You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
a combination of two or more of the playbooks to create an "investigation" (this is an upper level). The idea could be to help people organize a workflow where playbooks are executed based on the result of the previous ones. For example: you could run the playbook "ip basic info": based on the data that is found, the "investigation" will suggest to run "hash analysis playbook" on an hash found in an analyzer executed by the previous playbook or "domain analysis playbook" if a suspicios domain is found. Then the user would choose the next playbook.
updated: 15th March 2022
Idea / Motivation
a combination of two or more of the playbooks to create an "investigation" (this is an upper level). The idea could be to help people organize a workflow where playbooks are executed based on the result of the previous ones. For example: you could run the playbook "ip basic info": based on the data that is found, the "investigation" will suggest to run "hash analysis playbook" on an hash found in an analyzer executed by the previous playbook or "domain analysis playbook" if a suspicios domain is found. Then the user would choose the next playbook.
Originally posted by @mlodic in #628 (comment)
Pre-requisite(s)
Implementation Idea
We have no idea so please suggest! :)
The text was updated successfully, but these errors were encountered: