Shodan - Enrich Domain Name
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Content Index
This playbook can be triggered manually from a Domain Entity context to fetch geo location and running services details from Shodan.io.
Additional Documentation
📄 Source: ShodanPlaybooks/Shodan-EnrichDomain-EntityTrigger/readme.md
Shodan-EnrichDomain-EntityTrigger
Summary
The playbook can be triggered manually from a Domain Entity context to fetch geo location and running services details from Shodan.io. This playbook performs following actions:
- Get the domain name from entity.
- Query Shodan.io to fetch geo location and running services details.
- Collect all the details and format as table.
- Add the collected details as comment to the incident.


Prerequisites
- Prior to the deployment of this playbook, Shodan Logic App Custom Connector needs to be deployed under the same subscription.
- Refer to Shodan Logic App Custom Connector documentation for deployment instructions.
Deployment instructions
- To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
- Fill in the required parameters:
- Playbook Name
- Custom Connector Name

Post-Deployment instructions
a. Authorize connections
Once deployment is complete, authorize each connection.
- Select the Microsoft Sentinel connection resource
- Click Edit API connection blade
- Click Authorize/Provide credentials
- Click Save
- Repeat these steps for other connections
b. Assign Playbook Microsoft Sentinel Responder Role
- Select the Playbook (Logic App) resource
- Click on Identity Blade
- Choose System assigned tab
- Click on Azure role assignments
- Click on Add role assignments
- Select Scope - Resource group
- Select Subscription - where Playbook has been created
- Select Resource group - where Playbook has been created
- Select Role - Microsoft Sentinel Responder
- Click Save
References
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Playbooks · Back to Shodan