← Files CrowdStrike Falcon FusionARCHIVED FILE

skills/authoring/examples/identity-response/email-phishing-playbook-itp.yaml

16.7 KB · Oct 5, 2026 · 18:32 UTC

↓ Download file

# Example: Email phishing playbook with Identity Threat Protection actions
# Category: identity-response
# Source: CrowdStrike Content Library playbook "Email phishing playbook with
#   Identity Threat Protection actions"
#   (https://falcon.crowdstrike.com/login/?unilogin=true&next=/content-library/details/global:fusion_playbook:f13637f057cb4a1aa1496469d0c37e2e),
#   installed and exported unmodified from the Falcon console. Passes validate.py
#   at all tiers, including server-side API validation.
# This is an exported workflow. Editing this file is not recommended.

name: Email phishing playbook with Identity Threat Protection actions
description: 'Quickly enrich, investigate, and remediate user-reported phishing emails by enriching indicators observed in the email and detonating attachments with first and third party enrichment sources such as APIVoid, VirusTotal, and Falcon sandbox. This playbook includes actions exclusive to Identity Threat Protection allowing users to enrich the email addresses and check for user risk before taking an identity-based remediation action. Note: Customize per your phishing requirements prior to enabling.'
trigger:
    next:
        - activity_find_phishing_emails_processed_by_workflows_711fa954
    event: PhishingEmail/MicrosoftO365
    name: Phishing email > Microsoft O365
    type: Signal
actions:
    activity_6adbd02c-da4c-415e-bf84-b7f9d9190492:
        id: 180cccafdc5993b665ca0da37fb4b85e
        default_name: Send Microsoft Teams message (deprecated)
        name: Send Microsoft Teams message
        properties:
            _fields:
                - ${Workflow.Definition.Name}
                - ${Workflow.Execution.Time}
            msg: Email Phishing playbook triggered. Attachment quarantined, sender blocked, URLs analyzed, and user marked as risky
    activity_6e702455-00c9-4b2d-a417-0eb15b7fe2e7:
        id: 68819ad0d42d40d2bc41d8bf500aaa5f
        default_name: Entra ID - Mark User as Risky
        name: Entra ID - Mark User as Risky - 2
        properties:
            json:
                userIds:
                    - ${activity_a805fe6d-88e4-423d-83cd-3e516bd8960b.Enrich.User.UserEntraObjectID}
            params:
                header:
                    Content-Type: application/json
    activity_a805fe6d-88e4-423d-83cd-3e516bd8960b:
        id: 19c7e2af0a24f468be7797fe180c8329
        default_name: Get user identity context
        name: Get user identity context - 2
        next:
            - user_risk_severity_is_equal_to_high1
        properties:
            email: ${Trigger.Category.PhishingEmail.FromEmail}
    activity_c63a920e-8064-410b-849c-380c045a3215:
        id: 5aaf2c9c6acb4c94a417669c8d481669
        default_name: Add Sender to Org Block List with Proofpoint
        name: Add Sender to Org Block List with Proofpoint
        properties:
            json:
                attribute: $host
                operator: equal
                value: ${Trigger.Category.PhishingEmail.FromDomain}
    activity_create_custom_domain_ioc_245e3203:
        id: ecdace64ddcdc78030544a75fa766b0e
        default_name: Create Custom Domain IOC
        name: Create Custom Domain IOC
        properties:
            action_type: detect
            domain: ${Trigger.Category.PhishingEmail.FromDomain}
            expiration_ttl: 168h
            mobile_action: detect
            platforms:
                - windows
                - linux
            severity: medium
    activity_enrich_domain_af30a054:
        id: 18eb9bee7aa64071b2dd5f9829db681f
        default_name: APIVoid - Enrich Domain
        name: Enrich Domain
        next:
            - body_data_report_risk_score_result_is_greater_than_or_equal_to_80
        properties:
            params:
                query:
                    host: ${Trigger.Category.PhishingEmail.FromDomain}
    activity_find_phishing_emails_processed_by_workflows_711fa954:
        id: 69d872bffa2d42d7af42c21263922f16
        default_name: Find phishing emails processed by workflows
        name: Find phishing emails processed by workflows
        next:
            - unformatted_results_is_equal_to_
        properties:
            email_sha256_hash: ${Trigger.Category.PhishingEmail.EmailHash}
            latest: ${Workflow.Execution.Time}
            search_timeframe_minutes: 10080
    activity_write_to_log_repo_c969b889:
        id: 04c59ceb6dff9e6cd89e5f5cf13121ab
        default_name: Write to log repo
        name: Write to log repo
        next:
            - sub_model_category_phishingemail_weburlsinemailbody_e0b78203
            - sub_model_category_phishingemail_attachmentfilesha256_6d4a4d00
            - sub_model_category_phishingemail_emailprovider_microsofto365_receivedfromipv4_bc57f1df
            - activity_enrich_domain_af30a054
            - sub_model_cead5ea3-f689-4350-bee5-91eb20721220
            - activity_a805fe6d-88e4-423d-83cd-3e516bd8960b
        properties:
            custom_json:
                email:
                    attachments:
                        sha256: ${Trigger.Category.PhishingEmail.AttachmentFileSHA256}
                    content_sha256_hash: ${Trigger.Category.PhishingEmail.EmailHash}
                    from:
                        address: ${Trigger.Category.PhishingEmail.FromEmail}
                    local_id: ${Trigger.SourceEventID}
                    subject: ${Trigger.Category.PhishingEmail.Subject}
            remove_action_prefix: true
conditions:
    body_data_report_risk_score_result_is_greater_than_or_equal_to_80:
        next:
            - activity_create_custom_domain_ioc_245e3203
            - activity_c63a920e-8064-410b-849c-380c045a3215
        expression: activity_enrich_domain_af30a054.API_Integration.Custom_APIVoid.Enrich_Domain.body.data.report.risk_score.result:>=80
        display:
            - Body data report risk score result is greater than or equal to 80
    unformatted_results_is_equal_to_:
        next:
            - activity_write_to_log_repo_c969b889
        expression: activity_find_phishing_emails_processed_by_workflows_711fa954.EventSearch.phishing_emails.raw_results:'[]'
        display:
            - Unformatted results is equal to []
    user_risk_severity_is_equal_to_high1:
        next:
            - activity_6e702455-00c9-4b2d-a417-0eb15b7fe2e7
        expression: activity_a805fe6d-88e4-423d-83cd-3e516bd8960b.Enrich.User.RiskSeverity:'High'
        display:
            - User risk severity is equal to High
loops:
    sub_model_category_phishingemail_attachmentfilesha256_6d4a4d00:
        display: For each Attachment file SHA256; Concurrently
        name: For each Attachment file SHA256; Concurrently
        next:
            - activity_6adbd02c-da4c-415e-bf84-b7f9d9190492
        for:
            input: Trigger.Category.PhishingEmail.AttachmentFileSHA256
            continue_on_partial_execution: false
            sequential: false
        trigger:
            next:
                - activity_virustotal_file_hash_lookup_ea8fd3e7
        actions:
            activity_create_custom_hash_ioc_e3a8a14c:
                id: 557d9de82413677873ceb2e0d5480507
                default_name: Create Custom Hash IOC
                name: Create Custom Hash IOC
                properties:
                    action_type: prevent
                    expiration_ttl: 168h
                    hash: ${Trigger.Category.PhishingEmail.AttachmentFileSHA256.#}
                    mobile_action: prevent
                    platforms:
                        - windows
                        - linux
                    severity: medium
            activity_get_processes_associated_with_a_sha256_hash_71710816:
                id: 39ebbf77fd1d680c5ecbc790659dd4b0
                default_name: Get processes associated with a sha256 hash
                name: Get processes associated with a sha256 hash
                next:
                    - sub_model_activity_71710816_a976_425f_96bc_9087ebb31eac_threatgraph_processesranonsha256_processes_d69ce9f5
                    - activity_create_custom_hash_ioc_e3a8a14c
                properties:
                    indicator: ${Trigger.Category.PhishingEmail.AttachmentFileSHA256.#}
            activity_virustotal_file_hash_lookup_ea8fd3e7:
                id: 668bf0d0b832510e21d7c00386d277ea
                default_name: VirusTotal File Hash Lookup
                name: VirusTotal File Hash Lookup
                next:
                    - virustotal_malicious_percentage_is_greater_than_or_equal_to_75
                properties:
                    hash: ${Trigger.Category.PhishingEmail.AttachmentFileSHA256.#}
        conditions:
            virustotal_malicious_percentage_is_greater_than_or_equal_to_75:
                next:
                    - activity_get_processes_associated_with_a_sha256_hash_71710816
                expression: activity_virustotal_file_hash_lookup_ea8fd3e7.VirusTotal.HashLookup.malicious_percentage:>=75
                display:
                    - VirusTotal Malicious Percentage is greater than or equal to 75
        loops:
            sub_model_activity_71710816_a976_425f_96bc_9087ebb31eac_threatgraph_processesranonsha256_processes_d69ce9f5:
                display: For each Processes; Concurrently
                name: For each Processes; Concurrently
                for:
                    input: activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes
                    continue_on_partial_execution: false
                    sequential: false
                trigger:
                    next:
                        - process_terminated_instance_is_equal_to_no
                actions:
                    activity_1cc06141-d3e2-467d-b9d2-92db7cbabf93:
                        id: 1bf5b9585917e51f84f5c9f2ea1aea54
                        default_name: Remove file
                        name: Remove file - 2
                        properties:
                            device_id: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.HostID}
                            file_path: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.ImageFileName}
                    activity_1f6df532-df9a-4534-9c43-bb533c36f2bc:
                        id: 1bf5b9585917e51f84f5c9f2ea1aea54
                        default_name: Remove file
                        name: Remove file
                        next:
                            - activity_contain_device_ab3451d8
                        properties:
                            device_id: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.HostID}
                            file_path: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.ImageFileName}
                    activity_aa10ab8b-03cd-426f-8410-64658bdcbe31:
                        id: 9ac54d8989c68dbf601acffe8444f7dc
                        default_name: Kill process
                        name: Kill process
                        next:
                            - activity_1f6df532-df9a-4534-9c43-bb533c36f2bc
                        properties:
                            device_id: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.HostID}
                            process_id: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.RawProcessId}
                    activity_contain_device_ab3451d8:
                        id: bec9fbeb4999d207937854fd56088107
                        default_name: Contain device
                        name: Contain device
                        properties:
                            device_id: ${activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.HostID}
                conditions:
                    process_terminated_instance_is_equal_to_no:
                        next:
                            - activity_aa10ab8b-03cd-426f-8410-64658bdcbe31
                        expression: activity_get_processes_associated_with_a_sha256_hash_71710816.ThreatGraph.ProcessesRanOnSha256.Processes.#.ProcessTerminated:false
                        display:
                            - Process terminated instance is equal to No
                        else:
                            - activity_1cc06141-d3e2-467d-b9d2-92db7cbabf93
    sub_model_category_phishingemail_emailprovider_microsofto365_receivedfromipv4_bc57f1df:
        display: For each Received from ip addresses(v4); Concurrently
        name: For each Received from ip addresses(v4); Concurrently
        for:
            input: Trigger.Category.PhishingEmail.EmailProvider.MicrosoftO365.ReceivedFromIPV4
            continue_on_partial_execution: false
            sequential: false
        trigger:
            next:
                - activity_enrich_ip_321aec38
        actions:
            activity_create_custom_ip_ioc_213f3081:
                id: a3d7ed4a02bcfa221d485638860ee853
                default_name: Create Custom IP IOC
                name: Create Custom IP IOC
                properties:
                    action_type: detect
                    address: ${activity_enrich_ip_321aec38.API_Integration.Custom_APIVoid.Enrich_IP.body.data.report.ip}
                    platforms:
                        - windows
                        - linux
                    severity: medium
            activity_enrich_ip_321aec38:
                id: d9688e57542d45d0b79093dad46c9f3f
                default_name: APIVoid - Enrich IP
                name: Enrich IP
                next:
                    - risk_score_is_greater_than_or_equal_to_80
                properties:
                    params:
                        query:
                            ip: ${Trigger.Category.PhishingEmail.EmailProvider.MicrosoftO365.ReceivedFromIPV4.#}
        conditions:
            risk_score_is_greater_than_or_equal_to_80:
                next:
                    - activity_create_custom_ip_ioc_213f3081
                expression: activity_enrich_ip_321aec38.API_Integration.Custom_APIVoid.Enrich_IP.body.data.report.risk_score.result:>=80
                display:
                    - Risk Score is greater than or equal to 80
    sub_model_category_phishingemail_weburlsinemailbody_e0b78203:
        display: For each Web URLs in email; Concurrently
        name: For each Web URLs in email; Concurrently
        for:
            input: Trigger.Category.PhishingEmail.WebURLsInEmailBody
            continue_on_partial_execution: false
            sequential: false
        trigger:
            next:
                - activity_submit_url_to_sandbox_66c5d5bc
        actions:
            activity_submit_url_to_sandbox_66c5d5bc:
                id: 04dabe92e4aba77982c51af9e58edbfd
                default_name: Submit URL to sandbox
                name: Submit URL to sandbox
                properties:
                    action_script: default
                    environment_id: 160
                    network_settings: default
                    url: ${Trigger.Category.PhishingEmail.WebURLsInEmailBody.#}
    sub_model_cead5ea3-f689-4350-bee5-91eb20721220:
        display: For each To email addresses; Concurrently
        name: For each To email addresses; Concurrently
        for:
            input: Trigger.Category.PhishingEmail.ToEmails
            continue_on_partial_execution: false
            sequential: false
        trigger:
            next:
                - activity_4c78b784-f897-4a43-b8f6-374eee15121a
        actions:
            activity_4c78b784-f897-4a43-b8f6-374eee15121a:
                id: 19c7e2af0a24f468be7797fe180c8329
                default_name: Get user identity context
                name: Get user identity context
                next:
                    - user_risk_severity_is_equal_to_high
                properties:
                    email: ${Trigger.Category.PhishingEmail.ToEmails.#}
            activity_62882d03-0f89-47d0-b59c-729a837f276f:
                id: 68819ad0d42d40d2bc41d8bf500aaa5f
                default_name: Entra ID - Mark User as Risky
                name: Entra ID - Mark User as Risky
                properties:
                    json:
                        userIds:
                            - ${activity_4c78b784-f897-4a43-b8f6-374eee15121a.Enrich.User.UserEntraObjectID}
                    params:
                        header:
                            Content-Type: application/json
        conditions:
            user_risk_severity_is_equal_to_high:
                next:
                    - activity_62882d03-0f89-47d0-b59c-729a837f276f
                expression: activity_4c78b784-f897-4a43-b8f6-374eee15121a.Enrich.User.RiskSeverity:'High'
                display:
                    - User risk severity is equal to High

SHA-256: 5d224f459bc6ef0af1777be3134fa10890daa3d36f7a5d0d2214ea9b56744bd9