Files
splunk-security_content/playbooks/Identifier_Activity_Analysis_Dispatch.json
2026-04-28 10:47:57 -04:00

685 lines
29 KiB
JSON

{
"blockly": false,
"blockly_xml": "<xml></xml>",
"category": "Identifier Activity Analysis",
"coa": {
"data": {
"description": "Detects available indicators and routes them to related identifier activity analysis playbooks. The output of the analysis will update any artifacts, tasks, and indicator tags.",
"edges": [
{
"id": "port_0_to_port_2",
"sourceNode": "0",
"sourcePort": "0_out",
"targetNode": "2",
"targetPort": "2_in"
},
{
"conditions": [
{
"index": 0
}
],
"id": "port_2_to_port_3",
"sourceNode": "2",
"sourcePort": "2_out",
"targetNode": "3",
"targetPort": "3_in"
},
{
"conditions": [
{
"index": 1
}
],
"id": "port_2_to_port_4",
"sourceNode": "2",
"sourcePort": "2_out",
"targetNode": "4",
"targetPort": "4_in"
},
{
"conditions": [
{
"index": 0
}
],
"id": "port_3_to_port_6",
"sourceNode": "3",
"sourcePort": "3_out",
"targetNode": "6",
"targetPort": "6_in"
},
{
"id": "port_6_to_port_7",
"sourceNode": "6",
"sourcePort": "6_out",
"targetNode": "7",
"targetPort": "7_in"
},
{
"conditions": [
{
"index": 0
}
],
"id": "port_7_to_port_8",
"sourceNode": "7",
"sourcePort": "7_out",
"targetNode": "8",
"targetPort": "8_in"
},
{
"conditions": [
{
"index": 1
}
],
"id": "port_7_to_port_9",
"sourceNode": "7",
"sourcePort": "7_out",
"targetNode": "9",
"targetPort": "9_in"
},
{
"conditions": [
{
"index": 0
}
],
"id": "port_8_to_port_10",
"sourceNode": "8",
"sourcePort": "8_out",
"targetNode": "10",
"targetPort": "10_in"
},
{
"id": "port_10_to_port_11",
"sourceNode": "10",
"sourcePort": "10_out",
"targetNode": "11",
"targetPort": "11_in"
},
{
"id": "port_11_to_port_1",
"sourceNode": "11",
"sourcePort": "11_out",
"targetNode": "1",
"targetPort": "1_in"
}
],
"hash": "420742e453b73f08fcf67587b7e96d27210e00df",
"nodes": {
"0": {
"data": {
"advanced": {
"join": []
},
"functionName": "on_start",
"id": "0",
"type": "start"
},
"errors": {},
"id": "0",
"type": "start",
"warnings": {},
"x": 300,
"y": -4.476419235288631e-13
},
"1": {
"data": {
"advanced": {
"join": []
},
"functionName": "on_finish",
"id": "1",
"type": "end"
},
"errors": {},
"id": "1",
"type": "end",
"warnings": {},
"x": 180,
"y": 1380
},
"10": {
"data": {
"advanced": {
"customName": "merge reports",
"customNameId": 0,
"description": "Merge markdown outputs from dispatched playbooks",
"join": [],
"note": "Merge markdown outputs from dispatched playbooks"
},
"functionId": 1,
"functionName": "merge_reports",
"id": "10",
"parameters": [
"filtered-data:markdown_filter:condition_1:dispatch_activity_analysis_playbooks:playbook_output:markdown_report"
],
"template": "%%\n{0}\n\n\n%%",
"type": "format"
},
"errors": {},
"id": "10",
"type": "format",
"warnings": {},
"x": 0,
"y": 1040
},
"11": {
"data": {
"advanced": {
"customName": "Update Identifier Activity Analysis Task",
"customNameId": 0,
"join": [],
"note": "Update workbook task that called this playbook."
},
"customFunction": {
"draftMode": false,
"name": "workbook_task_update",
"repoName": "community"
},
"functionId": 3,
"functionName": "update_identifier_activity_analysis_task",
"id": "11",
"selectMore": false,
"tab": "customFunctions",
"type": "utility",
"utilities": {
"workbook_task_update": {
"description": "Update a workbook task by task name or the task where the currently running playbook appears. Requires a task_name, container_id, and a note_title, note_content, owner, or status.",
"fields": [
{
"dataTypes": [
"*"
],
"description": "Name of a workbook task or keyword 'playbook' to update the task where the currently running playbook appears. (Required)",
"inputType": "item",
"label": "task_name",
"name": "task_name",
"placeholder": "my_task",
"renderType": "datapath",
"required": false
},
{
"dataTypes": [
"*"
],
"description": "Note title. (Optional)",
"inputType": "item",
"label": "note_title",
"name": "note_title",
"placeholder": "My Title",
"renderType": "datapath",
"required": false
},
{
"dataTypes": [
"*"
],
"description": "Note content. (Optional)",
"inputType": "item",
"label": "note_content",
"name": "note_content",
"placeholder": "My notes",
"renderType": "datapath",
"required": false
},
{
"dataTypes": [
"*"
],
"description": "Accepts 'incomplete', 'in_progress, or 'complete'. (Optional)",
"inputType": "item",
"label": "status",
"name": "status",
"placeholder": "in_progress",
"renderType": "datapath",
"required": false
},
{
"dataTypes": [
"*"
],
"description": "A user to assign as the task owner or keyword 'current\" to assign the task to the user that launched the playbook. (Optional)",
"inputType": "item",
"label": "owner",
"name": "owner",
"placeholder": "username",
"renderType": "datapath",
"required": false
},
{
"dataTypes": [
"phantom container id"
],
"description": "The ID of a SOAR Container. (Required)",
"inputType": "item",
"label": "container",
"name": "container",
"placeholder": "container:id",
"renderType": "datapath",
"required": false
}
],
"label": "workbook_task_update",
"name": "workbook_task_update"
}
},
"utilityType": "custom_function",
"values": {
"comment": {
"_internal": [
"container",
"author",
"trace"
],
"comment": "No observable data found from playbook(s)."
},
"workbook_task_update": {
"container": "container:id",
"note_content": "merge_reports:formatted_data",
"note_title": "Identifier Activity Analysis Dispatch",
"owner": null,
"status": "complete",
"task_name": "playbook"
}
}
},
"errors": {},
"id": "11",
"type": "utility",
"warnings": {},
"x": 0,
"y": 1180
},
"2": {
"data": {
"advanced": {
"customName": "route_artifacts",
"customNameId": 0,
"description": "Only dispatch playbooks against new artifacts.",
"join": [],
"note": "Only dispatch playbooks against new artifacts."
},
"conditions": [
{
"comparisons": [
{
"conditionIndex": 0,
"op": "!=",
"param": "artifact:*.id",
"value": "None"
}
],
"conditionIndex": 0,
"customName": "artifacts exist",
"display": "If",
"logic": "and",
"type": "if"
},
{
"comparisons": [
{
"conditionIndex": 1,
"op": "==",
"param": "",
"value": ""
}
],
"conditionIndex": 1,
"customName": "artifacts do not exist",
"display": "Else",
"logic": "and",
"type": "else"
}
],
"functionId": 1,
"functionName": "route_artifacts",
"id": "2",
"type": "decision"
},
"errors": {},
"id": "2",
"type": "decision",
"warnings": {},
"x": 360,
"y": 148
},
"3": {
"data": {
"advanced": {
"customName": "filter_inputs",
"customNameId": 0,
"description": "Ensure there are artifacts",
"join": [],
"note": "Ensure there are artifacts"
},
"conditions": [
{
"comparisons": [
{
"conditionIndex": 0,
"op": "!=",
"param": "artifact:*.id",
"value": "None"
}
],
"conditionIndex": 0,
"customName": "artifacts",
"logic": "and"
}
],
"functionId": 1,
"functionName": "filter_inputs",
"id": "3",
"type": "filter"
},
"errors": {},
"id": "3",
"type": "filter",
"warnings": {},
"x": 200,
"y": 328
},
"4": {
"data": {
"advanced": {
"customName": "No Artifacts",
"customNameId": 0,
"description": "Comment and exit if there are no new artifacts",
"join": [],
"note": "Comment and exit if there are no new artifacts"
},
"functionId": 1,
"functionName": "no_artifacts",
"id": "4",
"selectMore": false,
"tab": "apis",
"type": "utility",
"utilities": {
"comment": {
"description": "",
"fields": [
{
"description": "",
"label": "comment",
"name": "comment",
"placeholder": "Enter a comment",
"renderType": "datapath",
"required": true
},
{
"hidden": true,
"name": "container",
"required": false
},
{
"hidden": true,
"name": "author",
"required": false
},
{
"hidden": true,
"name": "trace",
"required": false
}
],
"label": "add comment",
"name": "comment"
}
},
"utilityType": "api",
"values": {
"comment": {
"_internal": [
"container",
"author",
"trace"
],
"comment": "No new artifact data found in event."
}
}
},
"errors": {},
"id": "4",
"type": "utility",
"warnings": {},
"x": 420,
"y": 340
},
"6": {
"data": {
"advanced": {
"customName": "Dispatch Activity Analysis Playbooks",
"customNameId": 0,
"join": []
},
"functionId": 1,
"functionName": "dispatch_activity_analysis_playbooks",
"id": "6",
"inputs": {
"artifact_ids_include": {
"datapaths": [
"artifact:*.id"
],
"deduplicate": false
},
"indicator_tags_exclude": {
"datapaths": [],
"deduplicate": false
},
"indicator_tags_include": {
"datapaths": [],
"deduplicate": false
},
"playbook_repo": {
"datapaths": [
""
],
"deduplicate": false
},
"playbook_tags": {
"datapaths": [
"identifier_activity"
],
"deduplicate": false
}
},
"playbookName": "dispatch_input_playbooks",
"playbookRepo": 1,
"playbookRepoName": "community",
"playbookType": "data",
"synchronous": true,
"type": "playbook"
},
"errors": {},
"id": "6",
"type": "playbook",
"warnings": {},
"x": 140,
"y": 508
},
"7": {
"data": {
"advanced": {
"customName": "route outputs",
"customNameId": 0,
"description": "Determine if outputs exist",
"join": [],
"note": "Determine if outputs exist"
},
"conditions": [
{
"comparisons": [
{
"conditionIndex": 0,
"op": "!=",
"param": "dispatch_activity_analysis_playbooks:playbook_output:observable",
"value": "None"
}
],
"conditionIndex": 0,
"customName": "outputs exist",
"display": "If",
"logic": "and",
"type": "if"
},
{
"comparisons": [
{
"conditionIndex": 1,
"op": "==",
"param": "",
"value": ""
}
],
"conditionIndex": 1,
"customName": "outputs do not exist",
"display": "Else",
"logic": "and",
"type": "else"
}
],
"functionId": 2,
"functionName": "route_outputs",
"id": "7",
"type": "decision"
},
"errors": {},
"id": "7",
"type": "decision",
"warnings": {},
"x": 220,
"y": 672
},
"8": {
"data": {
"advanced": {
"customName": "markdown filter",
"customNameId": 0,
"description": "Ensure there are outputs",
"join": [],
"note": "Ensure there are outputs"
},
"conditions": [
{
"comparisons": [
{
"conditionIndex": 0,
"op": "!=",
"param": "dispatch_activity_analysis_playbooks:playbook_output:markdown_report",
"value": "None"
}
],
"conditionIndex": 0,
"customName": "outputs exist",
"logic": "and"
}
],
"functionId": 3,
"functionName": "markdown_filter",
"id": "8",
"type": "filter"
},
"errors": {},
"id": "8",
"type": "filter",
"warnings": {},
"x": 60,
"y": 860
},
"9": {
"data": {
"advanced": {
"customName": "No Outputs",
"customNameId": 0,
"description": "Comment and exit if there are no observables returned",
"join": [],
"note": "Comment and exit if there are no observables returned"
},
"functionId": 2,
"functionName": "no_outputs",
"id": "9",
"selectMore": false,
"tab": "apis",
"type": "utility",
"utilities": {
"comment": {
"description": "",
"fields": [
{
"description": "",
"label": "comment",
"name": "comment",
"placeholder": "Enter a comment",
"renderType": "datapath",
"required": true
},
{
"hidden": true,
"name": "container",
"required": false
},
{
"hidden": true,
"name": "author",
"required": false
},
{
"hidden": true,
"name": "trace",
"required": false
}
],
"label": "add comment",
"name": "comment"
}
},
"utilityType": "api",
"values": {
"comment": {
"_internal": [
"container",
"author",
"trace"
],
"comment": "No observable data found from playbook(s)."
}
}
},
"errors": {},
"id": "9",
"type": "utility",
"warnings": {},
"x": 280,
"y": 868
}
},
"notes": "Outputs:\nMarkdown note on cases\nMarks workbook task complete"
},
"input_spec": null,
"output_spec": [
{
"contains": [],
"datapaths": [],
"deduplicate": false,
"description": "",
"metadata": {},
"name": "observable"
}
],
"playbook_type": "automation",
"python_version": "3.13",
"schema": "5.0.9",
"version": "6.0.0.114895"
},
"create_time": "2023-05-19T13:56:00.984330+00:00",
"draft_mode": false,
"labels": [
"*"
],
"tags": [
"D3-IAA"
]
}