Playbook to update IOCs on Microsoft Advanced Threat Protection (APT)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Playbook to update IOCs on Microsoft Advanced Threat Protection (APT)

L1 Bithead

I want to achieve below steps. is there any exiting playbook or have to customized playbook?

Step 1: Checking Existing IOCs in Microsoft APT

In this first step, we will fetch the list of existing IOCs from Microsoft APT and compare them with the IOCs you wish to add.

Step 2: Handling Existing IOCs

Upon comparing the fetched list with your desired IOCs, we will identify the existing items. Those already present in Microsoft APT will be ignored, and a notification email will be sent to your team, providing details about these items.

Step 3: Adding New IOCs to Microsoft APT

For the IOCs that are not already in Microsoft APT, we will proceed to add them using the XSOAR integration with Microsoft APT.

Step 4: Cross-Checking Addition of IOCs

After successfully adding the new IOCs, we will perform a cross-check by fetching the IOCs from Microsoft APT again. This verification step ensures the accuracy of the additions.

Step 5: Notifying the Team

Once the cross-check confirms that the new IOCs are added to Microsoft APT, we will use the "Send Email" integration in XSOAR to notify your team about the successful addition.

if required custom playbook, kindly help me which automation I should use.?

1 REPLY 1

L3 Networker

Hello Vhebri,

 

I found this content pack from called 'Microsoft Defender for Endpoint' that includes this in the description:

  • Enriches IOCs from XSOAR to Microsoft Defender for Endpoint and vice versa,

and it allows the Microsoft Defender for Endpoint integration to import events as XSOAR incidents.

This should accomplish the items you are looking for. Hope this helps! 

 

Link here: https://cortex.marketplace.pan.dev/marketplace/details/MicrosoftDefenderAdvancedThreatProtection/

  • 1053 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!