Use the Office 365 Malicious File Detected playbook
Release version: Xanadu
Updated August 1, 2024
2 minutes to read
Use this playbook to investigate malicious files detected in Office 365. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Office 365 Malicious File Detected
playbook.
Before you begin
Role required:
sn_si.admin
flow_designer
Procedure
When the playbook is triggered and starts executing, in Action 1, you need to extract the malicious file from the Office 365 console.
In Action 2, you need to analyze whether the file or hash has been added as an observable in the Threat Intel Platform.
In Action 3, you need to investigate the file name and path to determine whether it is a known or non-malicious file/application.