HarfangLab EDR Pack.#This Playbook is part of the
Supported Cortex XSOAR versions: 6.2.0 and later.
This playbook allows is triggered by the Hurukai - Process Indicators - Manual Review playbook. It allows to search for IOC sightings in the HarfangLab EDR and tag sighted IOCs accordingly for manual review. All IOCs are tagged in order to be further inserted into a HarfangLab EDR IOC source.
This playbook uses the following sub-playbooks, integrations, and scripts.
This playbook does not use any sub-playbooks.
|Indicators matching the indicator query will be used as playbook input
|Indicators that are associated to EDR sightings and need reviewing.