TIM - Review Indicators Manually For Allowlisting

This playbook helps analysts manage the manual process of adding indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query is set to search for indicators that have the 'allowlist_review' tag. The playbooks layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags such as, 'approved_block', 'approved_allow', etc. Once the analyst completes the review, the playbook can optionally send an email with a list of changes done by the analyst which haven't been approved. Once complete, the playbook removes the 'allowlist review' tag from the indicators.

TIM - Indicator Auto-Processing · 13 tasks · 2 inputs · 0 outputs

Details

IDTIM - Review Indicators Manually For Allowlisting
From Version5.5.0
Tasks13

README

This playbook helps analysts manage the manual process of adding indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query is set to search for indicators that have the ‘allowlist_review’ tag. The playbooks layout displays all of the related indicators in the summary page. While reviewing the indicators, the analyst can go to the summary page and tag the indicators accordingly with tags such as, ‘approved_block’, ‘approved_allow’, etc. Once the analyst completes the review, the playbook can optionally send an email with a list of changes done by the analyst which haven’t been approved. Once complete, the playbook removes the ‘allowlist review’ tag from the indicators.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

This playbook does not use any scripts.

Commands

  • associateIndicatorToIncident
  • removeIndicatorField
  • appendIndicatorField

Playbook Inputs


Name Description Default Value Required
Indicator Query Indicators matching the indicator query will be used as playbook input tags:allowlist_review and -tags:being_reviewed Optional
ApproversEmailAddress This input specifies the email address to which to send the approval form if approval is required.   Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Playbook Image

Inputs

  • ApproversEmailAddress — This input specifies the email address to which to send the approval form if approval is required.

Commands used

appendIndicatorField associateIndicatorToIncident removeIndicatorField

Flowchart

yes yes yes yes Start Start Associate indicators to incident - associateIndicatorToIncident Associate indicators to i... associateIndicatorToIncident Manually review indicators Manually review indicators Done Done Add being reviewed tag to indicators - appendIndicatorField Add being reviewed tag to... appendIndicatorField Allow to remove allowlist review tag from all indicators Allow to remove allowlist... Remove allowlist review tag from indicators - removeIndicatorField Remove allowlist review t... removeIndicatorField Are there query results? Are there query results? Remove being reviewed tag from indicators - removeIndicatorField Remove being reviewed tag... removeIndicatorField Make changes according the approver's request Make changes according th... Email for indicator changes approval Email for indicator chang... Was an email address provided for approval? Was an email address prov... Are there indicators that weren't approved? Are there indicators that...
id: TIM - Review Indicators Manually For Allowlisting
version: -1
fromversion: 5.5.0
marketplaces:
- xsoar
name: TIM - Review Indicators Manually For Allowlisting
description: This playbook helps analysts manage the manual process of adding
  indicators from cloud providers, apps, services etc. to an allow list. The playbook indicator query
  is set to search for indicators that have the 'allowlist_review' tag. The playbooks
  layout displays all of the related indicators in the summary page. While reviewing
  the indicators, the analyst can go to the summary page and tag the indicators accordingly
  with tags such as, 'approved_block', 'approved_allow', etc. Once the analyst completes
  the review, the playbook can optionally send an email with a list of changes done
  by the analyst which haven't been approved. Once complete, the playbook removes
  the 'allowlist review' tag from the indicators.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: ec484071-3d69-4a74-8e11-72d0a8ebdc1a
    type: start
    task:
      id: ec484071-3d69-4a74-8e11-72d0a8ebdc1a
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "11"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -40,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "1":
    id: "1"
    taskid: 45a0bb8a-26a9-4af8-8099-84544bccad92
    type: regular
    task:
      id: 45a0bb8a-26a9-4af8-8099-84544bccad92
      version: -1
      name: Associate indicators to incident
      description: Associates indicators to an incident.
      script: Builtin|||associateIndicatorToIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "2"
    scriptarguments:
      id: {}
      incidentId:
        simple: ${incident.id}
      value:
        simple: ${playbookQuery.value}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "2":
    id: "2"
    taskid: bcc580c5-c88c-45a1-8ee7-b038d930c14b
    type: regular
    task:
      id: bcc580c5-c88c-45a1-8ee7-b038d930c14b
      version: -1
      name: Manually review indicators
      description: Manually review the indicators. The review process can include
        running reputation calculation on the indicator, or reviewing the indicator
        online in various engines. At the end of the process, the analyst needs to
        add the relevant indicator tags, such as approved_watchlist, approved_allow,
        approved_block, etc. These tags are later used by another playbook to send
        the indicators to relevant 3rd party systems such as SIEM, EDR, EDL etc.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "16"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "3":
    id: "3"
    taskid: 58ce9edb-06d2-4601-8b65-5efe0ff19ea1
    type: title
    task:
      id: 58ce9edb-06d2-4601-8b65-5efe0ff19ea1
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -40,
          "y": 2080
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "4":
    id: "4"
    taskid: 6347cecd-69c5-45e1-8e33-a9ff184ed697
    type: regular
    task:
      id: 6347cecd-69c5-45e1-8e33-a9ff184ed697
      version: -1
      name: Add being reviewed tag to indicators
      description: Add being reviewed tag to indicators
      script: Builtin|||appendIndicatorField
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "1"
    scriptarguments:
      field:
        simple: tags
      fieldValue:
        simple: being_reviewed
      indicatorsValues:
        simple: ${playbookQuery.value}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "6":
    id: "6"
    taskid: 21dc7963-c302-415d-843b-257e7d2861ac
    type: condition
    task:
      id: 21dc7963-c302-415d-843b-257e7d2861ac
      version: -1
      name: Allow to remove allowlist review tag from all indicators
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "12"
      "yes":
      - "8"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "8":
    id: "8"
    taskid: f7de89f6-eb9a-44e6-84da-8ef43a58aa25
    type: regular
    task:
      id: f7de89f6-eb9a-44e6-84da-8ef43a58aa25
      version: -1
      name: Remove allowlist review tag from indicators
      description: Removes the allowlist review tag from indicators
      script: Builtin|||removeIndicatorField
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "12"
    scriptarguments:
      field:
        simple: tags
      fieldValue:
        simple: allowlist_review
      indicatorsValues:
        simple: ${playbookQuery.value}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 410,
          "y": 1740
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "11":
    id: "11"
    taskid: ddb2dcd9-bacf-4de5-83a7-e15d66aac4f5
    type: condition
    task:
      id: ddb2dcd9-bacf-4de5-83a7-e15d66aac4f5
      version: -1
      name: Are there query results?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "4"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: playbookQuery.value
            iscontext: true
    view: |-
      {
        "position": {
          "x": -40,
          "y": 185
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "12":
    id: "12"
    taskid: 96afe586-c3c2-4b1c-823a-b9b2856f13ca
    type: regular
    task:
      id: 96afe586-c3c2-4b1c-823a-b9b2856f13ca
      version: -1
      name: Remove being reviewed tag from indicators
      description: Removes the 'being_reviewed' tag from the indicator.
      script: Builtin|||removeIndicatorField
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      field:
        simple: tags
      fieldValue:
        simple: being_reviewed
      indicatorsValues:
        simple: ${playbookQuery.value}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 1910
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "14":
    id: "14"
    taskid: e9f7c185-a753-4fb4-83d4-3dc7fe0c2652
    type: regular
    task:
      id: e9f7c185-a753-4fb4-83d4-3dc7fe0c2652
      version: -1
      name: Make changes according the approver's request
      type: regular
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "6"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 600,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "15":
    id: "15"
    taskid: b9b0154e-efc7-4f6a-808f-c9faff5ad536
    type: collection
    task:
      id: b9b0154e-efc7-4f6a-808f-c9faff5ad536
      version: -1
      name: Email for indicator changes approval
      type: collection
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "18"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 430,
          "y": 1070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
        simple: ${inputs.ApproversEmailAddress}
      subject:
        simple: Approve indicator changes
      body:
        simple: |-
          Please review this incident
          ${demistoUrls.server}/#/Custom/indeooemoh/${incident.investigationId}
          And approve the changes made to the indicators.
          Related indicators will appear in the Indicators tab.
      methods:
      - email
      format: html
      bcc: null
      cc: null
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
      replyOptions:
      - "Yes"
      - "No"
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: Specify the indicators that weren't approved
        required: false
        gridcolumns: []
        defaultrows: []
        type: longText
        options: []
        fieldassociated: ""
        placeholder: ""
        tooltip: ""
        readonly: false
      title: List the indicators are are not approved
      description: The approver reviews the incident and changes made by the analyst.
        In case the approver needs specific indicators to be changed, they will list
        the relevant indicators.
      sender: ""
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 2
  "16":
    id: "16"
    taskid: 22860fd3-c8dd-4c17-8f81-4f9537a1e3c3
    type: condition
    task:
      id: 22860fd3-c8dd-4c17-8f81-4f9537a1e3c3
      version: -1
      name: Was an email address provided for approval?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "6"
      "yes":
      - "15"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: inputs.ApproversEmailAddress
            iscontext: true
      - - operator: match
          left:
            value:
              simple: inputs.ApproversEmailAddress
            iscontext: true
          right:
            value:
              simple: .*@.*\.*
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "18":
    id: "18"
    taskid: 46edfee8-7778-4c27-85ed-d4b0fdc1825f
    type: condition
    task:
      id: 46edfee8-7778-4c27-85ed-d4b0fdc1825f
      version: -1
      name: Are there indicators that weren't approved?
      type: condition
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#default#':
      - "6"
      "yes":
      - "14"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: List the indicators are are not approved.Answers.0
            iscontext: true
    view: |-
      {
        "position": {
          "x": 430,
          "y": 1220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 2
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 2095,
        "width": 1020,
        "x": -40,
        "y": 50
      }
    }
  }
inputs:
- key: ""
  value: {}
  required: false
  description: ""
  playbookInputQuery:
    query: tags:allowlist_review and -tags:being_reviewed
    queryEntity: indicators
    results: null
    daterange:
      fromdate: 0001-01-01T00:00:00Z
      todate: 0001-01-01T00:00:00Z
      period:
        by: ""
        byto: ""
        byfrom: ""
        tovalue: null
        fromvalue: null
        field: ""
      fromdatelicenseval: 0001-01-01T00:00:00Z
    runFromLastJobTime: false
- key: ApproversEmailAddress
  value: {}
  required: false
  description: This input specifies the email address to which to send the approval
    form if approval is required.
  playbookInputQuery: null
outputs: []
quiet: true
tests:
- No test