Skip to main content

Proactive Threat Hunting - Execute Query

This Playbook is part of the Proactive Threat Hunting Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.9.0 and later.

This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of executing a query that will be provided by the analyst. The playbook supports executing a query using the following integrations:

  • Cortex XDR XQL Engine
  • Microsoft Defender For Endpoint


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


This playbook does not use any integrations.


  • JsonToTable
  • Print
  • DeleteContext


  • xdr-xql-generic-query
  • setIncident
  • microsoft-atp-advanced-hunting

Playbook Inputs#

There are no inputs for this playbook.

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Proactive Threat Hunting - Execute Query