Detailed alert example for Recorded Future.
This playbook is intended as guidance for how the command
recordedfuture-single-alert can be used in playbooks.
The single alert takes an alert id which can be retrieved from recordedfuture-alerts. If a specific alert rule is desired you can first fetch alert rules and input the alert rule id into
This playbook uses the following sub-playbooks, integrations, and scripts. Depends on the recorded futures indicator field; risk rules.
This playbook does not use any sub-playbooks.
- Recorded Future v2
This playbook does not use any scripts.
|freetext||Freetext to search for specific alert||Domain.Name||required|
|DBotScore.Indicator||The indicator that was tested||string|
|DBotScore.Vendor||Vendor used to calculate the score||string|
|DBotScore.Score||The actual score||number|