Courses of Action - Execution

This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input. ***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Tactic: - TA0002: Execution MITRE ATT&CK Description: The adversary is trying to run malicious code. Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery. Possible playbook triggers: - The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

MITRE ATT&CK - Courses of Action · 17 tasks · 5 inputs · 2 outputs

Details

IDCourses of Action - Execution
From Version6.5.0
Tasks17

README

This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.

***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).

Tactic:

  • TA0002: Execution

MITRE ATT&CK Description:
The adversary is trying to run malicious code.

Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.

Possible playbook triggers:

  • The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
  • The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • MITRE ATT&CK CoA - T1569.002 - Service Execution
  • MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter
  • MITRE ATT&CK CoA - T1204 - User Execution
  • MITRE ATT&CK CoA - T1059.001 - PowerShell

Integrations

This playbook does not use any integrations.

Scripts

  • SetAndHandleEmpty
  • Set

Commands

  • setIncident

Playbook Inputs


Name Description Default Value Required
technique Mitre ATT&CK ID of a technique.   Optional
template Template name to enforce WildFire best practices profile.   Optional
pre_post Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances.   Optional
device-group The device group for which to return addresses (Panorama instances).   Optional
tag Tag for which to filter the rules.   Optional

Playbook Outputs


Path Description Type
Handled.Techniques The technique handled in this playbook unknown
Execution.ProductList Products used for remediation. unknown

Playbook Image


Courses of Action - Execution

Inputs

  • technique — Mitre ATT&CK ID of a technique.
  • template — Template name to enforce WildFire best practices profile.
  • pre_post — Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  • device-group — The device group for which to return addresses (Panorama instances).
  • tag — Tag for which to filter the rules.

Outputs

  • Handled.Techniques — The technique handled in this playbook
  • Execution.ProductList — Products used for remediation.

Commands used

setIncident

Flowchart

yes yes yes yes Start Start Done Done Service Execution Service Execution Command and Scripting Interpreter Command and Scripting Int... MITRE ATT&CK CoA - T1569.002 - Service Execution - MITRE ATT&CK CoA - T1569.002 - Service Execution MITRE ATT&CK CoA - T1569.... MITRE ATT&CK CoA - T1569.002 ... MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter - MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter MITRE ATT&CK CoA - T1059 ... MITRE ATT&CK CoA - T1059 - Co... PowerShell PowerShell MITRE ATT&CK CoA - T1059.001 - PowerShell - MITRE ATT&CK CoA - T1059.001 - PowerShell MITRE ATT&CK CoA - T1059.... MITRE ATT&CK CoA - T1059.001 ... User Execution User Execution MITRE ATT&CK CoA - T1204 - User Execution - MITRE ATT&CK CoA - T1204 - User Execution MITRE ATT&CK CoA - T1204 ... MITRE ATT&CK CoA - T1204 - Us... Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set Execution Remediation products to the layout - setIncident Set Execution Remediation... setIncident Set techniques information to the layout Set techniques informatio... Set techniques information to the layout Set techniques informatio...
id: Courses of Action - Execution
name: Courses of Action - Execution
description: "This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.\n \n***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\n \nTactic:\n- TA0002: Execution\n\nMITRE ATT&CK Description: \nThe adversary is trying to run malicious code.\n\nExecution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.\n\nPossible playbook triggers:\n- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.\n"
inputs:
- description: Mitre ATT&CK ID of a technique.
  key: technique
  playbookInputQuery:
  required: false
  value: {}
- description: Template name to enforce WildFire best practices profile.
  key: template
  playbookInputQuery:
  required: false
  value: {}
- description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  key: pre_post
  playbookInputQuery:
  required: false
  value: {}
- description: The device group for which to return addresses (Panorama instances).
  key: device-group
  playbookInputQuery:
  required: false
  value: {}
- description: Tag for which to filter the rules.
  key: tag
  playbookInputQuery:
  required: false
  value: {}
outputs:
- contextPath: Handled.Techniques
  description: The technique handled in this playbook
  type: unknown
- contextPath: Execution.ProductList
  description: Products used for remediation.
  type: unknown
starttaskid: "0"
system: true
tasks:
  "0":
    id: "0"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "7"
      - "8"
      - "11"
      - "13"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 17ec8e25-dec7-40cd-8187-6a6bfaee976b
      iscommand: false
      name: ""
      version: -1
      description: ''
    taskid: 17ec8e25-dec7-40cd-8187-6a6bfaee976b
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 390,
          "y": 50
        }
      }
  "3":
    id: "3"
    ignoreworker: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 9b97e31d-30ef-4f70-8126-1e46329287e3
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: 9b97e31d-30ef-4f70-8126-1e46329287e3
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 390,
          "y": 1190
        }
      }
  "7":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1035
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
        - left:
            value:
              simple: T1569.002
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "7"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "9"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: bc00a21e-deae-4be6-833c-c05a86046e39
      iscommand: false
      name: Service Execution
      description: ""
      type: condition
      version: -1
    taskid: bc00a21e-deae-4be6-833c-c05a86046e39
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 690,
          "y": 190
        }
      }
  "8":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1059
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "8"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "10"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: f5aada71-a5a7-400c-8ae3-a89b94d05213
      iscommand: false
      name: Command and Scripting Interpreter
      description: ""
      type: condition
      version: -1
    taskid: f5aada71-a5a7-400c-8ae3-a89b94d05213
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 160,
          "y": 190
        }
      }
  "9":
    id: "9"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "16"
    note: false
    quietmode: 0
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 9b8fa670-765f-4fd8-8a19-670a53f2e4f4
      iscommand: false
      name: MITRE ATT&CK CoA - T1569.002 - Service Execution
      playbookId: MITRE ATT&CK CoA - T1569.002 - Service Execution
      type: playbook
      version: -1
      description: ''
    taskid: 9b8fa670-765f-4fd8-8a19-670a53f2e4f4
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 690,
          "y": 360
        }
      }
  "10":
    id: "10"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "17"
    note: false
    quietmode: 0
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 8c362a72-1625-45ec-8a6b-ac0922ae2d2d
      iscommand: false
      name: MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter
      playbookId: MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter
      type: playbook
      version: -1
      description: ''
    taskid: 8c362a72-1625-45ec-8a6b-ac0922ae2d2d
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 160,
          "y": 360
        }
      }
  "11":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1059.001
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "11"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "12"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 95d3d05c-79e1-494b-87d0-fca0f2c86fc5
      iscommand: false
      name: PowerShell
      description: ""
      type: condition
      version: -1
    taskid: 95d3d05c-79e1-494b-87d0-fca0f2c86fc5
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 1110,
          "y": 190
        }
      }
  "12":
    id: "12"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "15"
    note: false
    quietmode: 0
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 92f9fd53-0ad3-4e71-8c0a-7c92b2c447e1
      iscommand: false
      name: MITRE ATT&CK CoA - T1059.001 - PowerShell
      playbookId: MITRE ATT&CK CoA - T1059.001 - PowerShell
      type: playbook
      version: -1
      description: ''
    taskid: 92f9fd53-0ad3-4e71-8c0a-7c92b2c447e1
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 1110,
          "y": 360
        }
      }
  "13":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1204
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "13"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "14"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 8ee4ded6-53bb-4806-89f1-97f856edf26f
      iscommand: false
      name: User Execution
      description: ""
      type: condition
      version: -1
    taskid: 8ee4ded6-53bb-4806-89f1-97f856edf26f
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": -270,
          "y": 190
        }
      }
  "14":
    id: "14"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "18"
    note: false
    quietmode: 0
    scriptarguments:
      device-group:
        complex:
          root: inputs.device-group
      pre-post-rulebase:
        complex:
          root: inputs.pre_post
      tag:
        complex:
          root: inputs.tag
      template:
        complex:
          root: inputs.template
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 26a713b5-5c96-4444-8486-1f2795bd1810
      iscommand: false
      name: MITRE ATT&CK CoA - T1204 - User Execution
      playbookId: MITRE ATT&CK CoA - T1204 - User Execution
      type: playbook
      version: -1
      description: ''
    taskid: 26a713b5-5c96-4444-8486-1f2795bd1810
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": -270,
          "y": 360
        }
      }
  "15":
    id: "15"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "19"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Execution.Products
      value:
        simple: Cortex XDR
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 2fec3423-7d16-433b-8322-87781af3a55f
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 2fec3423-7d16-433b-8322-87781af3a55f
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 1110,
          "y": 530
        }
      }
  "16":
    id: "16"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "19"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Execution.Products
      value:
        simple: Cortex XDR
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: ac16e35a-e30c-4266-8c5d-3ef34e419243
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: ac16e35a-e30c-4266-8c5d-3ef34e419243
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 690,
          "y": 530
        }
      }
  "17":
    id: "17"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "19"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Execution.Products
      value:
        simple: Cortex XDR
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 66f6a4cf-bf10-4469-8ee2-89841095e7ea
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 66f6a4cf-bf10-4469-8ee2-89841095e7ea
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 160,
          "y": 530
        }
      }
  "18":
    id: "18"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "19"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Execution.Products
      value:
        simple: '["Cortex XDR","PAN-OS"]'
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 02826551-7d80-4d31-8b86-26b8b5e576c9
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 02826551-7d80-4d31-8b86-26b8b5e576c9
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": -270,
          "y": 530
        }
      }
  "19":
    id: "19"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "20"
    note: false
    quietmode: 0
    scriptarguments:
      executionremediationproducts:
        complex:
          root: Execution
          transformers:
          - args:
              title: {}
            operator: JsonToTable
    separatecontext: false
    skipunavailable: false
    task:
      brand: Builtin
      description: commands.local.cmd.set.incident
      id: d51e5bd4-bb2e-4243-892e-10ba1b6daf96
      iscommand: true
      name: Set Execution Remediation products to the layout
      script: Builtin|||setIncident
      type: regular
      version: -1
    taskid: d51e5bd4-bb2e-4243-892e-10ba1b6daf96
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 160,
          "y": 700
        }
      }
  "20":
    id: "20"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "21"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 9564d236-27ed-4dc6-880c-f94cd5ae6a6b
      iscommand: false
      name: Set techniques information to the layout
      description: ""
      type: title
      version: -1
    taskid: 9564d236-27ed-4dc6-880c-f94cd5ae6a6b
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 160,
          "y": 880
        }
      }
  "21":
    fieldMapping:
    - incidentfield: Remediated Techniques
      output:
        complex:
          root: Handled
          transformers:
          - args:
              title: {}
            operator: JsonToTable
    - incidentfield: Techniques to Handle
      output:
        complex:
          root: Unhandled
          transformers:
          - args:
              title: {}
            operator: JsonToTable
    id: "21"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "3"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "false"
      key:
        simple: Unhandled.Techniques
      stringify: {}
      value:
        complex:
          filters:
          - - left:
                iscontext: true
                value:
                  simple: TechniquesList
              operator: notIn
              right:
                iscontext: true
                value:
                  simple: Handled.Techniques
          root: TechniquesList
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered. If no value is entered, the script doesn't do anything.
      id: f1a71609-74ad-477a-81f2-a3f7c01b54c5
      iscommand: false
      name: Set techniques information to the layout
      script: SetAndHandleEmpty
      type: regular
      version: -1
    taskid: f1a71609-74ad-477a-81f2-a3f7c01b54c5
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 160,
          "y": 1020
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {
      "11_3_#default#": 0.28,
      "13_3_#default#": 0.18,
      "7_3_#default#": 0.17,
      "7_9_yes": 0.57,
      "8_10_yes": 0.59,
      "8_3_#default#": 0.18
    },
    "paper": {
      "dimensions": {
        "height": 1205,
        "width": 1760,
        "x": -270,
        "y": 50
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.5.0
marketplaces:
- xsoar
- marketplacev2
- platform