Hatching Triage
Submit a high volume of samples to run in a sandbox and view reports.
Forensics & Malware Analysis · Hatching Triage
Details
| ID | Hatching Triage |
|---|---|
| Provider | Recorded Future |
| Category | Forensics & Malware Analysis |
| From Version | 5.5.0 |
| Docker Image | demisto/python3:3.12.8.3296088 |
| Supported Modules | Agentix XSIAM EDR Cortex Cloud Cloud Runtime Security |
README
Submit a high volume of samples to run in a sandbox and view reports
This integration was integrated and tested with version 0 of Hatching Triage
Configure Hatching Triage in Cortex
| Parameter | Description | Required |
|---|---|---|
| API URL | Private url is https://private.tria.ge/api/v0/ | True |
| API Key | The API Key to use for the connection. | True |
| Verify SSL | False | |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
triage-query-samples
Get a list of all samples either private or public
Base Command
triage-query-samples
Input
| Argument Name | Description | Required |
|---|---|---|
| subset | Get samples from either private or public reports. Possible values are: owned, public. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.submissions.completed | Date | Date the sample analysis was completed |
| Triage.submissions.filename | String | Name of the file submitted |
| Triage.submissions.id | String | Unique identifier of the submission |
| Triage.submissions.kind | String | Type of analysis |
| Triage.submissions.private | Boolean | If the submissions is private or publically viewable |
| Triage.submissions.status | String | Status of the submitted file |
| Triage.submissions.submitted | Date | Date the sample was submitted |
| Triage.submissions.tasks.id | String | Array of tasks that have been applied to the sample (static, behavioral, etc) |
| Triage.submissions.tasks.status | String | Status of the task |
| Triage.submissions.tasks.target | String | Sample the task is being run on |
| Triage.submissions.url | String | URL that was submitted |
triage-submit-sample
Submits a file or url for analysis
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
Base Command
triage-submit-sample
Input
| Argument Name | Description | Required |
|---|---|---|
| kind | Select if sample is a URL, file, or a file that should be fetched from a URL. Possible values are: url, file, fetch. | Required |
| interactive | Choose if the sample should be interacted with in the GUI glovebox. Possible values are: false, true. Default is false. | Optional |
| profiles | Select what profile to run the sample with. Requires the user to be registered with a company. | Optional |
| data | Data to submit for analysis. For URLs give the URL. For files, give the entry-id of the file. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.submissions.filename | String | Name of the submitted file |
| Triage.submissions.id | String | Unique identifier of the submission |
| Triage.submissions.kind | String | Type of sample to analyze |
| Triage.submissions.private | Boolean | If the file is private or publicly viewable |
| Triage.submissions.status | String | Status of the analysis of the submission |
| Triage.submissions.submitted | Date | Date that the sample was submitted on |
Command example
!triage-submit-sample data="4@1" kind="file"
Human Readable Output
triage-get-sample
Pulls back basic information about the sample id given
Base Command
triage-get-sample
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.samples.completed | Date | Date the sample analysis was completed |
| Triage.samples.filename | String | Name of the submitted sample |
| Triage.samples.id | String | Unique identifier of the sample |
| Triage.samples.kind | String | Type of sample submitted |
| Triage.samples.private | Boolean | State of the visibility of the sample |
| Triage.samples.status | String | Current status of the sample analysis |
| Triage.samples.submitted | Date | Date the sample was submitted |
| Triage.samples.tasks.id | String | Task name that was applied to the sample |
| Triage.samples.tasks.status | String | Status of the task |
| Triage.samples.tasks.target | String | Target of the task, e.g. filename for file submissions |
triage-get-sample-summary
Gets a summary report of the sample id provided
Base Command
triage-get-sample-summary
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.sample-summaries.completed | Date | Date the sample analysis was completed |
| Triage.sample-summaries.created | Date | Date the analysis report was created |
| Triage.sample-summaries.custom | String | |
| Triage.sample-summaries.owner | String | |
| Triage.sample-summaries.sample | String | Unique identifier of the sample |
| Triage.sample-summaries.score | Number | Score of the sample on a scale of 0 to 10 |
| Triage.sample-summaries.sha256 | String | SHA256 of the sample |
| Triage.sample-summaries.status | String | Status of the analysis |
| Triage.sample-summaries.target | String | Target for analysis |
| Triage.sample-summaries.tasks | String | Tasks performed in the analysis |
Command example
!triage-get-sample-summary sample_id="220807-d5sxnaebbx"
Human Readable Output
triage-delete-sample
Deletes a sample from the sandbox
Base Command
triage-delete-sample
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
Context Output
There is no context output for this command.
triage-set-sample-profile
When a sample is in the static_analysis status, a profile should be selected in order to continue.
Base Command
triage-set-sample-profile
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
| auto | Let Triage automatically select a profile, default is True. Possible values are: true, false. | Optional |
| pick | If submitting an archive file, select which files to analyze. Multiple files can be specified with a comma seperator.Format is archive_file_name/sample_file.exe,archive_file_name/sample_file2.exe. | Optional |
| profiles | Profile ID to use. | Optional |
Context Output
There is no context output for this command.
triage-get-static-report
Get the static analysis of a sample
Base Command
triage-get-static-report
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.sample.reports.static.analysis.reported | Unknown | Date the sample was submitted |
| DBotScore.Indicator | String | Triage analysis target |
| DBotScore.Type | String | The indicator type - File or URL |
| DBotScore.Vendor | String | The integration used to generate the indicator |
| DBotScore.Score | Number | Analysis verdict as score from 1 to 10 |
| File.Name | String | The full file name (including file extension). |
| File.MD5 | String | The MD5 hash of the file. |
| File.SHA1 | String | The SHA1 hash of the file. |
| File.SHA256 | String | The SHA1 hash of the file. |
| URL.Data | String | The URL |
Command example
!triage-get-static-report sample_id="220807-d5sxnaebbx"
Human Readable Output
triage-get-report-triage
Retrieves the generated Triage behavioral report for a single task
Base Command
triage-get-report-triage
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
| task_id | Name of a behavioral task part of the sample analysis (e.g. behavioral1, behavioral2). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.sample.reports.triage | Unknown | Triage report of the submitted sample |
| DBotScore.Indicator | String | Triage analysis target |
| DBotScore.Type | String | The indicator type - File or URL |
| DBotScore.Vendor | String | The integration used to generate the indicator |
| DBotScore.Score | Number | Analysis verdict as score from 1 to 10 |
| File.Name | String | The full file name (including file extension). |
| File.MD5 | String | The MD5 hash of the file. |
| File.SHA1 | String | The SHA1 hash of the file. |
| File.SHA256 | String | The SHA1 hash of the file. |
| URL.Data | String | The URL |
Command example
!triage-get-report-triage sample_id="220807-d5sxnaebbx" task_id="behavioral1"
Human Readable Output
triage-get-kernel-monitor
Retrieves the output of the kernel monitor
Base Command
triage-get-kernel-monitor
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
| task_id | Name of a behavioral task part of the sample analysis (e.g. behavioral1, behavioral2). | Required |
Context Output
There is no context output for this command.
triage-get-pcap
Retrieves the PCAP of the analysis for further manual analysis
Base Command
triage-get-pcap
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
| task_id | Name of a behavioral task part of the sample analysis (e.g. behavioral1, behavioral2). | Required |
Context Output
There is no context output for this command.
triage-get-dumped-file
Retrieves files dumped by the sample. The names can be found under the “dumped” section from the triage report output
Base Command
triage-get-dumped-file
Input
| Argument Name | Description | Required |
|---|---|---|
| sample_id | Sample’s unique identifier, can be found using the query samples command. | Required |
| task_id | Name of the task for the sample (e.g. behavioral1, static1, etc). | Required |
| file_name | Name of the dumped file. | Required |
Context Output
There is no context output for this command.
triage-get-users
Return all users within the company as a paginated list. Returns a single user if a userID is provided
Base Command
triage-get-users
Input
| Argument Name | Description | Required |
|---|---|---|
| userID | Unique identifier of the user. Leave blank to query for all users. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.users.company_id | String | Company unique identifier |
| Triage.users.created_at | Date | Date users account was created |
| Triage.users.email | String | Users email |
| Triage.users.email_confirmed_at | Date | Date user confirmed their email/account |
| Triage.users.first_name | String | Users first name |
| Triage.users.id | String | Users unique identifier |
| Triage.users.last_name | String | Users last name |
| Triage.users.permissions | String | Users permissions |
triage-create-user
Creates a new user and returns it. The user will become a member of the company the requesting user is a member of
Base Command
triage-create-user
Input
| Argument Name | Description | Required |
|---|---|---|
| username | Users username, usually their email. | Required |
| firstName | Users first name. | Required |
| lastName | Users last name. | Required |
| password | Users password. | Required |
| permissions | Users permissions. Possible values are: view_samples, submit_samples, delete_samples, edit_profiles, access_api, manage_machines, manage_company. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.users.company_id | String | Company unique identifier |
| Triage.users.created_at | Date | Date users account was created |
| Triage.users.email | String | Users email |
| Triage.users.email_confirmed_at | Date | Date user confirmed their email/account |
| Triage.users.first_name | String | Users first name |
| Triage.users.id | String | Users unique identifier |
| Triage.users.last_name | String | Users last name |
| Triage.users.permissions | String | Users permissions |
triage-delete-user
Delete a user and all associated data, invalidating any sessions and removing their API keys. Any samples submitted by this user are kept
Base Command
triage-delete-user
Input
| Argument Name | Description | Required |
|---|---|---|
| userID | Users unique identifier, can be found by querying for all users. | Required |
Context Output
There is no context output for this command.
triage-create-api-key
Creates a new key can be used to make API calls on behalf of the specified user. The user should have been granted the access_api permission beforehand
Base Command
triage-create-api-key
Input
| Argument Name | Description | Required |
|---|---|---|
| userID | Users unique identifier, can be found by querying for all users. | Required |
| name | Name of the API key. Default is Created from XSOAR. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.apikey.key | String | API Key |
| Triage.apikey.name | String | Name of the API Key |
triage-get-api-key
Lists all API keys that the user has.
Base Command
triage-get-api-key
Input
| Argument Name | Description | Required |
|---|---|---|
| userID | Users unique identifier, can be found by querying for all users. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.apikey.key | String | API Key |
| Triage.apikey.name | String | Name of the API Key |
triage-delete-api-key
Delete the user’s API key with the specified name
Base Command
triage-delete-api-key
Input
| Argument Name | Description | Required |
|---|---|---|
| userID | Users unique identifier, can be found by querying for all users. | Required |
| name | Name of the API key to delete. | Required |
Context Output
There is no context output for this command.
triage-get-profiles
List all profiles that your company has
Base Command
triage-get-profiles
Input
| Argument Name | Description | Required |
|---|---|---|
| profileID | Unique identifier of the profile, can be found by querying for all profiles. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.profiles..id | String | Unique identifier of the profile |
| Triage.profiles..name | String | Name of the profile |
| Triage.profiles..network | String | Network configuration |
| Triage.profiles..options.browser | String | Browser options |
| Triage.profiles..tags | String | Applied tags |
| Triage.profiles..timeout | Number | Max run time of the profile |
triage-create-profile
Create a new profile
Base Command
triage-create-profile
Input
| Argument Name | Description | Required |
|---|---|---|
| name | Name of the profile to create. | Required |
| tags | Tags to apply to the profile. | Required |
| timeout | Length of time the profile should run for. | Optional |
| network | Network configuration the profile should use. Possible values are: drop, internet, proxy. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.profiles.id | String | Profile unique identifier |
| Triage.profiles.name | String | Profile name |
| Triage.profiles.network | String | Profile network configuration |
| Triage.profiles.options | Unknown | Profile options |
| Triage.profiles.tags | String | Profile tags |
| Triage.profiles.timeout | Number | Profile max run time |
triage-update-profile
Update an existing profile
Base Command
triage-update-profile
Input
| Argument Name | Description | Required |
|---|---|---|
| profileID | Unique identifier of the profile to update. | Required |
| name | Name of the profile. | Required |
| tags | Tags to apply to the profile. | Required |
| timeout | Length of time the profile should run for. | Optional |
Context Output
There is no context output for this command.
triage-query-search
Get a list of private and public samples matching the search query
Base Command
triage-query-search
Input
| Argument Name | Description | Required |
|---|---|---|
| query | The search query for Triage. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Triage.samples.completed | date | Date the sample analysis was completed |
| Triage.samples.filename | string | Name of the file submitted |
| Triage.samples.id | string | Unique identifier of the submission |
| Triage.samples.kind | string | Type of analysis |
| Triage.samples.private | boolean | If the submissions is private or publically viewable |
| Triage.samples.status | string | Status of the submitted file |
| Triage.samples.submitted | date | Date the sample was submitted |
| Triage.samples.tasks.id | string | Array of tasks that have been applied to the sample (static, behavioral, etc) |
| Triage.samples.tasks.status | string | Status of the task |
| Triage.samples.tasks.target | string | Sample the task is being run on |
| Triage.samples.url | string | URL that was submitted |
Command example
!triage-query-search query="tag:stealer AND tag:spyware"
Human Readable Output
triage-delete-profile
Update the profile with the specified ID or name. The stored profile is overwritten, so it is important that the submitted profile has all fields, with the exception of the ID
Base Command
triage-delete-profile
Input
| Argument Name | Description | Required |
|---|---|---|
| profileID | Unique identifier of the profile to delete. | Required |
Context Output
There is no context output for this command.
Configuration parameters
base_url— API URL (required)API Key— API Keycredentials—Verify SSL— Verify SSLproxy— Use system proxy settings
Commands (22)
-
triage-create-api-keyCreates a new key can be used to make API calls on behalf of the specified user. The user should have been granted the access_api permission beforehand.
-
triage-create-profileCreate a new profile.
-
triage-create-userCreates a new user and returns it. The user will become a member of the company the requesting user is a member of.
-
triage-delete-api-keyDelete the user's API key with the specified name.
-
triage-delete-profileUpdate the profile with the specified ID or name. The stored profile is overwritten, so it is important that the submitted profile has all fields, with the exception of the ID.
-
triage-delete-sampleDeletes a sample from the sandbox.
-
triage-delete-userDelete a user and all associated data, invalidating any sessions and removing their API keys. Any samples submitted by this user are kept.
-
triage-get-api-keyLists all API keys that the user has.
-
triage-get-dumped-fileRetrieves files dumped by the sample. The names can be found under the "dumped" section from the triage report output.
-
triage-get-kernel-monitorRetrieves the output of the kernel monitor.
-
triage-get-pcapRetrieves the PCAP of the analysis for further manual analysis.
-
triage-get-profilesList all profiles that your company has.
-
triage-get-report-triageRetrieves the generated Triage behavioral report for a single task.
-
triage-get-samplePulls back basic information about the sample id given.
-
triage-get-sample-summaryGets a summary report of the sample id provided.
-
triage-get-static-reportGet the static analysis of a sample.
-
triage-get-usersReturn all users within the company as a paginated list. Returns a single user if a userID is provided.
-
triage-query-samplesGet a list of all samples either private or public.
-
triage-query-searchGet a list of private and public samples matching the search query.
-
triage-set-sample-profileWhen a sample is in the static_analysis status, a profile should be selected in order to continue.
-
triage-submit-sampleSubmits a file or url for analysis.
-
triage-update-profileUpdate an existing profile.
category: Forensics & Malware Analysis provider: Recorded Future commonfields: id: Hatching Triage version: -1 fromversion: 5.5.0 configuration: - display: API URL additionalinfo: Private url is https://private.tria.ge/api/v0/ defaultvalue: https://api.tria.ge/v0/ name: base_url required: true type: 0 - display: API Key name: API Key required: false type: 4 additionalinfo: The API Key to use for the connection. hidden: true - name: credentials type: 9 required: false displaypassword: API Key hiddenusername: true - display: Verify SSL name: Verify SSL defaultvalue: 'true' type: 8 required: false - defaultvalue: 'false' display: Use system proxy settings name: proxy required: false type: 8 description: Submit a high volume of samples to run in a sandbox and view reports. display: Hatching Triage name: Hatching Triage script: commands: - arguments: - auto: PREDEFINED description: Get samples from either private or public reports. name: subset predefined: - owned - public name: triage-query-samples outputs: - contextPath: Triage.submissions.completed description: Date the sample analysis was completed. type: Date - contextPath: Triage.submissions.filename description: Name of the file submitted. type: String - contextPath: Triage.submissions.id description: Unique identifier of the submission. type: String - contextPath: Triage.submissions.kind description: Type of analysis. type: String - contextPath: Triage.submissions.private description: If the submissions is private or publically viewable. type: Boolean - contextPath: Triage.submissions.status description: Status of the submitted file. type: String - contextPath: Triage.submissions.submitted description: Date the sample was submitted. type: Date - contextPath: Triage.submissions.tasks.id description: Array of tasks that have been applied to the sample (static, behavioral, etc). type: String - contextPath: Triage.submissions.tasks.status description: Status of the task. type: String - contextPath: Triage.submissions.tasks.target description: Sample the task is being run on. type: String - contextPath: Triage.submissions.url description: URL that was submitted. type: String description: Get a list of all samples either private or public. - arguments: - auto: PREDEFINED description: Select if sample is a URL, file, or a file that should be fetched from a URL. name: kind predefined: - url - file - fetch required: true - auto: PREDEFINED defaultValue: 'false' description: Choose if the sample should be interacted with in the GUI glovebox. name: interactive predefined: - 'false' - 'true' - description: Select what profile to run the sample with. Requires the user to be registered with a company. name: profiles - description: Data to submit for analysis. For URLs and fetch, give the URL. For files, give the entry-id of the file. name: data required: true - name: password description: A password that may be used to decrypt the provided file, usually an archive. - name: timeout description: The timeout in seconds of the behavioral analysis. - name: network auto: PREDEFINED description: The type of network routing to use. predefined: - internet - drop - tor - sim200 - sim404 - simnx - nxdomain - name: user_tags description: An array of user-defined strings that lets the user mark a sample. The resulting tags are part of the overview and summary reports. isArray: true description: Submits a file or url for analysis. name: triage-submit-sample outputs: - contextPath: Triage.submissions.filename description: Name of the submitted file. type: String - contextPath: Triage.submissions.id description: Unique identifier of the submission. type: String - contextPath: Triage.submissions.kind description: Type of sample to analyze. type: String - contextPath: Triage.submissions.private description: If the file is private or publicly viewable. type: Boolean - contextPath: Triage.submissions.status description: Status of the analysis of the submission. type: String - contextPath: Triage.submissions.submitted description: Date that the sample was submitted on. type: Date - arguments: - description: Sample's unique identifier, can be found using the query samples command. name: sample_id required: true description: Pulls back basic information about the sample id given. name: triage-get-sample outputs: - contextPath: Triage.samples.completed description: Date the sample analysis was completed. type: Date - contextPath: Triage.samples.filename description: Name of the submitted sample. type: String - contextPath: Triage.samples.id description: Unique identifier of the sample. type: String - contextPath: Triage.samples.kind description: Type of sample submitted. type: String - contextPath: Triage.samples.private description: State of the visibility of the sample. type: Boolean - contextPath: Triage.samples.status description: Current status of the sample analysis. type: String - contextPath: Triage.samples.submitted description: Date the sample was submitted. type: Date - contextPath: Triage.samples.tasks.id description: Task name that was applied to the sample. type: String - contextPath: Triage.samples.tasks.status description: Status of the task. type: String - contextPath: Triage.samples.tasks.target description: Target of the task, e.g. filename for file submissions. type: String - arguments: - description: One or more comma-separated unique sample identifiers. These can be found using the query samples command. isArray: true name: sample_id required: true description: Gets a summary report of the sample id provided. name: triage-get-sample-summary outputs: - contextPath: Triage.sample-summaries.completed description: Date the sample analysis was completed. type: Date - contextPath: Triage.sample-summaries.created description: Date the analysis report was created. type: Date - contextPath: Triage.sample-summaries.custom description: '' type: String - contextPath: Triage.sample-summaries.owner description: '' type: String - contextPath: Triage.sample-summaries.sample description: Unique identifier of the sample. type: String - contextPath: Triage.sample-summaries.score description: Score of the sample on a scale of 0 to 10. type: Number - contextPath: Triage.sample-summaries.sha256 description: SHA256 of the sample. type: String - contextPath: Triage.sample-summaries.status description: Status of the analysis. type: String - contextPath: Triage.sample-summaries.target description: Target for analysis. type: String - contextPath: Triage.sample-summaries.tasks description: Tasks performed in the analysis. type: String - arguments: - description: Sample's unique identifier, can be found using the query samples command. name: sample_id required: true description: Deletes a sample from the sandbox. name: triage-delete-sample - arguments: - name: sample_id description: Sample's unique identifier, can be found using the query samples command. required: true - auto: PREDEFINED description: Let Triage automatically select a profile, default is True. name: auto predefined: - 'true' - 'false' - description: If submitting an archive file, select which files to analyze. Multiple files can be specified with a comma seperator.Format is archive_file_name/sample_file.exe,archive_file_name/sample_file2.exe. name: pick - description: Profile ID to use. name: profiles description: When a sample is in the static_analysis status, a profile should be selected in order to continue. name: triage-set-sample-profile - arguments: - name: sample_id description: Sample's unique identifier, can be found using the query samples command. required: true description: Get the static analysis of a sample. name: triage-get-static-report outputs: - contextPath: Triage.sample.reports.static.analysis.reported description: Date the sample was submitted. type: Unknown - contextPath: DBotScore.Indicator description: Triage analysis target. type: String - contextPath: DBotScore.Type description: The indicator type - File or URL. type: String - contextPath: DBotScore.Vendor description: The integration used to generate the indicator. type: String - contextPath: DBotScore.Score description: Analysis verdict as score from 1 to 10. type: Number - contextPath: File.Name description: The full file name (including file extension). type: String - contextPath: File.MD5 description: The MD5 hash of the file. type: String - contextPath: File.SHA1 description: The SHA1 hash of the file. type: String - contextPath: File.SHA256 description: The SHA1 hash of the file. type: String - contextPath: URL.Data description: The URL. type: String - arguments: - name: sample_id description: Sample's unique identifier, can be found using the query samples command. required: true - name: task_id description: Name of a behavioral task part of the sample analysis (e.g. behavioral1, behavioral2). required: true description: Retrieves the generated Triage behavioral report for a single task. name: triage-get-report-triage outputs: - contextPath: Triage.sample.reports.triage description: Triage report of the submitted sample. type: Unknown - contextPath: DBotScore.Indicator description: Triage analysis target. type: String - contextPath: DBotScore.Type description: The indicator type - File or URL. type: String - contextPath: DBotScore.Vendor description: The integration used to generate the indicator. type: String - contextPath: DBotScore.Score description: Analysis verdict as score from 1 to 10. type: Number - contextPath: File.Name description: The full file name (including file extension). type: String - contextPath: File.MD5 description: The MD5 hash of the file. type: String - contextPath: File.SHA1 description: The SHA1 hash of the file. type: String - contextPath: File.SHA256 description: The SHA1 hash of the file. type: String - contextPath: URL.Data description: The URL. type: String - arguments: - name: sample_id description: Sample's unique identifier, can be found using the query samples command. required: true - name: task_id description: Name of a behavioral task part of the sample analysis (e.g. behavioral1, behavioral2). required: true description: Retrieves the output of the kernel monitor. name: triage-get-kernel-monitor - arguments: - name: sample_id description: Sample's unique identifier, can be found using the query samples command. required: true - name: task_id description: Name of a behavioral task part of the sample analysis (e.g. behavioral1, behavioral2). required: true name: triage-get-pcap description: Retrieves the PCAP of the analysis for further manual analysis. - arguments: - name: sample_id description: Sample's unique identifier, can be found using the query samples command. required: true - name: task_id description: Name of the task for the sample (e.g. behavioral1, static1, etc). required: true - name: file_name description: Name of the dumped file. required: true name: triage-get-dumped-file description: Retrieves files dumped by the sample. The names can be found under the "dumped" section from the triage report output. - arguments: - name: userID description: Unique identifier of the user. Leave blank to query for all users. outputs: - contextPath: Triage.users.company_id description: Company unique identifier. type: String - contextPath: Triage.users.created_at description: Date users account was created. type: Date - contextPath: Triage.users.email description: Users email. type: String - contextPath: Triage.users.email_confirmed_at description: Date user confirmed their email/account. type: Date - contextPath: Triage.users.first_name description: Users first name. type: String - contextPath: Triage.users.id description: Users unique identifier. type: String - contextPath: Triage.users.last_name description: Users last name. type: String - contextPath: Triage.users.permissions description: Users permissions. type: String name: triage-get-users description: Return all users within the company as a paginated list. Returns a single user if a userID is provided. - arguments: - name: username description: Users username, usually their email. required: true - name: firstName description: Users first name. required: true - name: lastName description: Users last name. required: true - name: password description: Users password. required: true secret: true - auto: PREDEFINED name: permissions description: Users permissions. predefined: - view_samples - submit_samples - delete_samples - edit_profiles - access_api - manage_machines - manage_company required: true name: triage-create-user outputs: - contextPath: Triage.users.company_id description: Company unique identifier. type: String - contextPath: Triage.users.created_at description: Date users account was created. type: Date - contextPath: Triage.users.email description: Users email. type: String - contextPath: Triage.users.email_confirmed_at description: Date user confirmed their email/account. type: Date - contextPath: Triage.users.first_name description: Users first name. type: String - contextPath: Triage.users.id description: Users unique identifier. type: String - contextPath: Triage.users.last_name description: Users last name. type: String - contextPath: Triage.users.permissions description: Users permissions. type: String description: Creates a new user and returns it. The user will become a member of the company the requesting user is a member of. - arguments: - name: userID description: Users unique identifier, can be found by querying for all users. required: true name: triage-delete-user description: Delete a user and all associated data, invalidating any sessions and removing their API keys. Any samples submitted by this user are kept. - arguments: - name: userID description: Users unique identifier, can be found by querying for all users. required: true - defaultValue: Created from XSOAR name: name description: Name of the API key. name: triage-create-api-key outputs: - contextPath: Triage.apikey.key description: API Key. type: String - contextPath: Triage.apikey.name description: Name of the API Key. type: String description: Creates a new key can be used to make API calls on behalf of the specified user. The user should have been granted the access_api permission beforehand. - arguments: - name: userID description: Users unique identifier, can be found by querying for all users. required: true name: triage-get-api-key outputs: - contextPath: Triage.apikey.key description: API Key. type: String - contextPath: Triage.apikey.name description: Name of the API Key. type: String description: Lists all API keys that the user has. - arguments: - name: userID description: Users unique identifier, can be found by querying for all users. required: true - name: name description: Name of the API key to delete. required: true name: triage-delete-api-key description: Delete the user's API key with the specified name. - arguments: - name: profileID description: Unique identifier of the profile, can be found by querying for all profiles. name: triage-get-profiles outputs: - contextPath: Triage.profiles..id description: Unique identifier of the profile. type: String - contextPath: Triage.profiles..name description: Name of the profile. type: String - contextPath: Triage.profiles..network description: Network configuration. type: String - contextPath: Triage.profiles..options.browser description: Browser options. type: String - contextPath: Triage.profiles..tags description: Applied tags. type: String - contextPath: Triage.profiles..timeout description: Max run time of the profile. type: Number description: List all profiles that your company has. - arguments: - name: name description: Name of the profile to create. required: true - name: tags description: Tags to apply to the profile. required: true - name: timeout description: Length of time the profile should run for. - auto: PREDEFINED name: network description: Network configuration the profile should use. predefined: - drop - internet - proxy - tor - sim200 - sim404 name: triage-create-profile outputs: - contextPath: Triage.profiles.id description: Profile unique identifier. type: String - contextPath: Triage.profiles.name description: Profile name. type: String - contextPath: Triage.profiles.network description: Profile network configuration. type: String - contextPath: Triage.profiles.options description: Profile options. type: Unknown - contextPath: Triage.profiles.tags description: Profile tags. type: String - contextPath: Triage.profiles.timeout description: Profile max run time. type: Number description: Create a new profile. - arguments: - name: profileID description: Unique identifier of the profile to update. required: true - name: name description: Name of the profile. required: true - name: tags description: Tags to apply to the profile. required: true - name: timeout description: Length of time the profile should run for. name: triage-update-profile description: Update an existing profile. - arguments: - name: query description: The search query for Triage. required: true name: triage-query-search description: Get a list of private and public samples matching the search query. outputs: - contextPath: Triage.samples.completed description: Date the sample analysis was completed. type: date - contextPath: Triage.samples.filename description: Name of the file submitted. type: string - contextPath: Triage.samples.id description: Unique identifier of the submission. type: string - contextPath: Triage.samples.kind description: Type of analysis. type: string - contextPath: Triage.samples.private description: If the submissions is private or publically viewable. type: boolean - contextPath: Triage.samples.status description: Status of the submitted file. type: string - contextPath: Triage.samples.submitted description: Date the sample was submitted. type: date - contextPath: Triage.samples.tasks.id description: Array of tasks that have been applied to the sample (static, behavioral, etc). type: string - contextPath: Triage.samples.tasks.status description: Status of the task. type: string - contextPath: Triage.samples.tasks.target description: Sample the task is being run on. type: string - contextPath: Triage.samples.url description: URL that was submitted. type: string - arguments: - name: profileID description: Unique identifier of the profile to delete. required: true name: triage-delete-profile description: Update the profile with the specified ID or name. The stored profile is overwritten, so it is important that the submitted profile has all fields, with the exception of the ID. dockerimage: demisto/python3:3.12.8.3296088 runonce: false script: '' subtype: python3 type: python tests: - No tests (auto formatted)