Skip to main content

PhishLabs - Populate Indicators

This Playbook is part of the PhishLabs Pack.#

Populates indicators from PhishLabs, according to a defined period of time.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Builtin

Scripts#

  • PhishLabsPopulateIndicators

Commands#

  • closeInvestigation

Playbook Inputs#


NameDescriptionDefault ValueRequired
SinceGet indicators within this duration (from now).1hOptional
LimitThe maximum number of indicators.-Optional
Remove protocolRemoves the protocol part from indicators, when the rule can be applied.falseOptional
Remove queryRemoves the query string part from indicators, when the rules can be applied.falseOptional
Indicator typeThe filter of the indicators by indicator type.-Optional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


PhishLabsPopulateIndicators