Files
splunk-security_content/playbooks/Identifier_Reputation_Analysis_Dispatch.yml
2023-04-12 12:29:59 -05:00

21 lines
936 B
YAML

name: Dispatch Identifier Reputation Analysis
id: fc0edc96-ff2b-48b0-9b4d-63da6783fd64
version: 1
date: '2023-01-11'
author: Kelby Shelton, Splunk
type: Investigation
description: "Detects available indicators and routes them to indicator reputation analysis playbooks. The output of the analysis will update any artifacts, tasks, and indicator tags. https://d3fend.mitre.org/technique/d3f:IdentifierReputationAnalysis/"
playbook: Dispatch_Identifier_Reputation_Analysis
how_to_implement: This playbook looks for artifacts and then dispatches the community Reputation playbooks. This playbook takes the output of those playbooks and nicely formats them into notes and tags indicators with their results.
references:
- https://d3fend.mitre.org/technique/d3f:IdentifierReputationAnalysis/
app_list: []
tags:
platform_tags:
- D3-IRA
playbook_type: Automation
vpe_type: Modern
playbook_fields: []
product:
- Splunk SOAR