Hurukai - Add indicators to HarfangLab EDR
HarfangLab EDR Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.2.0 and later.
This playbook add indicators to a HarfangLab EDR IOC source list for detection and/or blocking.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Hurukai
#
ScriptsThis playbook does not use any scripts.
#
Commands- harfanglab-add-ioc-to-source
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Indicator Query | Indicators matching the indicator query will be used as playbook input | type:file -tags:pending_review and (tags:to_edr_blocklist or tags:approved_white or tags:approved_watchlist) and expirationStatus:active | Optional |
#
Playbook OutputsThere are no outputs for this playbook.