FileHash Enrichment - Palo Alto Wildfire

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook used to enrich sentinel incident with filehash information

Attribute Value
Type Playbook
Solution Standalone Content
Source View on GitHub

Logic App Connectors

This playbook uses 4 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 3
office365 Managed 1 1
wildfireconnector Managed 0 3
PaloAltoWildFire Custom 1 0
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_FileHash post /entities/filehash
Add_comment_to_incident post /Incidents/Comment
Add_comment_to_incident_when_exceeds_limit post /Incidents/Comment

office365 (Managed)

Action Method Endpoint Other
Send_email_with_FileHash_attachment post /v2/Mail

wildfireconnector (Managed)

Action Method Endpoint Other
Get_FileHash_analysis_report_in_PDF_or_XML_format post /get/report
Get_FileHash_analysis_report_in_PDF_or_XML_format_2 post /get/report
Get_URL_or_Hash_Verdict post /get/verdict

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks