{
  "type": "workflow_collections",
  "data": [
    {
      "@type": "WorkflowCollection",
      "name": "IOC Extraction from Attachments",
      "description": "",
      "visible": true,
      "image": null,
      "recordTags": [],
      "workflows": [
        {
          "@type": "Workflow",
          "triggerLimit": null,
          "name": "Auto Ingest IoCs >> Create Indicator Records",
          "aliasName": null,
          "tag": null,
          "description": "Create Indicators Form Attachments",
          "isActive": false,
          "debug": false,
          "singleRecordExecution": false,
          "remoteExecutableFlag": false,
          "parameters": [
            "data",
            "ioc_type",
            "ioc_blocked",
            "confidence",
            "reputation",
            "tlp",
            "alert_iri"
          ],
          "synchronous": false,
          "triggerStep": "/api/3/workflow_steps/08c0dd3d-4ac7-4d77-96e7-b3a47c9ddce7",
          "steps": [
            {
              "@type": "WorkflowStep",
              "name": "Configuration",
              "description": null,
              "arguments": {
                "expiry": "7",
                "iocList": "{{vars.input.params.data}}",
                "tlp_map": "{'Red': {{'TrafficLightProtocol'| picklist('Red') }}, 'Amber': {{'TrafficLightProtocol'| picklist('Amber') }}, 'Green': {{'TrafficLightProtocol'| picklist('Green') }}, 'White': {{'TrafficLightProtocol'| picklist('White') }}}",
                "type_map": "{\n  \"sha256s\": {{ \"IndicatorType\" | picklist(\"FileHash-SHA256\") }},\n  \"md5s\": {{ \"IndicatorType\" | picklist(\"FileHash-MD5\") }},\n  \"sha1s,\": {{ \"IndicatorType\" | picklist(\"FileHash-SHA1\") }},\n  \"urls\": {{ \"IndicatorType\" | picklist(\"URL\") }},\n  \"ipv4s, ipv6s\": {{ \"IndicatorType\" | picklist(\"IP Address\") }},\n  \"file_paths\": {{ \"IndicatorType\" | picklist(\"File\") }},\n  \"domains\": {{ \"IndicatorType\" | picklist(\"Domain\") }},\n  \"email_addresses_complete, email_addresses\": {{ \"IndicatorType\" | picklist(\"Email Address\") }},\n  \"mac_addresses\": {{ \"IndicatorType\" | picklist(\"MAC Address\") }},\n  \"registry_key_paths\": {{ \"IndicatorType\" | picklist(\"Registry\") }},\n  \"port\": {{ \"IndicatorType\" | picklist(\"Port\") }},\n  \"user\": {{ \"IndicatorType\" | picklist(\"User\") }}\n}",
                "alert_iri": "{{vars.input.params['alert_iri']}}",
                "ioc_status": "{{ 'IndicatorStatus' | picklist('Blocked')\n   if vars.input.params.ioc_blocked in [true, 'true', 'True', 1, '1']\n   else 'IndicatorStatus' | picklist('TBD') }}",
                "reputation_map": "{'Good': {{'IndicatorReputation'| picklist('Good') }}, 'Malicious': {{'IndicatorReputation'| picklist('Malicious') }}, 'Suspicious': {{'IndicatorReputation'| picklist('Suspicious') }}, 'TBD': {{'IndicatorReputation'| picklist('TBD') }}, 'No Reputation Available': {{'IndicatorReputation'| picklist('No Reputation Available') }}}"
              },
              "status": null,
              "top": "165",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "20cacc27-7b18-4c4e-b4c9-d36c7b15cb43"
            },
            {
              "@type": "WorkflowStep",
              "name": "Create IoCs",
              "description": null,
              "arguments": {
                "when": "{{vars.iocList | length > 0}}",
                "for_each": {
                  "item": "{{vars.iocList}}",
                  "__bulk": true,
                  "parallel": false,
                  "condition": "",
                  "batch_size": 100
                },
                "resource": {
                  "tlp": "{{vars.input.params.tlp | resolveRange(vars.tlp_map)}}",
                  "value": "{{vars.item}}",
                  "__link": {
                    "alerts": "{{vars.alert_iri}}"
                  },
                  "lastSeen": "{{arrow.utcnow().int_timestamp}}",
                  "__replace": "true",
                  "confidence": "{{vars.input.params.confidence}}",
                  "expiryDate": "{{ arrow.now().int_timestamp + (vars.expiry | int) * 86400 }}",
                  "reputation": "{{vars.input.params.reputation | resolveRange(vars.reputation_map)}}",
                  "indicatorStatus": "/api/3/picklists/4218cb58-4de5-4eff-ad08-185d36ef9bab",
                  "typeofindicator": "{{vars.input.params['ioc_type'] | resolveRange(vars.type_map)}}",
                  "__fieldsToUpdate": [
                    "expiryDate",
                    "confidence",
                    "lastSeen"
                  ],
                  "enrichmentStatus": "/api/3/picklists/a6d9da29-27b1-4b8a-965d-8d91518540d5"
                },
                "operation": "Append",
                "collection": "/api/3/upsert/indicators",
                "__recommend": [],
                "fieldOperation": {
                  "recordTags": "Append"
                },
                "step_variables": []
              },
              "status": null,
              "top": "300",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/2597053c-e718-44b4-8394-4d40fe26d357",
              "group": null,
              "uuid": "987e8806-e043-4273-9e8f-14be52b0c494"
            },
            {
              "@type": "WorkflowStep",
              "name": "Fetch Unblocked IoCs",
              "description": "This step will collect indicators with status is not blocked",
              "arguments": {
                "iocRecords": "{%- set ioclist = [] -%}\n{%- for i in vars.steps.Create_IoCs -%}{%- if \"Blocked\" not in i.indicatorStatus.itemValue -%}\n{%- set tmp = ioclist.append({\"IRI\":i['@id'],\"Value\": i.value , \"Type\":i.typeofindicator.itemValue})-%}{%-endif-%}{%-endfor-%}{{ioclist}}"
              },
              "status": null,
              "top": "435",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "2034def4-9d6a-470e-a773-80c679f7117d"
            },
            {
              "@type": "WorkflowStep",
              "name": "Start",
              "description": null,
              "arguments": {
                "__triggerLimit": true,
                "step_variables": {
                  "input": {
                    "params": []
                  }
                },
                "triggerOnSource": true,
                "triggerOnReplicate": false
              },
              "status": null,
              "top": "30",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/b348f017-9a94-471f-87f8-ce88b6a7ad62",
              "group": null,
              "uuid": "08c0dd3d-4ac7-4d77-96e7-b3a47c9ddce7"
            }
          ],
          "routes": [
            {
              "@type": "WorkflowRoute",
              "name": "Configuration -> Create IoCs",
              "targetStep": "/api/3/workflow_steps/987e8806-e043-4273-9e8f-14be52b0c494",
              "sourceStep": "/api/3/workflow_steps/20cacc27-7b18-4c4e-b4c9-d36c7b15cb43",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "2ee86bbf-a5e7-4805-9077-d5adf3d41632"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Create IoCs -> Fetch Selected IoC Fields",
              "targetStep": "/api/3/workflow_steps/2034def4-9d6a-470e-a773-80c679f7117d",
              "sourceStep": "/api/3/workflow_steps/987e8806-e043-4273-9e8f-14be52b0c494",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "06899555-035b-405a-8367-11e7e4caa416"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Start -> Configuration",
              "targetStep": "/api/3/workflow_steps/20cacc27-7b18-4c4e-b4c9-d36c7b15cb43",
              "sourceStep": "/api/3/workflow_steps/08c0dd3d-4ac7-4d77-96e7-b3a47c9ddce7",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "b583c216-e2e3-4854-9015-a225af2512a9"
            }
          ],
          "groups": [],
          "priority": "/api/3/picklists/2b563c61-ae2c-41c0-a85a-c9709585e3f2",
          "isEditable": false,
          "uuid": "a524141f-5e5b-4908-a1b7-64e47ecc251b",
          "isPrivate": false,
          "recordTags": [
            "Extract IoCs",
            "Subroutine"
          ]
        },
        {
          "@type": "Workflow",
          "triggerLimit": null,
          "name": "Auto IOC Ingest- Review and Send IOC to Block",
          "aliasName": null,
          "tag": null,
          "description": "This playbook will ingest the indicators from attached file and will block it to devices.",
          "isActive": false,
          "debug": false,
          "singleRecordExecution": false,
          "remoteExecutableFlag": false,
          "parameters": [],
          "synchronous": false,
          "triggerStep": "/api/3/workflow_steps/31227446-c49c-4631-89e5-73ca01bf451b",
          "steps": [
            {
              "@type": "WorkflowStep",
              "name": "Check Alert Has Attachments",
              "description": null,
              "arguments": {
                "conditions": [
                  {
                    "option": "Has Attachments",
                    "step_iri": "/api/3/workflow_steps/e0f03053-2de6-4b16-a301-e0747d83a19d",
                    "condition": "{{ vars.steps.Get_Attachment_IRI_from_Alert[0].attachments | length > 0 }}",
                    "step_name": "Get Attachment Details"
                  },
                  {
                    "option": "No Attachmnets",
                    "default": true,
                    "step_iri": "/api/3/workflow_steps/b5160005-81ff-41d2-9624-c97908e6c9b3",
                    "step_name": "No Operation"
                  }
                ],
                "step_variables": []
              },
              "status": null,
              "top": "435",
              "left": "300",
              "stepType": "/api/3/workflow_step_types/12254cf5-5db7-4b1a-8cb1-3af081924b28",
              "group": null,
              "uuid": "b36ee0e8-3973-488a-a3db-77d7c75439e9"
            },
            {
              "@type": "WorkflowStep",
              "name": "Configuration",
              "description": null,
              "arguments": {
                "alert_iri": "{{vars.input.records[0]['@id']}}"
              },
              "status": null,
              "top": "165",
              "left": "300",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "78fcdb6f-8b6f-47b2-822f-e7fb24846a3f"
            },
            {
              "@type": "WorkflowStep",
              "name": "Get Attachment Details",
              "description": null,
              "arguments": {
                "attachment_uuid": "{{ vars.steps.Get_Attachment_IRI_from_Alert[0].attachments\n   | map(attribute='@id')\n   | map('replace', '/api/3/attachments/', '')\n   | list }}"
              },
              "status": null,
              "top": "570",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "e0f03053-2de6-4b16-a301-e0747d83a19d"
            },
            {
              "@type": "WorkflowStep",
              "name": "Get Attachment IRI from Alert",
              "description": null,
              "arguments": {
                "query": {
                  "sort": [],
                  "limit": 30,
                  "logic": "AND",
                  "filters": [
                    {
                      "type": "primitive",
                      "field": "uuid",
                      "value": "{{ vars.input.records[0]['@id'] | split('/') | last }}",
                      "operator": "eq",
                      "_operator": "eq"
                    }
                  ],
                  "__selectFields": [
                    "attachments"
                  ]
                },
                "module": "alerts?$limit=30&$relationships=true&$fsr_max_relation_count=30",
                "checkboxFields": true,
                "step_variables": {
                  "has_attachment": "{{vars.steps.Get_Attachment_IRI_from_Alert}}"
                }
              },
              "status": null,
              "top": "300",
              "left": "300",
              "stepType": "/api/3/workflow_step_types/b593663d-7d13-40ce-a3a3-96dece928770",
              "group": null,
              "uuid": "3cfa4d3c-8280-408f-b184-5b3cbb521407"
            },
            {
              "@type": "WorkflowStep",
              "name": "No Operation",
              "description": null,
              "arguments": {
                "params": [],
                "message": {
                  "tags": [],
                  "type": "/api/3/picklists/ff599189-3eeb-4c86-acb0-a7915e85ac3b",
                  "tenant": "",
                  "thread": false,
                  "content": "<p>This alert has no attachments available for IoC processing.</p>",
                  "records": "{{vars.input.records[0]['@id']}}"
                },
                "version": "3.7.0",
                "connector": "cyops_utilities",
                "operation": "no_op",
                "ignore_errors": true,
                "operationTitle": "Utils: No Operation",
                "step_variables": []
              },
              "status": null,
              "top": "570",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/0109f35d-090b-4a2b-bd8a-94cbc3508562",
              "group": null,
              "uuid": "b5160005-81ff-41d2-9624-c97908e6c9b3"
            },
            {
              "@type": "WorkflowStep",
              "name": "Process IoCs",
              "description": null,
              "arguments": {
                "arguments": {
                  "alert_iri": "{{vars.alert_iri}}",
                  "attachment_uuid": "{{vars.attachment_uuid}}"
                },
                "apply_async": false,
                "step_variables": [],
                "pass_parent_env": false,
                "pass_input_record": false,
                "workflowReference": "/api/3/workflows/8d23cf2d-4f09-431f-af77-b14574851e2a"
              },
              "status": null,
              "top": "705",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/74932bdc-b8b6-4d24-88c4-1a4dfbc524f3",
              "group": null,
              "uuid": "7db3f9d5-2d75-4e10-a2aa-7d0903913377"
            },
            {
              "@type": "WorkflowStep",
              "name": "Start",
              "description": null,
              "arguments": {
                "route": "2ffec828-9c78-4a81-a455-b8c77c01a604",
                "resources": [
                  "alerts"
                ],
                "__triggerLimit": true,
                "inputVariables": [],
                "step_variables": {
                  "input": {
                    "params": [],
                    "records": "{{vars.input.records}}"
                  }
                },
                "_promptexpanded": true,
                "triggerOnSource": true,
                "displayConditions": {
                  "alerts": {
                    "sort": [],
                    "limit": 30,
                    "logic": "AND",
                    "filters": []
                  }
                },
                "executeButtonText": "Auto IOC Ingest",
                "noRecordExecution": false,
                "showToasterMessage": {
                  "message": "Ingest IoC from the attached file",
                  "visible": true,
                  "messageVisible": true
                },
                "triggerOnReplicate": false,
                "singleRecordExecution": true
              },
              "status": null,
              "top": "30",
              "left": "300",
              "stepType": "/api/3/workflow_step_types/f414d039-bb0d-4e59-9c39-a8f1e880b18a",
              "group": null,
              "uuid": "31227446-c49c-4631-89e5-73ca01bf451b"
            }
          ],
          "routes": [
            {
              "@type": "WorkflowRoute",
              "name": "Check whether Alerts has Attachment or not -> Get Attachment Details",
              "targetStep": "/api/3/workflow_steps/e0f03053-2de6-4b16-a301-e0747d83a19d",
              "sourceStep": "/api/3/workflow_steps/b36ee0e8-3973-488a-a3db-77d7c75439e9",
              "label": "Has Attachments",
              "isExecuted": false,
              "group": null,
              "uuid": "bcaa1e76-c856-4d70-a366-3eacd135e534"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Check whether Alerts has Attachment or not -> No Operation",
              "targetStep": "/api/3/workflow_steps/b5160005-81ff-41d2-9624-c97908e6c9b3",
              "sourceStep": "/api/3/workflow_steps/b36ee0e8-3973-488a-a3db-77d7c75439e9",
              "label": "No Attachmnets",
              "isExecuted": false,
              "group": null,
              "uuid": "05534c01-d416-4671-bc65-e16ed97932ea"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Configuration -> Get Attachment IRI from Alert_",
              "targetStep": "/api/3/workflow_steps/3cfa4d3c-8280-408f-b184-5b3cbb521407",
              "sourceStep": "/api/3/workflow_steps/78fcdb6f-8b6f-47b2-822f-e7fb24846a3f",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "61fb22bd-9c8f-49b5-a201-6868aed43e7b"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Get Attachment Details -> Process IoCs",
              "targetStep": "/api/3/workflow_steps/7db3f9d5-2d75-4e10-a2aa-7d0903913377",
              "sourceStep": "/api/3/workflow_steps/e0f03053-2de6-4b16-a301-e0747d83a19d",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "5635c51a-892f-4ed9-9162-e325313e7043"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Get Attachment IRI from Alert -> Check whether Alerts has Attachment or not",
              "targetStep": "/api/3/workflow_steps/b36ee0e8-3973-488a-a3db-77d7c75439e9",
              "sourceStep": "/api/3/workflow_steps/3cfa4d3c-8280-408f-b184-5b3cbb521407",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "08c4f5dd-a4ab-498e-b297-43ea0121eb38"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Start -> test",
              "targetStep": "/api/3/workflow_steps/78fcdb6f-8b6f-47b2-822f-e7fb24846a3f",
              "sourceStep": "/api/3/workflow_steps/31227446-c49c-4631-89e5-73ca01bf451b",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "566cc231-06b4-4049-9abe-603d64504046"
            }
          ],
          "groups": [],
          "priority": "/api/3/picklists/2b563c61-ae2c-41c0-a85a-c9709585e3f2",
          "isEditable": false,
          "uuid": "626c43e7-cd59-4b21-a2c6-2b2be33974d7",
          "isPrivate": false,
          "recordTags": [
            "Extract IoCs",
            "ManualTrigger"
          ]
        },
        {
          "@type": "Workflow",
          "triggerLimit": null,
          "name": "Scenario - Generating Alert with IOC attachments",
          "aliasName": null,
          "tag": null,
          "description": "Create Alert which has attachment record link to it.",
          "isActive": false,
          "debug": false,
          "singleRecordExecution": false,
          "remoteExecutableFlag": false,
          "parameters": [],
          "synchronous": false,
          "triggerStep": "/api/3/workflow_steps/6abb1518-b2f8-4217-9690-8fe6e6ea9560",
          "steps": [
            {
              "@type": "WorkflowStep",
              "name": "Configuration",
              "description": null,
              "arguments": {
                "file_content": "\"203.0.113.10\n203.0.113.25\n198.51.100.7\n198.51.100.42\n192.0.2.55\n192.0.2.81\ntest.com\ntest1.com\ntest2.com\nhttps://example.com\nhttps://example.org\nhttps://myapp.com\nhttps://secureapi.tech\""
              },
              "status": null,
              "top": "165",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "40f68db6-d9aa-4f91-8740-58d822edaa25"
            },
            {
              "@type": "WorkflowStep",
              "name": "Create Email Alert",
              "description": null,
              "arguments": {
                "resource": {
                  "beta": false,
                  "name": "IOC Processing",
                  "type": "/api/3/picklists/574a6ee2-7265-4701-815e-cff83b053bce",
                  "state": "/api/3/picklists/a1bac09b-1441-45aa-ad1b-c88744e48e72",
                  "raised": "/api/3/picklists/5434ed03-11ab-4652-ac72-bdfaf0e91ef5",
                  "source": "Exchange",
                  "status": "/api/3/picklists/7de816ff-7140-4ee5-bd05-93ce22002146",
                  "severity": "/api/3/picklists/58d0753f-f7e4-403b-953c-b0f521eab759",
                  "__replace": "true",
                  "spotCheck": false,
                  "assignedTo": "{{globalVars.Current_User}}",
                  "description": "This alert is generated by the scenario for demonstration purposes and showcases the IoC Processing Solution Pack playbooks.",
                  "ackSlaStatus": "/api/3/picklists/72979f64-e8b9-4888-a965-957e0ec24818",
                  "respSlaStatus": "/api/3/picklists/72979f64-e8b9-4888-a965-957e0ec24818",
                  "priorityWeight": 1,
                  "escalatedtoincident": "/api/3/picklists/2128a09c-153d-4db3-985d-de6be33deae5",
                  "resolvedAutomatedly": false,
                  "alertRemainingAckSLA": 0
                },
                "operation": "Overwrite",
                "collection": "/api/3/upsert/alerts",
                "__recommend": [],
                "fieldOperation": {
                  "automation": "Overwrite",
                  "enrichmentState": "Overwrite"
                },
                "step_variables": []
              },
              "status": null,
              "top": "300",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/2597053c-e718-44b4-8394-4d40fe26d357",
              "group": null,
              "uuid": "7ac1d28e-3e49-480a-81fd-6c1e1f16fc03"
            },
            {
              "@type": "WorkflowStep",
              "name": "Create File From String",
              "description": null,
              "arguments": {
                "params": {
                  "contents": "{{vars.file_content}}",
                  "filename": "test_ioc",
                  "mimetype": "text/plain"
                },
                "version": "3.7.0",
                "connector": "cyops_utilities",
                "operation": "create_file_from_string",
                "operationTitle": "File: Create File from String",
                "step_variables": []
              },
              "status": null,
              "top": "435",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/0109f35d-090b-4a2b-bd8a-94cbc3508562",
              "group": null,
              "uuid": "0d47f7f1-3409-4d92-abaf-1393299a5b13"
            },
            {
              "@type": "WorkflowStep",
              "name": "Create the Attachment Record",
              "description": null,
              "arguments": {
                "params": {
                  "name": "IOCs to Process",
                  "filename": "/tmp/{{vars.steps.Create_File_From_String.data.filename}}",
                  "description": "This file includes test IoCs intended to simulate scenarios for the IoC Processing Solution Pack. The provided IOCs can be further processed as part of investigation workflows.",
                  "request_headers": "",
                  "multipart_headers": "",
                  "extra_multipart_fields": ""
                },
                "version": "3.7.0",
                "connector": "cyops_utilities",
                "operation": "create_cyops_attachment",
                "operationTitle": "File: Create Attachment from File",
                "step_variables": []
              },
              "status": null,
              "top": "570",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/0109f35d-090b-4a2b-bd8a-94cbc3508562",
              "group": null,
              "uuid": "f1043563-cc50-4b97-8fda-5e1b2137ddf0"
            },
            {
              "@type": "WorkflowStep",
              "name": "Return Record IRI",
              "description": null,
              "arguments": {
                "recordIRIs": "{{vars.steps.Create_Email_Alert['@id'], vars.steps.Create_the_Attachment_Record.data['@id']}}"
              },
              "status": null,
              "top": "840",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "a3d92418-c1da-4186-8e26-542b6e5834d8"
            },
            {
              "@type": "WorkflowStep",
              "name": "Start",
              "description": null,
              "arguments": {
                "step_variables": {
                  "input": {
                    "params": []
                  }
                }
              },
              "status": null,
              "top": "30",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/b348f017-9a94-471f-87f8-ce88b6a7ad62",
              "group": null,
              "uuid": "6abb1518-b2f8-4217-9690-8fe6e6ea9560"
            },
            {
              "@type": "WorkflowStep",
              "name": "Update Alert",
              "description": null,
              "arguments": {
                "resource": {
                  "__link": {
                    "attachments": "{{vars.steps.Create_the_Attachment_Record.data['@id']}}"
                  }
                },
                "operation": "Append",
                "collection": "{{vars.steps.Create_Email_Alert['@id']}}",
                "__recommend": [],
                "collectionType": "/api/3/alerts",
                "fieldOperation": {
                  "automation": "Append",
                  "enrichmentState": "Append"
                },
                "step_variables": []
              },
              "status": null,
              "top": "705",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/b593663d-7d13-40ce-a3a3-96dece928722",
              "group": null,
              "uuid": "6e3e2527-2d07-41cc-bc4b-f59d1ac6bb87"
            }
          ],
          "routes": [
            {
              "@type": "WorkflowRoute",
              "name": "Configuration -> Create Email Alert",
              "targetStep": "/api/3/workflow_steps/7ac1d28e-3e49-480a-81fd-6c1e1f16fc03",
              "sourceStep": "/api/3/workflow_steps/40f68db6-d9aa-4f91-8740-58d822edaa25",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "b0bde281-0ab0-48c3-bff9-0c03fb863dc1"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Create Attachment Record -> create file",
              "targetStep": "/api/3/workflow_steps/f1043563-cc50-4b97-8fda-5e1b2137ddf0",
              "sourceStep": "/api/3/workflow_steps/0d47f7f1-3409-4d92-abaf-1393299a5b13",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "3f37c185-0cc2-4a78-a4dd-131023955926"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Create Email Alert -> Create Attachment Record_",
              "targetStep": "/api/3/workflow_steps/0d47f7f1-3409-4d92-abaf-1393299a5b13",
              "sourceStep": "/api/3/workflow_steps/7ac1d28e-3e49-480a-81fd-6c1e1f16fc03",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "944307d0-0082-4eb7-9e15-d9f78f98f207"
            },
            {
              "@type": "WorkflowRoute",
              "name": "create file -> Update Alert",
              "targetStep": "/api/3/workflow_steps/6e3e2527-2d07-41cc-bc4b-f59d1ac6bb87",
              "sourceStep": "/api/3/workflow_steps/f1043563-cc50-4b97-8fda-5e1b2137ddf0",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "80a2a3fa-8f07-4689-9a1d-583ba257745e"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Start -> Configuration",
              "targetStep": "/api/3/workflow_steps/40f68db6-d9aa-4f91-8740-58d822edaa25",
              "sourceStep": "/api/3/workflow_steps/6abb1518-b2f8-4217-9690-8fe6e6ea9560",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "30a895b1-032a-4a49-b02b-b190ffebe348"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Update Alert -> Return Record IRI",
              "targetStep": "/api/3/workflow_steps/a3d92418-c1da-4186-8e26-542b6e5834d8",
              "sourceStep": "/api/3/workflow_steps/6e3e2527-2d07-41cc-bc4b-f59d1ac6bb87",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "175539eb-fbcb-4d69-bd4d-976f054a2605"
            }
          ],
          "groups": [],
          "priority": "/api/3/picklists/2b563c61-ae2c-41c0-a85a-c9709585e3f2",
          "isEditable": false,
          "uuid": "bb6fe039-3e49-4091-b4f0-73bd492a4693",
          "isPrivate": false,
          "recordTags": [
            "Scenario"
          ]
        },
        {
          "@type": "Workflow",
          "triggerLimit": null,
          "name": "Auto Ingest IoCs > Extract Indicators from Attachment",
          "aliasName": null,
          "tag": null,
          "description": "This playbook will extract the indicators from attachment.",
          "isActive": false,
          "debug": false,
          "singleRecordExecution": false,
          "remoteExecutableFlag": false,
          "parameters": [
            "attachment_uuid",
            "alert_iri"
          ],
          "synchronous": false,
          "triggerStep": "/api/3/workflow_steps/529c41e1-93c2-45ab-a784-799e4b7fd248",
          "steps": [
            {
              "@type": "WorkflowStep",
              "name": "Block IOC or not",
              "description": null,
              "arguments": {
                "conditions": [
                  {
                    "option": "Do Not Block",
                    "default": true,
                    "step_iri": "/api/3/workflow_steps/ac39a332-3b23-4479-af92-eede9270131e",
                    "step_name": "Do Not Block"
                  },
                  {
                    "option": "Auto Block",
                    "step_iri": "/api/3/workflow_steps/31045e4f-a51e-4ba8-8ac7-9c4625f1e800",
                    "condition": "{{ vars.steps.Select_Actions_on_IoCs.input.actionOnExtractedIoCs == \"Block Automatically\" }}",
                    "step_name": "Create IoC from File"
                  },
                  {
                    "option": "Manual Block",
                    "step_iri": "/api/3/workflow_steps/4a07bb16-9a12-4d4a-8f48-b9fb2d344a8a",
                    "condition": "{{ vars.steps.Select_Actions_on_IoCs.input.actionOnExtractedIoCs == \"Block Manually\" }}",
                    "step_name": "Create IoC Records"
                  }
                ],
                "step_variables": []
              },
              "status": null,
              "top": "975",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/12254cf5-5db7-4b1a-8cb1-3af081924b28",
              "group": null,
              "uuid": "2a5b06e2-57eb-4531-9e30-391e5e4a18be"
            },
            {
              "@type": "WorkflowStep",
              "name": "Block IoCs",
              "description": null,
              "arguments": {
                "when": "{{vars.createIOC | length > 0}}",
                "for_each": {
                  "item": "{{vars.createIOC}}",
                  "__bulk": false,
                  "parallel": true,
                  "condition": ""
                },
                "arguments": {
                  "indicator_type": "{{vars.item.Type}}",
                  "indicator_value": "{{vars.item.Value}}",
                  "indicator_record_iri": "{{vars.item.IRI}}",
                  "indicator_block_reason": "{{vars.steps.Select_Actions_on_IoCs.input.reasonForBlocking}}"
                },
                "apply_async": false,
                "step_variables": [],
                "pass_parent_env": false,
                "pass_input_record": false,
                "workflowReference": "/api/3/workflows/1a1cac48-567a-4066-b0d1-c63457226f12"
              },
              "status": null,
              "top": "1380",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/74932bdc-b8b6-4d24-88c4-1a4dfbc524f3",
              "group": null,
              "uuid": "c05092a9-538d-46ce-b555-8d4b971da2a8"
            },
            {
              "@type": "WorkflowStep",
              "name": "Configuration",
              "description": null,
              "arguments": {
                "alert_iri": "{{vars.input.params['alert_iri']}}"
              },
              "status": null,
              "top": "165",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "2371638a-ed2b-47d8-b909-74c3dd75bef9"
            },
            {
              "@type": "WorkflowStep",
              "name": "Create IoC from File",
              "description": null,
              "arguments": {
                "for_each": {
                  "item": "{{vars.fetched_indicators.keys() | list}}",
                  "parallel": false,
                  "condition": ""
                },
                "arguments": {
                  "tlp": "{{vars.steps.Select_Actions_on_IoCs.input.tLP}}",
                  "data": "{{vars.fetched_indicators[vars.item]}}",
                  "ioc_type": "{{vars.item}}",
                  "alert_iri": "{{vars.alert_iri}}",
                  "confidence": "{{vars.steps.Select_Actions_on_IoCs.input.confidence}}",
                  "reputation": "{{vars.steps.Select_Actions_on_IoCs.input.reputation}}",
                  "ioc_blocked": "true"
                },
                "apply_async": false,
                "step_variables": [],
                "pass_parent_env": false,
                "pass_input_record": false,
                "workflowReference": "/api/3/workflows/a524141f-5e5b-4908-a1b7-64e47ecc251b"
              },
              "status": null,
              "top": "1110",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/74932bdc-b8b6-4d24-88c4-1a4dfbc524f3",
              "group": null,
              "uuid": "31045e4f-a51e-4ba8-8ac7-9c4625f1e800"
            },
            {
              "@type": "WorkflowStep",
              "name": "Create IoC Records",
              "description": null,
              "arguments": {
                "for_each": {
                  "item": "{{vars.fetched_indicators.keys() | list}}",
                  "parallel": false,
                  "condition": ""
                },
                "arguments": {
                  "tlp": "{{vars.steps.Select_Actions_on_IoCs.input.tLP}}",
                  "data": "{{vars.fetched_indicators[vars.item]}}",
                  "ioc_type": "{{vars.item}}",
                  "alert_iri": "{{vars.alert_iri}}",
                  "confidence": "{{vars.steps.Select_Actions_on_IoCs.input.confidence}}",
                  "reputation": "{{vars.steps.Select_Actions_on_IoCs.input.reputation}}",
                  "ioc_blocked": "false"
                },
                "apply_async": false,
                "step_variables": [],
                "pass_parent_env": false,
                "pass_input_record": false,
                "workflowReference": "/api/3/workflows/a524141f-5e5b-4908-a1b7-64e47ecc251b"
              },
              "status": null,
              "top": "1110",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/74932bdc-b8b6-4d24-88c4-1a4dfbc524f3",
              "group": null,
              "uuid": "4a07bb16-9a12-4d4a-8f48-b9fb2d344a8a"
            },
            {
              "@type": "WorkflowStep",
              "name": "Do Not Block",
              "description": null,
              "arguments": {
                "params": [],
                "version": "3.7.1",
                "connector": "cyops_utilities",
                "operation": "no_op",
                "operationTitle": "Utils: No Operation",
                "step_variables": []
              },
              "status": null,
              "top": "1110",
              "left": "825",
              "stepType": "/api/3/workflow_step_types/0109f35d-090b-4a2b-bd8a-94cbc3508562",
              "group": null,
              "uuid": "ac39a332-3b23-4479-af92-eede9270131e"
            },
            {
              "@type": "WorkflowStep",
              "name": "Extract IoCs From File",
              "description": null,
              "arguments": {
                "name": "File Content Extraction",
                "params": {
                  "file_iri": "{{vars.item}}"
                },
                "version": "1.3.1",
                "for_each": {
                  "item": "{{vars.file_iris}}",
                  "parallel": false,
                  "condition": ""
                },
                "connector": "file-content-extraction",
                "operation": "extract_indicators_from_file",
                "operationTitle": "Extract Artifacts Extended",
                "pickFromTenant": false,
                "step_variables": []
              },
              "status": null,
              "top": "570",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/0bfed618-0316-11e7-93ae-92361f002671",
              "group": null,
              "uuid": "92b513a0-7b29-43d7-821e-d596e81a4e33"
            },
            {
              "@type": "WorkflowStep",
              "name": "Fetch Newly Created IoCs",
              "description": null,
              "arguments": {
                "createIOC": "{{vars.steps.Create_IoC_from_File | map(attribute='iocRecords')|list | flatten(levels=1)}}"
              },
              "status": null,
              "top": "1245",
              "left": "125",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "fd36a69b-c406-40ce-9069-1c2b89aed419"
            },
            {
              "@type": "WorkflowStep",
              "name": "Get File IRIs",
              "description": null,
              "arguments": {
                "file_iris": "{% set files = [] %}\n{% for item in vars.steps.Get_the_Attachment %}\n    {% set _ = files.append(item.file['@id']) %}\n{% endfor %}\n{{ files }}"
              },
              "status": null,
              "top": "435",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "9b763eb2-5558-48b3-8a1d-12ccecf98821"
            },
            {
              "@type": "WorkflowStep",
              "name": "Get IoCs List",
              "description": null,
              "arguments": {
                "total_iocs": "{% set ns = namespace(total_feeds=0) %}\n\n{% for item in vars.steps.Extract_IoCs_From_File %}\n    {% for indicator_type, indicators in item.data.items() %}\n        {% set ns.total_feeds = ns.total_feeds + (indicators | length) %}\n    {% endfor %}\n{% endfor %}\n\n{{ ns.total_feeds }}",
                "fetched_indicators": "{% set ns = namespace(merged={}) %}\n\n{% for item in vars.steps.Extract_IoCs_From_File | default([]) %}\n    {% for indicator_type in item.data | default({}) %}\n        {% set indicators = item.data[indicator_type] | default([]) %}\n\n        {% if indicator_type not in ns.merged %}\n            {% set _ = ns.merged.update({ indicator_type: [] }) %}\n        {% endif %}\n\n        {% for ioc in indicators %}\n            {% if ioc not in ns.merged[indicator_type] %}\n                {% set _ = ns.merged[indicator_type].append(ioc) %}\n            {% endif %}\n        {% endfor %}\n\n    {% endfor %}\n{% endfor %}\n\n{{ ns.merged }}"
              },
              "status": null,
              "top": "705",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/04d0cf46-b6a8-42c4-8683-60a7eaa69e8f",
              "group": null,
              "uuid": "60b62665-23fe-4d35-8e69-0d078c803879"
            },
            {
              "@type": "WorkflowStep",
              "name": "Get the Attachment",
              "description": null,
              "arguments": {
                "query": {
                  "sort": [],
                  "limit": 30,
                  "logic": "AND",
                  "filters": [
                    {
                      "type": "primitive",
                      "field": "uuid",
                      "value": "{{vars.input.params['attachment_uuid']}}",
                      "operator": "in",
                      "_operator": "in"
                    }
                  ]
                },
                "module": "attachments?$limit=30",
                "step_variables": []
              },
              "status": null,
              "top": "300",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/b593663d-7d13-40ce-a3a3-96dece928770",
              "group": null,
              "uuid": "fd051471-0fc1-4e7f-9554-78c306b6023f"
            },
            {
              "@type": "WorkflowStep",
              "name": "Select Actions on IoCs",
              "description": null,
              "arguments": {
                "type": "InputBased",
                "input": {
                  "schema": {
                    "title": "Indicators Details",
                    "description": "<html>\n<p style=\"font-family:verdana;\">Dear Team,</p>\n\n<p style=\"font-family:verdana;\">Please review the extracted indicators and select the action to be performed:</b></p>\n\n<p style=\"color: #FFBF00; font-family:verdana;\">&#9888; Warning:</p>\n<p style=\"font-family:verdana;\"> - Existing (already created) indicators will retain their reputation.</p>\n\n<p style=\"font-family:verdana;\"> - Only indicators that are not currently in \"Blocked\" status will be considered for blocking.</p>\n <br>\n\n<head>\n<style>\ntable, th, td {\n  border: 1px solid;\n}\n</style>\n</head>\n<body>\n<table>\n<tr>\n<th style=\"background-color:teal;color:white;\">Type</th>\n<th style=\"background-color:teal;color:white;\">Value </th>\n</tr>\n{% for k, v in vars.fetched_indicators.items() %}\n<tr>\n<td>{{k}}</td>\n<td>{{v | join(\", \") | wordwrap(100)}}</td>\n</tr>\n{% endfor %}\n</table>\n</body>\n</html>\n",
                    "inputVariables": [
                      {
                        "name": "actionOnExtractedIoCs",
                        "type": "array",
                        "label": "Action on Extracted IoCs",
                        "title": "Dynamic List",
                        "usable": true,
                        "options": [
                          "Block Automatically",
                          "Block Manually",
                          "Do Not Block"
                        ],
                        "tooltip": "",
                        "dataType": "dynamicList",
                        "formType": "dynamicList",
                        "required": false,
                        "_expanded": true,
                        "mmdUpdate": true,
                        "collection": false,
                        "searchable": false,
                        "templateUrl": "app/components/form/fields/dynamicList.html",
                        "defaultValue": "Do Not Block",
                        "_previousName": "actionOnExtractedIoCs",
                        "playbookField": true,
                        "lengthConstraint": true,
                        "allowedGridColumn": false,
                        "requiredCondition": "notrequired",
                        "jinjaExpressionView": true,
                        "useRecordFieldDefault": false,
                        "_addRequiredConditions": false
                      },
                      {
                        "name": "confidence",
                        "type": "integer",
                        "label": "Confidence",
                        "title": "Integer Field",
                        "usable": true,
                        "tooltip": "Specify confidence to be set for these IoCs.",
                        "dataType": "integer",
                        "formType": "integer",
                        "required": false,
                        "_expanded": true,
                        "mmdUpdate": true,
                        "collection": false,
                        "searchable": true,
                        "templateUrl": "app/components/form/fields/integer.html",
                        "defaultValue": 50,
                        "_previousName": "confidence",
                        "playbookField": true,
                        "visibilityQuery": {
                          "sort": [],
                          "limit": 30,
                          "logic": "OR",
                          "filters": [
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Automatically"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            },
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Manually"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            }
                          ]
                        },
                        "lengthConstraint": true,
                        "allowedEncryption": false,
                        "allowedGridColumn": true,
                        "requiredCondition": "notrequired",
                        "jinjaExpressionView": true,
                        "useRecordFieldDefault": false,
                        "_addRequiredConditions": false,
                        "_addVisibilityConditions": true
                      },
                      {
                        "name": "reputation",
                        "type": "array",
                        "label": "Reputation",
                        "title": "Dynamic List",
                        "usable": true,
                        "options": [
                          "Good",
                          "Malicious",
                          "Suspicious",
                          "TBD",
                          "No Reputation Available"
                        ],
                        "tooltip": "Select the reputation to apply to these IOCs.",
                        "dataType": "dynamicList",
                        "formType": "dynamicList",
                        "required": false,
                        "_expanded": true,
                        "mmdUpdate": true,
                        "collection": false,
                        "searchable": false,
                        "templateUrl": "app/components/form/fields/dynamicList.html",
                        "defaultValue": "TBD",
                        "_previousName": "reputation",
                        "playbookField": true,
                        "visibilityQuery": {
                          "sort": [],
                          "limit": 30,
                          "logic": "OR",
                          "filters": [
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Manually"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            },
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Automatically"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            }
                          ]
                        },
                        "lengthConstraint": true,
                        "allowedGridColumn": false,
                        "requiredCondition": "notrequired",
                        "jinjaExpressionView": true,
                        "useRecordFieldDefault": false,
                        "_addRequiredConditions": false,
                        "_addVisibilityConditions": true
                      },
                      {
                        "name": "tLP",
                        "type": "array",
                        "label": "TLP",
                        "title": "Dynamic List",
                        "usable": true,
                        "options": [
                          "Red",
                          "Amber",
                          "Green",
                          "White"
                        ],
                        "tooltip": "Select the TLP level to apply to these IOCs",
                        "dataType": "dynamicList",
                        "formType": "dynamicList",
                        "required": false,
                        "_expanded": true,
                        "mmdUpdate": true,
                        "collection": false,
                        "searchable": false,
                        "templateUrl": "app/components/form/fields/dynamicList.html",
                        "defaultValue": "Amber",
                        "_previousName": "tLP",
                        "playbookField": true,
                        "visibilityQuery": {
                          "sort": [],
                          "limit": 30,
                          "logic": "OR",
                          "filters": [
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Automatically"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            },
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Manually"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            }
                          ]
                        },
                        "lengthConstraint": true,
                        "allowedGridColumn": false,
                        "requiredCondition": "notrequired",
                        "jinjaExpressionView": true,
                        "useRecordFieldDefault": false,
                        "_addRequiredConditions": false,
                        "_addVisibilityConditions": true
                      },
                      {
                        "name": "reasonForBlocking",
                        "type": "string",
                        "label": "Reason for Blocking",
                        "tooltip": "",
                        "dataType": "text",
                        "formType": "text",
                        "required": false,
                        "_expanded": true,
                        "defaultValue": "Block via FortiSOAR Automation",
                        "_previousName": "reasonForBl",
                        "visibilityQuery": {
                          "sort": [],
                          "limit": 30,
                          "logic": "OR",
                          "filters": [
                            {
                              "type": "array",
                              "field": "actionOnExtractedIoCs",
                              "value": [
                                "Block Automatically"
                              ],
                              "module": "actionOnExtractedIoCs",
                              "display": null,
                              "operator": "in",
                              "template": "tags",
                              "OPERATOR_KEY": "$",
                              "useInOperator": true,
                              "previousOperator": "in",
                              "previousTemplate": "tags"
                            }
                          ]
                        },
                        "requiredCondition": "notrequired",
                        "jinjaExpressionView": true,
                        "useRecordFieldDefault": false,
                        "_addRequiredConditions": true,
                        "_addVisibilityConditions": true
                      }
                    ]
                  }
                },
                "record": "{{vars.alert_iri}}",
                "agent_id": null,
                "resources": "alerts",
                "is_approval": false,
                "owner_detail": {
                  "isAssigned": false,
                  "emailRecipients": ""
                },
                "isRecordLinked": true,
                "step_variables": [],
                "response_mapping": {
                  "options": [
                    {
                      "option": "Proceed",
                      "primary": true,
                      "step_iri": "/api/3/workflow_steps/2a5b06e2-57eb-4531-9e30-391e5e4a18be"
                    }
                  ],
                  "duplicateOption": false,
                  "customSuccessMessage": "Awaiting Playbook resumed successfully."
                },
                "email_notification": {
                  "enabled": false,
                  "smtpParameters": []
                },
                "customEmailExternal": false,
                "inline_channel_list": [],
                "external_channel_list": [],
                "unauthenticated_input": false,
                "external_email_subject": null,
                "internal_email_subject": "A FortiSOAR playbook is requesting your input",
                "custom_email_body_external": null,
                "external_email_attachments": null
              },
              "status": null,
              "top": "840",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/fc04082a-d7dc-4299-96fb-6837b1baa0fe",
              "group": null,
              "uuid": "1ee37db3-bdca-44ce-9532-0d723484056d"
            },
            {
              "@type": "WorkflowStep",
              "name": "Start",
              "description": null,
              "arguments": {
                "__triggerLimit": true,
                "step_variables": {
                  "input": {
                    "params": []
                  },
                  "useMockOutput": "false"
                },
                "triggerOnSource": true,
                "triggerOnReplicate": false
              },
              "status": null,
              "top": "30",
              "left": "475",
              "stepType": "/api/3/workflow_step_types/b348f017-9a94-471f-87f8-ce88b6a7ad62",
              "group": null,
              "uuid": "529c41e1-93c2-45ab-a784-799e4b7fd248"
            }
          ],
          "routes": [
            {
              "@type": "WorkflowRoute",
              "name": "Block IOC or not -> Create IoC from File",
              "targetStep": "/api/3/workflow_steps/31045e4f-a51e-4ba8-8ac7-9c4625f1e800",
              "sourceStep": "/api/3/workflow_steps/2a5b06e2-57eb-4531-9e30-391e5e4a18be",
              "label": "Auto Block",
              "isExecuted": false,
              "group": null,
              "uuid": "1cd7b31c-a753-4d23-9378-dfbc2a454987"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Block IOC or not -> Create Ioc Records",
              "targetStep": "/api/3/workflow_steps/4a07bb16-9a12-4d4a-8f48-b9fb2d344a8a",
              "sourceStep": "/api/3/workflow_steps/2a5b06e2-57eb-4531-9e30-391e5e4a18be",
              "label": "Manual Block",
              "isExecuted": false,
              "group": null,
              "uuid": "66de958d-da97-4299-a65b-48610d8850fe"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Block IOC or not -> Reject",
              "targetStep": "/api/3/workflow_steps/ac39a332-3b23-4479-af92-eede9270131e",
              "sourceStep": "/api/3/workflow_steps/2a5b06e2-57eb-4531-9e30-391e5e4a18be",
              "label": "Do Not Block",
              "isExecuted": false,
              "group": null,
              "uuid": "ed8c0858-81d7-400e-a5fb-050710432882"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Configuration -> Get the Attachment",
              "targetStep": "/api/3/workflow_steps/fd051471-0fc1-4e7f-9554-78c306b6023f",
              "sourceStep": "/api/3/workflow_steps/2371638a-ed2b-47d8-b909-74c3dd75bef9",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "e3470faf-d6d6-4a3c-997e-7918801ffb1b"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Create IoC from File -> Gather result",
              "targetStep": "/api/3/workflow_steps/fd36a69b-c406-40ce-9069-1c2b89aed419",
              "sourceStep": "/api/3/workflow_steps/31045e4f-a51e-4ba8-8ac7-9c4625f1e800",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "f5ff516e-5db9-4a3d-bfc2-752eaf0bc3b8"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Extract Indicators From File -> Get Indicators",
              "targetStep": "/api/3/workflow_steps/60b62665-23fe-4d35-8e69-0d078c803879",
              "sourceStep": "/api/3/workflow_steps/92b513a0-7b29-43d7-821e-d596e81a4e33",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "8e4d994d-7449-4195-b92e-23c6e44e44ab"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Gather result -> Block IoCs",
              "targetStep": "/api/3/workflow_steps/c05092a9-538d-46ce-b555-8d4b971da2a8",
              "sourceStep": "/api/3/workflow_steps/fd36a69b-c406-40ce-9069-1c2b89aed419",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "e162683b-9bb8-40da-92eb-4cd95409a924"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Get File IRIs -> Extract Indicators From File",
              "targetStep": "/api/3/workflow_steps/92b513a0-7b29-43d7-821e-d596e81a4e33",
              "sourceStep": "/api/3/workflow_steps/9b763eb2-5558-48b3-8a1d-12ccecf98821",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "9150fcab-e297-476f-8a8b-6a9f0fcf3ba8"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Get IoCs List -> Select Actions on IoCs",
              "targetStep": "/api/3/workflow_steps/1ee37db3-bdca-44ce-9532-0d723484056d",
              "sourceStep": "/api/3/workflow_steps/60b62665-23fe-4d35-8e69-0d078c803879",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "51d73147-92f9-4c17-939e-2c867d48202f"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Get the Attachment -> Get File IRIs",
              "targetStep": "/api/3/workflow_steps/9b763eb2-5558-48b3-8a1d-12ccecf98821",
              "sourceStep": "/api/3/workflow_steps/fd051471-0fc1-4e7f-9554-78c306b6023f",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "a333d120-20ff-49ea-982f-f6fab0fd2528"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Select Actions on IoCs -> Block IOC or not",
              "targetStep": "/api/3/workflow_steps/2a5b06e2-57eb-4531-9e30-391e5e4a18be",
              "sourceStep": "/api/3/workflow_steps/1ee37db3-bdca-44ce-9532-0d723484056d",
              "label": "Proceed",
              "isExecuted": false,
              "group": null,
              "uuid": "df2cab04-8c15-40a9-b571-399e2fa3d199"
            },
            {
              "@type": "WorkflowRoute",
              "name": "Start -> Configuration",
              "targetStep": "/api/3/workflow_steps/2371638a-ed2b-47d8-b909-74c3dd75bef9",
              "sourceStep": "/api/3/workflow_steps/529c41e1-93c2-45ab-a784-799e4b7fd248",
              "label": null,
              "isExecuted": false,
              "group": null,
              "uuid": "eb280fed-821e-4c65-92de-5b730e754087"
            }
          ],
          "groups": [],
          "priority": "/api/3/picklists/2b563c61-ae2c-41c0-a85a-c9709585e3f2",
          "isEditable": false,
          "uuid": "8d23cf2d-4f09-431f-af77-b14574851e2a",
          "isPrivate": false,
          "recordTags": [
            "Extract IoCs",
            "Subroutine"
          ]
        }
      ]
    }
  ]
}
