Phish.AI Deprecated

Deprecated. Vendor has declared end of life for this integration. No available replacement.

Data Enrichment & Threat Intelligence · Phish.AI (Deprecated)

Details

IDPhish.AI
ProviderPhishAI
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Supported ModulesAgentix

README

Closing the gap on traditional solutions, training, and talent with next-generation anti-phishing platform powered by AI & Computer Vision.

Configure Phish.AI on Cortex XSOAR

  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for Phish.AI.
  3. Click Add instance to create and configure a new integration instance.
    • Name: a textual name for the integration instance.
    • Private API Key (Optional) get it from My Profile on your Phish.AI Web URL
    • Use system proxy settings
  4. Click Test to validate the URLs, token, and connection.

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

1. Scan a URL


Checks if a URL is phishing, and returns details about the brand that is being phished.

Base Command

phish-ai-scan-url

Input
Argument Name Description Required
url The URL to check. Required

 

Context Output
Path Type Description
URL.Data string The URL address.
URL.Malicious.Vendor string For malicious URLs, the vendor that made the decision.
URL.Malicious.Description string For malicious URLs, the reason that the vendor made the decision.
DBotScore.Indicator string The indicator that was tested.
DBotScore.Type string The indicator type.
DBotScore.Vendor string The vendor used to calculate the score.
DBotScore.Score number The actual score.
IP.Address string The IP address of the URL.
IP.Geo.Country string The geo-location of the URL.
PhishAI.ScanID string The Phish AI scan ID.
PhishAI.Status string The status of the scan.
PhishAI.URL string The URL address.

 

Command Example
!phish-ai-scan url=www.demisto.com
Human Readable Output
phishaiscan

2. Check a URL status


Checks the status of a URL, for example, “completed” or “in progress”.

Base Command

phish-ai-check-status

Input
Argument Name Description Required
scan_id The scan ID of the URL to check the status of. You must replace the url argument with the scan_id argument in automations and playbooks. Backward compatibility is not supported. Required

 

Context Output
Path Type Description
URL.Data string The IP address of the URL.
PhishAI.Status string That status of the scan.
PhishAI.ScanID string The Phish.AI scan ID.

 

Command Example
!phish-ai-check-status scan_id="{CsFCgZ494mmW2JMI4hkK}"
Human Readable Output
phishaicheck

3. Dispute a scan result


Disputes the result of a scan.

Base Command

phish-ai-dispute-url

Input
Argument Name Description Required
scan_id The scan ID of the URL to dispute. Required

 

Context Output

There is no context output for this command.

Command Example
!phish-ai-dispute-url scan_id="CsFCgZ494mmW2JMI4hkK"
Human Readable Output
phishaidispute

Configuration parameters

  • apiKey — Private API Key (Optional)
  • proxy — Use system proxy settings

Commands (3)

  • phish-ai-check-status

    Checks on url's status, e.g. completed, in progress

  • phish-ai-dispute-url

    Dispute the result of the scan

  • phish-ai-scan-url

    Check if url is phishing and get details about the brand that is being phished

commonfields:
  id: Phish.AI
  version: -1
name: Phish.AI
display: Phish.AI (Deprecated)
deprecated: true
category: Data Enrichment & Threat Intelligence
provider: PhishAI
description: "Deprecated. Vendor has declared end of life for this integration. No available replacement."
fromversion: "5.0.0"
configuration:
- display: Private API Key (Optional)
  name: apiKey
  defaultvalue: ""
  type: 4
  required: false
- display: Use system proxy settings
  name: proxy
  defaultvalue: "false"
  type: 8
  required: false
script:
  script: ''
  type: javascript
  commands:
  - name: phish-ai-scan-url
    arguments:
    - name: url
      required: true
      description: url to check
    outputs:
    - contextPath: URL.Data
      description: URL address
      type: string
    - contextPath: URL.Malicious.Vendor
      description: For malicious URLs, the vendor that made the decision
      type: string
    - contextPath: URL.Malicious.Description
      description: For malicious URLs, the reason for the vendor to make the decision
      type: string
    - contextPath: DBotScore.Indicator
      description: The indicator we tested
      type: string
    - contextPath: DBotScore.Type
      description: The type of the indicator
      type: string
    - contextPath: DBotScore.Vendor
      description: Vendor used to calculate the score
      type: string
    - contextPath: DBotScore.Score
      description: The actual score
      type: number
    - contextPath: IP.Address
      description: IP address of the url
      type: string
    - contextPath: IP.Geo.Country
      description: Geo location of the url
      type: string
    - contextPath: PhishAI.ScanID
      description: Phish.AI scan ID
      type: string
    - contextPath: PhishAI.Status
      description: Scan status
      type: string
    - contextPath: PhishAI.URL
      description: URL address
      type: string
    description: Check if url is phishing and get details about the brand that is being phished
  - name: phish-ai-check-status
    arguments:
    - name: scan_id
      required: true
      description: Scan ID of the URL to check its status
    outputs:
    - contextPath: URL.Data
      description: URL's Address
      type: string
    - contextPath: PhishAI.Status
      description: Scan status
      type: string
    - contextPath: PhishAI.ScanID
      description: Phish.AI scan ID
      type: string
    description: Checks on url's status, e.g. completed, in progress
  - name: phish-ai-dispute-url
    arguments:
    - name: scan_id
      required: true
      description: Scan ID of the URL to dispute
    description: Dispute the result of the scan
tests:
- No tests