TIM - Review Indicators Manually For Allowlisting
This playbook helps analysts manage the manual process of adding indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query is set to search for indicators that have the 'allowlist_review' tag. The playbooks layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags such as, 'approved_block', 'approved_allow', etc. Once the analyst completes the review, the playbook can optionally send an email with a list of changes done by the analyst which haven't been approved. Once complete, the playbook removes the 'allowlist review' tag from the indicators.
TIM - Indicator Auto-Processing · 13 tasks · 2 inputs · 0 outputs
Details
| ID | TIM - Review Indicators Manually For Allowlisting |
|---|---|
| From Version | 5.5.0 |
| Tasks | 13 |
README
This playbook helps analysts manage the manual process of adding indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query is set to search for indicators that have the ‘allowlist_review’ tag. The playbooks layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags such as, ‘approved_block’, ‘approved_allow’, etc. Once the analyst completes the review, the playbook can optionally send an email with a list of changes done by the analyst which haven’t been approved. Once complete, the playbook removes the ‘allowlist review’ tag from the indicators.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
This playbook does not use any scripts.
Commands
- associateIndicatorToIncident
- removeIndicatorField
- appendIndicatorField
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| Indicator Query | Indicators matching the indicator query will be used as playbook input | tags:allowlist_review and -tags:being_reviewed | Optional |
| ApproversEmailAddress | This input specifies the email address to which to send the approval form if approval is required. | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
—ApproversEmailAddress— This input specifies the email address to which to send the approval form if approval is required.
Commands used
appendIndicatorField
associateIndicatorToIncident
removeIndicatorField
Flowchart
id: TIM - Review Indicators Manually For Allowlisting version: -1 fromversion: 5.5.0 marketplaces: - xsoar name: TIM - Review Indicators Manually For Allowlisting description: This playbook helps analysts manage the manual process of adding indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query is set to search for indicators that have the 'allowlist_review' tag. The playbooks layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags such as, 'approved_block', 'approved_allow', etc. Once the analyst completes the review, the playbook can optionally send an email with a list of changes done by the analyst which haven't been approved. Once complete, the playbook removes the 'allowlist review' tag from the indicators. starttaskid: "0" tasks: "0": id: "0" taskid: ec484071-3d69-4a74-8e11-72d0a8ebdc1a type: start task: id: ec484071-3d69-4a74-8e11-72d0a8ebdc1a version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "11" separatecontext: false view: |- { "position": { "x": -40, "y": 50 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "1": id: "1" taskid: 45a0bb8a-26a9-4af8-8099-84544bccad92 type: regular task: id: 45a0bb8a-26a9-4af8-8099-84544bccad92 version: -1 name: Associate indicators to incident description: Associates indicators to an incident. script: Builtin|||associateIndicatorToIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "2" scriptarguments: id: {} incidentId: simple: ${incident.id} value: simple: ${playbookQuery.value} separatecontext: false view: |- { "position": { "x": 162.5, "y": 545 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "2": id: "2" taskid: bcc580c5-c88c-45a1-8ee7-b038d930c14b type: regular task: id: bcc580c5-c88c-45a1-8ee7-b038d930c14b version: -1 name: Manually review indicators description: Manually review the indicators. The review process can include running reputation calculation on the indicator, or reviewing the indicator online in various engines. At the end of the process, the analyst needs to add the relevant indicator tags, such as approved_watchlist, approved_allow, approved_block, etc. These tags are later used by another playbook to send the indicators to relevant 3rd party systems such as SIEM, EDR, EDL etc. type: regular iscommand: false brand: "" nexttasks: '#none#': - "16" separatecontext: false view: |- { "position": { "x": 162.5, "y": 720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "3": id: "3" taskid: 58ce9edb-06d2-4601-8b65-5efe0ff19ea1 type: title task: id: 58ce9edb-06d2-4601-8b65-5efe0ff19ea1 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": -40, "y": 2080 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "4": id: "4" taskid: 6347cecd-69c5-45e1-8e33-a9ff184ed697 type: regular task: id: 6347cecd-69c5-45e1-8e33-a9ff184ed697 version: -1 name: Add being reviewed tag to indicators description: Add being reviewed tag to indicators script: Builtin|||appendIndicatorField type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "1" scriptarguments: field: simple: tags fieldValue: simple: being_reviewed indicatorsValues: simple: ${playbookQuery.value} separatecontext: false view: |- { "position": { "x": 162.5, "y": 370 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "6": id: "6" taskid: 21dc7963-c302-415d-843b-257e7d2861ac type: condition task: id: 21dc7963-c302-415d-843b-257e7d2861ac version: -1 name: Allow to remove allowlist review tag from all indicators type: condition iscommand: false brand: "" description: '' nexttasks: '#default#': - "12" "yes": - "8" separatecontext: false view: |- { "position": { "x": 162.5, "y": 1570 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "8": id: "8" taskid: f7de89f6-eb9a-44e6-84da-8ef43a58aa25 type: regular task: id: f7de89f6-eb9a-44e6-84da-8ef43a58aa25 version: -1 name: Remove allowlist review tag from indicators description: Removes the allowlist review tag from indicators script: Builtin|||removeIndicatorField type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "12" scriptarguments: field: simple: tags fieldValue: simple: allowlist_review indicatorsValues: simple: ${playbookQuery.value} separatecontext: false view: |- { "position": { "x": 410, "y": 1740 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "11": id: "11" taskid: ddb2dcd9-bacf-4de5-83a7-e15d66aac4f5 type: condition task: id: ddb2dcd9-bacf-4de5-83a7-e15d66aac4f5 version: -1 name: Are there query results? type: condition iscommand: false brand: "" description: '' nexttasks: '#default#': - "3" "yes": - "4" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: playbookQuery.value iscontext: true view: |- { "position": { "x": -40, "y": 185 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "12": id: "12" taskid: 96afe586-c3c2-4b1c-823a-b9b2856f13ca type: regular task: id: 96afe586-c3c2-4b1c-823a-b9b2856f13ca version: -1 name: Remove being reviewed tag from indicators description: Removes the 'being_reviewed' tag from the indicator. script: Builtin|||removeIndicatorField type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "3" scriptarguments: field: simple: tags fieldValue: simple: being_reviewed indicatorsValues: simple: ${playbookQuery.value} separatecontext: false view: |- { "position": { "x": 162.5, "y": 1910 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "14": id: "14" taskid: e9f7c185-a753-4fb4-83d4-3dc7fe0c2652 type: regular task: id: e9f7c185-a753-4fb4-83d4-3dc7fe0c2652 version: -1 name: Make changes according the approver's request type: regular iscommand: false brand: "" description: '' nexttasks: '#none#': - "6" separatecontext: false view: |- { "position": { "x": 600, "y": 1400 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "15": id: "15" taskid: b9b0154e-efc7-4f6a-808f-c9faff5ad536 type: collection task: id: b9b0154e-efc7-4f6a-808f-c9faff5ad536 version: -1 name: Email for indicator changes approval type: collection iscommand: false brand: "" description: '' nexttasks: '#none#': - "18" separatecontext: false view: |- { "position": { "x": 430, "y": 1070 } } note: false timertriggers: [] ignoreworker: false message: to: simple: ${inputs.ApproversEmailAddress} subject: simple: Approve indicator changes body: simple: |- Please review this incident ${demistoUrls.server}/#/Custom/indeooemoh/${incident.investigationId} And approve the changes made to the indicators. Related indicators will appear in the Indicators tab. methods: - email format: html bcc: null cc: null timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 replyOptions: - "Yes" - "No" form: questions: - id: "0" label: "" labelarg: simple: Specify the indicators that weren't approved required: false gridcolumns: [] defaultrows: [] type: longText options: [] fieldassociated: "" placeholder: "" tooltip: "" readonly: false title: List the indicators are are not approved description: The approver reviews the incident and changes made by the analyst. In case the approver needs specific indicators to be changed, they will list the relevant indicators. sender: "" expired: false totalanswers: 0 skipunavailable: false quietmode: 2 "16": id: "16" taskid: 22860fd3-c8dd-4c17-8f81-4f9537a1e3c3 type: condition task: id: 22860fd3-c8dd-4c17-8f81-4f9537a1e3c3 version: -1 name: Was an email address provided for approval? type: condition iscommand: false brand: "" description: '' nexttasks: '#default#': - "6" "yes": - "15" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: inputs.ApproversEmailAddress iscontext: true - - operator: match left: value: simple: inputs.ApproversEmailAddress iscontext: true right: value: simple: .*@.*\.* view: |- { "position": { "x": 162.5, "y": 885 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "18": id: "18" taskid: 46edfee8-7778-4c27-85ed-d4b0fdc1825f type: condition task: id: 46edfee8-7778-4c27-85ed-d4b0fdc1825f version: -1 name: Are there indicators that weren't approved? type: condition iscommand: false brand: "" description: '' nexttasks: '#default#': - "6" "yes": - "14" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: List the indicators are are not approved.Answers.0 iscontext: true view: |- { "position": { "x": 430, "y": 1220 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 2 view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 2095, "width": 1020, "x": -40, "y": 50 } } } inputs: - key: "" value: {} required: false description: "" playbookInputQuery: query: tags:allowlist_review and -tags:being_reviewed queryEntity: indicators results: null daterange: fromdate: 0001-01-01T00:00:00Z todate: 0001-01-01T00:00:00Z period: by: "" byto: "" byfrom: "" tovalue: null fromvalue: null field: "" fromdatelicenseval: 0001-01-01T00:00:00Z runFromLastJobTime: false - key: ApproversEmailAddress value: {} required: false description: This input specifies the email address to which to send the approval form if approval is required. playbookInputQuery: null outputs: [] quiet: true tests: - No test