Recorded Future Detailed Alert example

Detailed alert example for Recorded Future.

This playbook is intended as guidance for how the command recordedfuture-single-alert can be used in playbooks.

The single alert takes an alert id which can be retrieved from recordedfuture-alerts. If a specific alert rule is desired you can first fetch alert rules and input the alert rule id into reccordedfuture-alerts.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts. Depends on the recorded futures indicator field; risk rules.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Recorded Future v2

Scripts#

This playbook does not use any scripts.

Commands#

  • recordedfuture-alerts
  • recordedfuture-single-alert

Playbook Inputs#


NameDescriptionDefault ValueRequired
freetextFreetext to search for specific alertDomain.Namerequired

Playbook Outputs#

There are no outputs for this playbook.#

PathDescriptionType
DBotScore.IndicatorThe indicator that was testedstring
DBotScore.TypeIndicator typestring
DBotScore.VendorVendor used to calculate the scorestring
DBotScore.ScoreThe actual scorenumber

Playbook Image#


Recorded Future Domain Intelligence