Enrichment Playbooks

Name SOAR App D3FEND Use Case
AD LDAP Entity Attribute Lookup AD LDAP Enrichment
Attribute Lookup Dispatch Enrichment
Azure AD Graph User Attribute Lookup Azure AD Graph Enrichment
Cisco Talos Intelligence Identifier Reputation Analysis Cisco Talos Intelligence D3-IRA Enrichment
CrowdStrike OAuth API Device Attribute Lookup CrowdStrike OAuth API Enrichment Endpoint
CrowdStrike OAuth API Dynamic Analysis CrowdStrike OAuth API D3-DA Enrichment Phishing Endpoint
CrowdStrike OAuth API Identifier Activity Analysis CrowdStrike OAuth API D3-IAA Enrichment Endpoint
Dynamic Analysis Dispatch D3-DA Enrichment Phishing Endpoint
Identifier Activity Analysis Dispatch D3-IAA Enrichment
Identifier Reputation Analysis Dispatch D3-IRA Enrichment
PhishTank URL Reputation Analysis PhishTank D3-IRA Enrichment Phishing
Related Tickets Search Dispatch Enrichment
ServiceNow Related Tickets Search ServiceNow D3-IRA Enrichment
Splunk Attack Analyzer Dynamic Analysis Splunk Attack Analyzer Connector for Splunk SOAR D3-DA Enrichment Phishing Endpoint
Splunk Identifier Activity Analysis Splunk D3-IAA Enrichment
Splunk Notable Related Tickets Search Splunk Enrichment
UrlScan IO Dynamic Analysis urlscan.io D3-DA Enrichment Phishing Endpoint
VirusTotal V3 Dynamic Analysis VirusTotal v3 D3-DA Enrichment Phishing Endpoint
VirusTotal v3 Identifier Reputation Analysis VirusTotal v3 D3-IRA D3-URA D3-DNRA D3-IPRA D3-FHRA Enrichment
Windows Defender ATP Identifier Activity Analysis Windows Defender ATP D3-IAA Enrichment Endpoint