PhishLabs IOC
Get indicators of compromise from PhishLabs.
Data Enrichment & Threat Intelligence · PhishLabs
Details
| ID | PhishLabs IOC |
|---|---|
| Provider | Fortra |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
PhishLabs’ three 24/7 Security Operations Centers enables enterprise security teams to rapidly detect and respond to the email-based threats that reach the inboxes of end users.
In Cortex XSOAR, PhishLabs IOC can be used to retrieve indicators from the global feed or fetch email based incidents from the user feed.
PhishLabs IOC Playbooks


Use Cases
- Retrieve and populate indicators from the PhishLabs IOC global feed
- Fetch and retrieve indicators for email based incidents in the PhishLabs IOC user feed
Configure PhishLabs IOC on Cortex XSOAR
- Navigate to Settings > Integrations > Servers & Services.
- Search for PhishLabs IOC.
- Click Add instance to create and configure a new integration instance.
- Name: a textual name for the integration instance.
- Server URL (e.g., https://ioc.phishlabs.com)
- Credentials
- Source Reliability. Reliability of the source providing the intelligence data. (The default value is: B - Usually reliable)
- Trust any certificate (not secure)
- Use system proxy settings
- Fetch incidents
- Fetch for this time period, e.g., “1d”, “1h”, “10m”. The default is 1h.
- Number of incidents to fetch each time
- Incident type
- Click Test to validate the URLs, token, and connection.
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
1. Get the global IOC feed
Retrieves the global IOC feed from PhishLabs.
Base Command
phishlabs-global-feed
Input
| Argument Name | Description | Required |
|---|---|---|
| since | Duration (from now) for which to pull updated data, for example, “1d”, “1h” or “10m”. | Optional |
| limit | Maximum number of results to return. | Optional |
| indicator_type | Filter the data by indicator type. | Optional |
| remove_protocol | Removes the protocol part from indicators, when the rule can be applied. | Optional |
| remove_query | Removes the query string part from indicators, when the rules can be applied. | Optional |
| false_positive | Whether the indicator is a false positive. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| URL.Data | String | URL address. |
| URL.Malicious.Vendor | String | Vendor reporting the malicious status. |
| URL.Malicious.Description | String | Description of the malicious URL. |
| PhishLabs.URL.Data | String | URL address. |
| PhishLabs.URL.ID | String | URL PhishLabs ID. |
| PhishLabs.URL.CreatedAt | Date | URL creation time, in PhishLabs. |
| PhishLabs.URL.UpdatedAt | Date | URL update time, in PhishLabs. |
| PhishLabs.URL.Attribute.Name | String | URL attribute name. |
| PhishLabs.URL.Attribute.Value | String | URL attribute value. |
| PhishLabs.URL.Attribute.CreatedAt | Date | URL attribute creation time. |
| PhishLabs.URL.FalsePositive | Boolean | Whether this URL is a false positive. |
| Domain.Name | String | Domain name. |
| Domain.Malicious.Vendor | String | Vendor reporting the malicious status. |
| Domain.Malicious.Description | String | Description of the malicious domain. |
| PhishLabs.Domain.Name | String | Domain name. |
| PhishLabs.Domain.ID | String | Domain PhishLabs ID. |
| PhishLabs.Domain.CreatedAt | Date | Domain creation time, in PhishLabs. |
| PhishLabs.Domain.UpdatedAt | Date | Domain update time, in PhishLabs. |
| PhishLabs.Domain.Attribute.Name | String | Domain attribute name. |
| PhishLabs.Domain.Attribute.Value | String | Domain attribute value. |
| PhishLabs.Domain.Attribute.CreatedAt | Date | Domain attribute creation time. |
| PhishLabs.Domain.FalsePositive | Boolean | Whether this domain is a false positive. |
| File.Name | String | Full filename. |
| File.MD5 | String | MD5 hash of the file. |
| File.Type | String | File type. |
| PhishLabs.File.ID | String | File PhishLabs ID. |
| PhishLabs.File.Name | String | Full filename. |
| PhishLabs.File.MD5 | String | MD5 hash of the file. |
| PhishLabs.File.Type | String | File type. |
| PhishLabs.File.CreatedAt | Date | File creation time, in PhishLabs. |
| PhishLabs.File.UpdatedAt | Date | File update time, in PhishLabs. |
| PhishLabs.File.Attribute.Name | String | File attribute name. |
| PhishLabs.File.Attribute.Value | String | File attribute value. |
| PhishLabs.File.Attribute.CreatedAt | Date | File attribute creation time. |
| PhishLabs.File.FalsePositive | Boolean | Whether this file is a false positive. |
| DBotScore.Indicator | string | The indicator that was tested. |
| DBotScore.Type | string | Indicator type. |
| DBotScore.Vendor | string | Vendor used to calculate the score. |
| DBotScore.Score | number | The actual score. |
Command Example
phishlabs-global-feed since=30d indicator_type=Domain remove_protocol=true limit=10
Context Example
{
"Domain": [
{
"Malicious": {
"Vendor": "PhishLabs",
"Description": "Domain in PhishLabs feed"
},
"Name": "malicious1.tk/"
},
{
"Malicious": {
"Vendor": "PhishLabs",
"Description": "Domain in PhishLabs feed"
},
"Name": "malicious2.tk/"
},
{
"Malicious": {
"Vendor": "PhishLabs",
"Description": "Domain in PhishLabs feed"
},
"Name": "malicious3.tk/"
},
{
"Malicious": {
"Vendor": "PhishLabs",
"Description": "Domain in PhishLabs feed"
},
"Name": "malicious4.com/"
}
],
"DBotScore": [
{
"type": "domain",
"Indicator": "malicious1.tk/",
"Score": 3,
"Vendor": "PhishLabs"
},
{
"type": "domain",
"Indicator": "malicious2.tk/",
"Score": 3,
"Vendor": "PhishLabs"
},
{
"type": "domain",
"Indicator": "malicious3.tk/",
"Score": 3,
"Vendor": "PhishLabs"
},
{
"type": "domain",
"Indicator": "malicious4.com/",
"Score": 3,
"Vendor": "PhishLabs"
}
],
"PhishLabs.Domain": [
{
"ID": "009d2062-bc79-4836-a649-80286612199e",
"CreatedAt": "2019-05-17T03:29:54Z",
"Name": "malicious1.tk/"
},
{
"ID": "80c16ebb-afe1-4898-91a6-c4b39d50a14f",
"CreatedAt": "2019-05-17T03:29:54Z",
"Name": "malicious2.tk/"
},
{
"ID": "a435f1e4-1e92-4921-8a5f-12bc1a7a67ce",
"CreatedAt": "2019-05-17T03:29:54Z",
"Name": "malicious3.tk/"
},
{
"ID": "f3923b6c-0445-40ef-998c-8cf57adb391d",
"CreatedAt": "2019-05-15T19:57:43Z",
"Name": "malicious4.com/"
}
]
}
Human Readable Output
PhishLabs Global Feed
| Indicator | Type | Created At | False Positive |
|---|---|---|---|
| malicious1.tk/ | Domain | 2019-05-17T03:29:54Z | false |
| malicious2.tk/ | Domain | 2019-05-17T03:29:54Z | false |
| malicious3.tk/ | Domain | 2019-05-17T03:29:54Z | false |
| malicious4.com/ | Domain | 2019-05-15T19:57:43Z | false |
2. Get indicators for an incident
Retrieves indicators from a specified PhishLabs incident. To fetch incidents to Cortex XSOAR, enable fetching incidents.
Base Command
phishlabs-get-incident-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | PhishLabs incident reference ID, for example, “INC123456”. | Required |
| since | Duration (from now) for which to pull updated data, for example, “1d”, “1h” or “10m”. | Optional |
| limit | Maximum number of results to return. | Optional |
| indicator_type | Filter the data by indicator type. | Optional |
| indicators_classification | How to classify indicators from the feed. | Optional |
| remove_protocol | Removes the protocol part from indicators, when the rule can be applied. | Optional |
| remove_query | Removes the query string part from indicators, when the rules can be applied. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| URL.Data | String | URL address. |
| URL.Malicious.Vendor | String | Vendor reporting the malicious status. |
| URL.Malicious.Description | String | Description of the malicious URL. |
| PhishLabs.URL.Data | String | URL address. |
| PhishLabs.URL.CreatedAt | Date | URL creation time, in PhishLabs |
| PhishLabs.URL.UpdatedAt | Date | URL update time, in PhishLabs. |
| PhishLabs.URL.Attribute.Name | String | URL attribute name. |
| PhishLabs.URL.Attribute.Value | String | URL attribute value. |
| PhishLabs.URL.Attribute.CreatedAt | Date | URL attribute creation time. |
| PhishLabs.URL.FalsePositive | Boolean | Whether this URL is a false positive. |
| Domain.Name | String | Domain name. |
| Domain.Malicious.Vendor | String | Vendor reporting the malicious status. |
| Domain.Malicious.Description | String | Description of the malicious domain. |
| PhishLabs.Domain.Name | String | Domain name |
| PhishLabs.Domain.CreatedAt | Date | Domain creation time, in PhishLabs. |
| PhishLabs.Domain.UpdatedAt | Date | Domain update time, in PhishLabs. |
| PhishLabs.Domain.Attribute.Name | String | Domain attribute name. |
| PhishLabs.Domain.Attribute.Value | String | Domain attribute value. |
| PhishLabs.Domain.Attribute.CreatedAt | Date | Domain attribute creation time. |
| PhishLabs.Domain.FalsePositive | Boolean | Whether this domain is a false positive. |
| Email.To | String | Recipient of the email. |
| Email.From | String | Sender of the email. |
| Email.Body | String | Body of the email. |
| Email.Subject | String | Subject of the email. |
| PhishLabs.Email.ID | String | Email PhishLabs ID. |
| PhishLabs.Email.To | String | Recipient of the email. |
| PhishLabs.Email.From | String | Sender of the email. |
| PhishLabs.Email.Body | String | Body of the email. |
| PhishLabs.Email.Subject | String | Subject of the email. |
| PhishLabs.Email.CreatedAt | Date | Email creation time, in PhishLabs. |
| PhishLabs.Email.UpdatedAt | Date | Email update time, in PhishLabs. |
| PhishLabs.Email.Attribute.Name | String | Email attribute name. |
| PhishLabs.Email.Attribute.Value | String | Email attribute value. |
| PhishLabs.Email.Attribute.CreatedAt | Date | Email attribute creation time. |
| File.Name | String | Full filename. |
| File.MD5 | String | MD5 hash of the file. |
| File.Type | String | File type. |
| PhishLabs.File.ID | String | File PhishLabs ID. |
| PhishLabs.File.Name | String | Full filename. |
| PhishLabs.File.MD5 | String | MD5 hash of the file. |
| PhishLabs.File.Type | String | File type. |
| PhishLabs.File.CreatedAt | Date | File creation time, in PhishLabs. |
| PhishLabs.File.UpdatedAt | Date | File update time, in PhishLabs. |
| PhishLabs.File.Attribute.Name | String | File attribute name. |
| PhishLabs.File.Attribute.Value | String | File attribute value. |
| PhishLabs.File.Attribute.CreatedAt | Date | File attribute creation time. |
| PhishLabs.File.FalsePositive | Boolean | Whether this file is a false positive. |
| DBotScore.Indicator | string | The indicator that was tested. |
| DBotScore.Type | string | Indicator type. |
| DBotScore.Vendor | string | Vendor used to calculate the score. |
| DBotScore.Score | number | The actual score. |
Command Example
phishlabs-get-incident-indicators incident_id=INC0037375 indicators_classification=Suspicious since=7d
Context Example
{
"URL": [
{
"Data": "https://malicious1?email=dbot@demisto.com"
},
{
"Data": "http://malicious2/index.html?l=_JeHFUq_VJOXK0QWHtoGYDw1774256418&fid.13InboxLight.aspxn.1774256418&fid.125289964252813InboxLight99642_Product-user&user=#dbot@demisto.com"
}
],
"PhishLabs.Email": [
{
"Body": "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\"><table border=\"0\" style=\"font-family: calibri; font-size: 16px; background-color: rgb(255, 255, 255);\" width=\"100%\">\n\t <tbody><tr><td align=\"center\">\n\t <table border=\"0\" cellpadding=\"0\" cellspacing=\"0\" height=\"100%\" style=\"min-width: 600px;\" width=\"100%\">\n\t <tbody><tr align=\"center\"><td>\n\t <table border=\"0\" cellpadding=\"0\" cellspacing=\"0\" style=\"max-width: 600px;\">\n\t <tbody><tr><td>\n <tbody></tbody></table></td></tr><tr height=\"16\"></tr><tr><td>\n <tbody><tr><td colspan=\"3\" height=\"69px\"> </td></tr><tr><td width=\"28px\"> </td>\n\t <td style=\"font-family: Roboto-Regular, Helvetica, Arial, sans-serif; font-size: 57px; color: rgb(255, 255, 255); line-height: 0.25;\">\n <span style=\"color:#f95316;\">Office-365 Password</span></a></td><td width=\"32px\"> </td></tr>\n <tr><td colspan=\"3\" height=\"18px\"> </td></tr></tbody></table></td></tr>\n <table bgcolor=\"#fff\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" style=\"min-width: 600px; max-width: 900px; border-width: 0px 1px 1px; border-right-style: solid; border-left-style: solid; border-right-color: rgb(240, 240, 240); border-left-color: rgb(240, 240, 240); border-bottom-style: solid; border-bottom-color: rgb(192, 192, 192); border-bottom-left-radius: 3px; border-bottom-right-radius: 3px;\" width=\"100%\">\n\t \n\n\t <tbody><tr height=\"16px\"><td rowspan=\"3\" width=\"32px\"> </td><td> </td>\n\t <td rowspan=\"3\" width=\"32px\"> </td></tr><tr><td><table border=\"0\" cellpadding=\"0\" cellspacing=\"0\" style=\"min-width: 300px;\">\n\t <tbody><tr><td style=\"font-family: Roboto-Regular, Helvetica, Arial, sans-serif; font-size: 13px; color: rgb(32, 32, 32); line-height: 1.5;\">\n <a href=\"https://bestiankelly.com/kp/index.php?email=dbot@demisto.com\" style=\"text-decoration: none;\">\n <span style=\"color:#f95316;\"> </span> .\n<br> <br>\n\n <a href=\"https://bestiankelly.com/kp/index.php?email=dbot@demisto.com\" style=\"text-decoration: none;\">\n <span style=\"color:#000000;\">\n Dear <b>dbot</b><div> </div>\n\n\n\t Your account password is due for expiration today\n<br><br>\t\n<body> Please kindly use the below to continue with same password.\n\n<body> \n<br>\n</head>\n<body style=\"margin: 0.4em;\">\n<p><font color=\"#ffffff\" size=\"4\" style=\"background-color: rgb(38, 136, 217);\"><u><strong>Keep Same password </strong></u></font></p>\n\n\n\n<br>\n \n<br>\n\t <p>Security Team <br></span></a><br> </p></td>\n\n </tr></tbody></table></td></tr></tbody></table></td></tr>\n\t <tr height=\"16\"></tr><tr><td style=\"max-width: 900px; font-family: Roboto-Regular, Helvetica, Arial, sans-serif; font-size: 10px; color: rgb(188, 188, 188); line-height: 1.5;\"> </td></tr><tr><td>\n <table style=\"font-family: Roboto-Regular, Helvetica, Arial, sans-serif; font-size: 10px; color: rgb(102, 102, 102); line-height: 18px; padding-bottom: 10px;\">\n\t <tbody><tr><td><span style=\"color:#424242;\">This notification was sent to <b>dbot@demisto.com</b> of Microsoft.com.</span></a></td></tr></tbody></table></td></tr></tbody></table></td>\n\t <td width=\"32px\"> </td></tr></tbody></table></td></tr></tbody>\n</table>",
"From": [
"Microsoft update <onme@www1079.sakura.ne.jp>"
],
"Attribute": [
{
"Value": "Microsoft update <onme@www1079.sakura.ne.jp>",
"Type": null,
"Name": "from",
"CreatedAt": "2019-05-23T16:56:59Z"
},
{
"Value": "<dbot@demisto.com>",
"Type": null,
"Name": "to",
"CreatedAt": "2019-05-23T16:56:59Z"
},
{
"Value": "<tbody><tr><td><span style=\"color:#424242;\">This notification was sent to <b>dbot@demisto.com</b> of Microsoft.com.</span></a></td></tr></tbody></table></td></tr></tbody></table></td>\n\t <td width=\"32px\"> </td></tr></tbody></table></td></tr></tbody>\n</table>",
"Type": null,
"Name": "email-body",
"CreatedAt": "2019-05-23T16:56:59Z"
}
],
"To": [
"<dbot@demisto.com>"
],
"ID": "cdb80cf5-d012-4b8d-86a7-7956ed026835",
"CreatedAt": "2019-05-23T16:56:59Z",
"Subject": "[[ Account Password Reset]]"
}
],
"DBotScore": [
{
"type": "url",
"Indicator": "malicious1?email=dbot@demisto.com",
"Score": 2,
"Vendor": "PhishLabs"
},
{
"type": "url",
"Indicator": "http://malicious2/index.html?l=_JeHFUq_VJOXK0QWHtoGYDw1774256418&fid.13InboxLight.aspxn.1774256418&fid.125289964252813InboxLight99642_Product-user&user=#dbot@demisto.com",
"Score": 2,
"Vendor": "PhishLabs"
}
],
"Email": [
{
"Body": " <tbody><tr><td><span style=\"color:#424242;\">This notification was sent to <b>dbot@demisto.com</b> of Microsoft.com.</span></a></td></tr></tbody></table></td></tr></tbody></table></td>\n\t <td width=\"32px\"> </td></tr></tbody></table></td></tr></tbody>\n</table>",
"To": "<dbot@demisto.com>",
"From": "Microsoft update <onme@www1079.sakura.ne.jp>",
"Subject": "[[ Account Password Reset]]"
}
],
"PhishLabs.URL": [
{
"Data": "https://malicious1/index.php?email=dbot@demisto.com",
"ID": "04e38909-53d8-4e4a-8593-8d1fd5a10261",
"CreatedAt": "2019-05-23T16:56:59Z"
},
{
"Data": "http://malicious2/index.html?l=_JeHFUq_VJOXK0QWHtoGYDw1774256418&fid.13InboxLight.aspxn.1774256418&fid.125289964252813InboxLight99642_Product-user&user=#dbot@demisto.com",
"ID": "354bbeb8-9fea-4ccd-85bb-ce68cd364113",
"CreatedAt": "2019-05-23T16:56:59Z"
}
]
}
Human Readable Output
Indicators for incident INC0037375
Indicator
| Indicator | Type | Created At | False Positive |
|---|---|---|---|
| malicious1/index.php?email=dbot@demisto.com | URL | 2019-05-23T16:56:59Z | false |
No attributes for this indicator
Indicator
| Indicator | Type | Created At | False Positive |
|---|---|---|---|
| malicious2/index.html?l=_JeHFUq_VJOXK0QWHtoGYDw1774256418&fid.13InboxLight.aspxn.1774256418&fid.125289964252813InboxLight99642_Product-user&user=#dbot@demisto.com | URL | 2019-05-23T16:56:59Z | false |
No attributes for this indicator
Indicator
| Indicator | Type | Created At | False Positive |
|---|---|---|---|
| [[ Account Password Reset]] | 2019-05-23T16:56:59Z | false |
Attributes
| Name | Value | Created At |
|---|---|---|
| from | Microsoft update onme@www1079.sakura.ne.jp | 2019-05-23T16:56:59Z |
| to | dbot@demisto.com | 2019-05-23T16:56:59Z |
| email-body | ||
| This notification was sent to dbot@demisto.comof Microsoft.com. |
2019-05-23T16:56:59Z
Additional Information
The IOC feed in PhishLabs is divided into two endpoints:
Global Feed
This is the PhishLabs global database for malicious indicators.
This feed consists of indicators that are classified as malicious by PhishLabs -
URLs, domains, and attachments (MD5 hashes). All the indicators from this feed are classified as malicious in Cortex XSOAR.
To populate indicators from PhishLabs in Cortex XSOAR, use the PhishLabsPopulateIndicators script/playbooks.
User Feed
This feed is exclusive for the user and consists of emails that were sent to PhishLabs and were classified as malicious emails. For each malicious email, an incident is created that contains the email details and the extracted indicators. These indicators are not necessarily malicious though. In Cortex XSOAR,
the user can choose whether to classify those indicators as malicious or suspicious. Incidents can be fetched by enabling fetch incidents in the integration configuration.
Known Limitations
The PhishLabs IOC API is on version 0.1.0, it may be subject to change.
Troubleshooting
Retrieving indicators for an incident - if the incident was fetched to Cortex XSOAR but wasn’t found by the command, try running it with a longer duration, for example, since=30d.
Possible error codes from the API:
400 Bad Request - Unsupported request format
401 Unauthorized - Incorrect credentials provided
403 Forbidden - Insufficient permissions
404 Not Found - Requested resource was not found
.
Configuration parameters
url— Server URL (e.g., https://ioc.phishlabs.com) (required)credentials— Username (required)integrationReliability— Source Reliability (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsisFetch— Fetch incidentsfetch_time— Fetch for this time period, e.g., "1d", "1h", "10m". The default is 1h.fetch_limit— Number of incidents to fetch each timeincidentType— Incident typeincidentFetchInterval— Incidents Fetch Interval
Commands (2)
-
phishlabs-get-incident-indicatorsRetrieves indicators from a speicifed PhishLabs incident. To fetch incidents to Demisto, enable fetching incidents.
-
phishlabs-global-feedRetrieves the global IOC feed from PhishLabs.
category: Data Enrichment & Threat Intelligence sectionorder: - Connect - Collect provider: Fortra commonfields: id: PhishLabs IOC version: -1 configuration: - defaultvalue: https://ioc.phishlabs.com display: Server URL (e.g., https://ioc.phishlabs.com) name: url required: true type: 0 section: Connect - display: Username name: credentials required: true type: 9 section: Connect - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - defaultvalue: 1h display: Fetch for this time period, e.g., "1d", "1h", "10m". The default is 1h. name: fetch_time type: 0 required: false section: Collect - defaultvalue: '10' display: Number of incidents to fetch each time name: fetch_limit type: 0 required: false section: Collect - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 advanced: true section: Collect description: Get indicators of compromise from PhishLabs. display: PhishLabs IOC name: PhishLabs IOC script: commands: - arguments: - defaultValue: 1h description: Duration (from now) for which to pull updated data, for example, "1d", "1h" or "10m". name: since - description: Maximum number of results to return. name: limit - auto: PREDEFINED description: Filter the data by indicator type. name: indicator_type predefined: - Domain - Attachment - URL - auto: PREDEFINED defaultValue: 'false' description: Removes the protocol part from indicators, when the rule can be applied. name: remove_protocol predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: 'false' description: Removes the query string part from indicators, when the rules can be applied. name: remove_query predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: 'false' description: Whether the indiciator is a false postive. name: false_positive predefined: - 'false' - 'true' description: Retrieves the global IOC feed from PhishLabs. name: phishlabs-global-feed outputs: - contextPath: URL.Data description: URL address. type: String - contextPath: URL.Malicious.Vendor description: Vendor reporting the malicious status. type: String - contextPath: URL.Malicious.Description description: Description of the malicious URL. type: String - contextPath: PhishLabs.URL.Data description: URL address. type: String - contextPath: PhishLabs.URL.ID description: URL PhishLabs ID. type: String - contextPath: PhishLabs.URL.CreatedAt description: URL creation time, in PhishLabs. type: Date - contextPath: PhishLabs.URL.UpdatedAt description: URL update time, in PhishLabs. type: Date - contextPath: PhishLabs.URL.Attribute.Name description: URL attribute name. type: String - contextPath: PhishLabs.URL.Attribute.Value description: URL attribute value. type: String - contextPath: PhishLabs.URL.Attribute.CreatedAt description: URL attribute creation time. type: Date - contextPath: PhishLabs.URL.FalsePositive description: Whether this URL is a false positive. type: Boolean - contextPath: Domain.Name description: Domain name. type: String - contextPath: Domain.Malicious.Vendor description: Vendor reporting the malicious status. type: String - contextPath: Domain.Malicious.Description description: Description of the malicious domain. type: String - contextPath: PhishLabs.Domain.Name description: Domain name. type: String - contextPath: PhishLabs.Domain.ID description: Domain PhishLabs ID. type: String - contextPath: PhishLabs.Domain.CreatedAt description: Domain creation time, in PhishLabs. type: Date - contextPath: PhishLabs.Domain.UpdatedAt description: Domain update time, in PhishLabs. type: Date - contextPath: PhishLabs.Domain.Attribute.Name description: Domain attribute name. type: String - contextPath: PhishLabs.Domain.Attribute.Value description: Domain attribute value. type: String - contextPath: PhishLabs.Domain.Attribute.CreatedAt description: Domain attribute creation time. type: Date - contextPath: PhishLabs.Domain.FalsePositive description: Whether this domain is a false positive. type: Boolean - contextPath: File.Name description: Full filename. type: String - contextPath: File.MD5 description: MD5 hash of the file. type: String - contextPath: File.Type description: File type. type: String - contextPath: PhishLabs.File.ID description: File PhishLabs ID. type: String - contextPath: PhishLabs.File.Name description: Full filename. type: String - contextPath: PhishLabs.File.MD5 description: MD5 hash of the file. type: String - contextPath: PhishLabs.File.Type description: File type. type: String - contextPath: PhishLabs.File.CreatedAt description: File creation time, in PhishLabs. type: Date - contextPath: PhishLabs.File.UpdatedAt description: File update time, in PhishLabs. type: Date - contextPath: PhishLabs.File.Attribute.Name description: File attribute name. type: String - contextPath: PhishLabs.File.Attribute.Value description: File attribute value. type: String - contextPath: PhishLabs.File.Attribute.CreatedAt description: File attribute creation time. type: Date - contextPath: PhishLabs.File.FalsePositive description: Whether this file is a false positive. type: Boolean - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: Indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - default: true description: PhishLabs incident reference ID, for example, "INC123456". name: incident_id required: true - defaultValue: 1h description: Duration (from now) for which to pull updated data, for example, "1d", "1h" or "10m". name: since - description: Maximum number of results to return. name: limit - auto: PREDEFINED description: Filter the data by indicator type. name: indicator_type predefined: - E-mail - Domain - URL - Attachment - auto: PREDEFINED defaultValue: Suspicious description: How to classify indicators from the feed. name: indicators_classification predefined: - Malicious - Suspicious - auto: PREDEFINED defaultValue: 'false' description: Removes the protocol part from indicators, when the rule can be applied. name: remove_protocol predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: 'false' description: Removes the query string part from indicators, when the rules can be applied. name: remove_query predefined: - 'true' - 'false' description: Retrieves indicators from a speicifed PhishLabs incident. To fetch incidents to Demisto, enable fetching incidents. name: phishlabs-get-incident-indicators outputs: - contextPath: URL.Data description: URL address. type: String - contextPath: URL.Malicious.Vendor description: Vendor reporting the malicious status. type: String - contextPath: URL.Malicious.Description description: Description of the malicious URL. type: String - contextPath: PhishLabs.URL.Data description: URL address. type: String - contextPath: PhishLabs.URL.CreatedAt description: URL creation time, in PhishLabs. type: Date - contextPath: PhishLabs.URL.UpdatedAt description: URL update time, in PhishLabs. type: Date - contextPath: PhishLabs.URL.Attribute.Name description: URL attribute name. type: String - contextPath: PhishLabs.URL.Attribute.Value description: URL attribute value. type: String - contextPath: PhishLabs.URL.Attribute.CreatedAt description: URL attribute creation time. type: Date - contextPath: PhishLabs.URL.FalsePositive description: Whether this URL is a false positive. type: Boolean - contextPath: Domain.Name description: Domain name. type: String - contextPath: Domain.Malicious.Vendor description: Vendor reporting the malicious status. type: String - contextPath: Domain.Malicious.Description description: Description of the malicious domain. type: String - contextPath: PhishLabs.Domain.Name description: Domain name. type: String - contextPath: PhishLabs.Domain.CreatedAt description: Domain creation time, in PhishLabs. type: Date - contextPath: PhishLabs.Domain.UpdatedAt description: Domain update time, in PhishLabs. type: Date - contextPath: PhishLabs.Domain.Attribute.Name description: Domain attribute name. type: String - contextPath: PhishLabs.Domain.Attribute.Value description: Domain attribute value. type: String - contextPath: PhishLabs.Domain.Attribute.CreatedAt description: Domain attribute creation time. type: Date - contextPath: PhishLabs.Domain.FalsePositive description: Whether this domain is a false positive. type: Boolean - contextPath: Email.To description: Recipient of the email. type: String - contextPath: Email.From description: Sender of the email. type: String - contextPath: Email.Body description: Body of the email. type: String - contextPath: Email.Subject description: Subject of the email. type: String - contextPath: PhishLabs.Email.ID description: Email PhishLabs ID. type: String - contextPath: PhishLabs.Email.To description: Recipient of the email. type: String - contextPath: PhishLabs.Email.From description: Sender of the email. type: String - contextPath: PhishLabs.Email.Body description: Body of the email. type: String - contextPath: PhishLabs.Email.Subject description: Subject of the email. type: String - contextPath: PhishLabs.Email.CreatedAt description: Email creation time, in PhishLabs. type: Date - contextPath: PhishLabs.Email.UpdatedAt description: Email update time, in PhishLabs. type: Date - contextPath: PhishLabs.Email.Attribute.Name description: Email attribute name. type: String - contextPath: PhishLabs.Email.Attribute.Value description: Email attribute value. type: String - contextPath: PhishLabs.Email.Attribute.CreatedAt description: Email attribute creation time. type: Date - contextPath: File.Name description: Full filename. type: String - contextPath: File.MD5 description: MD5 hash of the file. type: String - contextPath: File.Type description: File type. type: String - contextPath: PhishLabs.File.ID description: File PhishLabs ID. type: String - contextPath: PhishLabs.File.Name description: Full filename. type: String - contextPath: PhishLabs.File.MD5 description: MD5 hash of the file. type: String - contextPath: PhishLabs.File.Type description: File type. type: String - contextPath: PhishLabs.File.CreatedAt description: File creation time, in PhishLabs. type: Date - contextPath: PhishLabs.File.UpdatedAt description: File update time, in PhishLabs. type: Date - contextPath: PhishLabs.File.Attribute.Name description: File attribute name. type: String - contextPath: PhishLabs.File.Attribute.Value description: File attribute value. type: String - contextPath: PhishLabs.File.Attribute.CreatedAt description: File attribute creation time. type: Date - contextPath: PhishLabs.File.FalsePositive description: Whether this file is a false positive. type: Boolean - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: Indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number dockerimage: demisto/python3:3.12.13.10116658 isfetch: true runonce: false script: '-' subtype: python3 type: python tests: - PhishLabsIOC TestPlaybook fromversion: 5.0.0