Investigate On Bad Domain Matches - Chronicle
Chronicle Pack.#
This Playbook is part of theUse this playbook to investigate and remediate Bad IOC domain matches with recent activity found in the enterprise, as well as notify the SOC lead and network team about the matches. Supported Integrations:
- Chronicle
- Whois
- Mail Sender (New)
- Palo Alto Networks PAN-OS
- Palo Alto Networks AutoFocus v2
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Chronicle
- Whois
- Mail Sender (New)
- Palo Alto Networks PAN-OS
- Palo Alto Networks AutoFocus v2
#
Scripts- AssignAnalystToIncident
- GenerateInvestigationSummaryReport
#
Commands- domain
- gcb-ioc-details
- send-mail
- whois
- panorama-register-user-tag
- gcb-assets
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
networkteam_email | Enter the email address of the network team that needs to be notified. | Optional | |
stakeholder_email | Enter the email of the stakeholder to whom you want to send the investigation summary report. | Optional |
#
Playbook OutputsThere are no outputs for this playbook.