{ "blockly": false, "blockly_xml": "", "category": "Use Cases", "misc": { "apps_list": ["Palo Alto Networks Firewall", "Carbon Black Response", "OpenDNS Umbrella", "Phantom"] }, "coa": { "data": { "clean": true, "code_block": "", "description": "This playbook retrieves IP addresses, domains, and file hashes, blocks them on various services, and adds them to specific blocklists as custom lists.", "hash": "753b457bfed5fa341dd36803c11b681681df46f6", "joint": { "cells": [ { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "70140aee-e625-43c7-bf11-da4d1bc729c1", "router": { "name": "metro" }, "source": { "id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "81b07a3a-01ac-4d3a-b254-9cb7a3e97392", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 27 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "8f7b00cd-6206-4e1f-a1fd-c17ca7df99d1", "router": { "name": "metro" }, "source": { "id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "d230871e-ee71-44a6-af7f-fb4f2f584da4", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 43 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "d333fcd2-eb73-4914-8e92-ad8551a6b068", "router": { "name": "metro" }, "source": { "id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "ea4b2594-8ef5-42a4-8285-125126536531", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 66 }, { "0": "S", "1": "T", "2": "A", "3": "R", "4": "T", "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".color-band": { "fill": "#3C444D" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "ref-x": 33, "ref-y": 8, "text": "START" }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.icon image": { "ref-x": 13, "xlink:href": "/inc/coa/img/block_icon_start.svg" }, "g.notes": { "display": "block" } }, "block_code": "def on_start(container):\n phantom.debug('on_start() called')\n \n # call 'filter_1' block\n filter_1(container=container)\n\n # call 'filter_2' block\n filter_2(container=container)\n\n # call 'filter_3' block\n filter_3(container=container)\n\n return", "callback_code": "# read-only block view not available", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a", "inPorts": [], "join_code": "# read-only block view not available", "join_optional": [], "join_start": 1, "line_end": 22, "line_start": 8, "name": "", "notes": "", "number": 0, "order": 1, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 180, "y": 40 }, "previous_function": "", "previous_name": "", "show_number": true, "size": { "height": 54, "width": 80 }, "status": "", "title": "START", "type": "coa.StartEnd", "warn": false, "z": 95 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "f157b9dd-877a-4fbe-94c7-7709af7c1ceb", "router": { "name": "metro" }, "source": { "id": "81b07a3a-01ac-4d3a-b254-9cb7a3e97392", "port": "out-1", "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "9537d314-97d6-484b-ae20-3d9564bab6d6", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 160 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "98116e8f-35f5-4a4d-b09d-f2f254b3f36a", "router": { "name": "metro" }, "source": { "id": "9537d314-97d6-484b-ae20-3d9564bab6d6", "port": "out-1", "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "7a912b77-6a81-421d-b6f5-d865b3fffd73", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 177 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "ea7e5f03-8b63-43f5-a2cb-1adf63b89c88", "router": { "name": "metro" }, "source": { "id": "7a912b77-6a81-421d-b6f5-d865b3fffd73", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "08306503-f5d1-4cd0-b32b-90a7670ff1ca", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 190 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "429dcfde-c34b-40f8-9b0b-9614e6f0cb75", "router": { "name": "metro" }, "source": { "id": "08306503-f5d1-4cd0-b32b-90a7670ff1ca", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "7d6e7306-cd84-4798-bb84-804b79fb09ef", "port": null, "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" }, "type": "link", "z": 250 }, { "0": "E", "1": "N", "2": "D", "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".title": { "text": "END" }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_end.svg" }, "g.notes": { "display": "block" } }, "block_code": "def on_finish(container, summary):\n phantom.debug('on_finish() called')\n # This function is called after all actions are completed.\n # summary of all the action and/or all details of actions\n # can be collected here.\n\n # summary_json = phantom.get_summary()\n # if 'result' in summary_json:\n # for action_result in summary_json['result']:\n # if 'action_run_id' in action_result:\n # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False)\n # phantom.debug(action_results)\n\n return", "callback_code": "# read-only block view not available", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "add to IP blocklist, add to domain blocklist, add to hash blocklist", "connection_type": "action", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "7d6e7306-cd84-4798-bb84-804b79fb09ef", "inPorts": [ "in" ], "join_code": "# read-only block view not available", "join_optional": [], "join_start": 1, "line_end": 297, "line_start": 284, "name": "", "notes": "", "number": 0, "order": 14, "outPorts": [], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 1080, "y": 40 }, "previous_function": "", "previous_name": "", "show_number": true, "size": { "height": 54, "width": 80 }, "status": "", "title": "END", "type": "coa.StartEnd", "warn": false, "z": 264 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "f19bbeed-6445-4a8c-bc7c-a2171961cf69", "router": { "name": "metro" }, "source": { "id": "d230871e-ee71-44a6-af7f-fb4f2f584da4", "port": "out-1", "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "7862d46c-23ea-4cda-9ef9-db171fd5ac93", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 277 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "8b252e02-8361-4d12-8663-61c2e8965ed9", "router": { "name": "metro" }, "source": { "id": "7862d46c-23ea-4cda-9ef9-db171fd5ac93", "port": "out-1", "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "6ad60d9d-90e4-4515-9931-05f31cc5f87a", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 286 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "fddf6767-1020-4c4e-9178-5bdcc37ef938", "router": { "name": "metro" }, "source": { "id": "ea4b2594-8ef5-42a4-8285-125126536531", "port": "out-1", "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "25ad9a87-018a-440b-a48d-3a0bd95226f6", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 288 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "ea23ca12-a7c3-40e3-b38c-67a92493b1b8", "router": { "name": "metro" }, "source": { "id": "25ad9a87-018a-440b-a48d-3a0bd95226f6", "port": "out-1", "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "45d563b4-3a4a-4cc8-bf1f-dfe4de434928", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 293 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "778389f4-851e-4b64-b5c1-e567e1277660", "router": { "name": "metro" }, "source": { "id": "6ad60d9d-90e4-4515-9931-05f31cc5f87a", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "1924c418-d049-478e-8cfd-ec94eb22f7c6", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 295 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "a111892b-a198-4573-9271-5f68da45f08d", "router": { "name": "metro" }, "source": { "id": "1924c418-d049-478e-8cfd-ec94eb22f7c6", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "7d6e7306-cd84-4798-bb84-804b79fb09ef", "port": null, "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" }, "type": "link", "z": 297 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "c17d4063-43db-4dc2-9ec2-b9c554f1a1f8", "router": { "name": "metro" }, "source": { "id": "45d563b4-3a4a-4cc8-bf1f-dfe4de434928", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "dced0e6a-538a-4d02-800a-5e5c0caf92f7", "selector": ".port-body[type=\"input\"]" }, "type": "link", "z": 301 }, { "attrs": { ".connection": { "stroke": "#6C7A89", "stroke-width": 2 }, ".marker-target": { "d": "M 10 0 L 0 5 L 10 10 z", "fill": "#6a6c8a", "stroke": "#6a6c8a" } }, "connector": { "args": { "radius": 5 }, "name": "rounded" }, "endDirections": [ "left" ], "id": "0b7d5584-b8cd-47e6-8f0b-455358f4b318", "router": { "name": "metro" }, "source": { "id": "dced0e6a-538a-4d02-800a-5e5c0caf92f7", "port": null, "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" }, "startDirections": [ "right" ], "target": { "id": "7d6e7306-cd84-4798-bb84-804b79fb09ef", "port": null, "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" }, "type": "link", "z": 303 }, { "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773", "transform": "rotate(45 30 70)" }, ".border": { "transform": "rotate(45 30 70)" }, ".inPorts>.port-0>.port-body": { "port": { "id": "in", "type": "in" } }, ".number": { "text": 1 }, ".outPorts>.port-0": { "port": { "id": "out-1", "type": "out" }, "ref-x": 83, "ref-y": 40 }, ".outPorts>.port-0>.port-body": { "port": { "id": "out-1", "type": "out" } }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" } }, "block_code": "def filter_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_1() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"artifact:*.cef.destinationAddress\", \"!=\", \"\"],\n ],\n name=\"filter_1:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n filter_4(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", "callback_code": "", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "81b07a3a-01ac-4d3a-b254-9cb7a3e97392", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 264, "line_start": 247, "name": "filter", "notes": "Filtering on artifacts that have the destinationAddress CEF value populated.", "number": 1, "order": 12, "outPorts": [ "out-1" ], "outputs": [ { "conditions": [ { "comparison": "!=", "data_type": "", "param": "artifact:*.cef.destinationAddress", "value": "" } ], "display": "If", "logic": "and", "type": "if" } ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 320, "y": 20 }, "previous_function": "", "previous_name": "filter_1", "show_number": true, "size": { "height": 82, "width": 82 }, "state": "filter", "status": "", "type": "coa.Filter", "warn": false, "z": 404 }, { "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773", "transform": "rotate(45 30 70)" }, ".border": { "transform": "rotate(45 30 70)" }, ".inPorts>.port-0>.port-body": { "port": { "id": "in", "type": "in" } }, ".number": { "text": 3 }, ".outPorts>.port-0": { "port": { "id": "out-1", "type": "out" }, "ref-x": 83, "ref-y": 40 }, ".outPorts>.port-0>.port-body": { "port": { "id": "out-1", "type": "out" } }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" } }, "block_code": "def filter_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_3() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"artifact:*.cef.fileHash\", \"!=\", \"\"],\n ],\n name=\"filter_3:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n filter_6(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", "callback_code": "", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "ea4b2594-8ef5-42a4-8285-125126536531", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 123, "line_start": 106, "name": "filter", "notes": "Filtering on artifacts that have the destinationDnsDomain CEF value populated.", "number": 3, "order": 6, "outPorts": [ "out-1" ], "outputs": [ { "conditions": [ { "comparison": "!=", "data_type": "", "param": "artifact:*.cef.fileHash", "value": "" } ], "display": "If", "logic": "and", "type": "if" } ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 320, "y": 300 }, "previous_function": "", "previous_name": "filter_3", "show_number": true, "size": { "height": 82, "width": 82 }, "state": "filter", "status": "", "type": "coa.Filter", "warn": false, "z": 412 }, { "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773", "transform": "rotate(45 30 70)" }, ".border": { "transform": "rotate(45 30 70)" }, ".inPorts>.port-0>.port-body": { "port": { "id": "in", "type": "in" } }, ".number": { "text": 2 }, ".outPorts>.port-0": { "port": { "id": "out-1", "type": "out" }, "ref-x": 83, "ref-y": 40 }, ".outPorts>.port-0>.port-body": { "port": { "id": "out-1", "type": "out" } }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" } }, "block_code": "def filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_2() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"artifact:*.cef.destinationDnsDomain\", \"!=\", \"\"],\n ],\n name=\"filter_2:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n filter_5(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", "callback_code": "", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "d230871e-ee71-44a6-af7f-fb4f2f584da4", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 106, "line_start": 89, "name": "filter", "notes": "Filtering on artifacts that have the destinationDnsDomain CEF value populated.", "number": 2, "order": 5, "outPorts": [ "out-1" ], "outputs": [ { "conditions": [ { "comparison": "!=", "data_type": "", "param": "artifact:*.cef.destinationDnsDomain", "value": "" } ], "display": "If", "logic": "and", "type": "if" } ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 320, "y": 160 }, "previous_function": "", "previous_name": "filter_2", "show_number": true, "size": { "height": 82, "width": 82 }, "state": "filter", "status": "", "type": "coa.Filter", "warn": false, "z": 416 }, { "action": "add listitem", "action_type": "generic", "active": false, "active_keys": {}, "active_values": { "create": "True", "list": "custom_list:domain_blocklist", "new_row": "block_domain_1:action_result.parameter.domain" }, "angle": 0, "app": "", "approver": "", "assets": [ { "action": "add listitem", "actions": [ "no op", "update list", "get action result", "create container", "import container", "export container", "deflate item", "add artifact", "find listitem", "add listitem", "find artifacts", "update artifact tags", "add note", "update artifact", "test connectivity" ], "active": true, "app_name": "Phantom", "app_version": "3.0.2", "appid": "deb82aa9-22cc-4675-9cf1-534b8d006eb7", "asset_name": "phantom", "config_type": "asset", "count": 0, "fields": { "create": "True", "list": "custom_list:domain_blocklist", "new_row": "block_domain_1:action_result.parameter.domain" }, "has_app": true, "id": 16, "loaded": false, "missing": false, "name": "phantom", "output": [ { "column_name": "Status", "column_order": 0, "data_path": "action_result.status", "data_type": "string", "example_values": [ "success", "failed" ] }, { "data_path": "action_result.parameter.create", "data_type": "boolean", "example_values": [ true, false ] }, { "data_path": "action_result.parameter.list", "data_type": "string", "example_values": [ "demo_list" ] }, { "contains": [ "*" ], "data_path": "action_result.parameter.new_row", "data_type": "string", "example_values": [ "[\"value1\",\"value2\",\"value3\"]" ] }, { "data_path": "action_result.data.*.failed", "data_type": "boolean" }, { "data_path": "action_result.data.*.success", "data_type": "boolean", "example_values": [ true, false ] }, { "contains": [ "url" ], "data_path": "action_result.summary.server", "data_type": "string", "example_values": [ "https://10.1.1.10" ] }, { "data_path": "action_result.message", "data_type": "string", "example_values": [ "Server: https://10.1.1.10" ] }, { "data_path": "summary.total_objects", "data_type": "numeric", "example_values": [ 1 ] }, { "data_path": "summary.total_objects_successful", "data_type": "numeric", "example_values": [ 1 ] } ], "parameters": { "create": { "data_type": "boolean", "default": false, "description": "Create list if it does not exist (default: false)", "key": "create", "order": 2, "required": false }, "list": { "data_type": "string", "default": null, "description": "Name or ID of a custom list", "key": "list", "order": 0, "required": true }, "new_row": { "contains": [ "*" ], "data_type": "string", "default": null, "description": "New Row (string or JSON list)", "key": "new_row", "order": 1, "primary": true, "required": true } }, "product_name": "Phantom", "product_vendor": "Phantom", "targets": "16", "type": "information" } ], "attrs": { ".action": { "text": "add to domain blocklist" }, ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".border": { "height": 88, "opacity": 1, "stroke": "#E6984E" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".message": { "fill": "#FFFFFF", "font-size": 12, "font-weight": 300, "opacity": 0, "ref": ".background", "ref-x": 5, "ref-y": 105, "text": "Configuring now" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "text": "Generic" }, "g.approver image": { "opacity": 1 }, "g.code image": { "opacity": 1 }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.error image": { "xlink:href": "/inc/coa/img/block_icon_warn.svg" }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_generic.svg" }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" }, "g.timer image": { "opacity": 1 }, "rect.warn-background": { "fill": "#E6984E" }, "text.icon": { "fill": "#E6984E" } }, "block_code": "def add_to_domain_blocklist(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_to_domain_blocklist() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'add_to_domain_blocklist' call\n results_data_1 = phantom.collect2(container=container, datapath=['block_domain_1:action_result.parameter.domain', 'block_domain_1:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'add_to_domain_blocklist' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'list': \"custom_list:domain_blocklist\",\n 'create': True,\n 'new_row': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"add listitem\", parameters=parameters, assets=['phantom'], name=\"add_to_domain_blocklist\", parent_action=action)\n\n return", "callback_code": "", "callback_start": 1, "callsback": true, "color": "#5094D4", "connected_to_start": true, "connection_name": "block domain", "connection_type": "action", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "add to domain blocklist", "delay": 0, "description": "The domain is added to the custom list 'domain_blocklist' in order to prevent the Playbook from attempting to block a domain that has already been blocked.", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "1924c418-d049-478e-8cfd-ec94eb22f7c6", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 219, "line_start": 194, "message": "Configuring now", "name": "add listitem", "notes": "The domain is added to the custom list 'domain_blocklist' in order to prevent the Playbook from attempting to block a domain that has already been blocked.", "number": 2, "order": 10, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 840, "y": 160 }, "previous_function": "", "previous_name": "add_to_domain_blocklist", "required_params": { "list": true, "new_row": true }, "reviewer": "", "show_number": true, "size": { "height": 112, "width": 168 }, "state": "action_assets", "status": "", "title": "Generic", "type": "coa.Action", "warn": false, "z": 421 }, { "action": "block hash", "action_type": "contain", "active": false, "active_keys": {}, "active_values": { "comment": "", "hash": "filtered-data:filter_6:condition_1:artifact:*.cef.fileHash" }, "angle": 0, "app": "", "approver": "", "assets": [ { "action": "", "active": true, "app_name": "", "app_version": "", "appid": "", "config_type": "asset", "fields": { "comment": "", "hash": "filtered-data:filter_6:condition_1:artifact:*.cef.fileHash" }, "has_app": true, "id": "-", "loaded": false, "missing": false, "name": "carbonblack", "output": [ { "data_path": "action_result.status", "data_type": "string", "example_values": [ "success" ] }, { "data_path": "action_result.parameter.comment", "data_type": "string", "example_values": [ "Sample comment" ] }, { "column_name": "Hash", "column_order": 0, "contains": [ "md5", "hash" ], "data_path": "action_result.parameter.hash", "data_type": "string", "example_values": [ "180469AE0B239E31DB4C65F02FD70BC1" ] }, { "data_path": "action_result.data", "data_type": "string" }, { "data_path": "action_result.summary", "data_type": "string" }, { "column_name": "Message", "column_order": 1, "data_path": "action_result.message", "data_type": "string", "example_values": [ "Block hash action succeeded. It might take some time for blacklisting to take effect." ] }, { "data_path": "summary.total_objects", "data_type": "numeric", "example_values": [ 1 ] }, { "data_path": "summary.total_objects_successful", "data_type": "numeric", "example_values": [ 1 ] } ], "product_name": "", "product_vendor": "", "type": "endpoint" } ], "attrs": { ".action": { "text": "block hash" }, ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".border": { "height": 88, "opacity": 1, "stroke": "#E6984E" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".message": { "fill": "#FFFFFF", "font-size": 12, "font-weight": 300, "opacity": 0, "ref": ".background", "ref-x": 5, "ref-y": 105, "text": "Configuring now" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "text": "Contain" }, "g.approver image": { "opacity": 1 }, "g.code image": { "opacity": 1 }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_contain.svg" }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" }, "g.timer image": { "opacity": 1 }, "rect.warn-background": { "fill": "#E6984E" }, "text.icon": { "fill": "#E6984E" } }, "block_code": "def block_hash_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_hash_2() called')\n\n # collect data for 'block_hash_2' call\n filtered_artifacts_data_1 = phantom.collect2(container=container, datapath=['filtered-data:filter_6:condition_1:artifact:*.cef.fileHash', 'filtered-data:filter_6:condition_1:artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'block_hash_2' call\n for filtered_artifacts_item_1 in filtered_artifacts_data_1:\n if filtered_artifacts_item_1[0]:\n parameters.append({\n 'hash': filtered_artifacts_item_1[0],\n 'comment': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_artifacts_item_1[1]},\n })\n\n phantom.act(action=\"block hash\", parameters=parameters, assets=['carbonblack'], callback=add_to_hash_blocklist, name=\"block_hash_2\")\n\n return", "callback_code": "", "callback_start": 1, "callsback": true, "color": "#3D9959", "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "delay": 0, "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "45d563b4-3a4a-4cc8-bf1f-dfe4de434928", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 67, "line_start": 45, "message": "Configuring now", "name": "block hash", "notes": "Blocks the hash utilizing the CarbonBlack Response endpoint technology app, preventing the process from running on endpoints utilizing CarbonBlack Response.", "number": 2, "order": 3, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 600, "y": 300 }, "previous_function": "", "previous_name": "block_hash_2", "required_params": { "hash": true }, "reviewer": "", "show_number": false, "size": { "height": 112, "width": 168 }, "state": "asset", "status": "", "title": "Contain", "type": "coa.Action", "warn": false, "z": 423 }, { "action": "block domain", "action_type": "contain", "active": false, "active_keys": {}, "active_values": { "disable_safeguards": "", "domain": "filtered-data:filter_5:condition_1:artifact:*.cef.destinationDnsDomain" }, "angle": 0, "app": "", "approver": "", "assets": [ { "action": "", "active": true, "app_name": "", "app_version": "", "appid": "", "config_type": "asset", "fields": { "disable_safeguards": "", "domain": "filtered-data:filter_5:condition_1:artifact:*.cef.destinationDnsDomain" }, "has_app": true, "id": "-", "loaded": false, "missing": false, "name": "opendns_umbrella", "output": [ { "column_name": "Status", "column_order": 1, "data_path": "action_result.status", "data_type": "string" }, { "data_path": "action_result.parameter.disable_safeguards", "data_type": "boolean" }, { "column_name": "Domain", "column_order": 0, "contains": [ "domain" ], "data_path": "action_result.parameter.domain", "data_type": "string" }, { "data_path": "action_result.message", "data_type": "string" }, { "column_name": "ID", "column_order": 2, "data_path": "action_result.data.*.id", "data_type": "string" }, { "data_path": "summary.total_objects", "data_type": "numeric" }, { "data_path": "summary.total_objects_successful", "data_type": "numeric" } ], "product_name": "", "product_vendor": "", "type": "endpoint" } ], "attrs": { ".action": { "text": "block domain" }, ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".border": { "height": 88, "opacity": 1, "stroke": "#E6984E" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".message": { "fill": "#FFFFFF", "font-size": 12, "font-weight": 300, "opacity": 0, "ref": ".background", "ref-x": 5, "ref-y": 105, "text": "Configuring now" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "text": "Contain" }, "g.approver image": { "opacity": 1 }, "g.code image": { "opacity": 1 }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_contain.svg" }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" }, "g.timer image": { "opacity": 1 }, "rect.warn-background": { "fill": "#E6984E" }, "text.icon": { "fill": "#E6984E" } }, "block_code": "def block_domain_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_domain_1() called')\n\n # collect data for 'block_domain_1' call\n filtered_artifacts_data_1 = phantom.collect2(container=container, datapath=['filtered-data:filter_5:condition_1:artifact:*.cef.destinationDnsDomain', 'filtered-data:filter_5:condition_1:artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'block_domain_1' call\n for filtered_artifacts_item_1 in filtered_artifacts_data_1:\n if filtered_artifacts_item_1[0]:\n parameters.append({\n 'domain': filtered_artifacts_item_1[0],\n 'disable_safeguards': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_artifacts_item_1[1]},\n })\n\n phantom.act(action=\"block domain\", parameters=parameters, assets=['opendns_umbrella'], callback=add_to_domain_blocklist, name=\"block_domain_1\")\n\n return", "callback_code": "", "callback_start": 1, "callsback": true, "color": "#3D9959", "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "delay": 0, "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "6ad60d9d-90e4-4515-9931-05f31cc5f87a", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 89, "line_start": 67, "message": "Configuring now", "name": "block domain", "notes": "Blocks a domain utilizing the OpenDNS Umbrella app, preventing endpoints from accessing the domain from within the network.", "number": 1, "order": 4, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 600, "y": 160 }, "previous_function": "", "previous_name": "block_domain_1", "required_params": { "domain": true }, "reviewer": "", "show_number": false, "size": { "height": 112, "width": 168 }, "state": "asset", "status": "", "title": "Contain", "type": "coa.Action", "warn": false, "z": 424 }, { "action": "block ip", "action_type": "contain", "active": false, "active_keys": {}, "active_values": { "ip": "filtered-data:filter_4:condition_1:artifact:*.cef.destinationAddress", "is_source_address": "", "vsys": "" }, "angle": 0, "app": "", "approver": "", "assets": [ { "action": "", "active": true, "app_name": "", "app_version": "", "appid": "", "config_type": "asset", "fields": { "ip": "filtered-data:filter_4:condition_1:artifact:*.cef.destinationAddress", "is_source_address": "", "vsys": "" }, "has_app": true, "id": "-", "loaded": false, "missing": false, "name": "pan", "output": [ { "column_name": "IP", "column_order": 0, "contains": [ "ip" ], "data_path": "action_result.parameter.ip", "data_type": "string" }, { "data_path": "action_result.parameter.vsys", "data_type": "string" }, { "data_path": "action_result.parameter.is_source_address", "data_type": "boolean" }, { "column_name": "Status", "column_order": 1, "data_path": "action_result.status", "data_type": "string" }, { "column_name": "Message", "column_order": 2, "data_path": "action_result.message", "data_type": "string" }, { "data_path": "summary.total_objects", "data_type": "numeric" }, { "data_path": "summary.total_objects_successful", "data_type": "numeric" } ], "product_name": "", "product_vendor": "", "type": "firewall" } ], "attrs": { ".action": { "text": "block ip" }, ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".border": { "height": 88, "opacity": 1, "stroke": "#E6984E" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".message": { "fill": "#FFFFFF", "font-size": 12, "font-weight": 300, "opacity": 0, "ref": ".background", "ref-x": 5, "ref-y": 105, "text": "Configuring now" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "text": "Contain" }, "g.approver image": { "opacity": 1 }, "g.code image": { "opacity": 1 }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_contain.svg" }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" }, "g.timer image": { "opacity": 1 }, "rect.warn-background": { "fill": "#E6984E" }, "text.icon": { "fill": "#E6984E" } }, "block_code": "def block_ip_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_ip_1() called')\n\n # collect data for 'block_ip_1' call\n filtered_artifacts_data_1 = phantom.collect2(container=container, datapath=['filtered-data:filter_4:condition_1:artifact:*.cef.destinationAddress', 'filtered-data:filter_4:condition_1:artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'block_ip_1' call\n for filtered_artifacts_item_1 in filtered_artifacts_data_1:\n if filtered_artifacts_item_1[0]:\n parameters.append({\n 'ip': filtered_artifacts_item_1[0],\n 'vsys': \"\",\n 'is_source_address': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_artifacts_item_1[1]},\n })\n\n phantom.act(action=\"block ip\", parameters=parameters, assets=['pan'], callback=add_to_IP_blocklist, name=\"block_ip_1\")\n\n return", "callback_code": "", "callback_start": 1, "callsback": true, "color": "#3D9959", "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "delay": 0, "description": "", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "7a912b77-6a81-421d-b6f5-d865b3fffd73", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 45, "line_start": 22, "message": "Configuring now", "name": "block ip", "notes": "Blocks the IP as a destination address, utilizing the Palo Alto Networks Firewall app to prevent further access to the IP address as a destination.", "number": 1, "order": 2, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 600, "y": 20 }, "previous_function": "", "previous_name": "block_ip_1", "required_params": { "ip": true }, "reviewer": "", "show_number": false, "size": { "height": 112, "width": 168 }, "state": "asset", "status": "", "title": "Contain", "type": "coa.Action", "warn": false, "z": 425 }, { "action": "add listitem", "action_type": "generic", "active": false, "active_keys": {}, "active_values": { "create": "True", "list": "custom_list:filehash_blocklist", "new_row": "block_hash_2:action_result.parameter.hash" }, "angle": 0, "app": "", "approver": "", "assets": [ { "action": "add listitem", "actions": [ "no op", "update list", "get action result", "create container", "import container", "export container", "deflate item", "add artifact", "find listitem", "add listitem", "find artifacts", "update artifact tags", "add note", "update artifact", "test connectivity" ], "active": true, "app_name": "Phantom", "app_version": "3.0.2", "appid": "deb82aa9-22cc-4675-9cf1-534b8d006eb7", "asset_name": "phantom", "config_type": "asset", "count": 0, "fields": { "create": "True", "list": "custom_list:filehash_blocklist", "new_row": "block_hash_2:action_result.parameter.hash" }, "has_app": true, "id": 16, "loaded": false, "missing": false, "name": "phantom", "output": [ { "column_name": "Status", "column_order": 0, "data_path": "action_result.status", "data_type": "string", "example_values": [ "success", "failed" ] }, { "data_path": "action_result.parameter.create", "data_type": "boolean", "example_values": [ true, false ] }, { "data_path": "action_result.parameter.list", "data_type": "string", "example_values": [ "demo_list" ] }, { "contains": [ "*" ], "data_path": "action_result.parameter.new_row", "data_type": "string", "example_values": [ "[\"value1\",\"value2\",\"value3\"]" ] }, { "data_path": "action_result.data.*.failed", "data_type": "boolean" }, { "data_path": "action_result.data.*.success", "data_type": "boolean", "example_values": [ true, false ] }, { "contains": [ "url" ], "data_path": "action_result.summary.server", "data_type": "string", "example_values": [ "https://10.1.1.10" ] }, { "data_path": "action_result.message", "data_type": "string", "example_values": [ "Server: https://10.1.1.10" ] }, { "data_path": "summary.total_objects", "data_type": "numeric", "example_values": [ 1 ] }, { "data_path": "summary.total_objects_successful", "data_type": "numeric", "example_values": [ 1 ] } ], "parameters": { "create": { "data_type": "boolean", "default": false, "description": "Create list if it does not exist (default: false)", "key": "create", "order": 2, "required": false }, "list": { "data_type": "string", "default": null, "description": "Name or ID of a custom list", "key": "list", "order": 0, "required": true }, "new_row": { "contains": [ "*" ], "data_type": "string", "default": null, "description": "New Row (string or JSON list)", "key": "new_row", "order": 1, "primary": true, "required": true } }, "product_name": "Phantom", "product_vendor": "Phantom", "targets": "16", "type": "information" } ], "attrs": { ".action": { "text": "add to hash blocklist" }, ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".border": { "height": 88, "opacity": 1, "stroke": "#E6984E" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".message": { "fill": "#FFFFFF", "font-size": 12, "font-weight": 300, "opacity": 0, "ref": ".background", "ref-x": 5, "ref-y": 105, "text": "Configuring now" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "text": "Generic" }, "g.approver image": { "opacity": 1 }, "g.code image": { "opacity": 1 }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.error image": { "xlink:href": "/inc/coa/img/block_icon_warn.svg" }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_generic.svg" }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" }, "g.timer image": { "opacity": 1 }, "rect.warn-background": { "fill": "#E6984E" }, "text.icon": { "fill": "#E6984E" } }, "block_code": "def add_to_hash_blocklist(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_to_hash_blocklist() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'add_to_hash_blocklist' call\n results_data_1 = phantom.collect2(container=container, datapath=['block_hash_2:action_result.parameter.hash', 'block_hash_2:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'add_to_hash_blocklist' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'list': \"custom_list:filehash_blocklist\",\n 'create': True,\n 'new_row': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"add listitem\", parameters=parameters, assets=['phantom'], name=\"add_to_hash_blocklist\", parent_action=action)\n\n return", "callback_code": "", "callback_start": 1, "callsback": true, "color": "#5094D4", "connected_to_start": true, "connection_name": "block hash", "connection_type": "action", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "add to hash blocklist", "delay": 0, "description": "The file hash is added to the custom list 'filehash_blocklist' in order to prevent the Playbook from attempting to block a file hash that has already been blocked.", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "dced0e6a-538a-4d02-800a-5e5c0caf92f7", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 191, "line_start": 166, "message": "Configuring now", "name": "add listitem", "notes": "The file hash is added to the custom list 'filehash_blocklist' in order to prevent the Playbook from attempting to block a file hash that has already been blocked.", "number": 3, "order": 9, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 840, "y": 300 }, "previous_function": "", "previous_name": "add_to_hash_blocklist", "required_params": { "list": true, "new_row": true }, "reviewer": "", "show_number": true, "size": { "height": 112, "width": 168 }, "state": "action_assets", "status": "", "title": "Generic", "type": "coa.Action", "warn": false, "z": 426 }, { "action": "add listitem", "action_type": "generic", "active": false, "active_keys": {}, "active_values": { "create": "True", "list": "custom_list:ip_address_blocklist", "new_row": "block_ip_1:action_result.parameter.ip" }, "angle": 0, "app": "", "approver": "", "assets": [ { "action": "add listitem", "actions": [ "no op", "update list", "get action result", "create container", "import container", "export container", "deflate item", "add artifact", "find listitem", "add listitem", "find artifacts", "update artifact tags", "add note", "update artifact", "test connectivity" ], "active": true, "app_name": "Phantom", "app_version": "3.0.2", "appid": "deb82aa9-22cc-4675-9cf1-534b8d006eb7", "asset_name": "phantom", "config_type": "asset", "count": 0, "fields": { "create": "True", "list": "custom_list:ip_address_blocklist", "new_row": "block_ip_1:action_result.parameter.ip" }, "has_app": true, "id": 16, "loaded": false, "missing": false, "name": "phantom", "output": [ { "column_name": "Status", "column_order": 0, "data_path": "action_result.status", "data_type": "string", "example_values": [ "success", "failed" ] }, { "data_path": "action_result.parameter.create", "data_type": "boolean", "example_values": [ true, false ] }, { "data_path": "action_result.parameter.list", "data_type": "string", "example_values": [ "demo_list" ] }, { "contains": [ "*" ], "data_path": "action_result.parameter.new_row", "data_type": "string", "example_values": [ "[\"value1\",\"value2\",\"value3\"]" ] }, { "data_path": "action_result.data.*.failed", "data_type": "boolean" }, { "data_path": "action_result.data.*.success", "data_type": "boolean", "example_values": [ true, false ] }, { "contains": [ "url" ], "data_path": "action_result.summary.server", "data_type": "string", "example_values": [ "https://10.1.1.10" ] }, { "data_path": "action_result.message", "data_type": "string", "example_values": [ "Server: https://10.1.1.10" ] }, { "data_path": "summary.total_objects", "data_type": "numeric", "example_values": [ 1 ] }, { "data_path": "summary.total_objects_successful", "data_type": "numeric", "example_values": [ 1 ] } ], "parameters": { "create": { "data_type": "boolean", "default": false, "description": "Create list if it does not exist (default: false)", "key": "create", "order": 2, "required": false }, "list": { "data_type": "string", "default": null, "description": "Name or ID of a custom list", "key": "list", "order": 0, "required": true }, "new_row": { "contains": [ "*" ], "data_type": "string", "default": null, "description": "New Row (string or JSON list)", "key": "new_row", "order": 1, "primary": true, "required": true } }, "product_name": "Phantom", "product_vendor": "Phantom", "targets": "16", "type": "information" } ], "attrs": { ".action": { "text": "add to IP blocklist" }, ".background": { "fill": "#000000", "stroke": "#5C6773" }, ".border": { "height": 88, "opacity": 1, "stroke": "#E6984E" }, ".color-band": { "fill": "#3C444D" }, ".inPorts>.port-in": { "ref": ".background", "ref-x": 0.5 }, ".inPorts>.port-in>.port-body": { "port": { "id": "in", "type": "in" } }, ".message": { "fill": "#FFFFFF", "font-size": 12, "font-weight": 300, "opacity": 0, "ref": ".background", "ref-x": 5, "ref-y": 105, "text": "Configuring now" }, ".outPorts>.port-out": { "ref": ".background", "ref-x": 0.5 }, ".outPorts>.port-out>.port-body": { "port": { "id": "out", "type": "out" } }, ".title": { "text": "Generic" }, "g.approver image": { "opacity": 1 }, "g.code image": { "opacity": 1 }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.error image": { "xlink:href": "/inc/coa/img/block_icon_warn.svg" }, "g.icon image": { "xlink:href": "/inc/coa/img/block_icon_generic.svg" }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" }, "g.timer image": { "opacity": 1 }, "rect.warn-background": { "fill": "#E6984E" }, "text.icon": { "fill": "#E6984E" } }, "block_code": "def add_to_IP_blocklist(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_to_IP_blocklist() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'add_to_IP_blocklist' call\n results_data_1 = phantom.collect2(container=container, datapath=['block_ip_1:action_result.parameter.ip', 'block_ip_1:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'add_to_IP_blocklist' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'list': \"custom_list:ip_address_blocklist\",\n 'create': True,\n 'new_row': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"add listitem\", parameters=parameters, assets=['phantom'], name=\"add_to_IP_blocklist\", parent_action=action)\n\n return", "callback_code": "", "callback_start": 1, "callsback": true, "color": "#5094D4", "connected_to_start": true, "connection_name": "block ip", "connection_type": "action", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "add to IP blocklist", "delay": 0, "description": "The IP address is added to the custom list 'ip_address_blocklist' in order to prevent the Playbook from attempting to block an IP address that has already been blocked.", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "08306503-f5d1-4cd0-b32b-90a7670ff1ca", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 247, "line_start": 222, "message": "Configuring now", "name": "add listitem", "notes": "The IP address is added to the custom list 'ip_address_blocklist' in order to prevent the Playbook from attempting to block an IP address that has already been blocked.", "number": 1, "order": 11, "outPorts": [ "out" ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 840, "y": 20 }, "previous_function": "", "previous_name": "add_to_IP_blocklist", "required_params": { "list": true, "new_row": true }, "reviewer": "", "show_number": true, "size": { "height": 112, "width": 168 }, "state": "action_assets", "status": "", "title": "Generic", "type": "coa.Action", "warn": false, "z": 430 }, { "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773", "transform": "rotate(45 30 70)" }, ".border": { "transform": "rotate(45 30 70)" }, ".inPorts>.port-0>.port-body": { "port": { "id": "in", "type": "in" } }, ".number": { "text": 6 }, ".outPorts>.port-0": { "port": { "id": "out-1", "type": "out" }, "ref-x": 83, "ref-y": 40 }, ".outPorts>.port-0>.port-body": { "port": { "id": "out-1", "type": "out" } }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" } }, "block_code": "def filter_6(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_6() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"filtered-data:filter_3:condition_1:artifact:*.cef.fileHash\", \"in\", \"custom_list:filehash_blocklist\"],\n ],\n name=\"filter_6:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n block_hash_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", "callback_code": "", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "Checking to see if this filehash is in the custom list called \"filehash_blocklist\"", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "25ad9a87-018a-440b-a48d-3a0bd95226f6", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 163, "line_start": 146, "name": "filter", "notes": "Checking to see if this filehash is in the custom list called \"filehash_blocklist\"", "number": 6, "order": 8, "outPorts": [ "out-1" ], "outputs": [ { "conditions": [ { "comparison": "in", "data_type": "", "param": "filtered-data:filter_3:condition_1:artifact:*.cef.fileHash", "value": "custom_list:filehash_blocklist" } ], "display": "If", "logic": "and", "type": "if" } ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 460, "y": 300 }, "previous_function": "", "previous_name": "filter_6", "show_number": true, "size": { "height": 82, "width": 82 }, "state": "filter", "status": "", "type": "coa.Filter", "warn": false, "z": 432 }, { "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773", "transform": "rotate(45 30 70)" }, ".border": { "transform": "rotate(45 30 70)" }, ".inPorts>.port-0>.port-body": { "port": { "id": "in", "type": "in" } }, ".number": { "text": 5 }, ".outPorts>.port-0": { "port": { "id": "out-1", "type": "out" }, "ref-x": 83, "ref-y": 40 }, ".outPorts>.port-0>.port-body": { "port": { "id": "out-1", "type": "out" } }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" } }, "block_code": "def filter_5(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_5() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"filtered-data:filter_2:condition_1:artifact:*.cef.destinationDnsDomain\", \"in\", \"custom_list:domain_blocklist\"],\n ],\n name=\"filter_5:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n block_domain_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", "callback_code": "", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "Checking to see if this domain address is in the custom list called \"domain_blocklist\"", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "7862d46c-23ea-4cda-9ef9-db171fd5ac93", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 143, "line_start": 126, "name": "filter", "notes": "Checking to see if this domain address is in the custom list called \"domain_blocklist\"", "number": 5, "order": 7, "outPorts": [ "out-1" ], "outputs": [ { "conditions": [ { "comparison": "in", "data_type": "", "param": "filtered-data:filter_2:condition_1:artifact:*.cef.destinationDnsDomain", "value": "custom_list:domain_blocklist" } ], "display": "If", "logic": "and", "type": "if" } ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 460, "y": 160 }, "previous_function": "", "previous_name": "filter_5", "show_number": true, "size": { "height": 82, "width": 82 }, "state": "filter", "status": "", "type": "coa.Filter", "warn": false, "z": 433 }, { "active": false, "angle": 0, "attrs": { ".background": { "fill": "#000000", "stroke": "#5C6773", "transform": "rotate(45 30 70)" }, ".border": { "transform": "rotate(45 30 70)" }, ".inPorts>.port-0>.port-body": { "port": { "id": "in", "type": "in" } }, ".number": { "text": 4 }, ".outPorts>.port-0": { "port": { "id": "out-1", "type": "out" }, "ref-x": 83, "ref-y": 40 }, ".outPorts>.port-0>.port-body": { "port": { "id": "out-1", "type": "out" } }, "g.delete": { "display": "none" }, "g.error": { "opacity": 0 }, "g.notes": { "display": "block", "opacity": 1 }, "g.notes image": { "opacity": 1, "xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg" } }, "block_code": "def filter_4(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_4() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"filtered-data:filter_1:condition_1:artifact:*.cef.destinationAddress\", \"not in\", \"custom_list:ip_address_blocklist\"],\n ],\n name=\"filter_4:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n block_ip_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", "callback_code": "", "callback_start": 1, "callsback": false, "connected_to_start": true, "connection_name": "", "connection_type": "", "custom_callback": "", "custom_code": "", "custom_join": "", "custom_name": "", "description": "Checking to see if this IP address is in the custom list called \"ip_address_blocklist\"", "has_custom": false, "has_custom_block": false, "has_custom_callback": false, "has_custom_join": false, "id": "9537d314-97d6-484b-ae20-3d9564bab6d6", "inPorts": [ "in" ], "join_code": "", "join_optional": [], "join_start": 1, "line_end": 284, "line_start": 267, "name": "filter", "notes": "Checking to see if this IP address is in the custom list called \"ip_address_blocklist\"", "number": 4, "order": 13, "outPorts": [ "out-1" ], "outputs": [ { "conditions": [ { "comparison": "not in", "data_type": "", "param": "filtered-data:filter_1:condition_1:artifact:*.cef.destinationAddress", "value": "custom_list:ip_address_blocklist" } ], "display": "If", "logic": "and", "type": "if" } ], "ports": { "groups": { "in": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "left" } }, "position": { "name": "left" } }, "out": { "attrs": { ".port-body": { "fill": "#fff", "magnet": true, "r": 10, "stroke": "#000" }, ".port-label": { "fill": "#000" } }, "label": { "position": { "args": { "y": 10 }, "name": "right" } }, "position": { "name": "right" } } } }, "position": { "x": 460, "y": 20 }, "previous_function": "", "previous_name": "filter_4", "show_number": true, "size": { "height": 82, "width": 82 }, "state": "filter", "status": "", "type": "coa.Filter", "warn": false, "z": 434 } ] }, "notes": "This playbook uses the following Apps: \n\n- Palo Alto Networks Firewall (PAN)\n- CarbonBlack Response\n- OpenDNS Umbrella\n\nThis playbook uses the following custom list:\n\n- ip_address_blocklist\n- domain_blocklist\n- filehash_blocklist\n\nThis playbook provides an easy, automated, and straightforward solution to maintaining up-to-date IP address, file, and domain blocklists. The process is:\n\nEach Artifact within an event is checked for the presence of the following CEF fields:\nDestinationDnsDomain - Domains\nDestinationAddress - IP addresses\nFileHash - Files\nThe CEF value is then cross-referenced with their respective Custom Lists.\nIP addresses are blocked on a Firewall, while domains are blocked using a blocklist service. The blocking of these two will prevent access to the IOCs. Finally, file hashes are blocked using an endpoint protection service, which will prevent the process from running on affected endpoints within a network.\nAfter the IOCs are blocked using various apps, they are added to their respective custom lists as to maintain a running blocklist record." }, "python_version": "3", "schema": 4, "version": "4.10.0.40961" }, "create_time": "2021-01-21T21:26:58.710395+00:00", "draft_mode": false, "labels": [ "events" ], "tags": [] }