Skip to main content

PAN-OS Search for Post Quantum Crypto Vuln Sigs

This Playbook is part of the Post Quantum Crypto Hunting by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.8.0 and later.

Search Vuln Sigs in Threat Logs for use of Post Quantum Crypto Signatures

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Mail Sender (New)
  • Cortex Data Lake
  • PAN-OS

Scripts#

  • Print
  • PrettyPrint

Commands#

  • pan-os-query-logs
  • cdl-query-threat-logs
  • closeInvestigation
  • send-mail

Playbook Inputs#


NameDescriptionDefault ValueRequired
notify_emailSend email notification for new malwareNoneOptional
log_sourcewhere should we poll for Log Events to investigate
panos
cdl
siem
cdlOptional
threat_idsthreat ID to search for as CSV list93486,93487,93488,93489,93490,93492,93494,93496,93497,93498,93499,93500,93501,93502,93503,93504,93505,93506,93507Optional
time_range_hourshow many hours back to query for events in hours24Optional
num_logshow many logs to bring back100Optional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


PAN-OS Search for Post Quantum Crypto Vuln Sigs