Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions playbooks/templates/Alerts_Shodan_Enrichment.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
{
"name": "Enrich with Shodan",
"tags": [
"Alerts",
"Enrichment"
],
"nodes": {
"0": {
"icon": "data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMTcwIiBoZWlnaHQ9IjE3MCIgdmlld0JveD0iMCAwIDE3MCAxNzAiIGZpbGw9Im5vbmUiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+CjxwYXRoIGQ9Ik0zNy4zNjU3IDU3LjgwMzlIMjcuNzE1MVYxMTMuNjg2SDM3LjM2NTdWNTcuODAzOVoiIGZpbGw9ImJsYWNrIi8+CjxwYXRoIGQ9Ik05LjY1MDY2IDM3LjY4NjNINTYuNDE5Mkg2Ni4wNjk5SDE2MC4xMDJWMTMyLjA2NUg2Ni4wNjk5SDU2LjQxOTJIOS42NTA2NlYzNy42ODYzWk0wIDE0MkgxNzBWMjhIMFYxNDJaIiBmaWxsPSJibGFjayIvPgo8cGF0aCBkPSJNMTEzLjMzNCA1Ny44MDM5QzEyOC42NzYgNTcuODAzOSAxNDEuMDQ4IDcwLjIyMjIgMTQxLjA0OCA4NS42MjA5QzE0MS4wNDggMTAxLjAyIDEyOC42NzYgMTEzLjQzOCAxMTMuMzM0IDExMy40MzhDOTcuOTkxNiAxMTMuNDM4IDg1LjYxOSAxMDEuMDIgODUuNjE5IDg1LjYyMDlDODUuNjE5IDcwLjIyMjIgOTcuOTkxNiA1Ny44MDM5IDExMy4zMzQgNTcuODAzOVpNMTEzLjMzNCAxMjMuMzczQzEzNC4xMiAxMjMuMzczIDE1MC45NDYgMTA2LjQ4NCAxNTAuOTQ2IDg1LjYyMDlDMTUwLjk0NiA2NC43NTgxIDEzNC4xMiA0OC4xMTc2IDExMy4zMzQgNDguMTE3NkM5Mi41NDc2IDQ4LjExNzYgNzUuNzIwOSA2NS4wMDY1IDc1LjcyMDkgODUuODY5MkM3NS43MjA5IDEwNi43MzIgOTIuNTQ3NiAxMjMuMzczIDExMy4zMzQgMTIzLjM3M1oiIGZpbGw9ImJsYWNrIi8+Cjwvc3ZnPgo=",
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/CrowdSec_alert_enrichment.json
Original file line number Diff line number Diff line change
Expand Up @@ -154,8 +154,8 @@
"description": "Enrich with CrowdSec Smoke DB to check if the IP is known from this service direclty from SEKOIA.IO.",
"tags": [
"CrowdSec",
"alerts",
"enrichment"
"Alerts",
"Enrichment"
],
"uuid": "712e8303-fcbb-4e10-b27b-6e64e9a11b60"
}
Original file line number Diff line number Diff line change
Expand Up @@ -32,8 +32,7 @@
"workspace": "Operation Center",
"description": "Synchronise alerts from Digital Shadows SearchLight to SEKOIA.IO events",
"tags": [
"alerts",
"osint"
"Alerts"
],
"uuid": "cafeb7d7-d76d-4dcc-a111-b0d7fe991405"
}
4 changes: 4 additions & 0 deletions playbooks/templates/Enrich_alerts_with_AbuseIPDB.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,10 @@
{
"name": "Enrich alerts with AbuseIPDB",
"uuid": "0d745afb-de40-4a7d-af5f-e448ffe9f0ee",
"tags": [
"Alerts",
"Enrichment"
],
"nodes": {
"0": {
"name": "Manual trigger",
Expand Down
4 changes: 4 additions & 0 deletions playbooks/templates/Enrich_alerts_with_VirusTotal_Hash.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,10 @@
{
"name": "Scan for hash on VirusTotal",
"uuid": "558a4c09-bb8c-4d11-9c26-635c43ba9fd0",
"tags": [
"Alerts",
"Enrichment"
],
"nodes": {
"0": {
"name": "Manual trigger",
Expand Down
4 changes: 4 additions & 0 deletions playbooks/templates/Enrich_alerts_with_hostnames.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
{
"name": "Enrich alerts with hostnames",
"tags": [
"Alerts",
"Enrichment"
],
"nodes": {
"1": {
"icon": "data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMjYxIiBoZWlnaHQ9IjI2MSIgdmlld0JveD0iMCAwIDI2MSAyNjEiIGZpbGw9Im5vbmUiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+CjxwYXRoIGZpbGwtcnVsZT0iZXZlbm9kZCIgY2xpcC1ydWxlPSJldmVub2RkIiBkPSJNMTMwLjUzMiAwLjIzNjgyQzEwNC43NjcgMC4yMzA1MSA3OS41NzkxIDcuODY1IDU4LjE1MzIgMjIuMTc0N0MzNi43Mjc0IDM2LjQ4NDMgMjAuMDI2MiA1Ni44MjY0IDEwLjE2MiA4MC42MjgzQzAuMjk3ODQ4IDEwNC40MyAtMi4yODY2MiAxMzAuNjIzIDIuNzM2MDEgMTU1Ljg5M0M3Ljc1ODY0IDE4MS4xNjQgMjAuMTYyNSAyMDQuMzc4IDM4LjM3ODkgMjIyLjU5OUM1Ni41OTUyIDI0MC44MTkgNzkuODA1OSAyNTMuMjI5IDEwNS4wNzUgMjU4LjI1OEMxMzAuMzQ1IDI2My4yODcgMTU2LjUzOCAyNjAuNzA5IDE4MC4zNDMgMjUwLjg1QzIwNC4xNDcgMjQwLjk5MiAyMjQuNDkzIDIyNC4yOTYgMjM4LjgwOCAyMDIuODc0QzI1My4xMjMgMTgxLjQ1MSAyNjAuNzYzIDE1Ni4yNjUgMjYwLjc2MyAxMzAuNUMyNjAuNzI5IDk1Ljk2OCAyNDYuOTk5IDYyLjg1OTQgMjIyLjU4NCAzOC40Mzg2QzE5OC4xNjkgMTQuMDE3OCAxNjUuMDY0IDAuMjc5MDUgMTMwLjUzMiAwLjIzNjgyWk0xMzAuNTMyIDIzNi44MzVDMTA5LjQ5MyAyMzYuODM1IDg4LjkyNyAyMzAuNTk2IDcxLjQzNDMgMjE4LjkwN0M1My45NDE2IDIwNy4yMTggNDAuMzA4NCAxOTAuNjA0IDMyLjI1ODcgMTcxLjE2NkMyNC4yMDg5IDE1MS43MjggMjIuMTA0MSAxMzAuMzM5IDI2LjIxMDkgMTA5LjcwNUMzMC4zMTc3IDg5LjA3MSA0MC40NTE2IDcwLjExODIgNTUuMzMwNSA1NS4yNDM4QzcwLjIwOTQgNDAuMzY5MyA4OS4xNjUzIDMwLjI0MTQgMTA5LjgwMSAyNi4xNDA4QzEzMC40MzYgMjIuMDQwMiAxNTEuODIzIDI0LjE1MTEgMTcxLjI1OSAzMi4yMDY3QzE5MC42OTQgNDAuMjYyMyAyMDcuMzA1IDUzLjkwMDYgMjE4Ljk4OSA3MS4zOTY4QzIzMC42NzMgODguODkzIDIzNi45MDYgMTA5LjQ2MSAyMzYuODk5IDEzMC41QzIzNi44OTEgMTU4LjcxNCAyMjUuNjg0IDE4NS43NyAyMDUuNzQgMjA1LjcyNkMxODUuNzk2IDIyNS42ODIgMTU4Ljc0NiAyMzYuOTA2IDEzMC41MzIgMjM2LjkzMVYyMzYuODM1Wk0xNTYuMTA4IDcxLjQ5MTdDMTQ0LjY1NyA3MS40OTE3IDEzMy40NjQgNzQuODg3MiAxMjMuOTQzIDgxLjI0ODdDMTE0LjQyMiA4Ny42MTAzIDEwNy4wMDIgOTYuNjUyMiAxMDIuNjIgMTA3LjIzMUM5OC4yMzggMTE3LjgxIDk3LjA5MTMgMTI5LjQ1MSA5OS4zMjUyIDE0MC42ODFDMTAxLjU1OSAxNTEuOTEyIDEwNy4wNzMgMTYyLjIyNyAxMTUuMTcgMTcwLjMyNEMxMjMuMjY3IDE3OC40MjEgMTMzLjU4MiAxODMuOTM1IDE0NC44MTMgMTg2LjE2OUMxNTYuMDQzIDE4OC40MDMgMTY3LjY4NCAxODcuMjU2IDE3OC4yNjMgMTgyLjg3NEMxODguODQyIDE3OC40OTIgMTk3Ljg4NCAxNzEuMDcyIDIwNC4yNDUgMTYxLjU1MUMyMTAuNjA3IDE1Mi4wMyAyMTQuMDAyIDE0MC44MzcgMjE0LjAwMiAxMjkuMzg2QzIxNC4wMDIgMTE0LjAzMiAyMDcuOTAzIDk5LjMwNiAxOTcuMDQ1IDg4LjQ0ODdDMTg2LjE4OCA3Ny41OTEzIDE3MS40NjIgNzEuNDkxNyAxNTYuMTA4IDcxLjQ5MTdaTTE1Ni4xMDggMTYzLjMzN0MxNDkuMzkzIDE2My4zMzcgMTQyLjgyOSAxNjEuMzQ2IDEzNy4yNDYgMTU3LjYxNUMxMzEuNjYzIDE1My44ODUgMTI3LjMxMSAxNDguNTgyIDEyNC43NDEgMTQyLjM3OUMxMjIuMTcyIDEzNi4xNzUgMTIxLjUgMTI5LjM0OSAxMjIuODEgMTIyLjc2M0MxMjQuMTIgMTE2LjE3NyAxMjcuMzUzIDExMC4xMjggMTMyLjEwMSAxMDUuMzhDMTM2Ljg0OSAxMDAuNjMyIDE0Mi44OTggOTcuMzk4MyAxNDkuNDg0IDk2LjA4ODRDMTU2LjA3IDk0Ljc3ODQgMTYyLjg5NiA5NS40NTA3IDE2OS4xIDk4LjAyMDNDMTc1LjMwMyAxMDAuNTkgMTgwLjYwNiAxMDQuOTQxIDE4NC4zMzYgMTEwLjUyNUMxODguMDY3IDExNi4xMDggMTkwLjA1OCAxMjIuNjcyIDE5MC4wNTggMTI5LjM4NkMxOTAuMDUgMTM4LjM4OCAxODYuNDcgMTQ3LjAxOSAxODAuMTA1IDE1My4zODRDMTczLjc0IDE1OS43NDkgMTY1LjEwOSAxNjMuMzI4IDE1Ni4xMDggMTYzLjMzN1pNNjAuMzU4NCA4Mi42MjU3SDg1Ljk2NTdWMTc3LjI2MUg2MC4zNTg0VjgyLjYyNTdaIiBmaWxsPSIjNUQ0RkYyIi8+Cjwvc3ZnPgo=",
Expand Down
4 changes: 4 additions & 0 deletions playbooks/templates/Enrich_with_IKnow_What_You_Download.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
{
"name": "Enrich with IKnowWhatYouDownload",
"tags": [
"Alerts",
"Enrichment"
],
"nodes": {
"0": {
"name": "alert_webhook",
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/HTTP_request_Remediation.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
"name": "[Training usecase] Post an HTTP request based on alert information",
"description": "Send HTTP request to an external service based on alert data",
"tags": [
"alerts",
"webhook"
"Alerts",
"Webhook"
],
"nodes": {
"0": {
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/OSINT_to_observables.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
"workspace": "Intelligence Center",
"description": "Retrieve observables from an OSINT to add it to observable database with a tag (eg: https://github.com/MISP/misp-warninglists/tree/main/lists)",
"tags": [
"observable",
"fetch osint",
"Observables",
"OSINT",
"TIP"
],
"nodes": {
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/Shodan_search_to_observables.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
"description": "Get IP addresses from a shodan search and add it to Observable data base with a tag",
"workspace": "Intelligence Center",
"tags": [
"observable",
"shodan",
"Observables",
"Shodan",
"TIP"
],
"nodes": {
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/Tranco_top_domains_to_observables.json
Original file line number Diff line number Diff line change
Expand Up @@ -159,8 +159,8 @@
},
"workspace": "Intelligence Center",
"tags": [
"observable",
"tranco",
"Observables",
"Tranco",
"TIP"
],
"description": "Automatically import Tranco's top 1 000 000 domain names to observable database",
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/URL_scan_VirusTotal_Enrichement.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"name": "[Training usecase] Scan for url on VirusTotal",
"description": "Enrich to check if this url.domain is known from VirusTotal, directly from Sekoia.io",
"tags": [
"alerts",
"enrichment"
"Alerts",
"Enrichment"
],
"nodes": {
"0": {
Expand Down
4 changes: 4 additions & 0 deletions playbooks/templates/VirusTotal_Enrichement.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
{
"name": "Enhance network alerts with VirusTotal",
"tags": [
"Alerts",
"Enrichment"
],
"nodes": {
"0": {
"name": "Manual trigger",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
{
"name": "Add Destination IP address to IOC Collection",
"tags": [
"alerts",
"Alerts",
"IOC Collection",
"blocklist"
"Blocklist"
],
"workspace": "Operation Center",
"description": "Add the destination ip addresses from the events linked to the alert to an IOC collection",
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/add_domains_to_ioc_collection.json
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
{
"name": "Add Domain to blocklist",
"tags": [
"alerts",
"Alerts",
"IOC Collection",
"blocklist"
"Blocklist"
],
"workspace": "Operation Center",
"description": "Add the domains from the events linked to the alert to an IOC collection",
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/add_source_ips_to_ioc_collection.json
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
{
"name": "Add Source IP address to IOC Collection",
"tags": [
"alerts",
"Alerts",
"IOC Collection",
"blocklist"
"Blocklist"
],
"workspace": "Operation Center",
"description": "Add the source ip addresses from the events linked to the alert to an IOC collection",
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/alert_webhook_internet_scan.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"name": "Qualify Internet Scan webhook",
"description": "Qualify an Internet scan alert on webhook",
"tags": [
"alert",
"webhook"
"Alerts",
"Webhook"
],
"nodes": {
"0": {
Expand Down
4 changes: 2 additions & 2 deletions playbooks/templates/create_alert_on_the_hive_automatic.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"name": "Automatically create an alert on TheHive",
"description": "Automatically create an alert on TheHive when a new alert is raised in SEKOIA.IO.",
"tags": [
"alert",
"thehive"
"Alerts",
"TheHive"
],
"workspace": "Operation Center",
"nodes": {
Expand Down
6 changes: 3 additions & 3 deletions playbooks/templates/create_alert_on_the_hive_manual.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
"name": "Manually create an Alert on TheHive",
"description": "Create an alert on TheHive via the alert page.",
"tags": [
"alert",
"webhook",
"thehive"
"Alerts",
"Webhook",
"TheHive"
],
"workspace": "Operation Center",
"nodes": {
Expand Down
3 changes: 3 additions & 0 deletions playbooks/templates/create_incident_on_cortex_xsoar.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
{
"name": "Automatically create an incident on Palo Alto Cortex XSOAR",
"tags": [
"Alerts"
],
"nodes": {
"0": {
"icon": "data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iNjYwIiBoZWlnaHQ9IjY2MCIgdmlld0JveD0iMCAwIDY2MCA0NTMiIGZpbGw9Im5vbmUiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+CjxwYXRoIGQ9Ik00MzYuMjk4IDM3My4yN0M1MTYuOTM1IDM3My4yNyA1ODIuNDY0IDMwNy42NCA1ODIuNDY0IDIyNy4xMDNDNTgyLjQ2NCAxNDYuNDY3IDUxNi44MzUgODAuOTM2OCA0MzYuMjk4IDgwLjkzNjhDMzU1Ljc2MiA4MC45MzY4IDI5MC4xMzIgMTQ2LjU2NyAyOTAuMTMyIDIyNy4xMDNDMjkwLjAzMiAzMDcuNjQgMzU1LjY2MSAzNzMuMjcgNDM2LjI5OCAzNzMuMjdaTTQzNi4yOTggMTE4Ljg1NEM0OTUuOTI1IDExOC44NTQgNTQ0LjQ0NyAxNjcuMzc2IDU0NC40NDcgMjI3LjAwM0M1NDQuNDQ3IDI4Ni42MyA0OTUuOTI1IDMzNS4xNTIgNDM2LjI5OCAzMzUuMTUyQzM3Ni42NzEgMzM1LjE1MiAzMjguMTQ5IDI4Ni43MyAzMjguMTQ5IDIyNy4wMDNDMzI4LjE0OSAxNjcuMzc2IDM3Ni42NzEgMTE4Ljg1NCA0MzYuMjk4IDExOC44NTRaTTE0Mi41NjUgMTE4Ljk1NEgxMDQuNzQ3VjMzNS4xNTJIMTQyLjU2NVYxMTguOTU0Wk0zMS45MTQ0IDQyMy44OTNINjI3LjM4NVYyOC4wMTI3SDMxLjkxNDRWNDIzLjg5M1pNNjIxLjQ4MiA0MTguMTlIMzcuNzE3VjMzLjcxNTNINjIxLjQ4MlY0MTguMTlaIiBmaWxsPSIjMkQyRTgzIi8+Cjwvc3ZnPgo=",
Expand Down
3 changes: 3 additions & 0 deletions playbooks/templates/create_jira_ticket_on_alert.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
{
"name": "Jira ticket on alert",
"description": "",
"tags": [
"Alerts"
],
"nodes": {
"1": {
"icon": "data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iNjYwIiBoZWlnaHQ9IjY2MCIgdmlld0JveD0iMCAwIDY2MCA0NTMiIGZpbGw9Im5vbmUiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+CjxwYXRoIGQ9Ik00MzYuMjk4IDM3My4yN0M1MTYuOTM1IDM3My4yNyA1ODIuNDY0IDMwNy42NCA1ODIuNDY0IDIyNy4xMDNDNTgyLjQ2NCAxNDYuNDY3IDUxNi44MzUgODAuOTM2OCA0MzYuMjk4IDgwLjkzNjhDMzU1Ljc2MiA4MC45MzY4IDI5MC4xMzIgMTQ2LjU2NyAyOTAuMTMyIDIyNy4xMDNDMjkwLjAzMiAzMDcuNjQgMzU1LjY2MSAzNzMuMjcgNDM2LjI5OCAzNzMuMjdaTTQzNi4yOTggMTE4Ljg1NEM0OTUuOTI1IDExOC44NTQgNTQ0LjQ0NyAxNjcuMzc2IDU0NC40NDcgMjI3LjAwM0M1NDQuNDQ3IDI4Ni42MyA0OTUuOTI1IDMzNS4xNTIgNDM2LjI5OCAzMzUuMTUyQzM3Ni42NzEgMzM1LjE1MiAzMjguMTQ5IDI4Ni43MyAzMjguMTQ5IDIyNy4wMDNDMzI4LjE0OSAxNjcuMzc2IDM3Ni42NzEgMTE4Ljg1NCA0MzYuMjk4IDExOC44NTRaTTE0Mi41NjUgMTE4Ljk1NEgxMDQuNzQ3VjMzNS4xNTJIMTQyLjU2NVYxMTguOTU0Wk0zMS45MTQ0IDQyMy44OTNINjI3LjM4NVYyOC4wMTI3SDMxLjkxNDRWNDIzLjg5M1pNNjIxLjQ4MiA0MTguMTlIMzcuNzE3VjMzLjcxNTNINjIxLjQ4MlY0MTguMTlaIiBmaWxsPSIjMkQyRTgzIi8+Cjwvc3ZnPgo=",
Expand Down
6 changes: 3 additions & 3 deletions playbooks/templates/email_notification_on_alert_webhook.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
"name": "Manual e-mail notification on alert",
"description": "Send an email about an alert when receiving a webhook event",
"tags": [
"alert",
"notification",
"webhook"
"Alerts",
"Notifications",
"Webhook"
],
"nodes": {
"0": {
Expand Down
2 changes: 1 addition & 1 deletion playbooks/templates/forward_panda_security_events.json
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@
"workspace": "Operation Center",
"description": "This playbook pulls security events from the Panda Security Aether platform then push them to SEKOIA.IO",
"tags": [
"events"
"Events"
],
"uuid": "441eedde-1833-48f7-8935-a3b16a2f0c7c"
}
2 changes: 1 addition & 1 deletion playbooks/templates/forward_vadesecure_records.json
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@
"workspace": "Operation Center",
"description": "This playbook collect logs from 'Vade for M365' then push them to SEKOIA.IO",
"tags": [
"events"
"Events"
],
"uuid": "eb2baec5-a3c6-4f61-8ff7-3224b56bde36"
}
6 changes: 3 additions & 3 deletions playbooks/templates/get_additional_harfang_telemetry.json
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
{
"name": "HarfangLab telemetry events",
"tags": [
"alerts",
"enrich",
"events"
"Alerts",
"Enrichment",
"Events"
],
"nodes": {
"1": {
Expand Down
8 changes: 4 additions & 4 deletions playbooks/templates/get_data_and_enrich_with_cloudflare.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@
"name": "Get data from OSINT and enrich DNS names with cloudflare DNS over HTTPs API",
"description": "Playbook to get data from OSINT and enrich it with CloudFlare DNS over HTTPs API. The playbook then upload observables to database.\n\nPlease configure 'Fetch Osint' node and 'Get domains from Fetch OSINT' jpath to get domains.",
"tags": [
"observable",
"cloudflare",
"fetch osint",
"enrich"
"Observables",
"Cloudflare",
"OSINT",
"Enrichment"
],
"workspace": "Intelligence Center",
"nodes": {
Expand Down
Loading