Eradication Plan

This playbook handles all the eradication actions available with Cortex XSIAM, including the following sub-playbooks: * Eradication Plan - Reset user password * Eradication Plan - Delete file * Eradication Plan - Kill process (currently, the playbook supports terminating a process by name) Note: The playbook inputs enable manipulating the execution flow. Read the input descriptions for details.

Common Playbooks · 13 tasks · 8 inputs · 1 output

Details

IDEradication Plan
From Version6.6.0
Tasks13

README

This playbook handles all the eradication actions available with Cortex XSIAM, including the following sub-playbooks:

  • Eradication Plan - Reset user password
  • Eradication Plan - Delete file
  • Eradication Plan - Kill process (currently, the playbook supports terminating a process by name)

Note: The playbook inputs enable manipulating the execution flow. Read the input descriptions for details.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Eradication Plan - Terminate Process
  • Eradication Plan - Reset Password
  • Eradication Plan - Delete File

Integrations

This playbook does not use any integrations.

Scripts

  • Set

Commands

This playbook does not use any commands.

Playbook Inputs


Name Description Default Value Required
AutoEradicate Set to True to execute the eradication playbook automatically. True Optional
EndpointID The endpoint ID. alert.agentid Optional
FilePath The file path for the file deletion and for the process termination task. foundIncidents.CustomFields.initiatorpath Optional
Username The username to reset the password for. foundIncidents.CustomFields.username Optional
FileRemediation Choose ‘Quarantine’ or ‘Delete’ to avoid file remediation conflicts.
For example, choosing ‘Delete’ ignores the ‘Quarantine file’ task under the containment playbook and executes only file deletion.
Delete Optional
UserRemediation Set to ‘True’ to reset the user’s password. True Optional
ProcessTermination Choose ‘PID’ to terminate the process using the Process ID, or ‘Name’ to terminate the process using its name.
Please note that providing the file path is mandatory for the process termination.
If ‘PID’ is chosen, the input `ProcessID` should not be empty; otherwise, the termination will not proceed.
Name Optional
ProcessID The process ID to terminate.   Optional

Playbook Outputs


Path Description Type
TerminatedProcessFromEndpoints The terminated process from endpoint unknown

Playbook Image


Eradication Plan

Inputs

  • AutoEradicate — Set to True to execute the eradication playbook automatically.
  • EndpointID — The endpoint ID.
  • FilePath — The file path for the file deletion and for the process termination task.
  • Username — The username to reset the password for.
  • FileRemediation — Choose 'Quarantine' or 'Delete' to avoid file remediation conflicts. For example, choosing 'Delete' ignores the 'Quarantine file' task under the containment playbook and executes only file deletion.
  • UserRemediation — Set to 'True' to reset the user's password.
  • ProcessTermination — Choose 'PID' to terminate the process using the Process ID, or 'Name' to terminate the process using its name. Please note that providing the file path is mandatory for the process termination. If 'PID' is chosen, the input `ProcessID` should not be empty; otherwise, the termination will not proceed.
  • ProcessID — The process ID to terminate.

Outputs

  • TerminatedProcessFromEndpoints — The terminated process from endpoint

Flowchart

yes yes Start Start Which eradication actions would you like to perform? Which eradication actions... Eradication Eradication Should Eradicate automatically? Should Eradicate automati... Eradication Plan - Delete File - Eradication Plan - Delete File Eradication Plan - Delete... Eradication Plan - Delete File Eradication Plan - Reset Password - Eradication Plan - Reset Password Eradication Plan - Reset ... Eradication Plan - Reset Pass... Eradication Plan - Terminate Process - Eradication Plan - Terminate Process Eradication Plan - Termin... Eradication Plan - Terminate ... Reset Password Reset Password Delete File Delete File Terminate Process Terminate Process Done Done Set Process list - Set Set Process list Set The file path and PID defined? The file path and PID def...
id: Eradication Plan - Terminate Process
version: -1
name: Eradication Plan - Terminate Process
description: "This playbook is one of the sub-playbooks in the eradication plan. \nThis playbook handles the termination of the processes as a crucial step in the eradication action.\nThe playbook executes actions of process termination, which is a crucial step in the eradication process.\nThe process termination can be performed based on either the process ID or the process name."
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 0c2bd2d8-2747-473f-873c-fdf0258c1425
    type: start
    task:
      id: 0c2bd2d8-2747-473f-873c-fdf0258c1425
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 190,
          "y": -180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 387a0de2-f9a3-412a-8531-299ba47ac010
    type: condition
    task:
      id: 387a0de2-f9a3-412a-8531-299ba47ac010
      version: -1
      name: Should terminate the process?
      description: Whether to terminate the process automatically, manually, or not at all.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      Name:
      - "22"
      PID:
      - "21"
    separatecontext: false
    conditions:
    - label: PID
      condition:
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.EndpointID
            iscontext: true
          right:
            value: {}
          ignorecase: true
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.ProcessTermination
            iscontext: true
          right:
            value:
              simple: PID
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.ProcessID
            iscontext: true
      - - operator: notContainsGeneral
          left:
            value:
              complex:
                root: inputs.ProcessID
            iscontext: true
          right:
            value:
              simple: \
    - label: Name
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.ProcessTermination
            iscontext: true
          right:
            value:
              simple: Name
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.EndpointID
            iscontext: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.FilePath
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 190,
          "y": -40
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "5":
    id: "5"
    taskid: b6c458a7-8533-4692-87af-498de4ea894f
    type: title
    task:
      id: b6c458a7-8533-4692-87af-498de4ea894f
      version: -1
      name: Done - Process Termination
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 190,
          "y": 1240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: d1bf1eb3-8962-4fe0-8f37-dd1d6e67fc1d
    type: regular
    task:
      id: d1bf1eb3-8962-4fe0-8f37-dd1d6e67fc1d
      version: -1
      name: Get command result
      description: Retrieve the results of a script execution action.
      script: '|||core-get-script-execution-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "10"
    scriptarguments:
      action_id:
        complex:
          root: Core.GetActionStatus
          accessor: action_id
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -70,
          "y": 500
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: f3850073-38b9-4991-8e2e-ac78bd2372e6
    type: regular
    task:
      id: f3850073-38b9-4991-8e2e-ac78bd2372e6
      version: -1
      name: process termination
      description: Initiates a new endpoint script execution kill process.
      script: '|||core-run-script-kill-process'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      endpoint_ids:
        complex:
          root: inputs.EndpointID
      process_name:
        complex:
          root: FilePath
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: '[^\\]+$'
              unpack_matches: {}
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -70,
          "y": 320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "10":
    id: "10"
    taskid: 5bb3ab00-26df-4e11-89b2-a213d1eba8aa
    type: condition
    task:
      id: 5bb3ab00-26df-4e11-89b2-a213d1eba8aa
      version: -1
      name: Was the process terminated?
      description: Checks if the process was terminated.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "20"
      "yes":
      - "11"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: notEndWith
          left:
            value:
              complex:
                root: Core.ScriptResult.results
                accessor: standard_output
            iscontext: true
          right:
            value:
              simple: 'killed: 0.'
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -70,
          "y": 670
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "11":
    id: "11"
    taskid: 960374b2-8b4a-4577-8bf1-ac02f9ceccf4
    type: regular
    task:
      id: 960374b2-8b4a-4577-8bf1-ac02f9ceccf4
      version: -1
      name: Set terminated process per endpoint ID
      description: Set a value in context under the key you entered.
      scriptName: Set
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "12"
    scriptarguments:
      extend-context:
        simple: TerminatedProcessFromEndpoints=
      ignore-outputs:
        simple: "true"
      key:
        complex:
          root: inputs.EndpointID
      value:
        complex:
          root: Core.ScriptResult.results
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: Core.ScriptResult.results._return_value
                iscontext: true
              right:
                value:
                  simple: "True"
              ignorecase: true
          accessor: standard_output
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: .*name (.*) found.*
              unpack_matches: {}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -70,
          "y": 860
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: 42d427fd-6d4a-4b70-8b1a-35c76fdd8d45
    type: regular
    task:
      id: 42d427fd-6d4a-4b70-8b1a-35c76fdd8d45
      version: -1
      name: Set Deleted files per endpoint ID to the Incident context
      description: commands.local.cmd.set.parent.incident.context
      script: Builtin|||setParentIncidentContext
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      extend-context:
        simple: TerminatedProcessOnEndpoints=
      key:
        simple: TerminatedProcessPerEndpointsID
      value:
        complex:
          root: TerminatedProcessFromEndpoints
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -70,
          "y": 1040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: 961146c8-6afd-4e75-8de9-d6a3171cf051
    type: regular
    task:
      id: 961146c8-6afd-4e75-8de9-d6a3171cf051
      version: -1
      name: process termination
      description: Initiate a new endpoint script execution of shell commands.
      script: '|||core-run-script-execute-commands'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      commands:
        simple: taskkill /F /PID ${ProcessID}
      endpoint_ids:
        complex:
          root: inputs.EndpointID
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 440,
          "y": 320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "15":
    id: "15"
    taskid: 98faa8b1-1539-4e59-8274-c8434226eff7
    type: regular
    task:
      id: 98faa8b1-1539-4e59-8274-c8434226eff7
      version: -1
      name: Get command result
      description: Retrieve the results of a script execution action.
      script: '|||core-get-script-execution-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "16"
    scriptarguments:
      action_id:
        complex:
          root: Core.ScriptRun
          accessor: action_id
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 440,
          "y": 500
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "16":
    id: "16"
    taskid: 1a42b9b2-db4a-4905-8dd5-4b47d18449fc
    type: condition
    task:
      id: 1a42b9b2-db4a-4905-8dd5-4b47d18449fc
      version: -1
      name: Was the process terminated?
      description: Checks if the termination of the process was successful.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "19"
      "yes":
      - "17"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: endWith
          left:
            value:
              complex:
                root: Core.ScriptResult.results
                accessor: standard_output
            iscontext: true
          right:
            value:
              simple: has been terminated.
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 440,
          "y": 670
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 800bc596-f674-43ff-84cf-91da9573954b
    type: regular
    task:
      id: 800bc596-f674-43ff-84cf-91da9573954b
      version: -1
      name: Set terminated process per endpoint ID
      description: Set a value in context under the key you entered.
      scriptName: Set
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "18"
    scriptarguments:
      extend-context:
        simple: TerminatedProcessFromEndpoints=
      ignore-outputs:
        simple: "true"
      key:
        complex:
          root: inputs.EndpointID
      value:
        complex:
          root: Core.ScriptResult.results
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: Core.ScriptResult.results._return_value
                iscontext: true
              right:
                value:
                  simple: "True"
              ignorecase: true
          accessor: standard_output
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: .*name (.*) found.*
              unpack_matches: {}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 440,
          "y": 860
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "18":
    id: "18"
    taskid: 0056cbe7-0eda-4bea-832f-9438e1f45936
    type: regular
    task:
      id: 0056cbe7-0eda-4bea-832f-9438e1f45936
      version: -1
      name: Set Deleted files per endpoint ID to the Incident context
      description: commands.local.cmd.set.parent.incident.context
      script: Builtin|||setParentIncidentContext
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      extend-context:
        simple: TerminatedProcessOnEndpoints=
      key:
        simple: TerminatedProcessPerEndpointsID
      value:
        complex:
          root: TerminatedProcessFromEndpoints
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 440,
          "y": 1040
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "19":
    id: "19"
    taskid: c7749af3-73ff-4422-87dd-e8caeb84c069
    type: regular
    task:
      id: c7749af3-73ff-4422-87dd-e8caeb84c069
      version: -1
      name: Print Error
      description: Prints an error entry with a given message
      scriptName: PrintErrorEntry
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      message:
        simple: The process termination has failed.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 880,
          "y": 860
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: 4e7794f3-70a6-4941-8e9e-65ef20777dca
    type: regular
    task:
      id: 4e7794f3-70a6-4941-8e9e-65ef20777dca
      version: -1
      name: Print Error
      description: Prints an error entry with a given message
      scriptName: PrintErrorEntry
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      message:
        simple: The process termination has failed.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -490,
          "y": 860
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: e5475bb4-564f-4364-892b-12b130016b7a
    type: regular
    task:
      id: e5475bb4-564f-4364-892b-12b130016b7a
      version: -1
      name: Set PID
      description: Set a value in context under the key you entered.
      scriptName: Set
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "13"
    scriptarguments:
      key:
        simple: ProcessID
      value:
        complex:
          root: inputs.ProcessID
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: PID\":\"(\d+?)\"
              unpack_matches: {}
          - operator: SetIfEmpty
            args:
              applyIfEmpty: {}
              defaultValue:
                value:
                  simple: inputs.ProcessID
                iscontext: true
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 440,
          "y": 150
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: 77d2329d-39ac-4e97-8490-b759589f91ad
    type: regular
    task:
      id: 77d2329d-39ac-4e97-8490-b759589f91ad
      version: -1
      name: Set Path
      description: Set a value in context under the key you entered.
      scriptName: Set
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      key:
        simple: FilePath
      value:
        complex:
          root: inputs.FilePath
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: Path\":\"(.+?)\"
              unpack_matches: {}
          - operator: SetIfEmpty
            args:
              applyIfEmpty: {}
              defaultValue:
                value:
                  simple: inputs.FilePath
                iscontext: true
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -70,
          "y": 150
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "16_17_yes": 0.41,
      "1_5_#default#": 0.14
    },
    "paper": {
      "dimensions": {
        "height": 1485,
        "width": 1750,
        "x": -490,
        "y": -180
      }
    }
  }
inputs:
- key: ProcessTermination
  value:
    simple: Name
  required: false
  description: "Choose 'PID' to terminate the process by PID or 'Name' to terminate the process by process name. \nNote: If neither option is selected, the process will not be terminated."
  playbookInputQuery:
- key: EndpointID
  value: {}
  required: false
  description: The endpoint ID to run commands over.
  playbookInputQuery:
- key: FilePath
  value: {}
  required: false
  description: The file path for the process termination.
  playbookInputQuery:
- key: ProcessID
  value: {}
  required: false
  description: The process ID to terminate.
  playbookInputQuery:
outputs:
- contextPath: TerminatedProcessFromEndpoints
  description: The terminated process from endpoint
  type: unknown
tests:
- No tests (auto formatted)
fromversion: 6.6.0
marketplaces:
- marketplacev2
- platform
supportedModules:
- cloud_runtime_security
- xsiam
- edr
- agentix
- cloud