id: Pentera Filter And Create Incident version: -1 name: Pentera Filter And Create Incident description: Sub-playbook to select specific entries from the Pentera action report and create incidents for each of the selected entries starttaskid: '0' tasks: '0': id: '0' taskid: ed5fe622-78c8-499a-8122-404fad3e2339 type: start task: id: ed5fe622-78c8-499a-8122-404fad3e2339 version: -1 name: '' iscommand: false brand: '' description: '' nexttasks: '#none#': - '15' separatecontext: false view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 50\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '1': id: '1' taskid: 2ff4fb91-5267-486a-8139-c6bd26c43e42 type: regular task: id: 2ff4fb91-5267-486a-8139-c6bd26c43e42 version: -1 name: FilterBySeverity description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '4' scriptarguments: append: simple: 'false' key: simple: FilteredBySeverity stringify: {} value: complex: root: SuccessfulOperations filters: - - operator: greaterThan left: value: simple: SuccessfulOperations.Severity iscontext: true right: value: simple: inputs.Filter Minimum Severity iscontext: true separatecontext: false view: "{\n \"position\": {\n \"x\": 1165,\n \"y\": 835\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '2': id: '2' taskid: 8a58b205-8db2-4f66-833e-26292c0f4164 type: condition task: id: 8a58b205-8db2-4f66-833e-26292c0f4164 version: -1 name: Is Minimum Severity Greater Than Zero type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '3' 'yes': - '1' separatecontext: false conditions: - label: 'yes' condition: - - operator: greaterThan left: value: simple: inputs.Filter Minimum Severity iscontext: true right: value: simple: '0' view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 660\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '3': id: '3' taskid: a0aa3683-ff03-44d8-8c00-641e2791ae3a type: regular task: id: a0aa3683-ff03-44d8-8c00-641e2791ae3a version: -1 name: Select all the entries description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '4' scriptarguments: append: simple: 'false' key: simple: FilteredBySeverity stringify: {} value: complex: root: SuccessfulOperations separatecontext: false view: "{\n \"position\": {\n \"x\": 735,\n \"y\": 835\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '4': id: '4' taskid: 0cdc17a2-92ca-49db-8fbb-282b27ff6ec0 type: title task: id: 0cdc17a2-92ca-49db-8fbb-282b27ff6ec0 version: -1 name: Filter by Operation Type and a successful Status type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '5' - '9' - '11' - '13' - '25' separatecontext: false view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 1010\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '5': id: '5' taskid: 2c797aac-dfe4-4586-8833-660c3f57ba2b type: condition task: id: 2c797aac-dfe4-4586-8833-660c3f57ba2b version: -1 name: Are we filtering BlueKeep type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '8' 'yes': - '20' separatecontext: false conditions: - label: 'yes' condition: - - operator: isEqualString left: value: simple: inputs.Filter BlueKeep vulnerability iscontext: true right: value: simple: 'True' ignorecase: true view: "{\n \"position\": {\n \"x\": 50,\n \"y\": 1155\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '8': id: '8' taskid: f97ebe5a-1bad-432c-8cd2-4cce1ff9051c type: title task: id: f97ebe5a-1bad-432c-8cd2-4cce1ff9051c version: -1 name: Incidents type: title iscommand: false brand: '' description: '' separatecontext: false view: "{\n \"position\": {\n \"x\": -250,\n \"y\": 2280\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '9': id: '9' taskid: cccf54e0-f450-4e83-8299-036f0f144870 type: condition task: id: cccf54e0-f450-4e83-8299-036f0f144870 version: -1 name: Are filtering we MS17-010 vulnerability type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '8' 'yes': - '10' separatecontext: false conditions: - label: 'yes' condition: - - operator: isEqualString left: value: simple: inputs.Filter MS17-010 vulnerability iscontext: true right: value: simple: 'True' ignorecase: true view: "{\n \"position\": {\n \"x\": 500,\n \"y\": 1155\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '10': id: '10' taskid: ec9c975c-1556-4a4a-8d95-c5bf56968034 type: regular task: id: ec9c975c-1556-4a4a-8d95-c5bf56968034 version: -1 name: FilterMS17010OperationTypes description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '22' scriptarguments: append: simple: 'true' key: simple: FilterPenteraOperations stringify: {} value: complex: root: FilteredBySeverity filters: - - operator: containsString left: value: simple: FilteredBySeverity.Operation Type iscontext: true right: value: simple: MS017-10 Analysis ignorecase: true separatecontext: false view: "{\n \"position\": {\n \"x\": 612.5,\n \"y\": 1330\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '11': id: '11' taskid: 93c28eb8-dd1f-470e-869f-95cce6ff4162 type: condition task: id: 93c28eb8-dd1f-470e-869f-95cce6ff4162 version: -1 name: Are we filtering password cracking type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '8' 'yes': - '12' separatecontext: false conditions: - label: 'yes' condition: - - operator: isEqualString left: value: simple: inputs.Filter password cracking iscontext: true right: value: simple: 'True' ignorecase: true view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 1155\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '12': id: '12' taskid: 98ca5d8e-849f-4f7a-8e5a-90e748794ab8 type: regular task: id: 98ca5d8e-849f-4f7a-8e5a-90e748794ab8 version: -1 name: FilterPasswordCrackingOperationTypes description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '22' scriptarguments: append: simple: 'true' key: simple: FilterPenteraOperations stringify: {} value: complex: root: FilteredBySeverity filters: - - operator: containsString left: value: simple: FilteredBySeverity.Operation Type iscontext: true right: value: simple: Password Crack Level ignorecase: true separatecontext: false view: "{\n \"position\": {\n \"x\": 1062.5,\n \"y\": 1330\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '13': id: '13' taskid: 950328b4-5ced-4d17-8da7-4d7ddb56ca3b type: condition task: id: 950328b4-5ced-4d17-8da7-4d7ddb56ca3b version: -1 name: Are we filtering network device default password usage type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '8' 'yes': - '14' separatecontext: false conditions: - label: 'yes' condition: - - operator: isEqualString left: value: simple: inputs.Filter network device default password usage iscontext: true right: value: simple: 'True' ignorecase: true view: "{\n \"position\": {\n \"x\": 1400,\n \"y\": 1155\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '14': id: '14' taskid: 3d4d8e9b-e83a-4513-8a87-6ea8f45e6497 type: regular task: id: 3d4d8e9b-e83a-4513-8a87-6ea8f45e6497 version: -1 name: FilterDefaultPasswordsOperationTypes description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '22' scriptarguments: append: simple: 'true' key: simple: FilterPenteraOperations stringify: {} value: complex: root: FilteredBySeverity filters: - - operator: isEqualString left: value: simple: FilteredBySeverity.Operation Type iscontext: true right: value: simple: Using default credentials on a network device or a Firewall ignorecase: true separatecontext: false view: "{\n \"position\": {\n \"x\": 1512.5,\n \"y\": 1330\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '15': id: '15' taskid: 69b6dab6-7d90-459f-864f-49938335a70d type: title task: id: 69b6dab6-7d90-459f-864f-49938335a70d version: -1 name: Filter by "success" status type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '16' separatecontext: false view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 195\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '16': id: '16' taskid: 0643290f-a130-4c67-8bf8-008791c20138 type: regular task: id: 0643290f-a130-4c67-8bf8-008791c20138 version: -1 name: FilterSuccessStatus description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '17' scriptarguments: append: simple: 'false' key: simple: SuccessfulOperations stringify: {} value: complex: root: inputs.FullActionReport filters: - - operator: isEqualString left: value: simple: inputs.FullActionReport.Status iscontext: true right: value: simple: success ignorecase: true separatecontext: false view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 340\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '17': id: '17' taskid: f34f18b2-efb3-433d-8aaf-391dd5166b21 type: title task: id: f34f18b2-efb3-433d-8aaf-391dd5166b21 version: -1 name: Filter by severity type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '2' separatecontext: false view: "{\n \"position\": {\n \"x\": 950,\n \"y\": 515\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '18': id: '18' taskid: be8973c3-d090-4c22-8203-b1bf29dea320 type: regular task: id: be8973c3-d090-4c22-8203-b1bf29dea320 version: -1 name: Create Pentera Incidents description: commands.local.cmd.create.inc script: Builtin|||createNewIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - '8' scriptarguments: accountgroups: {} accountid: {} accountname: {} activedirectoryaccountstatus: {} activedirectorydisplayname: {} activedirectorypasswordstatus: {} affecteddata: {} affecteddatatype: {} affectedindividualscontactinformation: {} agentid: {} app: {} approximatenumberofaffecteddatasubjects: {} assetid: {} attachmentcount: {} attachmentextension: {} attachmenthash: {} attachmentid: {} attachmentname: {} attachmentsize: {} attachmenttype: {} blockedaction: {} bugtraq: {} city: {} clarotyalertresolved: {} clarotyalerttype: {} clarotycategory: {} clarotynetworkid: {} clarotyrelatedassets: {} clarotyresourceid: {} clarotysiteid: {} code42alerttype: {} code42fileevents: {} commandline: {} companyaddress: {} companycity: {} companycountry: {} companyhasinsuranceforthebreach: {} companyname: {} companypostalcode: {} companypropertystatus: {} contactaddress: {} contactname: {} coordinates: {} country: {} countrywherebusinesshasitsmainestablishment: {} countrywherethebreachtookplace: {} criticalassets: {} customFields: complex: root: PenteraIncidents accessor: penteraoperationdetails_cf cve: {} cvss: {} cymulateimmediatethreatsattackid: {} cymulateimmediatethreatsfiletype: {} cymulateimmediatethreatsid: {} cymulateimmediatethreatsmitigations: {} cymulateimmediatethreatsmodule: {} cymulateimmediatethreatspayloadname: {} cymulateimmediatethreatsstatus: {} cymulateimmediatethreatsvector: {} dataencryptionstatus: {} datetimeofthebreach: {} dbotprediction: {} dbotpredictionprobability: {} dbottextsuggestionhighlighted: {} dest: {} desthostname: {} destinationip: {} destntdomain: {} destos: {} details: complex: root: PenteraIncidents accessor: details detectionendtime: {} detectionid: {} detectionticketed: {} detectionupdatetime: {} detectionurl: {} devicegsuiteaccountstatus: {} devicename: {} dpoemailaddress: {} duoaccountstatus: {} duration: {} emailaddress: {} emailauthenticitycheck: {} emailautoreply: {} emailbcc: {} emailbody: {} emailbodyformat: {} emailbodyhtml: {} emailcc: {} emailclassification: {} emailclientname: {} emailfrom: {} emailheaders: {} emailhtml: {} emailinreplyto: {} emailkeywords: {} emailmessageid: {} emailreceived: {} emailreplyto: {} emailreturnpath: {} emailsenderip: {} emailsize: {} emailsource: {} emailsubject: {} emailto: {} emailtocount: {} emailurlclicked: {} employeedisplayname: {} employeeemail: {} employeemanageremail: {} entryIDs: {} exfiltratedfiles: {} expanseexposuretype: {} expanserawjsonevent: {} expanseseverity: {} extrahopapplianceid: {} extrahophostname: {} filehash: {} filename: {} filepath: {} filesize: {} firstseen: {} globaldirectoryvisibility: {} googleaccountstatus: {} googleadminrolesstatus: {} googledisplayname: {} googledrivestatus: {} googlemailstatus: {} googlepasswordstatus: {} helloworldid: {} helloworldstatus: {} helloworldtype: {} hostname: {} indenideviceid: {} indeniissueid: {} infectedhosts: {} investigationstage: {} isolated: {} isthedatasubjecttodpia: {} labels: {} lastmodifiedby: {} lastmodifiedon: {} lastseen: {} likelyimpact: {} loginattemptcount: {} macaddress: {} mailboxdelegation: {} maliciousbehavior: {} maliciouscauseifthecauseisamaliciousattack: {} malwarefamily: {} measurestomitigate: {} name: complex: root: PenteraIncidents accessor: name niststage: {} occurred: {} offboardingdate: {} offboardingstage: {} oktaaccountstatus: {} owner: {} parentprocessid: {} participants: {} passwordexpirationstatus: {} penteraoperationdetails: {} penteraoperationtype: complex: root: PenteraIncidents accessor: penteraoperationtype penteravulnerablehosts: {} phase: {} phishingsubtype: {} pid: {} policydeleted: {} policydescription: {} policydetails: {} policyid: {} policyrecommendation: {} policyremediable: {} policyseverity: {} policytype: {} possiblecauseofthebreach: {} postalcode: {} previouscoordinates: {} previouscountry: {} previoussignindatetime: {} previoussourceip: {} prismacloudcomputeactivitytype: {} prismacloudcomputeappid: {} prismacloudcomputecategory: {} prismacloudcomputecollections: {} prismacloudcomputecommand: {} prismacloudcomputecontainer: {} prismacloudcomputecredentialid: {} prismacloudcomputedistribution: {} prismacloudcomputeerror: {} prismacloudcomputeforensic: {} prismacloudcomputefqdn: {} prismacloudcomputefunction: {} prismacloudcomputehost: {} prismacloudcomputeimage: {} prismacloudcomputeinteractive: {} prismacloudcomputekubernetesresource: {} prismacloudcomputelabels: {} prismacloudcomputeline: {} prismacloudcomputelogfile: {} prismacloudcomputemarkdown: {} prismacloudcomputemessage: {} prismacloudcomputeproject: {} prismacloudcomputeprotected: {} prismacloudcomputeprovider: {} prismacloudcomputerawalertjson: {} prismacloudcomputeregion: {} prismacloudcomputeregistry: {} prismacloudcomputerule: {} prismacloudcomputeruntime: {} prismacloudcomputeservice: {} prismacloudcomputeservicetype: {} prismacloudcomputetotal: {} prismacloudcomputetype: {} prismacloudcomputeuser: {} prismacloudid: {} prismacloudreason: {} prismacloudrules: {} prismacloudstatus: {} prismacloudtime: {} rating: {} rawparticipants: {} region: {} regionid: {} reporteremailaddress: {} resourceapiname: {} resourcecloudtype: {} resourceid: {} resourcename: {} resourcetype: {} riskrating: {} riskscore: {} roles: {} rrn: {} safebreachsimulationid: {} samaccountname: {} sansstage: {} sectorofaffectedparty: {} severity: simple: High signature: {} signindatetime: {} sixgillalertid: {} sixgillcontent: {} sixgillthreatlevel: {} sixgillthreattype: {} sizenumberofemployees: {} sizeturnover: {} skuname: {} skutier: {} sla: {} slaField: {} sourcehostname: {} sourceip: {} src: {} srchostname: {} srcntdomain: {} srcos: {} srcuser: {} subscriptionassignedby: {} subscriptioncreatedby: {} subscriptioncreatedon: {} subscriptiondescription: {} subscriptionid: {} subscriptionname: {} subscriptiontype: {} subscriptionupdatedby: {} subscriptionupdatedon: {} subtype: {} successfullogin: {} systemdefault: {} systems: {} targetfirewallversion: {} telephoneno: {} terminatedaction: {} threatactor: {} trapsid: {} travelmaplink: {} triggeredsecurityprofile: {} type: simple: Pentera Insight urlsslverification: {} user: {} useraccountcontrol: {} userdisabledstatus: {} username: {} vendorid: {} vendorproduct: {} vpcid: {} vulnerabilitycategory: {} whereisdatahosted: {} xdralertcount: {} xdralerts: {} xdrassigneduseremail: {} xdrassigneduserprettyname: {} xdrdescription: {} xdrdetectiontime: {} xdrfileartifacts: {} xdrhighseverityalertcount: {} xdrhostcount: {} xdrincidentid: {} xdrlowseverityalertcount: {} xdrmediumseverityalertcount: {} xdrnetworkartifacts: {} xdrnotes: {} xdrresolvecomment: {} xdrstatus: {} xdrurl: {} xdrusercount: {} separatecontext: false view: "{\n \"position\": {\n \"x\": 1050,\n \"y\": 2020\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '20': id: '20' taskid: 8c0987ae-977b-4e76-8e51-559ee51c1cf2 type: regular task: id: 8c0987ae-977b-4e76-8e51-559ee51c1cf2 version: -1 name: FilterBlueKeepOperationTypes description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '22' scriptarguments: append: simple: 'true' key: simple: FilterPenteraOperations stringify: {} value: complex: root: FilteredBySeverity filters: - - operator: containsString left: value: simple: FilteredBySeverity.Operation Type iscontext: true right: value: simple: CVE-2019-0708 ignorecase: true separatecontext: false view: "{\n \"position\": {\n \"x\": 162.5,\n \"y\": 1330\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '22': id: '22' taskid: 9633a8b1-efb1-4750-8d67-c9c102caf026 type: condition task: id: 9633a8b1-efb1-4750-8d67-c9c102caf026 version: -1 name: Is Pentera Operations not empty? type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '8' 'yes': - '26' separatecontext: false conditions: - label: 'yes' condition: - - operator: isNotEmpty left: value: simple: FilterPenteraOperations iscontext: true view: "{\n \"position\": {\n \"x\": 1050,\n \"y\": 1640\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '24': id: '24' taskid: 9e73be18-14ab-43e2-87f2-6803f907f992 type: regular task: id: 9e73be18-14ab-43e2-87f2-6803f907f992 version: -1 name: FilterOpenShares description: Checks if the specified value exists in context. If the value exists, it will be set in context, otherwise no value will be set in context. scriptName: SetAndHandleEmpty type: regular iscommand: false brand: '' nexttasks: '#none#': - '22' scriptarguments: append: simple: 'true' key: simple: FilterPenteraOperations stringify: {} value: complex: root: FilteredBySeverity filters: - - operator: containsString left: value: simple: FilteredBySeverity.Operation Type iscontext: true right: value: simple: Ability to access an open share ignorecase: true separatecontext: false view: "{\n \"position\": {\n \"x\": 1962.5,\n \"y\": 1330\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '25': id: '25' taskid: 7d3b5789-9dce-49a5-8232-47040ef4e08b type: condition task: id: 7d3b5789-9dce-49a5-8232-47040ef4e08b version: -1 name: Are we filtering open shares type: condition iscommand: false brand: '' description: '' nexttasks: '#default#': - '8' 'yes': - '24' separatecontext: false conditions: - label: 'yes' condition: - - operator: isEqualString left: value: simple: 'inputs.Filter open shares ' iscontext: true right: value: simple: 'True' ignorecase: true view: "{\n \"position\": {\n \"x\": 1850,\n \"y\": 1155\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 '26': id: '26' taskid: 2466a731-6e00-4f30-8a8b-6079bd4d92ed type: regular task: id: 2466a731-6e00-4f30-8a8b-6079bd4d92ed version: -1 name: Pentera Group Incidents scriptName: PenteraOperationToIncident type: regular iscommand: false brand: '' description: '' nexttasks: '#none#': - '18' scriptarguments: context_key: {} custom_fields_output: simple: penteraoperationdetails full_action_report: complex: root: FilterPenteraOperations separatecontext: false view: "{\n \"position\": {\n \"x\": 1050,\n \"y\": 1860\n }\n}" note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 view: "{\n \"linkLabelsPosition\": {},\n \"paper\": {\n \"dimensions\": {\n \ \ \"height\": 2295,\n \"width\": 2592.5,\n \"x\": -250,\n \"\ y\": 50\n }\n }\n}" inputs: - key: Filter password cracking value: simple: 'True' required: true description: Filter all password cracking operation types playbookInputQuery: - key: Filter BlueKeep vulnerability value: simple: 'True' required: true description: Filter all BlueKeep operation types playbookInputQuery: - key: Filter Minimum Severity value: simple: '0' required: true description: "Filters actions according to given value. \nWill not filter anything\ \ if got zero (0) as value." playbookInputQuery: - key: FullActionReport value: {} required: true description: "Pentera Full Action Report is the summary of the given TaskName in\ \ a CSV format, that contains all the actions that Pentera performed during the\ \ task run. \nThe value will be provided from Pentera Run Scan and Create Incidents\ \ playbook." playbookInputQuery: - key: Filter MS17-010 vulnerability value: simple: 'True' required: true description: Filter all MS17-010 operation types playbookInputQuery: - key: Filter network device default password usage value: simple: 'True' required: true description: Filter all network device default password operation types playbookInputQuery: - key: 'Filter open shares ' value: simple: 'True' required: true description: Filter all open shares operation types playbookInputQuery: outputs: [] fromversion: 5.0.0 tests: - No tests (auto formatted)