CrowdStrike Rapid IOC Hunting v2
#
This Playbook is part of the FalconHost (Deprecated) Pack.Deprecated
Use CrowdStrike Falcon instead.
Hunt for endpoint activity involving hash and domain IOCs using Crowdstrike Falcon Host.\nAlso use AnalystEmail label to determine where to send an email alert if something is found.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- FalconHost
#
Scripts- Exists
#
Commands- cs-device-search
- cs-device-ran-on
- send-mail
#
Playbook InputsThere are no inputs for this playbook.
#
Playbook OutputsThere are no outputs for this playbook.