TIM - Run Enrichment For Url Indicators

This playbook processes indicators by enriching indicators based on the indicator feed's reputation, as specified in the playbook inputs. This playbook needs to be used with caution as it might use up the user enrichment integration's API license when running enrichment for large amounts of indicators.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

  • Malwr
  • aws
  • Mimecast
  • KeyLight
  • AzureSecurityCenter_v2
  • SlashNextPhishingIncidentResponse
  • Panorama
  • RiskSense
  • SecurityAdvisor
  • Shodan
  • AlienVaultOTX
  • SymantecEndpointProtectionDeprecated
  • PaloAltoNetworksCortex
  • PaloAlto_MineMeld
  • Intezer
  • ExtraHop
  • jira
  • Cylance_Protect
  • AzureSecurityCenter
  • MISP
  • CveInfo
  • PhishMe
  • DemistoRESTAPI
  • Flashpoint
  • opswat-metadefender
  • Mimecast-Auth
  • Lastline
  • Pwned
  • Kenna
  • ArcSightESM
  • PaloAltoNetworks_Traps
  • LightCyberMagna
  • Wildfire
  • ProofpointTAP

Scripts

This playbook does not use any scripts.

Commands

  • url

Playbook Inputs


NameDescriptionDefault ValueRequired
Indicator QueryIndicators matching the indicator query will be used as playbook inputOptional
EnrichBadIndicatorsEnter a value of True to enrich indicators whose reputation from the feed is bad.Optional
EnrichGoodIndicatorsEnter a value of True to enrich indicators whose reputation from the feed is good.Optional
EnrichSuspiciousIndicatorsEnter a value of True to enrich indicators whose reputation from the feed is suspicious.Optional
EnrichUnknownIndicatorsEnter a value of True to enrich indicators whose reputation from the feed is unknown.Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Playbook Image