Skip to main content

Haseen - Delta Feed - Generic

This Playbook is part of the HaseenThreatIntel Pack.#

Supported versions

Available on Cortex XSOAR (versions 8.9.0 and later) and Cortex XSIAM.

Haseen - Delta Feed - Generic#

Short description: A template playbook to run on Haseen delta-in-feed trigger jobs β€” stage newly-fetched indicators, hunt, and optionally block selected IOCs.

Overview#

Triggered by the Haseen feed's delta-in-feed job after each fetch. The playbook picks up indicators that arrived from the Haseen Threat Intel integration (sourceBrands:"Haseen Threat Intel") within the last 24 hours, gathers their relationships, associates them to the incident, and walks the analyst through a hunt β†’ manual-block-validation β†’ close flow.

The playbook is a template requiring customization: the hunt, blocking, and closure flows are placeholders you must replace with your own standard flows.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts:

  • Haseen Threat Intel integration (feeds the indicators).
  • SearchIndicator / SearchIndicatorRelationships builtin commands.
  • setIncident / associateIndicatorsToIncident builtin commands.

Flow#

StageTaskDescription
StageStage the fetched indicatorsSearchIndicator for sourceBrands:"Haseen Threat Intel" with sourcetimestamp/lastSeen within the last 24 hours (max 500). Haseen updates its STIX bundle roughly once per day, so a 24-hour window is the default; adjust it to match your environment.
StageSearch RelationshipsSearchIndicatorRelationships for the staged indicator values (max 500).
StageAdd all indicators to the incidentassociateIndicatorsToIncident on ${incident.id}, appending each relationship's EntityB so indicators referenced only via relationships (not as STIX SDO/SCO) are also staged.
StagePrepare all indicators for hunt and blockSearchIndicator for incident.id:${incident.id} (max 1000 β€” up to 500 new indicators plus up to 500 relationship objects).
HuntThreat Hunting on Security TechnologiesSection header. Replace the Replace with your Hunting Flow task with your actual hunting automation/flow. The hunt inputs are under the foundIndicators.value context path.
HuntCheck if results are returned from Threat HuntingBranches on whether the hunt returned results.
HuntIncrease incident severity to high if hunt process found matchesOn hunt hits, sets incident severity to 3 (High) via setIncident. The value is configurable β€” High or Critical is recommended, depending on your hunt prioritization process.
BlockBlock IndicatorsSection header.
BlockIOCs Analyst Validation for Blocking?Manual collection task β€” the analyst multi-selects Domains, IPs, URLs, and SHA256 hashes to block (from foundIndicators).
BlockCheck if any IOCs selected for blocking?Branches on whether any IOC was selected.
BlockFollowing IOCs will be Blocked Please confirm…Confirmation prompt listing the selected IPs/Domains/URLs/Hashes.
BlockReplace with your Blocking flowReplace this task with your blocking logic; the selected IOCs are passed via ${Block IOCs Manual Validation.Answers.0..3}.
CloseIncident ClosureSection header.
CloseReplace with your Incident Closure logicReplace this task with your closure logic. Ends at Done.

Customisation points#

The playbook is a template. Replace the three placeholder tasks with your own flows:

  • Replace with your Hunting Flow β€” consume foundIndicators.value and return hunt results.
  • Replace with your Blocking flow β€” consume ${Block IOCs Manual Validation.Answers.0..3} (Domains / IPs / URLs / Hashes) and enforce blocks.
  • Replace with your Incident Closure logic β€” close the incident per your SOC's SOP.

Notes on scope and limits#

  • 24-hour window β€” tasks stage indicators created or updated in the last 24 hours because Haseen publishes its bundle once per day. Adjust the sourcetimestamp/lastSeen window if your feed cadence differs.
  • Search limits β€” SearchIndicator returns 25 results by default and SearchIndicatorRelationships returns 20. The playbook raises these to 500/500/1000 because Haseen updates can carry up to ~500 new indicators and ~500 relationship objects; adjust freely if your volumes differ.
  • EntityB association β€” the Add all indicators to the incident task also appends each relationship's EntityB (Relationships.EntityB) so indicators that only appear inside Haseen relationship objects (rather than as STIX SDO/SCO entries) are staged for hunt and block.

Screenshot#

Haseen Delta Feed Job Playbook