Joe Security Deprecated
Deprecated. Use Joe Security v2 instead.
Forensics & Malware Analysis · Joe Security
Details
| ID | Joe Security |
|---|---|
| Provider | Joe Security LLC |
| Category | Forensics & Malware Analysis |
| From Version | 5.0.0 |
| Docker Image | demisto/python:2.7.18.6174823 |
| Supported Modules | Agentix XSIAM EDR Cortex Cloud Cloud Runtime Security |
README
Overview
Use the Joe Security Sandbox integration to detect and analyze potentially malicious files.
Using the integration you can analyze URL links and sample files on different machine types (Windows, Android, iOS and Mac OS X).
All file types are supported.
This integration was integrated and tested with Joe Security v2.
Playbooks
- JoeSecurity -Detonate URL
- JoeSecurity -Detonate File
- JoeSecurity -Detonate File From URL
Use Cases
- Add a file to the integrations war room.
- Sample a file.
- Get information on an old analysis.
- Send a URL sample to Joe Security.
Prerequisites
Before you configure the integration, retrieve the API key from your Joe Security environment.
- Use this link to log in to the Joe Security platform.
- Click the button in the top-right corner and select Settings.
- In the API Key section, select the I Agree checkbox.
- Click the Generate API key button.
- Copy the API key for later use.
Configure the Joe Security Integration on Cortex XSOAR
- Navigate to Settings > Integrations > Servers & Services.
- Search for Joe Security.
- Click Add instance to create and configure a new integration instance.
- Name: A textual name for the integration instance.
- Joe Security URL: URL of the Joe Security server
- API Key
- Trust any certificate (not secure)
- Do not use by default
- Cortex XSOAR engine
- Click Test to validate the URLs and connection.
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
- Ping the server: joe-is-online
- Submit a URL for analysis: joe-analysis-submit-url
- Get analysis information: joe-analysis-info
- Get analyes list: joe-list-analysis
- Submit sample for analysis: joe-analysis-submit-sample
- Search Analyses: joe-search
- Download a report: joe-download-report
- Download analysis file: joe-download-sample
- Detonate a file: joe-detonate-file
- Detonate a URL: joe-detonate-url
Ping the server
Pings the Joe Security server to verify that it is responsive.
Base Command
joe-is-online
Input
There is no input for this command.
Context Data
There is no context data for this command.
Raw Output
There is not raw output for this command.
Submit a URL for analysis
Submits a URL to Joe Security for analysis.
Base Command
joe-analysis-submit-url
Input
| Parameter | Required | Description |
| url | Required | URL to submit for analysis. |
| should_wait | Optional | Specifies if the command polls for the result of the analysis. |
| comments | Optional | Comments for the analysis. |
| Systems | Optional |
Comma separated list of operating systems to run analysis on. Valid values are:
|
| internet-access | Optional |
If to enable full internet access (boolean). Default is True. |
Context Data
| Path | Type | Description |
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.FileName | String | Sample data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Time submitted |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 hash of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 has of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | String |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | SHA-1 hash of the file |
Raw Output
There is no raw output for this command.
Get analysis information
Returns information for a specified analysis.
Base Command
joe-analysis-info
Input
| Parameter | Required | Description |
| webId | Required | Web ID. Supports comma-separated arrays. |
Context Data
| Path | Type | Description |
|---|---|---|
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.SampleName | String | Sample Data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Submitted time |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 hash of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 hash of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | string |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | The SHA-1 hash of the file |
Raw Output
There is no raw output for this command.
Get analyses list
Returns a list of all analyses.
Base Command
joe-list-analysis
Input
There is no input for this command.
Context Data
| Path | Type | Description |
|---|---|---|
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.SampleName | String | Sample Data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Submitted time |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 hash of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 hash of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | String |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | The SHA-1 hash of the file |
Raw Output
There is no raw output for this command.
Submit sample for analysis
Submits a sample to Joe Security for analysis.
Base Command
joe-analysis-submit-sample
Input
| Parameter | Required | Description |
|---|---|---|
| file_id | Optional | War Room entry of a file (for example, 3245@4). |
| sample_url | Optional | URL of a sample file. Supports comma-seperated arrays. |
| should_wait | Optional | Specifies if the command polls for the result of the analysis |
| comments | Optional | Comments for the analysis |
| systems | Optional |
Comma separated list of operating systems to run analysis on. Valid values are:
|
| internet-access | Optional | Enable full internet access. Default is True. |
Context Data
| Path | Type | Description |
|---|---|---|
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.SampleName | String | Sample data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Submitted time |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 hash of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 hash of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | String |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | The SHA-1 hash of the file |
Raw Output
There is no raw output for this command.
Search Analyses
Search through all analyses in Joe Security.
Base Command
joe-search
Input
| Parameter | Description |
| query |
String to search for in these fields:
|
Context Data
| Path | Type | Description |
|---|---|---|
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.SampleName | String | Sample data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Submitted time |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 has of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 has of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | String |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | The SHA-1 hash of the file |
Raw Output
There is no raw output for this command.
Download a report
Downloads a resource associated to a report. This can be the full report, dropped binaries, and so on. See all supported report types here:
Base Command
joe-download-report
Input
| Parameter | Required | Description |
| webid | Required |
Web ID |
| type | Optional |
Resource type to download, default is html |
Context Data
| Path | Type | Description |
|---|---|---|
| InfoFile.Name | String | Name of the file |
| InfoFile.EntryID | String | The entry ID of the sample |
| InfoFile.Size | Number | The size of the file |
| InfoFile.Type | String | File type (for example, PE) |
| InfoFile.Info | String | Basic information about the file |
| File.Extension | String | File extension |
Raw Output
There is no raw output for this command.
Download analysis file
Downloads the sample file of an analysis. For security considerations, the extension is dontrun.
Base Command
joe-download-sample
Input
| Parameter | Required | Description |
| webid | Required |
Web ID |
Context Data
| Path | Type | Description |
|---|---|---|
| File.Size | Number | The size of the file |
| File.SHA1 | String | SHA-1 hash of the file |
| File.SHA256 | String | SHA-256 hash of the file |
| File.Name | String | The sample name |
| File.SSDeep | String | ssdeep hash of the file |
| File.EntryID | String | War room entry ID of the file |
| File.Info | String | Basic information of the file |
| File.Type | String | File type (for example PE) |
| File MD5 | String | MD5 hash of the file |
| File.Extension | String | File extension |
Raw Output
There is no raw output for this command.
Detonate a file
Submits a file for analysis.
Base Command
joe-detonate-file
Input
| Parameter | Required | Description |
|---|---|---|
| file_id | Optional | War room entry of a file (for example, 3245@4) |
| sample_url | Optional | URL of a sample file |
| comments | Optional | Comments for the analysis |
| systems | Optional |
Comma separated list of operating systems to run the analysis on. Valid values are:
|
| internet-access | Optional | If to enable full internet access. Default is True |
Context Data
| Path | Type | Description |
|---|---|---|
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.SampleName | String | Sample Data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Submission time |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 hash of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 hash of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | String |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | The SHA-1 has of the file |
Raw Output
There is no raw output for this command.
Detonate a URL
Submits a URL for analysis.
Base Command
joe-detonate-url
Input
| Parameter | Required | Description |
|---|---|---|
| url | Required | sample URL |
| comments | Optional | Comments for the analysis |
| systems | Optional |
Comma separated list of operating systems to run the analysis on. Valid values are:
|
| internet-access | Optional | If to enable full internet access. Default is True. |
Context Data
| Path | Type | Description |
|---|---|---|
| Joe.Analysis.WebID | String | Web ID |
| Joe.Analysis.SampleName | String | Sample data, could be a file name or URL |
| Joe.Analysis.Status | String | Analysis status |
| Joe.Analysis.Comments | String | Analysis comments |
| Joe.Analysis.Time | Date | Submission time |
| Joe.Analysis.Runs | Unknown | Sub-analysis information |
| Joe.Analysis.Result | String | Analysis results |
| Joe.Analysis.Errors | Unknown | Errors raised during sampling |
| Joe.Analysis.Systems | Unknown | Analysis operating system |
| Joe.Analysis.MD5 | String | MD5 hash of the analysis sample |
| Joe.Analysis.SHA1 | String | SHA-1 hash of the analysis sample |
| Joe.Analysis.SHA256 | String | SHA-256 hash of the analysis sample |
| DBotScore.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Indicator | Unknown | The name of the sample file or URL |
| DBotScore.Type | String |
url - for URL samples file - for anything not URL sample |
| DBotScore.Score | String |
Cortex XSOAR Dbot Score:
|
| DBotScore.Malicious.Vendor | String | The name of the vendor (JoeSecurity) |
| DBotScore.Malicious.Detections | String | The sub analysis detection statuses |
| DBotScore.Malicious.SHA1 | String | The SHA-1 hash of the file |
Raw Output
There is no raw output for this command.
Configuration parameters
url— Joe Security Url (required)api_key— API Key (required)insecure— Trust any certificate (not secure)maxpolls— Max. Polling Time (in seconds):verbose— Verbose (show log in case of error)proxy— Use system proxy settings
Commands (10)
-
joe-analysis-infoDeprecatedShow information about an analysis.
-
joe-analysis-submit-sampleDeprecatedSubmit a sample for analysis.
-
joe-analysis-submit-urlDeprecatedSubmit a url for analysis.
-
joe-detonate-fileDeprecatedSubmit a sample for analysis.
-
joe-detonate-urlDeprecatedSubmit a url for analysis.
-
joe-download-reportDeprecatedDownload a resource belonging to a report. This can be the full report, dropped binaries, etc. See integration README for the full supported report types.
-
joe-download-sampleDeprecatedDownload the sample file of an analysis. for security reasons, the extension will be "dontrun"
-
joe-is-onlineDeprecatedCheck if Joe Sandbox is online or in maintenance mode.
-
joe-list-analysisDeprecatedList all analyses.
-
joe-searchDeprecatedSearch through all analyses.
category: Forensics & Malware Analysis provider: Joe Security LLC commonfields: id: Joe Security version: -1 configuration: - defaultvalue: https://jbxcloud.joesecurity.org display: Joe Security Url name: url required: true type: 0 - display: API Key name: api_key required: true type: 4 - display: Trust any certificate (not secure) name: insecure type: 8 required: false - defaultvalue: '300' display: 'Max. Polling Time (in seconds):' name: maxpolls type: 0 required: false - display: Verbose (show log in case of error) name: verbose type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false description: Deprecated. Use Joe Security v2 instead. display: Joe Security (Deprecated) name: Joe Security script: commands: - deprecated: true description: Check if Joe Sandbox is online or in maintenance mode. name: joe-is-online - arguments: - default: true description: sample url name: url required: true - auto: PREDEFINED defaultValue: 'False' description: Should the command poll for the result of the analysis name: should_wait predefined: - 'True' - 'False' - description: 'Comments for the analysis ' name: comments - defaultValue: w7x64 description: 'Operating System to run analysis on(comma separated). possible values are: w7, w7x64, w7_1, w7_2, w7native, android2, android3, mac1, w7l, w7x64l, w10, android4, w7x64native, w7_3, w10native, android5native_1, w7_4, w7_5, w10x64, w7x64_hvm, android6, iphone1, w7_sec, macvm, w7_lang_packs, w7x64native_hvm, lnxubuntu1, lnxcentos1, android7_nougat' name: systems - auto: PREDEFINED defaultValue: 'True' description: Enable full internet access. Default is True name: internet-access predefined: - 'True' - 'False' deprecated: true description: Submit a url for analysis. name: joe-analysis-submit-url outputs: - contextPath: Joe.Analysis.ID description: Analysis ID. type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - arguments: - default: true description: sample url name: url required: true - description: 'Comments for the analysis ' name: comments - defaultValue: w7x64 description: 'Operating System to run analysis on(comma separated). possible values are: w7, w7x64, w7_1, w7_2, w7native, android2, android3, mac1, w7l, w7x64l, w10, android4, w7x64native, w7_3, w10native, android5native_1, w7_4, w7_5, w10x64, w7x64_hvm, android6, iphone1, w7_sec, macvm, w7_lang_packs, w7x64native_hvm, lnxubuntu1, lnxcentos1, android7_nougat' name: systems - auto: PREDEFINED defaultValue: 'True' description: Enable full internet access. Default is True name: internet-access predefined: - 'True' - 'False' deprecated: true description: Submit a url for analysis. name: joe-detonate-url outputs: - contextPath: Joe.Analysis.ID description: Analysis ID type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - arguments: - default: true description: Web IDs, supports comma-seperated arrays. isArray: true name: webid required: true deprecated: true description: Show information about an analysis. name: joe-analysis-info outputs: - contextPath: Joe.Analysis.ID description: Web ID type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - deprecated: true description: List all analyses. name: joe-list-analysis outputs: - contextPath: Joe.Analysis.ID description: Web ID type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - arguments: - default: true description: War Room entry of a file (for example, 3245@4) name: file_id - description: Url to a sample file, supports comma-seperated arrays name: sample_url - auto: PREDEFINED defaultValue: 'False' description: Should the command poll for the result of the analysis name: should_wait predefined: - 'True' - 'False' - description: Comments for the analysis name: comments - description: 'Operating System to run analysis on(comma separated). possible values are: w7, w7x64, w7_1, w7_2, w7native, android2, android3, mac1, w7l, w7x64l, w10, android4, w7x64native, w7_3, w10native, android5native_1, w7_4, w7_5, w10x64, w7x64_hvm, android6, iphone1, w7_sec, macvm, w7_lang_packs, w7x64native_hvm, lnxubuntu1, lnxcentos1, android7_nougat' name: systems - auto: PREDEFINED defaultValue: 'True' description: Enable full internet access. Default is True name: internet-access predefined: - 'True' - 'False' deprecated: true description: Submit a sample for analysis. name: joe-analysis-submit-sample outputs: - contextPath: Joe.Analysis.ID description: Web ID type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - arguments: - default: true description: Web ID name: webid required: true - auto: PREDEFINED defaultValue: html description: The resource type to download. Defaults to html. name: type predefined: - html - json - pcap - pdf - xml - iocjson deprecated: true description: Download a resource belonging to a report. This can be the full report, dropped binaries, etc. See integration README for the full supported report types. name: joe-download-report outputs: - contextPath: InfoFile.Name description: FileName type: string - contextPath: InfoFile.EntryID description: The EntryID of the report type: string - contextPath: InfoFile.Size description: File Size type: number - contextPath: InfoFile.Type description: File type e.g. "PE" type: string - contextPath: InfoFile.Info description: Basic information of the file type: string - contextPath: File.Extension description: File Extension type: string - arguments: - default: true description: War Room entry of a file (for example, 3245@4) name: file_id - description: Url to a sample file name: sample_url - description: Comments for the analysis name: comments - description: 'Operating System to run analysis on(comma separated). possible values are: w7, w7x64, w7_1, w7_2, w7native, android2, android3, mac1, w7l, w7x64l, w10, android4, w7x64native, w7_3, w10native, android5native_1, w7_4, w7_5, w10x64, w7x64_hvm, android6, iphone1, w7_sec, macvm, w7_lang_packs, w7x64native_hvm, lnxubuntu1, lnxcentos1, android7_nougat' name: systems - auto: PREDEFINED defaultValue: 'True' description: Enable full internet access. Default is True name: internet-access predefined: - 'True' - 'False' deprecated: true description: Submit a sample for analysis. name: joe-detonate-file outputs: - contextPath: Joe.Analysis.ID description: Web ID type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - arguments: - default: true description: 'Search string which will search in the following fields only: webid, md5, sha1, sha256, filename, URL, comments.' name: query required: true deprecated: true description: Search through all analyses. name: joe-search outputs: - contextPath: Joe.Analysis.ID description: Web ID type: string - contextPath: Joe.Analysis.SampleName description: Sample Data, could be a file name or URL type: string - contextPath: Joe.Analysis.Status description: Analysis Status type: string - contextPath: Joe.Analysis.Comments description: Analysis Comments type: string - contextPath: Joe.Analysis.Time description: Submitted Time type: date - contextPath: Joe.Analysis.Runs description: Sub-Analysis Information type: Unknown - contextPath: Joe.Analysis.Result description: Analysis Results type: string - contextPath: Joe.Analysis.Errors description: Raised errors during sampling type: Unknown - contextPath: Joe.Analysis.Systems description: Analysis OS type: Unknown - contextPath: Joe.Analysis.MD5 description: MD5 of analysis sample type: string - contextPath: Joe.Analysis.SHA1 description: SHA1 of analysis sample type: string - contextPath: Joe.Analysis.SHA256 description: SHA256 of analysis sample type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: Unknown - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file type: string - arguments: - default: true description: Web ID name: webid required: true deprecated: true description: Download the sample file of an analysis. for security reasons, the extension will be "dontrun" name: joe-download-sample outputs: - contextPath: File.Size description: File Size type: number - contextPath: File.SHA1 description: SHA1 hash of the file type: string - contextPath: File.SHA256 description: SHA256 hash of the file type: string - contextPath: File.Name description: The sample name type: string - contextPath: File.SSDeep description: SSDeep hash of the file type: string - contextPath: File.EntryID description: War-Room Entry ID of the file type: string - contextPath: File.Info description: Basic information of the file type: string - contextPath: File.Type description: File type e.g. "PE" type: string - contextPath: File MD5 description: MD5 hash of the file type: string - contextPath: File.Extension description: File Extension type: string runonce: false script: '-' type: python subtype: python2 dockerimage: demisto/python:2.7.18.6174823 tests: - No tests (deprecated) fromversion: 5.0.0 deprecated: true