FileHash Enrichment - Palo Alto Wildfire

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook used to enrich sentinel incident with filehash information

Attribute Value
Type Playbook
Solution Standalone Content
Source View on GitHub

Logic App Connectors

This playbook uses 4 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 3
office365 Managed 1 1
wildfireconnector Managed 0 3
PaloAltoWildFire Custom 1 0
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_FileHash post /entities/filehash —
Add_comment_to_incident post /Incidents/Comment —
Add_comment_to_incident_when_exceeds_limit post /Incidents/Comment —

office365 (Managed)

Action Method Endpoint Other
Send_email_with_FileHash_attachment post /v2/Mail —

wildfireconnector (Managed)

Action Method Endpoint Other
Get_FileHash_analysis_report_in_PDF_or_XML_format post /get/report —
Get_FileHash_analysis_report_in_PDF_or_XML_format_2 post /get/report —
Get_URL_or_Hash_Verdict post /get/verdict —

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks