LastInfoSec

This integration allow to interact with the Gatewatcher LastInfoSec product via API.

Network Security · LastInfoSec

Details

IDLastInfoSec
ProviderGatewatcher
CategoryNetwork Security
From Version5.5.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

This integration allow to interact with the Gatewatcher LastInfoSec product via API.
This integration was integrated and tested with version 2 of LastInfoSec.

Configure LastInfoSec in Cortex

Parameter Description Required
LastInfoSec API token The API Key to use for connection True
Check the TLS certificate   False
Use system proxy settings   False
Integration Reliability Reliability of the source providing the intelligence data False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

gw-lis-get-by-minute


Retrieve the data from Gatewatcher CTI feed by minute.
Max 1440 minutes.

Base Command

gw-lis-get-by-minute

Input

Argument Name Description Required
Minute Number of minutes to get.
Max 1440 minutes.
Required
Categories Filter IoC by categories. Possible values are: phishing, malware, trojan, exploit, ransom, ransomware, tool, keylogger, agent, backdoor. Optional
Type Filter IoC by type. Possible values are: SHA1, SHA256, MD5, URL, Host. Optional
Mode Filter IoC by mode. Possible values are: detection, hunting. Optional
Risk Filter IoC by risk. Possible values are: Malicious, Suspicious, High suspicious. Optional
TLP Filter IoC by TLP. Possible values are: green, white. Optional

Context Output

Path Type Description
LIS.GetByMinute.Value String Value.

Command example

!gw-lis-get-by-minute Minute=10

Context Example

{
    "LIS": {
        "GetByMinute": [
            "http://103.182.16.23/900/HTMLcode.vbs",
            "http://103.182.16.23/900/i0ioi0iooioo0IOI0OIOIOiooioi00IOIoioioio0ioi0iOIOioiiOIoiOIOIOioIO0IOIO0.doc",
            "http://94.156.253.128/2144/io0Ioi0IOIOOIOi0i00ioioii0ioi0oiOII0OIO0OIOI0I0000%23%23%23%23%23%23%23%23%23%23%23%23%23%230000000%23%23%23%23%23%23%23%23%23%23%23%23%23%2300000000.doc",
        ]
    }
}

Human Readable Output

Get IoC by minute

Value
http://103.182.16.23/900/HTMLcode.vbs
http://103.182.16.23/900/i0ioi0iooioo0IOI0OIOIOiooioi00IOIoioioio0ioi0iOIOioiiOIoiOIOIOioIO0IOIO0.doc
http://94.156.253.128/2144/io0Ioi0IOIOOIOi0i00ioioii0ioi0oiOII0OIO0OIOI0I0000%23%23%23%23%23%23%23%23%23%23%23%23%23%230000000%23%23%23%23%23%23%23%23%23%23%23%23%23%2300000000.doc

gw-lis-get-by-value


Allows you to search for an IOC (url, hash, host) or a vulnerability in the Gatewatcher CTI database. If the data is known, only the IOC corresponding to the value will be returned.

Base Command

gw-lis-get-by-value

Input

Argument Name Description Required
Value Value to be search. Required

Context Output

Path Type Description
LIS.GetByValue.Categories String Categories.
LIS.GetByValue.Risk String Risk.
LIS.GetByValue.TLP String TLP.
LIS.GetByValue.Type String Type.
LIS.GetByValue.UsageMode String UsageMode.
LIS.GetByValue.Value String Value.
LIS.GetByValue.Vulnerabilities String Vulnerabilities.

Command example

!gw-lis-get-by-value Value="58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f"

Context Example

{
    "LIS": {
        "GetByValue": {
            "Categories": [
                "trojan",
                "malware",
                "agent"
            ],
            "Risk": "Suspicious",
            "TLP": "green",
            "Type": "SHA256",
            "UsageMode": "detection",
            "Value": "58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f",
            "Vulnerabilities": []
        }
    }
}

Human Readable Output

Get IoC corresponding to the value

Categories Risk TLP Type UsageMode Value Vulnerabilities
trojan,
malware,
agent
Suspicious green SHA256 detection 58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f  

gw-lis-leaked-email-by-domain


Allows you to search for leaked emails via a domain in Gatewatcher’s CTI database. If the data is found, a list of emails is returned. otherwise, nothing is returned.

Base Command

gw-lis-leaked-email-by-domain

Input

Argument Name Description Required
Domain domain to be searched. Required
After Only return emails that have leaked after this date (date format: 2023-01-15T10:00:00). Optional

Context Output

Path Type Description
LIS.LeakedEmail.GetByDomain String leaked emails.

Command example

!gw-lis-leaked-email-by-domain Domain=foobar.com

Context Example

{
    "LIS": {
        "LeakedEmail": {
            "GetByDomain": [
                "lucien@fr.foobar.com",
                "valerie@fr.foobar.com",
                "cyrille@nl.foobar.com",
                "patrique@us.foobar.com",
            ]
        }
    }
}

Human Readable Output

Leaked email

Emails
lucien@fr.foobar.com
valerie@fr.foobar.com
cyrille@nl.foobar.com
patrique@us.foobar.com

gw-lis-is-email-leaked


Allows you to search if a specific email was leaked in Gatewatcher’s CTI database. If the data is found, the email is returned. otherwise, nothing is returned.

Base Command

gw-lis-is-email-leaked

Input

Argument Name Description Required
Email email to be searched. Required
After Only return a value if the email has leaked after this date (date format: 2023-01-15T10:00:00). Optional

Context Output

Path Type Description
LIS.LeakedEmail.GetByEmail String leaked email.

Command example

!gw-lis-is-email-leaked Email=lucien@fr.foobar.com

Context Example

{
    "LIS": {
        "LeakedEmail": {
            "GetByEmail": "lucien@fr.foobar.com"
        }
    }
}

Human Readable Output

Is email leaked

Value
lucien@fr.foobar.com

url


search IOCs for URLs in Gatewatcher’s CTI database.

Base Command

url

Input

Argument Name Description Required
url list of URLs to search for, (comma separated values). Required

Context Output

Path Type Description
DBotScore.Indicator String The indicator that was tested.
DBotScore.Reliability String Reliability of the source providing the intelligence data.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
URL.Data String The URL.
URL.Description String Description of the URL.
URL.TrafficLightProtocol String TLP level.
LIS.URL.Categories String Categories matching this url.
LIS.URL.Risk String Risk associated to this URL.
LIS.URL.TLP String TLP level.
LIS.URL.UsageMode String Usage mode for LIS.
LIS.URL.Value String The URL.
LIS.URL.Vulnerabilities String Vulnerabilities associated to this URL.

Command example

!url url=http://217.196.96.84/WatchDog.exe

Context Example

{
    "DBotScore": {
        "Indicator": "http://217.196.96.84/WatchDog.exe",
        "Reliability": "B - Usually reliable",
        "Score": 2,
        "Type": "url",
        "Vendor": "LastInfoSec"
    },
    "LIS": {
        "URL": {
            "Categories": [
                "malware"
            ],
            "Risk": "Suspicious",
            "TLP": "green",
            "Type": "URL",
            "UsageMode": "detection",
            "Value": "http://217.196.96.84/WatchDog.exe",
            "Vulnerabilities": []
        }
    },
    "URL": {
        "Data": "http://217.196.96.84/WatchDog.exe",
        "Description": "'http://217.196.96.84/WatchDog.exe' is a Suspicious URL. It is linked to a PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows file with a size of 62.0322265625 KB.\nThis URL is linked to a malware attack.\nThe related TTP is: T1027.002 .\nWe advised to use this IoC in detection mode.",
        "TrafficLightProtocol": "green"
    }
}

Human Readable Output

Get IoC corresponding to the value

Categories Risk TLP Type UsageMode Value Vulnerabilities
malware Suspicious green URL detection http://217.196.96.84/WatchDog.exe  

file


search IOCs for file hashes in Gatewatcher’s CTI database.

Base Command

file

Input

Argument Name Description Required
file list of files to search for, (comma separated values). Required

Context Output

Path Type Description
DBotScore.Reliability String Reliability of the source providing the intelligence data.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
File.Hashes String List of hashes for this file.
File.Imphash String Imphash of the file.
File.SSDeep String SSDeep of the file.
File.TrafficLightProtocol String TLP level.
File.Type String Type of file.
File.MD5 String MD5 of the file.
File.SHA1 String SHA1 of the file.
File.SHA256 String SHA256 of the file.
File.SHA512 String SHA512 of the file.
LIS.File.Categories String Categories matching this file.
LIS.File.Risk String Risk associated to this file.
LIS.File.TLP String TLP level.
LIS.File.UsageMode String Usage mode for LIS.
LIS.File.Value String Hash of the file.
LIS.File.Vulnerabilities String Vulnerabilities associated to this file.
DBotScore.Indicator String The indicator that was tested.

Command example

!file file=58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f

Context Example

{
    "DBotScore": {
        "Indicator": "58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f",
        "Reliability": "B - Usually reliable",
        "Score": 2,
        "Type": "file",
        "Vendor": "LastInfoSec"
    },
    "File": {
        "Hashes": [
            {
                "type": "SHA256",
                "value": "58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f"
            },
            {
                "type": "SSDeep",
                "value": "1536:zhu9D+Oy/Dn/hP8PGTzBwZ6YWKSO5T3rZvSwEKSK99jzpma:zhu9WL/hEPeGU5S5TbZawEKSK99jVH"
            },
            {
                "type": "Imphash",
                "value": "3:rGsLdAIEK:tf"
            }
        ],
        "Imphash": "3:rGsLdAIEK:tf",
        "SHA256": "58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f",
        "SSDeep": "1536:zhu9D+Oy/Dn/hP8PGTzBwZ6YWKSO5T3rZvSwEKSK99jzpma:zhu9WL/hEPeGU5S5TbZawEKSK99jVH",
        "TrafficLightProtocol": "green",
        "Type": "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
    },
    "LIS": {
        "File": {
            "Categories": [
                "trojan",
                "malware",
                "agent"
            ],
            "Risk": "Suspicious",
            "TLP": "green",
            "Type": "SHA256",
            "UsageMode": "detection",
            "Value": "58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f",
            "Vulnerabilities": []
        }
    }
}

Human Readable Output

Get IoC corresponding to the value

Categories Risk TLP Type UsageMode Value Vulnerabilities
trojan,
malware,
agent
Suspicious green SHA256 detection 58b525579968cba0c68e8f7ae12e51e0b5542acc2c14a2e75fa6df44556e373f  

domain


search IOCs for domains in Gatewatcher’s CTI database.

Base Command

domain

Input

Argument Name Description Required
domain list of domains to search for, (comma separated values). Required

Context Output

Path Type Description
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.
DBotScore.Reliability String Reliability of the source providing the intelligence data.
Domain.Name String Domain found.
Domain.Description String description of the domain.
Domain.TrafficLightProtocol String TLP level.
LIS.Domain.Categories String Categories matching this domain.
LIS.Domain.Risk String Risk associated to this domain.
LIS.Domain.TLP String TLP level.
LIS.Domain.Type String Type of domain.
LIS.Domain.UsageMode String Usage mode for LIS.
LIS.Domain.Value String The domain name.
LIS.Domain.Vulnerabilities String Vulnerabilities associated to this domain.

Command example

!domain domain=kopabayport.co.tz

Context Example

{
    "DBotScore": {
        "Indicator": "kopabayport.co.tz",
        "Reliability": "B - Usually reliable",
        "Score": 2,
        "Type": "domain",
        "Vendor": "LastInfoSec"
    },
    "Domain": {
        "Description": "'kopabayport.co.tz' is a Suspicious Host.\nThis Host is linked to a malware attack.\nWe advised to use this IoC in detection mode.",
        "Name": "kopabayport.co.tz",
        "TrafficLightProtocol": "green"
    },
    "LIS": {
        "Domain": {
            "Categories": [
                "malware"
            ],
            "Risk": "Suspicious",
            "TLP": "green",
            "Type": "Host",
            "UsageMode": "detection",
            "Value": "kopabayport.co.tz",
            "Vulnerabilities": []
        }
    }
}

Human Readable Output

Get IoC corresponding to the value

Categories Risk TLP Type UsageMode Value Vulnerabilities
malware Suspicious green Host detection kopabayport.co.tz  

Configuration parameters

  • token — LastInfoSec API token (required)
  • check_cert — Check the TLS certificate
  • proxy — Use system proxy settings
  • integrationReliability — Integration Reliability

Commands (7)

  • domain

    search IOCs for domains in Gatewatcher's CTI database.

  • file

    search IOCs for file hashes in Gatewatcher's CTI database.

  • gw-lis-get-by-minute

    Retrieve the data from Gatewatcher CTI feed by minute. Max 1440 minutes.

  • gw-lis-get-by-value

    Allows you to search for an IOC (url, hash, host) or a vulnerability in the Gatewatcher CTI database. If the data is known, only the IOC corresponding to the value will be returned.

  • gw-lis-is-email-leaked

    Allows you to search if a specific email was leaked in Gatewatcher's CTI database. If the data is found, the email is returned. otherwise, nothing is returned.

  • gw-lis-leaked-email-by-domain

    Allows you to search for leaked emails via a domain in Gatewatcher's CTI database. If the data is found, a list of emails is returned. otherwise, nothing is returned.

  • url

    search IOCs for URLs in Gatewatcher's CTI database.

category: Network Security
provider: Gatewatcher
commonfields:
  id: LastInfoSec
  version: -1
configuration:
- additionalinfo: The API Key to use for connection
  display: LastInfoSec API token
  name: token
  required: true
  type: 4
- display: Check the TLS certificate
  name: check_cert
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
- name: integrationReliability
  display: Integration Reliability
  additionalinfo: Reliability of the source providing the intelligence data
  required: false
  type: 15
  options:
  - A+ - 3rd party enrichment
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
description: This integration allow to interact with the Gatewatcher LastInfoSec product via API.
display: LastInfoSec
name: LastInfoSec
script:
  commands:
  - arguments:
    - default: true
      description: |2-
         Number of minutes to get.
        Max 1440 minutes.
      name: Minute
      required: true
    - auto: PREDEFINED
      description: Filter IoC by categories.
      isArray: true
      name: Categories
      predefined:
      - phishing
      - malware
      - trojan
      - exploit
      - ransom
      - ransomware
      - tool
      - keylogger
      - agent
      - backdoor
    - auto: PREDEFINED
      description: Filter IoC by type.
      isArray: true
      name: Type
      predefined:
      - SHA1
      - SHA256
      - MD5
      - URL
      - Host
    - auto: PREDEFINED
      description: Filter IoC by mode.
      name: Mode
      predefined:
      - detection
      - hunting
    - auto: PREDEFINED
      description: Filter IoC by risk.
      isArray: true
      name: Risk
      predefined:
      - Malicious
      - Suspicious
      - High suspicious
    - auto: PREDEFINED
      description: Filter IoC by TLP.
      isArray: true
      name: TLP
      predefined:
      - green
      - white
    description: |-
      Retrieve the data from Gatewatcher CTI feed by minute.
      Max 1440 minutes.
    name: gw-lis-get-by-minute
    outputs:
    - contextPath: LIS.GetByMinute.Value
      description: Value.
      type: String
  - arguments:
    - default: true
      description: Value to be search.
      name: Value
      required: true
    description: Allows you to search for an IOC (url, hash, host) or a vulnerability in the Gatewatcher CTI database. If the data is known, only the IOC corresponding to the value will be returned.
    name: gw-lis-get-by-value
    outputs:
    - contextPath: LIS.GetByValue.Categories
      description: Categories.
      type: String
    - contextPath: LIS.GetByValue.Risk
      description: Risk.
      type: String
    - contextPath: LIS.GetByValue.TLP
      description: TLP.
      type: String
    - contextPath: LIS.GetByValue.Type
      description: Type.
      type: String
    - contextPath: LIS.GetByValue.UsageMode
      description: UsageMode.
      type: String
    - contextPath: LIS.GetByValue.Value
      description: Value.
      type: String
    - contextPath: LIS.GetByValue.Vulnerabilities
      description: Vulnerabilities.
      type: String
  - name: gw-lis-leaked-email-by-domain
    description: Allows you to search for leaked emails via a domain in Gatewatcher's CTI database. If the data is found, a list of emails is returned. otherwise, nothing is returned.
    arguments:
    - name: Domain
      description: domain to be searched.
      required: true
    - name: After
      description: "Only return emails that have leaked after this date (date format: 2023-01-15T10:00:00)."
      required: false
    outputs:
    - contextPath: LIS.LeakedEmail.GetByDomain
      description: leaked emails.
      type: String
  - name: gw-lis-is-email-leaked
    description: Allows you to search if a specific email was leaked in Gatewatcher's CTI database. If the data is found, the email is returned. otherwise, nothing is returned.
    arguments:
    - name: Email
      description: email to be searched.
      required: true
    - name: After
      description: "Only return a value if the email has leaked after this date (date format: 2023-01-15T10:00:00)."
      required: false
    outputs:
    - contextPath: LIS.LeakedEmail.GetByEmail
      description: leaked email.
      type: String
  - name: url
    description: search IOCs for URLs in Gatewatcher's CTI database.
    arguments:
    - name: url
      description: list of URLs to search for, (comma separated values).
      required: true
      isArray: true
      default: true
    outputs:
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: URL.Data
      description: The URL.
      type: String
    - contextPath: URL.Description
      description: Description of the URL.
      type: String
    - contextPath: URL.TrafficLightProtocol
      description: TLP level.
      type: String
    - contextPath: LIS.URL.Categories
      description: Categories matching this url.
      type: String
    - contextPath: LIS.URL.Risk
      description: Risk associated to this URL.
      type: String
    - contextPath: LIS.URL.TLP
      description: TLP level.
      type: String
    - contextPath: LIS.URL.UsageMode
      description: Usage mode for LIS.
      type: String
    - contextPath: LIS.URL.Value
      description: The URL.
      type: String
    - contextPath: LIS.URL.Vulnerabilities
      description: Vulnerabilities associated to this URL.
      type: String
  - name: file
    description: search IOCs for file hashes in Gatewatcher's CTI database.
    arguments:
    - name: file
      description: list of files to search for, (comma separated values).
      required: true
      isArray: true
    outputs:
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: File.Hashes
      description: List of hashes for this file.
      type: String
    - contextPath: File.Imphash
      description: Imphash of the file.
      type: String
    - contextPath: File.SSDeep
      description: SSDeep of the file.
      type: String
    - contextPath: File.TrafficLightProtocol
      description: TLP level.
      type: String
    - contextPath: File.Type
      description: Type of file.
      type: String
    - contextPath: File.MD5
      description: MD5 of the file.
      type: String
    - contextPath: File.SHA1
      description: SHA1 of the file.
      type: String
    - contextPath: File.SHA256
      description: SHA256 of the file.
      type: String
    - contextPath: File.SHA512
      description: SHA512 of the file.
      type: String
    - contextPath: LIS.File.Categories
      description: Categories matching this file.
      type: String
    - contextPath: LIS.File.Risk
      description: Risk associated to this file.
      type: String
    - contextPath: LIS.File.TLP
      description: TLP level.
      type: String
    - contextPath: LIS.File.UsageMode
      description: Usage mode for LIS.
      type: String
    - contextPath: LIS.File.Value
      description: Hash of the file.
      type: String
    - contextPath: LIS.File.Vulnerabilities
      description: Vulnerabilities associated to this file.
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
  - name: domain
    description: search IOCs for domains in Gatewatcher's CTI database.
    arguments:
    - name: domain
      description: list of domains to search for, (comma separated values).
      required: true
      isArray: true
    outputs:
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: Domain.Name
      description: Domain found.
      type: String
    - contextPath: Domain.Description
      description: description of the domain.
      type: String
    - contextPath: Domain.TrafficLightProtocol
      description: TLP level.
      type: String
    - contextPath: LIS.Domain.Categories
      description: Categories matching this domain.
      type: String
    - contextPath: LIS.Domain.Risk
      description: Risk associated to this domain.
      type: String
    - contextPath: LIS.Domain.TLP
      description: TLP level.
      type: String
    - contextPath: LIS.Domain.Type
      description: Type of domain.
      type: String
    - contextPath: LIS.Domain.UsageMode
      description: Usage mode for LIS.
      type: String
    - contextPath: LIS.Domain.Value
      description: The domain name.
      type: String
    - contextPath: LIS.Domain.Vulnerabilities
      description: Vulnerabilities associated to this domain.
      type: String
  dockerimage: demisto/python3:3.12.13.10116658
  runonce: false
  script: '-'
  subtype: python3
  type: python
  feed: false
  isfetch: false
  longRunning: false
  longRunningPort: false
tests:
- No tests (auto formatted)
fromversion: 5.5.0