Skip to main content

TIM - Run Enrichment For Hash Indicators

This Playbook is part of the TIM - Indicator Auto-Processing Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This playbook processes indicators by enriching indicators based on the indicator feed's reputation, as specified in the playbook inputs. This playbook needs to be used with caution as it might use up the user enrichment integration's API license when running enrichment for large amounts of indicators.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

This playbook does not use any integrations.

Scripts#

This playbook does not use any scripts.

Commands#

  • enrichIndicators

Playbook Inputs#


NameDescriptionDefault ValueRequired
Indicator QueryIndicators matching the indicator query will be used as playbook inputOptional
EnrichBadIndicatorsEnter a value of true to enrich indicators whose reputation from the feed is bad.Optional
EnrichGoodIndicatorsEnter a value of true to enrich indicators whose reputation from the feed is good.Optional
EnrichSuspiciousIndicatorsEnter a value of true to enrich indicators whose reputation from the feed is suspicious.Optional
EnrichUnknownIndicatorsEnter a value of true to enrich indicators whose reputation from the feed is unknown.Optional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


TIM - Run Enrichment For Hash Indicators