id: NGFW Internal Scan version: -1 name: NGFW Internal Scan description: | This playbook investigates a scan where the source is an internal IP address. An attacker might initiate an internal scan for discovery, lateral movement and more. **Attacker's Goals:** An attacker can leverage a scan for open ports and vulnerable systems on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services. **Investigative Actions:** * Endpoint Investigation Plan playbook **Response Actions** The playbook's response actions are based on the Endpoint Investigation Plan playbook results. In that phase, the playbook will execute: * Auto endpoint isolation * Manual block indicators * Manual file quarantine starttaskid: "0" tasks: "0": id: "0" taskid: 3ecd7ed7-c821-46c1-8a4e-dc6250b266ec type: start task: id: 3ecd7ed7-c821-46c1-8a4e-dc6250b266ec version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "7" separatecontext: false view: |- { "position": { "x": 440, "y": -140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "1": id: "1" taskid: 87c1a8ec-c2f2-4b91-8721-f44652f1634c type: playbook task: id: 87c1a8ec-c2f2-4b91-8721-f44652f1634c version: -1 name: Account Enrichment - Generic v2.1 description: |- Enrich accounts using one or more integrations. Supported integrations: - Active Directory playbookName: Account Enrichment - Generic v2.1 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "8" scriptarguments: Username: complex: root: alert accessor: username transformers: - operator: uniq separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 200, "y": 180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "7": id: "7" taskid: 8ed375b2-b63e-47b1-8f39-6d90c4bb0dcc type: title task: id: 8ed375b2-b63e-47b1-8f39-6d90c4bb0dcc version: -1 name: Enrichment type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "1" - "28" separatecontext: false view: |- { "position": { "x": 440, "y": 30 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "8": id: "8" taskid: f17016e4-9d9f-4d47-8621-87f10e27c144 type: title task: id: f17016e4-9d9f-4d47-8621-87f10e27c144 version: -1 name: Investigation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "24" separatecontext: false view: |- { "position": { "x": 440, "y": 360 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "11": id: "11" taskid: f84429f7-dd8d-4b8f-8746-e4f0e34f46e9 type: title task: id: f84429f7-dd8d-4b8f-8746-e4f0e34f46e9 version: -1 name: Remediation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "12" separatecontext: false view: |- { "position": { "x": 60, "y": 1340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "12": id: "12" taskid: 7dfb9c5d-5ad6-4bdd-881f-bfce33da263c type: playbook task: id: 7dfb9c5d-5ad6-4bdd-881f-bfce33da263c version: -1 name: Containment Plan description: |- This playbook handles all the containment actions available with Cortex XSIAM. The playbook allows to contain the alert with one of the following tasks: * Isolate endpoint * Disable account * Quarantine file * Block indicators * Clear user session (currently, the playbook supports only Okta) The playbook inputs allows you to manipulate the execution flow. Review the inputs description. playbookName: Containment Plan type: playbook iscommand: false brand: "" nexttasks: '#none#': - "18" scriptarguments: AutoContainment: complex: root: inputs.AutoContainment BlockIndicators: simple: "False" ClearUserSessions: simple: "False" EndpointID: complex: root: alert accessor: agentid FileContainment: simple: "False" FileHash: complex: root: foundIncidents.CustomFields filters: - - operator: isNotEqualString left: value: simple: foundIncidents.CustomFields.initiatorpath iscontext: true right: value: simple: c:\windows\explorer.exe ignorecase: true accessor: initiatorsha256 FilePath: complex: root: foundIncidents.CustomFields.initiatorpath filters: - - operator: isNotEqualString left: value: simple: foundIncidents.CustomFields.initiatorpath iscontext: true right: value: simple: c:\windows\explorer.exe ignorecase: true FileRemediation: simple: Quarantine HostAutoContainment: complex: root: inputs.HostAutoContainment IAMUserDomain: simple: '@xsoar.com' UserContainment: simple: "False" separatecontext: false loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 60, "y": 1480 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "15": id: "15" taskid: adea3df5-fc34-4ca3-83f5-ca3a7e60cec4 type: condition task: id: adea3df5-fc34-4ca3-83f5-ca3a7e60cec4 version: -1 name: Was other activity found for the scanning host? description: Checks if any other activity was found for the scanning host. type: condition iscommand: false brand: "" nexttasks: '#default#': - "18" "yes": - "25" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: foundincidents iscontext: true right: value: {} view: |- { "position": { "x": 440, "y": 660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "18": id: "18" taskid: 14a8536b-2d4e-4124-8712-39d147e4c6d0 type: condition task: id: 14a8536b-2d4e-4124-8712-39d147e4c6d0 version: -1 name: Should close the alert? description: Whether to close the alert automatically or continue with the investigation. type: condition iscommand: false brand: "" nexttasks: '#default#': - "19" "Yes": - "23" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.AutoCloseAlert iscontext: true right: value: simple: "true" ignorecase: true view: |- { "position": { "x": 440, "y": 1650 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "19": id: "19" taskid: cdde9f89-b5ae-4db0-85e0-bbcebbb4fd1a type: regular task: id: cdde9f89-b5ae-4db0-85e0-bbcebbb4fd1a version: -1 name: Continue with the investigation description: The AutoCloseAlert input is false, hence, a manual decision whether to close it or investigate further is needed. type: regular iscommand: false brand: "" nexttasks: '#none#': - "23" separatecontext: false view: |- { "position": { "x": 60, "y": 1820 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "20": id: "20" taskid: 8bb3b16b-4a01-4e95-81c3-95dafe8c3231 type: title task: id: 8bb3b16b-4a01-4e95-81c3-95dafe8c3231 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": 440, "y": 2180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "23": id: "23" taskid: 2c8a152f-e2e3-4c40-89a7-0eb0be8bc68d type: regular task: id: 2c8a152f-e2e3-4c40-89a7-0eb0be8bc68d version: -1 name: Close alert description: commands.local.cmd.close.inv script: Builtin|||closeInvestigation type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "20" separatecontext: false view: |- { "position": { "x": 440, "y": 2000 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "24": id: "24" taskid: 9f808ed4-3737-4536-8bb2-276ed2c9e330 type: playbook task: id: 9f808ed4-3737-4536-8bb2-276ed2c9e330 version: -1 name: Endpoint Investigation Plan description: |- This playbook handles all the endpoint investigation actions available with Cortex XSIAM. The playbook enables you to investigate and hunt for more information using one of the following tasks: * Pre-defined MITRE Tactics * Host fields (Host ID) * Attacker fields (Attacker IP, External host) * MITRE techniques * File hash (currently, the playbook supports only SHA256) The playbook inputs enable you to manipulate the execution flow. Review the inputs description. playbookName: Endpoint Investigation Plan type: playbook iscommand: false brand: "" nexttasks: '#none#': - "15" scriptarguments: HuntAttacker: simple: "True" HuntCnCTechniques: simple: "False" HuntCollectionTechniques: simple: "False" HuntDefenseEvasionTechniques: simple: "False" HuntDiscoveryTechniques: simple: "False" HuntExecutionTechniques: simple: "False" HuntImpactTechniques: simple: "False" HuntInitialAccessTechniques: simple: "False" HuntLateralMovementTechniques: simple: "False" HuntPersistenceTechniques: simple: "False" HuntPrivilegeEscalationTechniques: simple: "False" HuntReconnaissanceTechniques: simple: "False" agentID: simple: '*' attackerRemoteIP: complex: root: inputs.scannerIP separatecontext: false loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 440, "y": 490 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "25": id: "25" taskid: 6dbec345-05c5-4203-8c12-1b2ab81410d8 type: regular task: id: 6dbec345-05c5-4203-8c12-1b2ab81410d8 version: -1 name: Set Alert Severity to High description: commands.local.cmd.set.parent.alert.field script: Builtin|||setParentIncidentFields type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "26" scriptarguments: manual_severity: simple: high separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 60, "y": 835 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 2 isoversize: false isautoswitchedtoquietmode: false "26": id: "26" taskid: 3e3cd67a-5288-4489-8697-11ddbd6c6c5f type: condition task: id: 3e3cd67a-5288-4489-8697-11ddbd6c6c5f version: -1 name: Should open a ticket automatically in a ticketing system? description: Checks whether to open a ticket automatically in a ticketing system. type: condition iscommand: false brand: "" nexttasks: '#default#': - "11" "yes": - "27" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.ShouldOpenTicket iscontext: true right: value: simple: "True" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 60, "y": 1000 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "27": id: "27" taskid: 9c16cf70-885d-4b45-8333-5722e50f131a type: playbook task: id: 9c16cf70-885d-4b45-8333-5722e50f131a version: -1 name: Ticket Management - Generic description: "`Ticket Management - Generic` allows you to open new tickets or update comments to the existing ticket in the following ticketing systems:\n-ServiceNow \n-Zendesk \nusing the following sub-playbooks:\n-`ServiceNow - Ticket Management`\n-`Zendesk - Ticket Management`\n" playbookName: Ticket Management - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "11" scriptarguments: CommentToAdd: complex: root: inputs.CommentToAdd ZendeskAssigne: complex: root: inputs.ZendeskAssigne ZendeskCollaborators: complex: root: inputs.ZendeskCollaborators ZendeskPriority: complex: root: inputs.ZendeskPriority ZendeskRequester: complex: root: inputs.ZendeskRequester ZendeskStatus: complex: root: inputs.ZendeskStatus ZendeskSubject: complex: root: inputs.ZendeskSubject ZendeskTags: complex: root: inputs.ZendeskTags ZendeskType: complex: root: inputs.ZendeskType addCommentPerEndpoint: complex: root: inputs.addCommentPerEndpoint description: complex: root: inputs.description serviceNowAssignmentGroup: complex: root: inputs.serviceNowAssignmentGroup serviceNowCategory: complex: root: inputs.serviceNowCategory serviceNowImpact: complex: root: inputs.serviceNowImpact serviceNowSeverity: complex: root: inputs.serviceNowSeverity serviceNowShortDescription: complex: root: inputs.serviceNowShortDescription serviceNowTicketType: complex: root: inputs.serviceNowTicketType serviceNowUrgency: complex: root: inputs.serviceNowUrgency separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -200, "y": 1170 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "28": id: "28" taskid: 42116819-eaab-4919-830d-3d86bcfb2bb5 type: playbook task: id: 42116819-eaab-4919-830d-3d86bcfb2bb5 version: -1 name: Endpoint Enrichment - Generic v2.1 description: |- Enrich an endpoint by hostname using one or more integrations. Supported integrations: - Active Directory Query v2 - McAfee ePO v2 - VMware Carbon Black EDR v2 - Cylance Protect v2 - CrowdStrike Falcon - ExtraHop Reveal(x) - Cortex XDR / Core (endpoint enrichment, reputation and risk) - Endpoint reputation using !endpoint command playbookName: Endpoint Enrichment - Generic v2.1 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "8" scriptarguments: IPAddress: complex: root: inputs.scannerIP transformers: - operator: uniq UseReputationCommand: simple: "False" separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 680, "y": 180 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": { "18_19_#default#": 0.4 }, "paper": { "dimensions": { "height": 2385, "width": 1260, "x": -200, "y": -140 } } } inputs: - key: scannerIP value: complex: root: alert accessor: hostip required: false description: The scanner IP address playbookInputQuery: - key: AutoCloseAlert value: simple: "false" required: false description: Whether to close the alert automatically or manually, after an analyst's review. playbookInputQuery: - key: AutoContainment value: {} required: false description: |- Whether to execute automatically or manually the containment plan tasks: * Block indicators * Quarantine file * Disable user playbookInputQuery: - key: HostAutoContainment value: {} required: false description: Whether to execute endpoint isolation automatically or manually. playbookInputQuery: - key: ShouldOpenTicket value: simple: "False" required: false description: Whether to open a ticket automatically in a ticketing system. (True/False). playbookInputQuery: - key: serviceNowShortDescription value: simple: XSIAM Incident ID - ${parentIncidentFields.incident_id} required: false description: A short description of the ticket. playbookInputQuery: - key: serviceNowImpact value: {} required: false description: The impact for the new ticket. Leave empty for ServiceNow default impact. playbookInputQuery: - key: serviceNowUrgency value: {} required: false description: The urgency of the new ticket. Leave empty for ServiceNow default urgency. playbookInputQuery: - key: serviceNowSeverity value: {} required: false description: The severity of the new ticket. Leave empty for ServiceNow default severity. playbookInputQuery: - key: serviceNowTicketType value: {} required: false description: The ServiceNow ticket type. Options are "incident", "problem", "change_request", "sc_request", "sc_task", or "sc_req_item". Default is "incident". playbookInputQuery: - key: serviceNowCategory value: {} required: false description: The category of the ServiceNow ticket. playbookInputQuery: - key: serviceNowAssignmentGroup value: {} required: false description: The group to which to assign the new ticket. playbookInputQuery: - key: ZendeskPriority value: {} required: false description: The urgency with which the ticket should be addressed. Allowed values are "urgent", "high", "normal", or "low". playbookInputQuery: - key: ZendeskRequester value: {} required: false description: The user who requested this ticket. playbookInputQuery: - key: ZendeskStatus value: {} required: false description: The state of the ticket. Allowed values are "new", "open", "pending", "hold", "solved", or "closed". playbookInputQuery: - key: ZendeskSubject value: simple: XSIAM Incident ID - ${parentIncidentFields.incident_id} required: false description: The value of the subject field for this ticket. playbookInputQuery: - key: ZendeskTags value: {} required: false description: The array of tags applied to this ticket. playbookInputQuery: - key: ZendeskType value: {} required: false description: The type of this ticket. Allowed values are "problem", "incident", "question", or "task". playbookInputQuery: - key: ZendeskAssigne value: {} required: false description: The agent currently assigned to the ticket. playbookInputQuery: - key: ZendeskCollaborators value: {} required: false description: The users currently CC'ed on the ticket. playbookInputQuery: - key: description value: simple: ${parentIncidentFields.description}. ${parentIncidentFields.xdr_url} required: false description: The ticket description. playbookInputQuery: - key: addCommentPerEndpoint value: simple: "True" required: false description: 'Whether to append a new comment to the ticket for each endpoint in the incident. Possible values: True/False.' playbookInputQuery: - key: CommentToAdd value: simple: '${alert.name}. Alert ID: ${alert.id}' required: false description: Comment for the ticket. playbookInputQuery: inputSections: - inputs: - AutoCloseAlert name: Alert Management description: Alert management settings and data, including escalation processes, and user engagements. - inputs: - scannerIP name: Investigation description: Investigation settings and data, including any deep dive alert investigation and verdict determination. - inputs: - AutoContainment - HostAutoContainment name: Remediation description: Remediation settings and data, including containment, eradication, and recovery. - inputs: - ShouldOpenTicket - serviceNowShortDescription - serviceNowImpact - serviceNowUrgency - serviceNowSeverity - serviceNowTicketType - serviceNowCategory - serviceNowAssignmentGroup - ZendeskPriority - ZendeskRequester - ZendeskStatus - ZendeskSubject - ZendeskTags - ZendeskType - ZendeskAssigne - ZendeskCollaborators - description - addCommentPerEndpoint - CommentToAdd name: Ticket Management description: Ticket management settings and data. outputSections: - outputs: [] name: General (Outputs group) description: Generic group for outputs outputs: [] tests: - No tests (auto formatted) marketplaces: - marketplacev2 - platform fromversion: 6.6.0 supportedModules: - agentix - cloud - cloud_posture - cloud_runtime_security - edr - xsiam