ACTI Block High Severity Indicators
Accenture CTI v2 Pack.#
This Playbook is part of theDeprecated
No available replacement.
- NOTE: This playbook is deprecated.
- Sends indicators imported from ACTI feeds with a severity rating of 5 or higher to your firewall to be blocked.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Block IP - Generic v2
- Block Domain - Generic
- Block URL - Generic
#
IntegrationsThis playbook does not use any integrations.
#
ScriptsThis playbook does not use any scripts.
#
CommandsThis playbook does not use any commands.
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
IP | Considers IP(s) which have severity 5 or more | ${DBotScore.Indicator} | Optional |
URL | Considers URL(s) which have severity 5 or more | ${DBotScore.Indicator} | Optional |
Domain | Considers Domain(s) which have severity 5 or more | ${DBotScore.Indicator} | Optional |
#
Playbook OutputsThere are no outputs for this playbook.