{ "id": "Malware Use Case Adoption Wizard", "version": -1, "modified": "2022-07-10T11:55:54.250933+03:00", "fromVersion": "6.8.0", "toVersion": "6.8.9", "name": "Malware Use Case Adoption Wizard", "description": "Welcome to the Deployment Wizard! These steps will guide you through configuring your content pack so you'll have a working use case when the wizard finishes. Make sure to follow the steps in order, you can always continue the wizard where you left off. Learn more about this pack’s deployment.", "dependency_packs": [ { "name": "Endpoint Detection & Response", "min_required": 1, "packs": [ { "name": "CrowdStrikeFalcon", "display_name": "CrowdStrike Falcon" }, { "name": "MicrosoftDefenderAdvancedThreatProtection", "display_name": "Microsoft Defender for Endpoint" }, { "name": "CortexXDR", "display_name": "Palo Alto Networks Cortex XDR - Investigation and Response" } ] }, { "name": "Sandbox", "min_required": 0, "packs": [ { "name": "Palo_Alto_Networks_WildFire", "display_name": "Palo Alto Networks WildFire" }, { "name": "CrowdStrikeFalconX", "display_name": "CrowdStrike Falcon X" }, { "name": "JoeSecurity", "display_name": "Joe Security" } ] }, { "name": "Messaging", "min_required": 0, "packs": [ { "name": "MicrosoftExchangeOnPremise", "display_name": "Microsoft Exchange On-Premise" }, { "name": "Gmail", "display_name": "Gmail" }, { "name": "MicrosoftGraphMail", "display_name": "Microsoft Graph Mail" } ] }, { "name": "Case Management", "min_required": 0, "packs": [ { "name": "Jira", "display_name": "Atlassian Jira v2" }, { "name": "ServiceNow", "display_name": "ServiceNow v2" } ] }, { "name": "Data Enrichment & Threat Intelligence", "min_required": 0, "packs": [ { "name": "AutoFocus", "display_name": "Palo Alto Networks AutoFocus" }, { "name": "VirusTotal", "display_name": "VirusTotal" }, { "name": "FeedMitreAttackv2", "display_name": "Mitre Attack v2" } ] } ], "wizard": { "fetching_integrations": [ { "priority": 3, "name": "Microsoft Defender Advanced Threat Protection", "action": { "existing": "Update your current instance to work with the new Malware Investigation and Response incident type: \n1. Enable fetching. \n2. Set the Incident type field to Malware Investigation and Response. \n3. Set the Mapper field to 'Microsoft Defender For Endpoint Mapper'. \n4. Check the 'Fetch alert evidence' option.", "new": "Set up a new 'Microsoft Defender Advanced Threat Protection' instance to start fetching Malware Investigation and Response incidents: \n1. Enable fetching. \n2. Set the Incident type field to Malware Investigation and Response. \n3. Set the Mapper field to 'Microsoft Defender For Endpoint Mapper'. \n4. Check the 'Fetch alert evidence' option." }, "description": "Set up the 'Microsoft Defender for Endpoint' integration to work with your Malware Investigation and Response use case." }, { "priority": 2, "name": "CrowdstrikeFalcon", "action": { "existing": "Update your current instance to work with the new Malware incident type: \n1. Enable fetching. \n2. Remove the default Classifier. \n3. Set the Incident type field to Malware Investigation and Response. \n4. Set the Mapper field to 'CrowdStrike Falcon Mapper'.", "new": "Set up a new 'Crowdstrike Falcon' instance to start fetching Malware Investigation and Response incidents: \n1. Enable fetching.\n2. Remove the default Classifier. \n3. Set the Incident type field to Malware Investigation and Response. \n4. Set the Mapper field to 'CrowdStrike Falcon Mapper'." }, "description": "Set up the 'Crowdstrike Falcon' integration to work with your Malware Investigation and Response use case." }, { "priority": 1, "name": "Cortex XDR - IR", "action": { "existing": "Update your current instance to work with the new Malware Investigation and Response incident type: \n1. Enable fetching. \n2. Set the 'Cortex XDR Incident Handler - Classifier'.\n3. Set the Incident type field to Malware Investigation and Response. \n4. Set the Mapper field to 'XDR - Incoming Mapper'.", "new": "Set up a new 'Cortex XDR - IR' instance to work with the Malware Investigation and Response incident type: \n1. Enable fetching. \n2. Choose the 'Cortex XDR Incident Handler - Classifier .\n3. Set the Incident type field to Malware Investigation and Response. \n4. Set the Mapper field to 'XDR - Incoming Mapper'." }, "description": "Set up the 'Cortex XDR - IR' integration to work with your Malware Investigation and Response use case." } ], "set_playbook": [ { "name": "Malware Investigation & Response Incident Handler" } ], "supporting_integrations": [ { "name": "WildFire-v2", "action": { "existing": "Configure 'Wildfire' to enable file detonation to improve investigation.", "new": "Configure 'Wildfire' to enable file detonation to improve investigation." }, "description": "Configure Wildfire to enable file detonation to improve investigation." }, { "name": "CrowdStrike Falcon X", "action": { "existing": "Configure 'CrowdStrike Falcon X' to enable file detonation to improve investigation.", "new": "Configure 'CrowdStrike Falcon X' to enable file detonation to improve investigation." }, "description": "Configure 'CrowdStrike Falcon X' to enable file detonation to improve investigation." }, { "name": "JoeSecurityV2", "action": { "existing": "Configure 'Joe Security V2' to enable file detonation to improve investigation.", "new": "Configure 'Joe Security V2' to enable file detonation to improve investigation." }, "description": "Configure 'Joe Security V2' to enable file detonation to improve investigation." }, { "name": "EWS Mail Sender", "action": { "existing": "Configure 'EWS Mail Sender' to enable email notifications.", "new": "Configure 'EWS Mail Sender' to enable email notifications." }, "description": "Configure 'EWS Mail Sender' to enable email notifications." }, { "name": "Gmail", "action": { "existing": "Configure 'Gmail' to enable email notifications.", "new": "Configure 'Gmail' to enable email notifications." }, "description": "Configure 'Gmail' to enable email notifications." }, { "name": "MicrosoftGraphMail", "action": { "existing": "Configure 'Microsoft Graph Mail' to enable email notifications.", "new": "Configure 'Microsoft Graph Mail' to enable email notifications." }, "description": "Configure 'Microsoft Graph Mail' to enable email notifications." }, { "name": "ServiceNow v2", "action": { "existing": "Configure 'ServiceNow v2' to open a ticket for a true positive incident.", "new": "Configure 'ServiceNow v2' to open a ticket for a true positive incident." }, "description": "Configure 'ServiceNow v2' to open a ticket for a true positive incident." }, { "name": "jira-v2", "action": { "existing": "Configure 'jira-v2' to open a ticket for a true positive incident.", "new": "Configure 'jira-v2' to open a ticket for a true positive incident." }, "description": "Configure 'jira-v2' to open a ticket for a true positive incident." }, { "name": "AutoFocus V2", "action": { "existing": "Configure 'AutoFocus v2' to enrich IOCs as part of the investigation.", "new": "Configure 'AutoFocus v2' to enrich IOCs as part of the investigation." }, "description": "Configure 'AutoFocus v2' to enrich IOCs as part of the investigation." }, { "name": "VirusTotal (API v3)", "action": { "existing": "Configure 'VirusTotal (API v3)' to enrich IOCs as part of the investigation.", "new": "Configure 'VirusTotal (API v3)' to enrich IOCs as part of the investigation." }, "description": "Configure 'VirusTotal (API v3)' to enrich IOCs as part of the investigation." }, { "name": "MITRE ATT&CK v2", "action": { "existing": "Configure 'MITRE ATT&CK v2' to enrich IOCs as part of the investigation.", "new": "Configure 'MITRE ATT&CK v2' to enrich IOCs as part of the investigation." }, "description": "Configure 'MITRE ATT&CK v2' to enrich IOCs as part of the investigation." } ], "next": [ { "name": "Enable Your Use Case", "action": { "existing": "Enable the fetching integrations to start ingesting data and run the playbook.", "new": "Enable the fetching integrations to start ingesting data and run the playbook." } } ] } }