Azure-Sentinel/Playbooks/RecordedFuture_IP_Enrichment
Adrian P d68e207bf7
Add files via upload
2020-11-26 12:39:55 +00:00
..
RecordedFuture_IP_Enrichment.json Add files via upload 2020-11-26 12:39:55 +00:00
readme.md Add files via upload 2020-11-09 10:17:16 +00:00

readme.md

Recorded Future - IP - Enrichment

author: Adrian Porcescu, Recorded Future

This playbook leverages the Recorded Future API to automatically enrich the IP indicators found in the alert with the following Recorded Future context: Risk Score, Risk Rules and Link to Intelligence Card. The enrichment content will be posted as a comment in the Sentinel incident. For additional information please visit Recorded Future

Links to deploy the RecordedFuture_IP_Enrichment playbook template: