Azure-Sentinel/Playbooks/RecordedFuture_IOC_Enrichment
Adrian P 72f4b5d4c2
Add files via upload
2021-04-26 10:23:23 +01:00
..
RecordedFuture_IOC_Enrichment.json Add files via upload 2021-04-26 10:23:23 +01:00
readme.md Add files via upload 2021-04-26 10:23:23 +01:00

readme.md

Recorded Future - IOC - Enrichment

author: Adrian Porcescu, Recorded Future

This playbook leverages the Recorded Future API to automatically enrich the IP, Domain, Url and Hash indicators, found in incidents, with the following Recorded Future context: Risk Score, Risk Rules and Link to Intelligence Card. The enrichment content will be posted as a comment in the Sentinel incident. For additional information please visit Recorded Future

Links to deploy the RecordedFuture_IOC_Enrichment playbook template: