Search Endpoints By Hash - Carbon Black Protection
Carbon Black Enterprise Protection Pack.#
This Playbook is part of theHunts for endpoint activity involving hash IOCs, using Carbon Black Protection.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- carbonblackprotection
#
Scripts- CBPCatalogFindHash
- Exists
- CBPFindRule
- Set
#
Commands- cbp-computer-get
#
Playbook InputsName | Description | Default Value | Source | Required |
---|---|---|---|---|
Hash | The MD5 file Hash to hunt for. | MD5 | File | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
Endpoint.Hostname | The device hostname. | string |
Endpoint | The endpoint. | unknown |