Skip to main content

Cortex ASM - Extract IP Indicator

This Playbook is part of the Cortex Attack Surface Management Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

Playbook to Extract IP indicators from ASM alerts and associate indicators with the alert#

This playbook aims to extract the related IP address from ASM alert data and associated the newly created indicator with the alert.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

There are no sub-playbooks for this playbook.

Integrations#

There are no integrations for this playbook.

Scripts#

There are no scripts for this playbook.

Commands#

  • extractIndicators
  • createNewIndicator
  • associateIndicatorToAlert

Playbook Inputs#


NameDescriptionDefault ValueRequired
AlertNameThe formatted name of the alertOptional

Playbook Outputs#


NameDescription
ExtractedIndicatorsoutputs.extractindicators

Playbook Image#


Cortex ASM - Extract IP Indicator