--- title: "Email Notification for Malware" last_modified_at: 2021-01-19 toc: true toc_label: "" tags: - Response - Splunk SOAR - VirusTotal - WildFire - CarbonBlack Response - SMTP --- [Try in Splunk SOAR](https://www.splunk.com/en_us/software/splunk-security-orchestration-and-automation.html){: .btn .btn--success} #### Description This playbook tries to determine if a file is malware and whether or not the file is present on any managed machines. VirusTotal "file reputation" and PAN WildFire "detonate file" are used to determine if a file is malware, and CarbonBlack Response "hunt file" is used to search managed machines for the file. The results of these investigations are summarized in an email to the incident response team. - **Type**: Response - **Product**: Splunk SOAR - **Apps**: [VirusTotal](https://splunkbase.splunk.com/apps/#/search/VirusTotal/product/soar), [WildFire](https://splunkbase.splunk.com/apps/#/search/WildFire/product/soar), [CarbonBlack Response](https://splunkbase.splunk.com/apps/#/search/CarbonBlack Response/product/soar), [SMTP](https://splunkbase.splunk.com/apps/#/search/SMTP/product/soar) - **Last Updated**: 2021-01-19 - **Author**: Philip Royer, Splunk - **ID**: fb3edc76-ff2b-48b0-5f6f-63da6483fd63 #### Associated Detections #### How To Implement Be sure to update asset naming to reflect the asset names configured in your environment. #### Playbooks ![](https://raw.githubusercontent.com/splunk/security_content/develop/playbooks/email_notification_for_malware.png) #### Required field * fileHash * vaultId #### Reference [*source*](https://github.com/splunk/security_content/tree/develop/playbooks/email_notification_for_malware.yml) \| *version*: **1**