Skip to main content

Darkmon - Block IOC

This Playbook is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

Analyst-facing wrapper around Darkmon - Generic Block Indicator. Lets analysts paste an IOC into a War Room form and trigger a provider-routed block action.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • Dispatch block via provider switchboard
  • Notify SOC of manual block

Integrations#

This playbook does not use any integrations.

Scripts#

This playbook does not use any scripts.

Commands#

This playbook does not use any commands.

Playbook Inputs#


NameDescriptionDefault ValueRequired
IndicatorThe indicator value to block.Required
Typeip | domain | url.ipOptional
ReasonReason annotated on the block rule.Manual analyst-triggered blockOptional

Playbook Outputs#


There are no outputs for this playbook.