Endpoint Playbooks

Name SOAR App D3FEND Use Case
AD LDAP Account Locking AD LDAP D3-AL Phishing Endpoint
AWS IAM Account Locking AWS IAM D3-AL Phishing Endpoint
Active Directory Disable Account Dispatch AD LDAP, Azure AD Graph D3-AL Phishing Endpoint
Azure AD Account Locking Azure AD Graph D3-AL Phishing Endpoint
Cisco Umbrella DNS Denylisting Cisco Umbrella D3-DNSDL Phishing Endpoint
CrowdStrike OAuth API Device Attribute Lookup CrowdStrike OAuth API Enrichment Endpoint
CrowdStrike OAuth API Dynamic Analysis CrowdStrike OAuth API D3-DA Enrichment Phishing Endpoint
CrowdStrike OAuth API Endpoint Analysis CrowdStrike OAuth API D3-NTA D3-PA D3-AI Enrichment Malware Endpoint
CrowdStrike OAuth API Executable Denylisting CrowdStrike OAuth API D3-EDL Response Malware Endpoint
CrowdStrike OAuth API File Collection CrowdStrike OAuth API D3-FA Collection Malware Endpoint
CrowdStrike OAuth API File Eviction CrowdStrike OAuth API D3-FEV Response Malware Endpoint
CrowdStrike OAuth API File Restore CrowdStrike OAuth API D3-RF Response Malware Endpoint
CrowdStrike OAuth API Get Device Info CrowdStrike OAuth API Utility Endpoint
CrowdStrike OAuth API Identifier Activity Analysis CrowdStrike OAuth API D3-IAA Enrichment Endpoint
CrowdStrike OAuth API Network Isolation CrowdStrike OAuth API D3-NAM Response Malware Endpoint
CrowdStrike OAuth API Network Restore CrowdStrike OAuth API D3-RNA Response Malware Endpoint
CrowdStrike OAuth API Process Termination CrowdStrike OAuth API D3-PT Response Malware Endpoint
DNS Denylisting Dispatch D3-DNSDL Phishing Endpoint
Dynamic Analysis Dispatch D3-DA Enrichment Phishing Endpoint
Panorama Outbound Traffic Filtering Panorama D3-OTF Phishing Endpoint
Splunk Attack Analyzer Dynamic Analysis Splunk Attack Analyzer Connector for Splunk SOAR D3-DA Enrichment Phishing Endpoint
URL Outbound Traffic Filtering Dispatch D3-OTF Phishing Endpoint
UrlScan IO Dynamic Analysis urlscan.io D3-DA Enrichment Phishing Endpoint
VirusTotal V3 Dynamic Analysis VirusTotal v3 D3-DA Enrichment Phishing Endpoint
Windows Defender ATP Identifier Activity Analysis Windows Defender ATP D3-IAA Enrichment Endpoint
ZScaler Outbound Traffic Filtering Zscaler D3-OTF Phishing Endpoint