CyrenThreatInDepthRandomHunt
This script will take a random Cyren Threat InDepth feed indicator and its relationships and create a threat hunting incident for you. The main query parameters for the resulting, internal indicator query are: 1. Seen for the first time by the feed source within the last 7 days. 2. No investigation on it yet. 3. Must have relationships to other indicators.
Details
| ID | CyrenThreatInDepthRandomHunt |
|---|---|
| Language | python |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Tags | incidents iocs cyren hunt |
README
This script will take a random Cyren Threat InDepth feed indicator and its relationships
and create a threat hunting incident for you.
The main query parameters for the resulting, internal indicator query are:
- Seen for the first time by the feed source within the last 7 days.
- No investigation on it yet.
- Must have relationships to other indicators.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | incidents, ioc, cyren, hunt |
| XSOAR Version | 6.0.0 |
Inputs
| Argument Name | Description |
|---|---|
| indicator_type | Optional: One of ip_reputation, malware_files, malware_urls, phishing_urls, will determine the Cyren Threat InDepth feed the indicator is taken from (if not provided a random indicator type is chosen) |
| incident_type | Optional: If not provided, an incident of type “Hunt” is created |
Outputs
There are no outputs for this script.
Human Readable Output
Successfully created incident Cyren Threat InDepth Threat Hunt.
Click here to investigate: 1234.
args: - auto: PREDEFINED description: Determines the Cyren Threat InDepth feed the indicator is taken from (optional, can be left empty) name: indicator_type predefined: - ip_reputation - malware_files - malware_urls - phishing_urls - defaultValue: Hunt description: Specify the incident type you want to have created (optional, default is Hunt) name: incident_type - description: Specify the user you want to assign the new incident (optional, default is current user) name: assignee comment: 'This script will take a random Cyren Threat InDepth feed indicator and its relationships and create a threat hunting incident for you. The main query parameters for the resulting, internal indicator query are: 1. Seen for the first time by the feed source within the last 7 days. 2. No investigation on it yet. 3. Must have relationships to other indicators.' commonfields: id: CyrenThreatInDepthRandomHunt version: -1 dockerimage: demisto/python3:3.12.13.10116658 enabled: true name: CyrenThreatInDepthRandomHunt script: '-' subtype: python3 tags: - incidents - iocs - cyren - hunt type: python fromversion: 6.0.0