Recorded Future IP Reputation
Recorded Future Intelligence Pack.#This Playbook is part of the
IP address reputation using Recorded Future SOAR Enrichment
This playbook uses the following sub-playbooks, integrations, and scripts. Depends on the recorded futures indicator field; risk rules.
This playbook does not use any sub-playbooks.
- Recorded Future v2
This playbook does not use any scripts.
|IP||The IP address to get reputation of.||IP.Address||Optional|
|DBotScore.Indicator||The indicator that was tested||string|
|DBotScore.Vendor||Vendor used to calculate the score||string|
|DBotScore.Score||The actual score||number|
|IP.Malicious.Vendor||For malicious IP addresses, the vendor that made the decision||string|
|IP.Malicious.Description||For malicious IP addresses, the reason that the vendor made the decision||string|
|RecordedFuture.IP.riskScore||Recorded Future IP Risk Score||number|
|RecordedFuture.IP.riskLevel||Recorded Future IP Risk Level||string|
|RecordedFuture.IP.Evidence.rule||Recorded Risk Rule Name||string|
|RecordedFuture.IP.Evidence.mitigation||Recorded Risk Rule Mitigation||string|
|RecordedFuture.IP.Evidence.description||Recorded Risk Rule Description||string|
|RecordedFuture.IP.Evidence.timestamp||Recorded Risk Rule Timestamp||date|
|RecordedFuture.IP.Evidence.level||Recorded Risk Rule Level||number|
|RecordedFuture.IP.Evidence.ruleid||Recorded Risk Rule ID||string|
|RecordedFuture.IP.maxRules||Maximum count of Recorded Future IP Risk Rules||number|
|RecordedFuture.IP.ruleCount||Number of triggered Recorded Future IP Risk Rules||number|