Recorded Future - Threat Actor Search
Recorded Future Intelligence Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.9.0 and later.
Template playbook to initiate an Automated Threat Hunt based on the Threat Map in Recorded Future. The Playbook fetches links related to the Threat Actors part of the Threat Map from Recorded Future and launches a hunt in the SIEM for any detections within the environment.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- QRadar Indicator Hunting V2
- Splunk Indicator Hunting
#
Integrations- RecordedFuture
- Recorded Future v2
#
ScriptsThis playbook does not use any scripts.
#
Commands- recordedfuture-detection-rules
- recordedfuture-threat-links
- recordedfuture-threat-map
- extractIndicators
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
threat_actor | The threat actor to enrich & hunt indicators for. | Optional |
#
Playbook OutputsThere are no outputs for this playbook.