mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
21 lines
867 B
YAML
21 lines
867 B
YAML
name: Identifier Reputation Analysis Dispatch
|
|
id: fc0edc96-ff2b-48b0-9b4d-63da6783fd64
|
|
version: 1
|
|
date: '2023-01-11'
|
|
author: Kelby Shelton, Splunk
|
|
type: Investigation
|
|
description: "Detects available indicators and routes them to indicator reputation analysis playbooks. The output of the analysis will update any artifacts, tasks, and indicator tags."
|
|
playbook: Identifier_Reputation_Analysis Dispatch
|
|
how_to_implement: This playbook looks for artifacts and then dispatches the community Reputation playbooks. This playbook takes the output of those playbooks and nicely formats them into notes and tags indicators with their results.
|
|
references:
|
|
- https://d3fend.mitre.org/technique/d3f:IdentifierReputationAnalysis/
|
|
app_list: []
|
|
tags:
|
|
platform_tags:
|
|
- D3-IRA
|
|
playbook_type: Automation
|
|
vpe_type: Modern
|
|
playbook_fields: []
|
|
product:
|
|
- Splunk SOAR
|