Social Engineering Domain Investigation
Social Engineering Domain Analysis Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.2.0 and later.
Enrich and Investigate domains which may present a social engineering threat to your organization. Review before blocking potentially dangerous indicators.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooks- Social Engineering Domain Enrichment
#
IntegrationsThis playbook does not use any integrations.
#
Scripts- ConvertTableToHTML
#
Commands- setIndicator
- extractIndicators
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
SocialEngineeringDomainList | The CSV list of domains to test or array of domains | ${incident.socialengineeringdomainanalysislist} | Optional |
SocialEngineeringRegisteredDomain | Your company domain | ${incident.socialengineeringdomainanalysisregistereddomain} | Optional |
BadNameservers | An XSOAR BadNameserver list. This should be a CSV list with a single column and the header of "nameserver" Example List Contents: nameserver badnameserver1.com badnameserver2.com | Optional |
#
Playbook OutputsThere are no outputs for this playbook.