TIM - Process Indicators Against Business Partners IP List

This playbook processes indicators to check if they exist in a Cortex XSOAR list containing business partner IP addresses, and tags the indicators accordingly.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

  • FilterByList
  • SetAndHandleEmpty

Commands

  • appendIndicatorField

Playbook Inputs


NameDescriptionDefault ValueRequired
Indicator QueryIndicators matching the indicator query will be used as playbook inputtype:ipOptional
BusinessPartnersIPListNameA Cortex XSOAR list containing business partner IP address values. IP Indicators that appear in the list are tagged as business partner ip.Optional

Playbook Outputs


PathDescriptionType
BusinessPartnerIPIP addresses that are found in the business partner ip list.string
NotBusinessPartnerIPIP addresses that are not found in the business partner ip list.string

Playbook Image


Playbook Image