SOCRadarThreatFusion
Enrich indicators by obtaining enhanced information and reputation via ThreatFusion of SOCRadar.
Data Enrichment & Threat Intelligence · SOCRadar
Details
| ID | SOCRadarThreatFusion |
|---|---|
| Provider | SOCRadar |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Enrich indicators by obtaining enhanced information and reputation via ThreatFusion of SOCRadar.
This integration was integrated and tested with v21.11 of SOCRadar.
Configure SOCRadarThreatFusion on Cortex XSOAR
- Navigate to Settings > Integrations > Servers & Services.
- Search for SOCRadarThreatFusion.
-
Click Add instance to create and configure a new integration instance.
Parameter Description Required API Key The API Key to use for connection to SOCRadar ThreatFusion API. True insecure Trust any certificate (not secure). False proxy Whether to use XSOAR’s system proxy settings to connect to the API. False - Click Test to validate API key and connection to SOCRadar ThreatFusion API.
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
How to obtain SOCRadar ThreatFusion API key?
To obtain your SOCRadar ThreatFusion API key please contact with the SOCRadar operation team via operation@socradar.io
After obtaining the SOCRadar ThreatFusion API key insert it into API Key field and start using the SOCRadar ThreatFusion integration by creating the instance.
ip
Scores provided IP entities’ reputation in SOCRadar ThreatFusion.
Base Command
ip
Input
| Argument Name | Description | Required |
|---|---|---|
| ip | IP entities to score. (IPv4 or IPv6). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarThreatFusion.Reputation.IP.Risk Score | Number | Reputation score of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Score Details | JSON | Risk score details of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Total Encounters | Number | Number of times that SOCRadar has encountered with the queried IP address in its threat sources. |
| SOCRadarThreatFusion.Reputation.IP.IP | String | Queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn | String | ASN field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_cidr | String | ASN CIDR field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_country_code | String | ASN country code field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_date | Date | ASN date field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_description | String | ASN description field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_registry | String | ASN registry field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.address | String | Nets>address field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.cidr | String | Nets>CIDR field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.city | String | Nets>city field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.country | String | Nets>country field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.created | String | Nets>created field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.description | String | Nets>description field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.emails | String | Nets>emails field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.handle | String | Nets>handle field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.name | String | Nets>name field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.postal_code | Number | Nets>postal code field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.range | String | Nets>range field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.state | String | Nets>state field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.updated | Date | Nets>updated field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nir | String | NIR field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.query | String | Query field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.raw_referral | String | Raw referral field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.referral | String | Referral field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.DNS Details | JSON | DNS information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.ASN | Number | ASN field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnCode | Number | ASN code field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnName | String | ASN name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Cidr | String | CIDR field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.CityName | String | City name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryCode | String | Country code field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryName | String | Country name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Latitude | Number | Latitude field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Longitude | Number | Longitude field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.RegionName | String | Region name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Timezone | String | Timezone field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.ZipCode | String | Zip code field Geographical location information of queried IP address. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| IP.Address | String | IP address |
| IP.ASN | String | The autonomous system name for the IP address, for example: “AS8948”. |
| IP.Geo.Location | String | The geolocation where the IP address is located, in the format: latitude:longitude. |
| IP.Geo.Country | String | The country in which the IP address is located. |
Command Example
!ip ip="1.1.1.1"
Context Example
{
"DBotScore": {
"Indicator": "1.1.1.1",
"Score": 1,
"Type": "ip",
"Vendor": "SOCRadar ThreatFusion"
},
"IP": {
"ASN": "[13335] CLOUDFLARENET, US",
"Address": "1.1.1.1",
"Geo": {
"Country": "US",
"Location": "0.0:0.0"
},
"Region": "California"
},
"SOCRadarThreatFusion": {
"Reputation": {
"IP": {
"DNS Details": {
"PTR": [
"one.one.one.one"
]
},
"Geo Location": {
"ASN": "[13335] CLOUDFLARENET, US",
"AsnCode": 13335,
"AsnName": "CloudFlare Inc",
"Cidr": "1.1.1.0/24",
"CityName": "Los Angeles",
"CountryCode": "US",
"CountryName": "United States of America",
"Latitude": 0.0,
"Longitude": 0.0,
"RegionName": "California",
"Timezone": "-07:00",
"ZipCode": "90001"
},
"IP": "1.1.1.1",
"Risk Score (Out of 1000)": 0,
"Score Details": {},
"Total Encounters": 0,
"Whois Details": {
"asn": "13335",
"asn_cidr": "1.1.1.0/24",
"asn_country_code": "AU",
"asn_date": "2011-08-11",
"asn_description": "CLOUDFLARENET, US",
"asn_registry": "apnic",
"nets": [
{
"address": "PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia",
"cidr": "1.1.1.0/24",
"city": null,
"country": "AU",
"created": null,
"description": "APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs",
"emails": [
"resolver-abuse@cloudflare.com"
],
"handle": "AA1412-AP",
"name": "APNIC-LABS",
"postal_code": null,
"range": "1.1.1.0 - 1.1.1.255",
"state": null,
"updated": null
},
{
"address": null,
"cidr": "1.1.1.0/24",
"city": null,
"country": null,
"created": null,
"description": "APNIC Research and Development\n 6 Cordelia St",
"emails": null,
"handle": null,
"name": null,
"postal_code": null,
"range": "1.1.1.0 - 1.1.1.255",
"state": null,
"updated": null
}
],
"nir": null,
"query": "1.1.1.1",
"raw_referral": null,
"referral": null
}
}
}
}
}
Human Readable Output
SOCRadar - Analysis results for IP: 1.1.1.1
DNS Details Geo Location IP Risk Score (Out of 1000) Score Details Total Encounters Whois Details PTR: one.one.one.one Cidr: 1.1.1.0/24
AsnCode: 13335
AsnName: CloudFlare Inc
ZipCode: 90001
CityName: Los Angeles
Latitude: 0.0
Timezone: -07:00
Longitude: 0.0
RegionName: California
CountryCode: US
CountryName: United States of America
ASN: [13335] CLOUDFLARENET, US1.1.1.1 0 0 asn: 13335
nir: null
nets: {‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘name’: ‘APNIC-LABS’, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘emails’: [‘resolver-abuse@cloudflare.com’], ‘handle’: ‘AA1412-AP’, ‘address’: ‘PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia’, ‘country’: ‘AU’, ‘created’: None, ‘updated’: None, ‘description’: ‘APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs’, ‘postal_code’: None},
{‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘name’: None, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘emails’: None, ‘handle’: None, ‘address’: None, ‘country’: None, ‘created’: None, ‘updated’: None, ‘description’: ‘APNIC Research and Development\n 6 Cordelia St’, ‘postal_code’: None}
query: 1.1.1.1
asn_cidr: 1.1.1.0/24
asn_date: 2011-08-11
referral: null
asn_registry: apnic
raw_referral: null
asn_description: CLOUDFLARENET, US
asn_country_code: AU
domain
Scores provided domain entities’ reputation in SOCRadar ThreatFusion.
Base Command
domain
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | Domain entities to score. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarThreatFusion.Reputation.Domain.Risk Score | Number | Reputation score of queried domain. |
| SOCRadarThreatFusion.Reputation.IP.Score Details | JSON | Risk score details of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Total Encounters | Number | Number of times that SOCRadar has encountered with the queried domain in its threat sources. |
| SOCRadarThreatFusion.Reputation.Domain.Domain | String | Queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.org | String | Org field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.city | String | City field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.name | String | Name field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.state | String | State field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.dnssec | String | Dnssec field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.emails | String | Emails field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.status | String | Status field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.address | String | Address field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.country | String | Country field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.zipcode | Number | Zip code field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.registrar | String | Registrar field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.domain_name | String | Domain name field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.name_servers | String | Name servers field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.referral_url | String | Referral URL field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.updated_date | Date | Updated date field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.whois_server | String | Whois server field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.creation_date | Date | Creation date field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.expiration_date | Date | Expiration date field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.DNS Details | String | DNS information of queried domain. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| Domain.Name | String | The domain name, for example: “google.com”. |
| Domain.DNS | String | A list of IP objects resolved by DNS. |
| Domain.CreationDate | Date | The date that the domain was created. |
| Domain.UpdatedDate | String | The date that the domain was last updated. |
| Domain.ExpirationDate | Date | The expiration date of the domain. |
| Domain.NameServers | Unknown | (List<String>) Name servers of the domain. |
| Domain.Organization | String | The organization of the domain. |
| Domain.Registrant.Name | String | The name of the registrant. |
| Domain.WHOIS.CreationDate | Date | The date that the domain was created. |
| Domain.WHOIS.UpdatedDate | Date | The date that the domain was last updated. |
| Domain.WHOIS.ExpirationDate | Date | The expiration date of the domain. |
| Domain.WHOIS.NameServers | String | (List<String>) Name servers of the domain. |
| Domain.WHOIS.Registrant.Name | String | The name of the registrant. |
| Domain.WHOIS.Registrar.Name | String | The name of the registrar, for example: “GoDaddy” |
| Domain.Geo.Country | String | The country in which the domain address is located. |
| Domain.Subdomains | Unknown | (List<String>) Subdomains of the domain. |
| Domain.Registrant.Country | String | The country of the registrant. |
Command Example
!domain domain="paloaltonetworks.com"
Context Example
{
"DBotScore": {
"Indicator": "paloaltonetworks.com",
"Score": 1,
"Type": "domain",
"Vendor": "SOCRadar ThreatFusion"
},
"Domain": {
"CreationDate": "Mon, 21 Feb 2005 02:42:10 GMT",
"DNS": "1.1.1.1",
"ExpirationDate": "Wed, 21 Feb 2024 02:42:10 GMT",
"Geo": {
"Country": "US"
},
"Name": "paloaltonetworks.com",
"NameServers": [
"ns record"
],
"Organization": "Palo Alto Networks, Inc.",
"Registrar": {
"AbuseEmail": null,
"AbusePhone": null,
"Name": "MarkMonitor Inc."
},
"UpdatedDate": "Thu, 01 Jul 2021 00:32:38 GMT",
"WHOIS": {
"CreationDate": "Mon, 21 Feb 2005 02:42:10 GMT",
"ExpirationDate": "Wed, 21 Feb 2024 02:42:10 GMT",
"NameServers": [
"ns record"
],
"Registrar": {
"AbuseEmail": null,
"AbusePhone": null,
"Name": "MarkMonitor Inc."
},
"UpdatedDate": "Thu, 01 Jul 2021 00:32:38 GMT"
}
},
"SOCRadarThreatFusion": {
"Reputation": {
"Domain": {
"DNS Details": {
"A": [
"1.1.1.1"
],
"MX": [
"mx record"
],
"NS": [
"ns record"
],
"SOA": [
"domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600"
],
"TXT": [
"txt record"
]
},
"Domain": "paloaltonetworks.com",
"Risk Score (Out of 1000)": 0,
"Score Details": {},
"Subdomains": [],
"Total Encounters": 0,
"Whois Details": {
"address": null,
"city": null,
"country": "US",
"creation_date": "Mon, 21 Feb 2005 02:42:10 GMT",
"dnssec": "signedDelegation",
"domain_name": "PALOALTONETWORKS.COM",
"emails": [
"abusecomplaints@markmonitor.com",
"whoisrequest@markmonitor.com"
],
"expiration_date": "Wed, 21 Feb 2024 02:42:10 GMT",
"name": null,
"name_servers": [
"ns record"
],
"org": "Palo Alto Networks, Inc.",
"referral_url": null,
"registrar": "MarkMonitor Inc.",
"state": "CA",
"status": [
"clientTransferProhibited https://icann.org/epp#clientTransferProhibited",
"clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited)",
"clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited)",
"clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited",
"clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)",
"clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited"
],
"updated_date": "Thu, 01 Jul 2021 00:32:38 GMT",
"whois_server": "whois.markmonitor.com",
"zipcode": null
}
}
}
}
}
Human Readable Output
SOCRadar - Analysis results for domain: paloaltonetworks.com
DNS Details Domain Risk Score (Out of 1000) Score Details Subdomains Total Encounters Whois Details A: 1.1.1.1
MX: mx record
NS: ns record
SOA: domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600
TXT: txt recordpaloaltonetworks.com 0 0 org: Palo Alto Networks, Inc.
city: null
name: null
state: CA
dnssec: signedDelegation
emails: abusecomplaints@markmonitor.com,
whoisrequest@markmonitor.com
status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited,
clientTransferProhibited https://icann.org/epp#clientTransferProhibited,
clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited,
clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited),
clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited),
clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)
address: null
country: US
zipcode: null
registrar: MarkMonitor Inc.
domain_name: PALOALTONETWORKS.COM
name_servers: ns record
referral_url: null
updated_date: Thu, 01 Jul 2021 00:32:38 GMT
whois_server: whois.markmonitor.com
creation_date: Mon, 21 Feb 2005 02:42:10 GMT
expiration_date: Wed, 21 Feb 2024 02:42:10 GMT
file
Scores provided hash entities’ reputation in SOCRadar ThreatFusion.
Base Command
file
Input
| Argument Name | Description | Required |
|---|---|---|
| file | Hash entities to score. (MD5 or SHA1). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarThreatFusion.Reputation.Hash.Risk Score | Number | Reputation score of queried hash. |
| SOCRadarThreatFusion.Reputation.Hash.Score Details | JSON | Risk score details of queried hash. |
| SOCRadarThreatFusion.Reputation.Hash.Total Encounters | Number | Number of times that SOCRadar has encountered with the queried hash in its threat sources. |
| SOCRadarThreatFusion.Reputation.Hash.File | String | Queried hash. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| File.MD5 | String | The MD5 hash of the file. |
| File.SHA1 | String | The SHA1 hash of the file. |
Command Example
!file file="3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"
Context Example
{
"DBotScore": {
"Indicator": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
"Score": 1,
"Type": "file",
"Vendor": "SOCRadar ThreatFusion"
},
"File": {
"MD5": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"
},
"SOCRadarThreatFusion": {
"Reputation": {
"Hash": {
"File": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
"Risk Score (Out of 1000)": 360,
"Score Details": {
"Maldatabase": 360
},
"Total Encounters": 1
}
}
}
}
Human Readable Output
SOCRadar - Analysis results for hash: 3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792
File Risk Score (Out of 1000) Score Details Total Encounters 3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792 360.0 Maldatabase: 360.0 1
socradar-score-ip
Scores provided IP entity’s reputation in SOCRadar ThreatFusion.
Base Command
socradar-score-ip
Input
| Argument Name | Description | Required |
|---|---|---|
| ip | IP entity to score. (IPv4 or IPv6). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarThreatFusion.Reputation.IP.Risk Score | Number | Reputation score of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Score Details | JSON | Risk score details of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Total Encounters | Number | Number of times that SOCRadar has encountered with the queried IP address in its threat sources. |
| SOCRadarThreatFusion.Reputation.IP.IP | String | Queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn | String | ASN field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_cidr | String | ASN CIDR field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_country_code | String | ASN country code field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_date | Date | ASN date field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_description | String | ASN description field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_registry | String | ASN registry field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.address | String | Nets>address field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.cidr | String | Nets>CIDR field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.city | String | Nets>city field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.country | String | Nets>country field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.created | String | Nets>created field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.description | String | Nets>description field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.emails | String | Nets>emails field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.handle | String | Nets>handle field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.name | String | Nets>name field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.postal_code | Number | Nets>postal code field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.range | String | Nets>range field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.state | String | Nets>state field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.updated | Date | Nets>updated field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.nir | String | NIR field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.query | String | Query field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.raw_referral | String | Raw referral field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Whois Details.referral | String | Referral field Whois information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.DNS Details | JSON | DNS information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.ASN | Number | ASN field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnCode | Number | ASN code field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnName | String | ASN name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Cidr | String | CIDR field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.CityName | String | City name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryCode | String | Country code field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryName | String | Country name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Latitude | Number | Latitude field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Longitude | Number | Longitude field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.RegionName | String | Region name field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.Timezone | String | Timezone field Geographical location information of queried IP address. |
| SOCRadarThreatFusion.Reputation.IP.Geo Location.ZipCode | String | Zip code field Geographical location information of queried IP address. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the indicator score. |
Command Example
!socradar-score-ip ip="1.1.1.1"
Context Example
{
"SOCRadarThreatFusion": {
"Reputation": {
"IP": {
"DBotScore": {
"Indicator": "1.1.1.1",
"Score": 1,
"Type": "ip",
"Vendor": "SOCRadar ThreatFusion"
},
"DNS Details": {
"PTR": [
"one.one.one.one"
]
},
"Geo Location": {
"ASN": "[13335] CLOUDFLARENET, US",
"AsnCode": 13335,
"AsnName": "CloudFlare Inc",
"Cidr": "1.1.1.0/24",
"CityName": "Los Angeles",
"CountryCode": "US",
"CountryName": "United States of America",
"Latitude": 0.0,
"Longitude": 0.0,
"RegionName": "California",
"Timezone": "-07:00",
"ZipCode": "90001"
},
"IP": "1.1.1.1",
"Risk Score (Out of 1000)": 0,
"Score Details": {},
"Total Encounters": 0,
"Whois Details": {
"asn": "13335",
"asn_cidr": "1.1.1.0/24",
"asn_country_code": "AU",
"asn_date": "2011-08-11",
"asn_description": "CLOUDFLARENET, US",
"asn_registry": "apnic",
"nets": [
{
"address": "PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia",
"cidr": "1.1.1.0/24",
"city": null,
"country": "AU",
"created": null,
"description": "APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs",
"emails": [
"resolver-abuse@cloudflare.com"
],
"handle": "AA1412-AP",
"name": "APNIC-LABS",
"postal_code": null,
"range": "1.1.1.0 - 1.1.1.255",
"state": null,
"updated": null
},
{
"address": null,
"cidr": "1.1.1.0/24",
"city": null,
"country": null,
"created": null,
"description": "APNIC Research and Development\n 6 Cordelia St",
"emails": null,
"handle": null,
"name": null,
"postal_code": null,
"range": "1.1.1.0 - 1.1.1.255",
"state": null,
"updated": null
}
],
"nir": null,
"query": "1.1.1.1",
"raw_referral": null,
"referral": null
}
}
}
}
}
Human Readable Output
SOCRadar - Analysis results for IP: 1.1.1.1
DNS Details Geo Location IP Risk Score (Out of 1000) Score Details Total Encounters Whois Details PTR: one.one.one.one AsnCode: 13335
AsnName: CloudFlare Inc
Cidr: 1.1.1.0/24
CityName: Los Angeles
CountryCode: US
CountryName: United States of America
ASN: [13335] CLOUDFLARENET, US
Latitude: 0.0
Longitude: 0.0
RegionName: California
Timezone: -07:00
ZipCode: 900011.1.1.1 0 0 asn: 13335
asn_cidr: 1.1.1.0/24
asn_country_code: AU
asn_date: 2011-08-11
asn_description: CLOUDFLARENET, US
asn_registry: apnic
nets: {‘address’: ‘PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia’, ‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘country’: ‘AU’, ‘created’: None, ‘description’: ‘APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs’, ‘emails’: [‘resolver-abuse@cloudflare.com’], ‘handle’: ‘AA1412-AP’, ‘name’: ‘APNIC-LABS’, ‘postal_code’: None, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘updated’: None},
{‘address’: None, ‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘country’: None, ‘created’: None, ‘description’: ‘APNIC Research and Development\n 6 Cordelia St’, ‘emails’: None, ‘handle’: None, ‘name’: None, ‘postal_code’: None, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘updated’: None}
nir: null
query: 1.1.1.1
raw_referral: null
referral: null
socradar-score-domain
Scores provided domain entity’s reputation in SOCRadar ThreatFusion.
Base Command
socradar-score-domain
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | Domain entity to score. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarThreatFusion.Reputation.Domain.Risk Score | Number | Reputation score of queried domain. |
| SOCRadarThreatFusion.Reputation.IP.Score Details | JSON | Risk score details of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Total Encounters | Number | Number of times that SOCRadar has encountered with the queried domain in its threat sources. |
| SOCRadarThreatFusion.Reputation.Domain.Domain | String | Queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.org | String | Org field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.city | String | City field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.name | String | Name field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.state | String | State field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.dnssec | String | Dnssec field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.emails | String | Emails field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.status | String | Status field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.address | String | Address field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.country | String | Country field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.zipcode | Number | Zip code field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.registrar | String | Registrar field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.domain_name | String | Domain name field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.name_servers | String | Name servers field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.referral_url | String | Referral URL field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.updated_date | Date | Updated date field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.whois_server | String | Whois server field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.creation_date | Date | Creation date field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.Whois Details.expiration_date | Date | Expiration date field Whois information of queried domain. |
| SOCRadarThreatFusion.Reputation.Domain.DNS Details | String | DNS information of queried domain. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the indicator score. |
Command Example
!socradar-score-domain domain="paloaltonetworks.com"
Context Example
{
"SOCRadarThreatFusion": {
"Reputation": {
"Domain": {
"DBotScore": {
"Indicator": "paloaltonetworks.com",
"Score": 1,
"Type": "domain",
"Vendor": "SOCRadar ThreatFusion"
},
"DNS Details": {
"A": [
"1.1.1.1"
],
"MX": [
"mx record"
],
"NS": [
"ns record"
],
"SOA": [
"domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600"
],
"TXT": [
"txt record"
]
},
"Domain": "paloaltonetworks.com",
"Risk Score (Out of 1000)": 0,
"Score Details": {},
"Subdomains": [],
"Total Encounters": 0,
"Whois Details": {
"address": null,
"city": null,
"country": "US",
"creation_date": "Mon, 21 Feb 2005 02:42:10 GMT",
"dnssec": "signedDelegation",
"domain_name": "PALOALTONETWORKS.COM",
"emails": [
"abusecomplaints@markmonitor.com",
"whoisrequest@markmonitor.com"
],
"expiration_date": "Wed, 21 Feb 2024 02:42:10 GMT",
"name": null,
"name_servers": [
"ns record"
],
"org": "Palo Alto Networks, Inc.",
"referral_url": null,
"registrar": "MarkMonitor Inc.",
"state": "CA",
"status": [
"clientTransferProhibited https://icann.org/epp#clientTransferProhibited",
"clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited)",
"clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited)",
"clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited",
"clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)",
"clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited"
],
"updated_date": "Thu, 01 Jul 2021 00:32:38 GMT",
"whois_server": "whois.markmonitor.com",
"zipcode": null
}
}
}
}
}
Human Readable Output
SOCRadar - Analysis results for domain: paloaltonetworks.com
DNS Details Domain Risk Score (Out of 1000) Score Details Subdomains Total Encounters Whois Details A: 1.1.1.1
MX: mx record
NS: ns record
SOA: domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600
TXT: txt recordpaloaltonetworks.com 0 0 org: Palo Alto Networks, Inc.
city: null
name: null
state: CA
dnssec: signedDelegation
emails: abusecomplaints@markmonitor.com,
whoisrequest@markmonitor.com
status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited,
clientTransferProhibited https://icann.org/epp#clientTransferProhibited,
clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited,
clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited),
clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited),
clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)
address: null
country: US
zipcode: null
registrar: MarkMonitor Inc.
domain_name: PALOALTONETWORKS.COM
name_servers: ns record
referral_url: null
updated_date: Thu, 01 Jul 2021 00:32:38 GMT
whois_server: whois.markmonitor.com
creation_date: Mon, 21 Feb 2005 02:42:10 GMT
expiration_date: Wed, 21 Feb 2024 02:42:10 GMT
socradar-score-hash
Scores provided hash entity’s reputation in SOCRadar ThreatFusion.
Base Command
socradar-score-hash
Input
| Argument Name | Description | Required |
|---|---|---|
| hash | Hash entity to score. (MD5 or SHA1). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarThreatFusion.Reputation.Hash.Risk Score | Number | Reputation score of queried hash. |
| SOCRadarThreatFusion.Reputation.Hash.Score Details | JSON | Risk score details of queried hash. |
| SOCRadarThreatFusion.Reputation.Hash.Total Encounters | Number | Number of times that SOCRadar has encountered with the queried hash in its threat sources. |
| SOCRadarThreatFusion.Reputation.Hash.File | String | Queried hash. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the indicator score. |
Command Example
!socradar-score-hash hash="3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"
Context Example
{
"SOCRadarThreatFusion": {
"Reputation": {
"Hash": {
"DBotScore": {
"Indicator": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
"Score": 1,
"Type": "file",
"Vendor": "SOCRadar ThreatFusion"
},
"File": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
"Risk Score (Out of 1000)": 360,
"Score Details": {
"Maldatabase": 360
},
"Total Encounters": 1
}
}
}
}
Human Readable Output
SOCRadar - Analysis results for hash: 3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792
File Risk Score (Out of 1000) Score Details Total Encounters 3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792 360.0 Maldatabase: 360.0 1
Configuration parameters
apikey— API Key (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsintegrationReliability— Source ReliabilityfeedExpirationPolicy—feedExpirationInterval—
Commands (6)
-
domainScores provided domain entities' reputation in SOCRadar ThreatFusion.
-
fileScores provided hash entities' reputation in SOCRadar ThreatFusion.
-
ipScores provided IP entities' reputation in SOCRadar ThreatFusion.
-
socradar-score-domainScores provided domain entity's reputation in SOCRadar ThreatFusion.
-
socradar-score-hashScores provided hash entity's reputation in SOCRadar ThreatFusion.
-
socradar-score-ipScores provided IP entity's reputation in SOCRadar ThreatFusion.
import demistomock as demisto # noqa: F401 from CommonServerPython import * # noqa: F401 from json.decoder import JSONDecodeError from CommonServerUserPython import * # noqa import urllib3 import traceback from typing import Any # Disable insecure warnings urllib3.disable_warnings() # pylint: disable=no-member """ CONSTANTS """ SOCRADAR_API_ENDPOINT = "https://platform.socradar.com/api" MESSAGES: dict[str, str] = { "BAD_REQUEST_ERROR": "An error occurred while fetching the data.", "AUTHORIZATION_ERROR": "Authorization Error: make sure API Key is correctly set.", "RATE_LIMIT_EXCEED_ERROR": "Rate limit has been exceeded. Please make sure your your API key's rate limit is adequate.", } INTEGRATION_NAME = "SOCRadar ThreatFusion" """ CLIENT CLASS """ class Client(BaseClient): """ Client class to interact with the SOCRadar API """ def __init__(self, base_url, api_key, verify, proxy): super().__init__(base_url, verify=verify, proxy=proxy) self.api_key = api_key def get_entity_score(self, entity): suffix = "/threat/analysis" api_params = {"key": self.api_key, "entity": entity} response = self._http_request( method="GET", url_suffix=suffix, params=api_params, timeout=60, error_handler=self.handle_error_response, ) return response def check_auth(self): suffix = "/threat/analysis/check/auth" api_params = {"key": self.api_key} response = self._http_request( method="GET", url_suffix=suffix, params=api_params, error_handler=self.handle_error_response, ) return response @staticmethod def handle_error_response(response) -> None: """Handles API response to display descriptive error messages based on status code :param response: SOCRadar API response. :return: DemistoException for particular error code. """ error_reason = "" try: json_resp = response.json() error_reason = json_resp.get("error") or json_resp.get("message") except JSONDecodeError: pass status_code_messages = { 400: f"{MESSAGES['BAD_REQUEST_ERROR']} Reason: {error_reason}", 401: MESSAGES["AUTHORIZATION_ERROR"], 404: f"{MESSAGES['BAD_REQUEST_ERROR']} Reason: {error_reason}", 429: MESSAGES["RATE_LIMIT_EXCEED_ERROR"], } if response.status_code in status_code_messages: demisto.debug(f"Response Code: {response.status_code}, Reason: {status_code_messages[response.status_code]}") raise DemistoException(status_code_messages[response.status_code]) else: raise DemistoException(response.raise_for_status()) """ HELPER FUNCTIONS """ def calculate_dbot_score(score: int) -> int: """Transforms cyber risk score (reputation) from SOCRadar API to DBot Score and using threshold. Args: score: Cyber risk score (reputation) from SOCRadar API Returns: Score representation in DBot """ return_score = 0 # Malicious if score > 800: return_score = 3 # Suspicious elif score > 400: return_score = 2 # Good elif score > 0: return_score = 1 # Unknown return return_score class Validator: @staticmethod def validate_domain(domain_to_validate): if not isinstance(domain_to_validate, str) or len(domain_to_validate) > 255: return False if domain_to_validate.endswith("."): domain_to_validate = domain_to_validate[:-1] domain_regex = re.compile(r"(?!-)[A-Z\d-]{1,63}(?<!-)$", re.IGNORECASE) return all(domain_regex.match(x) for x in domain_to_validate.split(".")) @staticmethod def validate_ipv4(ip_to_validate): return is_ip_valid(ip_to_validate) @staticmethod def validate_ipv6(ip_to_validate): return is_ipv6_valid(ip_to_validate) @staticmethod def validate_hash(hash_to_validate): return get_hash_type(hash_to_validate) != "Unknown" @staticmethod def raise_if_ip_not_valid(ip: str): """Raises an error if ip is not valid Args: ip: ip Raises: ValueError: if ip is not type of ipv4 or ipv6 Examples: >>> Validator.raise_if_ip_not_valid('not an ip') Traceback (most recent call last): ... ValueError: IP "not an ip" is not a type of IPv4 or IPv6 >>> Validator.raise_if_ip_not_valid('1.1.1.1') """ if not Validator.validate_ipv4(ip) and not Validator.validate_ipv6(ip): raise ValueError(f'IP "{ip}" is not a type of IPv4 or IPv6') @staticmethod def raise_if_domain_not_valid(domain: str): """Raises an error if domain is not valid Args: domain: domain Raises: ValueError: if domain is not a valid domain address Examples: >>> Validator.raise_if_domain_not_valid('not a domain') Traceback (most recent call last): ... ValueError: Domain "not a domain" is not a valid domain address >>> Validator.raise_if_hash_not_valid('not a domain') """ if not Validator.validate_domain(domain): raise ValueError(f'Domain "{domain}" is not a valid domain address') @staticmethod def raise_if_hash_not_valid(file_hash: str): """Raises an error if file_hash is not valid Args: file_hash: file hash Raises: ValueError: if hash is not of type SHA-1 or MD5 Examples: >>> Validator.raise_if_hash_not_valid('not a hash') Traceback (most recent call last): ... ValueError: Hash "not a hash" is not of type SHA-1 or MD5 >>> Validator.raise_if_hash_not_valid('7e641f6b9706d860baf09fe418b6cc87') """ if not Validator.validate_hash(file_hash): raise ValueError(f'Hash "{file_hash}" is not of type SHA-1 or MD5') def verify_entity_type(entity_to_control_list: list, entity_type: str): """Verify intended entity type. Raise exception if the provided entity type is not expected. :type entity_to_control_list: ``list`` :param entity_to_control_list: Intended entity list to be verified. :type entity_type: ``str`` :param entity_type: Intended entity type to be verified. """ control_dict = { "ip": Validator.raise_if_ip_not_valid, "domain": Validator.raise_if_domain_not_valid, "hash": Validator.raise_if_hash_not_valid, } for entity_to_control in entity_to_control_list: control_dict[entity_type](entity_to_control) def map_indicator_type(socradar_indicator_type: str) -> Optional[str]: """Map SOCRadar indicator type to XSOAR indicator type :type socradar_indicator_type: ``str`` :param socradar_indicator_type: The SOCRadar indicator type :return: XSOAR indicator type :rtype: ``Optional[str]`` """ indicator_map = { "ipv4": FeedIndicatorType.IP, "ipv6": FeedIndicatorType.IPv6, "hash": FeedIndicatorType.File, "hostname": FeedIndicatorType.Domain, } return indicator_map.get(socradar_indicator_type) def build_entry_context(results: Union[dict, List], indicator_type: str): """Formatting results from SOCRadar API to Demisto Context :type results: ``Union[Dict, List]`` :param results: Raw results obtained from SOCRadar API. :type indicator_type: ``str`` :param results: Type of indicator to be used in context creation. """ if isinstance(results, list): return [build_entry_context(entry, indicator_type) for entry in results] # pragma: no cover result_data = results.get("data", {}) return_context = { "Risk Score (Out of 100)": result_data.get("score"), "Score Details": result_data.get("score_details"), "Total Encounters": len(result_data.get("findings", [])), map_indicator_type(result_data.get("classification")): result_data.get("value"), } if indicator_type == "domain": return_context["Subdomains"] = result_data.get("subdomains", []) if indicator_type != "hash": return_context["Whois Details"] = {} for key, value in result_data.get("whois", {}).items(): # Exclude raw whois if key == "raw": continue if value and type(value) is list and key in ("creation_date", "expiration_date", "updated_date", "registrar"): value = value[0] return_context["Whois Details"][key] = value return_context["DNS Details"] = result_data.get("dns_info", {}) if indicator_type == "ip": geo_location_dict = {} if result_data.get("geo_location", []): geo_location = result_data["geo_location"][0] geo_location_dict = {key: value for key, value in geo_location.items() if key.lower() != "ip"} asn_code = result_data.get("whois", {}).get("asn", "") if not asn_code: asn_code = geo_location_dict.get("AsnCode", "") asn_description = result_data.get("whois", {}).get("asn_description", "") if not asn_description: asn_description = geo_location_dict.get("AsnName", "") asn = f"[{asn_code}] {asn_description}" geo_location_dict["ASN"] = asn return_context["Geo Location"] = geo_location_dict return return_context """ COMMAND FUNCTIONS """ def test_module(client: Client) -> str: """Tests API connectivity and authentication' Returning 'ok' indicates that the integration works like it is supposed to. Connection to the service is successful. Raises exceptions if something goes wrong. :type client: ``Client`` :param client: client to use :return: 'ok' if test passed, anything else will fail the test. :rtype: ``str`` """ client.check_auth() return "ok" def ip_command(client: Client, args: dict[str, Any]) -> List[CommandResults]: """Returns SOCRadar reputation details for the given IP entities. :type client: ``Client`` :param client: client to use :type args: Dict[str, Any] :param args: contains all arguments for ip_command :return: List of ``CommandResults`` objects that is then passed to ``return_results`` :rtype: ``List[CommandResults]`` """ ip_addresses = args.get("ip", "") ip_list: list = argToList(ip_addresses) verify_entity_type(ip_list, "ip") command_results_list: List[CommandResults] = [] for ip_to_score in ip_list: raw_response = client.get_entity_score(ip_to_score) if raw_response.get("is_success"): if raw_response.get("data", {}).get("is_whitelisted"): score = 1 elif (score := raw_response.get("data", {}).get("score", 0)) is not None: score = calculate_dbot_score(score) title = f"SOCRadar - Analysis results for IP: {ip_to_score}" context_entry = build_entry_context(raw_response, "ip") human_readable = tableToMarkdown(title, context_entry) dbot_score = Common.DBotScore( indicator=ip_to_score, indicator_type=DBotScoreType.IP, integration_name=INTEGRATION_NAME, score=score, reliability=demisto.params().get("integrationReliability"), ) ip_object = Common.IP( ip=ip_to_score, dbot_score=dbot_score, asn=context_entry["Geo Location"].get("ASN"), geo_country=context_entry["Geo Location"].get("CountryCode"), geo_latitude=context_entry["Geo Location"].get("Latitude"), geo_longitude=context_entry["Geo Location"].get("Longitude"), region=context_entry["Geo Location"].get("RegionName"), ) command_results_list.append( CommandResults( outputs_prefix="SOCRadarThreatFusion.Reputation.IP", outputs_key_field="IP", readable_output=human_readable, raw_response=raw_response, outputs=context_entry, indicator=ip_object, ) ) else: message = ( f"Error at scoring IP {ip_to_score} while getting API response. " f"SOCRadar ThreatFusion API Response: {raw_response.get('message', '')}" ) command_results_list.append(CommandResults(readable_output=message)) if not command_results_list: command_results_list = [CommandResults("SOCRadar ThreatFusion could not find any results for the given IP address(es).")] return command_results_list def domain_command(client: Client, args: dict[str, Any]) -> List[CommandResults]: """Returns SOCRadar reputation details for the given domain entities. :type client: ``Client`` :param client: client to use :type args: Dict[str, Any] :param args: contains all arguments for domain_command :return: List of ``CommandResults`` objects that is then passed to ``return_results`` :rtype: ``List[CommandResults]`` """ domains = args.get("domain", "") domains_list: list = argToList(domains) verify_entity_type(domains_list, "domain") command_results_list: List[CommandResults] = [] for domain_to_score in domains_list: raw_response = client.get_entity_score(domain_to_score) if raw_response.get("is_success"): if raw_response.get("data", {}).get("is_whitelisted"): score = 1 elif (score := raw_response.get("data", {}).get("score", 0)) is not None: score = calculate_dbot_score(score) title = f"SOCRadar - Analysis results for domain: {domain_to_score}" context_entry = build_entry_context(raw_response, "domain") human_readable = tableToMarkdown(title, context_entry) dbot_score = Common.DBotScore( indicator=domain_to_score, indicator_type=DBotScoreType.DOMAIN, integration_name=INTEGRATION_NAME, score=score, reliability=demisto.params().get("integrationReliability"), ) domain_object = Common.Domain( domain=domain_to_score, dbot_score=dbot_score, dns=", ".join(context_entry["DNS Details"].get("A", [])), creation_date=context_entry["Whois Details"].get("creation_date"), expiration_date=context_entry["Whois Details"].get("expiration_date"), updated_date=context_entry["Whois Details"].get("updated_date"), registrant_country=context_entry["Whois Details"].get("registrant_country"), registrant_name=context_entry["Whois Details"].get("registrant_name") or context_entry["Whois Details"].get("name"), registrar_name=context_entry["Whois Details"].get("registrar"), organization=context_entry["Whois Details"].get("org"), geo_country=context_entry["Whois Details"].get("country"), sub_domains=context_entry["Subdomains"], name_servers=context_entry["DNS Details"].get("NS") or context_entry["Whois Details"].get("name_servers"), ) command_results_list.append( CommandResults( outputs_prefix="SOCRadarThreatFusion.Reputation.Domain", outputs_key_field="Domain", readable_output=human_readable, raw_response=raw_response, outputs=context_entry, indicator=domain_object, ) ) else: message = ( f"Error at scoring domain {domain_to_score} while getting API response. " f"SOCRadar ThreatFusion API Response: {raw_response.get('message', '')}" ) command_results_list.append(CommandResults(readable_output=message)) if not command_results_list: command_results_list = [CommandResults("SOCRadar ThreatFusion could not find any results for the given domain(s).")] return command_results_list def file_command(client: Client, args: dict[str, Any]) -> List[CommandResults]: """Returns SOCRadar reputation details for the given hash entities. :type client: ``Client`` :param client: client to use :type args: Dict[str, Any] :param args: contains all arguments for hash_command :return: List of ``CommandResults`` objects that is then passed to ``return_results`` :rtype: ``List[CommandResults]`` """ file_hashes = args.get("file", "") file_hash_list: list = argToList(file_hashes) verify_entity_type(file_hash_list, "hash") command_results_list: List[CommandResults] = [] for hash_to_score in file_hash_list: hash_type = get_hash_type(hash_to_score) raw_response = client.get_entity_score(hash_to_score) if raw_response.get("is_success"): if raw_response.get("data", {}).get("is_whitelisted"): score = 1 elif (score := raw_response.get("data", {}).get("score", 0)) is not None: score = calculate_dbot_score(score) title = f"SOCRadar - Analysis results for hash: {hash_to_score}" context_entry = build_entry_context(raw_response, "hash") human_readable = tableToMarkdown(title, context_entry) dbot_score = Common.DBotScore( indicator=hash_to_score, indicator_type=DBotScoreType.FILE, integration_name=INTEGRATION_NAME, score=score, reliability=demisto.params().get("integrationReliability"), ) file_object = Common.File(dbot_score=dbot_score) # hash_type can either be 'sha-1' or 'md5' at this point. if hash_type == "sha-1": file_object.sha1 = hash_to_score else: file_object.md5 = hash_to_score command_results_list.append( CommandResults( outputs_prefix="SOCRadarThreatFusion.Reputation.Hash", outputs_key_field="File", readable_output=human_readable, raw_response=raw_response, outputs=context_entry, indicator=file_object, ) ) else: message = ( f"Error at scoring file hash {hash_to_score} while getting API response. " f"SOCRadar ThreatFusion API Response: {raw_response.get('message', '')}" ) command_results_list.append(CommandResults(readable_output=message)) if not command_results_list: command_results_list = [CommandResults("SOCRadar ThreatFusion could not find any results for the given file hash(es).")] return command_results_list def score_ip_command(client: Client, args: dict[str, Any]) -> CommandResults: """Returns SOCRadar reputation details for the given IP entity. :type client: ``Client`` :param client: client to use :type args: Dict[str, Any] :param args: contains all arguments for list-detections command :return: A ``CommandResults`` object that is then passed to ``return_results`` :rtype: ``CommandResults`` """ ip_to_score = args.get("ip", "") verify_entity_type([ip_to_score], "ip") raw_response = client.get_entity_score(ip_to_score) if raw_response.get("is_success"): if raw_response.get("data", {}).get("is_whitelisted"): score = 1 elif (score := raw_response.get("data", {}).get("score", 0)) is not None: score = calculate_dbot_score(score) title = f"SOCRadar - Analysis results for IP: {ip_to_score}" context_entry = build_entry_context(raw_response, "ip") dbot_entry = build_dbot_entry(ip_to_score, DBotScoreType.IP, "SOCRadar ThreatFusion", score) human_readable = tableToMarkdown(title, context_entry) context_entry.update(dbot_entry) else: message = f"Error while getting API response. SOCRadar API Response: {raw_response.get('message', '')}" raise DemistoException(message=message) return CommandResults( outputs_prefix="SOCRadarThreatFusion.Reputation.IP", outputs_key_field="IP", readable_output=human_readable, raw_response=raw_response, outputs=context_entry, ) def score_domain_command(client: Client, args: dict[str, Any]) -> CommandResults: """Returns SOCRadar reputation details for the given domain entity. :type client: ``Client`` :param client: client to use :type args: Dict[str, Any] :param args: contains all arguments for list-detections command :return: A ``CommandResults`` object that is then passed to ``return_results`` :rtype: ``CommandResults`` """ domain_to_score = args.get("domain", "") verify_entity_type([domain_to_score], "domain") raw_response = client.get_entity_score(domain_to_score) if raw_response.get("is_success"): if raw_response.get("data", {}).get("is_whitelisted"): score = 1 elif (score := raw_response.get("data", {}).get("score", 0)) is not None: score = calculate_dbot_score(score) title = f"SOCRadar - Analysis results for domain: {domain_to_score}" context_entry = build_entry_context(raw_response, "domain") dbot_entry = build_dbot_entry(domain_to_score, DBotScoreType.DOMAIN, "SOCRadar ThreatFusion", score) human_readable = tableToMarkdown(title, context_entry) context_entry.update(dbot_entry) else: message = f"Error while getting API response. SOCRadar API Response: {raw_response.get('message', '')}" raise DemistoException(message=message) return CommandResults( outputs_prefix="SOCRadarThreatFusion.Reputation.Domain", outputs_key_field="Domain", readable_output=human_readable, raw_response=raw_response, outputs=context_entry, ) def score_hash_command(client: Client, args: dict[str, Any]) -> CommandResults: """Returns SOCRadar reputation details for the given hash entity. :type client: ``Client`` :param client: client to use :type args: Dict[str, Any] :param args: contains all arguments for list-detections command :return: A ``CommandResults`` object that is then passed to ``return_results`` :rtype: ``CommandResults`` """ hash_to_score = args.get("hash", "") verify_entity_type([hash_to_score], "hash") hash_type = get_hash_type(hash_to_score) raw_response = client.get_entity_score(hash_to_score) if raw_response.get("is_success"): if raw_response.get("data", {}).get("is_whitelisted"): score = 1 elif (score := raw_response.get("data", {}).get("score", 0)) is not None: score = calculate_dbot_score(score) title = f"SOCRadar - Analysis results for hash: {hash_to_score}" context_entry = build_entry_context(raw_response, "hash") dbot_entry = build_dbot_entry(hash_to_score, hash_type, "SOCRadar ThreatFusion", score) human_readable = tableToMarkdown(title, context_entry) context_entry.update(dbot_entry) else: message = f"Error while getting API response. SOCRadar API Response: {raw_response.get('message', '')}" raise DemistoException(message=message) return CommandResults( outputs_prefix="SOCRadarThreatFusion.Reputation.Hash", outputs_key_field="File", readable_output=human_readable, raw_response=raw_response, outputs=context_entry, ) """ MAIN FUNCTION """ def main() -> None: """main function, parses params and runs command functions :return: :rtype: """ api_key = demisto.params().get("apikey") base_url = SOCRADAR_API_ENDPOINT verify_certificate = not demisto.params().get("insecure", False) proxy = demisto.params().get("proxy", False) demisto.debug(f"Command being called is {demisto.command()}") try: client = Client(base_url=base_url, api_key=api_key, verify=verify_certificate, proxy=proxy) command = demisto.command() commands = { "ip": ip_command, "domain": domain_command, "file": file_command, "socradar-score-ip": score_ip_command, "socradar-score-domain": score_domain_command, "socradar-score-hash": score_hash_command, } if command == "test-module": return_results(test_module(client)) else: command_function = commands.get(command) if command_function: return_results(command_function(client, demisto.args())) except Exception as e: demisto.error(traceback.format_exc()) return_error(f"Failed to execute {demisto.command()} command.\nError:\n{str(e)}") """ ENTRY POINT """ if __name__ in ("__main__", "__builtin__", "builtins"): main()