Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proactive threat hunting pack latest #28853

Merged
merged 367 commits into from Nov 19, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
367 commits
Select commit Hold shift + click to select a range
3b9c6d9
Script Test
ArikDay Aug 8, 2023
834f5be
Script Test
ArikDay Aug 8, 2023
305155b
Script Test
ArikDay Aug 8, 2023
45ad369
Script Test
ArikDay Aug 8, 2023
0619b4d
Script Test
ArikDay Aug 8, 2023
e6e33be
Script Test
ArikDay Aug 8, 2023
3e5da91
Script Test
ArikDay Aug 8, 2023
e0474dc
Script Test
ArikDay Aug 8, 2023
e44fa9f
Script Test
ArikDay Aug 8, 2023
4cabde8
Script Test
ArikDay Aug 8, 2023
cfb80ac
Script Test
ArikDay Aug 8, 2023
d45e951
Script Test
ArikDay Aug 8, 2023
bea28f4
Script Test
ArikDay Aug 8, 2023
9ca0143
Readme fix
ArikDay Aug 8, 2023
8cf5a3c
dependencies fix
ArikDay Aug 8, 2023
a8323aa
Readme fix
ArikDay Aug 8, 2023
e8ea409
Indicator Layout Fix
ArikDay Aug 8, 2023
f484386
playbook fix
ArikDay Aug 8, 2023
e8f0a10
Playbook fixes
ArikDay Aug 8, 2023
480c307
Release-note fix
ArikDay Aug 8, 2023
84b5054
Release-note fix
ArikDay Aug 8, 2023
e3d6bab
vix validation
ArikDay Aug 8, 2023
4887245
Resolve conflicts
ArikDay Aug 8, 2023
a768182
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack' i…
ArikDay Aug 8, 2023
ef51175
Resolve conflicts
ArikDay Aug 8, 2023
e7e9486
Resolve conflicts
ArikDay Aug 8, 2023
76c16a6
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack' i…
ArikDay Aug 8, 2023
136b162
Resolve conflicts
ArikDay Aug 8, 2023
0ac7b36
Resolve conflicts
ArikDay Aug 8, 2023
62ea326
Add no indicator unittest
ArikDay Aug 8, 2023
ca0ca5b
Add no indicator unittest
ArikDay Aug 8, 2023
d9f8a1e
Add no indicator unittest
ArikDay Aug 8, 2023
eaeb9da
Add no indicator unittest
ArikDay Aug 8, 2023
01ec662
Add no indicator unittest
ArikDay Aug 9, 2023
98e8755
Add no indicator unittest
ArikDay Aug 9, 2023
53ecb3e
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Aug 9, 2023
61e454b
Fix readme
ArikDay Aug 9, 2023
d1dc3f0
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack_La…
ArikDay Aug 9, 2023
890c1ac
Script review fixes
ArikDay Aug 9, 2023
fb1a1c9
Merged master into current branch.
Aug 9, 2023
442366a
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Aug 9, 2023
aca6ec5
Wizard Trial
ArikDay Aug 12, 2023
22bc3eb
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack_La…
ArikDay Aug 12, 2023
afe65a9
delete wizard
ArikDay Aug 12, 2023
4af08fe
Merged master into current branch.
Aug 13, 2023
3fc23cf
Bump pack from version CortexXDR to 5.0.8.
Aug 13, 2023
0807a81
Merged master into current branch.
Aug 13, 2023
3eb8221
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Aug 13, 2023
6a9cb57
Apply suggestions from code review
ArikDay Aug 13, 2023
6e37384
Apply suggestions from code review
ArikDay Aug 14, 2023
fc9e2e2
Apply suggestions from code review
ArikDay Aug 14, 2023
3dc7784
Apply suggestions from code review
ArikDay Aug 14, 2023
397c8df
Apply suggestions from code review
ArikDay Aug 14, 2023
a47a98a
Apply suggestions from code review
ArikDay Aug 14, 2023
2a577a9
Apply suggestions from code review
ArikDay Aug 14, 2023
c4aa950
Update Packs/MicrosoftDefenderAdvancedThreatProtection/Playbooks/play…
ArikDay Aug 14, 2023
e236bc7
Apply suggestions from code review
ArikDay Aug 14, 2023
e8edb78
Apply suggestions from code review
ArikDay Aug 14, 2023
56a7b3c
Apply suggestions from code review
ArikDay Aug 14, 2023
aa11881
Apply suggestions from code review
ArikDay Aug 14, 2023
7c870a3
Apply suggestions from code review
ArikDay Aug 14, 2023
f7d076e
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Aug 14, 2023
6f877dc
fix docker image
ArikDay Aug 14, 2023
6c0dbca
Merged master into current branch.
Aug 14, 2023
fba3b8f
Bump pack from version CommonPlaybooks to 2.3.90.
Aug 14, 2023
639ca13
Merged master into current branch.
Aug 14, 2023
d2a6e19
Bump pack from version CommonPlaybooks to 2.3.91.
Aug 14, 2023
235410c
Merged master into current branch.
Aug 16, 2023
726b9b7
Bump pack from version CommonPlaybooks to 2.3.92.
Aug 16, 2023
c823f99
Merged master into current branch.
Aug 16, 2023
adb6270
Bump pack from version CommonPlaybooks to 2.3.93.
Aug 16, 2023
1fcc6c8
Merged master into current branch.
Aug 17, 2023
b323e93
Bump pack from version CortexXDR to 5.0.9.
Aug 17, 2023
d8c9dc8
Merged master into current branch.
Aug 20, 2023
15f2c4a
Bump pack from version FeedLOLBAS to 1.0.7.
Aug 20, 2023
9912beb
Merged master into current branch.
Aug 20, 2023
3524092
Bump pack from version CommonPlaybooks to 2.3.94.
Aug 20, 2023
7d072a8
Merged master into current branch.
Aug 20, 2023
6e4fbf8
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Aug 20, 2023
3dc3f0b
Merged master into current branch.
Aug 21, 2023
12058d9
Bump pack from version CortexXDR to 5.0.10.
Aug 21, 2023
216c08c
Merged master into current branch.
Aug 21, 2023
a33eee5
Bump pack from version CommonPlaybooks to 2.3.95.
Aug 21, 2023
0b5da14
Merged master into current branch.
Aug 22, 2023
6038d3a
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Aug 22, 2023
378595c
Merged master into current branch.
Aug 23, 2023
f5c392d
Bump pack from version CortexXDR to 5.0.11.
Aug 23, 2023
8dbdbfe
Bump pack from version CommonPlaybooks to 2.3.96.
Aug 23, 2023
867c7de
Merged master into current branch.
Aug 23, 2023
fdab3c6
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Aug 23, 2023
41f1cb1
Merged master into current branch.
Aug 24, 2023
abd283f
Bump pack from version CortexXDR to 5.1.1.
Aug 24, 2023
1921e1f
Merged master into current branch.
Aug 24, 2023
75691c5
Bump pack from version CommonPlaybooks to 2.3.97.
Aug 24, 2023
661992f
Merged master into current branch.
Aug 24, 2023
3f2728b
Bump pack from version CortexXDR to 5.1.2.
Aug 24, 2023
9c86e05
Merged master into current branch.
Aug 27, 2023
1bf9429
Bump pack from version CommonPlaybooks to 2.3.98.
Aug 27, 2023
1543cb9
Merged master into current branch.
Aug 28, 2023
53d73ef
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Aug 28, 2023
f93e6ba
Merged master into current branch.
Aug 28, 2023
39ca38f
Bump pack from version CommonPlaybooks to 2.3.99.
Aug 28, 2023
ad6b17a
Merged master into current branch.
Aug 29, 2023
2eb20a3
Bump pack from version CortexXDR to 5.1.3.
Aug 29, 2023
d4da99a
Merged master into current branch.
Sep 3, 2023
c0981e5
Bump pack from version FeedLOLBAS to 1.0.8.
Sep 3, 2023
f9ee12d
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 3, 2023
1c056bc
Docker
ArikDay Sep 3, 2023
de0a8a6
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 3, 2023
f3ad175
Merged master into current branch.
Sep 3, 2023
ec8239d
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Sep 3, 2023
c9e790d
Merged master into current branch.
Sep 4, 2023
498dbf9
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Sep 4, 2023
b54b182
Merged master into current branch.
Sep 5, 2023
0193e4e
Bump pack from version CommonTypes to 3.3.85.
Sep 5, 2023
43a4047
Merged master into current branch.
Sep 5, 2023
37374d5
Bump pack from version CortexXDR to 5.1.4.
Sep 5, 2023
bdb403b
fixes
ArikDay Sep 5, 2023
db17894
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack_La…
ArikDay Sep 5, 2023
98d8ca8
fixes
ArikDay Sep 5, 2023
5c7de11
fixes
ArikDay Sep 5, 2023
c5c5da0
fixes
ArikDay Sep 5, 2023
453ca7b
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 5, 2023
e95ddf8
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 6, 2023
09710d1
Merged master into current branch.
Sep 6, 2023
cb21e75
Bump pack from version CommonPlaybooks to 2.4.2.
Sep 6, 2023
968ca57
Merged master into current branch.
Sep 7, 2023
451f562
Bump pack from version CommonTypes to 3.3.86.
Sep 7, 2023
fea7834
Merged master into current branch.
Sep 7, 2023
9977c13
Bump pack from version CortexXDR to 5.1.5.
Sep 7, 2023
6828c71
Merged master into current branch.
Sep 10, 2023
c78fc1c
Bump pack from version CommonPlaybooks to 2.4.3.
Sep 10, 2023
cc79d00
Merged master into current branch.
Sep 10, 2023
4bafebd
Bump pack from version CommonPlaybooks to 2.4.4.
Sep 10, 2023
5808dbc
Bump pack from version CommonTypes to 3.3.87.
Sep 10, 2023
f29b9ff
Merged master into current branch.
Sep 11, 2023
639382f
Bump pack from version CommonTypes to 3.3.88.
Sep 11, 2023
08584a2
Merged master into current branch.
Sep 12, 2023
fdba8ab
Bump pack from version CortexXDR to 5.1.6.
Sep 12, 2023
819f07e
updated docker
ArikDay Sep 12, 2023
7bf8623
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack_La…
ArikDay Sep 12, 2023
e867986
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 12, 2023
04fa3fb
fix
ArikDay Sep 12, 2023
3b33e92
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack_La…
ArikDay Sep 12, 2023
906fefb
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 12, 2023
c69cfc0
fix
ArikDay Sep 12, 2023
20ebb17
Merge remote-tracking branch 'origin/Proactive_Threat_Hunting_Pack_La…
ArikDay Sep 12, 2023
aeb7eaa
Merged master into current branch.
Sep 13, 2023
41c2cfc
Bump pack from version CortexXDR to 5.1.7.
Sep 13, 2023
5225293
Merged master into current branch.
Sep 18, 2023
1bd5d8f
Bump pack from version CortexXDR to 5.1.8.
Sep 18, 2023
4e1852f
Add ons
ArikDay Sep 19, 2023
04004f9
input fix
ArikDay Sep 19, 2023
97a630a
FieldToPackIgnore
ArikDay Sep 19, 2023
54772aa
add fromversion
ArikDay Sep 19, 2023
7634142
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 19, 2023
acef77f
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Sep 20, 2023
443087a
Cheat Sheet Fix
ArikDay Sep 20, 2023
72606ae
Merged master into current branch.
Sep 21, 2023
c1707bc
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Sep 21, 2023
e1ccfa7
Merged master into current branch.
Sep 26, 2023
4b0cd25
Bump pack from version CommonPlaybooks to 2.4.5.
Sep 26, 2023
bc18fc2
Merged master into current branch.
Sep 26, 2023
b866a61
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Sep 26, 2023
313cd61
Merged master into current branch.
Sep 27, 2023
c36b6c7
Bump pack from version FeedLOLBAS to 1.0.9.
Sep 27, 2023
b032eca
Merged master into current branch.
Sep 27, 2023
d2e9640
Bump pack from version CommonPlaybooks to 2.4.6.
Sep 27, 2023
f45c6ae
Merged master into current branch.
Oct 1, 2023
d0690d3
Bump pack from version CortexXDR to 5.1.9.
Oct 1, 2023
e9c0b9a
Merged master into current branch.
Oct 1, 2023
c5ab3da
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Oct 1, 2023
aaafc82
Merged master into current branch.
Oct 10, 2023
d4d4693
Bump pack from version CommonPlaybooks to 2.4.7.
Oct 10, 2023
75455ac
Merged master into current branch.
Oct 10, 2023
c1db6b5
Bump pack from version CortexXDR to 5.1.10.
Oct 10, 2023
769ce42
Merged master into current branch.
Oct 11, 2023
53541b0
Bump pack from version CommonPlaybooks to 2.4.8.
Oct 11, 2023
cd4ddb6
Merged master into current branch.
Oct 11, 2023
1fb11f7
Bump pack from version CommonPlaybooks to 2.4.9.
Oct 11, 2023
d30c77d
Merged master into current branch.
Oct 11, 2023
0e038c4
Bump pack from version CommonPlaybooks to 2.4.10.
Oct 11, 2023
006244d
Merged master into current branch.
Oct 12, 2023
b12d475
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Oct 12, 2023
e602f5d
Merged master into current branch.
Oct 12, 2023
ab29bba
Bump pack from version CommonPlaybooks to 2.4.11.
Oct 12, 2023
63507e0
Merged master into current branch.
Oct 15, 2023
455bae0
Bump pack from version CommonPlaybooks to 2.4.12.
Oct 15, 2023
94fcd3c
Bump pack from version CortexXDR to 5.2.1.
Oct 15, 2023
111aa2d
Merged master into current branch.
Oct 16, 2023
f6a7bc0
Bump pack from version CortexXDR to 5.2.2.
Oct 16, 2023
754a7f6
Merged master into current branch.
Oct 16, 2023
bd3ed29
Bump pack from version FeedLOLBAS to 1.0.10.
Oct 16, 2023
b8d6701
Merged master into current branch.
Oct 18, 2023
69225c7
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Oct 18, 2023
638fc22
Merged master into current branch.
Oct 18, 2023
349ec0b
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Oct 18, 2023
f9c337b
Merged master into current branch.
Oct 18, 2023
c628580
Bump pack from version CommonPlaybooks to 2.4.13.
Oct 18, 2023
73e88e9
Merged master into current branch.
Oct 18, 2023
fd7f052
Bump pack from version CommonPlaybooks to 2.4.14.
Oct 18, 2023
9c24ad6
Merged master into current branch.
Oct 22, 2023
c3adbda
Bump pack from version CortexXDR to 5.2.3.
Oct 22, 2023
3d361b2
Merged master into current branch.
Oct 23, 2023
30337eb
Bump pack from version MicrosoftDefenderAdvancedThreatProtection to 1…
Oct 23, 2023
a38deaf
Merged master into current branch.
Oct 28, 2023
0be20c4
Bump pack from version CortexXDR to 5.2.4.
Oct 28, 2023
b44ef4e
Review Fixes
ArikDay Oct 30, 2023
68c7a92
Review Fixes
ArikDay Oct 30, 2023
a8ac78d
bump
ArikDay Oct 30, 2023
910a0c7
fix
ArikDay Oct 30, 2023
8123bf8
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Oct 30, 2023
302a401
Fixes
ArikDay Oct 30, 2023
d9c484e
fix README
ArikDay Oct 30, 2023
fc68110
Merge branch 'master' of github.com:demisto/content into Proactive_Th…
ArikDay Nov 13, 2023
066037f
bump
ArikDay Nov 13, 2023
5da466e
fix
ArikDay Nov 13, 2023
bd91b13
fixes
ArikDay Nov 13, 2023
c366035
fix
ArikDay Nov 13, 2023
4beca63
fix
ArikDay Nov 13, 2023
18d9d13
Merged master into current branch.
Nov 14, 2023
ab312ae
Bump pack from version CommonPlaybooks to 2.4.18.
Nov 14, 2023
c9829ae
fix
ArikDay Nov 14, 2023
b56f65c
Merge branch 'Proactive_Threat_Hunting_Pack_Latest' of github.com:dem…
ArikDay Nov 14, 2023
2b58204
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Nov 14, 2023
6f2a57e
fix rn
ArikDay Nov 14, 2023
cbf9983
Merge branch 'Proactive_Threat_Hunting_Pack_Latest' of github.com:dem…
ArikDay Nov 14, 2023
1fa72b6
Merged master into current branch.
Nov 14, 2023
73d486f
Bump pack from version CommonPlaybooks to 2.4.19.
Nov 14, 2023
67c0214
Merged master into current branch.
Nov 14, 2023
4798be3
Bump pack from version CommonPlaybooks to 2.4.20.
Nov 14, 2023
b526409
fix
ArikDay Nov 15, 2023
a7e59c5
Merge branch 'Proactive_Threat_Hunting_Pack_Latest' of github.com:dem…
ArikDay Nov 15, 2023
fa640c0
rn
ArikDay Nov 15, 2023
ed8abaa
Merged master into current branch.
Nov 15, 2023
c021367
Bump pack from version CortexXDR to 6.0.2.
Nov 15, 2023
f642ab8
Merged master into current branch.
Nov 16, 2023
a8b56a3
Bump pack from version CommonPlaybooks to 2.4.21.
Nov 16, 2023
c4c4aec
Merged master into current branch.
Nov 16, 2023
b78d0cc
Bump pack from version CommonPlaybooks to 2.4.22.
Nov 16, 2023
3686045
Merged master into current branch.
Nov 16, 2023
7d09589
Bump pack from version CommonPlaybooks to 2.4.23.
Nov 16, 2023
7c72f42
add video
ArikDay Nov 16, 2023
7785467
Merge branch 'Proactive_Threat_Hunting_Pack_Latest' of github.com:dem…
ArikDay Nov 16, 2023
03cfb17
Merged master into current branch.
Nov 16, 2023
ea1e060
Bump pack from version CommonPlaybooks to 2.4.24.
Nov 16, 2023
8db757b
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Nov 19, 2023
f42c4dd
udpatedockerimage
ArikDay Nov 19, 2023
bf70355
Merge branch 'Proactive_Threat_Hunting_Pack_Latest' of github.com:dem…
ArikDay Nov 19, 2023
654445a
Merge branch 'master' into Proactive_Threat_Hunting_Pack_Latest
ArikDay Nov 19, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view

Large diffs are not rendered by default.

@@ -0,0 +1,47 @@
This playbook will search a file or process activity of a software by a given image file name. The analyst can then choose the files to block.
The following integrations are supported:

- Cortex XDR XQL Engine
- Microsoft Defender For Endpoint

## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

### Sub-playbooks

* MDE - Search And Block Software
* Cortex XDR - Search And Block Software - XQL Engine

### Integrations

This playbook does not use any integrations.

### Scripts

* DeleteContext

### Commands

This playbook does not use any commands.

## Playbook Inputs

---

| **Name** | **Description** | **Default Value** | **Required** |
| --- | --- | --- | --- |
| FileName | File name to search | | Optional |
| TimeFrame | Time in relative date or range format \(for example: "1 day", "3 weeks ago", "between 2021-01-01 12:34:56 \+02:00 and 2021-02-01 12:34:56 \+02:00"\). The default is the last 24 hours. | | Optional |
| Indicator Expiration | DateTime string indicating when the indicator expires. Format: \(<number> <time unit>, e.g., 12 hours, 7 days\). | | Optional |

## Playbook Outputs

---
There are no outputs for this playbook.

## Playbook Image

---

![Search And Block Software - Generic](../doc_files/Search_And_Block_Software_-_Generic.png)
@@ -0,0 +1,283 @@
id: Search and Compare Process Executions - Generic
version: -1
name: Search and Compare Process Executions - Generic
description: |-
This playbook is a generic playbook that receives a process name and a command-line argument. It searches for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input. The playbook supports searching process executions using the following integrations:

- Cortex XDR XQL Engine
- Cortex XDR IR(Search executions inside XDR alerts)
- Microsoft Defender For Endpoint

Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
starttaskid: "0"
tasks:
"0":
id: "0"
taskid: e4d8d0c7-56ec-4b27-8fbb-ae3a02490091
type: start
task:
id: e4d8d0c7-56ec-4b27-8fbb-ae3a02490091
version: -1
name: ""
iscommand: false
brand: ""
description: ''
nexttasks:
'#none#':
- "15"
- "16"
- "17"
separatecontext: false
continueonerrortype: ""
view: |-
{
"position": {
"x": 450,
"y": 80
}
}
note: false
timertriggers: []
ignoreworker: false
skipunavailable: false
quietmode: 0
isoversize: false
isautoswitchedtoquietmode: false
"14":
id: "14"
taskid: 6511abc4-4a61-4657-86b8-3809cbcc5dae
type: title
task:
id: 6511abc4-4a61-4657-86b8-3809cbcc5dae
version: -1
name: Done
type: title
iscommand: false
brand: ""
description: ''
separatecontext: false
continueonerrortype: ""
view: |-
{
"position": {
"x": 450,
"y": 400
}
}
note: false
timertriggers: []
ignoreworker: false
skipunavailable: false
quietmode: 0
isoversize: false
isautoswitchedtoquietmode: false
"15":
id: "15"
taskid: 0c2ea311-165b-48ae-8f5f-92cb5ec5e81b
type: playbook
task:
id: 0c2ea311-165b-48ae-8f5f-92cb5ec5e81b
version: -1
name: MDE - Search and Compare Process Executions
description: |-
This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Microsoft Defender For Endpoint" integration to search for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input.

Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
playbookName: MDE - Search and Compare Process Executions
type: playbook
iscommand: false
brand: ""
nexttasks:
'#none#':
- "14"
scriptarguments:
HuntingTimeFrame:
complex:
root: inputs.HuntingTimeFrame
Processes:
complex:
root: inputs.Processes
StringSimilarityThreshold:
complex:
root: inputs.StringSimilarityThreshold
separatecontext: true
continueonerrortype: ""
loop:
iscommand: false
exitCondition: ""
wait: 1
max: 100
view: |-
{
"position": {
"x": 450,
"y": 220
}
}
note: false
timertriggers: []
ignoreworker: false
skipunavailable: true
quietmode: 0
isoversize: false
isautoswitchedtoquietmode: false
"16":
id: "16"
taskid: 936cbb1b-fc14-42e0-80e4-9ca0bbec9f10
type: playbook
task:
id: 936cbb1b-fc14-42e0-80e4-9ca0bbec9f10
version: -1
name: Cortex XDR - Search and Compare Process Executions - XDR Alerts
description: |-
This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Cortex XDR IR" integration to search for the given process executions inside XDR alerts and compares the command-line argument from the results to the command-line argument received from the playbook input.

Note: Under the "Processes" input the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
playbookName: Cortex XDR - Search and Compare Process Executions - XDR Alerts
type: playbook
iscommand: false
brand: ""
nexttasks:
'#none#':
- "14"
scriptarguments:
HuntingTimeFrame:
complex:
root: inputs.HuntingTimeFrame
Processes:
complex:
root: inputs.Processes
SearchXDRAlerts:
complex:
root: inputs.SearchXDRAlerts
StringSimilarityThreshold:
complex:
root: inputs.StringSimilarityThreshold
separatecontext: true
continueonerrortype: ""
loop:
iscommand: false
exitCondition: ""
wait: 1
max: 100
forEach: true
view: |-
{
"position": {
"x": 40,
"y": 220
}
}
note: false
timertriggers: []
ignoreworker: false
skipunavailable: true
quietmode: 0
isoversize: false
isautoswitchedtoquietmode: false
"17":
id: "17"
taskid: 6246b45d-476d-4e3d-8c6a-6eccafe838ef
type: playbook
task:
id: 6246b45d-476d-4e3d-8c6a-6eccafe838ef
version: -1
name: Cortex XDR - Search and Compare Process Executions - XQL Engine
description: |-
This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Cortex XDR - XQL Engine" integration to search for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input.

Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
playbookName: Cortex XDR - Search and Compare Process Executions - XQL Engine
type: playbook
iscommand: false
brand: ""
nexttasks:
'#none#':
- "14"
scriptarguments:
HuntingTimeFrame:
complex:
root: inputs.HuntingTimeFrame
Processes:
complex:
root: inputs.Processes
StringSimilarityThreshold:
complex:
root: inputs.StringSimilarityThreshold
separatecontext: true
continueonerrortype: ""
loop:
iscommand: false
exitCondition: ""
wait: 1
max: 100
view: |-
{
"position": {
"x": 870,
"y": 220
}
}
note: false
timertriggers: []
ignoreworker: false
skipunavailable: true
quietmode: 0
isoversize: false
isautoswitchedtoquietmode: false
view: |-
{
"linkLabelsPosition": {},
"paper": {
"dimensions": {
"height": 385,
"width": 1210,
"x": 40,
"y": 80
}
}
}
inputs:
- key: Processes
value: {}
required: false
description: |-
Process name to search and command-line argument to compare. This input should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*
playbookInputQuery:
- key: HuntingTimeFrame
value:
simple: 7 days
required: false
description: 'Time in relative date or range format (for example: "1 day", "3 weeks ago", "between 2021-01-01 12:34:56 +02:00 and 2021-02-01 12:34:56 +02:00"). The default is the last 24 hours.'
playbookInputQuery:
- key: StringSimilarityThreshold
value:
simple: "0.5"
required: false
description: StringSimilarity automation threshold. A number between 0 and 1, where 1 represents the most similar results of string comparisons. The automation will output only the results with a similarity score equal to or greater than the specified threshold.
playbookInputQuery:
- key: SearchXDRAlerts
value: {}
required: false
description: Set to "True" if you want to hunt for processes that are part of XDR alerts
playbookInputQuery:
outputs:
- contextPath: StringSimilarity
description: StringSimilarity automation results.
type: unknown
- contextPath: Findings
description: Suspicious process executions found.
type: unknown
tests:
- No tests (auto formatted)
fromversion: 6.9.0
@@ -0,0 +1,57 @@
This playbook is a generic playbook that receives a process name and a command-line argument. It searches for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input. The playbook supports searching process executions using the following integrations:

- Cortex XDR XQL Engine
- Cortex XDR IR(Search executions inside XDR alerts)
- Microsoft Defender For Endpoint

Note: Under the "Processes" input, the playbook should receive an array that contains the following keys:
- value: *process name*
- commands: *command-line arguments*

## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

### Sub-playbooks

* MDE - Search and Compare Process Executions
* Cortex XDR - Search and Compare Process Executions - XQL Engine
* Cortex XDR - Search and Compare Process Executions - XDR Alerts

### Integrations

This playbook does not use any integrations.

### Scripts

This playbook does not use any scripts.

### Commands

This playbook does not use any commands.

## Playbook Inputs

---

| **Name** | **Description** | **Default Value** | **Required** |
| --- | --- | --- | --- |
| Processes | Process name to search and command-line argument to compare. This input should receive an array that contains the following keys:<br/>- value: \*process name\*<br/>- commands: \*command-line arguments\* | | Optional |
| HuntingTimeFrame | Time in relative date or range format \(for example: "1 day", "3 weeks ago", "between 2021-01-01 12:34:56 \+02:00 and 2021-02-01 12:34:56 \+02:00"\). The default is the last 24 hours. | 7 days | Optional |
| StringSimilarityThreshold | StringSimilarity automation threshold. A number between 0 and 1, where 1 represents the most similar results of string comparisons. The automation will output only the results with a similarity score equal to or greater than the specified threshold. | 0.5 | Optional |
| SearchXDRAlerts | Set to "True" if you want to hunt for processes that are part of XDR alerts | | Optional |

## Playbook Outputs

---

| **Path** | **Description** | **Type** |
| --- | --- | --- |
| StringSimilarity | StringSimilarity automation results. | unknown |
| Findings | Suspicious process executions found. | unknown |

## Playbook Image

---

![Search and Compare Process Executions - Generic](../doc_files/Search_and_Compare_Process_Executions_-_Generic.png)