Hurukai - Hunt IOCs

This Playbook is part of the HarfangLab EDR Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.2.0 and later.

This playbook allows is triggered by the Hurukai - Process Indicators - Manual Review playbook. It allows to search for IOC sightings in the HarfangLab EDR and tag sighted IOCs accordingly for manual review. All IOCs are tagged in order to be further inserted into a HarfangLab EDR IOC source.


This playbook uses the following sub-playbooks, integrations, and scripts.


  • Hurukai


  • SetAndHandleEmpty


  • appendIndicatorField
  • harfanglab-hunt-search-hash

Playbook Inputs#

NameDescriptionDefault ValueRequired
Indicator QueryIndicators matching the indicator query will be used as playbook inputOptional

Playbook Outputs#

ProcessedIndicatorsIndicators that are associated to EDR sightings and need reviewing.unknown

