Skip to content
Playbook Connectors on Content Hub

Extract IOCs from alert attachments

Extracts indicators from files attached to an alert, creates indicator records and sends the analyst-approved ones to block.

@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Oct 6, 2026
Download JSON · 64 KB

ioc-attachment-extraction-1.0.0.json

sha256:88b855e1a3f90b8ba1dfd34279d75707038c374940f75132a31d6534560086d4

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

Pulls indicators out of files attached to an alert, creates indicator records for them, and lets an analyst decide whether to block them.

  • Auto Ingest IoCs > Extract Indicators from Attachment: reads each attachment with the File Content Extraction connector, then asks the analyst to review the indicators it found and pick TLP and an action (block or don't block). The chosen indicators are created and, if requested, sent to block.
  • Auto Ingest IoCs >> Create Indicator Records: creates the indicator records and links them to the alert.
  • Auto IOC Ingest- Review and Send IOC to Block: the same review and block flow, started from a button.
  • Scenario - Generating Alert with IOC attachments: creates a test alert with a sample IOC file (documentation IP ranges) so you can try the flow end to end.

The blocking step calls "Action (Type All) - Block Indicators" from the SOAR Framework solution pack on the Content Hub. Install that pack, or point the reference step at your own block playbook.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000