← Files CrowdStrike Falcon FusionARCHIVED FILE
skills/authoring/workflows/ngsiem-detection-ti-enrichment-copilot.yaml
21.5 KB · Oct 5, 2026 · 18:32 UTC
# This is an exported workflow.
# Workflow: NG-SIEM Detection Threat Intel Enrichment - copilot
# Category: threat-intel / ngsiem-detection-response
#
# Fires on any Next-Gen SIEM detection (Signal trigger, event:
# Investigatable/NGSIEM), hydrates the full detection context with an Event
# Query (joined on Ngsiem.alert.id, dropping the correlation-rule meta-event),
# extracts user/host/domain/url/file-hash/ip indicators, and fans out
# VirusTotal Cloud HTTP Request enrichment for domain, URL, file hash, and IP
# in parallel (gated on each indicator being present). VirusTotal is used for
# every indicator type here; DomainTools Iris Investigate is a Store *plugin*
# action (compound id, requires a console-configured config_id) and can be
# swapped in for the domain branch once that credential exists in the target
# CID - see the comment on DomainHTTPRequest below. User and host names are
# extracted and carried into the summary directly since neither VirusTotal
# nor DomainTools offer a username/hostname reputation lookup.
#
# All four HTTP actions are authored credential-less (Authentication = "None")
# per the console-credential boundary - attach a VirusTotal API key to each
# after import: action -> Authentication -> Create new -> API key -> Header ->
# x-apikey -> Test -> Schema builder -> Save.
name: NG-SIEM Detection Threat Intel Enrichment - copilot
description: Triggers on a Next-Gen SIEM detection, hydrates it with an Event Query, extracts user/host/domain/url/file-hash/ip indicators, enriches domain/url/file-hash/ip in parallel via VirusTotal Cloud HTTP Requests, summarizes all findings with Charlotte AI, and emails an HTML report.
trigger:
next:
- InitEnrichmentVariable
name: NG-SIEM Detection
event: Investigatable/NGSIEM
type: Signal
actions:
InitEnrichmentVariable:
id: 702d15788dbbffdf0b68d8e2f3599aa4
class: CreateVariable
name: Create variable - Initialize enrichment context
next:
- HydrateDetection
properties:
variable_schema:
type: object
properties:
user_name:
type: string
host_name:
type: string
domain_name:
type: string
url:
type: string
file_hash:
type: string
ip_address:
type: string
domain_enrichment:
type: string
url_enrichment:
type: string
hash_enrichment:
type: string
ip_enrichment:
type: string
version_constraint: ~1
HydrateDetection:
id: cdf5c3e0d69f156eaaf56c1f5d3f1b66
class: Inline.QueryEvent
name: Query event - Hydrate NG-SIEM detection
next:
- ExtractIndicators
properties:
detection_id: ${data['Trigger.Detection.DetectionID']}
logscale_search_start_time: 7 days
output_files_only: false
workflow_csv_header_fields: []
workflow_export_event_query_results_to_csv: false
inline_configuration:
config:
description: Hydrate the full NG-SIEM detection context by its composite detection ID, dropping the correlation-rule meta-event.
end: now
repo_or_view: search-all
search_name: Hydrate NG-SIEM detection
search_query: "#repo=xdr_indicatorsrepo Ngsiem.alert.id=?detection_id | xdr_type != correlation-rule-detection | report_name != *"
search_query_args:
detection_id: '*'
start: 7d
tags: []
input_schema:
$schema: https://json-schema.org/draft-07/schema
type: object
description: Generated request schema
required:
- detection_id
properties:
detection_id:
type: string
title: Detection ID
default: '*'
version_constraint: ~1
ExtractIndicators:
id: 6c6eab39063fa3b72d98c82af60deb8a
class: UpdateVariable
name: Update variable - Extract indicators from hydrated detection
next:
- domain_present
- url_present
- hash_present
- ip_present
properties:
WorkflowCustomVariable:
user_name: "${data['HydrateDetection.results'].size() > 0 ? data['HydrateDetection.results'][0].UserName.orValue('') : ''}"
host_name: "${data['HydrateDetection.results'].size() > 0 ? data['HydrateDetection.results'][0].HostName.orValue('') : ''}"
domain_name: "${data['HydrateDetection.results'].size() > 0 ? data['HydrateDetection.results'][0].DomainName.orValue('') : ''}"
url: "${data['HydrateDetection.results'].size() > 0 ? data['HydrateDetection.results'][0].Url.orValue('') : ''}"
file_hash: "${data['HydrateDetection.results'].size() > 0 ? data['HydrateDetection.results'][0].FileHash.orValue('') : ''}"
ip_address: "${data['HydrateDetection.results'].size() > 0 ? data['HydrateDetection.results'][0].IpAddress.orValue('') : ''}"
version_constraint: ~1
DomainHTTPRequest:
id: 1ba474f407d9228fc8fa02cdce8ae8ef
class: Inline.HTTPRequest
name: Cloud HTTP Request - VirusTotal Domain Enrichment
next:
- UpdateDomainEnrichment
inline_configuration:
output_schema:
$schema: https://json-schema.org/draft-07/schema
type: object
properties:
data:
type: object
properties:
id:
type: string
attributes:
type: object
properties:
reputation:
type: integer
categories:
type: object
last_analysis_stats:
type: object
properties:
malicious:
type: integer
suspicious:
type: integer
harmless:
type: integer
undetected:
type: integer
properties:
http_transaction:
request_http_method: GET
request_url: "https://www.virustotal.com/api/v3/domains/${data['WorkflowCustomVariable.domain_name']}"
request_content_type: NONE
request_headers: {}
request_body: '{}'
_cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","type":"object","properties":{"data":{"type":"object","properties":{"id":{"type":"string"},"attributes":{"type":"object","properties":{"reputation":{"type":"integer"},"categories":{"type":"object"},"last_analysis_stats":{"type":"object","properties":{"malicious":{"type":"integer"},"suspicious":{"type":"integer"},"harmless":{"type":"integer"},"undetected":{"type":"integer"}}}}}}}}}'
version_constraint: ~1
UpdateDomainEnrichment:
id: 6c6eab39063fa3b72d98c82af60deb8a
class: UpdateVariable
name: Update variable - Store domain enrichment
next:
- SummarizeEnrichment
properties:
WorkflowCustomVariable:
domain_enrichment: "Domain: ${data['WorkflowCustomVariable.domain_name']} | Reputation: ${data['DomainHTTPRequest.data.attributes.reputation']} | Malicious: ${data['DomainHTTPRequest.data.attributes.last_analysis_stats.malicious']} | Suspicious: ${data['DomainHTTPRequest.data.attributes.last_analysis_stats.suspicious']}"
version_constraint: ~1
HashHTTPRequest:
id: 1ba474f407d9228fc8fa02cdce8ae8ef
class: Inline.HTTPRequest
name: Cloud HTTP Request - VirusTotal File Hash Enrichment
next:
- UpdateHashEnrichment
inline_configuration:
output_schema:
$schema: https://json-schema.org/draft-07/schema
type: object
properties:
data:
type: object
properties:
id:
type: string
attributes:
type: object
properties:
reputation:
type: integer
type_description:
type: string
meaningful_name:
type: string
last_analysis_stats:
type: object
properties:
malicious:
type: integer
suspicious:
type: integer
harmless:
type: integer
undetected:
type: integer
properties:
http_transaction:
request_http_method: GET
request_url: "https://www.virustotal.com/api/v3/files/${data['WorkflowCustomVariable.file_hash']}"
request_content_type: NONE
request_headers: {}
request_body: '{}'
_cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","type":"object","properties":{"data":{"type":"object","properties":{"id":{"type":"string"},"attributes":{"type":"object","properties":{"reputation":{"type":"integer"},"type_description":{"type":"string"},"meaningful_name":{"type":"string"},"last_analysis_stats":{"type":"object","properties":{"malicious":{"type":"integer"},"suspicious":{"type":"integer"},"harmless":{"type":"integer"},"undetected":{"type":"integer"}}}}}}}}}'
version_constraint: ~1
UpdateHashEnrichment:
id: 6c6eab39063fa3b72d98c82af60deb8a
class: UpdateVariable
name: Update variable - Store file hash enrichment
next:
- SummarizeEnrichment
properties:
WorkflowCustomVariable:
hash_enrichment: "File hash: ${data['WorkflowCustomVariable.file_hash']} | Name: ${data['HashHTTPRequest.data.attributes.meaningful_name']} | Type: ${data['HashHTTPRequest.data.attributes.type_description']} | Malicious: ${data['HashHTTPRequest.data.attributes.last_analysis_stats.malicious']} | Suspicious: ${data['HashHTTPRequest.data.attributes.last_analysis_stats.suspicious']}"
version_constraint: ~1
IPHTTPRequest:
id: 1ba474f407d9228fc8fa02cdce8ae8ef
class: Inline.HTTPRequest
name: Cloud HTTP Request - VirusTotal IP Enrichment
next:
- UpdateIPEnrichment
inline_configuration:
output_schema:
$schema: https://json-schema.org/draft-07/schema
type: object
properties:
data:
type: object
properties:
id:
type: string
attributes:
type: object
properties:
reputation:
type: integer
country:
type: string
as_owner:
type: string
last_analysis_stats:
type: object
properties:
malicious:
type: integer
suspicious:
type: integer
harmless:
type: integer
undetected:
type: integer
properties:
http_transaction:
request_http_method: GET
request_url: "https://www.virustotal.com/api/v3/ip_addresses/${data['WorkflowCustomVariable.ip_address']}"
request_content_type: NONE
request_headers: {}
request_body: '{}'
_cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","type":"object","properties":{"data":{"type":"object","properties":{"id":{"type":"string"},"attributes":{"type":"object","properties":{"reputation":{"type":"integer"},"country":{"type":"string"},"as_owner":{"type":"string"},"last_analysis_stats":{"type":"object","properties":{"malicious":{"type":"integer"},"suspicious":{"type":"integer"},"harmless":{"type":"integer"},"undetected":{"type":"integer"}}}}}}}}}'
version_constraint: ~1
UpdateIPEnrichment:
id: 6c6eab39063fa3b72d98c82af60deb8a
class: UpdateVariable
name: Update variable - Store IP enrichment
next:
- SummarizeEnrichment
properties:
WorkflowCustomVariable:
ip_enrichment: "IP: ${data['WorkflowCustomVariable.ip_address']} | Owner: ${data['IPHTTPRequest.data.attributes.as_owner']} | Country: ${data['IPHTTPRequest.data.attributes.country']} | Reputation: ${data['IPHTTPRequest.data.attributes.reputation']} | Malicious: ${data['IPHTTPRequest.data.attributes.last_analysis_stats.malicious']} | Suspicious: ${data['IPHTTPRequest.data.attributes.last_analysis_stats.suspicious']}"
version_constraint: ~1
URLSubmitHTTPRequest:
id: 1ba474f407d9228fc8fa02cdce8ae8ef
class: Inline.HTTPRequest
name: Cloud HTTP Request - VirusTotal URL Submission
next:
- URLAnalysisHTTPRequest
inline_configuration:
output_schema:
$schema: https://json-schema.org/draft-07/schema
type: object
properties:
data:
type: object
properties:
id:
type: string
properties:
http_transaction:
request_http_method: POST
request_url: https://www.virustotal.com/api/v3/urls
request_content_type: JSON
request_headers: {}
request_body: "{\"url\": \"${data['WorkflowCustomVariable.url']}\"}"
_cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","type":"object","properties":{"data":{"type":"object","properties":{"id":{"type":"string"}}}}}'
version_constraint: ~1
URLAnalysisHTTPRequest:
id: 1ba474f407d9228fc8fa02cdce8ae8ef
class: Inline.HTTPRequest
name: Cloud HTTP Request - VirusTotal URL Analysis Result
next:
- UpdateURLEnrichment
inline_configuration:
output_schema:
$schema: https://json-schema.org/draft-07/schema
type: object
properties:
data:
type: object
properties:
attributes:
type: object
properties:
status:
type: string
stats:
type: object
properties:
malicious:
type: integer
suspicious:
type: integer
harmless:
type: integer
undetected:
type: integer
properties:
http_transaction:
request_http_method: GET
request_url: "https://www.virustotal.com/api/v3/analyses/${data['URLSubmitHTTPRequest.data.id']}"
request_content_type: NONE
request_headers: {}
request_body: '{}'
_cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","type":"object","properties":{"data":{"type":"object","properties":{"attributes":{"type":"object","properties":{"status":{"type":"string"},"stats":{"type":"object","properties":{"malicious":{"type":"integer"},"suspicious":{"type":"integer"},"harmless":{"type":"integer"},"undetected":{"type":"integer"}}}}}}}}}'
version_constraint: ~1
UpdateURLEnrichment:
id: 6c6eab39063fa3b72d98c82af60deb8a
class: UpdateVariable
name: Update variable - Store URL enrichment
next:
- SummarizeEnrichment
properties:
WorkflowCustomVariable:
url_enrichment: "URL: ${data['WorkflowCustomVariable.url']} | Status: ${data['URLAnalysisHTTPRequest.data.attributes.status']} | Malicious: ${data['URLAnalysisHTTPRequest.data.attributes.stats.malicious']} | Suspicious: ${data['URLAnalysisHTTPRequest.data.attributes.stats.suspicious']}"
version_constraint: ~1
SummarizeEnrichment:
id: bdfecafafdb44919a458fcf51d6b93a7_98dec86072334d24b37dd798098cfd63
name: Charlotte AI - LLM Completion - Summarize threat intel enrichment
next:
- SendEmail
properties:
data_to_include:
- "Detection: ${data['Trigger.Detection.Name']} (ID ${data['Trigger.Detection.DetectionID']}), Severity ${data['Trigger.Detection.Severity']}"
- "User: ${data['WorkflowCustomVariable.user_name']}"
- "Host: ${data['WorkflowCustomVariable.host_name']}"
- "Domain enrichment: ${data['WorkflowCustomVariable.domain_enrichment']}"
- "URL enrichment: ${data['WorkflowCustomVariable.url_enrichment']}"
- "File hash enrichment: ${data['WorkflowCustomVariable.hash_enrichment']}"
- "IP enrichment: ${data['WorkflowCustomVariable.ip_enrichment']}"
model_name: Claude Sonnet 4
temperature: 0
user_prompt: "You are a CrowdStrike threat analyst. Summarize this NG-SIEM detection and its threat intelligence enrichment results across all providers (VirusTotal domain/URL/file-hash/IP lookups). Call out the affected user and host, note which indicators were malicious/suspicious versus clean, and give an overall risk assessment with recommended next steps. Be concise and actionable. Respond with raw HTML only (headings, lists, bold) - do NOT wrap the response in markdown code fences such as ```html."
version_constraint: ~0
SendEmail:
id: 07413ef9ba7c47bf5a242799f59902cc
name: Send email - NG-SIEM detection threat intel summary
properties:
to:
- soc-team@crowdstrike.com
subject: "[Falcon Fusion] NG-SIEM Detection Threat Intel Summary - ${data['Trigger.Detection.Name']}"
msg: "<html><body>${data['SummarizeEnrichment.FaaS.nlpassistantapi.llminvocator_handler.completion']}</body></html>"
msg_type: html
version_constraint: ~1
conditions:
domain_present:
next:
- DomainHTTPRequest
cel_expression: "data['WorkflowCustomVariable.domain_name'] != null && data['WorkflowCustomVariable.domain_name'] != ''"
display:
- Domain indicator present
else:
- SummarizeEnrichment
url_present:
next:
- URLSubmitHTTPRequest
cel_expression: "data['WorkflowCustomVariable.url'] != null && data['WorkflowCustomVariable.url'] != ''"
display:
- URL indicator present
else:
- SummarizeEnrichment
hash_present:
next:
- HashHTTPRequest
cel_expression: "data['WorkflowCustomVariable.file_hash'] != null && data['WorkflowCustomVariable.file_hash'] != ''"
display:
- File hash indicator present
else:
- SummarizeEnrichment
ip_present:
next:
- IPHTTPRequest
cel_expression: "data['WorkflowCustomVariable.ip_address'] != null && data['WorkflowCustomVariable.ip_address'] != ''"
display:
- IP indicator present
else:
- SummarizeEnrichment
output_fields: []
SHA-256: 5dc29c816a33168404f518b8f46ca817781ddb1cb8e1d436eb562800be7bc6bd