Skip to main content

Social Engineering Domain Investigation

This Playbook is part of the Social Engineering Domain Analysis Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.2.0 and later.

Enrich and Investigate domains which may present a social engineering threat to your organization. Review before blocking potentially dangerous indicators.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • Social Engineering Domain Enrichment

Integrations#

This playbook does not use any integrations.

Scripts#

  • ConvertTableToHTML

Commands#

  • setIndicator
  • extractIndicators

Playbook Inputs#


NameDescriptionDefault ValueRequired
SocialEngineeringDomainListThe CSV list of domains to test or array of domains${incident.socialengineeringdomainanalysislist}Optional
SocialEngineeringRegisteredDomainYour company domain${incident.socialengineeringdomainanalysisregistereddomain}Optional
BadNameserversAn XSOAR BadNameserver list. This should be a CSV list with a single column and the header of "nameserver"

Example List Contents:

nameserver
badnameserver1.com
badnameserver2.com
Optional

Playbook Outputs#


There are no outputs for this playbook.