Skip to content

Commit 86feb04

Browse files
fixes for the playbook (#40643)
* fixes for the playbook * rn added * added dec * fix
1 parent a8db23b commit 86feb04

File tree

3 files changed

+168
-39
lines changed

3 files changed

+168
-39
lines changed

Packs/CortexResponseAndRemediation/Playbooks/silent-playbook-A_user_created_a_pfx_in_a_suspicious_folder_for_the_first_time.yml

Lines changed: 164 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ tasks:
2727
view: |-
2828
{
2929
"position": {
30-
"x": 450,
31-
"y": 61
30+
"x": 459,
31+
"y": -77
3232
}
3333
}
3434
note: false
@@ -58,8 +58,8 @@ tasks:
5858
view: |-
5959
{
6060
"position": {
61-
"x": 450,
62-
"y": 173
61+
"x": 459,
62+
"y": 35
6363
}
6464
}
6565
note: false
@@ -95,8 +95,8 @@ tasks:
9595
view: |-
9696
{
9797
"position": {
98-
"x": 450,
99-
"y": 276
98+
"x": 459,
99+
"y": 138
100100
}
101101
}
102102
note: false
@@ -127,8 +127,8 @@ tasks:
127127
view: |-
128128
{
129129
"position": {
130-
"x": 450,
131-
"y": 394
130+
"x": 459,
131+
"y": 256
132132
}
133133
}
134134
note: false
@@ -162,8 +162,8 @@ tasks:
162162
view: |-
163163
{
164164
"position": {
165-
"x": 670,
166-
"y": 1148
165+
"x": 682,
166+
"y": 1234
167167
}
168168
}
169169
note: false
@@ -197,8 +197,8 @@ tasks:
197197
view: |-
198198
{
199199
"position": {
200-
"x": 670,
201-
"y": 1011
200+
"x": 682,
201+
"y": 1112
202202
}
203203
}
204204
note: false
@@ -222,14 +222,14 @@ tasks:
222222
description: ''
223223
nexttasks:
224224
'#none#':
225-
- "13"
225+
- "43"
226226
separatecontext: false
227227
continueonerrortype: ""
228228
view: |-
229229
{
230230
"position": {
231-
"x": 670,
232-
"y": 514
231+
"x": 682,
232+
"y": 376
233233
}
234234
}
235235
note: false
@@ -260,7 +260,7 @@ tasks:
260260
{
261261
"position": {
262262
"x": 228,
263-
"y": 514
263+
"y": 376
264264
}
265265
}
266266
note: false
@@ -297,7 +297,7 @@ tasks:
297297
{
298298
"position": {
299299
"x": 228,
300-
"y": 644
300+
"y": 484
301301
}
302302
}
303303
note: false
@@ -349,7 +349,7 @@ tasks:
349349
{
350350
"position": {
351351
"x": 228,
352-
"y": 1148
352+
"y": 1127
353353
}
354354
}
355355
note: false
@@ -391,8 +391,8 @@ tasks:
391391
view: |-
392392
{
393393
"position": {
394-
"x": 670,
395-
"y": 644
394+
"x": 682,
395+
"y": 606
396396
}
397397
}
398398
note: false
@@ -417,7 +417,7 @@ tasks:
417417
brand: ""
418418
nexttasks:
419419
'#none#':
420-
- "15"
420+
- "44"
421421
scriptarguments:
422422
key:
423423
simple: SuspiciousCommandLines
@@ -451,8 +451,8 @@ tasks:
451451
view: |-
452452
{
453453
"position": {
454-
"x": 670,
455-
"y": 769
454+
"x": 682,
455+
"y": 731
456456
}
457457
}
458458
note: false
@@ -486,8 +486,8 @@ tasks:
486486
view: |-
487487
{
488488
"position": {
489-
"x": 670,
490-
"y": 892
489+
"x": 682,
490+
"y": 983
491491
}
492492
}
493493
note: false
@@ -671,7 +671,7 @@ tasks:
671671
{
672672
"position": {
673673
"x": 228,
674-
"y": 1011
674+
"y": 995
675675
}
676676
}
677677
note: false
@@ -706,7 +706,7 @@ tasks:
706706
{
707707
"position": {
708708
"x": 228,
709-
"y": 769
709+
"y": 609
710710
}
711711
}
712712
note: false
@@ -733,8 +733,8 @@ tasks:
733733
view: |-
734734
{
735735
"position": {
736-
"x": 28,
737-
"y": 1274
736+
"x": -55,
737+
"y": 1258
738738
}
739739
}
740740
note: false
@@ -751,25 +751,28 @@ tasks:
751751
task:
752752
id: 00147d5b-75bc-4aa5-8c39-089122952851
753753
version: -1
754-
name: Extract PFX from ZIP
754+
name: Extract PFX from ZIP using 7zip
755755
description: Unzip a file using fileName or entryID to specify a file. Unzipped files will be loaded to the War Room and names will be put into the context.
756756
scriptName: UnzipFile
757757
type: regular
758758
iscommand: false
759759
brand: ""
760760
nexttasks:
761+
'#error#':
762+
- "45"
761763
'#none#':
762764
- "19"
763765
scriptarguments:
764766
entryID:
765767
simple: ${File.EntryID}
766768
separatecontext: false
767-
continueonerrortype: ""
769+
continueonerror: true
770+
continueonerrortype: errorPath
768771
view: |-
769772
{
770773
"position": {
771774
"x": 228,
772-
"y": 892
775+
"y": 731
773776
}
774777
}
775778
note: false
@@ -1284,27 +1287,150 @@ tasks:
12841287
quietmode: 0
12851288
isoversize: false
12861289
isautoswitchedtoquietmode: false
1290+
"43":
1291+
id: "43"
1292+
taskid: a5ebfd37-bd9b-4611-9338-a759db5e7452
1293+
type: condition
1294+
task:
1295+
id: a5ebfd37-bd9b-4611-9338-a759db5e7452
1296+
version: -1
1297+
name: 'Is there a command line? '
1298+
description: 'Check if the command line exists. '
1299+
type: condition
1300+
iscommand: false
1301+
brand: ""
1302+
nexttasks:
1303+
'#default#':
1304+
- "44"
1305+
"yes":
1306+
- "13"
1307+
separatecontext: false
1308+
conditions:
1309+
- label: "yes"
1310+
condition:
1311+
- - operator: isNotEmpty
1312+
left:
1313+
value:
1314+
simple: Core.OriginalAlert.event.actor_process_command_line
1315+
iscontext: true
1316+
continueonerrortype: ""
1317+
view: |-
1318+
{
1319+
"position": {
1320+
"x": 682,
1321+
"y": 484
1322+
}
1323+
}
1324+
note: false
1325+
timertriggers: []
1326+
ignoreworker: false
1327+
skipunavailable: false
1328+
quietmode: 0
1329+
isoversize: false
1330+
isautoswitchedtoquietmode: false
1331+
"44":
1332+
id: "44"
1333+
taskid: 4a936c96-aa51-4132-b4cd-e79ad923ec7c
1334+
type: condition
1335+
task:
1336+
id: 4a936c96-aa51-4132-b4cd-e79ad923ec7c
1337+
version: -1
1338+
name: Does actor process exist?
1339+
type: condition
1340+
iscommand: false
1341+
brand: ""
1342+
description: "Check if process name is exists."
1343+
nexttasks:
1344+
'#default#':
1345+
- "5"
1346+
"yes":
1347+
- "15"
1348+
separatecontext: false
1349+
conditions:
1350+
- label: "yes"
1351+
condition:
1352+
- - operator: isNotEmpty
1353+
left:
1354+
value:
1355+
simple: Core.OriginalAlert.event.actor_process_file_original_name
1356+
iscontext: true
1357+
continueonerrortype: ""
1358+
view: |-
1359+
{
1360+
"position": {
1361+
"x": 682,
1362+
"y": 864
1363+
}
1364+
}
1365+
note: false
1366+
timertriggers: []
1367+
ignoreworker: false
1368+
skipunavailable: false
1369+
quietmode: 0
1370+
isoversize: false
1371+
isautoswitchedtoquietmode: false
1372+
"45":
1373+
id: "45"
1374+
taskid: e3fd423b-a242-41bd-a5b9-ceecc7e3caa2
1375+
type: regular
1376+
task:
1377+
id: e3fd423b-a242-41bd-a5b9-ceecc7e3caa2
1378+
version: -1
1379+
name: Extract PFX from ZIP using zipfile
1380+
description: Unzip a file using fileName or entryID to specify a file. Unzipped files will be loaded to the War Room and names will be put into the context.
1381+
scriptName: UnzipFile
1382+
type: regular
1383+
iscommand: false
1384+
brand: ""
1385+
nexttasks:
1386+
'#error#':
1387+
- "21"
1388+
'#none#':
1389+
- "19"
1390+
scriptarguments:
1391+
entryID:
1392+
simple: ${File.EntryID}
1393+
zipTool:
1394+
simple: zipfile
1395+
separatecontext: false
1396+
continueonerror: true
1397+
continueonerrortype: errorPath
1398+
view: |-
1399+
{
1400+
"position": {
1401+
"x": -55,
1402+
"y": 864
1403+
}
1404+
}
1405+
note: false
1406+
timertriggers: []
1407+
ignoreworker: false
1408+
skipunavailable: false
1409+
quietmode: 0
1410+
isoversize: false
1411+
isautoswitchedtoquietmode: false
12871412
view: |-
12881413
{
12891414
"linkLabelsPosition": {
12901415
"17_30_yes": 0.53,
12911416
"18_17_#default#": 0.33,
12921417
"18_41_yes": 0.48,
1293-
"19_16_#default#": 0.5,
12941418
"19_9_yes": 0.57,
1419+
"22_45_#error#": 0.54,
12951420
"30_38_No": 0.14,
12961421
"30_41_Yes": 0.34,
12971422
"34_38_No": 0.54,
12981423
"36_38_#default#": 0.49,
12991424
"39_38_#default#": 0.38,
1300-
"9_21_#error#": 0.41
1425+
"44_15_yes": 0.3,
1426+
"9_21_#error#": 0.38
13011427
},
13021428
"paper": {
13031429
"dimensions": {
1304-
"height": 2750,
1305-
"width": 1543,
1306-
"x": 28,
1307-
"y": 61
1430+
"height": 2888,
1431+
"width": 1626,
1432+
"x": -55,
1433+
"y": -77
13081434
}
13091435
}
13101436
}
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
## Cortex Response And Remediation
2+
3+
Documentation and Metadata improvements.

Packs/CortexResponseAndRemediation/pack_metadata.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
"name": "Cortex Response And Remediation",
33
"description": "The Cortex Response & Remediation Pack delivers a powerful collection of automated playbooks designed to streamline incident response and remediation processes. Built to support an Autonomous SOC vision.",
44
"support": "xsoar",
5-
"currentVersion": "1.1.90",
5+
"currentVersion": "1.1.91",
66
"author": "Cortex XSOAR",
77
"url": "https://www.paloaltonetworks.com/cortex",
88
"email": "",

0 commit comments

Comments
 (0)