Courses of Action - Initial Access

This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input. ***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Tactic: - TA0001: Initial Access MITRE ATT&CK Description: The adversary is trying to get into your network. Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords. Possible playbook triggers: - The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

MITRE ATT&CK - Courses of Action · 23 tasks · 5 inputs · 2 outputs

Details

IDCourses of Action - Initial Access
From Version6.5.0
Tasks23

README

This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.

***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).

Tactic:

  • TA0001: Initial Access

MITRE ATT&CK Description:
The adversary is trying to get into your network.

Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.

Possible playbook triggers:

  • The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.
  • The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • MITRE ATT&CK CoA - T1078 - Valid Accounts
  • MITRE ATT&CK CoA - T1189 - Drive-by Compromise
  • MITRE ATT&CK CoA - T1199 - Trusted Relationship
  • MITRE ATT&CK CoA - T1133 - External Remote Services
  • MITRE ATT&CK CoA - T1566 - Phishing
  • MITRE ATT&CK CoA - T1566.001 - Spear-Phishing Attachment

Integrations

This playbook does not use any integrations.

Scripts

  • Set
  • SetAndHandleEmpty

Commands

  • setIncident

Playbook Inputs


Name Description Default Value Required
technique Mitre ATT&CK ID of a technique   Optional
template Template name to enforce WildFire best practices profile.   Optional
pre_post Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances.   Optional
device-group The device group for which to return addresses (Panorama instances).   Optional
tag Tag for which to filter the rules.   Optional

Playbook Outputs


Path Description Type
Handled.Techniques The techniques handled in this playbook string
InitialAccess.ProductList Products used for remediation. unknown

Playbook Image


Courses of Action - Initial Access

Inputs

  • technique — Mitre ATT&CK ID of a technique
  • template — Template name to enforce WildFire best practices profile.
  • pre_post — Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  • device-group — The device group for which to return addresses (Panorama instances).
  • tag — Tag for which to filter the rules.

Outputs

  • Handled.Techniques — The techniques handled in this playbook
  • InitialAccess.ProductList — Products used for remediation.

Commands used

setIncident

Flowchart

yes yes yes yes yes yes Start Start Done Done External Remote Services External Remote Services Trusted Relationship Trusted Relationship Drive-by Compromise Drive-by Compromise Valid Accounts Valid Accounts Spear-Phishing Attachment Spear-Phishing Attachment Phishing Phishing MITRE ATT&CK CoA - T1078 - Valid Accounts - MITRE ATT&CK CoA - T1078 - Valid Accounts MITRE ATT&CK CoA - T1078 ... MITRE ATT&CK CoA - T1078 - Va... MITRE ATT&CK CoA - T1189 - Drive-by Compromise - MITRE ATT&CK CoA - T1189 - Drive-by Compromise MITRE ATT&CK CoA - T1189 ... MITRE ATT&CK CoA - T1189 - Dr... MITRE ATT&CK CoA - T1199 - Trusted Relationship - MITRE ATT&CK CoA - T1199 - Trusted Relationship MITRE ATT&CK CoA - T1199 ... MITRE ATT&CK CoA - T1199 - Tr... MITRE ATT&CK CoA - T1566 - Phishing - MITRE ATT&CK CoA - T1566 - Phishing MITRE ATT&CK CoA - T1566 ... MITRE ATT&CK CoA - T1566 - Ph... MITRE ATT&CK CoA - T1566.001 - Spear-Phishing Attachment - MITRE ATT&CK CoA - T1566.001 - Spear-Phishing Attachment MITRE ATT&CK CoA - T1566.... MITRE ATT&CK CoA - T1566.001 ... MITRE ATT&CK CoA - T1133 - External Remote Services - MITRE ATT&CK CoA - T1133 - External Remote Services MITRE ATT&CK CoA - T1133 ... MITRE ATT&CK CoA - T1133 - Ex... Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set remediation products Set Initial Access Remediation products to the layout - setIncident Set Initial Access Remedi... setIncident Set techniques information to the layout Set techniques informatio... Set techniques information to the layout Set techniques informatio...
id: Courses of Action - Initial Access
name: Courses of Action - Initial Access
description: "This playbook handles MITRE ATT&CK Techniques using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. It utilizes each of the sub-playbooks for specific techniques that belong to this phase (tactic) according to the MITRE ATT&CK kill chain. The sub-playbook called depends on the technique input.\n \n***Disclaimer: This playbook does not simulate an attack using the specified techniques, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\n \nTactic:\n- TA0001: Initial Access\n\nMITRE ATT&CK Description: \nThe adversary is trying to get into your network.\n\nInitial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.\n\nPossible playbook triggers:\n- The playbook can be used as a part of the “Courses of Action - Collection” playbook to remediate techniques based on kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, that can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.\n"
inputs:
- description: Mitre ATT&CK ID of a technique
  key: technique
  playbookInputQuery:
  required: false
  value: {}
- description: Template name to enforce WildFire best practices profile.
  key: template
  playbookInputQuery:
  required: false
  value: {}
- description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  key: pre_post
  playbookInputQuery:
  required: false
  value: {}
- description: The device group for which to return addresses (Panorama instances).
  key: device-group
  playbookInputQuery:
  required: false
  value: {}
- description: Tag for which to filter the rules.
  key: tag
  playbookInputQuery:
  required: false
  value: {}
outputs:
- contextPath: Handled.Techniques
  description: The techniques handled in this playbook
  type: string
- contextPath: InitialAccess.ProductList
  description: Products used for remediation.
  type: unknown
starttaskid: "0"
system: true
tasks:
  "0":
    id: "0"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "10"
      - "14"
      - "15"
      - "11"
      - "12"
      - "13"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 2a74bce9-551b-4848-8cb3-c5d50bda5aca
      iscommand: false
      name: ""
      version: -1
      description: ''
    taskid: 2a74bce9-551b-4848-8cb3-c5d50bda5aca
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 1287.5,
          "y": 50
        }
      }
  "3":
    id: "3"
    ignoreworker: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 8820062a-1d3f-4210-83ca-ebb10fee34e5
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: 8820062a-1d3f-4210-83ca-ebb10fee34e5
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 1287.5,
          "y": 1210
        }
      }
  "10":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1133
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "10"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "21"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: b0f73144-6044-4fcb-83fd-ba3bb4dc996e
      iscommand: false
      name: External Remote Services
      description: ""
      type: condition
      version: -1
    taskid: b0f73144-6044-4fcb-83fd-ba3bb4dc996e
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 195
        }
      }
  "11":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1199
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "11"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "18"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: d9aee512-2229-47c5-8835-682787132331
      iscommand: false
      name: Trusted Relationship
      description: ""
      type: condition
      version: -1
    taskid: d9aee512-2229-47c5-8835-682787132331
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 1512.5,
          "y": 195
        }
      }
  "12":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1189
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "12"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "17"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 634b5301-8cf1-48a0-872f-b7ff6522ed7d
      iscommand: false
      name: Drive-by Compromise
      description: ""
      type: condition
      version: -1
    taskid: 634b5301-8cf1-48a0-872f-b7ff6522ed7d
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 1962.5,
          "y": 195
        }
      }
  "13":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1078
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "13"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "16"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 854b65ae-ca6e-49cd-8e9d-13f22333e450
      iscommand: false
      name: Valid Accounts
      description: ""
      type: condition
      version: -1
    taskid: 854b65ae-ca6e-49cd-8e9d-13f22333e450
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 2412.5,
          "y": 195
        }
      }
  "14":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1193
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
        - left:
            value:
              simple: T1566.001
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "14"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "20"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 346ea5b3-5d00-4fc7-8237-cfaf3720f7b4
      iscommand: false
      name: Spear-Phishing Attachment
      description: ""
      type: condition
      version: -1
    taskid: 346ea5b3-5d00-4fc7-8237-cfaf3720f7b4
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 195
        }
      }
  "15":
    conditions:
    - condition:
      - - left:
            value:
              simple: T1566
          operator: inList
          right:
            iscontext: true
            value:
              complex:
                root: inputs.technique
                transformers:
                - args:
                    delimiter:
                      value:
                        simple: ','
                  operator: split
      label: "yes"
    id: "15"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "19"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 0cf0567d-d1ab-4c03-8be0-d86dcc4dfb88
      iscommand: false
      name: Phishing
      description: ""
      type: condition
      version: -1
    taskid: 0cf0567d-d1ab-4c03-8be0-d86dcc4dfb88
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 1062.5,
          "y": 195
        }
      }
  "16":
    id: "16"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "22"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre_post:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 8375f529-ff96-4303-8e03-66c673b1a39e
      iscommand: false
      name: MITRE ATT&CK CoA - T1078 - Valid Accounts
      playbookId: MITRE ATT&CK CoA - T1078 - Valid Accounts
      type: playbook
      version: -1
      description: ''
    taskid: 8375f529-ff96-4303-8e03-66c673b1a39e
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 2412.5,
          "y": 370
        }
      }
  "17":
    id: "17"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "23"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre_post:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
      template:
        complex:
          root: inputs.template
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 1254ba96-d3ee-480d-8efe-18fafc37d04f
      iscommand: false
      name: MITRE ATT&CK CoA - T1189 - Drive-by Compromise
      playbookId: MITRE ATT&CK CoA - T1189 - Drive-by Compromise
      type: playbook
      version: -1
      description: ''
    taskid: 1254ba96-d3ee-480d-8efe-18fafc37d04f
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 1962.5,
          "y": 370
        }
      }
  "18":
    id: "18"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "24"
    note: false
    quietmode: 0
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: b6526849-6ce1-4aa6-84dc-f0e1e9f219de
      iscommand: false
      name: MITRE ATT&CK CoA - T1199 - Trusted Relationship
      playbookId: MITRE ATT&CK CoA - T1199 - Trusted Relationship
      type: playbook
      version: -1
      description: ''
    taskid: b6526849-6ce1-4aa6-84dc-f0e1e9f219de
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 1512.5,
          "y": 370
        }
      }
  "19":
    id: "19"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "25"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre_post:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
      template:
        complex:
          root: inputs.template
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 3816bdaf-2ea9-44a9-8354-ad8731ace6d9
      iscommand: false
      name: MITRE ATT&CK CoA - T1566 - Phishing
      playbookId: MITRE ATT&CK CoA - T1566 - Phishing
      type: playbook
      version: -1
      description: ''
    taskid: 3816bdaf-2ea9-44a9-8354-ad8731ace6d9
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 1062.5,
          "y": 370
        }
      }
  "20":
    id: "20"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "26"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre_post:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
      template:
        complex:
          root: inputs.template
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 00861e9d-7456-497f-8d46-7b84174135c8
      iscommand: false
      name: MITRE ATT&CK CoA - T1566.001 - Spear-Phishing Attachment
      playbookId: MITRE ATT&CK CoA - T1566.001 - Spear-Phishing Attachment
      type: playbook
      version: -1
      description: ''
    taskid: 00861e9d-7456-497f-8d46-7b84174135c8
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 370
        }
      }
  "21":
    id: "21"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "27"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre_post:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
    separatecontext: true
    skipunavailable: false
    task:
      brand: ""
      id: 375833bb-fc1f-4154-85aa-825af60070d7
      iscommand: false
      name: MITRE ATT&CK CoA - T1133 - External Remote Services
      playbookId: MITRE ATT&CK CoA - T1133 - External Remote Services
      type: playbook
      version: -1
      description: ''
    taskid: 375833bb-fc1f-4154-85aa-825af60070d7
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 370
        }
      }
  "22":
    id: "22"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "28"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: InitialAccess.Products
      value:
        simple: '["Cortex XSOAR","PAN-OS"]'
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: dc6fd1ee-a660-43fe-895d-5ece5c092583
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: dc6fd1ee-a660-43fe-895d-5ece5c092583
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 2412.5,
          "y": 540
        }
      }
  "23":
    id: "23"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "28"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: InitialAccess.Products
      value:
        simple: PAN-OS
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 2c35c341-fb76-4a24-8136-8f7109575c9f
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 2c35c341-fb76-4a24-8136-8f7109575c9f
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 1962.5,
          "y": 540
        }
      }
  "24":
    id: "24"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "28"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: InitialAccess.Products
      value:
        simple: PAN-OS
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: ab0667a0-eb8f-4bc0-88d8-df72499316e6
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: ab0667a0-eb8f-4bc0-88d8-df72499316e6
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 1512.5,
          "y": 540
        }
      }
  "25":
    id: "25"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "28"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: InitialAccess.Products
      value:
        simple: '["Cortex XSOAR","PAN-OS","Cortex XDR"]'
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 2751c072-388e-4fdc-8ec3-7f251522c0aa
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 2751c072-388e-4fdc-8ec3-7f251522c0aa
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 1062.5,
          "y": 540
        }
      }
  "26":
    id: "26"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "28"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: InitialAccess.Products
      value:
        simple: '["PAN-OS","Cortex XDR"]'
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 9175d50b-803e-4de2-8316-d838e96a7c9f
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 9175d50b-803e-4de2-8316-d838e96a7c9f
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 540
        }
      }
  "27":
    id: "27"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "28"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: InitialAccess.Products
      value:
        simple: '["PAN-OS","Cortex XDR"]'
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 5508ea1d-bc35-4b83-81c1-c42c38388c44
      iscommand: false
      name: Set remediation products
      script: Set
      type: regular
      version: -1
    taskid: 5508ea1d-bc35-4b83-81c1-c42c38388c44
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 540
        }
      }
  "28":
    id: "28"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "29"
    note: false
    quietmode: 0
    scriptarguments:
      initialaccessremediationproducts:
        complex:
          root: InitialAccess
          transformers:
          - operator: uniq
    separatecontext: false
    skipunavailable: false
    task:
      brand: Builtin
      description: commands.local.cmd.set.incident
      id: 3a07dde9-b7cd-49de-8eae-649b39bd022c
      iscommand: true
      name: Set Initial Access Remediation products to the layout
      script: Builtin|||setIncident
      type: regular
      version: -1
    taskid: 3a07dde9-b7cd-49de-8eae-649b39bd022c
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 710
        }
      }
  "29":
    id: "29"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "30"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 4ec4f1ba-3914-4a4d-8dbe-d2bbecac6a3d
      iscommand: false
      name: Set techniques information to the layout
      description: ""
      type: title
      version: -1
    taskid: 4ec4f1ba-3914-4a4d-8dbe-d2bbecac6a3d
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 890
        }
      }
  "30":
    fieldMapping:
    - incidentfield: Remediated Techniques
      output:
        complex:
          root: Handled
          transformers:
          - args:
              title: {}
            operator: JsonToTable
    - incidentfield: Techniques to Handle
      output:
        complex:
          root: Unhandled
          transformers:
          - args:
              title: {}
            operator: JsonToTable
    id: "30"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "3"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "false"
      key:
        simple: Unhandled.Techniques
      stringify: {}
      value:
        complex:
          filters:
          - - left:
                iscontext: true
                value:
                  simple: TechniquesList
              operator: notIn
              right:
                iscontext: true
                value:
                  simple: Handled.Techniques
          root: TechniquesList
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered. If no value is entered, the script doesn't do anything.
      id: cf52482e-48bc-4b06-89d3-306bb2468aaf
      iscommand: false
      name: Set techniques information to the layout
      script: SetAndHandleEmpty
      type: regular
      version: -1
    taskid: cf52482e-48bc-4b06-89d3-306bb2468aaf
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 612.5,
          "y": 1040
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {
      "10_3_#default#": 0.19,
      "11_3_#default#": 0.38,
      "12_3_#default#": 0.29,
      "13_3_#default#": 0.18,
      "14_3_#default#": 0.29,
      "15_3_#default#": 0.37
    },
    "paper": {
      "dimensions": {
        "height": 1225,
        "width": 2630,
        "x": 162.5,
        "y": 50
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.5.0