Cofense Triage v2
Use the Cofense Triage integration to ingest reported phishing indicators.
Data Enrichment & Threat Intelligence · Cofense Triage
Details
| ID | Cofense Triage v2 |
|---|---|
| Provider | Cofense |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Docker Image | demisto/chromium:149.0.7827.10133006 |
| Supported Modules | Agentix XSIAM |
README
Use the Cofense Triage integration to ingest reported phishing indicators.
This integration was integrated and tested with version 1.20 of Cofense Triage v2
Configure Cofense Triage v2 in Cortex
| Parameter | Description | Required |
|---|---|---|
| host | Server URL (e.g., https://192.168.0.1) | True |
| user | User | True |
| token | API Token | True |
| isFetch | Fetch incidents | False |
| incidentType | Incident type | False |
| date_range | First fetch time (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year) | False |
| category_id | Category ID to fetch | False |
| match_priority | Match Priority - the highest match priority based on rule hits for the report | False |
| tags | Tags - CSV list of tags of processed reports by which to filter | False |
| max_fetch | Maximum number of incidents to fetch each time | False |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
cofense-search-reports
Runs a query for reports.
Base Command
cofense-search-reports
Input
| Argument Name | Description | Required |
|---|---|---|
| file_hash | File hash, MD5 or SHA256. | Optional |
| url | The reported URLs. | Optional |
| subject | Report’s subject | Optional |
| reported_at | Retrieve reports that were reported after this time, for example: “2 hours, 4 minutes, 6 month, 1 day”. | Optional |
| created_at | Retrieve reports that were created after this time, for example: “2 hours, 4 minutes, 6 month, 1 day”. | Optional |
| reporter | Address or ID of the reporter. | Optional |
| max_matches | Maximum number of matches to fetch. Default is 30. | Optional |
| verbose | Returns all fields of a report. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Cofense.Report.ID | unknown | ID number of the report. |
| Cofense.Report.EmailAttachments | unknown | Email attachments. |
| Cofense.Report.EmailAttachments.id | unknown | Email attachment ID. |
| Cofense.Report.Tags | string | Report tags. |
| Cofense.Report.ClusterId | number | Cluster ID number. |
| Cofense.Report.CategoryId | number | Report category. |
| Cofense.Report.CreatedAt | date | Report creation date. |
| Cofense.Report.ReportedAt | string | Reporting time. |
| Cofense.Report.MatchPriority | number | The highest match priority based on rule hits for the report. |
| Cofense.Report.ReporterId | number | Reporter ID. |
| Cofense.Report.Location | string | Location of the report. |
| Cofense.Report.Reporter | string | Reporter email address. |
| Cofense.Report.SuspectFromAddress | string | Suspect from address. |
| Cofense.Report.ReportSubject | string | Report subject. |
| Cofense.Report.ReportBody | string | Report body. |
| Cofense.Report.Md5 | number | MD5 hash of the file. |
| Cofense.Report.Sha256 | unknown | SHA256 hash of the file. |
Command Example
!cofense-search-reports reported_at="7 days" created_at="7 days" max_matches="1"
Context Example
{
"Cofense": {
"Report": {
"CategoryId": 4,
"ClusterId": null,
"CreatedAt": "2020-06-04T13:42:26.173Z",
"EmailAttachments": [
{
"content_type": "image/png; name=image001.png",
"decoded_filename": "image001.png",
"email_attachment_payload": {
"id": 7095,
"md5": "5008fb6e6652f56cac5bdc5bf1cbe9c2",
"mime_type": "image/png; charset=binary",
"sha256": "554aeaaace31c7038a09dd408945583e1035ec124a46b04e5c6c5b148dc96f68"
},
"id": 18087,
"report_id": 13429,
"size_in_bytes": 1397
},
{
"content_type": "image/png; name=image003.png",
"decoded_filename": "image003.png",
"email_attachment_payload": {
"id": 7097,
"md5": "731ffb7846c22e41e9de8de307c93ece",
"mime_type": "image/png; charset=binary",
"sha256": "c911d07d1f7be624e00e44821148629d98cf6d0f2bfac112362c7c564522ea51"
},
"id": 18089,
"report_id": 13429,
"size_in_bytes": 1701
},
{
"content_type": "image/png; name=image006.png",
"decoded_filename": "image006.png",
"email_attachment_payload": {
"id": 7100,
"md5": "124bd437f87181fdfe3154b31fd2cf6b",
"mime_type": "image/png; charset=binary",
"sha256": "3d804c705545bf2a1e5ac6b0ea9b93a41ceb16d7453adebc58fba5df75335b20"
},
"id": 18092,
"report_id": 13429,
"size_in_bytes": 1994
},
{
"content_type": "image/png; name=image002.png",
"decoded_filename": "image002.png",
"email_attachment_payload": {
"id": 7096,
"md5": "cc07463ceeaaed79783a7f2a607797f9",
"mime_type": "image/png; charset=binary",
"sha256": "c6c2c95238f52648faaef4520fa9bba49c10ca0f1df9bfd1912be544f319b80b"
},
"id": 18088,
"report_id": 13429,
"size_in_bytes": 1430
},
{
"content_type": "image/png; name=image004.png",
"decoded_filename": "image004.png",
"email_attachment_payload": {
"id": 7098,
"md5": "95878e37974ed3cad67154d36dd58a9a",
"mime_type": "image/png; charset=binary",
"sha256": "e0d478f6ce56721867a0584ddea0016d713b9b2ab758fd0c9be3f1409d6e2634"
},
"id": 18090,
"report_id": 13429,
"size_in_bytes": 1557
},
{
"content_type": "image/png; name=image005.png",
"decoded_filename": "image005.png",
"email_attachment_payload": {
"id": 7099,
"md5": "0e911498bf4dc5eddb544ab5ece4b06a",
"mime_type": "image/png; charset=binary",
"sha256": "5f2046b3c55a874aadde052f9da4af3c17e2b5bf5baf704f58b1dd1eadf08544"
},
"id": 18091,
"report_id": 13429,
"size_in_bytes": 1609
},
{
"content_type": "application/pdf; name=\"XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf\"",
"decoded_filename": "XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf",
"email_attachment_payload": {
"id": 7110,
"md5": "fb7f083f4fb93a88ab8110d857312978",
"mime_type": "application/pdf; charset=binary",
"sha256": "15ab1b20ada04dfc6285caff5e4da4eab09a9157c2cbe32cd96113da6304a5ee"
},
"id": 18093,
"report_id": 13429,
"size_in_bytes": 49597
}
],
"ID": 13429,
"Location": "Processed",
"MatchPriority": 1,
"Md5": "d312e79695d5de744436006aab6b4ec1",
"ReportBody": "Testing PDF attachment\r\n\r\n\r\nTest User | Director\r\nTEST\r\nm. 123-456-7890\r\ne. test@test.com<mailto:test@test.com>\r\n\r\nConnect with Cofense:\r\n\r\n[signature_527626984]<https://cofense.com/>[signature_379086648]<https://facebook.com/cofense>[signature_426568440]<https://twitter.com/cofense>[signature_1467413640]<https://linkedin.com/company/cofense>[signature_749445379]<https://www.instagram.com/cofense/>[signature_1384270593]<https://www.themuse.com/profiles/cofense>\r\n\r\nUniting Humanity Against Phishing. Watch Our Video<https://cofense.com/project/uhap-video/>\r\n\r\n",
"ReportSubject": "2020-06-04 XSOAR attachment test",
"ReportedAt": "2020-06-04T13:40:29.000Z",
"ReporterId": 5331,
"Sha256": "ba77b5d984f7da97b6f96daa442535c79f47e4b6ea0055e3472b855ee8c244e4",
"Tags": []
}
}
}
Human Readable Output
Reports
Category Id Created At Email Attachments Id Location Match Priority Md5 Report Body Report Subject Reported At Reporter Id Sha256 4 2020-06-04T13:42:26.173Z {‘id’: 18087, ‘report_id’: 13429, ‘decoded_filename’: ‘image001.png’, ‘content_type’: ‘image/png; name=image001.png’, ‘size_in_bytes’: 1397, ‘email_attachment_payload’: {‘id’: 7095, ‘md5’: ‘5008fb6e6652f56cac5bdc5bf1cbe9c2’, ‘sha256’: ‘554aeaaace31c7038a09dd408945583e1035ec124a46b04e5c6c5b148dc96f68’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18089, ‘report_id’: 13429, ‘decoded_filename’: ‘image003.png’, ‘content_type’: ‘image/png; name=image003.png’, ‘size_in_bytes’: 1701, ‘email_attachment_payload’: {‘id’: 7097, ‘md5’: ‘731ffb7846c22e41e9de8de307c93ece’, ‘sha256’: ‘c911d07d1f7be624e00e44821148629d98cf6d0f2bfac112362c7c564522ea51’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18092, ‘report_id’: 13429, ‘decoded_filename’: ‘image006.png’, ‘content_type’: ‘image/png; name=image006.png’, ‘size_in_bytes’: 1994, ‘email_attachment_payload’: {‘id’: 7100, ‘md5’: ‘124bd437f87181fdfe3154b31fd2cf6b’, ‘sha256’: ‘3d804c705545bf2a1e5ac6b0ea9b93a41ceb16d7453adebc58fba5df75335b20’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18088, ‘report_id’: 13429, ‘decoded_filename’: ‘image002.png’, ‘content_type’: ‘image/png; name=image002.png’, ‘size_in_bytes’: 1430, ‘email_attachment_payload’: {‘id’: 7096, ‘md5’: ‘cc07463ceeaaed79783a7f2a607797f9’, ‘sha256’: ‘c6c2c95238f52648faaef4520fa9bba49c10ca0f1df9bfd1912be544f319b80b’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18090, ‘report_id’: 13429, ‘decoded_filename’: ‘image004.png’, ‘content_type’: ‘image/png; name=image004.png’, ‘size_in_bytes’: 1557, ‘email_attachment_payload’: {‘id’: 7098, ‘md5’: ‘95878e37974ed3cad67154d36dd58a9a’, ‘sha256’: ‘e0d478f6ce56721867a0584ddea0016d713b9b2ab758fd0c9be3f1409d6e2634’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18091, ‘report_id’: 13429, ‘decoded_filename’: ‘image005.png’, ‘content_type’: ‘image/png; name=image005.png’, ‘size_in_bytes’: 1609, ‘email_attachment_payload’: {‘id’: 7099, ‘md5’: ‘0e911498bf4dc5eddb544ab5ece4b06a’, ‘sha256’: ‘5f2046b3c55a874aadde052f9da4af3c17e2b5bf5baf704f58b1dd1eadf08544’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18093, ‘report_id’: 13429, ‘decoded_filename’: ‘XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf’, ‘content_type’: ‘application/pdf; name=”XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf”’, ‘size_in_bytes’: 49597, ‘email_attachment_payload’: {‘id’: 7110, ‘md5’: ‘fb7f083f4fb93a88ab8110d857312978’, ‘sha256’: ‘15ab1b20ada04dfc6285caff5e4da4eab09a9157c2cbe32cd96113da6304a5ee’, ‘mime_type’: ‘application/pdf; charset=binary’}}13429 Processed 1 d312e79695d5de744436006aab6b4ec1 Testing PDF attachment
Test User | Director
COFENSE
m. 123-456-7890
e. test@test.comtest@test.com
Connect with Cofense:
[signature_527626984]https://cofense.com/[signature_379086648]https://facebook.com/cofense[signature_426568440]https://twitter.com/cofense[signature_1467413640]https://linkedin.com/company/cofense[signature_749445379]https://www.instagram.com/cofense/[signature_1384270593]https://www.themuse.com/profiles/cofense
Uniting Humanity Against Phishing. Watch Our Videohttps://cofense.com/project/uhap-video/2020-06-04 XSOAR attachment test 2020-06-04T13:40:29.000Z 5331 ba77b5d984f7da97b6f96daa442535c79f47e4b6ea0055e3472b855ee8c244e4
cofense-search-inbox-reports
Runs a query for reports from the inbox mailbox.
Base Command
cofense-search-reports
Input
| Argument Name | Description | Required |
|---|---|---|
| file_hash | File hash, MD5 or SHA256. | Optional |
| url | The reported URLs. | Optional |
| subject | Report’s subject | Optional |
| reported_at | Retrieve reports that were reported after this time, for example: “2 hours, 4 minutes, 6 month, 1 day”. | Optional |
| created_at | Retrieve reports that were created after this time, for example: “2 hours, 4 minutes, 6 month, 1 day”. | Optional |
| reporter | Address or ID of the reporter. | Optional |
| max_matches | Maximum number of matches to fetch. Default is 30. | Optional |
| verbose | Returns all fields of a report. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Cofense.Report.ID | unknown | ID number of the report. |
| Cofense.Report.EmailAttachments | unknown | Email attachments. |
| Cofense.Report.EmailAttachments.id | unknown | Email attachment ID. |
| Cofense.Report.Tags | string | Report tags. |
| Cofense.Report.ClusterId | number | Cluster ID number. |
| Cofense.Report.CategoryId | number | Report category. |
| Cofense.Report.CreatedAt | date | Report creation date. |
| Cofense.Report.ReportedAt | string | Reporting time. |
| Cofense.Report.MatchPriority | number | The highest match priority based on rule hits for the report. |
| Cofense.Report.ReporterId | number | Reporter ID. |
| Cofense.Report.Location | string | Location of the report. |
| Cofense.Report.Reporter | string | Reporter email address. |
| Cofense.Report.SuspectFromAddress | string | Suspect from address. |
| Cofense.Report.ReportSubject | string | Report subject. |
| Cofense.Report.ReportBody | string | Report body. |
| Cofense.Report.Md5 | number | MD5 hash of the file. |
| Cofense.Report.Sha256 | unknown | SHA256 hash of the file. |
Command Example
!cofense-search-inbox-reports reported_at="7 days" created_at="7 days" max_matches="1"
Context Example
{
"Cofense": {
"Report": {
"CategoryId": 4,
"ClusterId": null,
"CreatedAt": "2020-06-04T13:42:26.173Z",
"EmailAttachments": [
{
"content_type": "image/png; name=image001.png",
"decoded_filename": "image001.png",
"email_attachment_payload": {
"id": 7095,
"md5": "5008fb6e6652f56cac5bdc5bf1cbe9c2",
"mime_type": "image/png; charset=binary",
"sha256": "554aeaaace31c7038a09dd408945583e1035ec124a46b04e5c6c5b148dc96f68"
},
"id": 18087,
"report_id": 13429,
"size_in_bytes": 1397
},
{
"content_type": "image/png; name=image003.png",
"decoded_filename": "image003.png",
"email_attachment_payload": {
"id": 7097,
"md5": "731ffb7846c22e41e9de8de307c93ece",
"mime_type": "image/png; charset=binary",
"sha256": "c911d07d1f7be624e00e44821148629d98cf6d0f2bfac112362c7c564522ea51"
},
"id": 18089,
"report_id": 13429,
"size_in_bytes": 1701
},
{
"content_type": "image/png; name=image006.png",
"decoded_filename": "image006.png",
"email_attachment_payload": {
"id": 7100,
"md5": "124bd437f87181fdfe3154b31fd2cf6b",
"mime_type": "image/png; charset=binary",
"sha256": "3d804c705545bf2a1e5ac6b0ea9b93a41ceb16d7453adebc58fba5df75335b20"
},
"id": 18092,
"report_id": 13429,
"size_in_bytes": 1994
},
{
"content_type": "image/png; name=image002.png",
"decoded_filename": "image002.png",
"email_attachment_payload": {
"id": 7096,
"md5": "cc07463ceeaaed79783a7f2a607797f9",
"mime_type": "image/png; charset=binary",
"sha256": "c6c2c95238f52648faaef4520fa9bba49c10ca0f1df9bfd1912be544f319b80b"
},
"id": 18088,
"report_id": 13429,
"size_in_bytes": 1430
},
{
"content_type": "image/png; name=image004.png",
"decoded_filename": "image004.png",
"email_attachment_payload": {
"id": 7098,
"md5": "95878e37974ed3cad67154d36dd58a9a",
"mime_type": "image/png; charset=binary",
"sha256": "e0d478f6ce56721867a0584ddea0016d713b9b2ab758fd0c9be3f1409d6e2634"
},
"id": 18090,
"report_id": 13429,
"size_in_bytes": 1557
},
{
"content_type": "image/png; name=image005.png",
"decoded_filename": "image005.png",
"email_attachment_payload": {
"id": 7099,
"md5": "0e911498bf4dc5eddb544ab5ece4b06a",
"mime_type": "image/png; charset=binary",
"sha256": "5f2046b3c55a874aadde052f9da4af3c17e2b5bf5baf704f58b1dd1eadf08544"
},
"id": 18091,
"report_id": 13429,
"size_in_bytes": 1609
},
{
"content_type": "application/pdf; name=\"XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf\"",
"decoded_filename": "XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf",
"email_attachment_payload": {
"id": 7110,
"md5": "fb7f083f4fb93a88ab8110d857312978",
"mime_type": "application/pdf; charset=binary",
"sha256": "15ab1b20ada04dfc6285caff5e4da4eab09a9157c2cbe32cd96113da6304a5ee"
},
"id": 18093,
"report_id": 13429,
"size_in_bytes": 49597
}
],
"ID": 13429,
"Location": "Inbox",
"MatchPriority": 1,
"Md5": "d312e79695d5de744436006aab6b4ec1",
"ReportBody": "Testing PDF attachment\r\n\r\n\r\nTest User | Director\r\nTEST\r\nm. 123-456-7890\r\ne. test@test.com<mailto:test@test.com>\r\n\r\nConnect with Cofense:\r\n\r\n[signature_527626984]<https://cofense.com/>[signature_379086648]<https://facebook.com/cofense>[signature_426568440]<https://twitter.com/cofense>[signature_1467413640]<https://linkedin.com/company/cofense>[signature_749445379]<https://www.instagram.com/cofense/>[signature_1384270593]<https://www.themuse.com/profiles/cofense>\r\n\r\nUniting Humanity Against Phishing. Watch Our Video<https://cofense.com/project/uhap-video/>\r\n\r\n",
"ReportSubject": "2020-06-04 XSOAR attachment test",
"ReportedAt": "2020-06-04T13:40:29.000Z",
"ReporterId": 5331,
"Sha256": "ba77b5d984f7da97b6f96daa442535c79f47e4b6ea0055e3472b855ee8c244e4",
"Tags": []
}
}
}
Human Readable Output
Reports
Category Id Created At Email Attachments Id Location Match Priority Md5 Report Body Report Subject Reported At Reporter Id Sha256 4 2020-06-04T13:42:26.173Z {‘id’: 18087, ‘report_id’: 13429, ‘decoded_filename’: ‘image001.png’, ‘content_type’: ‘image/png; name=image001.png’, ‘size_in_bytes’: 1397, ‘email_attachment_payload’: {‘id’: 7095, ‘md5’: ‘5008fb6e6652f56cac5bdc5bf1cbe9c2’, ‘sha256’: ‘554aeaaace31c7038a09dd408945583e1035ec124a46b04e5c6c5b148dc96f68’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18089, ‘report_id’: 13429, ‘decoded_filename’: ‘image003.png’, ‘content_type’: ‘image/png; name=image003.png’, ‘size_in_bytes’: 1701, ‘email_attachment_payload’: {‘id’: 7097, ‘md5’: ‘731ffb7846c22e41e9de8de307c93ece’, ‘sha256’: ‘c911d07d1f7be624e00e44821148629d98cf6d0f2bfac112362c7c564522ea51’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18092, ‘report_id’: 13429, ‘decoded_filename’: ‘image006.png’, ‘content_type’: ‘image/png; name=image006.png’, ‘size_in_bytes’: 1994, ‘email_attachment_payload’: {‘id’: 7100, ‘md5’: ‘124bd437f87181fdfe3154b31fd2cf6b’, ‘sha256’: ‘3d804c705545bf2a1e5ac6b0ea9b93a41ceb16d7453adebc58fba5df75335b20’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18088, ‘report_id’: 13429, ‘decoded_filename’: ‘image002.png’, ‘content_type’: ‘image/png; name=image002.png’, ‘size_in_bytes’: 1430, ‘email_attachment_payload’: {‘id’: 7096, ‘md5’: ‘cc07463ceeaaed79783a7f2a607797f9’, ‘sha256’: ‘c6c2c95238f52648faaef4520fa9bba49c10ca0f1df9bfd1912be544f319b80b’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18090, ‘report_id’: 13429, ‘decoded_filename’: ‘image004.png’, ‘content_type’: ‘image/png; name=image004.png’, ‘size_in_bytes’: 1557, ‘email_attachment_payload’: {‘id’: 7098, ‘md5’: ‘95878e37974ed3cad67154d36dd58a9a’, ‘sha256’: ‘e0d478f6ce56721867a0584ddea0016d713b9b2ab758fd0c9be3f1409d6e2634’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18091, ‘report_id’: 13429, ‘decoded_filename’: ‘image005.png’, ‘content_type’: ‘image/png; name=image005.png’, ‘size_in_bytes’: 1609, ‘email_attachment_payload’: {‘id’: 7099, ‘md5’: ‘0e911498bf4dc5eddb544ab5ece4b06a’, ‘sha256’: ‘5f2046b3c55a874aadde052f9da4af3c17e2b5bf5baf704f58b1dd1eadf08544’, ‘mime_type’: ‘image/png; charset=binary’}},
{‘id’: 18093, ‘report_id’: 13429, ‘decoded_filename’: ‘XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf’, ‘content_type’: ‘application/pdf; name=”XSOAR Attachment Test -Inquiry - Agent Tesla Keylogger.pdf”’, ‘size_in_bytes’: 49597, ‘email_attachment_payload’: {‘id’: 7110, ‘md5’: ‘fb7f083f4fb93a88ab8110d857312978’, ‘sha256’: ‘15ab1b20ada04dfc6285caff5e4da4eab09a9157c2cbe32cd96113da6304a5ee’, ‘mime_type’: ‘application/pdf; charset=binary’}}13429 Processed 1 d312e79695d5de744436006aab6b4ec1 Testing PDF attachment
Test User | Director
TEST
m. 123-456-7890
e. test@test.comtest@test.com
Connect with Cofense:
[signature_527626984]https://cofense.com/[signature_379086648]https://facebook.com/cofense[signature_426568440]https://twitter.com/cofense[signature_1467413640]https://linkedin.com/company/cofense[signature_749445379]https://www.instagram.com/cofense/[signature_1384270593]https://www.themuse.com/profiles/cofense
Uniting Humanity Against Phishing. Watch Our Videohttps://cofense.com/project/uhap-video/2020-06-04 XSOAR attachment test 2020-06-04T13:40:29.000Z 5331 ba77b5d984f7da97b6f96daa442535c79f47e4b6ea0055e3472b855ee8c244e4
cofense-get-attachment
Retrieves an attachment by the attachment ID number.
Base Command
cofense-get-attachment
Input
| Argument Name | Description | Required |
|---|---|---|
| attachment_id | ID of the attachment. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| File.Size | number | File size. |
| File.Type | string | File type, for example: “PE”, “txt” |
| File.EntryID | string | The file entry ID. |
| File.Name | string | File name. |
| File.SHA1 | string | File SHA1 hash. |
| File.SHA256 | string | File SHA256 hash. |
| File.MD5 | string | File MD5 hash. |
Command Example
!cofense-get-attachment attachment_id="13311"
Context Example
{
"File": {
"EntryID": "603@cc18bdc4-7c64-494c-879c-23c3aee60818",
"Info": "text/plain",
"MD5": "97ee1d575640245abadbba15c0672eec",
"Name": "13311",
"SHA1": "13395876300d0a575812878446e15b9bbddda0b2",
"SHA256": "19d9c63bf4067a897950cfb72c14e8d05d8dcab0655979c6b60b925fb91e329f",
"SHA512": "31df48f235cc82247c6edc05850f910d6a057717d5d5f6ce84a4bc6c6fc3cc1f6ebae706ac592ace106b0559753928a838a1aee7018bec5b4316b90d95f55bcf",
"SSDeep": "24:nDBTBpJG4hbUWBFcXekJPkJ1WkJM8PWkJKckJvV/WskJvV28BesR1zvX0:nDNrHb1BWXekJPkJ1WkJfPWkJDkJvV/n",
"Size": 988,
"Type": "ASCII text, with CRLF line terminators"
}
}
Human Readable Output
cofense-get-reporter
Retrieves Email address of the reporter by ID
Base Command
cofense-get-reporter
Input
| Argument Name | Description | Required |
|---|---|---|
| reporter_id | ID of the reporter. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Cofense.Reporter.ID | number | ID of the reporter. |
| Cofense.Reporter.Email | string | Reporter email address. |
| Cofense.Reporter.CreatedAt | string | Reporter creation date. |
| Cofense.Reporter.UpdatedAt | string | Reporter last-updated date. |
| Cofense.Reporter.CredibilityScore | number | Reporter credibility score. |
| Cofense.Reporter.ReportsCount | number | Number of reports. |
| Cofense.Reporter.LastReportedAt | string | Date of most recent report. |
| Cofense.Reporter.VIP | bool | Whether Reporter is a VIP. |
Command Example
!cofense-get-reporter reporter_id="1"
Context Example
{
"Cofense": {
"Reporter": {
"CreatedAt": "2019-04-12T02:58:17.401Z",
"CredibilityScore": 0,
"Email": "ha.oullette@example.com",
"ID": 1,
"LastReportedAt": "2016-02-18T00:24:45.000Z",
"ReportsCount": 3,
"UpdatedAt": "2019-04-12T02:59:22.287Z",
"Vip": false
}
}
}
Human Readable Output
Integration log: cmel case attrs: {‘ID’: 1, ‘Email’: ‘ha.oullette@example.com’, ‘CreatedAt’: ‘2019-04-12T02:58:17.401Z’, ‘UpdatedAt’: ‘2019-04-12T02:59:22.287Z’, ‘CredibilityScore’: 0, ‘ReportsCount’: 3, ‘LastReportedAt’: ‘2016-02-18T00:24:45.000Z’, ‘Vip’: False}### Reporter Results:
Created At Credibility Score Id Last Reported At Reports Count Updated At Vip 2019-04-12T02:58:17.401Z 0 ha.oullette@example.com 1 2016-02-18T00:24:45.000Z 3 2019-04-12T02:59:22.287Z false
cofense-get-report-by-id
Retrieves a report by the report ID number.
Base Command
cofense-get-report-by-id
Input
| Argument Name | Description | Required |
|---|---|---|
| report_id | ID of the report | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Cofense.Report.ID | number | ID number of the report. |
| Cofense.Report.EmailAttachments | string | Email attachments. |
| Cofense.Report.EmailAttachments.id | string | Email attachment ID. |
| Cofense.Report.Tags | string | Report tags. |
| Cofense.Report.ClusterId | number | Cluster ID number. |
| Cofense.Report.CategoryId | number | Report category. |
| Cofense.Report.CreatedAt | string | Report creation date. |
| Cofense.Report.ReportedAt | string | Reporting time. |
| Cofense.Report.MatchPriority | number | The highest match priority based on rule hits for the report. |
| Cofense.Report.ReporterId | number | Reporter ID. |
| Cofense.Report.Location | string | Location of the report. |
| Cofense.Report.Reporter | string | Reporter email address. |
| Cofense.Report.SuspectFromAddress | string | Suspect from address. |
| Cofense.Report.ReportSubject | string | Report subject. |
| Cofense.Report.ReportBody | string | Report body. |
| Cofense.Report.Md5 | number | MD5 hash of the file. |
| Cofense.Report.Sha256 | unknown | SHA256 hash of the file. |
Command Example
!cofense-get-report-by-id report_id="5760"
Context Example
{
"Cofense": {
"Report": {
"CategoryId": 4,
"ClusterId": null,
"CreatedAt": "2019-04-17T20:53:02.090Z",
"EmailAttachments": [],
"ID": 5760,
"Location": "Processed",
"MatchPriority": 0,
"Md5": "f13bbc172fe7d394828ccabb25c3c99e",
"ReportSubject": "test@test.net Reset password instruction",
"ReportedAt": "2019-04-17T16:54:57.000Z",
"ReporterId": 3280,
"Sha256": "4f6bc0d9c1217a2a6f327423e16b7a6e9294c68cfb33864541bd805fe4ab2d72",
"Tags": []
}
}
}
Human Readable Output
{“HumanReadable”:”### Cofense HTML Report:\nHTML report download request has been completed”,”name”:”5760-report.html”,”path”:”aaf1160b-9176-45d9-aab9-90efd278e05d”}### Report Summary:
Category Id Created At Id Location Match Priority Md5 Report Subject Reported At Reporter Id Sha256 4 2019-04-17T20:53:02.090Z 5760 Processed 0 f13bbc172fe7d394828ccabb25c3c99e test@test.nul Reset password instruction 2019-04-17T16:54:57.000Z 3280 4f6bc0d9c1217a2a6f327423e16b7a6e9294c68cfb33864541bd805fe4ab2d72
cofense-get-report-png-by-id
Retrieves a report by the report ID number and displays as PNG
Base Command
cofense-get-report-png-by-id
Input
| Argument Name | Description | Required |
|---|---|---|
| report_id | Report ID PNG output | Required |
| set_white_bg | Change background to white | Optional |
Context Output
There is no context output for this command.
Command Example
!cofense-get-report-png-by-id report_id="5760" set_white_bg="True"
Context Example
{
"InfoFile": {
"EntryID": "616@cc18bdc4-7c64-494c-879c-23c3aee60818",
"Extension": "png",
"Info": "image/png",
"Name": "cofense_report_5760.png",
"Size": 40692,
"Type": "PNG image data, 400 x 369, 8-bit/color RGBA, non-interlaced"
}
}
Human Readable Output
Cofense: PNG of Report 5760
cofense-get-threat-indicators
Threat Indicators that are designated by analysts as malicious, suspicious or benign
Base Command
cofense-get-threat-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| type | indicator type | Optional |
| level | indicator severity | Optional |
| start_date | designated start date tagged by analyst (format example: YYYY-MM-DD+HH:MM:SS). Default: 6 days ago. | Optional |
| end_date | designated end date from assignment (format example: YYYY-MM-DD+HH:MM:SS). Default: current date. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Cofense.ThreatIndicators | unknown | Threat indicator output |
| Cofense.ThreatIndicators.ID | number | Threat indicator ID in Cofense Triage. |
| Cofense.ThreatIndicators.OperatorId | number | Cofense Triage operator who designated the threat indicator. |
| Cofense.ThreatIndicators.ReportId | number | Associated Report in Cofense Triage. |
| Cofense.ThreatIndicators.ThreatKey | string | Threat indicator type. |
| Cofense.ThreatIndicators.ThreatLevel | string | Threat indicator level. |
| Cofense.ThreatIndicators.ThreatValue | string | Value of the threat indicator. |
Command Example
!cofense-get-threat-indicators type="URL" level="Malicious" start_date="2020-05-28"
Context Example
{
"Cofense": {
"ThreatIndicators": {
"CreatedAt": "2020-05-28T22:14:52.690Z",
"ID": 75,
"OperatorId": 2,
"ReportId": 5760,
"ThreatKey": "URL",
"ThreatLevel": "Malicious",
"ThreatValue": "http://bold-air0example.com/notification.php?email=test@test.net"
}
}
}
Human Readable Output
Threat Indicators
Created At Id Operator Id Report Id Threat Key Threat Level Threat Value 2020-05-28T22:14:52.690Z 75 2 5760 URL Malicious http://bold-air0example.com/notification.php?email=test@test.net
Configuration parameters
host— Server URL (e.g., https://192.168.0.1) (required)user— User (required)token— API Token (required)isFetch— Fetch incidentsincidentType— Incident typeincidentFetchInterval— Incidents Fetch Intervalmailbox_location— Mailbox Location (required)date_range— First fetch time (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)category_id— Category ID to fetchmatch_priority— Match Priority - the highest match priority based on rule hits for the reporttags— Tags - CSV list of tags of processed reports by which to filtermax_fetch— Maximum number of incidents to fetch each timeinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (7)
-
cofense-get-attachmentRetrieves an attachment by the attachment ID number.
-
cofense-get-report-by-idRetrieves a report by the report ID number.
-
cofense-get-report-png-by-idRetrieves a report by the report ID number and displays as PNG.
-
cofense-get-reporterRetrieves Email address of the reporter by ID.
-
cofense-get-threat-indicatorsThreat Indicators that are designated by analysts as malicious, suspicious or benign.
-
cofense-search-inbox-reportsRuns a query for reports from the `inbox` mailbox.
-
cofense-search-reportsRuns a query for reports.
import datetime from pathlib import Path from unittest.mock import patch import pytest from CofenseTriagev2 import ( TriageInboxReports, TriageNoReportersFoundError, TriageReport, TriageReporter, TriageRequestFailedError, ) from freezegun import freeze_time @pytest.fixture def fixture_from_file(): def _fixture_from_file(fname): with (Path(__file__).parent / "test_data" / "fixtures" / fname).open() as file: return file.read() return _fixture_from_file DEMISTO_ARGS = {} def set_demisto_arg(name, value): DEMISTO_ARGS[name] = value def set_demisto_args(args): for name, value in args.items(): set_demisto_arg(name, value) def get_demisto_arg(name): if name in DEMISTO_ARGS: return DEMISTO_ARGS[name] raise Exception(f'Test setup did not specify a Demisto argument named {name}. Use `set_demisto_arg("{name}", "value")`.') set_demisto_arg("host", "https://some-triage-host/") set_demisto_arg("token", "api_token") set_demisto_arg("user", "user") set_demisto_arg("date_range", "1 day") set_demisto_arg("max_fetch", 30) set_demisto_arg("category_id", "") set_demisto_arg("match_priority", "") set_demisto_arg("tags", "") set_demisto_arg("mailbox_location", "Processed_Reports") patch("demistomock.getParam", get_demisto_arg) # args ≡ params in tests import CofenseTriagev2 # noqa: E402 from CofenseTriagev2 import parse_triage_date # noqa: E402 @pytest.fixture(autouse=True) def stub_demisto_setup(mocker): mocker.patch("CofenseTriagev2.return_error") mocker.patch( "CofenseTriagev2.fileResult", lambda filename="file_result_name", data="file_result_id": { "Contents": "", "ContentsFormat": "text", "Type": "what", "File": filename, "FileID": "/path/to/temp/file", }, ) mocker.patch("demistomock.getArg", get_demisto_arg) mocker.patch("demistomock.getParam", get_demisto_arg) # args ≡ params in tests mocker.patch("demistomock.results") mocker.patch("demistomock.incidents") mocker.patch("demistomock.setLastRun") @pytest.fixture @freeze_time("2000-10-31") def triage_instance(): return CofenseTriagev2.build_triage_instance() class TestCofenseTriage: def test_test_function(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports", text=fixture_from_file("processed_reports.json"), ) CofenseTriagev2.test_function(triage_instance) CofenseTriagev2.demisto.results.assert_called_once_with("ok") def test_test_function_error(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports", status_code=404, text=fixture_from_file("processed_reports.json"), ) with pytest.raises(TriageRequestFailedError): CofenseTriagev2.test_function(triage_instance) @freeze_time("2000-10-31") def test_fetch_reports(self, mocker, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports?category_id=&" "match_priority=&tags=&start_date=2000-10-30T00%3A00%3A00", # noqa: E501 text=fixture_from_file("processed_reports.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5331", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.fetch_reports(triage_instance) demisto_incidents = CofenseTriagev2.demisto.incidents.call_args_list[0][0][0] assert len(demisto_incidents) == 2 assert demisto_incidents[0]["name"] == "cofense triage report 13363: Phishing Simulation" assert demisto_incidents[0]["occurred"] == "2020-03-19T16:43:09.715Z" assert demisto_incidents[0]["severity"] == 1 assert len(demisto_incidents[0]["rawJSON"]) == 1931 assert demisto_incidents[1]["attachment"] == [{"name": "13392-report.html", "path": "/path/to/temp/file"}] CofenseTriagev2.demisto.setLastRun.assert_called_once_with({"reports_fetched": "[13392, 13363]"}) @freeze_time("2000-10-31") def test_fetch_reports_already_fetched(self, mocker, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports?category_id=&" "match_priority=&tags=&start_date=2000-10-30T00%3A00%3A00", # noqa: E501 text=fixture_from_file("processed_reports.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5331", text=fixture_from_file("reporters.json"), ) mocker.patch("demistomock.getLastRun", lambda: {"reports_fetched": "[13363]"}) CofenseTriagev2.fetch_reports(triage_instance) demisto_incidents = CofenseTriagev2.demisto.incidents.call_args_list[0][0][0] assert len(demisto_incidents) == 1 assert demisto_incidents[0]["name"] == "cofense triage report 13392: Crimeware" CofenseTriagev2.demisto.setLastRun.assert_called_once_with({"reports_fetched": "[13392, 13363]"}) @freeze_time("2000-10-31") def test_search_reports_command(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("subject", "suspicious subject") set_demisto_arg("url", "") set_demisto_arg("file_hash", "") set_demisto_arg("reporter", "") set_demisto_arg("max_matches", 10) set_demisto_arg("verbose", "") requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports?start_date=2000-10-24+00%3A00%3A00%2B00%3A00", # noqa: E501 text=fixture_from_file("processed_reports.json"), ) CofenseTriagev2.search_reports_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert ( demisto_results[0]["HumanReadable"] == ( "### Reports:\n" "|Category Id|Created At|Email Attachments|Id|Location|Match Priority|Md5|Report Body|Report Subject|Reported At|Reporter Id|Sha256|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|---|\n" # noqa: E501 "| 5 | 2020-03-19T16:43:09.715Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | 13363 | Processed | 1 | 111 | From: Sender <sender@example.com><br>Reply-To: \"sender@example.com\" <sender@example.com><br>Date: Wednesday, March 18, 2020 at 3:34 PM<br>To: recipient@example.com<br>Subject: suspicious subject<br>click on this link! trust me! <a href=\"http://example.com/malicious\">here</a> | suspicious subject | 2020-03-19T16:42:22.000Z | 5331 | 222 |\n" # noqa: E501 ) ) def test_build_reporters_clause_found(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("reporter", "reporter2@example.com") requests_mock.get( "https://some-triage-host/api/public/v1/reporters?email=reporter2%40example.com&page=0", # noqa: E501 text=fixture_from_file("reporters_by_email_reporter2.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/222", text=fixture_from_file("reporters.json"), ) assert CofenseTriagev2.build_reporters_clause(triage_instance) == {"reporter_ids": [111]} def test_build_reporters_clause_id(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("reporter", "222") requests_mock.get( "https://some-triage-host/api/public/v1/reporters/222", text=fixture_from_file("reporters.json"), ) assert CofenseTriagev2.build_reporters_clause(triage_instance) == {"reporter_ids": [222]} def test_build_reporters_clause_not_found(self, requests_mock, triage_instance): set_demisto_arg("reporter", "does_not_exist@example.com") requests_mock.get( "https://some-triage-host/api/public/v1/reporters?email=does_not_exist%40example.com&page=0", # noqa: E501 text="[]", ) with pytest.raises(TriageNoReportersFoundError): CofenseTriagev2.build_reporters_clause(triage_instance) def test_build_reporters_clause_nothing_specified(self, requests_mock, triage_instance): set_demisto_arg("reporter", "") assert CofenseTriagev2.build_reporters_clause(triage_instance) == {} @freeze_time("2000-10-31") def test_search_reports_command_not_found(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("subject", "my great subject") set_demisto_arg("url", "my-great-url") set_demisto_arg("file_hash", "") set_demisto_arg("reporter", "") set_demisto_arg("max_matches", 10) set_demisto_arg("verbose", "") requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports?start_date=2000-10-24+00%3A00%3A00%2B00%3A00", text=fixture_from_file("processed_reports.json"), ) CofenseTriagev2.search_reports_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert demisto_results[0]["HumanReadable"] == "no results were found." @freeze_time("2000-10-31") @pytest.mark.parametrize( "filter_attrs, expected_found_report_ids", [ ({"subject": "suspicious subject"}, [13363]), ({"subject": "suspicious"}, []), ({"subject": "nah"}, []), ({"url": "http://example.com/malicious"}, [13363]), ({"url": "example.com"}, []), ({"url": "nah"}, []), ({"created_at": parse_triage_date("2055-03-19T16:43:09.715Z")}, []), ( {"created_at": parse_triage_date("1999-03-19T16:43:09.715Z")}, [13363, 13392], ), ({"file_hash": "123"}, [13363]), ({"file_hash": "1234"}, [13363]), ({"file_hash": "5"}, []), ], ) def test_search_reports_filtering( self, requests_mock, triage_instance, filter_attrs, expected_found_report_ids, fixture_from_file ): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports?start_date=2000-10-31+00%3A00%3A00", # noqa: E501 text=fixture_from_file("processed_reports.json"), ) found_reports = CofenseTriagev2.search_reports(triage_instance, **filter_attrs, reported_at=datetime.datetime.now()) assert [report["id"] for report in found_reports] == expected_found_report_ids @freeze_time("2000-10-31") def test_search_inbox_reports_command(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("subject", "aaa") set_demisto_arg("url", "") set_demisto_arg("file_hash", "") set_demisto_arg("reporter", "") set_demisto_arg("max_matches", 10) requests_mock.get( "https://some-triage-host/api/public/v1/inbox_reports?start_date=2000-10-24+00%3A00%3A00%2B00%3A00&page=0", # noqa: E501 text=fixture_from_file("inbox_reports.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/222", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.search_inbox_reports_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert ( demisto_results[0]["HumanReadable"] == ( "### Reports:\n" "|Cluster Id|Created At|Email Attachments|Email Urls|Id|Location|Match Priority|Md5|Report Body|Report Headers|Report Subject|Reported At|Reporter Created At|Reporter Credibility Score|Reporter Email|Reporter Id|Reporter Last Reported At|Reporter Phishme Reports Count|Reporter Reports Count|Reporter Updated At|Reporter Vip|Rules|Sha256|Suspect Received At|Updated At|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|\n" "| 3887 | 2020-08-26T15:13:30.920Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | {'url': 'https://example.com/url1.png'},<br>{'url': 'https://example.com/url2.png'},<br>{'url': 'https://example.com/url3.png'} | 13461 | Inbox | 1 | 555 | Report body 1 | Date: Wed, 26 Aug 2020 15:13:30 +0000<br>Subject: Report subject 1<br>Mime-Version: 1.0<br>Content-Type: multipart/mixed;<br>charset=UTF-8<br>Content-Transfer-Encoding: 7bit | Report subject 1 aaa | 2020-08-26T14:36:43.000Z | 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 0 | 3 | 2019-04-12T02:59:22.287Z | false | {'id': 6417, 'name': 'Triage_rule_1', 'reports_count': 67, 'active': True, 'created_at': '2019-04-11T17:15:53.940Z', 'updated_at': '2019-04-11T17:15:53.940Z', 'priority': 1, 'author_name': 'Cofense'} | 555555 | 2020-08-26T14:36:51.000Z | 2020-08-26T15:13:35.200Z |\n" # noqa: E501 "| 3884 | 2020-08-24T16:43:04.412Z | | {'url': 'https://example.com/url1.png'},<br>{'url': 'https://example.com/url2.png'},<br>{'url': 'https://example.com/url3.png'} | 13458 | Inbox | 1 | 555 | Report body 3 | Date: Wed, 26 Aug 2020 15:13:30 +0000<br>Subject: Report subject 3<br>Mime-Version: 1.0<br>Content-Type: multipart/mixed;<br>charset=UTF-8<br>Content-Transfer-Encoding: 7bit | Report subject 3 aaa | 2020-08-24T16:15:52.000Z | 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 0 | 3 | 2019-04-12T02:59:22.287Z | false | {'id': 667, 'name': 'Triage_rule_1', 'reports_count': 41, 'active': True, 'created_at': '2019-04-11T16:46:11.078Z', 'updated_at': '2019-04-11T16:46:11.078Z', 'priority': 1, 'author_name': 'Cofense'} | 555555 | 2020-08-24T16:21:07.000Z | 2020-08-24T16:43:05.946Z |\n" # noqa: E501 ) ) @freeze_time("2000-10-31") def test_search_inbox_reports_command_with_reporter(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("subject", "aaa") set_demisto_arg("url", "") set_demisto_arg("file_hash", "") set_demisto_arg("reporter", "reporter2") set_demisto_arg("max_matches", 10) requests_mock.get( "https://some-triage-host/api/public/v1/inbox_reports?start_date=2000-10-24+00%3A00%3A00%2B00%3A00&page=0", # noqa: E501 text=fixture_from_file("inbox_reports.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters?email=reporter2&page=0", text=fixture_from_file("reporters_by_email_reporter2.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/222", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.search_inbox_reports_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert ( demisto_results[0]["HumanReadable"] == ( "### Reports:\n" "|Cluster Id|Created At|Email Attachments|Email Urls|Id|Location|Match Priority|Md5|Report Body|Report Headers|Report Subject|Reported At|Reporter Created At|Reporter Credibility Score|Reporter Email|Reporter Id|Reporter Last Reported At|Reporter Phishme Reports Count|Reporter Reports Count|Reporter Updated At|Reporter Vip|Rules|Sha256|Suspect Received At|Updated At|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|\n" "| 3887 | 2020-08-26T15:13:30.920Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | {'url': 'https://example.com/url1.png'},<br>{'url': 'https://example.com/url2.png'},<br>{'url': 'https://example.com/url3.png'} | 13461 | Inbox | 1 | 555 | Report body 1 | Date: Wed, 26 Aug 2020 15:13:30 +0000<br>Subject: Report subject 1<br>Mime-Version: 1.0<br>Content-Type: multipart/mixed;<br>charset=UTF-8<br>Content-Transfer-Encoding: 7bit | Report subject 1 aaa | 2020-08-26T14:36:43.000Z | 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 0 | 3 | 2019-04-12T02:59:22.287Z | false | {'id': 6417, 'name': 'Triage_rule_1', 'reports_count': 67, 'active': True, 'created_at': '2019-04-11T17:15:53.940Z', 'updated_at': '2019-04-11T17:15:53.940Z', 'priority': 1, 'author_name': 'Cofense'} | 555555 | 2020-08-26T14:36:51.000Z | 2020-08-26T15:13:35.200Z |\n" # noqa: E501 "| 3884 | 2020-08-24T16:43:04.412Z | | {'url': 'https://example.com/url1.png'},<br>{'url': 'https://example.com/url2.png'},<br>{'url': 'https://example.com/url3.png'} | 13458 | Inbox | 1 | 555 | Report body 3 | Date: Wed, 26 Aug 2020 15:13:30 +0000<br>Subject: Report subject 3<br>Mime-Version: 1.0<br>Content-Type: multipart/mixed;<br>charset=UTF-8<br>Content-Transfer-Encoding: 7bit | Report subject 3 aaa | 2020-08-24T16:15:52.000Z | 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 0 | 3 | 2019-04-12T02:59:22.287Z | false | {'id': 667, 'name': 'Triage_rule_1', 'reports_count': 41, 'active': True, 'created_at': '2019-04-11T16:46:11.078Z', 'updated_at': '2019-04-11T16:46:11.078Z', 'priority': 1, 'author_name': 'Cofense'} | 555555 | 2020-08-24T16:21:07.000Z | 2020-08-24T16:43:05.946Z |\n" # noqa: E501 ) ) @freeze_time("2000-10-31") def test_search_inbox_reports_command_with_file_hash(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("subject", "aaa") set_demisto_arg("url", "") set_demisto_arg("file_hash", "1234") set_demisto_arg("reporter", "") set_demisto_arg("max_matches", 10) requests_mock.get( "https://some-triage-host/api/public/v1/inbox_reports?start_date=2000-10-24+00%3A00%3A00%2B00%3A00&page=0", # noqa: E501 text=fixture_from_file("inbox_reports.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/222", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.search_inbox_reports_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert ( demisto_results[0]["HumanReadable"] == ( "### Reports:\n" "|Cluster Id|Created At|Email Attachments|Email Urls|Id|Location|Match Priority|Md5|Report Body|Report Headers|Report Subject|Reported At|Reporter Created At|Reporter Credibility Score|Reporter Email|Reporter Id|Reporter Last Reported At|Reporter Phishme Reports Count|Reporter Reports Count|Reporter Updated At|Reporter Vip|Rules|Sha256|Suspect Received At|Updated At|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|\n" "| 3887 | 2020-08-26T15:13:30.920Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | {'url': 'https://example.com/url1.png'},<br>{'url': 'https://example.com/url2.png'},<br>{'url': 'https://example.com/url3.png'} | 13461 | Inbox | 1 | 555 | Report body 1 | Date: Wed, 26 Aug 2020 15:13:30 +0000<br>Subject: Report subject 1<br>Mime-Version: 1.0<br>Content-Type: multipart/mixed;<br>charset=UTF-8<br>Content-Transfer-Encoding: 7bit | Report subject 1 aaa | 2020-08-26T14:36:43.000Z | 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 0 | 3 | 2019-04-12T02:59:22.287Z | false | {'id': 6417, 'name': 'Triage_rule_1', 'reports_count': 67, 'active': True, 'created_at': '2019-04-11T17:15:53.940Z', 'updated_at': '2019-04-11T17:15:53.940Z', 'priority': 1, 'author_name': 'Cofense'} | 555555 | 2020-08-26T14:36:51.000Z | 2020-08-26T15:13:35.200Z |\n" # noqa: E501 ) ) @freeze_time("2000-10-31") def test_search_inbox_reports_command_with_max_matches(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("subject", "aaa") set_demisto_arg("url", "") set_demisto_arg("file_hash", "") set_demisto_arg("reporter", "reporter2") set_demisto_arg("max_matches", 1) requests_mock.get( "https://some-triage-host/api/public/v1/inbox_reports?start_date=2000-10-24+00%3A00%3A00%2B00%3A00&page=0", # noqa: E501 text=fixture_from_file("inbox_reports.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters?email=reporter2&page=0", text=fixture_from_file("reporters_by_email_reporter2.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/222", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.search_inbox_reports_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert ( demisto_results[0]["HumanReadable"] == ( "### Reports:\n" "|Cluster Id|Created At|Email Attachments|Email Urls|Id|Location|Match Priority|Md5|Report Body|Report Headers|Report Subject|Reported At|Reporter Created At|Reporter Credibility Score|Reporter Email|Reporter Id|Reporter Last Reported At|Reporter Phishme Reports Count|Reporter Reports Count|Reporter Updated At|Reporter Vip|Rules|Sha256|Suspect Received At|Updated At|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|\n" "| 3887 | 2020-08-26T15:13:30.920Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | {'url': 'https://example.com/url1.png'},<br>{'url': 'https://example.com/url2.png'},<br>{'url': 'https://example.com/url3.png'} | 13461 | Inbox | 1 | 555 | Report body 1 | Date: Wed, 26 Aug 2020 15:13:30 +0000<br>Subject: Report subject 1<br>Mime-Version: 1.0<br>Content-Type: multipart/mixed;<br>charset=UTF-8<br>Content-Transfer-Encoding: 7bit | Report subject 1 aaa | 2020-08-26T14:36:43.000Z | 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 0 | 3 | 2019-04-12T02:59:22.287Z | false | {'id': 6417, 'name': 'Triage_rule_1', 'reports_count': 67, 'active': True, 'created_at': '2019-04-11T17:15:53.940Z', 'updated_at': '2019-04-11T17:15:53.940Z', 'priority': 1, 'author_name': 'Cofense'} | 555555 | 2020-08-26T14:36:51.000Z | 2020-08-26T15:13:35.200Z |\n" # noqa: E501 ) ) def test_get_attachment_command(self, mocker, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("attachment_id", "5") set_demisto_arg("file_name", "my_great_file") requests_mock.get( "https://some-triage-host/api/public/v1/attachment/5", text=fixture_from_file("attachment.txt"), ) CofenseTriagev2.get_attachment_command(triage_instance) CofenseTriagev2.get_attachment_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert demisto_results[0]["FileID"] == "/path/to/temp/file" assert demisto_results[0]["File"] == "my_great_file" def test_get_reporter_command(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("reporter_id", "5") requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.get_reporter_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert demisto_results[0]["HumanReadable"] == ( "### Reporter Results:\n" "|Created At|Credibility Score|Email|Id|Last Reported At|Reports Count|Updated At|Vip|\n" "|---|---|---|---|---|---|---|---|\n" "| 2019-04-12T02:58:17.401Z | 0 | reporter1@example.com | 111 | 2016-02-18T00:24:45.000Z | 3 | 2019-04-12T02:59:22.287Z | false |\n" # noqa: E501 ) assert demisto_results[0]["EntryContext"] == { "Cofense.Reporter(val.Id && val.Id == obj.Id)": { "ID": 111, "Email": "reporter1@example.com", "CreatedAt": "2019-04-12T02:58:17.401Z", "UpdatedAt": "2019-04-12T02:59:22.287Z", "CredibilityScore": 0, "ReportsCount": 3, "LastReportedAt": "2016-02-18T00:24:45.000Z", "Vip": False, } } def test_get_report_by_id_command(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("report_id", "6") set_demisto_arg("verbose", "false") requests_mock.get( "https://some-triage-host/api/public/v1/reports/6", text=fixture_from_file("single_report.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5331", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.get_report_by_id_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert ( demisto_results[0]["HumanReadable"] == ( "### Report Summary:\n" "|Category Id|Created At|Email Attachments|Id|Location|Match Priority|Md5|Report Body|Report Subject|Reported At|Reporter Id|Sha256|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|---|\n" "| 7 | 2020-03-19T16:43:09.715Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | 13363 | Processed | 1 | 111 | From: Sender <sender@example.com><br>Reply-To: \"sender@example.com\" <sender@example.com><br>Date: Wednesday, March 18, 2020 at 3:34 PM<br>To: recipient@example.com<br>Subject: suspicious subject<br>click on this link! trust me! <a href=\"http://example.com/malicious\">here</a> | suspicious subject | 2020-03-19T16:42:22.000Z | 5331 | 222 |\n" # noqa: E501 ) ) def test_get_report_by_id_command_with_attachment(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("report_id", "6") set_demisto_arg("verbose", "false") requests_mock.get( "https://some-triage-host/api/public/v1/reports/6", text=fixture_from_file("single_report_with_attachment.json"), ) requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5331", text=fixture_from_file("reporters.json"), ) CofenseTriagev2.get_report_by_id_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list assert demisto_results[0][0][0]["HumanReadable"] == ( "### Cofense HTML Report:\nHTML report download request has been completed" ) assert ( demisto_results[1][0][0]["HumanReadable"] == ( "### Report Summary:\n" "|Category Id|Created At|Email Attachments|Id|Location|Match Priority|Md5|Report Subject|Reported At|Reporter Id|Sha256|\n" # noqa: E501 "|---|---|---|---|---|---|---|---|---|---|---|\n" "| 7 | 2020-03-19T16:43:09.715Z | {'id': 18054, 'report_id': 13363, 'decoded_filename': 'image003.png', 'content_type': 'image/png; name=image003.png', 'size_in_bytes': 7286, 'email_attachment_payload': {'id': 7082, 'md5': '123', 'sha256': '1234', 'mime_type': 'image/png; charset=binary'}} | 13363 | Processed | 1 | 111 | suspicious subject | 2020-03-19T16:42:22.000Z | 5331 | 222 |\n" # noqa: E501 ) ) def test_get_all_reporters(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reporters?start_date=1995-01-01", text=fixture_from_file("reporters.json"), ) reporters = CofenseTriagev2.get_all_reporters(triage_instance, "1995-01-01") assert reporters == [ "reporter1@example.com", "reporter2@example.com", ] def test_get_threat_indicators_command(self, requests_mock, triage_instance, fixture_from_file): set_demisto_arg("type", "what") set_demisto_arg("level", "what") set_demisto_arg("start_date", "what") set_demisto_arg("end_date", "what") set_demisto_arg("page", "what") set_demisto_arg("per_page", "what") requests_mock.get( "https://some-triage-host/api/public/v1/triage_threat_indicators?type=what&level=what&start_date=what&end_date=what&page=what&per_page=what", # noqa: E501 text=fixture_from_file("threat_indicators.json"), ) CofenseTriagev2.get_threat_indicators_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert demisto_results[0]["HumanReadable"] == ( "### Threat Indicators:\n" "|Created At|Id|Operator Id|Report Id|Threat Key|Threat Level|Threat Value|\n" "|---|---|---|---|---|---|---|\n" "| 2020-03-16T17:39:14.579Z | 37 | 2 | 13353 | Domain | Malicious | malicious.example.com |\n" ) def test_get_threat_indicators_command_not_found(self, requests_mock, triage_instance): set_demisto_arg("type", "what") set_demisto_arg("level", "what") set_demisto_arg("start_date", "what") set_demisto_arg("end_date", "what") set_demisto_arg("page", "what") set_demisto_arg("per_page", "what") requests_mock.get( "https://some-triage-host/api/public/v1/triage_threat_indicators?type=what&level=what&start_date=what&end_date=what&page=what&per_page=what", # noqa: E501 text="[]", ) CofenseTriagev2.get_threat_indicators_command(triage_instance) demisto_results = CofenseTriagev2.demisto.results.call_args_list[0][0] assert len(demisto_results) == 1 assert demisto_results[0]["HumanReadable"] == ("no results were found.") class TestTriageInstance: def test_request(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports", text=fixture_from_file("processed_reports.json"), ) requests = triage_instance.request("processed_reports") assert len(requests) == 2 assert requests[0]["report_subject"] == "suspicious subject" def test_request_unsuccessful(self, mocker, requests_mock, triage_instance): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports", status_code=403, text="a bad error", ) with pytest.raises(TriageRequestFailedError) as e: triage_instance.request("processed_reports") assert e.message == "Call to Cofense Triage failed (403): a bad error" def test_request_raw(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports", text=fixture_from_file("processed_reports.json"), ) response = triage_instance.request("processed_reports", raw_response=True) assert response.__class__.__name__ == "Response" def test_request_empty(self, requests_mock, triage_instance): requests_mock.get("https://some-triage-host/api/public/v1/processed_reports", text="[]") assert triage_instance.request("processed_reports") == {} def test_request_malformed_json(self, mocker, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/processed_reports", text=fixture_from_file("malformed_json.not_json"), ) with pytest.raises(TriageRequestFailedError) as e: triage_instance.request("processed_reports") assert e.message == "Could not parse result from Cofense Triage (200)" def test_api_url(self, triage_instance): assert triage_instance.api_url("endpoint") == "https://some-triage-host/api/public/v1/endpoint" assert triage_instance.api_url("/endpoint") == "https://some-triage-host/api/public/v1/endpoint" assert ( triage_instance.api_url("///endpoint/edit?query_string&") == "https://some-triage-host/api/public/v1/endpoint/edit?query_string&" ) # noqa 501 class TestTriageInboxReports: def test_inbox_reports(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/inbox_reports?page=0", text=fixture_from_file("inbox_reports.json"), ) reports = TriageInboxReports(triage_instance).inbox_reports() assert len(reports) == 3 assert reports[0].id == 13461 assert reports[2].date == "2020-08-24T16:43:04.412Z" def test_inbox_reports_with_filter(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/inbox_reports?page=0", text=fixture_from_file("inbox_reports.json"), ) reports = TriageInboxReports(triage_instance, filter_params={"subject": "aaa"}).inbox_reports() assert [report.report_subject for report in reports] == [ "Report subject 1 aaa", "Report subject 3 aaa", ] class TestTriageReport: def test_attrs(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reports/6", text=fixture_from_file("single_report.json"), ) report = TriageReport.fetch(triage_instance, "6") assert len(report.attrs) == 25 assert report.id == 13363 assert report.date == "2020-03-19T16:43:09.715Z" def test_reporter(self, mocker, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reports/6", text=fixture_from_file("single_report.json"), ) stubbed_triagereporter_init = mocker.patch("CofenseTriagev2.TriageReporter") TriageReport.fetch(triage_instance, "6").reporter # noqa: B018 stubbed_triagereporter_init.assert_called_once_with(triage_instance, 5331) def test_attachment_none(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reports/6", text=fixture_from_file("single_report.json"), ) report = TriageReport.fetch(triage_instance, "6") assert report.attachment is None def test_attachment_present(self, mocker, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reports/6", text=fixture_from_file("single_report_with_attachment.json"), ) report = TriageReport.fetch(triage_instance, "6") attachment = report.attachment assert attachment == {"path": "/path/to/temp/file", "name": "13363-report.html"} class TestTriageReporter: def test_init(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5", text=fixture_from_file("reporters.json"), ) reporter = TriageReporter(triage_instance, 5) assert reporter.attrs["email"] == "reporter1@example.com" def test_exists(self, requests_mock, triage_instance, fixture_from_file): requests_mock.get( "https://some-triage-host/api/public/v1/reporters/5", text=fixture_from_file("reporters.json"), ) requests_mock.get("https://some-triage-host/api/public/v1/reporters/6", text="[]") assert TriageReporter(triage_instance, 5).exists() is True assert TriageReporter(triage_instance, 6).exists() is False