Search Endpoints By Hash - CrowdStrike
#
This Playbook is part of the FalconHost (Deprecated) Pack.Deprecated
Use CrowdStrike Falcon instead.
Hunts for endpoint activity involving hash and domain IOCs, using Crowdstrike Falcon Host.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- FalconHost
#
ScriptsThis playbook does not use any scripts.
#
Commands- cs-device-details
- cs-device-ran-on
#
Playbook InputsName | Description | Default Value | Source | Required |
---|---|---|---|---|
MD5Hash | The MD5 file hash. | MD5 | File | Optional |
SHA1Hash | The SHA1 file hash. | SHA1 | File | Optional |
SHA256Hash | The SHA256 file hash. | SHA256 | File | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
Endpoint.Hostname | The device hostname. | string |
Endpoint | The endpoint. | unknown |