GCenter

This integration allows, via about twenty commands, to interact with the GCenter appliance via its API.

Network Security · Gatewatcher AionIQ

Details

IDGCenter
ProviderGatewatcher
CategoryNetwork Security
From Version6.2.0
Docker Imagedemisto/python3:3.12.8.3296088
Supported ModulesAgentix XSIAM

README

This integration allows, via about twenty commands, to interact with the GCenter appliance via its API.
This integration was integrated and tested with version v2.5.3.102 of GCenter.
To simplify GCenter v2.5.3.102 is called GCenter in the Pack.

Configure GCenter in Cortex

Parameter Description Required
GCenter IP address   True
GCenter Version   False
GCenter API token You must provide either an API token or a username and a password. False
GCenter username   False
GCenter password   False
Check the TLS certificate   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

gw-get-alert


Get an alert by it’s uid

Base Command

gw-get-alert

Input

Argument Name Description Required
uid Alert identifier. Required

Context Output

Path Type Description
GCenter.Alert.Single.sha256 String The 256 Shasum Of The File
GCenter.Alert.Single.id String The Id Of The Inspectra Alert
GCenter.Alert.Single.flow_id Number The Flow Id Of The Alert
GCenter.Alert.Single.severity Number The Severity Of The Alert
GCenter.Alert.Single.src_ip String The Ip Address Of The Alert’S Source
GCenter.Alert.Single.dest_ip String The Ip Address Of The Alert’S Target
GCenter.Alert.Single.src_port Number The Port Of The Alert’S Source
GCenter.Alert.Single.dest_port Number The Port Of The Alert’S Target
GCenter.Alert.Single.gcap String The Gcap That Raised The Alert
GCenter.Alert.Single.type String Which Type Of Alert (Sigflow, Codebreaker…)
GCenter.Alert.Single.proto String The Protocol Used
GCenter.Alert.Single.host String The Host Where The Alert Was Found
GCenter.Alert.Single.app_proto String The Malware Application Prototype
GCenter.Alert.Single.alert_type String Which Event It Is ?
GCenter.Alert.Single.state String The State Of The Alert
GCenter.Alert.Single.matched_event String Value Of The Id Of An Other Alert That Matched (Allows The Correlation Between Alerts)
GCenter.Alert.Single.domain_name String For Dga Alerts Only
GCenter.Alert.Single.probability Number The Severity Probability
GCenter.Alert.Single.timestamp_detected Date When The Alert Was Detected
GCenter.Alert.Single.timestamp_analyzed Date When The Alert Was Analysed
GCenter.Alert.Single.retrohunt.timestamp_package String Utc Date When The Ioc Was Added To The Lastinfosec Update Package
GCenter.Alert.Single.retrohunt.ioc_creation_date Date The Ioc Creation Date
GCenter.Alert.Single.retrohunt.ioc_updated_date Date The Ioc Updated Date
GCenter.Alert.Single.retrohunt.description String The Alert Description
GCenter.Alert.Single.retrohunt.ioc_type String Host, Md5, Sha1, Sha256, Url
GCenter.Alert.Single.retrohunt.ioc_value String Characteristic Value Of The Ioc
GCenter.Alert.Single.retrohunt.matched_app_proto String The Sigflow Protocol That Contains This Ioc
GCenter.Alert.Single.retrohunt.matched_event_type String The Sigflow Event Type That Contains This Ioc
GCenter.Alert.Single.retrohunt.case_id String Uuid Of The Box To Which The Ioc Belongs
GCenter.Alert.Single.retrohunt.ioc_id String Uuid Of The Ioc
GCenter.Alert.Single.retrohunt.risk String Suspicious, High Suspicious, Malicious
GCenter.Alert.Single.retrohunt.usage_mode String Usage Mode
GCenter.Alert.Single.retrohunt.tlp String Tlp
GCenter.Alert.Single.powershell.file_id String The File Id
GCenter.Alert.Single.powershell.scores.proba_obfuscated Number The Probability It Is Obfuscated
GCenter.Alert.Single.powershell.scores.analysis Number The Powershell Analysis Score
GCenter.Alert.Single.shellcode.file_id String The File Id
GCenter.Alert.Single.shellcode.encodings.name String The Name Of The Encoding
GCenter.Alert.Single.shellcode.encodings.count Number The Number Of The Encoding Elements
GCenter.Alert.Single.shellcode.calls.call String The Name Of The Call Of The Alert
GCenter.Alert.Single.shellcode.calls.args String The Argument Used For The Call
GCenter.Alert.Single.shellcode.calls.ret String The Retention Of The Call
GCenter.Alert.Single.shellcode.calls.index Number The Call Index
GCenter.Alert.Single.malware.analyzed_clean Number Number Of Engines That Returned A Clean Status
GCenter.Alert.Single.malware.analyzed_infected Number Number Of Engines That Returned An Infected Status
GCenter.Alert.Single.malware.analyzed_suspicious Number Number Of Engines That Returned A Suspicious Status
GCenter.Alert.Single.malware.analyzed_other Number Number Of Engines That Returned Other Statuses
GCenter.Alert.Single.malware.analyzed_error Number Number Of Engines That Failed To Analyze The File
GCenter.Alert.Single.malware.code Number The Global Code Result
GCenter.Alert.Single.malware.def_time Date When The Last Engines Have Ended The Scan
GCenter.Alert.Single.malware.scan_time Number The Scan Time In Ms.
GCenter.Alert.Single.malware.threats_found String The Threats Found By The Engines
GCenter.Alert.Single.malware.reporting_token String The Reporting Token Returned By The Gbox.
GCenter.Alert.Single.malware.engines_report.0.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.0.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.0.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.1.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.1.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.1.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.2.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.2.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.2.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.3.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.3.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.3.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.4.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.4.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.4.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.5.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.5.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.5.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.6.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.6.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.6.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.7.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.7.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.7.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.8.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.8.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.8.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.9.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.9.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.9.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.10.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.10.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.10.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.11.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.11.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.11.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.12.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.12.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.12.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.13.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.13.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.13.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.14.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.14.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.14.scan_result String Analysis Result
GCenter.Alert.Single.malware.engines_report.15.id String The Hash Pf The Engine
GCenter.Alert.Single.malware.engines_report.15.threat_details String The Threat Found By The Engine
GCenter.Alert.Single.malware.engines_report.15.scan_result String Analysis Result
GCenter.Alert.Single.malware.magic_details String The File Magic
GCenter.Alert.Single.malware.total_found String The Malcore Number Of Engines That Found The File Suspicious / The Total Number Of Engines
GCenter.Alert.Single.sigflow.alert.action String Action
GCenter.Alert.Single.sigflow.alert.signature_id String Signature Id
GCenter.Alert.Single.sigflow.alert.gid String Gid
GCenter.Alert.Single.sigflow.alert.category String Category
GCenter.Alert.Single.sigflow.packet String Packet
GCenter.Alert.Single.sigflow.in_iface String In Which Interface The Alert Occurred
GCenter.Alert.Single.sigflow.stream Number Is It Streaming (!= 0)
GCenter.Alert.Single.sigflow.payload String Payload
GCenter.Alert.Single.sigflow.payload_printable String Payload Printable
Command Example

!gw-get-alert uid="d7e612cb-567a-431b-a14b-9f9f4e88c9a4"

Context Example
{
    "sha256": "f16d19ac9697d9892b0f910601a61d041d64",
    "id": "45e6ed3c-1082-4d33-9514-162748d7d41f",
    "flow_id": 1544096072809159,
    "severity": 1,
    "src_ip": "192.168.0.2",
    "dest_ip": "192.168.0.1",
    "src_port": 80,
    "dest_port": 35168,
    "gcap": "test.domain.com",
    "type": "malcore",
    "proto": "TCP",
    "host": "test.domain.com",
    "app_proto": "http",
    "alert_type": "malware",
    "state": "Infected",
    "matched_event": "3d35e491-cfc8-4271-815b-ff018a036c7c",
    "domain_name": "nzpzxcox.com",
    "probability": 0.55555555,
    "timestamp_detected": "2022-03-21T11:34:47.000Z",
    "timestamp_analyzed": "2022-03-21T13:58:42.742Z",
    "dest_geoip": {},
    "src_geoip": {},
    "retrohunt": {
        "timestamp_package": "2022-06-06T22:00:01.632829+0000",
        "ioc_creation_date": "2022-05-27T18:37:30+00:00",
        "ioc_updated_date": "2022-06-06T21:05:12+00:00",
        "description": "'test.domain.com' is a Suspicious Host.",
        "ioc_type": "Host",
        "ioc_value": "test.domain.com",
        "matched_app_proto": "http",
        "matched_event_type": "http",
        "meta_data": {},
        "targeted_organizations": [],
        "targeted_platforms": [],
        "targeted_sectors": [],
        "threat_actor": [],
        "external_links": [],
        "relations": [],
        "campaigns": [],
        "categories": [],
        "families": [],
        "vulnerabilities": [],
        "ttp": [],
        "case_id": "1746d38d-58f3-4b43-b4ee-6f0b43527d49",
        "ioc_id": "183abf8e-b0a5-4ed0-a93f-e5d7927648b8",
        "risk": "Suspicious",
        "usage_mode": "hunting",
        "tlp": "green"
    },
    "powershell": {
        "file_id": "06-08-2022T11:37:11_1348935773_gcap-dean.org",
        "scores": {
            "proba_obfuscated": 0.2,
            "analysis": 241,
            "analysis_detailed": {}
        }
    },
    "shellcode": {
        "file_id": "file_id",
        "encodings": [
            {
                "name": "Bloxor",
                "count": 2
            }
        ],
        "calls": [
            {
                "call": "ws2_32_recv",
                "args": "{'sockfd': 'Socket_1-bind (4)', 'backlog': 19103712}",
                "ret": "90137289",
                "index": 0
            }
        ]
    },
    "malware": {
        "analyzed_clean": 11,
        "analyzed_infected": 5,
        "analyzed_suspicious": 0,
        "analyzed_other": 0,
        "analyzed_error": 0,
        "code": 1,
        "def_time": "2022-05-31T21:45:33Z",
        "scan_time": 3785,
        "threats_found": "Infected : Gen:Variant.Ulise.315566 (B)",
        "reporting_token": "No GBOX",
        "engines_report": {
            "0": {
                "id": "XXX",
                "threat_details": "Gen:Variant.Ulise.315566 (B)",
                "scan_result": "INFECTED"
            },
            "1": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "2": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "3": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "4": {
                "id": "XXX",
                "threat_details": "WinGo/TrojanDownloader.Agent.BD trojan",
                "scan_result": "INFECTED"
            },
            "5": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "6": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "7": {
                "id": "XXX",
                "threat_details": "Trojan.Donut.Win64.545",
                "scan_result": "INFECTED"
            },
            "8": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "9": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "10": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "11": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "12": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "13": {
                "id": "XXX",
                "threat_details": "",
                "scan_result": "CLEAN"
            },
            "14": {
                "id": "XXX",
                "threat_details": "W64/Donut.B.gen!Eldorado",
                "scan_result": "INFECTED"
            },
            "15": {
                "id": "XXX",
                "threat_details": "Trojan.Win64.Crypt",
                "scan_result": "INFECTED"
            }
        },
        "magic_details": "PE32+ executable (DLL) (GUI) x86-64, for MS Windows",
        "total_found": "5/16"
    },
    "sigflow": {
        "alert": {
            "action": "allowed",
            "signature_id": "202",
            "gid": "1",
            "category": "A Network Trojan was detected"
        },
        "packet": "XXXXXXXXXXXXXXXXXX",
        "in_iface": "mon5",
        "stream": 0,
        "payload": "XXXXXXXXXXXXXXXXXX",
        "payload_printable": "XXXXXXXXXXXXXXXXXX",
        "extra_keys": {}
    }
}
Human Readable Output

Elasticsearch alert entry

alert_type app_proto dest_geoip dest_ip dest_port domain_name flow_id gcap host id malware matched_event powershell probability proto retrohunt severity sha256 shellcode sigflow src_geoip src_ip src_port state timestamp_analyzed timestamp_detected type
malware http   192.168.0.1 35168 nzpzxcox.com 1544096072809159 test.domain.com test.domain.com 45e6ed3c-1082-4d33-9514-162748d7d41f analyzed_clean: 11
analyzed_infected: 5
analyzed_suspicious: 0
analyzed_other: 0
analyzed_error: 0
code: 1
def_time: 2022-05-31T21:45:33Z
scan_time: 3785
threats_found: Infected : Gen:Variant.Ulise.315566 (B)
reporting_token: No GBOX
engines_report: {“0”: {“id”: “XXX”, “threat_details”: “Gen:Variant.Ulise.315566 (B)”, “scan_result”: “INFECTED”}, “1”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “2”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “3”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “4”: {“id”: “XXX”, “threat_details”: “WinGo/TrojanDownloader.Agent.BD trojan”, “scan_result”: “INFECTED”}, “5”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “6”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “7”: {“id”: “XXX”, “threat_details”: “Trojan.Donut.Win64.545”, “scan_result”: “INFECTED”}, “8”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “9”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “10”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “11”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “12”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “13”: {“id”: “XXX”, “threat_details”: “”, “scan_result”: “CLEAN”}, “14”: {“id”: “XXX”, “threat_details”: “W64/Donut.B.gen!Eldorado”, “scan_result”: “INFECTED”}, “15”: {“id”: “XXX”, “threat_details”: “Trojan.Win64.Crypt”, “scan_result”: “INFECTED”}}
magic_details: PE32+ executable (DLL) (GUI) x86-64, for MS Windows
total_found: 5/16
3d35e491-cfc8-4271-815b-ff018a036c7c file_id: 06-08-2022T11:37:11_1348935773_gcap-dean.org
scores: {“proba_obfuscated”: 0.2, “analysis”: 241, “analysis_detailed”: {}}
0.55555555 TCP timestamp_package: 2022-06-06T22:00:01.632829+0000
ioc_creation_date: 2022-05-27T18:37:30+00:00
ioc_updated_date: 2022-06-06T21:05:12+00:00
description: ‘test.domain.com’ is a Suspicious Host.
ioc_type: Host
ioc_value: test.domain.com
matched_app_proto: http
matched_event_type: http
meta_data: {}
targeted_organizations:
targeted_platforms:
targeted_sectors:
threat_actor:
external_links:
relations:
campaigns:
categories:
families:
vulnerabilities:
ttp:
case_id: 1746d38d-58f3-4b43-b4ee-6f0b43527d49
ioc_id: 183abf8e-b0a5-4ed0-a93f-e5d7927648b8
risk: Suspicious
usage_mode: hunting
tlp: green
1 f16d19ac9697d9892b0f910601a61d041d64 file_id: file_id
encodings: {‘name’: ‘Bloxor’, ‘count’: 2}
calls: {‘call’: ‘ws2_32_recv’, ‘args’: “{‘sockfd’: ‘Socket_1-bind (4)’, ‘backlog’: 19103712}”, ‘ret’: ‘90137289’, ‘index’: 0}
alert: {“action”: “allowed”, “signature_id”: “202”, “gid”: “1”, “category”: “A Network Trojan was detected”}
packet: XXXXXXXXXXXXXXXXXX
in_iface: mon5
stream: 0
payload: XXXXXXXXXXXXXXXXXX
payload_printable: XXXXXXXXXXXXXXXXXX
extra_keys: {}
  192.168.0.2 80 Infected 2022-03-21T13:58:42.742Z 2022-03-21T11:34:47.000Z malcore

gw-es-query


Get Elasticsearch data

Base Command

gw-es-query

Input

Argument Name Description Required
index Index to be queried. Possible values are: suricata, malware, codebreaker, netdata, syslog, machine_learning, retrohunt, iocs. Default is suricata. Optional
query Elaticsearch query. Default is {}. Optional

Context Output

There is no context output for this command.

Command Example

!gw-es-query index="suricata" query="{}"

gw-add-malcore-list-entry


Add malcore whitelist/blacklist entry

Base Command

gw-add-malcore-list-entry

Input

Argument Name Description Required
type List type. Possible values are: white, black. Required
sha256 SHA256 to be added. Required
comment Comment to be added. Optional
threat Comment to be added. Optional

Context Output

Path Type Description
GCenter.Malcore.sha256 String Sha256
GCenter.Malcore.created Date Created
GCenter.Malcore.comment String Comment
GCenter.Malcore.threat String Name Of Threat For Reference
Command Example

!gw-add-malcore-list-entry type="white" sha256="d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351e"

Context Example
{
    "sha256": "d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351e",
    "created": "2022-03-21T16:36:58.957178Z",
    "comment": "test",
    "threat": "undefined"
}
Human Readable Output

Malcore whitelist/blacklist entry

comment created sha256 threat
test 2022-03-21T16:36:58.957178Z d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351e undefined

gw-del-malcore-list-entry


Delete malcore whitelist/blacklist entry

Base Command

gw-del-malcore-list-entry

Input

Argument Name Description Required
type List type. Possible values are: white, black. Required
sha256 SHA256 to be deleted. Required

Context Output

There is no context output for this command.

Command Example

!gw-del-malcore-list-entry type="white" sha256="d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351e"

gw-add-dga-list-entry


Add dga whitelist/blacklist entry

Base Command

gw-add-dga-list-entry

Input

Argument Name Description Required
type List type. Possible values are: white, black. Required
domain Domain name to be added. Required
comment Comment to be added. Optional

Context Output

Path Type Description
GCenter.Dga.domain_name String Domain Name
GCenter.Dga.created Date Created
GCenter.Dga.comment String Comment
GCenter.Dga.is_wildcard Boolean Is Wildcard
Command Example

!gw-add-dga-list-entry type="white" domain="test.domain.com"

Context Example
{
    "domain_name": "test.domain.com",
    "created": "2022-03-21T16:30:20.012035Z",
    "comment": "test",
    "is_wildcard": false
}
Human Readable Output

DGA whitelist/blacklist entry

comment created domain_name is_wildcard
test 2022-03-21T16:30:20.012035Z test.domain.com false

gw-del-dga-list-entry


Delete dga whitelist/blacklist entry

Base Command

gw-del-dga-list-entry

Input

Argument Name Description Required
type List type. Possible values are: white, black. Required
domain Domain name to be deleted. Required

Context Output

There is no context output for this command.

Command Example

!gw-del-dga-list-entry type="white" domain="test.domain.com"

gw-add-ignore-asset-name


Ignore asset name

Base Command

gw-add-ignore-asset-name

Input

Argument Name Description Required
name Name to be ignored. Required
start Will be ignored if they start with this name. Required
end Will be ignored if they end with this name. Required

Context Output

Path Type Description
GCenter.Ignore.AssetName.id String Id
GCenter.Ignore.AssetName.created_at Date Created At
GCenter.Ignore.AssetName.created_by String Created By
GCenter.Ignore.AssetName.name String Ignored Name For The Assets (Hostnames). Case Insensitive.
GCenter.Ignore.AssetName.is_startswith_pattern Boolean Should The Assets (Hostnames) Be Ignored If They Start With This Name ?
GCenter.Ignore.AssetName.is_endswith_pattern Boolean Should The Assets (Hostnames) Be Ignored If They End With This Name ?
Command Example

!gw-add-ignore-asset-name name="test_asset"

Context Example
{
    "id": "1",
    "created_at": "2022-03-21T16:37:54.657263Z",
    "created_by": "admin",
    "name": "test_asset",
    "is_startswith_pattern": true,
    "is_endswith_pattern": false
}
Human Readable Output

Asset name entry

created_at created_by id is_endswith_pattern is_startswith_pattern name
2022-03-21T16:37:54.657263Z admin 1 false true test_asset

gw-add-ignore-kuser-ip


Ignore kuser IP

Base Command

gw-add-ignore-kuser-ip

Input

Argument Name Description Required
ip IP to be ignored. Required

Context Output

Path Type Description
GCenter.Ignore.KuserIP.id String Id
GCenter.Ignore.KuserIP.created_at Date Created At
GCenter.Ignore.KuserIP.created_by String Created By
GCenter.Ignore.KuserIP.ip String Ignored Ip For The Kerberos Users
Command Example

!gw-add-ignore-kuser-ip ip="10.10.10.0"

Context Example
{
    "id": "2",
    "created_at": "2022-03-21T16:38:35.484082Z",
    "created_by": "admin",
    "ip": "10.10.10.0"
}
Human Readable Output

Kuser IP entry

created_at created_by id ip
2022-03-21T16:38:35.484082Z admin 2 10.10.10.0

gw-add-ignore-kuser-name


Ignore kuser name

Base Command

gw-add-ignore-kuser-name

Input

Argument Name Description Required
name Name to be ignored. Required
start Will be ignored if they start with this name. Required
end Will be ignored if they end with this name. Required

Context Output

Path Type Description
GCenter.Ignore.KuserName.id String Id
GCenter.Ignore.KuserName.created_at Date Created At
GCenter.Ignore.KuserName.created_by String Created By
GCenter.Ignore.KuserName.name String Ignored Name For The Kerberos Users. Case Insensitive.
GCenter.Ignore.KuserName.is_startswith_pattern Boolean Should The Kerberos Users Be Ignored If They Start With This Name ?
GCenter.Ignore.KuserName.is_endswith_pattern Boolean Should The Kerberos Users Be Ignored If They End With This Name ?
Command Example

!gw-add-ignore-kuser-name name="test_kuser"

Context Example
{
    "id": "1",
    "created_at": "2022-03-21T16:39:18.435420Z",
    "created_by": "admin",
    "name": "test_kuser",
    "is_startswith_pattern": true,
    "is_endswith_pattern": false
}
Human Readable Output

Kuser name entry

created_at created_by id is_endswith_pattern is_startswith_pattern name
2022-03-21T16:39:18.435420Z admin 1 false true test_kuser

gw-add-ignore-mac-address


Ignore mac address

Base Command

gw-add-ignore-mac-address

Input

Argument Name Description Required
mac MAC address to be ignored. Required
start Will be ignored if they start with this name. Required

Context Output

Path Type Description
GCenter.Ignore.MacAddress.id String Id
GCenter.Ignore.MacAddress.created_at Date Created At
GCenter.Ignore.MacAddress.created_by String Created By
GCenter.Ignore.MacAddress.address String Address
GCenter.Ignore.MacAddress.is_startswith_pattern Boolean Should The Mac Addresses Be Ignored If They Start With This Address Value ?
Command Example

!gw-add-ignore-mac-address mac="50:50:50:50:50:50"

Context Example
{
    "id": "1",
    "created_at": "2022-03-21T16:39:48.363094Z",
    "created_by": "admin",
    "address": "00:50:50:50:50:50",
    "is_startswith_pattern": true
}
Human Readable Output

MAC adrress entry

address created_at created_by id is_startswith_pattern
00:50:50:50:50:50 2022-03-21T16:39:48.363094Z admin 1 true

gw-del-ignore-asset-name


Delete an ignore asset ID

Base Command

gw-del-ignore-asset-name

Input

Argument Name Description Required
ignore_id Ignore asset ID. Required

Context Output

There is no context output for this command.

Command Example

!gw-del-ignore-asset-name ignore_id=1

gw-del-ignore-kuser-ip


Delete an ignore kuser IP ID

Base Command

gw-del-ignore-kuser-ip

Input

Argument Name Description Required
ignore_id Ignore kuser IP ID. Required

Context Output

There is no context output for this command.

Command Example

!gw-del-ignore-kuser-ip ignore_id=1

gw-del-ignore-kuser-name


Delete an ignore kuser name ID

Base Command

gw-del-ignore-kuser-name

Input

Argument Name Description Required
ignore_id Ignore kuser name ID. Required

Context Output

There is no context output for this command.

Command Example

!gw-del-ignore-kuser-name ignore_id=1

gw-del-ignore-mac-address


Delete an ignore mac address ID

Base Command

gw-del-ignore-mac-address

Input

Argument Name Description Required
ignore_id Ignore mac address ID. Required

Context Output

There is no context output for this command.

Command Example

!gw-del-ignore-mac-address ignore_id=1

gw-send-malware


Send malware

Base Command

gw-send-malware

Input

Argument Name Description Required
filename Filename. Required
file_id File entry id. Required

Context Output

Path Type Description
GCenter.Gscan.Malware.id String The Id Of The Gscan History Message
GCenter.Gscan.Malware.created Date Date Of Creation
GCenter.Gscan.Malware.username String The User’S Username Who Uploaded The File
GCenter.Gscan.Malware.user_agent String The Client’S User-Agent
GCenter.Gscan.Malware.ip_address String The Ip Address Of The User Who Uploaded The File
GCenter.Gscan.Malware.file_name String Original File Name
GCenter.Gscan.Malware.sha256 String Sha256
GCenter.Gscan.Malware.is_clean Unknown Clean
GCenter.Gscan.Malware.is_analysis_successful Boolean Scan Succes
GCenter.Gscan.Malware.malcore_code_result String Malcore Code Result
GCenter.Gscan.Malware.threat_name String Threat Name
GCenter.Gscan.Malware.nb_alerts Number Number Or Malcore Alerts
GCenter.Gscan.Malware.nb_engines Number Number Or Malcore Engines
GCenter.Gscan.Malware.is_whiteblack_listed Boolean Is White Or Black Listed?
GCenter.Gscan.Malware.malcore_code_result_name String Malcore Code Result Name
GCenter.Gscan.Malware.status String The Malcore Status
Command Example

!gw-send-malware filename="test" file_id="331@dfca9ea2-5198-4d64-8c36-5282ac3b2dc5"

Context Example
{
    "id": "1",
    "created": "2022-03-21T16:42:11.996076Z",
    "username": "admin",
    "user_agent": "Mozilla/5.0",
    "ip_address": "10.10.10.10",
    "file_name": "Arch.jpg",
    "sha256": "1a9487d49d842ebdee5ad870065eb74dc7044",
    "is_clean": null,
    "is_analysis_successful": false,
    "malcore_code_result": "5",
    "threat_name": "",
    "nb_alerts": 0,
    "nb_engines": 0,
    "is_whiteblack_listed": false,
    "malcore_code_result_name": "Unknown",
    "status": "Unknown"
}
Human Readable Output

Malcore analysis result

created file_name id ip_address is_analysis_successful is_clean is_whiteblack_listed malcore_code_result malcore_code_result_name nb_alerts nb_engines sha256 status threat_name user_agent username
2022-03-21T16:42:11.996076Z Arch.jpg 1 10.10.10.10 false   false 5 Unknown 0 0 1a9487d49d842ebdee5ad870065eb74dc7044 Unknown   Mozilla/5.0 admin

gw-send-powershell


Send powershell

Base Command

gw-send-powershell

Input

Argument Name Description Required
filename Filename. Required
file_id File entry id. Required

Context Output

Path Type Description
GCenter.Gscan.Powershell.id String The Id Of The Gscan History Message
GCenter.Gscan.Powershell.created Date Date Of Creation
GCenter.Gscan.Powershell.username String The User’S Username Who Uploaded The File
GCenter.Gscan.Powershell.user_agent String The Client’S User-Agent
GCenter.Gscan.Powershell.ip_address String The Ip Address Of The User Who Uploaded The File
GCenter.Gscan.Powershell.file_name String Original File Name
GCenter.Gscan.Powershell.sha256 String Sha256
GCenter.Gscan.Powershell.is_clean Boolean Clean
GCenter.Gscan.Powershell.is_analysis_successful Boolean Scan Succes
GCenter.Gscan.Powershell.status String Status
GCenter.Gscan.Powershell.proba_obfuscated Number Proba_Obfuscated
GCenter.Gscan.Powershell.analysis_score Number Analysis_Score
GCenter.Gscan.Powershell.is_whiteblack_listed Boolean Is White Or Black Listed?
Command Example

!gw-send-powershell filename="test" file_id="331@dfca9ea2-5198-4d64-8c36-5282ac3b2dc5"

Context Example
{
    "id": "2",
    "created": "2022-03-21T16:43:35.591406Z",
    "username": "admin",
    "user_agent": "Mozilla/5.0",
    "ip_address": "10.10.10.10",
    "file_name": "Arch.jpg",
    "sha256": "1a9487d49d842ebdee5ad870065eb74dc7044",
    "is_clean": true,
    "is_analysis_successful": true,
    "status": "Clean",
    "proba_obfuscated": 0,
    "analysis_score": 0,
    "is_whiteblack_listed": false
}
Human Readable Output

Powershell analysis result

analysis_score created file_name id ip_address is_analysis_successful is_clean is_whiteblack_listed proba_obfuscated sha256 status user_agent username
0 2022-03-21T16:43:35.591406Z Arch.jpg 2 10.10.10.10 true true false 0 1a9487d49d842ebdee5ad870065eb74dc7044 Clean Mozilla/5.0 admin

gw-send-shellcode


Send shellcode

Base Command

gw-send-shellcode

Input

Argument Name Description Required
filename Filename. Required
file_id File entry id. Required
deep Deep scan. Optional
timeout Deep scan timeout. Default is 120. Optional

Context Output

Path Type Description
GCenter.Gscan.Shellcode.id String The Id Of The Gscan History Message
GCenter.Gscan.Shellcode.created Date Date Of Creation
GCenter.Gscan.Shellcode.username String The User’S Username Who Uploaded The File
GCenter.Gscan.Shellcode.user_agent String The Client’S User-Agent
GCenter.Gscan.Shellcode.ip_address String The Ip Address Of The User Who Uploaded The File
GCenter.Gscan.Shellcode.file_name String Original File Name
GCenter.Gscan.Shellcode.sha256 String Sha256
GCenter.Gscan.Shellcode.is_clean Boolean Clean
GCenter.Gscan.Shellcode.is_analysis_successful Boolean Scan Succes
GCenter.Gscan.Shellcode.status String Status
GCenter.Gscan.Shellcode.architecture Unknown Architecture
GCenter.Gscan.Shellcode.is_whiteblack_listed Boolean Is White Or Black Listed?
Command Example

!gw-send-shellcode filename="test" file_id="331@dfca9ea2-5198-4d64-8c36-5282ac3b2dc5" deep=false timeout=120

Context Example
{
    "id": "3",
    "created": "2022-03-21T16:44:26.214241Z",
    "username": "admin",
    "user_agent": "Mozilla/5.0",
    "ip_address": "10.10.10.10",
    "file_name": "Arch.jpg",
    "sha256": "1a9487d49d842ebdee5ad870065eb74dc7044",
    "is_clean": true,
    "is_analysis_successful": true,
    "status": "Clean",
    "architecture": null,
    "encodings": [],
    "is_whiteblack_listed": false
}
Human Readable Output

Shellcode analysis result

architecture created encodings file_name id ip_address is_analysis_successful is_clean is_whiteblack_listed sha256 status user_agent username
  2022-03-21T16:44:26.214241Z   Arch.jpg 3 10.10.10.10 true true false 1a9487d49d842ebdee5ad870065eb74dc7044 Clean Mozilla/5.0 admin

gw-es-wrapper


Get Elasticsearch data using a wrapper

Base Command

gw-es-wrapper

Input

Argument Name Description Required
index index. Possible values are: suricata, codebreaker, malware, netdata, syslog, machine_learning, retrohunt, iocs. Required
aggs_term List and count each distinct values of a document field using the terms aggregation
If aggs_term is empty list hits value
Exemple : “src_ip,dest_ip”. Possible values are: src_ip, dest_ip, http.hostname, tls.sni, SHA256.
Optional
must_match Filter document that match the value using the term query
Exemple : “alert.severity=1,app_proto=http”.
Optional
must_exists Filter document with existing key using the exists query
Exemple : “http.hostname,http.url”.
Optional
timerange Set the lower timerange in hour based on the now keyword. Default is 24. Optional
formatted True to get the list of aggregation value False to get entire response. Possible values are: True, False. Default is True. Optional
size Set the number of aggregate or hits value that can be returned. Default is 100. Optional

Context Output

There is no context output for this command.

Command Example

!gw-es-wrapper index="malware" aggs_term="src_ip" must_match="state=Infected" timerange="240" formatted="True"

Context Example
{
    "src_ip": [
        "10.10.10.10"
    ]
}
Human Readable Output

Elasticsearch wrapper result

src_ip
10.10.10.10

gw-get-malcore-list-entry


Get the malcore whitelist/blacklist

Base Command

gw-get-malcore-list-entry

Input

Argument Name Description Required
type List type. Possible values are: white, black. Required

Context Output

Path Type Description
GCenter.Malcore.List.sha256 String Sha256
GCenter.Malcore.List.created Date Created
GCenter.Malcore.List.comment String Comment
GCenter.Malcore.List.threat String Name Of Threat For Reference
Command Example

!gw-get-malcore-list-entry type=black

Context Example
[
    {
        "sha256": "d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351f",
        "created": "2022-09-13T08:16:21.400100Z",
        "comment": "added by cortex",
        "threat": "undefined"
    },
    {
        "sha256": "d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351e",
        "created": "2022-09-13T08:16:09.880381Z",
        "comment": "added by cortex",
        "threat": "undefined"
    }
]
Human Readable Output

Malcore whitelist/blacklist entry

comment created sha256 threat
added by cortex 2022-09-13T08:16:21.400100Z d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351f undefined
added by cortex 2022-09-13T08:16:09.880381Z d955e262d7a05fc436e65c2a312593e4c7031482d90cebd29e69059053b1351e undefined

gw-get-dga-list-entry


Get the dga whitelist/blacklist

Base Command

gw-get-dga-list-entry

Input

Argument Name Description Required
type List type. Possible values are: white, black. Required

Context Output

Path Type Description
GCenter.Dga.List.domain_name String Domain Name
GCenter.Dga.List.created Date Created
GCenter.Dga.List.comment String Comment
GCenter.Dga.List.is_wildcard Boolean Is Wildcard
Command Example

!gw-get-dga-list-entry type=black

Context Example
[
    {
        "domain_name": "test.domain.com",
        "created": "2022-03-21T16:30:20.012035Z",
        "comment": "added by cortex",
        "is_wildcard": false
    }
]
Human Readable Output

DGA whitelist/blacklist entry

comment created domain_name is_wildcard
added by cortex 2022-03-21T16:30:20.012035Z test.domain.com false

gw-get-ignore-asset-name


Get all the ignored asset names

Base Command

gw-get-ignore-asset-name

Input

There are no input arguments for this command.

Context Output

Path Type Description
GCenter.Ignore.AssetName.List.id String Id
GCenter.Ignore.AssetName.List.created_at Date Created At
GCenter.Ignore.AssetName.List.created_by String Created By
GCenter.Ignore.AssetName.List.name String Ignored Name For The Assets (Hostnames). Case Insensitive.
GCenter.Ignore.AssetName.List.is_startswith_pattern Boolean Should The Assets (Hostnames) Be Ignored If They Start With This Name ?
GCenter.Ignore.AssetName.List.is_endswith_pattern Boolean Should The Assets (Hostnames) Be Ignored If They End With This Name ?
Command Example

##### Context Example

```json
[
    {
        "id": "1",
        "created_at": "2022-09-13T13:31:18.427519Z",
        "created_by": "admin",
        "name": "test",
        "is_startswith_pattern": false,
        "is_endswith_pattern": true
    },
    {
        "id": "2",
        "created_at": "2022-09-13T13:31:31.049593Z",
        "created_by": "admin",
        "name": "test2",
        "is_startswith_pattern": true,
        "is_endswith_pattern": false
    }
]
Human Readable Output

Asset name entry

created_at created_by id is_endswith_pattern is_startswith_pattern name
2022-09-13T13:31:18.427519Z admin 1 true false test
2022-09-13T13:31:31.049593Z admin 2 false true test2

gw-get-ignore-kuser-ip


Get all the ignored kuser IP

Base Command

gw-get-ignore-kuser-ip

Input

There are no input arguments for this command.

Context Output

Path Type Description
GCenter.Ignore.KuserIP.List.id String Id
GCenter.Ignore.KuserIP.List.created_at Date Created At
GCenter.Ignore.KuserIP.List.created_by String Created By
GCenter.Ignore.KuserIP.List.ip String Ignored Ip For The Kerberos Users
Command Example

##### Context Example

```json
[
    {
        "id": "1",
        "created_at": "2022-09-13T12:06:29.575735Z",
        "created_by": "admin",
        "ip": "10.10.10.0"
    },
    {
        "id": "2",
        "created_at": "2022-09-13T13:30:26.791512Z",
        "created_by": "admin",
        "ip": "10.10.10.0"
    }
]
Human Readable Output

Kuser IP entry

created_at created_by id ip
2022-09-13T12:06:29.575735Z admin 1 10.10.10.0
2022-09-13T13:30:26.791512Z admin 2 10.10.10.0

gw-get-ignore-kuser-name


Get all the ignored kuser name

Base Command

gw-get-ignore-kuser-name

Input

There are no input arguments for this command.

Context Output

Path Type Description
GCenter.Ignore.KuserName.List.id String Id
GCenter.Ignore.KuserName.List.created_at Date Created At
GCenter.Ignore.KuserName.List.created_by String Created By
GCenter.Ignore.KuserName.List.name String Ignored Name For The Kerberos Users. Case Insensitive.
GCenter.Ignore.KuserName.List.is_startswith_pattern Boolean Should The Kerberos Users Be Ignored If They Start With This Name ?
GCenter.Ignore.KuserName.List.is_endswith_pattern Boolean Should The Kerberos Users Be Ignored If They End With This Name ?
Command Example

##### Context Example

```json
[
    {
        "id": "1",
        "created_at": "2022-09-13T13:27:50.136561Z",
        "created_by": "admin",
        "name": "test",
        "is_startswith_pattern": true,
        "is_endswith_pattern": false
    },
    {
        "id": "2",
        "created_at": "2022-09-13T13:28:02.072013Z",
        "created_by": "admin",
        "name": "test2",
        "is_startswith_pattern": false,
        "is_endswith_pattern": true
    }
]
Human Readable Output

Kuser name entry

created_at created_by id is_endswith_pattern is_startswith_pattern name
2022-09-13T13:27:50.136561Z admin 1 false true test
2022-09-13T13:28:02.072013Z admin 2 true false test2

gw-get-ignore-mac-address


Get all the ignored mac addresses

Base Command

gw-get-ignore-mac-address

Input

There are no input arguments for this command.

Context Output

Path Type Description
GCenter.Ignore.MacAddress.List.id String Id
GCenter.Ignore.MacAddress.List.created_at Date Created At
GCenter.Ignore.MacAddress.List.created_by String Created By
GCenter.Ignore.MacAddress.List.address String Address
GCenter.Ignore.MacAddress.List.is_startswith_pattern Boolean Should The Mac Addresses Be Ignored If They Start With This Address Value ?
Command Example

##### Context Example

```json
[
    {
        "id": "1",
        "created_at": "2022-09-13T13:25:55.679624Z",
        "created_by": "admin",
        "address": "00:50:50:50:50:50",
        "is_startswith_pattern": true
    },
    {
        "id": "2",
        "created_at": "2022-09-13T13:26:11.338296Z",
        "created_by": "admin",
        "address": "00:40:40:40:40:40",
        "is_startswith_pattern": true
    }
]
Human Readable Output

MAC adrress entry

address created_at created_by id is_startswith_pattern
00:50:50:50:50:50 2022-09-13T13:25:55.679624Z admin 1 true
00:40:40:40:40:40 2022-09-13T13:26:11.338296Z admin 2 true

gw-get-file-infected


Get a file from an uuid.
If there is no uuid, get all the files infected from a time interval.

Base Command

gw-get-file-infected

Input

Argument Name Description Required
timerange Set the lower timerange in minute based on the now keyword when uuid is not given
Default value to 60 minutes.
Optional
size Set the number of aggregate value that can be returned when uuid is not given
Get all the values by default.
Optional
uuid The uuid of the file to get. Optional
state The state of the files to get, in list, when uuid is not given
Default value to Infected,Suspicious. Possible values are: .
Optional

Context Output

Path Type Description
Gcenter.File.Infected String File infected
Command Example

!gw-get-file-infected timerange="1440"

Context Example
[
    {
        "Content": "",
        "ContentFormat": "text",
        "File": "malcore_b34fc6de9763e3640f93dda3f7a97470af6f009089bca588272a03807ae9f5bf_2022-12-12_18-21-40.zip",
        "FileID": "f956f5cd-bad2-4f9c-ab75-cc6b16e58873",
        "Type": "3"
    }
]
Human Readable Output

Files infected entry

Contents ContentsFormat File FileID Type
  text malcore_b34fc6de9763e3640f93dda3f7a97470af6f009089bca588272a03807ae9f5bf_2022-12-12_18-21-40.zip f956f5cd-bad2-4f9c-ab75-cc6b16e58873 3

Configuration parameters

  • ip — GCenter IP address (required)
  • version — GCenter Version
  • token — GCenter API token
  • credentials — GCenter username
  • check_cert — Check the TLS certificate

Commands (26)

  • gw-add-dga-list-entry

    Add dga whitelist/blacklist entry.

  • gw-add-ignore-asset-name

    Ignore asset name.

  • gw-add-ignore-kuser-ip

    Ignore kuser IP.

  • gw-add-ignore-kuser-name

    Ignore kuser name.

  • gw-add-ignore-mac-address

    Ignore mac address.

  • gw-add-malcore-list-entry

    Add malcore whitelist/blacklist entry.

  • gw-del-dga-list-entry

    Delete dga whitelist/blacklist entry.

  • gw-del-ignore-asset-name

    Delete an ignore asset ID.

  • gw-del-ignore-kuser-ip

    Delete an ignore kuser IP ID.

  • gw-del-ignore-kuser-name

    Delete an ignore kuser name ID.

  • gw-del-ignore-mac-address

    Delete an ignore mac address ID.

  • gw-del-malcore-list-entry

    Delete malcore whitelist/blacklist entry.

  • gw-es-query

    Get Elasticsearch data.

  • gw-es-wrapper

    Get Elasticsearch data using a wrapper.

  • gw-get-alert

    Get an alert by it's uid.

  • gw-get-dga-list-entry

    Get the dga whitelist/blacklist.

  • gw-get-file-infected

    Get a file from an uuid. If there is no uuid, get all the files infected from a time interval.

  • gw-get-ignore-asset-name

    Get all the ignored asset names.

  • gw-get-ignore-kuser-ip

    Get all the ignored kuser IP.

  • gw-get-ignore-kuser-name

    Get all the ignored kuser name.

  • gw-get-ignore-mac-address

    Get all the ignored mac addresses.

  • gw-get-malcore-list-entry

    Get the malcore whitelist/blacklist.

  • gw-list-alerts Deprecated

    List all alerts (Deprecated. use gw-es-wrapper command instead).

  • gw-send-malware

    Send malware.

  • gw-send-powershell

    Send powershell.

  • gw-send-shellcode

    Send shellcode.

category: Network Security
provider: Gatewatcher
sectionorder:
- Connect
- Collect
commonfields:
  id: GCenter
  version: -1
configuration:
- display: GCenter IP address
  name: ip
  type: 0
  required: true
  section: Connect
- display: GCenter Version
  name: version
  type: 0
  defaultvalue: 2.5.3.102
  required: false
  section: Connect
- display: GCenter API token
  name: token
  type: 4
  additionalinfo: You must provide either an API token or a username and a password.
  required: false
  section: Connect
- display: GCenter username
  displaypassword: GCenter password
  name: credentials
  type: 9
  required: false
  section: Connect
- display: Check the TLS certificate
  name: check_cert
  type: 8
  required: false
  section: Connect
description: This integration allows, via about twenty commands, to interact with the GCenter appliance via its API.
display: GCenter
name: GCenter
script:
  commands:
  - name: gw-list-alerts
    description: List all alerts (Deprecated. use gw-es-wrapper command instead).
    deprecated: true
    outputs:
    - contextPath: GCenter.Alert.List.sha256
      description: The 256 Shasum Of The File.
      type: String
    - contextPath: GCenter.Alert.List.id
      description: The Id Of The Inspectra Alert.
      type: String
    - contextPath: GCenter.Alert.List.flow_id
      description: The Flow Id Of The Alert.
      type: Number
    - contextPath: GCenter.Alert.List.severity
      description: The Severity Of The Alert.
      type: Number
    - contextPath: GCenter.Alert.List.src_ip
      description: The Ip Address Of The Alert'S Source.
      type: String
    - contextPath: GCenter.Alert.List.dest_ip
      description: The Ip Address Of The Alert'S Target.
      type: String
    - contextPath: GCenter.Alert.List.src_port
      description: The Port Of The Alert'S Source.
      type: Number
    - contextPath: GCenter.Alert.List.dest_port
      description: The Port Of The Alert'S Target.
      type: Number
    - contextPath: GCenter.Alert.List.gcap
      description: The Gcap That Raised The Alert.
      type: String
    - contextPath: GCenter.Alert.List.type
      description: Which Type Of Alert (Sigflow, Codebreaker...)
      type: String
    - contextPath: GCenter.Alert.List.proto
      description: The Protocol Used.
      type: String
    - contextPath: GCenter.Alert.List.host
      description: The Host Where The Alert Was Found.
      type: String
    - contextPath: GCenter.Alert.List.app_proto
      description: The Malware Application Prototype.
      type: String
    - contextPath: GCenter.Alert.List.alert_type
      description: Which Event It Is ?
      type: String
    - contextPath: GCenter.Alert.List.state
      description: The State Of The Alert.
      type: String
    - contextPath: GCenter.Alert.List.matched_event
      description: Value Of The Id Of An Other Alert That Matched (Allows The Correlation Between Alerts).
      type: String
    - contextPath: GCenter.Alert.List.domain_name
      description: For Dga Alerts Only.
      type: String
    - contextPath: GCenter.Alert.List.probability
      description: The Severity Probability.
      type: Number
    - contextPath: GCenter.Alert.List.timestamp_detected
      description: When The Alert Was Detected.
      type: Date
    - contextPath: GCenter.Alert.List.timestamp_analyzed
      description: When The Alert Was Analysed.
      type: Date
    - contextPath: GCenter.Alert.List.retrohunt.timestamp_package
      description: Utc Date When The Ioc Was Added To The Lastinfosec Update Package.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.ioc_creation_date
      description: The Ioc Creation Date.
      type: Date
    - contextPath: GCenter.Alert.List.retrohunt.ioc_updated_date
      description: The Ioc Updated Date.
      type: Date
    - contextPath: GCenter.Alert.List.retrohunt.description
      description: The Alert Description.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.ioc_type
      description: Host, Md5, Sha1, Sha256, Url.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.ioc_value
      description: Characteristic Value Of The Ioc.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.matched_app_proto
      description: The Sigflow Protocol That Contains This Ioc.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.matched_event_type
      description: The Sigflow Event Type That Contains This Ioc.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.case_id
      description: Uuid Of The Box To Which The Ioc Belongs.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.ioc_id
      description: Uuid Of The Ioc.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.risk
      description: Suspicious, High Suspicious, Malicious.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.usage_mode
      description: Usage Mode.
      type: String
    - contextPath: GCenter.Alert.List.retrohunt.tlp
      description: Tlp.
      type: String
    - contextPath: GCenter.Alert.List.powershell.file_id
      description: The File Id.
      type: String
    - contextPath: GCenter.Alert.List.powershell.scores.proba_obfuscated
      description: The Probability It Is Obfuscated.
      type: Number
    - contextPath: GCenter.Alert.List.powershell.scores.analysis
      description: The Powershell Analysis Score.
      type: Number
    - contextPath: GCenter.Alert.List.shellcode.file_id
      description: The File Id.
      type: String
    - contextPath: GCenter.Alert.List.shellcode.encodings.name
      description: The Name Of The Encoding.
      type: String
    - contextPath: GCenter.Alert.List.shellcode.encodings.count
      description: The Number Of The Encoding Elements.
      type: Number
    - contextPath: GCenter.Alert.List.shellcode.calls.call
      description: The Name Of The Call Of The Alert.
      type: String
    - contextPath: GCenter.Alert.List.shellcode.calls.args
      description: The Argument Used For The Call.
      type: String
    - contextPath: GCenter.Alert.List.shellcode.calls.ret
      description: The Retention Of The Call.
      type: String
    - contextPath: GCenter.Alert.List.shellcode.calls.index
      description: The Call Index.
      type: Number
    - contextPath: GCenter.Alert.List.malware.analyzed_clean
      description: Number Of Engines That Returned A Clean Status.
      type: Number
    - contextPath: GCenter.Alert.List.malware.analyzed_infected
      description: Number Of Engines That Returned An Infected Status.
      type: Number
    - contextPath: GCenter.Alert.List.malware.analyzed_suspicious
      description: Number Of Engines That Returned A Suspicious Status.
      type: Number
    - contextPath: GCenter.Alert.List.malware.analyzed_other
      description: Number Of Engines That Returned Other Statuses.
      type: Number
    - contextPath: GCenter.Alert.List.malware.analyzed_error
      description: Number Of Engines That Failed To Analyze The File.
      type: Number
    - contextPath: GCenter.Alert.List.malware.code
      description: The Global Code Result.
      type: Number
    - contextPath: GCenter.Alert.List.malware.def_time
      description: 'When The Last Engines Have Ended The Scan.'
      type: Date
    - contextPath: GCenter.Alert.List.malware.scan_time
      description: The Scan Time In Ms.
      type: Number
    - contextPath: GCenter.Alert.List.malware.threats_found
      description: The Threats Found By The Engines.
      type: String
    - contextPath: GCenter.Alert.List.malware.reporting_token
      description: The Reporting Token Returned By The Gbox.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.0.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.0.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.0.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.1.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.1.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.1.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.2.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.2.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.2.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.3.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.3.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.3.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.4.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.4.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.4.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.5.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.5.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.5.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.6.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.6.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.6.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.7.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.7.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.7.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.8.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.8.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.8.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.9.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.9.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.9.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.10.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.10.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.10.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.11.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.11.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.11.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.12.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.12.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.12.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.13.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.13.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.13.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.14.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.14.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.14.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.15.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.15.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.List.malware.engines_report.15.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.List.malware.magic_details
      description: The File Magic.
      type: String
    - contextPath: GCenter.Alert.List.malware.total_found
      description: The Malcore Number Of Engines That Found The File Suspicious / The Total Number Of Engines.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.alert.action
      description: Action.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.alert.signature_id
      description: Signature Id.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.alert.gid
      description: Gid.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.alert.category
      description: Category.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.packet
      description: Packet.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.in_iface
      description: In Which Interface The Alert Occurred.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.stream
      description: Is It Streaming (!= 0).
      type: Number
    - contextPath: GCenter.Alert.List.sigflow.payload
      description: Payload.
      type: String
    - contextPath: GCenter.Alert.List.sigflow.payload_printable
      description: Payload Printable.
      type: String
  - name: gw-get-alert
    description: Get an alert by it's uid.
    arguments:
    - name: uid
      required: true
      description: Alert identifier.
    outputs:
    - contextPath: GCenter.Alert.Single.sha256
      description: The 256 Shasum Of The File.
      type: String
    - contextPath: GCenter.Alert.Single.id
      description: The Id Of The Inspectra Alert.
      type: String
    - contextPath: GCenter.Alert.Single.flow_id
      description: The Flow Id Of The Alert.
      type: Number
    - contextPath: GCenter.Alert.Single.severity
      description: The Severity Of The Alert.
      type: Number
    - contextPath: GCenter.Alert.Single.src_ip
      description: The Ip Address Of The Alert'S Source.
      type: String
    - contextPath: GCenter.Alert.Single.dest_ip
      description: The Ip Address Of The Alert'S Target.
      type: String
    - contextPath: GCenter.Alert.Single.src_port
      description: The Port Of The Alert'S Source.
      type: Number
    - contextPath: GCenter.Alert.Single.dest_port
      description: The Port Of The Alert'S Target.
      type: Number
    - contextPath: GCenter.Alert.Single.gcap
      description: The Gcap That Raised The Alert.
      type: String
    - contextPath: GCenter.Alert.Single.type
      description: Which Type Of Alert (Sigflow, Codebreaker...)
      type: String
    - contextPath: GCenter.Alert.Single.proto
      description: The Protocol Used.
      type: String
    - contextPath: GCenter.Alert.Single.host
      description: The Host Where The Alert Was Found.
      type: String
    - contextPath: GCenter.Alert.Single.app_proto
      description: The Malware Application Prototype.
      type: String
    - contextPath: GCenter.Alert.Single.alert_type
      description: Which Event It Is ?
      type: String
    - contextPath: GCenter.Alert.Single.state
      description: The State Of The Alert.
      type: String
    - contextPath: GCenter.Alert.Single.matched_event
      description: Value Of The Id Of An Other Alert That Matched (Allows The Correlation Between Alerts).
      type: String
    - contextPath: GCenter.Alert.Single.domain_name
      description: For Dga Alerts Only.
      type: String
    - contextPath: GCenter.Alert.Single.probability
      description: The Severity Probability.
      type: Number
    - contextPath: GCenter.Alert.Single.timestamp_detected
      description: When The Alert Was Detected.
      type: Date
    - contextPath: GCenter.Alert.Single.timestamp_analyzed
      description: When The Alert Was Analysed.
      type: Date
    - contextPath: GCenter.Alert.Single.retrohunt.timestamp_package
      description: Utc Date When The Ioc Was Added To The Lastinfosec Update Package.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.ioc_creation_date
      description: The Ioc Creation Date.
      type: Date
    - contextPath: GCenter.Alert.Single.retrohunt.ioc_updated_date
      description: The Ioc Updated Date.
      type: Date
    - contextPath: GCenter.Alert.Single.retrohunt.description
      description: The Alert Description.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.ioc_type
      description: Host, Md5, Sha1, Sha256, Url.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.ioc_value
      description: Characteristic Value Of The Ioc.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.matched_app_proto
      description: The Sigflow Protocol That Contains This Ioc.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.matched_event_type
      description: The Sigflow Event Type That Contains This Ioc.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.case_id
      description: Uuid Of The Box To Which The Ioc Belongs.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.ioc_id
      description: Uuid Of The Ioc.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.risk
      description: Suspicious, High Suspicious, Malicious.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.usage_mode
      description: Usage Mode.
      type: String
    - contextPath: GCenter.Alert.Single.retrohunt.tlp
      description: Tlp.
      type: String
    - contextPath: GCenter.Alert.Single.powershell.file_id
      description: The File Id.
      type: String
    - contextPath: GCenter.Alert.Single.powershell.scores.proba_obfuscated
      description: The Probability It Is Obfuscated.
      type: Number
    - contextPath: GCenter.Alert.Single.powershell.scores.analysis
      description: The Powershell Analysis Score.
      type: Number
    - contextPath: GCenter.Alert.Single.shellcode.file_id
      description: The File Id.
      type: String
    - contextPath: GCenter.Alert.Single.shellcode.encodings.name
      description: The Name Of The Encoding.
      type: String
    - contextPath: GCenter.Alert.Single.shellcode.encodings.count
      description: The Number Of The Encoding Elements.
      type: Number
    - contextPath: GCenter.Alert.Single.shellcode.calls.call
      description: The Name Of The Call Of The Alert.
      type: String
    - contextPath: GCenter.Alert.Single.shellcode.calls.args
      description: The Argument Used For The Call.
      type: String
    - contextPath: GCenter.Alert.Single.shellcode.calls.ret
      description: The Retention Of The Call.
      type: String
    - contextPath: GCenter.Alert.Single.shellcode.calls.index
      description: The Call Index.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.analyzed_clean
      description: Number Of Engines That Returned A Clean Status.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.analyzed_infected
      description: Number Of Engines That Returned An Infected Status.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.analyzed_suspicious
      description: Number Of Engines That Returned A Suspicious Status.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.analyzed_other
      description: Number Of Engines That Returned Other Statuses.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.analyzed_error
      description: Number Of Engines That Failed To Analyze The File.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.code
      description: The Global Code Result.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.def_time
      description: 'When The Last Engines Have Ended The Scan.'
      type: Date
    - contextPath: GCenter.Alert.Single.malware.scan_time
      description: The Scan Time In Ms.
      type: Number
    - contextPath: GCenter.Alert.Single.malware.threats_found
      description: The Threats Found By The Engines.
      type: String
    - contextPath: GCenter.Alert.Single.malware.reporting_token
      description: The Reporting Token Returned By The Gbox.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.0.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.0.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.0.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.1.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.1.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.1.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.2.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.2.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.2.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.3.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.3.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.3.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.4.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.4.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.4.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.5.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.5.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.5.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.6.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.6.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.6.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.7.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.7.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.7.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.8.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.8.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.8.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.9.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.9.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.9.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.10.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.10.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.10.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.11.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.11.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.11.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.12.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.12.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.12.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.13.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.13.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.13.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.14.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.14.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.14.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.15.id
      description: The Hash Pf The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.15.threat_details
      description: The Threat Found By The Engine.
      type: String
    - contextPath: GCenter.Alert.Single.malware.engines_report.15.scan_result
      description: Analysis Result.
      type: String
    - contextPath: GCenter.Alert.Single.malware.magic_details
      description: The File Magic.
      type: String
    - contextPath: GCenter.Alert.Single.malware.total_found
      description: The Malcore Number Of Engines That Found The File Suspicious / The Total Number Of Engines.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.alert.action
      description: Action.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.alert.signature_id
      description: Signature Id.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.alert.gid
      description: Gid.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.alert.category
      description: Category.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.packet
      description: Packet.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.in_iface
      description: In Which Interface The Alert Occurred.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.stream
      description: Is It Streaming (!= 0).
      type: Number
    - contextPath: GCenter.Alert.Single.sigflow.payload
      description: Payload.
      type: String
    - contextPath: GCenter.Alert.Single.sigflow.payload_printable
      description: Payload Printable.
      type: String
  - name: gw-es-query
    description: Get Elasticsearch data.
    arguments:
    - name: index
      auto: PREDEFINED
      predefined:
      - suricata
      - malware
      - codebreaker
      - netdata
      - syslog
      - machine_learning
      - retrohunt
      - iocs
      description: Index to be queried.
      defaultValue: suricata
    - name: query
      description: Elaticsearch query.
      defaultValue: '{}'
  - name: gw-add-malcore-list-entry
    description: Add malcore whitelist/blacklist entry.
    arguments:
    - name: type
      required: true
      auto: PREDEFINED
      predefined:
      - white
      - black
      description: List type.
    - name: sha256
      required: true
      description: SHA256 to be added.
    - name: comment
      description: Comment to be added.
    - name: threat
      description: Comment to be added.
    outputs:
    - contextPath: GCenter.Malcore.sha256
      description: Sha256.
      type: String
    - contextPath: GCenter.Malcore.created
      description: Created.
      type: Date
    - contextPath: GCenter.Malcore.comment
      description: Comment.
      type: String
    - contextPath: GCenter.Malcore.threat
      description: Name Of Threat For Reference.
      type: String
  - name: gw-del-malcore-list-entry
    description: Delete malcore whitelist/blacklist entry.
    arguments:
    - name: type
      required: true
      auto: PREDEFINED
      predefined:
      - white
      - black
      description: List type.
    - name: sha256
      required: true
      description: SHA256 to be deleted.
  - name: gw-add-dga-list-entry
    description: Add dga whitelist/blacklist entry.
    arguments:
    - name: type
      required: true
      auto: PREDEFINED
      predefined:
      - white
      - black
      description: List type.
    - name: domain
      required: true
      description: Domain name to be added.
    - name: comment
      description: Comment to be added.
    outputs:
    - contextPath: GCenter.Dga.domain_name
      description: Domain Name.
      type: String
    - contextPath: GCenter.Dga.created
      description: Created.
      type: Date
    - contextPath: GCenter.Dga.comment
      description: Comment.
      type: String
    - contextPath: GCenter.Dga.is_wildcard
      description: Is Wildcard.
      type: Boolean
  - name: gw-del-dga-list-entry
    description: Delete dga whitelist/blacklist entry.
    arguments:
    - name: type
      required: true
      auto: PREDEFINED
      predefined:
      - white
      - black
      description: List type.
    - name: domain
      required: true
      description: Domain name to be deleted.
  - name: gw-add-ignore-asset-name
    description: Ignore asset name.
    arguments:
    - name: name
      required: true
      description: Name to be ignored.
    - name: start
      required: true
      description: Will be ignored if they start with this name.
      defaultValue: false
    - name: end
      required: true
      description: Will be ignored if they end with this name.
      defaultValue: false
    outputs:
    - contextPath: GCenter.Ignore.AssetName.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.AssetName.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.AssetName.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.AssetName.name
      description: Ignored Name For The Assets (Hostnames). Case Insensitive.
      type: String
    - contextPath: GCenter.Ignore.AssetName.is_startswith_pattern
      description: Should The Assets (Hostnames) Be Ignored If They Start With This Name ?
      type: Boolean
    - contextPath: GCenter.Ignore.AssetName.is_endswith_pattern
      description: Should The Assets (Hostnames) Be Ignored If They End With This Name ?
      type: Boolean
  - name: gw-add-ignore-kuser-ip
    description: Ignore kuser IP.
    arguments:
    - name: ip
      required: true
      description: IP to be ignored.
    outputs:
    - contextPath: GCenter.Ignore.KuserIP.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.KuserIP.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.KuserIP.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.KuserIP.ip
      description: Ignored Ip For The Kerberos Users.
      type: String
  - name: gw-add-ignore-kuser-name
    description: Ignore kuser name.
    arguments:
    - name: name
      required: true
      description: Name to be ignored.
    - name: start
      required: true
      description: Will be ignored if they start with this name.
      defaultValue: false
    - name: end
      required: true
      description: Will be ignored if they end with this name.
      defaultValue: false
    outputs:
    - contextPath: GCenter.Ignore.KuserName.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.KuserName.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.KuserName.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.KuserName.name
      description: Ignored Name For The Kerberos Users. Case Insensitive.
      type: String
    - contextPath: GCenter.Ignore.KuserName.is_startswith_pattern
      description: Should The Kerberos Users Be Ignored If They Start With This Name ?
      type: Boolean
    - contextPath: GCenter.Ignore.KuserName.is_endswith_pattern
      description: Should The Kerberos Users Be Ignored If They End With This Name ?
      type: Boolean
  - name: gw-add-ignore-mac-address
    description: Ignore mac address.
    arguments:
    - name: mac
      required: true
      description: MAC address to be ignored.
    - name: start
      required: true
      description: Will be ignored if they start with this name.
      defaultValue: false
    outputs:
    - contextPath: GCenter.Ignore.MacAddress.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.MacAddress.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.MacAddress.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.MacAddress.address
      description: Address.
      type: String
    - contextPath: GCenter.Ignore.MacAddress.is_startswith_pattern
      description: Should The Mac Addresses Be Ignored If They Start With This Address Value ?
      type: Boolean
  - name: gw-del-ignore-asset-name
    description: Delete an ignore asset ID.
    arguments:
    - name: ignore_id
      required: true
      description: Ignore asset ID.
  - name: gw-del-ignore-kuser-ip
    description: Delete an ignore kuser IP ID.
    arguments:
    - name: ignore_id
      required: true
      description: Ignore kuser IP ID.
  - name: gw-del-ignore-kuser-name
    description: Delete an ignore kuser name ID.
    arguments:
    - name: ignore_id
      required: true
      description: Ignore kuser name ID.
  - name: gw-del-ignore-mac-address
    description: Delete an ignore mac address ID.
    arguments:
    - name: ignore_id
      required: true
      description: Ignore mac address ID.
  - name: gw-send-malware
    description: Send malware.
    arguments:
    - name: filename
      required: true
      description: Filename.
    - name: file_id
      required: true
      description: File entry id.
    outputs:
    - contextPath: GCenter.Gscan.Malware.id
      description: The Id Of The Gscan History Message.
      type: String
    - contextPath: GCenter.Gscan.Malware.created
      description: Date Of Creation.
      type: Date
    - contextPath: GCenter.Gscan.Malware.username
      description: The User'S Username Who Uploaded The File.
      type: String
    - contextPath: GCenter.Gscan.Malware.user_agent
      description: The Client'S User-Agent.
      type: String
    - contextPath: GCenter.Gscan.Malware.ip_address
      description: The Ip Address Of The User Who Uploaded The File.
      type: String
    - contextPath: GCenter.Gscan.Malware.file_name
      description: Original File Name.
      type: String
    - contextPath: GCenter.Gscan.Malware.sha256
      description: Sha256.
      type: String
    - contextPath: GCenter.Gscan.Malware.is_clean
      description: Clean.
      type: Unknown
    - contextPath: GCenter.Gscan.Malware.is_analysis_successful
      description: Scan Succes.
      type: Boolean
    - contextPath: GCenter.Gscan.Malware.malcore_code_result
      description: Malcore Code Result.
      type: String
    - contextPath: GCenter.Gscan.Malware.threat_name
      description: Threat Name.
      type: String
    - contextPath: GCenter.Gscan.Malware.nb_alerts
      description: Number Or Malcore Alerts.
      type: Number
    - contextPath: GCenter.Gscan.Malware.nb_engines
      description: Number Or Malcore Engines.
      type: Number
    - contextPath: GCenter.Gscan.Malware.is_whiteblack_listed
      description: Is White Or Black Listed?
      type: Boolean
    - contextPath: GCenter.Gscan.Malware.malcore_code_result_name
      description: Malcore Code Result Name.
      type: String
    - contextPath: GCenter.Gscan.Malware.status
      description: The Malcore Status.
      type: String
  - name: gw-send-powershell
    description: Send powershell.
    arguments:
    - name: filename
      required: true
      description: Filename.
    - name: file_id
      required: true
      description: File entry id.
    outputs:
    - contextPath: GCenter.Gscan.Powershell.id
      description: The Id Of The Gscan History Message.
      type: String
    - contextPath: GCenter.Gscan.Powershell.created
      description: Date Of Creation.
      type: Date
    - contextPath: GCenter.Gscan.Powershell.username
      description: The User'S Username Who Uploaded The File.
      type: String
    - contextPath: GCenter.Gscan.Powershell.user_agent
      description: The Client'S User-Agent.
      type: String
    - contextPath: GCenter.Gscan.Powershell.ip_address
      description: The Ip Address Of The User Who Uploaded The File.
      type: String
    - contextPath: GCenter.Gscan.Powershell.file_name
      description: Original File Name.
      type: String
    - contextPath: GCenter.Gscan.Powershell.sha256
      description: Sha256.
      type: String
    - contextPath: GCenter.Gscan.Powershell.is_clean
      description: Clean.
      type: Boolean
    - contextPath: GCenter.Gscan.Powershell.is_analysis_successful
      description: Scan Succes.
      type: Boolean
    - contextPath: GCenter.Gscan.Powershell.status
      description: Status.
      type: String
    - contextPath: GCenter.Gscan.Powershell.proba_obfuscated
      description: Proba_Obfuscated.
      type: Number
    - contextPath: GCenter.Gscan.Powershell.analysis_score
      description: Analysis_Score.
      type: Number
    - contextPath: GCenter.Gscan.Powershell.is_whiteblack_listed
      description: Is White Or Black Listed?
      type: Boolean
  - name: gw-send-shellcode
    description: Send shellcode.
    arguments:
    - name: filename
      required: true
      description: Filename.
    - name: file_id
      required: true
      description: File entry id.
    - name: deep
      description: Deep scan.
      defaultValue: false
    - name: timeout
      description: Deep scan timeout.
      defaultValue: 120
    outputs:
    - contextPath: GCenter.Gscan.Shellcode.id
      description: The Id Of The Gscan History Message.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.created
      description: Date Of Creation.
      type: Date
    - contextPath: GCenter.Gscan.Shellcode.username
      description: The User'S Username Who Uploaded The File.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.user_agent
      description: The Client'S User-Agent.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.ip_address
      description: The Ip Address Of The User Who Uploaded The File.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.file_name
      description: Original File Name.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.sha256
      description: Sha256.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.is_clean
      description: Clean.
      type: Boolean
    - contextPath: GCenter.Gscan.Shellcode.is_analysis_successful
      description: Scan Succes.
      type: Boolean
    - contextPath: GCenter.Gscan.Shellcode.status
      description: Status.
      type: String
    - contextPath: GCenter.Gscan.Shellcode.architecture
      description: Architecture.
      type: Unknown
    - contextPath: GCenter.Gscan.Shellcode.is_whiteblack_listed
      description: Is White Or Black Listed?
      type: Boolean
  - arguments:
    - auto: PREDEFINED
      default: true
      description: index.
      name: index
      predefined:
      - suricata
      - codebreaker
      - malware
      - netdata
      - syslog
      - machine_learning
      - retrohunt
      - iocs
      required: true
    - auto: PREDEFINED
      description: |-
        List and count each distinct values of a document field using the terms aggregation
        If aggs_term is empty list hits value
        Exemple : "src_ip,dest_ip".
      isArray: true
      name: aggs_term
      predefined:
      - src_ip
      - dest_ip
      - http.hostname
      - tls.sni
      - SHA256
    - description: |-
        Filter document that match the value using the term query
        Exemple : "alert.severity=1,app_proto=http".
      name: must_match
    - description: |-
        Filter document with existing key using the exists query
        Exemple : "http.hostname,http.url".
      name: must_exists
    - defaultValue: '24'
      description: Set the lower timerange in hour based on the now keyword.
      name: timerange
    - auto: PREDEFINED
      defaultValue: 'True'
      description: True to get the list of aggregation value False to get entire response.
      name: formatted
      predefined:
      - 'True'
      - 'False'
    - defaultValue: '100'
      description: Set the number of aggregate or hits value that can be returned.
      name: size
    description: Get Elasticsearch data using a wrapper.
    name: gw-es-wrapper
  - arguments:
    - auto: PREDEFINED
      description: List type.
      name: type
      predefined:
      - white
      - black
      required: true
    description: Get the malcore whitelist/blacklist.
    name: gw-get-malcore-list-entry
    outputs:
    - contextPath: GCenter.Malcore.List.sha256
      description: Sha256.
      type: String
    - contextPath: GCenter.Malcore.List.created
      description: Created.
      type: Date
    - contextPath: GCenter.Malcore.List.comment
      description: Comment.
      type: String
    - contextPath: GCenter.Malcore.List.threat
      description: Name Of Threat For Reference.
      type: String
  - arguments:
    - auto: PREDEFINED
      description: List type.
      name: type
      predefined:
      - white
      - black
      required: true
    description: Get the dga whitelist/blacklist.
    name: gw-get-dga-list-entry
    outputs:
    - contextPath: GCenter.Dga.List.domain_name
      description: Domain Name.
      type: String
    - contextPath: GCenter.Dga.List.created
      description: Created.
      type: Date
    - contextPath: GCenter.Dga.List.comment
      description: Comment.
      type: String
    - contextPath: GCenter.Dga.List.is_wildcard
      description: Is Wildcard.
      type: Boolean
  - description: Get all the ignored asset names.
    name: gw-get-ignore-asset-name
    outputs:
    - contextPath: GCenter.Ignore.AssetName.List.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.AssetName.List.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.AssetName.List.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.AssetName.List.name
      description: Ignored Name For The Assets (Hostnames). Case Insensitive.
      type: String
    - contextPath: GCenter.Ignore.AssetName.List.is_startswith_pattern
      description: Should The Assets (Hostnames) Be Ignored If They Start With This Name ?
      type: Boolean
    - contextPath: GCenter.Ignore.AssetName.List.is_endswith_pattern
      description: Should The Assets (Hostnames) Be Ignored If They End With This Name ?
      type: Boolean
  - description: Get all the ignored kuser IP.
    name: gw-get-ignore-kuser-ip
    outputs:
    - contextPath: GCenter.Ignore.KuserIP.List.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.KuserIP.List.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.KuserIP.List.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.KuserIP.List.ip
      description: Ignored Ip For The Kerberos Users.
      type: String
  - description: Get all the ignored kuser name.
    name: gw-get-ignore-kuser-name
    outputs:
    - contextPath: GCenter.Ignore.KuserName.List.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.KuserName.List.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.KuserName.List.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.KuserName.List.name
      description: Ignored Name For The Kerberos Users. Case Insensitive.
      type: String
    - contextPath: GCenter.Ignore.KuserName.List.is_startswith_pattern
      description: Should The Kerberos Users Be Ignored If They Start With This Name ?
      type: Boolean
    - contextPath: GCenter.Ignore.KuserName.List.is_endswith_pattern
      description: Should The Kerberos Users Be Ignored If They End With This Name ?
      type: Boolean
  - description: Get all the ignored mac addresses.
    name: gw-get-ignore-mac-address
    outputs:
    - contextPath: GCenter.Ignore.MacAddress.List.id
      description: Id.
      type: String
    - contextPath: GCenter.Ignore.MacAddress.List.created_at
      description: Created At.
      type: Date
    - contextPath: GCenter.Ignore.MacAddress.List.created_by
      description: Created By.
      type: String
    - contextPath: GCenter.Ignore.MacAddress.List.address
      description: Address.
      type: String
    - contextPath: GCenter.Ignore.MacAddress.List.is_startswith_pattern
      description: Should The Mac Addresses Be Ignored If They Start With This Address Value ?
      type: Boolean
  - arguments:
    - description: 'Set the lower timerange in minute based on the now keyword when uuid is not given

        Default value to 60 minutes.'
      name: timerange
    - description: 'Set the number of aggregate value that can be returned when uuid is not given

        Get all the values by default.'
      name: size
    - description: The uuid of the file to get.
      name: uuid
    - description: 'The state of the files to get, in list, when uuid is not given

        Default value to Infected,Suspicious.'
      name: state
      predefined:
      - ''
    description: 'Get a file from an uuid.

      If there is no uuid, get all the files infected from a time interval.'
    name: gw-get-file-infected
    outputs:
    - contextPath: Gcenter.File.Infected
      description: File infected.
      type: String
  runonce: false
  script: '-'
  type: python
  subtype: python3
  dockerimage: demisto/python3:3.12.8.3296088
fromversion: 6.2.0
tests:
- Gcenter Test Playbook