TIM - Indicator Relationships Analysis
TIM - Indicator Auto-Processing Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.8.0 and later.
This playbook is designed to assist with a security investigation by providing an analysis of indicator relationships. The following information is included:
- Indicators of compromise (IOCs) related to the investigation.
- Attack patterns related to the investigation.
- Campaigns related to the investigation.
- IOCs associated with the identified campaigns.
- Reports containing details on the identified campaigns.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
IntegrationsThis playbook does not use any integrations.
#
Scripts- Set
- SearchIndicatorRelationships
#
CommandsThis playbook does not use any commands.
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Indicator | Input an indicator to analyze its relationships. | Optional | |
LimitResults | The number of results to return. If the input is empty, the limit will be 20. | 200 | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
RelatedAttackPatterns | Attack patterns related to the indicator. | unknown |
RelatedCampaign | Campaign related to the indicator. | unknown |
RelatedReport | Report related to the campaign. | unknown |
RelatedFiles | Files related to the indicator and campaign. | unknown |
RelatedDomains | Domains related to the indicator and campaign. | unknown |
RelatedIPs | IPs related to the indicator and campaign. | unknown |
RelatedURLs | URLs related to the indicator and campaign. | unknown |