Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CIAC-10488/Add-Masquerading-playbook-to-XSOAR #35063

Closed
Closed
Show file tree
Hide file tree
Changes from 13 commits
Commits
Show all changes
96 commits
Select commit Hold shift + click to select a range
35754da
Add Masquerading playbook
efelmandar May 19, 2024
13c5ff2
Add playbook image
efelmandar May 19, 2024
04020b5
Update playbook image and docs, update possible verdict task name, up…
efelmandar May 30, 2024
4c1f3e3
Update possible verdict task name
efelmandar May 30, 2024
e44593a
Merge branch 'master' into CIAC-10488/Add-Masquerading-playbook-to-XSOAR
efelmandar Jun 25, 2024
3ef3b2b
Update subplaybook inputs
efelmandar Jun 25, 2024
1f61aed
Fix changes according to review comments
efelmandar Jun 25, 2024
a030b60
Update playbook description
efelmandar Jun 25, 2024
31a9b65
Update playbook image
efelmandar Jun 25, 2024
3c7d889
Fix validation errors
efelmandar Jun 25, 2024
268960f
Update release notes
efelmandar Jun 25, 2024
7f5f28e
Fix validation errors
efelmandar Jun 25, 2024
fa141a0
Fix validation errors
efelmandar Jun 26, 2024
3692ac3
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml
efelmandar Jun 27, 2024
ac1205b
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml
efelmandar Jun 27, 2024
b605565
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml
efelmandar Jun 27, 2024
7490b8a
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml
efelmandar Jun 27, 2024
c48fc7d
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml
efelmandar Jun 27, 2024
3f2ca86
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml
efelmandar Jun 27, 2024
5242e6c
Update Packs/CortexXDR/Playbooks/Cortex_XDR_Alerts_Handling_v2.yml
efelmandar Jun 27, 2024
43ea3c8
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
6df78f3
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
787b297
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
1b18759
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
5784903
Update Packs/CortexXDR/ReleaseNotes/6_1_49.md
efelmandar Jun 27, 2024
e8100a7
Update Packs/CortexXDR/Playbooks/Cortex_XDR_Alerts_Handling_v2.yml
efelmandar Jun 27, 2024
5d6ab44
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
bf417b9
Update Packs/CortexXDR/Playbooks/Cortex_XDR_Alerts_Handling_v2.yml
efelmandar Jun 27, 2024
4674869
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
cb3572b
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
3f3fb05
Update Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading_RE…
efelmandar Jun 27, 2024
304fcd6
Remove Manual containment, Update condition check all CommandlineVerd…
efelmandar Jun 30, 2024
e357a8d
Merge branch 'CIAC-10488/Add-Masquerading-playbook-to-XSOAR' of https…
efelmandar Jun 30, 2024
9f94356
Update playbook image
efelmandar Jun 30, 2024
a37412f
Remove unnecessary OnError task
efelmandar Jun 30, 2024
c3d01d8
Merge branch 'master' into CIAC-10488/Add-Masquerading-playbook-to-XSOAR
efelmandar Jun 30, 2024
d7c2a88
Merged master into current branch.
Jul 1, 2024
15c62d1
Bump pack from version CortexXDR to 6.1.50.
Jul 1, 2024
f4592c6
Merged master into current branch.
Jul 2, 2024
937c377
Bump pack from version CortexXDR to 6.1.51.
Jul 2, 2024
62185e9
Merged master into current branch.
Jul 4, 2024
2782015
Bump pack from version CortexXDR to 6.1.52.
Jul 4, 2024
fd8bfd7
Merge branch 'master' into CIAC-10488/Add-Masquerading-playbook-to-XSOAR
efelmandar Jul 6, 2024
73a547c
Update changes in playbook
efelmandar Jul 6, 2024
baf4317
Update playbook from master
efelmandar Jul 6, 2024
a7a4467
Update release notes
efelmandar Jul 6, 2024
ddd91ef
Fix validation errors
efelmandar Jul 7, 2024
54352ab
Merge branch 'master' into CIAC-10488/Add-Masquerading-playbook-to-XSOAR
efelmandar Jul 7, 2024
ecf85f2
Merge branch 'master' into CIAC-10488/Add-Masquerading-playbook-to-XSOAR
efelmandar Jul 7, 2024
9500e70
Remove quarantine file task
efelmandar Jul 7, 2024
2077589
Remove FilePath input
efelmandar Jul 7, 2024
e5d908a
Merged master into current branch.
Jul 8, 2024
24121b3
Bump pack from version CortexXDR to 6.1.54.
Jul 8, 2024
c9e608e
Merged master into current branch.
Jul 9, 2024
7e553ef
Bump pack from version CortexXDR to 6.1.55.
Jul 9, 2024
4085572
Merged master into current branch.
Jul 9, 2024
f9d812d
Bump pack from version CortexXDR to 6.1.56.
Jul 9, 2024
982d613
Merged master into current branch.
Jul 9, 2024
bce9c4b
Bump pack from version CortexXDR to 6.1.55.
Jul 9, 2024
dcbc377
Fix validation errors
efelmandar Jul 10, 2024
d8c95e9
Merge branch 'CIAC-10488/Add-Masquerading-playbook-to-XSOAR' of https…
efelmandar Jul 10, 2024
c0de239
Merge branch 'master' into CIAC-10488/Add-Masquerading-playbook-to-XSOAR
efelmandar Jul 10, 2024
8f4ba40
updated missing keys from master
efelmandar Jul 14, 2024
af1e764
Merge branch 'master' of https://github.com/demisto/content into CIAC…
efelmandar Jul 14, 2024
e9c8c61
Merged master into current branch.
Jul 21, 2024
a62cee2
Bump pack from version CortexXDR to 6.1.56.
Jul 21, 2024
c112897
Merged master into current branch.
Jul 23, 2024
51bc577
Bump pack from version CortexXDR to 6.1.57.
Jul 23, 2024
07eb22e
Merged master into current branch.
Jul 24, 2024
24de5f4
Bump pack from version CortexXDR to 6.1.58.
Jul 24, 2024
022d4fd
Merged master into current branch.
Jul 25, 2024
8564754
Bump pack from version CortexXDR to 6.1.59.
Jul 25, 2024
eb4285c
Merged master into current branch.
Aug 5, 2024
8936fca
Bump pack from version CortexXDR to 6.1.60.
Aug 5, 2024
352b214
Merged master into current branch.
Aug 6, 2024
c15fc88
Bump pack from version CortexXDR to 6.1.61.
Aug 6, 2024
a322ebd
Merged master into current branch.
Aug 7, 2024
8b80d1d
Bump pack from version CortexXDR to 6.1.62.
Aug 7, 2024
5eecc9b
Merged master into current branch.
Aug 9, 2024
6dff1ba
Bump pack from version CortexXDR to 6.1.63.
Aug 9, 2024
eaf49cb
Merged master into current branch.
Aug 15, 2024
4467e7a
Bump pack from version CortexXDR to 6.1.64.
Aug 15, 2024
33e7f14
Merged master into current branch.
Aug 15, 2024
1a87dff
Bump pack from version CortexXDR to 6.1.65.
Aug 15, 2024
bc25ecb
Merged master into current branch.
Aug 18, 2024
51ae1dc
Bump pack from version CortexXDR to 6.1.66.
Aug 18, 2024
a1c1e50
Merged master into current branch.
Aug 28, 2024
28e4a33
Bump pack from version CortexXDR to 6.1.67.
Aug 28, 2024
0733e90
Merged master into current branch.
Sep 4, 2024
e3d1a6f
Bump pack from version CortexXDR to 6.1.68.
Sep 4, 2024
6e5cfe2
Merged master into current branch.
Sep 5, 2024
2edf6d0
Bump pack from version CortexXDR to 6.1.69.
Sep 5, 2024
9db7e98
Merged master into current branch.
Sep 9, 2024
64a249d
Bump pack from version CortexXDR to 6.1.70.
Sep 9, 2024
9fdcffa
Merged master into current branch.
Sep 11, 2024
6ea22db
Bump pack from version CortexXDR to 6.1.71.
Sep 11, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1,045 changes: 1,045 additions & 0 deletions Packs/CortexXDR/Playbooks/Cortex_XDR_-_T1036_-_Masquerading.yml

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
This playbook handles masquerading alerts based on the MITRE T1036 technique.
An attacker might leverage Microsoft Windows well-known image names to run malicious processes without being caught.

**Attacker's Goals:**

An attacker is attempting to masquerade as standard windows images by using a trusted name to execute malicious code.
efelmandar marked this conversation as resolved.
Show resolved Hide resolved

**Investigative Actions:**

Investigate the executed process image and verify if it is malicious using:

* XDR trusted signers
* VT trusted signers
* VT detection rate
* NSRL DB

**Response Actions**

The playbook's first response action is a containment plan which is based on the initial data provided within the alert. In that phase, the playbook will execute:

* Auto block indicators
* Auto file quarantine
* Manual endpoint isolation

When the playbook executes, it checks for additional activity, and if a malicious behavior is found, the playbook proceeds with containment and eradication, is executed.
efelmandar marked this conversation as resolved.
Show resolved Hide resolved

This phase will execute the following containment actions:

* Manual block indicators
* Manual file quarantine
* Auto endpoint isolation
* Auto process termination

External resources:

[MITRE Technique T1036](https://attack.mitre.org/techniques/T1036/)

[Possible Microsoft process masquerading](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR-Analytics-Alert-Reference/Possible-Microsoft-process-masquerading).
efelmandar marked this conversation as resolved.
Show resolved Hide resolved

## Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

### Sub-playbooks

* Detonate File - Generic
* Command-Line Analysis
* Entity Enrichment - Generic v3
* Cortex XDR - Quarantine File v2
* Cortex XDR - Endpoint Investigation

### Integrations

* CortexXDRIR
efelmandar marked this conversation as resolved.
Show resolved Hide resolved

### Scripts

* GetErrorsFromEntry
* HttpV2
* ParseJSON

### Commands

* xdr-snippet-code-script-execute
efelmandar marked this conversation as resolved.
Show resolved Hide resolved

## Playbook Inputs

---

| **Name** | **Description** | **Default Value** | **Required** |
| --- | --- | --- | --- |
| AutoContainment | Setting this input to True will quarantine the file automatically in case of malicious file. | True | Optional |
efelmandar marked this conversation as resolved.
Show resolved Hide resolved
| FileSHA256 | The file SHA256 to investigate. | PaloAltoNetworksXDR.Incident.alerts.actor_process_image_sha256 | Optional |
| FilePath | The file path to investigate. | PaloAltoNetworksXDR.Incident.alerts.actor_process_image_path | Optional |
| Username | The alert's username. | PaloAltoNetworksXDR.Incident.alerts.user_name | Optional |
| EndpointID | The IP, Hostname or ID of the Endpoint | PaloAltoNetworksXDR.Incident.alerts.endpoint_id | Optional |
efelmandar marked this conversation as resolved.
Show resolved Hide resolved
| AlertID | The ID of the alert | PaloAltoNetworksXDR.Incident.alerts.aler_id | Optional |
efelmandar marked this conversation as resolved.
Show resolved Hide resolved

## Playbook Outputs

---
There are no outputs for this playbook.

## Playbook Image

---

![Cortex XDR - T1036 - Masquerading](../doc_files/Cortex_XDR_-_T1036_-_Masquerading.png)
Loading
Loading