mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3809 lines
187 KiB
JSON
3809 lines
187 KiB
JSON
{
|
|
"blockly": false,
|
|
"blockly_xml": "<xml></xml>",
|
|
"category": "Use Cases",
|
|
"misc": { "apps_list": ["Palo Alto Networks Firewall", "Carbon Black Response", "OpenDNS Umbrella", "Phantom"] },
|
|
"coa": {
|
|
"data": {
|
|
"clean": true,
|
|
"code_block": "",
|
|
"description": "This playbook retrieves IP addresses, domains, and file hashes, blocks them on various services, and adds them to specific blocklists as custom lists.",
|
|
"hash": "753b457bfed5fa341dd36803c11b681681df46f6",
|
|
"joint": {
|
|
"cells": [
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "70140aee-e625-43c7-bf11-da4d1bc729c1",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "81b07a3a-01ac-4d3a-b254-9cb7a3e97392",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 27
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "8f7b00cd-6206-4e1f-a1fd-c17ca7df99d1",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "d230871e-ee71-44a6-af7f-fb4f2f584da4",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 43
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "d333fcd2-eb73-4914-8e92-ad8551a6b068",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "ea4b2594-8ef5-42a4-8285-125126536531",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 66
|
|
},
|
|
{
|
|
"0": "S",
|
|
"1": "T",
|
|
"2": "A",
|
|
"3": "R",
|
|
"4": "T",
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"ref-x": 33,
|
|
"ref-y": 8,
|
|
"text": "START"
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"ref-x": 13,
|
|
"xlink:href": "/inc/coa/img/block_icon_start.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
}
|
|
},
|
|
"block_code": "def on_start(container):\n phantom.debug('on_start() called')\n \n # call 'filter_1' block\n filter_1(container=container)\n\n # call 'filter_2' block\n filter_2(container=container)\n\n # call 'filter_3' block\n filter_3(container=container)\n\n return",
|
|
"callback_code": "# read-only block view not available",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "0aa8e6f7-9c21-41b7-8930-8c2416a0509a",
|
|
"inPorts": [],
|
|
"join_code": "# read-only block view not available",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 22,
|
|
"line_start": 8,
|
|
"name": "",
|
|
"notes": "",
|
|
"number": 0,
|
|
"order": 1,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 180,
|
|
"y": 40
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 54,
|
|
"width": 80
|
|
},
|
|
"status": "",
|
|
"title": "START",
|
|
"type": "coa.StartEnd",
|
|
"warn": false,
|
|
"z": 95
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "f157b9dd-877a-4fbe-94c7-7709af7c1ceb",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "81b07a3a-01ac-4d3a-b254-9cb7a3e97392",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "9537d314-97d6-484b-ae20-3d9564bab6d6",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 160
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "98116e8f-35f5-4a4d-b09d-f2f254b3f36a",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "9537d314-97d6-484b-ae20-3d9564bab6d6",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "7a912b77-6a81-421d-b6f5-d865b3fffd73",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 177
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "ea7e5f03-8b63-43f5-a2cb-1adf63b89c88",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "7a912b77-6a81-421d-b6f5-d865b3fffd73",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "08306503-f5d1-4cd0-b32b-90a7670ff1ca",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 190
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "429dcfde-c34b-40f8-9b0b-9614e6f0cb75",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "08306503-f5d1-4cd0-b32b-90a7670ff1ca",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "7d6e7306-cd84-4798-bb84-804b79fb09ef",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 250
|
|
},
|
|
{
|
|
"0": "E",
|
|
"1": "N",
|
|
"2": "D",
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "END"
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_end.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
}
|
|
},
|
|
"block_code": "def on_finish(container, summary):\n phantom.debug('on_finish() called')\n # This function is called after all actions are completed.\n # summary of all the action and/or all details of actions\n # can be collected here.\n\n # summary_json = phantom.get_summary()\n # if 'result' in summary_json:\n # for action_result in summary_json['result']:\n # if 'action_run_id' in action_result:\n # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False)\n # phantom.debug(action_results)\n\n return",
|
|
"callback_code": "# read-only block view not available",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "add to IP blocklist, add to domain blocklist, add to hash blocklist",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "7d6e7306-cd84-4798-bb84-804b79fb09ef",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "# read-only block view not available",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 297,
|
|
"line_start": 284,
|
|
"name": "",
|
|
"notes": "",
|
|
"number": 0,
|
|
"order": 14,
|
|
"outPorts": [],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 1080,
|
|
"y": 40
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 54,
|
|
"width": 80
|
|
},
|
|
"status": "",
|
|
"title": "END",
|
|
"type": "coa.StartEnd",
|
|
"warn": false,
|
|
"z": 264
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "f19bbeed-6445-4a8c-bc7c-a2171961cf69",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "d230871e-ee71-44a6-af7f-fb4f2f584da4",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "7862d46c-23ea-4cda-9ef9-db171fd5ac93",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 277
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "8b252e02-8361-4d12-8663-61c2e8965ed9",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "7862d46c-23ea-4cda-9ef9-db171fd5ac93",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "6ad60d9d-90e4-4515-9931-05f31cc5f87a",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 286
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "fddf6767-1020-4c4e-9178-5bdcc37ef938",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "ea4b2594-8ef5-42a4-8285-125126536531",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "25ad9a87-018a-440b-a48d-3a0bd95226f6",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 288
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "ea23ca12-a7c3-40e3-b38c-67a92493b1b8",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "25ad9a87-018a-440b-a48d-3a0bd95226f6",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "45d563b4-3a4a-4cc8-bf1f-dfe4de434928",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 293
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "778389f4-851e-4b64-b5c1-e567e1277660",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "6ad60d9d-90e4-4515-9931-05f31cc5f87a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "1924c418-d049-478e-8cfd-ec94eb22f7c6",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 295
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "a111892b-a198-4573-9271-5f68da45f08d",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "1924c418-d049-478e-8cfd-ec94eb22f7c6",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "7d6e7306-cd84-4798-bb84-804b79fb09ef",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 297
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "c17d4063-43db-4dc2-9ec2-b9c554f1a1f8",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "45d563b4-3a4a-4cc8-bf1f-dfe4de434928",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "dced0e6a-538a-4d02-800a-5e5c0caf92f7",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 301
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#6C7A89",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#6a6c8a",
|
|
"stroke": "#6a6c8a"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "0b7d5584-b8cd-47e6-8f0b-455358f4b318",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "dced0e6a-538a-4d02-800a-5e5c0caf92f7",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "7d6e7306-cd84-4798-bb84-804b79fb09ef",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 303
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".border": {
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 1
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def filter_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_1() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"artifact:*.cef.destinationAddress\", \"!=\", \"\"],\n ],\n name=\"filter_1:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n filter_4(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "81b07a3a-01ac-4d3a-b254-9cb7a3e97392",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 264,
|
|
"line_start": 247,
|
|
"name": "filter",
|
|
"notes": "Filtering on artifacts that have the destinationAddress CEF value populated.",
|
|
"number": 1,
|
|
"order": 12,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "!=",
|
|
"data_type": "",
|
|
"param": "artifact:*.cef.destinationAddress",
|
|
"value": ""
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 320,
|
|
"y": 20
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "filter_1",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "filter",
|
|
"status": "",
|
|
"type": "coa.Filter",
|
|
"warn": false,
|
|
"z": 404
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".border": {
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 3
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def filter_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_3() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"artifact:*.cef.fileHash\", \"!=\", \"\"],\n ],\n name=\"filter_3:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n filter_6(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "ea4b2594-8ef5-42a4-8285-125126536531",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 123,
|
|
"line_start": 106,
|
|
"name": "filter",
|
|
"notes": "Filtering on artifacts that have the destinationDnsDomain CEF value populated.",
|
|
"number": 3,
|
|
"order": 6,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "!=",
|
|
"data_type": "",
|
|
"param": "artifact:*.cef.fileHash",
|
|
"value": ""
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 320,
|
|
"y": 300
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "filter_3",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "filter",
|
|
"status": "",
|
|
"type": "coa.Filter",
|
|
"warn": false,
|
|
"z": 412
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".border": {
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 2
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_2() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"artifact:*.cef.destinationDnsDomain\", \"!=\", \"\"],\n ],\n name=\"filter_2:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n filter_5(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "d230871e-ee71-44a6-af7f-fb4f2f584da4",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 106,
|
|
"line_start": 89,
|
|
"name": "filter",
|
|
"notes": "Filtering on artifacts that have the destinationDnsDomain CEF value populated.",
|
|
"number": 2,
|
|
"order": 5,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "!=",
|
|
"data_type": "",
|
|
"param": "artifact:*.cef.destinationDnsDomain",
|
|
"value": ""
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 320,
|
|
"y": 160
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "filter_2",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "filter",
|
|
"status": "",
|
|
"type": "coa.Filter",
|
|
"warn": false,
|
|
"z": 416
|
|
},
|
|
{
|
|
"action": "add listitem",
|
|
"action_type": "generic",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"create": "True",
|
|
"list": "custom_list:domain_blocklist",
|
|
"new_row": "block_domain_1:action_result.parameter.domain"
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "add listitem",
|
|
"actions": [
|
|
"no op",
|
|
"update list",
|
|
"get action result",
|
|
"create container",
|
|
"import container",
|
|
"export container",
|
|
"deflate item",
|
|
"add artifact",
|
|
"find listitem",
|
|
"add listitem",
|
|
"find artifacts",
|
|
"update artifact tags",
|
|
"add note",
|
|
"update artifact",
|
|
"test connectivity"
|
|
],
|
|
"active": true,
|
|
"app_name": "Phantom",
|
|
"app_version": "3.0.2",
|
|
"appid": "deb82aa9-22cc-4675-9cf1-534b8d006eb7",
|
|
"asset_name": "phantom",
|
|
"config_type": "asset",
|
|
"count": 0,
|
|
"fields": {
|
|
"create": "True",
|
|
"list": "custom_list:domain_blocklist",
|
|
"new_row": "block_domain_1:action_result.parameter.domain"
|
|
},
|
|
"has_app": true,
|
|
"id": 16,
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "phantom",
|
|
"output": [
|
|
{
|
|
"column_name": "Status",
|
|
"column_order": 0,
|
|
"data_path": "action_result.status",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"success",
|
|
"failed"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.create",
|
|
"data_type": "boolean",
|
|
"example_values": [
|
|
true,
|
|
false
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.list",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"demo_list"
|
|
]
|
|
},
|
|
{
|
|
"contains": [
|
|
"*"
|
|
],
|
|
"data_path": "action_result.parameter.new_row",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"[\"value1\",\"value2\",\"value3\"]"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.data.*.failed",
|
|
"data_type": "boolean"
|
|
},
|
|
{
|
|
"data_path": "action_result.data.*.success",
|
|
"data_type": "boolean",
|
|
"example_values": [
|
|
true,
|
|
false
|
|
]
|
|
},
|
|
{
|
|
"contains": [
|
|
"url"
|
|
],
|
|
"data_path": "action_result.summary.server",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"https://10.1.1.10"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.message",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"Server: https://10.1.1.10"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
}
|
|
],
|
|
"parameters": {
|
|
"create": {
|
|
"data_type": "boolean",
|
|
"default": false,
|
|
"description": "Create list if it does not exist (default: false)",
|
|
"key": "create",
|
|
"order": 2,
|
|
"required": false
|
|
},
|
|
"list": {
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "Name or ID of a custom list",
|
|
"key": "list",
|
|
"order": 0,
|
|
"required": true
|
|
},
|
|
"new_row": {
|
|
"contains": [
|
|
"*"
|
|
],
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "New Row (string or JSON list)",
|
|
"key": "new_row",
|
|
"order": 1,
|
|
"primary": true,
|
|
"required": true
|
|
}
|
|
},
|
|
"product_name": "Phantom",
|
|
"product_vendor": "Phantom",
|
|
"targets": "16",
|
|
"type": "information"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "add to domain blocklist"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".border": {
|
|
"height": 88,
|
|
"opacity": 1,
|
|
"stroke": "#E6984E"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"fill": "#FFFFFF",
|
|
"font-size": 12,
|
|
"font-weight": 300,
|
|
"opacity": 0,
|
|
"ref": ".background",
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Generic"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_generic.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
},
|
|
"rect.warn-background": {
|
|
"fill": "#E6984E"
|
|
},
|
|
"text.icon": {
|
|
"fill": "#E6984E"
|
|
}
|
|
},
|
|
"block_code": "def add_to_domain_blocklist(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_to_domain_blocklist() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'add_to_domain_blocklist' call\n results_data_1 = phantom.collect2(container=container, datapath=['block_domain_1:action_result.parameter.domain', 'block_domain_1:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'add_to_domain_blocklist' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'list': \"custom_list:domain_blocklist\",\n 'create': True,\n 'new_row': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"add listitem\", parameters=parameters, assets=['phantom'], name=\"add_to_domain_blocklist\", parent_action=action)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "#5094D4",
|
|
"connected_to_start": true,
|
|
"connection_name": "block domain",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "add to domain blocklist",
|
|
"delay": 0,
|
|
"description": "The domain is added to the custom list 'domain_blocklist' in order to prevent the Playbook from attempting to block a domain that has already been blocked.",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "1924c418-d049-478e-8cfd-ec94eb22f7c6",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 219,
|
|
"line_start": 194,
|
|
"message": "Configuring now",
|
|
"name": "add listitem",
|
|
"notes": "The domain is added to the custom list 'domain_blocklist' in order to prevent the Playbook from attempting to block a domain that has already been blocked.",
|
|
"number": 2,
|
|
"order": 10,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 840,
|
|
"y": 160
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "add_to_domain_blocklist",
|
|
"required_params": {
|
|
"list": true,
|
|
"new_row": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 112,
|
|
"width": 168
|
|
},
|
|
"state": "action_assets",
|
|
"status": "",
|
|
"title": "Generic",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 421
|
|
},
|
|
{
|
|
"action": "block hash",
|
|
"action_type": "contain",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"comment": "",
|
|
"hash": "filtered-data:filter_6:condition_1:artifact:*.cef.fileHash"
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "",
|
|
"active": true,
|
|
"app_name": "",
|
|
"app_version": "",
|
|
"appid": "",
|
|
"config_type": "asset",
|
|
"fields": {
|
|
"comment": "",
|
|
"hash": "filtered-data:filter_6:condition_1:artifact:*.cef.fileHash"
|
|
},
|
|
"has_app": true,
|
|
"id": "-",
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "carbonblack",
|
|
"output": [
|
|
{
|
|
"data_path": "action_result.status",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"success"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.comment",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"Sample comment"
|
|
]
|
|
},
|
|
{
|
|
"column_name": "Hash",
|
|
"column_order": 0,
|
|
"contains": [
|
|
"md5",
|
|
"hash"
|
|
],
|
|
"data_path": "action_result.parameter.hash",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"180469AE0B239E31DB4C65F02FD70BC1"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.data",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "action_result.summary",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"column_name": "Message",
|
|
"column_order": 1,
|
|
"data_path": "action_result.message",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"Block hash action succeeded. It might take some time for blacklisting to take effect."
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
}
|
|
],
|
|
"product_name": "",
|
|
"product_vendor": "",
|
|
"type": "endpoint"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "block hash"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".border": {
|
|
"height": 88,
|
|
"opacity": 1,
|
|
"stroke": "#E6984E"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"fill": "#FFFFFF",
|
|
"font-size": 12,
|
|
"font-weight": 300,
|
|
"opacity": 0,
|
|
"ref": ".background",
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Contain"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_contain.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
},
|
|
"rect.warn-background": {
|
|
"fill": "#E6984E"
|
|
},
|
|
"text.icon": {
|
|
"fill": "#E6984E"
|
|
}
|
|
},
|
|
"block_code": "def block_hash_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_hash_2() called')\n\n # collect data for 'block_hash_2' call\n filtered_artifacts_data_1 = phantom.collect2(container=container, datapath=['filtered-data:filter_6:condition_1:artifact:*.cef.fileHash', 'filtered-data:filter_6:condition_1:artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'block_hash_2' call\n for filtered_artifacts_item_1 in filtered_artifacts_data_1:\n if filtered_artifacts_item_1[0]:\n parameters.append({\n 'hash': filtered_artifacts_item_1[0],\n 'comment': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_artifacts_item_1[1]},\n })\n\n phantom.act(action=\"block hash\", parameters=parameters, assets=['carbonblack'], callback=add_to_hash_blocklist, name=\"block_hash_2\")\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "#3D9959",
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"delay": 0,
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "45d563b4-3a4a-4cc8-bf1f-dfe4de434928",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 67,
|
|
"line_start": 45,
|
|
"message": "Configuring now",
|
|
"name": "block hash",
|
|
"notes": "Blocks the hash utilizing the CarbonBlack Response endpoint technology app, preventing the process from running on endpoints utilizing CarbonBlack Response.",
|
|
"number": 2,
|
|
"order": 3,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 600,
|
|
"y": 300
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "block_hash_2",
|
|
"required_params": {
|
|
"hash": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": false,
|
|
"size": {
|
|
"height": 112,
|
|
"width": 168
|
|
},
|
|
"state": "asset",
|
|
"status": "",
|
|
"title": "Contain",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 423
|
|
},
|
|
{
|
|
"action": "block domain",
|
|
"action_type": "contain",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"disable_safeguards": "",
|
|
"domain": "filtered-data:filter_5:condition_1:artifact:*.cef.destinationDnsDomain"
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "",
|
|
"active": true,
|
|
"app_name": "",
|
|
"app_version": "",
|
|
"appid": "",
|
|
"config_type": "asset",
|
|
"fields": {
|
|
"disable_safeguards": "",
|
|
"domain": "filtered-data:filter_5:condition_1:artifact:*.cef.destinationDnsDomain"
|
|
},
|
|
"has_app": true,
|
|
"id": "-",
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "opendns_umbrella",
|
|
"output": [
|
|
{
|
|
"column_name": "Status",
|
|
"column_order": 1,
|
|
"data_path": "action_result.status",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.disable_safeguards",
|
|
"data_type": "boolean"
|
|
},
|
|
{
|
|
"column_name": "Domain",
|
|
"column_order": 0,
|
|
"contains": [
|
|
"domain"
|
|
],
|
|
"data_path": "action_result.parameter.domain",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "action_result.message",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"column_name": "ID",
|
|
"column_order": 2,
|
|
"data_path": "action_result.data.*.id",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric"
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric"
|
|
}
|
|
],
|
|
"product_name": "",
|
|
"product_vendor": "",
|
|
"type": "endpoint"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "block domain"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".border": {
|
|
"height": 88,
|
|
"opacity": 1,
|
|
"stroke": "#E6984E"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"fill": "#FFFFFF",
|
|
"font-size": 12,
|
|
"font-weight": 300,
|
|
"opacity": 0,
|
|
"ref": ".background",
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Contain"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_contain.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
},
|
|
"rect.warn-background": {
|
|
"fill": "#E6984E"
|
|
},
|
|
"text.icon": {
|
|
"fill": "#E6984E"
|
|
}
|
|
},
|
|
"block_code": "def block_domain_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_domain_1() called')\n\n # collect data for 'block_domain_1' call\n filtered_artifacts_data_1 = phantom.collect2(container=container, datapath=['filtered-data:filter_5:condition_1:artifact:*.cef.destinationDnsDomain', 'filtered-data:filter_5:condition_1:artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'block_domain_1' call\n for filtered_artifacts_item_1 in filtered_artifacts_data_1:\n if filtered_artifacts_item_1[0]:\n parameters.append({\n 'domain': filtered_artifacts_item_1[0],\n 'disable_safeguards': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_artifacts_item_1[1]},\n })\n\n phantom.act(action=\"block domain\", parameters=parameters, assets=['opendns_umbrella'], callback=add_to_domain_blocklist, name=\"block_domain_1\")\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "#3D9959",
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"delay": 0,
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "6ad60d9d-90e4-4515-9931-05f31cc5f87a",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 89,
|
|
"line_start": 67,
|
|
"message": "Configuring now",
|
|
"name": "block domain",
|
|
"notes": "Blocks a domain utilizing the OpenDNS Umbrella app, preventing endpoints from accessing the domain from within the network.",
|
|
"number": 1,
|
|
"order": 4,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 600,
|
|
"y": 160
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "block_domain_1",
|
|
"required_params": {
|
|
"domain": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": false,
|
|
"size": {
|
|
"height": 112,
|
|
"width": 168
|
|
},
|
|
"state": "asset",
|
|
"status": "",
|
|
"title": "Contain",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 424
|
|
},
|
|
{
|
|
"action": "block ip",
|
|
"action_type": "contain",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"ip": "filtered-data:filter_4:condition_1:artifact:*.cef.destinationAddress",
|
|
"is_source_address": "",
|
|
"vsys": ""
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "",
|
|
"active": true,
|
|
"app_name": "",
|
|
"app_version": "",
|
|
"appid": "",
|
|
"config_type": "asset",
|
|
"fields": {
|
|
"ip": "filtered-data:filter_4:condition_1:artifact:*.cef.destinationAddress",
|
|
"is_source_address": "",
|
|
"vsys": ""
|
|
},
|
|
"has_app": true,
|
|
"id": "-",
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "pan",
|
|
"output": [
|
|
{
|
|
"column_name": "IP",
|
|
"column_order": 0,
|
|
"contains": [
|
|
"ip"
|
|
],
|
|
"data_path": "action_result.parameter.ip",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.vsys",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.is_source_address",
|
|
"data_type": "boolean"
|
|
},
|
|
{
|
|
"column_name": "Status",
|
|
"column_order": 1,
|
|
"data_path": "action_result.status",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"column_name": "Message",
|
|
"column_order": 2,
|
|
"data_path": "action_result.message",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric"
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric"
|
|
}
|
|
],
|
|
"product_name": "",
|
|
"product_vendor": "",
|
|
"type": "firewall"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "block ip"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".border": {
|
|
"height": 88,
|
|
"opacity": 1,
|
|
"stroke": "#E6984E"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"fill": "#FFFFFF",
|
|
"font-size": 12,
|
|
"font-weight": 300,
|
|
"opacity": 0,
|
|
"ref": ".background",
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Contain"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_contain.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
},
|
|
"rect.warn-background": {
|
|
"fill": "#E6984E"
|
|
},
|
|
"text.icon": {
|
|
"fill": "#E6984E"
|
|
}
|
|
},
|
|
"block_code": "def block_ip_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_ip_1() called')\n\n # collect data for 'block_ip_1' call\n filtered_artifacts_data_1 = phantom.collect2(container=container, datapath=['filtered-data:filter_4:condition_1:artifact:*.cef.destinationAddress', 'filtered-data:filter_4:condition_1:artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'block_ip_1' call\n for filtered_artifacts_item_1 in filtered_artifacts_data_1:\n if filtered_artifacts_item_1[0]:\n parameters.append({\n 'ip': filtered_artifacts_item_1[0],\n 'vsys': \"\",\n 'is_source_address': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_artifacts_item_1[1]},\n })\n\n phantom.act(action=\"block ip\", parameters=parameters, assets=['pan'], callback=add_to_IP_blocklist, name=\"block_ip_1\")\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "#3D9959",
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"delay": 0,
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "7a912b77-6a81-421d-b6f5-d865b3fffd73",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 45,
|
|
"line_start": 22,
|
|
"message": "Configuring now",
|
|
"name": "block ip",
|
|
"notes": "Blocks the IP as a destination address, utilizing the Palo Alto Networks Firewall app to prevent further access to the IP address as a destination.",
|
|
"number": 1,
|
|
"order": 2,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 600,
|
|
"y": 20
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "block_ip_1",
|
|
"required_params": {
|
|
"ip": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": false,
|
|
"size": {
|
|
"height": 112,
|
|
"width": 168
|
|
},
|
|
"state": "asset",
|
|
"status": "",
|
|
"title": "Contain",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 425
|
|
},
|
|
{
|
|
"action": "add listitem",
|
|
"action_type": "generic",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"create": "True",
|
|
"list": "custom_list:filehash_blocklist",
|
|
"new_row": "block_hash_2:action_result.parameter.hash"
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "add listitem",
|
|
"actions": [
|
|
"no op",
|
|
"update list",
|
|
"get action result",
|
|
"create container",
|
|
"import container",
|
|
"export container",
|
|
"deflate item",
|
|
"add artifact",
|
|
"find listitem",
|
|
"add listitem",
|
|
"find artifacts",
|
|
"update artifact tags",
|
|
"add note",
|
|
"update artifact",
|
|
"test connectivity"
|
|
],
|
|
"active": true,
|
|
"app_name": "Phantom",
|
|
"app_version": "3.0.2",
|
|
"appid": "deb82aa9-22cc-4675-9cf1-534b8d006eb7",
|
|
"asset_name": "phantom",
|
|
"config_type": "asset",
|
|
"count": 0,
|
|
"fields": {
|
|
"create": "True",
|
|
"list": "custom_list:filehash_blocklist",
|
|
"new_row": "block_hash_2:action_result.parameter.hash"
|
|
},
|
|
"has_app": true,
|
|
"id": 16,
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "phantom",
|
|
"output": [
|
|
{
|
|
"column_name": "Status",
|
|
"column_order": 0,
|
|
"data_path": "action_result.status",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"success",
|
|
"failed"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.create",
|
|
"data_type": "boolean",
|
|
"example_values": [
|
|
true,
|
|
false
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.list",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"demo_list"
|
|
]
|
|
},
|
|
{
|
|
"contains": [
|
|
"*"
|
|
],
|
|
"data_path": "action_result.parameter.new_row",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"[\"value1\",\"value2\",\"value3\"]"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.data.*.failed",
|
|
"data_type": "boolean"
|
|
},
|
|
{
|
|
"data_path": "action_result.data.*.success",
|
|
"data_type": "boolean",
|
|
"example_values": [
|
|
true,
|
|
false
|
|
]
|
|
},
|
|
{
|
|
"contains": [
|
|
"url"
|
|
],
|
|
"data_path": "action_result.summary.server",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"https://10.1.1.10"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.message",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"Server: https://10.1.1.10"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
}
|
|
],
|
|
"parameters": {
|
|
"create": {
|
|
"data_type": "boolean",
|
|
"default": false,
|
|
"description": "Create list if it does not exist (default: false)",
|
|
"key": "create",
|
|
"order": 2,
|
|
"required": false
|
|
},
|
|
"list": {
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "Name or ID of a custom list",
|
|
"key": "list",
|
|
"order": 0,
|
|
"required": true
|
|
},
|
|
"new_row": {
|
|
"contains": [
|
|
"*"
|
|
],
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "New Row (string or JSON list)",
|
|
"key": "new_row",
|
|
"order": 1,
|
|
"primary": true,
|
|
"required": true
|
|
}
|
|
},
|
|
"product_name": "Phantom",
|
|
"product_vendor": "Phantom",
|
|
"targets": "16",
|
|
"type": "information"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "add to hash blocklist"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".border": {
|
|
"height": 88,
|
|
"opacity": 1,
|
|
"stroke": "#E6984E"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"fill": "#FFFFFF",
|
|
"font-size": 12,
|
|
"font-weight": 300,
|
|
"opacity": 0,
|
|
"ref": ".background",
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Generic"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_generic.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
},
|
|
"rect.warn-background": {
|
|
"fill": "#E6984E"
|
|
},
|
|
"text.icon": {
|
|
"fill": "#E6984E"
|
|
}
|
|
},
|
|
"block_code": "def add_to_hash_blocklist(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_to_hash_blocklist() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'add_to_hash_blocklist' call\n results_data_1 = phantom.collect2(container=container, datapath=['block_hash_2:action_result.parameter.hash', 'block_hash_2:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'add_to_hash_blocklist' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'list': \"custom_list:filehash_blocklist\",\n 'create': True,\n 'new_row': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"add listitem\", parameters=parameters, assets=['phantom'], name=\"add_to_hash_blocklist\", parent_action=action)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "#5094D4",
|
|
"connected_to_start": true,
|
|
"connection_name": "block hash",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "add to hash blocklist",
|
|
"delay": 0,
|
|
"description": "The file hash is added to the custom list 'filehash_blocklist' in order to prevent the Playbook from attempting to block a file hash that has already been blocked.",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "dced0e6a-538a-4d02-800a-5e5c0caf92f7",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 191,
|
|
"line_start": 166,
|
|
"message": "Configuring now",
|
|
"name": "add listitem",
|
|
"notes": "The file hash is added to the custom list 'filehash_blocklist' in order to prevent the Playbook from attempting to block a file hash that has already been blocked.",
|
|
"number": 3,
|
|
"order": 9,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 840,
|
|
"y": 300
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "add_to_hash_blocklist",
|
|
"required_params": {
|
|
"list": true,
|
|
"new_row": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 112,
|
|
"width": 168
|
|
},
|
|
"state": "action_assets",
|
|
"status": "",
|
|
"title": "Generic",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 426
|
|
},
|
|
{
|
|
"action": "add listitem",
|
|
"action_type": "generic",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"create": "True",
|
|
"list": "custom_list:ip_address_blocklist",
|
|
"new_row": "block_ip_1:action_result.parameter.ip"
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "add listitem",
|
|
"actions": [
|
|
"no op",
|
|
"update list",
|
|
"get action result",
|
|
"create container",
|
|
"import container",
|
|
"export container",
|
|
"deflate item",
|
|
"add artifact",
|
|
"find listitem",
|
|
"add listitem",
|
|
"find artifacts",
|
|
"update artifact tags",
|
|
"add note",
|
|
"update artifact",
|
|
"test connectivity"
|
|
],
|
|
"active": true,
|
|
"app_name": "Phantom",
|
|
"app_version": "3.0.2",
|
|
"appid": "deb82aa9-22cc-4675-9cf1-534b8d006eb7",
|
|
"asset_name": "phantom",
|
|
"config_type": "asset",
|
|
"count": 0,
|
|
"fields": {
|
|
"create": "True",
|
|
"list": "custom_list:ip_address_blocklist",
|
|
"new_row": "block_ip_1:action_result.parameter.ip"
|
|
},
|
|
"has_app": true,
|
|
"id": 16,
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "phantom",
|
|
"output": [
|
|
{
|
|
"column_name": "Status",
|
|
"column_order": 0,
|
|
"data_path": "action_result.status",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"success",
|
|
"failed"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.create",
|
|
"data_type": "boolean",
|
|
"example_values": [
|
|
true,
|
|
false
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.list",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"demo_list"
|
|
]
|
|
},
|
|
{
|
|
"contains": [
|
|
"*"
|
|
],
|
|
"data_path": "action_result.parameter.new_row",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"[\"value1\",\"value2\",\"value3\"]"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.data.*.failed",
|
|
"data_type": "boolean"
|
|
},
|
|
{
|
|
"data_path": "action_result.data.*.success",
|
|
"data_type": "boolean",
|
|
"example_values": [
|
|
true,
|
|
false
|
|
]
|
|
},
|
|
{
|
|
"contains": [
|
|
"url"
|
|
],
|
|
"data_path": "action_result.summary.server",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"https://10.1.1.10"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.message",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"Server: https://10.1.1.10"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
}
|
|
],
|
|
"parameters": {
|
|
"create": {
|
|
"data_type": "boolean",
|
|
"default": false,
|
|
"description": "Create list if it does not exist (default: false)",
|
|
"key": "create",
|
|
"order": 2,
|
|
"required": false
|
|
},
|
|
"list": {
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "Name or ID of a custom list",
|
|
"key": "list",
|
|
"order": 0,
|
|
"required": true
|
|
},
|
|
"new_row": {
|
|
"contains": [
|
|
"*"
|
|
],
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "New Row (string or JSON list)",
|
|
"key": "new_row",
|
|
"order": 1,
|
|
"primary": true,
|
|
"required": true
|
|
}
|
|
},
|
|
"product_name": "Phantom",
|
|
"product_vendor": "Phantom",
|
|
"targets": "16",
|
|
"type": "information"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "add to IP blocklist"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".border": {
|
|
"height": 88,
|
|
"opacity": 1,
|
|
"stroke": "#E6984E"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"fill": "#FFFFFF",
|
|
"font-size": 12,
|
|
"font-weight": 300,
|
|
"opacity": 0,
|
|
"ref": ".background",
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Generic"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_generic.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
},
|
|
"rect.warn-background": {
|
|
"fill": "#E6984E"
|
|
},
|
|
"text.icon": {
|
|
"fill": "#E6984E"
|
|
}
|
|
},
|
|
"block_code": "def add_to_IP_blocklist(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_to_IP_blocklist() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'add_to_IP_blocklist' call\n results_data_1 = phantom.collect2(container=container, datapath=['block_ip_1:action_result.parameter.ip', 'block_ip_1:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'add_to_IP_blocklist' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'list': \"custom_list:ip_address_blocklist\",\n 'create': True,\n 'new_row': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"add listitem\", parameters=parameters, assets=['phantom'], name=\"add_to_IP_blocklist\", parent_action=action)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "#5094D4",
|
|
"connected_to_start": true,
|
|
"connection_name": "block ip",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "add to IP blocklist",
|
|
"delay": 0,
|
|
"description": "The IP address is added to the custom list 'ip_address_blocklist' in order to prevent the Playbook from attempting to block an IP address that has already been blocked.",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "08306503-f5d1-4cd0-b32b-90a7670ff1ca",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 247,
|
|
"line_start": 222,
|
|
"message": "Configuring now",
|
|
"name": "add listitem",
|
|
"notes": "The IP address is added to the custom list 'ip_address_blocklist' in order to prevent the Playbook from attempting to block an IP address that has already been blocked.",
|
|
"number": 1,
|
|
"order": 11,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 840,
|
|
"y": 20
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "add_to_IP_blocklist",
|
|
"required_params": {
|
|
"list": true,
|
|
"new_row": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 112,
|
|
"width": 168
|
|
},
|
|
"state": "action_assets",
|
|
"status": "",
|
|
"title": "Generic",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 430
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".border": {
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 6
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def filter_6(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_6() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"filtered-data:filter_3:condition_1:artifact:*.cef.fileHash\", \"in\", \"custom_list:filehash_blocklist\"],\n ],\n name=\"filter_6:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n block_hash_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "Checking to see if this filehash is in the custom list called \"filehash_blocklist\"",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "25ad9a87-018a-440b-a48d-3a0bd95226f6",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 163,
|
|
"line_start": 146,
|
|
"name": "filter",
|
|
"notes": "Checking to see if this filehash is in the custom list called \"filehash_blocklist\"",
|
|
"number": 6,
|
|
"order": 8,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "in",
|
|
"data_type": "",
|
|
"param": "filtered-data:filter_3:condition_1:artifact:*.cef.fileHash",
|
|
"value": "custom_list:filehash_blocklist"
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 460,
|
|
"y": 300
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "filter_6",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "filter",
|
|
"status": "",
|
|
"type": "coa.Filter",
|
|
"warn": false,
|
|
"z": 432
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".border": {
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 5
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def filter_5(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_5() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"filtered-data:filter_2:condition_1:artifact:*.cef.destinationDnsDomain\", \"in\", \"custom_list:domain_blocklist\"],\n ],\n name=\"filter_5:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n block_domain_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "Checking to see if this domain address is in the custom list called \"domain_blocklist\"",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "7862d46c-23ea-4cda-9ef9-db171fd5ac93",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 143,
|
|
"line_start": 126,
|
|
"name": "filter",
|
|
"notes": "Checking to see if this domain address is in the custom list called \"domain_blocklist\"",
|
|
"number": 5,
|
|
"order": 7,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "in",
|
|
"data_type": "",
|
|
"param": "filtered-data:filter_2:condition_1:artifact:*.cef.destinationDnsDomain",
|
|
"value": "custom_list:domain_blocklist"
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 460,
|
|
"y": 160
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "filter_5",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "filter",
|
|
"status": "",
|
|
"type": "coa.Filter",
|
|
"warn": false,
|
|
"z": 433
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".border": {
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 4
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.notes": {
|
|
"display": "block",
|
|
"opacity": 1
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def filter_4(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_4() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n conditions=[\n [\"filtered-data:filter_1:condition_1:artifact:*.cef.destinationAddress\", \"not in\", \"custom_list:ip_address_blocklist\"],\n ],\n name=\"filter_4:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n block_ip_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "Checking to see if this IP address is in the custom list called \"ip_address_blocklist\"",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "9537d314-97d6-484b-ae20-3d9564bab6d6",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 284,
|
|
"line_start": 267,
|
|
"name": "filter",
|
|
"notes": "Checking to see if this IP address is in the custom list called \"ip_address_blocklist\"",
|
|
"number": 4,
|
|
"order": 13,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "not in",
|
|
"data_type": "",
|
|
"param": "filtered-data:filter_1:condition_1:artifact:*.cef.destinationAddress",
|
|
"value": "custom_list:ip_address_blocklist"
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 460,
|
|
"y": 20
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "filter_4",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "filter",
|
|
"status": "",
|
|
"type": "coa.Filter",
|
|
"warn": false,
|
|
"z": 434
|
|
}
|
|
]
|
|
},
|
|
"notes": "This playbook uses the following Apps: \n\n- Palo Alto Networks Firewall (PAN)\n- CarbonBlack Response\n- OpenDNS Umbrella\n\nThis playbook uses the following custom list:\n\n- ip_address_blocklist\n- domain_blocklist\n- filehash_blocklist\n\nThis playbook provides an easy, automated, and straightforward solution to maintaining up-to-date IP address, file, and domain blocklists. The process is:\n\nEach Artifact within an event is checked for the presence of the following CEF fields:\nDestinationDnsDomain - Domains\nDestinationAddress - IP addresses\nFileHash - Files\nThe CEF value is then cross-referenced with their respective Custom Lists.\nIP addresses are blocked on a Firewall, while domains are blocked using a blocklist service. The blocking of these two will prevent access to the IOCs. Finally, file hashes are blocked using an endpoint protection service, which will prevent the process from running on affected endpoints within a network.\nAfter the IOCs are blocked using various apps, they are added to their respective custom lists as to maintain a running blocklist record."
|
|
},
|
|
"python_version": "3",
|
|
"schema": 4,
|
|
"version": "4.10.0.40961"
|
|
},
|
|
"create_time": "2021-01-21T21:26:58.710395+00:00",
|
|
"draft_mode": false,
|
|
"labels": [
|
|
"events"
|
|
],
|
|
"tags": []
|
|
}
|