Endpoint Malware Investigation - Generic Deprecated

Deprecated. Use 'Malware Investigation & Response Incident handler' instead. (From the 'Malware Investigation And Response Pack') This playbook is triggered by a malware incident from an 'Endpoint' type integration. The playbook performs enrichment, detonation, and hunting within the organization, and remediation on the malware. Used sub-playbooks: - Endpoint Enrichment - Generic v2.1 - Retrieve File from Endpoint - Generic - Detonate File - Generic - File Enrichment - Generic v2 - Calculate Severity - Generic v2 - Isolate Endpoint - Generic - Block Indicators - Generic v2

Malware Core · 34 tasks · 8 inputs · 0 outputs

Details

IDEndpoint Malware Investigation - Generic
From Version5.0.0
Tasks34

README

Deprecated. Please use the ‘Malware Investigation & Response Incident handler (From the ‘Malware Investigation And Response’ Pack).


Performs enrichment, detonation, and hunting within the organization, and remediation on the malware. This playbook is triggered by a malware incident from an Endpoint type integration.

Used sub-playbooks:

  • Endpoint Enrichment - Generic v2.1
  • Retrieve File from Endpoint - Generic
  • Detonate File - Generic
  • File Enrichment - Generic v2
  • Calculate Severity - Generic v2
  • Isolate Endpoint - Generic
  • Block Indicators - Generic v2

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Endpoint Enrichment - Generic v2.1
  • Detonate File - Generic
  • Retrieve File from Endpoint - Generic
  • Calculate Severity - Generic v2
  • Isolate Endpoint - Generic
  • Block Indicators - Generic v2
  • File Enrichment - Generic v2

Integrations

  • Builtin

Scripts

  • GenerateInvestigationSummaryReport

Commands

  • send-mail
  • setIncident
  • closeInvestigation

Playbook Inputs


Name Description Default Value Source Required
AutoIsolation This input determines the threshold severity from which to perform auto-isolation for the infected endpoint. Specify the severity number (default is High): Specify the severity number:”0” means Unknown, “0.5” means Informational, “1” means Low, “2” means Medium, “3” means High, “4” means Critical. 3 - Optional
Email The email address to notify if there is a possibility of the malware spreading and infecting other endpoints. - - Optional
MD5 The MD5 hash of the file. md5string incident Optional
SHA256 The SHA256 hash of the file. sha256 incident Optional
Hostname The hostname of the machine on which the file is located. Hostname Endpoint Optional
FilePath The file path. Path File Optional
UseD2 Whether to use the D2 agent to retrieve the file. no - Optional
SHA1 The SHA1 hash of the file. sha1 incident Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Endpoint_Malware_Investigation_Generic

Inputs

  • AutoIsolation — This input determines the threshold severity from which to perform auto-isolation for the infected endpoint. Specify the severity number (default is High): Specify the severity number: 0 - Unknown 0.5 - Informational 1 - Low 2 - Medium 3 - High 4 - Critical
  • Email — The Email address to notify if there is a possibility of the malware spreading and infecting other endpoints.
  • MD5 — File MD5.
  • SHA256 — File SHA256.
  • Hostname — Hostname of the machine on which the file is located.
  • FilePath — File path.
  • UseD2 — Specifies whether to use D2 agent to retrieve the file.
  • SHA1 — File SHA1.

Commands used

closeInvestigation send-mail setIncident

Flowchart

No Yes yes No Yes No Yes yes Close as False positive Continue yes Start Start Detonation Detonation File enrichment File enrichment Hunting Hunting Remediation Remediation Manual - Get analyst approval for auto-remediation Manual - Get analyst appr... Analyst review of the investigation Analyst review of the inv... Manual - Unisolate endpoints Manual - Unisolate endpoints Endpoint Enrichment - Generic v2.1 - Endpoint Enrichment - Generic v2.1 Endpoint Enrichment - Gen... Endpoint Enrichment - Generic... File Enrichment - Generic v2 - File Enrichment - Generic v2 File Enrichment - Generic v2 File Enrichment - Generic v2 Detonate File - Generic - Detonate File - Generic Detonate File - Generic Detonate File - Generic Generate Investigation Summary Report - GenerateInvestigationSummaryReport Generate Investigation Su... GenerateInvestigationSummaryR... Was a file retrieved? Was a file retrieved? Retrieve file manually Retrieve file manually Manual - Hunt for other infected endpoints Manual - Hunt for other i... Were there any more infected endpoints found? Were there any more infec... Analyst manual remediation Analyst manual remediation Perform manual malware analysis and forensics Perform manual malware an... False Positive False Positive Get analyst approval for local containment Get analyst approval for ... Auto-Isolation? Auto-Isolation? Continue with the investigation or close as false positive? Continue with the investi... Calculate Severity - Generic v2 - Calculate Severity - Generic v2 Calculate Severity - Gene... Calculate Severity - Generic v2 Notify that more infected endpoints were found - send-mail Notify that more infected... send-mail Notify? Notify? Done Done Close Demisto Investigation - closeInvestigation Close Demisto Investigation closeInvestigation Manual - Close incident in the source product Manual - Close incident i... Set incident - Isolated field - setIncident Set incident - Isolated f... setIncident Retrieve File from Endpoint - Generic - Retrieve File from Endpoint - Generic Retrieve File from Endpoi... Retrieve File from Endpoint -... Isolate Endpoint - Generic - Isolate Endpoint - Generic Isolate Endpoint - Generic Isolate Endpoint - Generic Isolate Endpoint - Generic - Isolate Endpoint - Generic Isolate Endpoint - Generic Isolate Endpoint - Generic Block Indicators - Generic v2 - Block Indicators - Generic v2 Block Indicators - Generi... Block Indicators - Generic v2 Isolate infected endpoints Isolate infected endpoints
id: Endpoint Malware Investigation - Generic
version: -1
name: Endpoint Malware Investigation - Generic
fromversion: 5.0.0
deprecated: true
description: |-
  Deprecated. Use 'Malware Investigation & Response Incident handler' instead. (From the 'Malware Investigation And Response Pack')
  This playbook is triggered by a malware incident from an 'Endpoint' type integration. The playbook performs enrichment, detonation, and hunting within the organization, and remediation on the malware.
  Used sub-playbooks:
  - Endpoint Enrichment - Generic v2.1
  - Retrieve File from Endpoint - Generic
  - Detonate File - Generic
  - File Enrichment - Generic v2
  - Calculate Severity - Generic v2
  - Isolate Endpoint - Generic
  - Block Indicators - Generic v2
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 485b00ff-6655-4a20-8fd6-f40ce5b43d80
    type: start
    task:
      id: 485b00ff-6655-4a20-8fd6-f40ce5b43d80
      version: -1
      name: ""
      description: ""
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "26"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 500,
          "y": 70
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "5":
    id: "5"
    taskid: f8f052e5-1335-4cf0-8ad1-24fb809b3d63
    type: title
    task:
      id: f8f052e5-1335-4cf0-8ad1-24fb809b3d63
      version: -1
      name: Detonation
      description: ""
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "62"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 750,
          "y": 385
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "6":
    id: "6"
    taskid: a92117d3-1ccf-4dc8-833a-01ac2d172cad
    type: title
    task:
      id: a92117d3-1ccf-4dc8-833a-01ac2d172cad
      version: -1
      name: File enrichment
      description: ""
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "27"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 260,
          "y": 385
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "12":
    id: "12"
    taskid: 89dabb98-4cdf-4ea6-87e4-cf5e4c935911
    type: title
    task:
      id: 89dabb98-4cdf-4ea6-87e4-cf5e4c935911
      version: -1
      name: Hunting
      description: ""
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "38"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 2385
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "15":
    id: "15"
    taskid: 8bc813e6-4731-4348-8a93-9ab9de5b28f1
    type: title
    task:
      id: 8bc813e6-4731-4348-8a93-9ab9de5b28f1
      version: -1
      name: Remediation
      description: ""
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 3515
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "19":
    id: "19"
    taskid: e85c9761-257f-4461-88f7-c094e476abd7
    type: condition
    task:
      id: e85c9761-257f-4461-88f7-c094e476abd7
      version: -1
      name: Manual - Get analyst approval for auto-remediation
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "41"
      "Yes":
      - "65"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 3650
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "20":
    id: "20"
    taskid: 7d6c7837-c713-4066-839c-4766a2c9f299
    type: regular
    task:
      id: 7d6c7837-c713-4066-839c-4766a2c9f299
      version: -1
      name: Analyst review of the investigation
      description: ""
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "31"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 3990
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "21":
    id: "21"
    taskid: 06bf2b3b-4c90-433f-85c1-576ae9279ade
    type: regular
    task:
      id: 06bf2b3b-4c90-433f-85c1-576ae9279ade
      version: -1
      name: Manual - Unisolate endpoints
      description: Unisolate endpoints that were isolated during the investigation
        after remediation.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "59"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 4330
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "26":
    id: "26"
    taskid: 7352a626-e4dc-4d5a-8a79-2bb7af03c95e
    type: playbook
    task:
      id: 7352a626-e4dc-4d5a-8a79-2bb7af03c95e
      version: -1
      name: Endpoint Enrichment - Generic v2.1
      playbookName: Endpoint Enrichment - Generic v2.1
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "5"
      - "6"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 500,
          "y": 210
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "27":
    id: "27"
    taskid: 2f313453-70b6-4d5a-8d5c-0c6f78379848
    type: playbook
    task:
      id: 2f313453-70b6-4d5a-8d5c-0c6f78379848
      version: -1
      name: File Enrichment - Generic v2
      playbookName: File Enrichment - Generic v2
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "52"
    scriptarguments:
      MD5:
        complex:
          root: inputs.MD5
          transformers:
          - operator: uniq
      SHA1:
        complex:
          root: inputs.SHA1
          transformers:
          - operator: uniq
      SHA256:
        complex:
          root: inputs.SHA256
          transformers:
          - operator: uniq
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
    view: |-
      {
        "position": {
          "x": 260,
          "y": 1040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "28":
    id: "28"
    taskid: 7ee18890-38d2-4bd4-82b9-2c29a4dff0c2
    type: playbook
    task:
      id: 7ee18890-38d2-4bd4-82b9-2c29a4dff0c2
      version: -1
      name: Detonate File - Generic
      playbookName: Detonate File - Generic
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "52"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 750,
          "y": 1040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "31":
    id: "31"
    taskid: f07c10bc-483f-472b-88f4-31833520e949
    type: regular
    task:
      id: f07c10bc-483f-472b-88f4-31833520e949
      version: -1
      name: Generate Investigation Summary Report
      description: |-
        A script to generate an investigation summary report in an automated way
        Can be used in post-processing flow as well.
      scriptName: GenerateInvestigationSummaryReport
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "21"
    scriptarguments:
      incidentId:
        complex:
          root: incident
          accessor: id
      name: {}
      type: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 4160
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "36":
    id: "36"
    taskid: 265ab7e6-4ea1-4851-8cc3-33f6ecd6e50f
    type: condition
    task:
      id: 265ab7e6-4ea1-4851-8cc3-33f6ecd6e50f
      version: -1
      name: Was a file retrieved?
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "37"
      "yes":
      - "28"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              simple: File
            iscontext: true
      - - operator: isExists
          left:
            value:
              complex:
                root: File
                accessor: EntryID
            iscontext: true
    view: |-
      {
        "position": {
          "x": 750,
          "y": 700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "37":
    id: "37"
    taskid: 0e2a9053-3524-4d1c-84ae-9740ce6253ca
    type: regular
    task:
      id: 0e2a9053-3524-4d1c-84ae-9740ce6253ca
      version: -1
      name: Retrieve file manually
      description: ""
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1010,
          "y": 870
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "38":
    id: "38"
    taskid: 563f2a69-ede9-4377-8c1b-670ab7606f67
    type: regular
    task:
      id: 563f2a69-ede9-4377-8c1b-670ab7606f67
      version: -1
      name: Manual - Hunt for other infected endpoints
      description: Manually hunt for other infected endpoints.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "39"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 2515
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "39":
    id: "39"
    taskid: 8312dd87-7d5f-4458-8f00-4cd532445ecd
    type: condition
    task:
      id: 8312dd87-7d5f-4458-8f00-4cd532445ecd
      version: -1
      name: Were there any more infected endpoints found?
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "15"
      "Yes":
      - "56"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 2680
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "41":
    id: "41"
    taskid: a229e915-638d-47c7-8be5-a21cdd4a9028
    type: regular
    task:
      id: a229e915-638d-47c7-8be5-a21cdd4a9028
      version: -1
      name: Analyst manual remediation
      description: ""
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 490,
          "y": 3820
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "44":
    id: "44"
    taskid: 932cb41a-9b95-4f2e-8fc9-eecf5d0fecdf
    type: regular
    task:
      id: 932cb41a-9b95-4f2e-8fc9-eecf5d0fecdf
      version: -1
      name: Perform manual malware analysis and forensics
      description: ""
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "12"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 2220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "45":
    id: "45"
    taskid: 21220e7b-dcd9-453c-8760-ec6ad2609160
    type: title
    task:
      id: 21220e7b-dcd9-453c-8760-ec6ad2609160
      version: -1
      name: False Positive
      description: ""
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "59"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -300,
          "y": 1720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "46":
    id: "46"
    taskid: d542dd80-062d-4e32-8d87-221cc6793aba
    type: condition
    task:
      id: d542dd80-062d-4e32-8d87-221cc6793aba
      version: -1
      name: Get analyst approval for local containment
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "44"
      "Yes":
      - "63"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 1720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "50":
    id: "50"
    taskid: 8cef4a7e-9abd-4e7a-8747-950ff1363fdd
    type: condition
    task:
      id: 8cef4a7e-9abd-4e7a-8747-950ff1363fdd
      version: -1
      name: Auto-Isolation?
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "51"
      "yes":
      - "63"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: inputs.AutoIsolation
                filters:
                - - operator: lessThanOrEqual
                    left:
                      value:
                        simple: inputs.AutoIsolation
                      iscontext: true
                    right:
                      value:
                        simple: incident.severity
                      iscontext: true
            iscontext: true
    view: |-
      {
        "position": {
          "x": 500,
          "y": 1380
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "51":
    id: "51"
    taskid: 927f8b9d-dd0f-4068-865d-15e565b1215c
    type: condition
    task:
      id: 927f8b9d-dd0f-4068-865d-15e565b1215c
      version: -1
      name: Continue with the investigation or close as false positive?
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      Close as False positive:
      - "45"
      Continue:
      - "46"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -60,
          "y": 1550
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "52":
    id: "52"
    taskid: f8403bed-32be-4f44-8a46-4fc2d703666d
    type: playbook
    task:
      id: f8403bed-32be-4f44-8a46-4fc2d703666d
      version: -1
      name: Calculate Severity - Generic v2
      playbookName: Calculate Severity - Generic v2
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "50"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 500,
          "y": 1210
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "55":
    id: "55"
    taskid: fd751354-1d35-44ad-81dd-2ec7ac0b4cdf
    type: regular
    task:
      id: fd751354-1d35-44ad-81dd-2ec7ac0b4cdf
      version: -1
      name: Notify that more infected endpoints were found
      description: Send an email
      script: '|||send-mail'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "66"
    scriptarguments:
      additionalHeader: {}
      attachCIDs: {}
      attachIDs: {}
      attachNames: {}
      bcc: {}
      body:
        simple: |-
          During an endpoint malware investigation in Demisto, other infected endpoints were found, which can possibly indicate the malware is spreading in your organization and requires your attention.
          To get more information, go to this incident in Demisto: ${incident.id}
      cc: {}
      htmlBody: {}
      replyTo: {}
      subject:
        simple: Potential malware spreading in your organization
      templateParams: {}
      to:
        complex:
          root: inputs.Email
      transientFile: {}
      transientFileCID: {}
      transientFileContent: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 820,
          "y": 3020
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "56":
    id: "56"
    taskid: 9e5fcae4-8f37-4c3d-8537-ef6823ed747b
    type: condition
    task:
      id: 9e5fcae4-8f37-4c3d-8537-ef6823ed747b
      version: -1
      name: Notify?
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "66"
      "yes":
      - "55"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.Email
            iscontext: true
    view: |-
      {
        "position": {
          "x": 500,
          "y": 2850
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "57":
    id: "57"
    taskid: af45ad3a-c7df-46a6-8b71-eb7c691a9a94
    type: title
    task:
      id: af45ad3a-c7df-46a6-8b71-eb7c691a9a94
      version: -1
      name: Done
      description: ""
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -300,
          "y": 4820
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "58":
    id: "58"
    taskid: 0282cd22-6365-4dcb-8426-49a1503ee40c
    type: regular
    task:
      id: 0282cd22-6365-4dcb-8426-49a1503ee40c
      version: -1
      name: Close Demisto Investigation
      description: commands.local.cmd.close.inv
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "57"
    scriptarguments:
      assetid: {}
      closeNotes: {}
      closeReason: {}
      emailclassification: {}
      id:
        complex:
          root: incident
          accessor: id
      mndadone: {}
      phishingconfirmationstatus: {}
      phishingsubtype: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -300,
          "y": 4660
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "59":
    id: "59"
    taskid: a82031e5-2b56-4734-815a-4ec30ac09b52
    type: regular
    task:
      id: a82031e5-2b56-4734-815a-4ec30ac09b52
      version: -1
      name: Manual - Close incident in the source product
      description: Close the incident in the source product that triggered it.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "58"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -300,
          "y": 4500
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "61":
    id: "61"
    taskid: 4e2224f0-7a53-40b6-8d37-85a36e2929a5
    type: regular
    task:
      id: 4e2224f0-7a53-40b6-8d37-85a36e2929a5
      version: -1
      name: Set incident - Isolated field
      description: Change the properties of an incident
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "44"
    scriptarguments:
      Crowdstrikefamily: {}
      Crowdstrikescore: {}
      account: {}
      accountid: {}
      addLabels: {}
      affecteddata: {}
      affecteddatatype: {}
      affectedindividualscontactinformation: {}
      agentid: {}
      agentversion: {}
      alertid: {}
      alertrules: {}
      alertstatus: {}
      alerttime: {}
      app: {}
      approximatenumberofaffecteddatasubjects: {}
      assetid: {}
      attachmentcount: {}
      attachmentextension: {}
      attachmenthash: {}
      attachmentid: {}
      attachmentname: {}
      attachmentsize: {}
      attachmenttype: {}
      awsfindingid: {}
      awsfindingtype: {}
      awsinstanceid: {}
      awsinstancename: {}
      bdcontactemail: {}
      bdcontactname: {}
      blockedaction: {}
      bugtraq: {}
      city: {}
      clicktime: {}
      closeNotes: {}
      closeReason: {}
      cluster: {}
      commandline: {}
      companyaddress: {}
      companycity: {}
      companycountry: {}
      companyhasinsuranceforthebreach: {}
      companyname: {}
      companypostalcode: {}
      compliancemetadata: {}
      contactaddress: {}
      contactname: {}
      country: {}
      countrywherebusinesshasitsmainestablishment: {}
      countrywherethebreachtookplace: {}
      criticalassets: {}
      currentip: {}
      customFields: {}
      customidstring: {}
      cve: {}
      cvss: {}
      dataencryptionstatus: {}
      datetimeofthebreach: {}
      deleteEmptyField: {}
      demoautomatedcondition: {}
      demomanualcondition: {}
      description: {}
      dest: {}
      destntdomain: {}
      details: {}
      detectid: {}
      detectname: {}
      detectorid: {}
      detecttime: {}
      devicename: {}
      dpoemailaddress: {}
      duration: {}
      emailaddress: {}
      emailauthenticitycheck: {}
      emailbcc: {}
      emailbody: {}
      emailbodyformat: {}
      emailbodyhtml: {}
      emailcc: {}
      emailclassification: {}
      emailclientname: {}
      emailfrom: {}
      emailhtml: {}
      emailinreplyto: {}
      emailkeywords: {}
      emailmessageid: {}
      emailreceived: {}
      emailrecipient: {}
      emailreplyto: {}
      emailreturnpath: {}
      emailsenderip: {}
      emailsize: {}
      emailsource: {}
      emailsubject: {}
      emailto: {}
      emailtocount: {}
      emailurlclicked: {}
      endpointgrid: {}
      eventtype: {}
      executableswritten: {}
      exposedport: {}
      externalip: {}
      falconhostlink: {}
      filehash: {}
      filename: {}
      filepath: {}
      filesize: {}
      findingid: {}
      firstseen: {}
      groupid: {}
      guid: {}
      hadasanothershorttext: {}
      hadasanothertest: {}
      hostname: {}
      id: {}
      indicatorsofinterest: {}
      infected: {}
      infectedhosts: {}
      internalip: {}
      involvedusers: {}
      ioctype: {}
      iocvalue: {}
      isolated:
        simple: Endpoint was isolated successfully.
      isthedatasubjecttodpia: {}
      labels: {}
      lastmodifiedby: {}
      lastmodifiedon: {}
      lastseen: {}
      licenseexpirydate: {}
      likelyimpact: {}
      localip: {}
      macaddress: {}
      maliciousbehavior: {}
      maliciouscauseifthecauseisamaliciousattack: {}
      malwarefamily: {}
      malwarescore: {}
      md5string: {}
      measurestomitigate: {}
      messageparts: {}
      messagetime: {}
      mnda: {}
      mndadone: {}
      myhtml: {}
      mymultiselect: {}
      myrequiredtext: {}
      name: {}
      nextsteps: {}
      notes: {}
      objective: {}
      occurred: {}
      offset: {}
      operator: {}
      osname: {}
      ostype: {}
      osversion: {}
      owner: {}
      parantprocessname: {}
      parentprocessid: {}
      parentprocessname: {}
      partnercontacts: {}
      partnerproduct: {}
      patterndispositiondescription: {}
      patterndispositionflags: {}
      patterndispositionvalue: {}
      phase: {}
      phishingconfirmationstatus: {}
      phishingsubtype: {}
      phishscore: {}
      pid: {}
      platform: {}
      policydeleted: {}
      policydescription: {}
      policydetails: {}
      policyid: {}
      policyname: {}
      policyrecommendation: {}
      policyremediable: {}
      policyroutes: {}
      policyscanconfigid: {}
      policyseverity: {}
      policytype: {}
      possiblecauseofthebreach: {}
      postalcode: {}
      previousip: {}
      processendtime: {}
      processid: {}
      processname: {}
      processstarttime: {}
      qid: {}
      quarantined: {}
      quarantinefolder: {}
      quarantinerule: {}
      rating: {}
      redlockalertid: {}
      redlockpolicyname: {}
      region: {}
      regionid: {}
      replacePlaybook: {}
      reportingdepartment: {}
      resourceapiname: {}
      resourcecloudtype: {}
      resourceid: {}
      resourcename: {}
      resourcetype: {}
      riskrating: {}
      riskscore: {}
      roles: {}
      rrn: {}
      samaccountname: {}
      sectorofaffectedparty: {}
      securitygroupid: {}
      sensorid: {}
      severity: {}
      severityname: {}
      sha1: {}
      sha256: {}
      signature: {}
      sizenumberofemployees: {}
      sizeturnover: {}
      skuname: {}
      skutier: {}
      sla: {}
      slaField: {}
      solutionbrief: {}
      spamscore: {}
      src: {}
      srcntdomain: {}
      srcos: {}
      srcuser: {}
      subscriptionassignedby: {}
      subscriptioncreatedby: {}
      subscriptioncreatedon: {}
      subscriptiondescription: {}
      subscriptionid: {}
      subscriptionname: {}
      subscriptiontype: {}
      subscriptionupdatedby: {}
      subscriptionupdatedon: {}
      subtype: {}
      systemdefault: {}
      systems: {}
      tactic: {}
      technique: {}
      telephoneno: {}
      terminatedaction: {}
      test: {}
      testfieldhadas: {}
      threatactor: {}
      threatinfomap: {}
      threattime: {}
      ticketnumber: {}
      trapsid: {}
      triggeredsecurityprofile: {}
      type: {}
      user: {}
      useragent: {}
      vendorid: {}
      vendorproduct: {}
      version: {}
      vpcid: {}
      vulnerabilitycategory: {}
      whereisdatahosted: {}
      wildfiresubtype: {}
      xdralertcount: {}
      xdralerts: {}
      xdrassigneduseremail: {}
      xdrassigneduserprettyname: {}
      xdrdescription: {}
      xdrdetectiontime: {}
      xdrfileartifacts: {}
      xdrhighseverityalertcount: {}
      xdrhighseverityalerts: {}
      xdrhostcount: {}
      xdrincidentid: {}
      xdrincidentmarkdown: {}
      xdrlowseverityalertcount: {}
      xdrlowseverityalerts: {}
      xdrmanualseverity: {}
      xdrmediumseverityalertcount: {}
      xdrmediumseverityalerts: {}
      xdrnetworkartifacts: {}
      xdrnotes: {}
      xdrresolvecomment: {}
      xdrstatus: {}
      xdrurl: {}
      xdrusercount: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 500,
          "y": 2050
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "62":
    id: "62"
    taskid: b578ac1a-1d46-4661-8d0e-f16132e1c714
    type: playbook
    task:
      id: b578ac1a-1d46-4661-8d0e-f16132e1c714
      version: -1
      name: Retrieve File from Endpoint - Generic
      playbookName: Retrieve File from Endpoint - Generic
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "36"
    scriptarguments:
      Hostname:
        complex:
          root: inputs.Hostname
          transformers:
          - operator: uniq
      MD5:
        complex:
          root: inputs.MD5
      Path:
        complex:
          root: inputs.FilePath
      SHA256:
        complex:
          root: inputs.SHA256
      UseD2:
        complex:
          root: inputs.UseD2
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
    view: |-
      {
        "position": {
          "x": 750,
          "y": 530
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "63":
    id: "63"
    taskid: 0c3fb220-ba27-4125-8ac9-261a47683b6f
    type: playbook
    task:
      id: 0c3fb220-ba27-4125-8ac9-261a47683b6f
      version: -1
      name: Isolate Endpoint - Generic
      description: |-
        This playbook isolates a given endpoint using the following integrations:
        - Carbon Black Enterprise Response
        - Palo Alto Networks Traps
      playbookName: Isolate Endpoint - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "61"
    scriptarguments:
      EndpointId:
        complex:
          root: Traps
          accessor: EndpointID
      Hostname:
        complex:
          root: Endpoint
          accessor: Hostname
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
    view: |-
      {
        "position": {
          "x": 500,
          "y": 1890
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "64":
    id: "64"
    taskid: b06b38e8-71f6-4bfe-8c50-db47474adfc9
    type: playbook
    task:
      id: b06b38e8-71f6-4bfe-8c50-db47474adfc9
      version: -1
      name: Isolate Endpoint - Generic
      playbookName: Isolate Endpoint - Generic
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 500,
          "y": 3340
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "65":
    id: "65"
    taskid: 34b92e50-ae2d-42aa-8838-68af465ca448
    type: playbook
    task:
      id: 34b92e50-ae2d-42aa-8838-68af465ca448
      version: -1
      name: Block Indicators - Generic v2
      playbookName: Block Indicators - Generic v2
      description: ""
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": -40,
          "y": 3820
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "66":
    id: "66"
    taskid: 5ced3ed5-4b18-4424-8392-48fa126a1fea
    type: title
    task:
      id: 5ced3ed5-4b18-4424-8392-48fa126a1fea
      version: -1
      name: Isolate infected endpoints
      description: ""
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "64"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 500,
          "y": 3190
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
view: |-
  {
    "linkLabelsPosition": {
      "36_28_yes": 0.49,
      "36_37_#default#": 0.64,
      "39_15_No": 0.44,
      "39_56_Yes": 0.5,
      "46_44_No": 0.58,
      "50_51_#default#": 0.64,
      "51_45_Close as False positive": 0.51,
      "51_46_Continue": 0.52,
      "56_15_#default#": 0.37,
      "56_55_yes": 0.6
    },
    "paper": {
      "dimensions": {
        "height": 4815,
        "width": 1690,
        "x": -300,
        "y": 70
      }
    }
  }
inputs:
- key: AutoIsolation
  value:
    simple: "3"
  required: false
  description: |-
    This input determines the threshold severity from which to perform auto-isolation for the infected endpoint.
    Specify the severity number (default is High):
    Specify the severity number:
    0 - Unknown
    0.5 - Informational
    1 - Low
    2 - Medium
    3 - High
    4 - Critical
- key: Email
  value: {}
  required: false
  description: The Email address to notify if there is a possibility of the malware spreading
    and infecting other endpoints.
- key: MD5
  value:
    complex:
      root: incident
      accessor: md5string
  required: false
  description: File MD5.
- key: SHA256
  value:
    complex:
      root: incident
      accessor: sha256
  required: false
  description: File SHA256.
- key: Hostname
  value:
    complex:
      root: Endpoint
      accessor: Hostname
  required: false
  description: Hostname of the machine on which the file is located.
- key: FilePath
  value:
    complex:
      root: File
      accessor: Path
  required: false
  description: File path.
- key: UseD2
  value:
    simple: "no"
  required: false
  description: Specifies whether to use D2 agent to retrieve the file.
- key: SHA1
  value:
    complex:
      root: incident
      accessor: sha1
  required: false
  description: File SHA1.
outputs: []
tests:
  - No Test