Courses of Action - Execution
This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input. ***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Tactic: - TA0002: Execution MITRE ATT&CK Description: The adversary is trying to run malicious code. Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery. Possible playbook triggers: - The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK - Courses of Action · 17 tasks · 5 inputs · 2 outputs
Details
| ID | Courses of Action - Execution |
|---|---|
| From Version | 6.5.0 |
| Tasks | 17 |
README
This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.
***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Tactic:
- TA0002: Execution
MITRE ATT&CK Description:
The adversary is trying to run malicious code.
Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.
Possible playbook triggers:
- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- MITRE ATT&CK CoA - T1569.002 - Service Execution
- MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter
- MITRE ATT&CK CoA - T1204 - User Execution
- MITRE ATT&CK CoA - T1059.001 - PowerShell
Integrations
This playbook does not use any integrations.
Scripts
- SetAndHandleEmpty
- Set
Commands
- setIncident
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| technique | Mitre ATT&CK ID of a technique. | Optional | |
| template | Template name to enforce WildFire best practices profile. | Optional | |
| pre_post | Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances. | Optional | |
| device-group | The device group for which to return addresses (Panorama instances). | Optional | |
| tag | Tag for which to filter the rules. | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| Handled.Techniques | The technique handled in this playbook | unknown |
| Execution.ProductList | Products used for remediation. | unknown |
Playbook Image

Inputs
technique— Mitre ATT&CK ID of a technique.template— Template name to enforce WildFire best practices profile.pre_post— Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.device-group— The device group for which to return addresses (Panorama instances).tag— Tag for which to filter the rules.
Outputs
Handled.Techniques— The technique handled in this playbookExecution.ProductList— Products used for remediation.
Commands used
setIncident
Flowchart
id: Courses of Action - Execution name: Courses of Action - Execution description: "This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.\n \n***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\n \nTactic:\n- TA0002: Execution\n\nMITRE ATT&CK Description: \nThe adversary is trying to run malicious code.\n\nExecution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.\n\nPossible playbook triggers:\n- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.\n" inputs: - description: Mitre ATT&CK ID of a technique. key: technique playbookInputQuery: required: false value: {} - description: Template name to enforce WildFire best practices profile. key: template playbookInputQuery: required: false value: {} - description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances. key: pre_post playbookInputQuery: required: false value: {} - description: The device group for which to return addresses (Panorama instances). key: device-group playbookInputQuery: required: false value: {} - description: Tag for which to filter the rules. key: tag playbookInputQuery: required: false value: {} outputs: - contextPath: Handled.Techniques description: The technique handled in this playbook type: unknown - contextPath: Execution.ProductList description: Products used for remediation. type: unknown starttaskid: "0" system: true tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "7" - "8" - "11" - "13" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 17ec8e25-dec7-40cd-8187-6a6bfaee976b iscommand: false name: "" version: -1 description: '' taskid: 17ec8e25-dec7-40cd-8187-6a6bfaee976b timertriggers: [] type: start view: |- { "position": { "x": 390, "y": 50 } } "3": id: "3" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 9b97e31d-30ef-4f70-8126-1e46329287e3 iscommand: false name: Done type: title version: -1 description: '' taskid: 9b97e31d-30ef-4f70-8126-1e46329287e3 timertriggers: [] type: title view: |- { "position": { "x": 390, "y": 1190 } } "7": conditions: - condition: - - left: value: simple: T1035 operator: inList right: iscontext: true value: complex: root: inputs.technique transformers: - args: delimiter: value: simple: ',' operator: split - left: value: simple: T1569.002 operator: inList right: iscontext: true value: complex: root: inputs.technique transformers: - args: delimiter: value: simple: ',' operator: split label: "yes" id: "7" ignoreworker: false nexttasks: '#default#': - "3" "yes": - "9" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: bc00a21e-deae-4be6-833c-c05a86046e39 iscommand: false name: Service Execution description: "" type: condition version: -1 taskid: bc00a21e-deae-4be6-833c-c05a86046e39 timertriggers: [] type: condition view: |- { "position": { "x": 690, "y": 190 } } "8": conditions: - condition: - - left: value: simple: T1059 operator: inList right: iscontext: true value: complex: root: inputs.technique transformers: - args: delimiter: value: simple: ',' operator: split label: "yes" id: "8" ignoreworker: false nexttasks: '#default#': - "3" "yes": - "10" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: f5aada71-a5a7-400c-8ae3-a89b94d05213 iscommand: false name: Command and Scripting Interpreter description: "" type: condition version: -1 taskid: f5aada71-a5a7-400c-8ae3-a89b94d05213 timertriggers: [] type: condition view: |- { "position": { "x": 160, "y": 190 } } "9": id: "9" ignoreworker: false nexttasks: '#none#': - "16" note: false quietmode: 0 separatecontext: true skipunavailable: false task: brand: "" id: 9b8fa670-765f-4fd8-8a19-670a53f2e4f4 iscommand: false name: MITRE ATT&CK CoA - T1569.002 - Service Execution playbookId: MITRE ATT&CK CoA - T1569.002 - Service Execution type: playbook version: -1 description: '' taskid: 9b8fa670-765f-4fd8-8a19-670a53f2e4f4 timertriggers: [] type: playbook view: |- { "position": { "x": 690, "y": 360 } } "10": id: "10" ignoreworker: false nexttasks: '#none#': - "17" note: false quietmode: 0 separatecontext: true skipunavailable: false task: brand: "" id: 8c362a72-1625-45ec-8a6b-ac0922ae2d2d iscommand: false name: MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter playbookId: MITRE ATT&CK CoA - T1059 - Command and Scripting Interpreter type: playbook version: -1 description: '' taskid: 8c362a72-1625-45ec-8a6b-ac0922ae2d2d timertriggers: [] type: playbook view: |- { "position": { "x": 160, "y": 360 } } "11": conditions: - condition: - - left: value: simple: T1059.001 operator: inList right: iscontext: true value: complex: root: inputs.technique transformers: - args: delimiter: value: simple: ',' operator: split label: "yes" id: "11" ignoreworker: false nexttasks: '#default#': - "3" "yes": - "12" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 95d3d05c-79e1-494b-87d0-fca0f2c86fc5 iscommand: false name: PowerShell description: "" type: condition version: -1 taskid: 95d3d05c-79e1-494b-87d0-fca0f2c86fc5 timertriggers: [] type: condition view: |- { "position": { "x": 1110, "y": 190 } } "12": id: "12" ignoreworker: false nexttasks: '#none#': - "15" note: false quietmode: 0 separatecontext: true skipunavailable: false task: brand: "" id: 92f9fd53-0ad3-4e71-8c0a-7c92b2c447e1 iscommand: false name: MITRE ATT&CK CoA - T1059.001 - PowerShell playbookId: MITRE ATT&CK CoA - T1059.001 - PowerShell type: playbook version: -1 description: '' taskid: 92f9fd53-0ad3-4e71-8c0a-7c92b2c447e1 timertriggers: [] type: playbook view: |- { "position": { "x": 1110, "y": 360 } } "13": conditions: - condition: - - left: value: simple: T1204 operator: inList right: iscontext: true value: complex: root: inputs.technique transformers: - args: delimiter: value: simple: ',' operator: split label: "yes" id: "13" ignoreworker: false nexttasks: '#default#': - "3" "yes": - "14" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 8ee4ded6-53bb-4806-89f1-97f856edf26f iscommand: false name: User Execution description: "" type: condition version: -1 taskid: 8ee4ded6-53bb-4806-89f1-97f856edf26f timertriggers: [] type: condition view: |- { "position": { "x": -270, "y": 190 } } "14": id: "14" ignoreworker: false loop: exitCondition: "" iscommand: false max: 100 wait: 1 nexttasks: '#none#': - "18" note: false quietmode: 0 scriptarguments: device-group: complex: root: inputs.device-group pre-post-rulebase: complex: root: inputs.pre_post tag: complex: root: inputs.tag template: complex: root: inputs.template separatecontext: true skipunavailable: false task: brand: "" id: 26a713b5-5c96-4444-8486-1f2795bd1810 iscommand: false name: MITRE ATT&CK CoA - T1204 - User Execution playbookId: MITRE ATT&CK CoA - T1204 - User Execution type: playbook version: -1 description: '' taskid: 26a713b5-5c96-4444-8486-1f2795bd1810 timertriggers: [] type: playbook view: |- { "position": { "x": -270, "y": 360 } } "15": id: "15" ignoreworker: false nexttasks: '#none#': - "19" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Execution.Products value: simple: Cortex XDR separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: 2fec3423-7d16-433b-8322-87781af3a55f iscommand: false name: Set remediation products script: Set type: regular version: -1 taskid: 2fec3423-7d16-433b-8322-87781af3a55f timertriggers: [] type: regular view: |- { "position": { "x": 1110, "y": 530 } } "16": id: "16" ignoreworker: false nexttasks: '#none#': - "19" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Execution.Products value: simple: Cortex XDR separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: ac16e35a-e30c-4266-8c5d-3ef34e419243 iscommand: false name: Set remediation products script: Set type: regular version: -1 taskid: ac16e35a-e30c-4266-8c5d-3ef34e419243 timertriggers: [] type: regular view: |- { "position": { "x": 690, "y": 530 } } "17": id: "17" ignoreworker: false nexttasks: '#none#': - "19" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Execution.Products value: simple: Cortex XDR separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: 66f6a4cf-bf10-4469-8ee2-89841095e7ea iscommand: false name: Set remediation products script: Set type: regular version: -1 taskid: 66f6a4cf-bf10-4469-8ee2-89841095e7ea timertriggers: [] type: regular view: |- { "position": { "x": 160, "y": 530 } } "18": id: "18" ignoreworker: false nexttasks: '#none#': - "19" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Execution.Products value: simple: '["Cortex XDR","PAN-OS"]' separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: 02826551-7d80-4d31-8b86-26b8b5e576c9 iscommand: false name: Set remediation products script: Set type: regular version: -1 taskid: 02826551-7d80-4d31-8b86-26b8b5e576c9 timertriggers: [] type: regular view: |- { "position": { "x": -270, "y": 530 } } "19": id: "19" ignoreworker: false nexttasks: '#none#': - "20" note: false quietmode: 0 scriptarguments: executionremediationproducts: complex: root: Execution transformers: - args: title: {} operator: JsonToTable separatecontext: false skipunavailable: false task: brand: Builtin description: commands.local.cmd.set.incident id: d51e5bd4-bb2e-4243-892e-10ba1b6daf96 iscommand: true name: Set Execution Remediation products to the layout script: Builtin|||setIncident type: regular version: -1 taskid: d51e5bd4-bb2e-4243-892e-10ba1b6daf96 timertriggers: [] type: regular view: |- { "position": { "x": 160, "y": 700 } } "20": id: "20" ignoreworker: false nexttasks: '#none#': - "21" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 9564d236-27ed-4dc6-880c-f94cd5ae6a6b iscommand: false name: Set techniques information to the layout description: "" type: title version: -1 taskid: 9564d236-27ed-4dc6-880c-f94cd5ae6a6b timertriggers: [] type: title view: |- { "position": { "x": 160, "y": 880 } } "21": fieldMapping: - incidentfield: Remediated Techniques output: complex: root: Handled transformers: - args: title: {} operator: JsonToTable - incidentfield: Techniques to Handle output: complex: root: Unhandled transformers: - args: title: {} operator: JsonToTable id: "21" ignoreworker: false nexttasks: '#none#': - "3" note: false quietmode: 0 scriptarguments: append: simple: "false" key: simple: Unhandled.Techniques stringify: {} value: complex: filters: - - left: iscontext: true value: simple: TechniquesList operator: notIn right: iscontext: true value: simple: Handled.Techniques root: TechniquesList separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. If no value is entered, the script doesn't do anything. id: f1a71609-74ad-477a-81f2-a3f7c01b54c5 iscommand: false name: Set techniques information to the layout script: SetAndHandleEmpty type: regular version: -1 taskid: f1a71609-74ad-477a-81f2-a3f7c01b54c5 timertriggers: [] type: regular view: |- { "position": { "x": 160, "y": 1020 } } version: -1 view: |- { "linkLabelsPosition": { "11_3_#default#": 0.28, "13_3_#default#": 0.18, "7_3_#default#": 0.17, "7_9_yes": 0.57, "8_10_yes": 0.59, "8_3_#default#": 0.18 }, "paper": { "dimensions": { "height": 1205, "width": 1760, "x": -270, "y": 50 } } } tests: - No tests (auto formatted) fromversion: 6.5.0 marketplaces: - xsoar - marketplacev2 - platform