Playbook
Find and tag an existing indicator
Looks up an indicator by value and adds a tag to it.
@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Aug 30, 2026
Download JSON · 4.3 KB
tag-existing-indicator.json
sha256:9692a8045600a5e76c51fe44507e56efde4db5e6d180a17f4dfc02090aeaf945
Sanitized by the pipeline and shipped inactive. Follow the before turning it on.
Shows the find-then-update pattern: query the Indicators module by value and update the match. Handy as a building block inside larger enrichment flows.
Something wrong with this item? Sign in to report