TIM - Process Indicators Against Business Partners IP List
TIM - Indicator Auto-Processing Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 5.5.0 and later.
This playbook processes indicators to check if they exist in a Cortex XSOAR list containing business partner IP addresses, and tags the indicators accordingly.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
IntegrationsThis playbook does not use any integrations.
#
Scripts- FilterByList
- SetAndHandleEmpty
#
Commands- appendIndicatorField
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Indicator Query | Indicators matching the indicator query will be used as playbook input | type:ip | Optional |
BusinessPartnersIPListName | A Cortex XSOAR list containing business partner IP address values. IP Indicators that appear in the list are tagged as business partner ip. | Optional |
#
Playbook OutputsPath | Description | Type |
---|---|---|
BusinessPartnerIP | IP addresses that are found in the business partner ip list. | string |
NotBusinessPartnerIP | IP addresses that are not found in the business partner ip list. | string |