Files
splunk-security_content/playbooks/crowdstrike_malware_triage.yml
2026-05-19 11:12:49 -07:00

22 lines
1.1 KiB
YAML

name: Crowdstrike Malware Triage
id: fc0edc96-fa2b-48b0-9a6f-63da6783fd63
version: 2
creation_date: '2021-12-08'
modification_date: '2026-05-19'
author: Philip Royer, Splunk
type: Response
description: This playbook is used to enrich and respond to a CrowdStrike Falcon detection involving a potentially malicious executable on an endpoint. Check for previous sightings of the same executable, hunt across other endpoints for the file, gather details about all processes associated with the file, and collect all the gathered information into a prompt for an analyst to review. Based on the analyst's choice, the file can be added to the custom indicators list in CrowdStrike with a detection policy of "detect" or "none", and the endpoint can be optionally quarantined from the network.
playbook: crowdstrike_malware_triage
how_to_implement: This playbook uses the Crowdstrike OAuth app. Change the target user of the prompt from admin to the appropriate user or role.
references: []
app_list:
- CrowdStrike OAuth API
platform_tags: []
playbook_type: Automation
vpe_type: Classic
playbook_fields:
- filePath
- destinationAddress
product:
- Splunk SOAR