Endpoint Investigation Plan

This playbook handles all the endpoint investigation actions by performing the following tasks on every alert associated with the incident: * Pre-defined MITRE Tactics * Host fields (Host ID) * Attacker fields (Attacker IP, External host) * MITRE techniques * File hash (currently, the playbook supports only SHA256) Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.

Common Playbooks · 53 tasks · 20 inputs · 0 outputs

Details

IDEndpoint Investigation Plan
From Version6.6.0
Tasks53

README

This playbook handles all the endpoint investigation actions by performing the following tasks on every alert associated with the incident:

  • Pre-defined MITRE Tactics
  • Host fields (Host ID)
  • Attacker fields (Attacker IP, External host)
  • MITRE techniques
  • File hash (currently, the playbook supports only SHA256)

Note: The playbook inputs enable manipulating the execution flow; read the input descriptions for details.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

  • SearchIncidentsV2

Commands

This playbook does not use any commands.

Playbook Inputs


Name Description Default Value Required
HuntReconnaissanceTechniques Set to True to hunt for identified alerts with MITRE Reconnaissance techniques. True Optional
HuntInitialAccessTechniques Set to True to hunt for identified alerts with MITRE Access techniques. True Optional
HuntExecutionTechniques Set to True to hunt for identified alerts with MITRE Execution techniques. True Optional
HuntPersistenceTechniques Set to True to hunt for identified alerts with MITRE Persistence techniques. True Optional
HuntPrivilegeEscalationTechniques Set to True to hunt for identified alerts with MITRE Privilege Escalation techniques. True Optional
HuntDefenseEvasionTechniques Set to True to hunt for identified alerts with MITRE Defense Evasion techniques. True Optional
HuntDiscoveryTechniques Set to True to hunt for identified alerts with MITRE Discovery techniques. True Optional
HuntLateralMovementTechniques Set to True to hunt for identified alerts with MITRE Lateral Movement techniques. True Optional
HuntCollectionTechniques Set to True to hunt for MITRE Collection techniques identified alerts. True Optional
HuntCnCTechniques Set to True to hunt for identified alerts with MITRE Command and Control techniques. True Optional
HuntImpactTechniques Set to True to hunt for identified alerts with MITRE Impact techniques. True Optional
HuntAttacker Set to True to hunt the attacker IP address or external hostname.   Optional
HuntByTechnique Set to True to hunt by a specific MITRE technique.   Optional
HuntByHost Set to True to hunt by the endpoint ID. The agentID input must be provided as well.   Optional
HuntByFile Boolean. Set to True to hunt by a specific file hash.
Supports SHA256.
  Optional
agentID The agent ID. * Optional
attackerRemoteIP The IP address of the attacker. The ‘HuntAttacker’ inputs should also be set to True.   Optional
attackerExternalHost The external host used by the attacker. The ‘HuntAttacker’ inputs should also be set to True.   Optional
mitreTechniqueID A MITRE technique identifier. The ‘HuntByTechnique’ inputs should also be set to True.   Optional
FileSHA256 The file SHA256. The ‘HuntByFile’ inputs should also be set to True.   Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Endpoint Investigation Plan

Inputs

  • HuntReconnaissanceTechniques — Set to True to hunt for identified alerts with MITRE Reconnaissance techniques.
  • HuntInitialAccessTechniques — Set to True to hunt for identified alerts with MITRE Access techniques.
  • HuntExecutionTechniques — Set to True to hunt for identified alerts with MITRE Execution techniques.
  • HuntPersistenceTechniques — Set to True to hunt for identified alerts with MITRE Persistence techniques.
  • HuntPrivilegeEscalationTechniques — Set to True to hunt for identified alerts with MITRE Privilege Escalation techniques.
  • HuntDefenseEvasionTechniques — Set to True to hunt for identified alerts with MITRE Defense Evasion techniques.
  • HuntDiscoveryTechniques — Set to True to hunt for identified alerts with MITRE Discovery techniques.
  • HuntLateralMovementTechniques — Set to True to hunt for identified alerts with MITRE Lateral Movement techniques.
  • HuntCollectionTechniques — Set to True to hunt for MITRE Collection techniques identified alerts.
  • HuntCnCTechniques — Set to True to hunt for identified alerts with MITRE Command and Control techniques.
  • HuntImpactTechniques — Set to True to hunt for identified alerts with MITRE Impact techniques.
  • HuntAttacker — Set to True to hunt the attacker IP address or external hostname.
  • HuntByTechnique — Set to True to hunt by a specific MITRE technique.
  • HuntByHost — Set to True to hunt by the endpoint ID. The agentID input must be provided as well.
  • HuntByFile — Boolean. Set to True to hunt by a specific file hash. Supports SHA256.
  • agentID — The agent ID.
  • attackerRemoteIP — The IP address of the attacker. The 'HuntAttacker' inputs should also be set to True.
  • attackerExternalHost — The external host used by the attacker. The 'HuntAttacker' inputs should also be set to True.
  • mitreTechniqueID — A MITRE technique identifier. The 'HuntByTechnique' inputs should also be set to True.
  • FileSHA256 — The file SHA256. The 'HuntByFile' inputs should also be set to True.

Flowchart

yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes yes Start Start Should hunt for Discovery techniques? Should hunt for Discovery... Should hunt for Persistence techniques? Should hunt for Persisten... Should hunt for Initial Access techniques? Should hunt for Initial A... Should hunt for Privilege Escalation techniques? Should hunt for Privilege... Should hunt for Defense Evasion techniques? Should hunt for Defense E... Should hunt for Execution techniques? Should hunt for Execution... Should hunt for Lateral Movement techniques? Should hunt for Lateral M... Should hunt for Collection techniques? Should hunt for Collectio... Should investigate by attacker source IP? Should investigate by att... Should hunt by host fields? Should hunt by host fields? Should investigate by MITRE techniques? Should investigate by MIT... Should investigate by file hash? Should investigate by fil... Done Done Persistence Persistence Hunt Persistence techniques - SearchIncidentsV2 Hunt Persistence techniques SearchIncidentsV2 Initial Access Initial Access Execution Execution Privilege Escalation Privilege Escalation Defense Evasion Defense Evasion Discovery Discovery Lateral Movement Lateral Movement Collection Collection Should hunt for CnC techniques? Should hunt for CnC techn... Should hunt for Impact techniques? Should hunt for Impact te... Command and Control Command and Control Impact Impact Should hunt for suspicious Reconnaissance techniques? Should hunt for suspiciou... Reconnaissance Reconnaissance Hunt Reconnaissance techniques - SearchIncidentsV2 Hunt Reconnaissance techn... SearchIncidentsV2 Hunt Initial Access techniques - SearchIncidentsV2 Hunt Initial Access techn... SearchIncidentsV2 Hunt Execution techniques - SearchIncidentsV2 Hunt Execution techniques SearchIncidentsV2 Hunt Privilege Escalation techniques - SearchIncidentsV2 Hunt Privilege Escalation... SearchIncidentsV2 Hunt Defense Evasion techniques - SearchIncidentsV2 Hunt Defense Evasion tech... SearchIncidentsV2 Hunt Discovery techniques - SearchIncidentsV2 Hunt Discovery techniques SearchIncidentsV2 Hunt Lateral Movement techniques - SearchIncidentsV2 Hunt Lateral Movement tec... SearchIncidentsV2 Hunt Collection techniques - SearchIncidentsV2 Hunt Collection techniques SearchIncidentsV2 Hunt Command and Control techniques - SearchIncidentsV2 Hunt Command and Control ... SearchIncidentsV2 Hunt Impact techniques - SearchIncidentsV2 Hunt Impact techniques SearchIncidentsV2 Host activity Host activity Hunt by host ID - SearchIncidentsV2 Hunt by host ID SearchIncidentsV2 Attacker network activity Attacker network activity Hunt by attacker source IP - SearchIncidentsV2 Hunt by attacker source IP SearchIncidentsV2 MITRE Techniques MITRE Techniques Hunt by technique ID - SearchIncidentsV2 Hunt by technique ID SearchIncidentsV2 Hunt File Hash Hunt File Hash Hunt by file hash - SearchIncidentsV2 Hunt by file hash SearchIncidentsV2 Hunt by MITRE Tactics Hunt by MITRE Tactics Hunt by Indicators Hunt by Indicators Done Done Should investigate by attacker's external host? Should investigate by att... Attacker network activity Attacker network activity Hunt by attacker source external host - SearchIncidentsV2 Hunt by attacker source e... SearchIncidentsV2
id: Endpoint Investigation Plan
version: -1
contentitemexportablefields:
  contentitemfields: {}
name: Endpoint Investigation Plan
description: "This playbook handles all the endpoint investigation actions by performing the following tasks  on every alert associated with the incident:\n* Pre-defined MITRE Tactics\n* Host fields (Host ID)\n* Attacker fields (Attacker IP, External host)\n* MITRE techniques\n* File hash (currently, the playbook supports only SHA256)  \n\nNote: The playbook inputs enable manipulating the execution flow; read the input descriptions for details."
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 26771da9-59e7-422f-8f4b-5c08be96bdfa
    type: start
    task:
      id: 26771da9-59e7-422f-8f4b-5c08be96bdfa
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "50"
      - "51"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 880,
          "y": -1090
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 81e61b1f-bd6c-4751-856d-c11bdd35354f
    type: condition
    task:
      id: 81e61b1f-bd6c-4751-856d-c11bdd35354f
      version: -1
      name: Should hunt for Discovery techniques?
      description: Whether to hunt for discovery techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "7"
      "yes":
      - "20"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntDiscoveryTechniques
            iscontext: true
          right:
            value:
              simple: "True"
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: 26f1e9ec-dddf-454a-8d1c-e770f7a0a4d7
    type: condition
    task:
      id: 26f1e9ec-dddf-454a-8d1c-e770f7a0a4d7
      version: -1
      name: Should hunt for Persistence techniques?
      description: Whether to hunt for persistence techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "4"
      "yes":
      - "14"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntPersistenceTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 650
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "3":
    id: "3"
    taskid: 6631c326-a3b2-4bf9-859e-e7718e61eb1e
    type: condition
    task:
      id: 6631c326-a3b2-4bf9-859e-e7718e61eb1e
      version: -1
      name: Should hunt for Initial Access techniques?
      description: Whether to hunt for initial access techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "6"
      "yes":
      - "16"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntInitialAccessTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": -290
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: 018c1cab-9901-43fa-8995-ee0325036bcb
    type: condition
    task:
      id: 018c1cab-9901-43fa-8995-ee0325036bcb
      version: -1
      name: Should hunt for Privilege Escalation techniques?
      description: Whether to hunt for privilege escalation techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "18"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntPrivilegeEscalationTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "5":
    id: "5"
    taskid: baa1e20f-4b89-4ef2-86e4-2eaf12d733c2
    type: condition
    task:
      id: baa1e20f-4b89-4ef2-86e4-2eaf12d733c2
      version: -1
      name: Should hunt for Defense Evasion techniques?
      description: Whether to hunt for defense evasion techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "1"
      "yes":
      - "19"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntDefenseEvasionTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1590
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: 6daefce0-8773-4e2b-84c0-c298adf12464
    type: condition
    task:
      id: 6daefce0-8773-4e2b-84c0-c298adf12464
      version: -1
      name: Should hunt for Execution techniques?
      description: Whether to hunt for execution techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "2"
      "yes":
      - "17"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntExecutionTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: b0f80114-76f0-4a92-8e6c-b74f4ee31de6
    type: condition
    task:
      id: b0f80114-76f0-4a92-8e6c-b74f4ee31de6
      version: -1
      name: Should hunt for Lateral Movement techniques?
      description: Whether to hunt for lateral movement techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "8"
      "yes":
      - "21"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntLateralMovementTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2550
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: 87c3bced-78d4-49ce-83a9-e99b8df241e3
    type: condition
    task:
      id: 87c3bced-78d4-49ce-83a9-e99b8df241e3
      version: -1
      name: Should hunt for Collection techniques?
      description: Whether to hunt for collection techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "23"
      "yes":
      - "22"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntCollectionTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 3045
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: 4814aba4-bd30-4c19-895a-8d3e28e73393
    type: condition
    task:
      id: 4814aba4-bd30-4c19-895a-8d3e28e73393
      version: -1
      name: Should investigate by attacker source IP?
      description: Whether to hunt by the attacker indicators.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "53"
      "yes":
      - "43"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntAttacker
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.attackerRemoteIP
            iscontext: true
    view: |-
      {
        "position": {
          "x": 1310,
          "y": -290
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "10":
    id: "10"
    taskid: c896ea76-878a-43f4-80bd-5d5be9f46fc2
    type: condition
    task:
      id: c896ea76-878a-43f4-80bd-5d5be9f46fc2
      version: -1
      name: Should hunt by host fields?
      description: Whether to hunt by the host fields.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "9"
      "yes":
      - "39"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntByHost
            iscontext: true
          right:
            value:
              simple: "True"
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.agentID
            iscontext: true
    view: |-
      {
        "position": {
          "x": 1310,
          "y": -770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "11":
    id: "11"
    taskid: 7553edad-1b98-4459-834c-07f66fe82731
    type: condition
    task:
      id: 7553edad-1b98-4459-834c-07f66fe82731
      version: -1
      name: Should investigate by MITRE techniques?
      description: Whether to hunt by MITRE technique.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "12"
      "yes":
      - "46"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntByTechnique
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.mitreTechniqueID
            iscontext: true
    view: |-
      {
        "position": {
          "x": 1310,
          "y": 670
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: d2a6e731-c4f1-4e1c-8cfe-ff42b7726e8a
    type: condition
    task:
      id: d2a6e731-c4f1-4e1c-8cfe-ff42b7726e8a
      version: -1
      name: Should investigate by file hash?
      description: Whether to hunt by file hash.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "13"
      "yes":
      - "48"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntByFile
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.FileSHA256
            iscontext: true
    view: |-
      {
        "position": {
          "x": 1310,
          "y": 1140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: bd9e01ff-9927-453d-8702-b81c3fe81f0a
    type: title
    task:
      id: bd9e01ff-9927-453d-8702-b81c3fe81f0a
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1310,
          "y": 1625
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "14":
    id: "14"
    taskid: aa13b3d0-4124-4586-87d0-a122a811588e
    type: title
    task:
      id: aa13b3d0-4124-4586-87d0-a122a811588e
      version: -1
      name: Persistence
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "15"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 820
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "15":
    id: "15"
    taskid: c171f1d7-1909-4e3e-8e4d-66761315d8d6
    type: regular
    task:
      id: c171f1d7-1909-4e3e-8e4d-66761315d8d6
      version: -1
      name: Hunt Persistence techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*1037* or mitreattcktechnique:*T1542* or mitreattcktechnique:*T1053* or mitreattcktechnique:*T1543.002* or mitreattcktechnique:*T1543.003* or mitreattcktechnique:*T1569.002* or mitreattcktechnique:*T1547.001* or mitreattcktechnique:*T1547.005* or mitreattcktechnique:*T1546.002* or mitreattcktechnique:*T1546.011* or mitreattcktechnique:*T1546.012* or mitreattcktechnique:*T1136* or mitreattcktechnique:*T1150*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 950
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "16":
    id: "16"
    taskid: 17850962-ee9d-462e-8a68-86992f3476b1
    type: title
    task:
      id: 17850962-ee9d-462e-8a68-86992f3476b1
      version: -1
      name: Initial Access
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "30"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": -120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 38d79a1d-432e-4b43-84fb-2df946466f06
    type: title
    task:
      id: 38d79a1d-432e-4b43-84fb-2df946466f06
      version: -1
      name: Execution
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "31"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 350
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "18":
    id: "18"
    taskid: 54aede8a-286a-47f8-8578-da4cd0b042ce
    type: title
    task:
      id: 54aede8a-286a-47f8-8578-da4cd0b042ce
      version: -1
      name: Privilege Escalation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "32"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 1290
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "19":
    id: "19"
    taskid: d9287202-7433-4836-8e86-59f0acebaf1b
    type: title
    task:
      id: d9287202-7433-4836-8e86-59f0acebaf1b
      version: -1
      name: Defense Evasion
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "33"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 1760
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: bb43e613-8041-41cc-8d6a-031d2ea4bcb6
    type: title
    task:
      id: bb43e613-8041-41cc-8d6a-031d2ea4bcb6
      version: -1
      name: Discovery
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "34"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 2240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: e132947f-bf00-48da-8305-fa34c72c42dc
    type: title
    task:
      id: e132947f-bf00-48da-8305-fa34c72c42dc
      version: -1
      name: Lateral Movement
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "35"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 2720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: 7f301311-2cb6-4f0a-8d10-4e8d5f82cea1
    type: title
    task:
      id: 7f301311-2cb6-4f0a-8d10-4e8d5f82cea1
      version: -1
      name: Collection
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "36"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 3220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 1ff80560-73b2-4e6d-8713-fdbddb0c8958
    type: condition
    task:
      id: 1ff80560-73b2-4e6d-8713-fdbddb0c8958
      version: -1
      name: Should hunt for CnC techniques?
      description: Whether to hunt for command and control techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "24"
      "yes":
      - "25"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntCnCTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 3530
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "24":
    id: "24"
    taskid: 21f9942f-6dd3-426f-8e9a-eb3ae3a2fb4b
    type: condition
    task:
      id: 21f9942f-6dd3-426f-8e9a-eb3ae3a2fb4b
      version: -1
      name: Should hunt for Impact techniques?
      description: Whether to hunt for impact techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "52"
      "yes":
      - "26"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntImpactTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": 4000
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "25":
    id: "25"
    taskid: ff4496b4-e914-4bba-8112-6ed6b4508c79
    type: title
    task:
      id: ff4496b4-e914-4bba-8112-6ed6b4508c79
      version: -1
      name: Command and Control
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "37"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 3700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "26":
    id: "26"
    taskid: c89859a8-0333-4872-8dc7-9feb1fad74fb
    type: title
    task:
      id: c89859a8-0333-4872-8dc7-9feb1fad74fb
      version: -1
      name: Impact
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "38"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 4170
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: 9cd16df8-9f8c-4040-81e9-345ffb028daf
    type: condition
    task:
      id: 9cd16df8-9f8c-4040-81e9-345ffb028daf
      version: -1
      name: Should hunt for suspicious Reconnaissance techniques?
      description: Whether to hunt for reconnaissance techniques.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "28"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntReconnaissanceTechniques
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 450,
          "y": -770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: fda5f54d-76eb-4fba-8dd4-7e74b0e9da86
    type: title
    task:
      id: fda5f54d-76eb-4fba-8dd4-7e74b0e9da86
      version: -1
      name: Reconnaissance
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "29"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": -600
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "29":
    id: "29"
    taskid: fe8a2a21-ea37-4a7d-8c9c-156ae13b2c3a
    type: regular
    task:
      id: fe8a2a21-ea37-4a7d-8c9c-156ae13b2c3a
      version: -1
      name: Hunt Reconnaissance techniques
      description: |-
        Searches Cortex XSIAM incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      query:
        simple: mitreattcktechnique:*T1595* and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": -470
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "30":
    id: "30"
    taskid: fcaf59e8-6da8-4276-8d68-01bbf4b32ad8
    type: regular
    task:
      id: fcaf59e8-6da8-4276-8d68-01bbf4b32ad8
      version: -1
      name: Hunt Initial Access techniques
      description: |-
        Searches Cortex XSIAM incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "6"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*T1078* or mitreattcktechnique:*T1078.002*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 10
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "31":
    id: "31"
    taskid: a9a020af-3724-46e0-8895-d9ac8b8db88a
    type: regular
    task:
      id: a9a020af-3724-46e0-8895-d9ac8b8db88a
      version: -1
      name: Hunt Execution techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "2"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*T1204* or mitreattcktechnique:*T1569.002* or mitreattcktechnique:*T1059.001* or mitreattcktechnique:*T1059.002* or mitreattcktechnique:*T1059.004* or mitreattcktechnique:*T1059.005*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "32":
    id: "32"
    taskid: fc87d063-74fb-4c8a-8fbf-59b6f64fbf26
    type: regular
    task:
      id: fc87d063-74fb-4c8a-8fbf-59b6f64fbf26
      version: -1
      name: Hunt Privilege Escalation techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*T1055* or mitreattcktechnique:*T1546.001*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 1420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "33":
    id: "33"
    taskid: e7403fe7-b8b6-4a35-88d8-d78b140cc703
    type: regular
    task:
      id: e7403fe7-b8b6-4a35-88d8-d78b140cc703
      version: -1
      name: Hunt Defense Evasion techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "1"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*T1218.005* or mitreattcktechnique:*T1218.008* or mitreattcktechnique:*T1218.011* or mitreattcktechnique:*T1036* or mitreattcktechnique:*T1140* or mitreattcktechnique:*T1564.001* or mitreattcktechnique:*T1222* or mitreattcktechnique:*T1197*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 1900
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "34":
    id: "34"
    taskid: 9f0fdace-ea0d-4667-80b3-192681279a76
    type: regular
    task:
      id: 9f0fdace-ea0d-4667-80b3-192681279a76
      version: -1
      name: Hunt Discovery techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*1087* or mitreattcktechnique:*1046* or mitreattcktechnique:*1018* or mitreattcktechnique:*1135* or mitreattcktechnique:*1016*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 2380
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: e5c9f989-be36-4539-8b14-b452403671a1
    type: regular
    task:
      id: e5c9f989-be36-4539-8b14-b452403671a1
      version: -1
      name: Hunt Lateral Movement techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*1021.001* or mitreattcktechnique:*1021.002* or mitreattcktechnique:*1021.003* or mitreattcktechnique:*1021.006* or mitreattcktechnique:*1021* or mitreattcktechnique:*1550.002*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 2870
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: 4229a499-c399-49db-8be6-e72102760e0a
    type: regular
    task:
      id: 4229a499-c399-49db-8be6-e72102760e0a
      version: -1
      name: Hunt Collection techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "23"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*1213*  or mitreattcktechnique:*1074* or mitreattcktechnique:*1074.001*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 3360
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "37":
    id: "37"
    taskid: c31cce38-c1cd-4b87-8ea8-ab7d1962d945
    type: regular
    task:
      id: c31cce38-c1cd-4b87-8ea8-ab7d1962d945
      version: -1
      name: Hunt Command and Control techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "24"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*1132*  or mitreattcktechnique:*1102* or mitreattcktechnique:*1071*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 3830
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "38":
    id: "38"
    taskid: cb04294c-829c-492d-89f7-3bd67e3031b8
    type: regular
    task:
      id: cb04294c-829c-492d-89f7-3bd67e3031b8
      version: -1
      name: Hunt Impact techniques
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "52"
    scriptarguments:
      query:
        simple: (mitreattcktechnique:*1561*  or mitreattcktechnique:*1485* or mitreattcktechnique:*1486* or mitreattcktechnique:*1490* or mitreattcktechnique:*1495*) and agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 40,
          "y": 4310
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "39":
    id: "39"
    taskid: 790c95cf-af51-440a-8cc6-0d22ec470532
    type: title
    task:
      id: 790c95cf-af51-440a-8cc6-0d22ec470532
      version: -1
      name: Host activity
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "41"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": -600
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "41":
    id: "41"
    taskid: 51eb1abc-7166-45d8-83c0-9829258bb17d
    type: regular
    task:
      id: 51eb1abc-7166-45d8-83c0-9829258bb17d
      version: -1
      name: Hunt by host ID
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      query:
        simple: agentid:${inputs.agentID} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": -470
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "43":
    id: "43"
    taskid: d679a72b-0099-4649-8887-8458fb29b79c
    type: title
    task:
      id: d679a72b-0099-4649-8887-8458fb29b79c
      version: -1
      name: Attacker network activity
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "44"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": -120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "44":
    id: "44"
    taskid: 5f2ba1a9-54c3-4c18-8332-31e820dc3238
    type: regular
    task:
      id: 5f2ba1a9-54c3-4c18-8332-31e820dc3238
      version: -1
      name: Hunt by attacker source IP
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "53"
    scriptarguments:
      query:
        simple: localip:${inputs.attackerRemoteIP} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 10
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "46":
    id: "46"
    taskid: 710569db-85e4-4d8d-8f63-dd9904d01d04
    type: title
    task:
      id: 710569db-85e4-4d8d-8f63-dd9904d01d04
      version: -1
      name: MITRE Techniques
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "47"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 840
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "47":
    id: "47"
    taskid: 90e12387-bcbb-4341-85e2-22f89ede1b50
    type: regular
    task:
      id: 90e12387-bcbb-4341-85e2-22f89ede1b50
      version: -1
      name: Hunt by technique ID
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "12"
    scriptarguments:
      query:
        simple: mitreattcktechnique:*${inputs.mitreTechniqueID}* and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 970
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "48":
    id: "48"
    taskid: d481827b-144e-4cc6-8dff-92f2293d587e
    type: title
    task:
      id: d481827b-144e-4cc6-8dff-92f2293d587e
      version: -1
      name: Hunt File Hash
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "49"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 1310
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "49":
    id: "49"
    taskid: 6a9284a2-6372-48c8-83ef-5588d41fca18
    type: regular
    task:
      id: 6a9284a2-6372-48c8-83ef-5588d41fca18
      version: -1
      name: Hunt by file hash
      description: |-
        Searches Demisto incidents.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "13"
    scriptarguments:
      query:
        simple: (initiatorsha256:${inputs.FileSHA256} or cgosha256:${inputs.FileSHA256} or filesha256:${inputs.FileSHA256} or filemacrosha256:${inputs.FileSHA256} or osparentsha256:${inputs.FileSHA256}) and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 1440
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "50":
    id: "50"
    taskid: c224069c-cebb-446b-8dc6-07d9a5a63438
    type: title
    task:
      id: c224069c-cebb-446b-8dc6-07d9a5a63438
      version: -1
      name: Hunt by MITRE Tactics
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "27"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 450,
          "y": -940
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "51":
    id: "51"
    taskid: 1b10baff-223f-4a9b-88fc-f6e30e6d0273
    type: title
    task:
      id: 1b10baff-223f-4a9b-88fc-f6e30e6d0273
      version: -1
      name: Hunt by Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "10"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1310,
          "y": -940
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "52":
    id: "52"
    taskid: f5f485bf-8035-4c97-8529-bc289e584adf
    type: title
    task:
      id: f5f485bf-8035-4c97-8529-bc289e584adf
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 450,
          "y": 4480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "53":
    id: "53"
    taskid: ea421052-65ec-4e66-81e9-179f1b37c4c3
    type: condition
    task:
      id: ea421052-65ec-4e66-81e9-179f1b37c4c3
      version: -1
      name: Should investigate by attacker's external host?
      description: Whether to hunt by the attacker indicators.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "11"
      "yes":
      - "54"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.HuntAttacker
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.attackerExternalHost
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1310,
          "y": 180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "54":
    id: "54"
    taskid: 94139bf4-5524-4a4a-8d8e-d3860d4d1054
    type: title
    task:
      id: 94139bf4-5524-4a4a-8d8e-d3860d4d1054
      version: -1
      name: Attacker network activity
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "55"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 350
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "55":
    id: "55"
    taskid: 82c5b670-b168-4827-818e-917e725f93b8
    type: regular
    task:
      id: 82c5b670-b168-4827-818e-917e725f93b8
      version: -1
      name: Hunt by attacker source external host
      description: |-
        Searches Demisto alerts.

        This automation runs using the default Limited User role, unless you explicitly change the permissions.
        For more information, see the section about permissions here:
        - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations 
        - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script
        - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "11"
    scriptarguments:
      query:
        simple: dnsqueryname:${inputs.attackerExternalHost} and caseid:${parentIncidentFields.incident_id}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1710,
          "y": 490
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 5635,
        "width": 2050,
        "x": 40,
        "y": -1090
      }
    }
  }
inputs:
- key: HuntReconnaissanceTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Reconnaissance techniques.
  playbookInputQuery:
- key: HuntInitialAccessTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Access techniques.
  playbookInputQuery:
- key: HuntExecutionTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Execution techniques.
  playbookInputQuery:
- key: HuntPersistenceTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Persistence techniques.
  playbookInputQuery:
- key: HuntPrivilegeEscalationTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Privilege Escalation techniques.
  playbookInputQuery:
- key: HuntDefenseEvasionTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Defense Evasion techniques.
  playbookInputQuery:
- key: HuntDiscoveryTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Discovery techniques.
  playbookInputQuery:
- key: HuntLateralMovementTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Lateral Movement techniques.
  playbookInputQuery:
- key: HuntCollectionTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for MITRE Collection techniques identified alerts.
  playbookInputQuery:
- key: HuntCnCTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Command and Control techniques.
  playbookInputQuery:
- key: HuntImpactTechniques
  value:
    simple: "True"
  required: false
  description: Set to True to hunt for identified alerts with MITRE Impact techniques.
  playbookInputQuery:
- key: HuntAttacker
  value: {}
  required: false
  description: Set to True to hunt the attacker IP address or external hostname.
  playbookInputQuery:
- key: HuntByTechnique
  value: {}
  required: false
  description: Set to True to hunt by a specific MITRE technique.
  playbookInputQuery:
- key: HuntByHost
  value: {}
  required: false
  description: Set to True to hunt by the endpoint ID. The agentID input must be provided as well.
  playbookInputQuery:
- key: HuntByFile
  value: {}
  required: false
  description: |-
    Boolean. Set to True to hunt by a specific file hash.
    Supports SHA256.
  playbookInputQuery:
- key: agentID
  value:
    simple: '*'
  required: false
  description: The agent ID.
  playbookInputQuery:
- key: attackerRemoteIP
  value: {}
  required: false
  description: The IP address of the attacker. The 'HuntAttacker' inputs should also be set to True.
  playbookInputQuery:
- key: attackerExternalHost
  value: {}
  required: false
  description: The external host used by the attacker. The 'HuntAttacker' inputs should also be set to True.
  playbookInputQuery:
- key: mitreTechniqueID
  value: {}
  required: false
  description: A MITRE technique identifier. The 'HuntByTechnique' inputs should also be set to True.
  playbookInputQuery:
- key: FileSHA256
  value: {}
  required: false
  description: The file SHA256. The 'HuntByFile' inputs should also be set to True.
  playbookInputQuery:
outputs: []
tests:
- Endpoint Investigation Plan - Test
marketplaces:
- marketplacev2
- platform
- xpanse
fromversion: 6.6.0