-Intel-Management-Guide/Indicator-Relationships) or [Cortex XSOAR 8.7 On-prem](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Manage-indicator-relationships)" sender: "" expired: false totalanswers: 0 skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "16": id: "16" taskid: da0e26b8-3acd-4ddd-8336-2fbb9339f26e type: regular task: id: da0e26b8-3acd-4ddd-8336-2fbb9339f26e version: -1 name: 'Check your answer #2' description: "Question #2:\nWhat is the type of the malicious indicator? " scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "22" scriptarguments: question_ID: simple: "02" secret: complex: root: Check the various indicators that are extracted from the incident.Answers accessor: "0" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 210, "y": 1010 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "17": id: "17" taskid: 818d59f0-29d3-4257-84bf-8ee191cf7425 type: regular task: id: 818d59f0-29d3-4257-84bf-8ee191cf7425 version: -1 name: 'Check your answer #3' description: |- Question #3: How many relationships does the malicious indicator have? scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "22" scriptarguments: question_ID: simple: "03" secret: complex: root: Check the various indicators that are extracted from the incident.Answers accessor: "1" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 1010 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "20": id: "20" taskid: 30d26ae3-a2a2-4744-860b-8b797754b206 type: collection task: id: 30d26ae3-a2a2-4744-860b-8b797754b206 version: -1 name: Check if the indicator is associated with a campaign description: Check if the indicator is associated with a campaign type: collection iscommand: false brand: "" nexttasks: '#none#': - "21" - "35" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 1315 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false form: questions: - id: "0" label: "" labelarg: simple: |- Based on the Campaign's Report Description, what was the year when a banking trojan malware associated with this campaign was first seen? To answer - search for the report indicator type associated with that campaign required: false gridcolumns: [] defaultrows: [] type: shortText options: [] optionsarg: - simple: "Yes" - simple: "No" fieldassociated: "" placeholder: "" tooltip: 'Check the description of the campaign''s report ' readonly: false - id: "1" label: "" labelarg: simple: How many indicators are associated with the campaign? required: false gridcolumns: [] defaultrows: [] type: shortText options: [] optionsarg: [] fieldassociated: "" placeholder: "" tooltip: You can do that by searching the campaign name in the Threat Intel Tab and check how many relationships it has. readonly: false title: Threat Campaign description: |- Based on what we have found, this malicious indicator is also associated with a well-known campaign as indicated in a threat report from Unit-42. And now, let’s dive into other indicators. **Did you know?** Unit 42 Intel provides threat intelligence from multiple Palo Alto Networks services. Using Unit 42 Intel data, you can investigate indicators and their behaviors, and use that knowledge to better safeguard your network from malicious activity. [Check out the UNIT 42 Intel pack](https://cortex.marketplace.pan.dev/marketplace/details/Unit42Intel/). [Click here to read more.](https://cortex.marketplace.pan.dev/marketplace/details/Unit42Intel/) sender: "" expired: false totalanswers: 0 skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "21": id: "21" taskid: 1d0237e7-a9ad-4683-81d7-c5b8c23cc6c0 type: regular task: id: 1d0237e7-a9ad-4683-81d7-c5b8c23cc6c0 version: -1 name: 'Check your answer #4' description: |- Question #4: Based on the Campaign's Report, what was the year when this campaign was first seen? scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "27" scriptarguments: question_ID: simple: "04" secret: complex: root: Threat Campaign.Answers accessor: "0" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 230, "y": 1495 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "22": id: "22" taskid: 7e5d148a-3484-4309-8ea4-e46dc935f76b type: title task: id: 7e5d148a-3484-4309-8ea4-e46dc935f76b version: -1 name: Campaign and report type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "20" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 1190 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "23": id: "23" taskid: 44da2012-d4ff-4b1e-8f54-a21294e249ab type: title task: id: 44da2012-d4ff-4b1e-8f54-a21294e249ab version: -1 name: TIM and Auto-extract type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "15" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 700 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "27": id: "27" taskid: 70d59eaf-9851-4372-885a-292e9ca7f430 type: title task: id: 70d59eaf-9851-4372-885a-292e9ca7f430 version: -1 name: Related Incidents type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "32" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 1670 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "32": id: "32" taskid: 06b6424a-932d-4103-802e-da444608984d type: collection task: id: 06b6424a-932d-4103-802e-da444608984d version: -1 name: Classify this incident! description: Classify this incident! type: collection iscommand: false brand: "" nexttasks: '#none#': - "4" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 1800 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false form: questions: - id: "0" label: "" labelarg: simple: Classify this Incident required: false gridcolumns: [] defaultrows: [] type: singleSelect options: [] optionsarg: - simple: True Positive - simple: False Positive fieldassociated: "" placeholder: "" tooltip: Look at the RDP Brute Force Tab readonly: false title: Classification description: "This playbook can classify this incident for you. So what's it going to be? True Or False Positive? \n\nYou can go over the collected data from the playbook and the information provided in the layout, you should have all the information to accomplish this mission.\n\n**Did you know?**\nCortex XSOAR can \n- Get faster closure and false positive detection with automated playbooks.\n- Leverage historical cross-correlation for duplicate detection.\n- Combine analyst knowledge with a collaboration window for joint investigations.\nThe result is that customers can cut weekly alert volume by 95%, increase analyst productivity, and reduce organizational risks.\n[Click here to read more.](https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/cortex-xsoar-esri-case-study/ta-p/329087)\n___\n\n___\n" sender: Your SOC team expired: false totalanswers: 0 skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "33": id: "33" taskid: deb05f1a-58b2-48f3-827b-a6b0acc8ad9a type: title task: id: deb05f1a-58b2-48f3-827b-a6b0acc8ad9a version: -1 name: Post classification actions type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "37" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 2130 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "34": id: "34" taskid: 9096ef81-9d7f-4e9e-862c-fa8ebcf60606 type: title task: id: 9096ef81-9d7f-4e9e-862c-fa8ebcf60606 version: -1 name: Investigate the incident type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "13" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 190 } } note: false timertriggers: - fieldname: ctf02 action: start ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "35": id: "35" taskid: 1e9e6d56-7636-4df2-8e72-23d3bca7335a type: regular task: id: 1e9e6d56-7636-4df2-8e72-23d3bca7335a version: -1 name: 'Check your answer #5' description: |- Question #5: How many indicators are associated with the campaign? scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "27" scriptarguments: question_ID: simple: "05" secret: complex: root: Threat Campaign.Answers accessor: "1" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 680, "y": 1495 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "36": id: "36" taskid: 7c43443b-65f3-4d0d-881b-2a4737f85e8e type: title task: id: 7c43443b-65f3-4d0d-881b-2a4737f85e8e version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 2920 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "37": id: "37" taskid: f1962682-823e-4c9c-8de5-9664e9689ac6 type: collection task: id: f1962682-823e-4c9c-8de5-9664e9689ac6 version: -1 name: Check the tag associated with the malicious indicator description: Check the tag associated with the malicious indicator type: collection iscommand: false brand: "" nexttasks: '#none#': - "38" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 2265 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: true completeaftersla: false form: questions: - id: "0" label: "" labelarg: simple: What is the malicious indicator tag in our investigation? required: false gridcolumns: [] defaultrows: [] type: shortText options: [] optionsarg: - simple: "Yes" - simple: "No" fieldassociated: "" placeholder: "" tooltip: You can check indicators information from the incident's indicator quick view or through the Threat Intel section. readonly: false title: Check the tag associated with the malicious indicator description: |- Great! Now, we have classified the incident as true positive, we would like to verify that we blocked the malicious indicator. Let’s export this indicator to an External Dynamic List (EDL) using the Export Dynamic Lists integration. The EDL integration utilizes the TIM query to populate indicators to an external dynamic list. For example, a TIM query can use a dedicated tag for blocking (such as "Bad" or "BlockMe"). sender: Your SOC team expired: false totalanswers: 0 skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "38": id: "38" taskid: ad47b1e6-f810-4afa-8c14-6b1c71b2e5e5 type: regular task: id: ad47b1e6-f810-4afa-8c14-6b1c71b2e5e5 version: -1 name: 'Check your answer #7' description: |- Question #7: What is the malicious indicator tag in our investigation? scriptName: CTF_2_BF type: regular iscommand: false brand: "" nexttasks: '#none#': - "7" scriptarguments: question_ID: simple: "07" secret: complex: root: Check the tag associated with the malicious indicator.Answers accessor: "0" transformers: - operator: LastArrayElement - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 460, "y": 2425 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "39": id: "39" taskid: 71663406-c22e-4381-8aa7-cbf2fbb38645 type: regular task: id: 71663406-c22e-4381-8aa7-cbf2fbb38645 version: -1 name: Delete Context description: precaution task for re-running the playbook without deleting context. scriptName: DeleteContext type: regular iscommand: false brand: "" nexttasks: '#none#': - "1" scriptarguments: all: simple: "yes" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": -150 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false system: true view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 3605, "width": 850, "x": 210, "y": -290 } } } inputs: [] outputs: [] tests: - No tests (auto formatted) fromversion: 8.2.0 description: 'Classify an RDP Brute Force Incident - Run this playbook and follow the questions.'