MetaDefender Sandbox Deprecated
Deprecated. Use MetaDefender Aether instead.
Forensics & Malware Analysis · MetaDefender Sandbox (Deprecated)
Details
| ID | MetaDefender Sandbox |
|---|---|
| Provider | OPSWAT |
| Category | Forensics & Malware Analysis |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.8.3296088 |
README
Unique adaptive threat analysis technology, enabling zero-day malware detection and more Indicator of Compromise (IOCs) extraction. (previously known as OPSWAT Filescan Sandbox)
Configure MetaDefender Sandbox in Cortex
| Parameter | Required |
|---|---|
| Server URL (e.g. https://www.filescan.io/api) | True |
| API Key | True |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
| Verbose | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
metadefender-sandbox-scan-url
Scan URL with MetaDefender Sandbox
Note: MetaDefender Sandbox handles URL scanning as a file scan.
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
Base Command
metadefender-sandbox-scan-url
Input
| Argument Name | Description | Required |
|---|---|---|
| url | The URL to submit | Required |
| timeout | The timeout for the polling in seconds | Optional |
| hide_polling_output | Hide polling output | Optional |
| description | Uploaded file/url description | Optional |
| tags | Tags array to propagate | Optional |
| password | Custom password, in case uploaded archive is protected | Optional |
| is_private | If file should not be available for download by other users | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
| File.Name | String | The full file name. |
| File.SHA256 | String | The SHA256 hash of the file. |
| File.Malicious.Vendor | String | The vendor that reported the file as malicious. |
| MetaDefender.Sandbox.Analysis.finalVerdict.verdict | String | The final verdict. |
| MetaDefender.Sandbox.Analysis.allTags | Unknown | All tags. |
| MetaDefender.Sandbox.Analysis.overallState | String | Overall state of the scan. |
| MetaDefender.Sandbox.Analysis.taskReference.name | String | Name of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.additionalInfo | Unknown | Additional informations about the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.ID | String | ID of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.state | String | State of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.resourceReference | Unknown | Resource reference of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.opcount | Number | Counter. |
| MetaDefender.Sandbox.Analysis.taskReference.processTime | Number | processTime. |
| MetaDefender.Sandbox.Analysis.subtaskReferences | Unknown | Status of scan subtasks. |
| MetaDefender.Sandbox.Analysis.allSignalGroups | Unknown | All signal groups. |
| MetaDefender.Sandbox.Analysis.resources | Unknown | Resources. |
| MetaDefender.Sandbox.Analysis.file.name | String | The name of the file. |
| MetaDefender.Sandbox.Analysis.file.hash | String | The SHA256 of the file. |
| MetaDefender.Sandbox.Analysis.file.type | String | The type of the submission. |
Command example
!metadefender-sandbox-scan-url url=https://www.test.com
Context Example
{
{
"DBotScore":
[
{
"Indicator": "1111111111111111111111111111111111111111111111111111111111111111",
"Score": 1,
"Type": "file",
"Vendor": "MetaDefender Sandbox"
}
],
"File":
[
{
"Name": "https://www.test.com",
"SHA256": "1111111111111111111111111111111111111111111111111111111111111111"
}
],
"MetaDefender":
{
"Sandbox":
{
"Analysis":
[
{
"finalVerdict":
{
"verdict": "BENIGN"
},
"allTags":
[
{
"source": "MEDIA_TYPE",
"sourceIdentifier": "12345678",
"isRootTag": true,
"tag":
{
"name": "html",
"synonyms":
[],
"descriptions":
[],
"verdict":
{
"verdict": "NO_THREAT",
"threatLevel": 0.1,
"confidence": 1
}
}
}
],
"overallState": "success_partial",
"taskReference":
{
"name": "transform-file",
"additionalInfo":
{
"submitName": "https://www.test.com",
"submitTime": 1679014774270,
"digests":
{
"SHA-256": "1111111111111111111111111111111111111111111111111111111111111111"
}
},
"ID": "abcd-1234",
"state": "SUCCESS",
"resourceReference":
{
"type": "TRANSFORM_FILE",
"name": "file",
"ID": "abcd-5678"
},
"opcount": 1,
"processTime": 20350
},
"subtaskReferences":
[
{
"name": "domain-resolve",
"additionalInfo": 72,
"ID": "12345678",
"state": "SUCCESS",
"resourceReference":
{
"type": "DOMAIN_RESOLVE",
"name": "domain-resolve",
"ID": "123456789"
},
"opcount": 20,
"processTime": 11309
}
],
"allSignalGroups":
[
{
"identifier": "I000",
"description": "OSINT source detected malicious resource",
"averageSignalStrength": 0.75,
"peakSignalStrength": 0.75,
"finalSignalStrength": 0.75,
"verdict":
{
"verdict": "LIKELY_MALICIOUS",
"threatLevel": 0.75,
"confidence": 1
},
"allTags":
[],
"signals":
[
{
"strength": 0.75,
"isStrictlyBasedOnInputData": false,
"signalReadable": "OSINT provider TEST provider (2/93)",
"additionalInfo": "https://www.google.com",
"originPath": "osint.results.verdict",
"originType": "INPUT_FILE",
"originIdentifier": "1234"
}
]
}
],
"resources":
{
"00f1e4d6-27fb-45e8-8a02-dc53818044ec":
{
"resourceReference":
{
"name": "osint"
},
"results":
[]
}
},
"file":
{
"name": "https://www.test.com",
"hash": "1111111111111111111111111111111111111111111111111111111111111111",
"type": "other"
}
}
]
}
}
}
Human Readable Output
Scan Result (digest)
FileHash FileName FileType FinalVerdict SubtaskReferences Tags 1111111111111111111111111111111111111111111111111111111111111111 https://www.test.com other BENIGN osint, url-render, domain-resolve html, png
metadefender-sandbox-scan-file
Scan File with MetaDefender Sandbox
Base Command
metadefender-sandbox-scan-file
Input
| Argument Name | Description | Required |
|---|---|---|
| entry_id | he War Room entry ID of the file to submit | Required |
| timeout | The timeout for the polling in seconds | Optional |
| hide_polling_output | Hide polling output | Optional |
| description | Uploaded file/url description | Optional |
| tags | Tags array to propagate | Optional |
| password | Custom password, in case uploaded archive is protected | Optional |
| is_private | If file should not be available for download by other users | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
| File.Name | String | The full file name. |
| File.SHA256 | String | The SHA256 hash of the file. |
| File.Malicious.Vendor | String | The vendor that reported the file as malicious. |
| MetaDefender.Sandbox.Analysis.finalVerdict.verdict | String | The final verdict. |
| MetaDefender.Sandbox.Analysis.allTags | Unknown | All tags. |
| MetaDefender.Sandbox.Analysis.overallState | String | Overall state of the scan. |
| MetaDefender.Sandbox.Analysis.taskReference.name | String | Name of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.additionalInfo | Unknown | Additional informations about the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.ID | String | ID of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.state | String | State of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.resourceReference | Unknown | Resource reference of the main scan task. |
| MetaDefender.Sandbox.Analysis.taskReference.opcount | Number | Counter. |
| MetaDefender.Sandbox.Analysis.taskReference.processTime | Number | processTime. |
| MetaDefender.Sandbox.Analysis.subtaskReferences | Unknown | Status of scan subtasks. |
| MetaDefender.Sandbox.Analysis.allSignalGroups | Unknown | All signal groups. |
| MetaDefender.Sandbox.Analysis.resources | Unknown | Resources. |
| MetaDefender.Sandbox.Analysis.file.name | String | The name of the file. |
| MetaDefender.Sandbox.Analysis.file.hash | String | The SHA256 of the file. |
| MetaDefender.Sandbox.Analysis.file.type | String | The type of the submission. |
Command example
!metadefender-sandbox-scan-file entry_id=1234@abcd-efgh-ijkl-mnop-xyz
Context Example
{
{
"DBotScore":
[
{
"Indicator": "1111111111111111111111111111111111111111111111111111111111111111",
"Score": 1,
"Type": "file",
"Vendor": "MetaDefender Sandbox"
}
],
"File":
[
{
"Name": "1234@abcd-efgh-ijkl-mnop-xyz",
"SHA256": "1111111111111111111111111111111111111111111111111111111111111111"
}
],
"MetaDefender":
{
"Sandbox":
{
"Analysis":
[
{
"finalVerdict":
{
"verdict": "MALICIOUS"
},
"allTags":
[
{
"source": "SIGNAL",
"sourceIdentifier": "1234",
"isRootTag": false,
"tag":
{
"name": "packed",
"synonyms": [],
"descriptions": [],
"verdict": {
"verdict": "SUSPICIOUS",
"threatLevel": 0.5,
"confidence": 1
}
}
}
],
"overallState": "success_partial",
"taskReference":
{
"name": "transform-file",
"additionalInfo": {
"submitName": "bad_file.exe",
"submitTime": 1679011634945,
"digests": {
"SHA-256": "1111111111111111111111111111111111111111111111111111111111111111"
}
},
"ID": "1234",
"state": "SUCCESS",
"resourceReference": {
"type": "TRANSFORM_FILE",
"name": "file",
"ID": "0101010101"
},
"opcount": 1,
"processTime": 7180
},
"subtaskReferences":
[
{
"name": "domain-resolve",
"additionalInfo": 72,
"ID": "12345678",
"state": "SUCCESS",
"resourceReference":
{
"type": "DOMAIN_RESOLVE",
"name": "domain-resolve",
"ID": "123456789"
},
"opcount": 20,
"processTime": 11309
}
],
"allSignalGroups":
[
{
"identifier": "Y002",
"description": "Matched a malicious YARA rule",
"averageSignalStrength": 1,
"peakSignalStrength": 1,
"finalSignalStrength": 1,
"verdict": {
"verdict": "MALICIOUS",
"threatLevel": 1,
"confidence": 1
},
"allTags": [],
"signals": [
{
"strength": 1,
"isStrictlyBasedOnInputData": true,
"signalReadable": "Matched YARA with strength \"0.75\"",
"additionalInfo": "PUP_InstallRex_AntiFWb",
"originPath": "file.yaraMatches",
"originType": "INPUT_FILE",
"originIdentifier": "111111111111111111111111111"
}
]
}
],
"resources":
{
"00f1e4d6-27fb-45e8-8a02-dc53818044ec":
{
"resourceReference":
{
"name": "osint"
},
"results":
[]
}
},
"file":
{
"name": "1234@abcd-efgh-ijkl-mnop-xyz",
"hash": "1111111111111111111111111111111111111111111111111111111111111111",
"type": "other"
}
}
]
}
}
}
Human Readable Output
Scan Result (digest)
FileHash FileName FileType FinalVerdict SubtaskReferences Tags 1111111111111111111111111111111111111111111111111111111111111111 1234@abcd-efgh-ijkl-mnop-xyz pe MALICIOUS visualization, osint, domain-resolve html, peexe
metadefender-sandbox-search-query
Search for reports. Finds reports and uploaded files by various tokens.
Base Command
metadefender-sandbox-search-query
Input
| Argument Name | Description | Required |
|---|---|---|
| query | The query string | Required |
| limit | Number of total results. Maximum 50 | Optional |
| page | Page number, starting from 1 | Optional |
| page_size | The page size. Can be 5, 10 or 20 | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| MetaDefender.Sandbox.Analysis.id | String | The analysis id. |
| MetaDefender.Sandbox.Analysis.file.name | String | The name of the file. |
| MetaDefender.Sandbox.Analysis.file.sha256 | String | The SHA256 of the file. |
| MetaDefender.Sandbox.Analysis.verdict | String | The final verdict. |
| MetaDefender.Sandbox.Analysis.state | String | Overall state of the scan. |
| MetaDefender.Sandbox.Analysis.date | Date | The scan date. |
| MetaDefender.Sandbox.Analysis.file.mime_type | String | The file MimeType. |
| MetaDefender.Sandbox.Analysis.file.short_type | String | The type of the submission. |
| MetaDefender.Sandbox.Analysis.tags | Unknown | All tags. |
Command example
!metadefender-sandbox-search-query query="834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc"
Context Example
{
"MetaDefender":
{
"Sandbox":
{
"Analysis":
[
{
"id": "b4f92c03-0fc2-4a40-9d34-8f2b05dd240c",
"file": {
"name": "bad_file.exe",
"mime_type": "application/x-msdownload",
"short_type": "peexe",
"sha256": "834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc",
},
"state": "success",
"verdict": "malicious",
"tags": [
{
"source": "MEDIA_TYPE",
"sourceIdentifier": "834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc",
"isRootTag": true,
"tag": {
"name": "peexe",
"synonyms": [],
"descriptions": [],
"verdict": {
"verdict": "NO_THREAT",
"threatLevel": 0.1,
"confidence": 1
}
}
}
],
"date": "03/20/2023, 14:28:09"
}
]
}
}
}
Human Readable Output
Analysis Result
Id SampleName SHA256 Verdict State Date 8c38be8c-7cfd-4d64-be41-c98a795c9ce0 bad_file.exe 834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc MALICIOUS success_partial 03/14/2023, 15:07:07 e334d27f-e2b1-46c9-9936-7d3155eb3706 bad_file.exe 834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc UNKNOWN success 03/14/2020, 15:03:48
Configuration parameters
url— Server URL (e.g. https://www.filescan.io/api) (required)api_key— (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (3)
-
metadefender-sandbox-scan-fileScan file resource.
-
metadefender-sandbox-scan-urlScan URL resource.
-
metadefender-sandbox-search-querySearch for reports. Finds reports and uploaded files by various tokens.
from typing import Any from CommonServerPython import DemistoException import json import pytest import importlib MD_Sandbox = importlib.import_module("MetaDefenderSandbox") def util_load_json(path: str) -> Any: with open(path, encoding="utf-8") as f: return json.loads(f.read()) @pytest.fixture() def client(): return MD_Sandbox.Client(base_url="https://test.com", api_key="mockkey", proxy=False, verify=False) APIKEY_VALIDATION_SUCCESS = { "accountId": "1234", "username": "Aniko", "email": "aniko@o.com", } @pytest.mark.parametrize("result, expected", [(APIKEY_VALIDATION_SUCCESS, "ok")]) def test_test_module_positive(mocker, client, result, expected): mocker.patch.object(client, "test_module", return_value=result) response = MD_Sandbox.test_module_command(client) assert response == expected APIKEY_VALIDATION_FAILURE = {"detail": "Could not validate credentials"} @pytest.mark.parametrize("result, expected", [(APIKEY_VALIDATION_FAILURE, DemistoException)]) def test_test_module_negative(mocker, client, result, expected): mocker.patch.object(client, "test_module", return_value=result) with pytest.raises(Exception) as e: MD_Sandbox.test_module_command(client) assert isinstance(e.value, expected) def test_search_query_command_hash_badfile(mocker, client): raw_response = util_load_json("test_data/query_hash_badfile.json") mocker.patch.object(client, "get_search_query", return_value=raw_response) response = MD_Sandbox.search_query_command(client, {}) assert response.outputs[0]["file"]["sha256"] == "834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc" assert response.outputs[0]["verdict"] == "malicious" def test_search_query_command_hash_cleanfile(mocker, client): raw_response = util_load_json("test_data/query_hash_cleanfile.json") mocker.patch.object(client, "get_search_query", return_value=raw_response) response = MD_Sandbox.search_query_command(client, {}) assert response.outputs[0]["file"]["sha256"] == "a33a6ee82144b97bf75728a7ec302dd88ae2fa54389caeb8442839580b259b85" assert response.outputs[0]["verdict"] == "informational" def test_search_query_command_url(mocker, client): raw_response = util_load_json("test_data/query_url_google.json") mocker.patch.object(client, "get_search_query", return_value=raw_response) response = MD_Sandbox.search_query_command(client, {}) assert len(response.outputs) == 10 assert response.outputs[0]["file"]["sha256"] == "5302e0de83c841169f0543eaf5f9a2b7313d49d35d9f3ecbeed4e6b353b5a2c8" assert response.outputs[0]["verdict"] == "informational" assert response.outputs[1]["file"]["sha256"] == "3a136f9524a2a1235a8cdd1b9fb229e20a04c2788b58a58f6904e256fa1ba0c4" assert response.outputs[1]["verdict"] == "malicious" @pytest.mark.parametrize( "args, outputs", [ ({"limit": "-1"}, DemistoException), ({"limit": "100"}, DemistoException), ({"limit": "a"}, Exception), ({"page": "-1"}, DemistoException), ({"page": "a"}, Exception), ({"page_size": "1"}, DemistoException), ({"page_size": "a"}, Exception), ], ) def test_search_query_command_argument_check(mocker, client, args, outputs): mocker.patch.object(client, "get_search_query", return_value={}) with pytest.raises(Exception) as e: MD_Sandbox.search_query_command(client, args) assert isinstance(e.value, outputs) def test_scan_command_url_polling_waiting(requests_mock, mocker, client): from CommonServerPython import ScheduledCommand mocker.patch.object(client, "_http_request", return_value={"flow_id": "1234"}) mocker.patch.object(ScheduledCommand, "raise_error_if_not_supported", return_value=None) mocker.patch("builtins.open", create=True) args = { "entry_id": "test_entry_id", "description": "test_file", "tags": "tag1", "password": "pass1234", "is_private": True, } response = MD_Sandbox.scan_command(client, args) assert response.readable_output == 'Waiting for submission "1234" to finish...' def test_scan_command_url_polling(mocker, client): from CommonServerPython import ScheduledCommand args = {"url": "https://www.google.com"} raw_response = util_load_json("test_data/scan_command_url_response.json") mocker.patch.object(client, "_http_request", return_value={"flow_id": "1234"}) mocker.patch.object(ScheduledCommand, "raise_error_if_not_supported", return_value=None) response = MD_Sandbox.scan_command(client, args) assert response.readable_output == 'Waiting for submission "1234" to finish...' polling_args = { "flow_id": "1234", "hide_polling_output": True, "continue_to_poll": True, "url": "test.com", } mocker.patch.object(client, "get_scan_result", return_value=raw_response) response = MD_Sandbox.scan_command(client, polling_args) assert response[0].indicator.dbot_score.indicator == "ac6bb669e40e44a8d9f8f0c94dfc63734049dcf6219aac77f02edf94b9162c09" assert response[0].indicator.dbot_score.score == 1 assert response[0].indicator.dbot_score.integration_name == "MetaDefender Sandbox" assert response[0].indicator.name == "https://www.google.com" assert response[0].indicator.sha256 == "ac6bb669e40e44a8d9f8f0c94dfc63734049dcf6219aac77f02edf94b9162c09" assert response[0].outputs["finalVerdict"]["verdict"] == "BENIGN" assert len(response[0].outputs["allTags"]) == 2 assert response[0].outputs["overallState"] == "success_partial" assert response[0].outputs["taskReference"]["name"] == "transform-file" assert response[0].outputs["file"]["name"] == "https://www.google.com" assert response[0].outputs["file"]["hash"] == "ac6bb669e40e44a8d9f8f0c94dfc63734049dcf6219aac77f02edf94b9162c09" assert response[0].outputs["file"]["type"] == "other" def test_scan_command_file_polling(mocker, client): from CommonServerPython import ScheduledCommand args = {"entry_id": "test_entry_id"} raw_response = util_load_json("test_data/scan_command_zip_response.json") mocker.patch.object(client, "post_sample", return_value={"flow_id": "1234"}) mocker.patch.object(ScheduledCommand, "raise_error_if_not_supported", return_value=None) response = MD_Sandbox.scan_command(client, args) assert response.readable_output == 'Waiting for submission "1234" to finish...' polling_args = { "flow_id": "1234", "hide_polling_output": True, "continue_to_poll": True, "url": "test.com", } mocker.patch.object(client, "_http_request", return_value=raw_response) response = MD_Sandbox.scan_command(client, polling_args) assert len(response) == 3 assert response[0].indicator.dbot_score.indicator == "834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc" assert response[0].indicator.dbot_score.score == 3 assert response[0].indicator.dbot_score.integration_name == "MetaDefender Sandbox" assert response[0].indicator.name == "bad_file.exe" assert response[0].indicator.sha256 == "834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc" assert response[0].outputs["finalVerdict"]["verdict"] == "MALICIOUS" assert len(response[0].outputs["allTags"]) == 5 assert response[0].outputs["overallState"] == "success" assert response[0].outputs["taskReference"]["name"] == "transform-file" assert response[0].outputs["file"]["name"] == "bad_file.exe" assert response[0].outputs["file"]["hash"] == "834d1dbfab8330ea5f1844f6e905ed0ac19d1033ee9a9f1122ad2051c56783dc" assert response[0].outputs["file"]["type"] == "pe" assert response[1].indicator.dbot_score.indicator == "ede5221225a03b12d11df11f4babf24e9c4a55e05aff27612813dd44876a71c2" assert response[1].indicator.dbot_score.score == 1 assert response[1].indicator.dbot_score.integration_name == "MetaDefender Sandbox" assert response[1].indicator.name == "contract.docx" assert response[1].indicator.sha256 == "ede5221225a03b12d11df11f4babf24e9c4a55e05aff27612813dd44876a71c2" assert response[1].outputs["finalVerdict"]["verdict"] == "INFORMATIONAL" assert len(response[1].outputs["allTags"]) == 3 assert response[1].outputs["overallState"] == "success" assert response[1].outputs["taskReference"]["name"] == "transform-file" assert response[1].outputs["file"]["name"] == "contract.docx" assert response[1].outputs["file"]["hash"] == "ede5221225a03b12d11df11f4babf24e9c4a55e05aff27612813dd44876a71c2" assert response[1].outputs["file"]["type"] == "ms-office" assert response[2].indicator.dbot_score.indicator == "2ee79f9a52e660f2322985c72c9dffefdfb5a3c302576d61b4e629d049098cb5" assert response[2].indicator.dbot_score.score == 1 assert response[2].indicator.dbot_score.integration_name == "MetaDefender Sandbox" assert response[2].indicator.name == "poorguy.png" assert response[2].indicator.sha256 == "2ee79f9a52e660f2322985c72c9dffefdfb5a3c302576d61b4e629d049098cb5" assert response[2].outputs["finalVerdict"]["verdict"] == "INFORMATIONAL" assert len(response[2].outputs["allTags"]) == 1 assert response[2].outputs["overallState"] == "success" assert response[2].outputs["taskReference"]["name"] == "transform-file" assert response[2].outputs["file"]["name"] == "poorguy.png" assert response[2].outputs["file"]["hash"] == "2ee79f9a52e660f2322985c72c9dffefdfb5a3c302576d61b4e629d049098cb5" assert response[2].outputs["file"]["type"] == "other" def test_scan_command_file_polling_no_threat(mocker, client): from CommonServerPython import ScheduledCommand args = {"entry_id": "test_entry_id"} raw_response = util_load_json("test_data/scan_command_file_response.json") mocker.patch.object(client, "post_sample", return_value={"flow_id": "1234"}) mocker.patch.object(ScheduledCommand, "raise_error_if_not_supported", return_value=None) response = MD_Sandbox.scan_command(client, args) assert response.readable_output == 'Waiting for submission "1234" to finish...' polling_args = { "flow_id": "1234", "hide_polling_output": True, "continue_to_poll": True, "url": "test.com", } mocker.patch.object(client, "_http_request", return_value=raw_response) response = MD_Sandbox.scan_command(client, polling_args) assert response[0].indicator.dbot_score.indicator == "b280719e9f2dd010260e6a023e0d69c64fbee8b6cbb8669c722a1da8142d3325" assert response[0].indicator.dbot_score.score == 1 assert response[0].indicator.name == "gabi_bogre.png" assert response[0].outputs["finalVerdict"]["verdict"] == "NO_THREAT" def test_scan_command_file_invalid_password(mocker, client): from CommonServerPython import ScheduledCommand args = {"entry_id": "test_entry_id"} raw_response = util_load_json("test_data/scan_command_zip_invalid_pass.json") mocker.patch.object(client, "post_sample", return_value={"flow_id": "1234"}) mocker.patch.object(ScheduledCommand, "raise_error_if_not_supported", return_value=None) response = MD_Sandbox.scan_command(client, args) assert response.readable_output == 'Waiting for submission "1234" to finish...' polling_args = { "flow_id": "1234", "hide_polling_output": True, "continue_to_poll": True, "url": "test.com", } mocker.patch.object(client, "get_scan_result", return_value=raw_response) with pytest.raises(Exception) as e: MD_Sandbox.scan_command(client, polling_args) assert isinstance(e.value, DemistoException) def test_password_validator(): raw_response = util_load_json("test_data/scan_command_zip_valid_pass.json") is_valid = MD_Sandbox.is_valid_pass(raw_response) assert is_valid @pytest.mark.parametrize( "report, DBotScore", [ ( { "finalVerdict": { "verdict": "UNKNOWN", } }, 0, ), ( { "finalVerdict": { "verdict": "BENIGN", } }, 1, ), ( { "finalVerdict": { "verdict": "INFORMATIONAL", } }, 1, ), ( { "finalVerdict": { "verdict": "MALICIOUS", } }, 3, ), ( { "finalVerdict": { "verdict": "LIKELY_MALICIOUS", } }, 3, ), ( { "finalVerdict": { "verdict": "SUSPICIOUS", } }, 2, ), ( { "finalVerdict": { "verdict": "SOME_FANCY", } }, 0, ), ], ) def test_build_one_reputation_result(report, DBotScore): reputation_result = MD_Sandbox.build_one_reputation_result(report) score = reputation_result.indicator.dbot_score.score assert score == DBotScore