Skip to main content

MDE - Host Advanced Hunting For Persistence

This Playbook is part of the Microsoft Defender for Endpoint Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

This playbook uses the Microsoft Defender For Endpoint Advanced Hunting feature to hunt for host persistence evidence.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

MicrosoftDefenderAdvancedThreatProtection

Scripts#

This playbook does not use any scripts.

Commands#

  • microsoft-atp-advanced-hunting-persistence-evidence
  • setIncident

Playbook Inputs#


NameDescriptionDefault ValueRequired
FileSha256A comma-separated list of file SHA256 hashes to hunt.incident.filesha256Optional
FileSha1A comma-separated list of file SHA1 hashes to hunt.incident.filesha1Optional
FileMd5A comma-separated list of file MD5 hashes to hunt.incident.filemd5Optional
IPA comma-separated list of IPs to hunt.incident.detectedipsOptional
DeviceNameA comma-separated list of host names to hunt.incident.hostnamesOptional
FileNameA comma-separated list of file names to hunt.incident.filenamesOptional
DeviceIDA comma-separated list of a device IDs to hunt.incident.agentsidOptional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


MDE - Host Advanced Hunting For Persistence