SOCRadarThreatFusion

Enrich indicators by obtaining enhanced information and reputation via ThreatFusion of SOCRadar.

Data Enrichment & Threat Intelligence · SOCRadar

Details

IDSOCRadarThreatFusion
ProviderSOCRadar
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Enrich indicators by obtaining enhanced information and reputation via ThreatFusion of SOCRadar.
This integration was integrated and tested with v21.11 of SOCRadar.

Configure SOCRadarThreatFusion on Cortex XSOAR

  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for SOCRadarThreatFusion.
  3. Click Add instance to create and configure a new integration instance.

    Parameter Description Required
    API Key The API Key to use for connection to SOCRadar ThreatFusion API. True
    insecure Trust any certificate (not secure). False
    proxy Whether to use XSOAR’s system proxy settings to connect to the API. False
  4. Click Test to validate API key and connection to SOCRadar ThreatFusion API.

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

How to obtain SOCRadar ThreatFusion API key?

To obtain your SOCRadar ThreatFusion API key please contact with the SOCRadar operation team via operation@socradar.io

After obtaining the SOCRadar ThreatFusion API key insert it into API Key field and start using the SOCRadar ThreatFusion integration by creating the instance.

ip


Scores provided IP entities’ reputation in SOCRadar ThreatFusion.

Base Command

ip

Input

Argument Name Description Required
ip IP entities to score. (IPv4 or IPv6). Required

Context Output

Path Type Description
SOCRadarThreatFusion.Reputation.IP.Risk Score Number Reputation score of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Score Details JSON Risk score details of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Total Encounters Number Number of times that SOCRadar has encountered with the queried IP address in its threat sources.
SOCRadarThreatFusion.Reputation.IP.IP String Queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn String ASN field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_cidr String ASN CIDR field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_country_code String ASN country code field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_date Date ASN date field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_description String ASN description field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_registry String ASN registry field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.address String Nets>address field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.cidr String Nets>CIDR field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.city String Nets>city field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.country String Nets>country field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.created String Nets>created field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.description String Nets>description field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.emails String Nets>emails field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.handle String Nets>handle field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.name String Nets>name field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.postal_code Number Nets>postal code field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.range String Nets>range field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.state String Nets>state field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.updated Date Nets>updated field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nir String NIR field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.query String Query field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.raw_referral String Raw referral field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.referral String Referral field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.DNS Details JSON DNS information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.ASN Number ASN field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnCode Number ASN code field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnName String ASN name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Cidr String CIDR field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.CityName String City name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryCode String Country code field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryName String Country name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Latitude Number Latitude field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Longitude Number Longitude field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.RegionName String Region name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Timezone String Timezone field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.ZipCode String Zip code field Geographical location information of queried IP address.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
IP.Address String IP address
IP.ASN String The autonomous system name for the IP address, for example: “AS8948”.
IP.Geo.Location String The geolocation where the IP address is located, in the format: latitude:longitude.
IP.Geo.Country String The country in which the IP address is located.

Command Example

!ip ip="1.1.1.1"

Context Example

{
    "DBotScore": {
        "Indicator": "1.1.1.1",
        "Score": 1,
        "Type": "ip",
        "Vendor": "SOCRadar ThreatFusion"
    },
    "IP": {
        "ASN": "[13335] CLOUDFLARENET, US",
        "Address": "1.1.1.1",
        "Geo": {
            "Country": "US",
            "Location": "0.0:0.0"
        },
        "Region": "California"
    },
    "SOCRadarThreatFusion": {
        "Reputation": {
            "IP": {
                "DNS Details": {
                    "PTR": [
                        "one.one.one.one"
                    ]
                },
                "Geo Location": {
                    "ASN": "[13335] CLOUDFLARENET, US",
                    "AsnCode": 13335,
                    "AsnName": "CloudFlare Inc",
                    "Cidr": "1.1.1.0/24",
                    "CityName": "Los Angeles",
                    "CountryCode": "US",
                    "CountryName": "United States of America",
                    "Latitude": 0.0,
                    "Longitude": 0.0,
                    "RegionName": "California",
                    "Timezone": "-07:00",
                    "ZipCode": "90001"
                },
                "IP": "1.1.1.1",
                "Risk Score (Out of 1000)": 0,
                "Score Details": {},
                "Total Encounters": 0,
                "Whois Details": {
                    "asn": "13335",
                    "asn_cidr": "1.1.1.0/24",
                    "asn_country_code": "AU",
                    "asn_date": "2011-08-11",
                    "asn_description": "CLOUDFLARENET, US",
                    "asn_registry": "apnic",
                    "nets": [
                        {
                            "address": "PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia",
                            "cidr": "1.1.1.0/24",
                            "city": null,
                            "country": "AU",
                            "created": null,
                            "description": "APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs",
                            "emails": [
                                "resolver-abuse@cloudflare.com"
                            ],
                            "handle": "AA1412-AP",
                            "name": "APNIC-LABS",
                            "postal_code": null,
                            "range": "1.1.1.0 - 1.1.1.255",
                            "state": null,
                            "updated": null
                        },
                        {
                            "address": null,
                            "cidr": "1.1.1.0/24",
                            "city": null,
                            "country": null,
                            "created": null,
                            "description": "APNIC Research and Development\n                6 Cordelia St",
                            "emails": null,
                            "handle": null,
                            "name": null,
                            "postal_code": null,
                            "range": "1.1.1.0 - 1.1.1.255",
                            "state": null,
                            "updated": null
                        }
                    ],
                    "nir": null,
                    "query": "1.1.1.1",
                    "raw_referral": null,
                    "referral": null
                }
            }
        }
    }
}

Human Readable Output

SOCRadar - Analysis results for IP: 1.1.1.1

DNS Details Geo Location IP Risk Score (Out of 1000) Score Details Total Encounters Whois Details
PTR: one.one.one.one Cidr: 1.1.1.0/24
AsnCode: 13335
AsnName: CloudFlare Inc
ZipCode: 90001
CityName: Los Angeles
Latitude: 0.0
Timezone: -07:00
Longitude: 0.0
RegionName: California
CountryCode: US
CountryName: United States of America
ASN: [13335] CLOUDFLARENET, US
1.1.1.1 0   0 asn: 13335
nir: null
nets: {‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘name’: ‘APNIC-LABS’, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘emails’: [‘resolver-abuse@cloudflare.com’], ‘handle’: ‘AA1412-AP’, ‘address’: ‘PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia’, ‘country’: ‘AU’, ‘created’: None, ‘updated’: None, ‘description’: ‘APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs’, ‘postal_code’: None},
{‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘name’: None, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘emails’: None, ‘handle’: None, ‘address’: None, ‘country’: None, ‘created’: None, ‘updated’: None, ‘description’: ‘APNIC Research and Development\n 6 Cordelia St’, ‘postal_code’: None}
query: 1.1.1.1
asn_cidr: 1.1.1.0/24
asn_date: 2011-08-11
referral: null
asn_registry: apnic
raw_referral: null
asn_description: CLOUDFLARENET, US
asn_country_code: AU

domain


Scores provided domain entities’ reputation in SOCRadar ThreatFusion.

Base Command

domain

Input

Argument Name Description Required
domain Domain entities to score. Required

Context Output

Path Type Description
SOCRadarThreatFusion.Reputation.Domain.Risk Score Number Reputation score of queried domain.
SOCRadarThreatFusion.Reputation.IP.Score Details JSON Risk score details of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Total Encounters Number Number of times that SOCRadar has encountered with the queried domain in its threat sources.
SOCRadarThreatFusion.Reputation.Domain.Domain String Queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.org String Org field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.city String City field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.name String Name field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.state String State field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.dnssec String Dnssec field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.emails String Emails field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.status String Status field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.address String Address field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.country String Country field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.zipcode Number Zip code field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.registrar String Registrar field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.domain_name String Domain name field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.name_servers String Name servers field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.referral_url String Referral URL field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.updated_date Date Updated date field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.whois_server String Whois server field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.creation_date Date Creation date field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.expiration_date Date Expiration date field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.DNS Details String DNS information of queried domain.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
Domain.Name String The domain name, for example: “google.com”.
Domain.DNS String A list of IP objects resolved by DNS.
Domain.CreationDate Date The date that the domain was created.
Domain.UpdatedDate String The date that the domain was last updated.
Domain.ExpirationDate Date The expiration date of the domain.
Domain.NameServers Unknown (List<String>) Name servers of the domain.
Domain.Organization String The organization of the domain.
Domain.Registrant.Name String The name of the registrant.
Domain.WHOIS.CreationDate Date The date that the domain was created.
Domain.WHOIS.UpdatedDate Date The date that the domain was last updated.
Domain.WHOIS.ExpirationDate Date The expiration date of the domain.
Domain.WHOIS.NameServers String (List<String>) Name servers of the domain.
Domain.WHOIS.Registrant.Name String The name of the registrant.
Domain.WHOIS.Registrar.Name String The name of the registrar, for example: “GoDaddy”
Domain.Geo.Country String The country in which the domain address is located.
Domain.Subdomains Unknown (List<String>) Subdomains of the domain.
Domain.Registrant.Country String The country of the registrant.

Command Example

!domain domain="paloaltonetworks.com"

Context Example

{
    "DBotScore": {
        "Indicator": "paloaltonetworks.com",
        "Score": 1,
        "Type": "domain",
        "Vendor": "SOCRadar ThreatFusion"
    },
    "Domain": {
        "CreationDate": "Mon, 21 Feb 2005 02:42:10 GMT",
        "DNS": "1.1.1.1",
        "ExpirationDate": "Wed, 21 Feb 2024 02:42:10 GMT",
        "Geo": {
            "Country": "US"
        },
        "Name": "paloaltonetworks.com",
        "NameServers": [
            "ns record"
        ],
        "Organization": "Palo Alto Networks, Inc.",
        "Registrar": {
            "AbuseEmail": null,
            "AbusePhone": null,
            "Name": "MarkMonitor Inc."
        },
        "UpdatedDate": "Thu, 01 Jul 2021 00:32:38 GMT",
        "WHOIS": {
            "CreationDate": "Mon, 21 Feb 2005 02:42:10 GMT",
            "ExpirationDate": "Wed, 21 Feb 2024 02:42:10 GMT",
            "NameServers": [
                "ns record"
            ],
            "Registrar": {
                "AbuseEmail": null,
                "AbusePhone": null,
                "Name": "MarkMonitor Inc."
            },
            "UpdatedDate": "Thu, 01 Jul 2021 00:32:38 GMT"
        }
    },
    "SOCRadarThreatFusion": {
        "Reputation": {
            "Domain": {
                "DNS Details": {
                    "A": [
                        "1.1.1.1"
                    ],
                    "MX": [
                        "mx record"
                    ],
                    "NS": [
                        "ns record"
                    ],
                    "SOA": [
                        "domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600"
                    ],
                    "TXT": [
                        "txt record"
                    ]
                },
                "Domain": "paloaltonetworks.com",
                "Risk Score (Out of 1000)": 0,
                "Score Details": {},
                "Subdomains": [],
                "Total Encounters": 0,
                "Whois Details": {
                    "address": null,
                    "city": null,
                    "country": "US",
                    "creation_date": "Mon, 21 Feb 2005 02:42:10 GMT",
                    "dnssec": "signedDelegation",
                    "domain_name": "PALOALTONETWORKS.COM",
                    "emails": [
                        "abusecomplaints@markmonitor.com",
                        "whoisrequest@markmonitor.com"
                    ],
                    "expiration_date": "Wed, 21 Feb 2024 02:42:10 GMT",
                    "name": null,
                    "name_servers": [
                        "ns record"
                    ],
                    "org": "Palo Alto Networks, Inc.",
                    "referral_url": null,
                    "registrar": "MarkMonitor Inc.",
                    "state": "CA",
                    "status": [
                        "clientTransferProhibited https://icann.org/epp#clientTransferProhibited",
                        "clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited)",
                        "clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited)",
                        "clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited",
                        "clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)",
                        "clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited"
                    ],
                    "updated_date": "Thu, 01 Jul 2021 00:32:38 GMT",
                    "whois_server": "whois.markmonitor.com",
                    "zipcode": null
                }
            }
        }
    }
}

Human Readable Output

SOCRadar - Analysis results for domain: paloaltonetworks.com

DNS Details Domain Risk Score (Out of 1000) Score Details Subdomains Total Encounters Whois Details
A: 1.1.1.1
MX: mx record
NS: ns record
SOA: domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600
TXT: txt record
paloaltonetworks.com 0     0 org: Palo Alto Networks, Inc.
city: null
name: null
state: CA
dnssec: signedDelegation
emails: abusecomplaints@markmonitor.com,
whoisrequest@markmonitor.com
status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited,
clientTransferProhibited https://icann.org/epp#clientTransferProhibited,
clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited,
clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited),
clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited),
clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)
address: null
country: US
zipcode: null
registrar: MarkMonitor Inc.
domain_name: PALOALTONETWORKS.COM
name_servers: ns record
referral_url: null
updated_date: Thu, 01 Jul 2021 00:32:38 GMT
whois_server: whois.markmonitor.com
creation_date: Mon, 21 Feb 2005 02:42:10 GMT
expiration_date: Wed, 21 Feb 2024 02:42:10 GMT

file


Scores provided hash entities’ reputation in SOCRadar ThreatFusion.

Base Command

file

Input

Argument Name Description Required
file Hash entities to score. (MD5 or SHA1). Required

Context Output

Path Type Description
SOCRadarThreatFusion.Reputation.Hash.Risk Score Number Reputation score of queried hash.
SOCRadarThreatFusion.Reputation.Hash.Score Details JSON Risk score details of queried hash.
SOCRadarThreatFusion.Reputation.Hash.Total Encounters Number Number of times that SOCRadar has encountered with the queried hash in its threat sources.
SOCRadarThreatFusion.Reputation.Hash.File String Queried hash.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
File.MD5 String The MD5 hash of the file.
File.SHA1 String The SHA1 hash of the file.

Command Example

!file file="3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"

Context Example

{
    "DBotScore": {
        "Indicator": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
        "Score": 1,
        "Type": "file",
        "Vendor": "SOCRadar ThreatFusion"
    },
    "File": {
        "MD5": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"
    },
    "SOCRadarThreatFusion": {
        "Reputation": {
            "Hash": {
                "File": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
                "Risk Score (Out of 1000)": 360,
                "Score Details": {
                    "Maldatabase": 360
                },
                "Total Encounters": 1
            }
        }
    }
}

Human Readable Output

SOCRadar - Analysis results for hash: 3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792

File Risk Score (Out of 1000) Score Details Total Encounters
3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792 360.0 Maldatabase: 360.0 1

socradar-score-ip


Scores provided IP entity’s reputation in SOCRadar ThreatFusion.

Base Command

socradar-score-ip

Input

Argument Name Description Required
ip IP entity to score. (IPv4 or IPv6). Required

Context Output

Path Type Description
SOCRadarThreatFusion.Reputation.IP.Risk Score Number Reputation score of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Score Details JSON Risk score details of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Total Encounters Number Number of times that SOCRadar has encountered with the queried IP address in its threat sources.
SOCRadarThreatFusion.Reputation.IP.IP String Queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn String ASN field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_cidr String ASN CIDR field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_country_code String ASN country code field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_date Date ASN date field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_description String ASN description field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.asn_registry String ASN registry field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.address String Nets>address field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.cidr String Nets>CIDR field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.city String Nets>city field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.country String Nets>country field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.created String Nets>created field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.description String Nets>description field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.emails String Nets>emails field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.handle String Nets>handle field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.name String Nets>name field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.postal_code Number Nets>postal code field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.range String Nets>range field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.state String Nets>state field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nets.updated Date Nets>updated field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.nir String NIR field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.query String Query field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.raw_referral String Raw referral field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Whois Details.referral String Referral field Whois information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.DNS Details JSON DNS information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.ASN Number ASN field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnCode Number ASN code field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.AsnName String ASN name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Cidr String CIDR field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.CityName String City name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryCode String Country code field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.CountryName String Country name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Latitude Number Latitude field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Longitude Number Longitude field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.RegionName String Region name field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.Timezone String Timezone field Geographical location information of queried IP address.
SOCRadarThreatFusion.Reputation.IP.Geo Location.ZipCode String Zip code field Geographical location information of queried IP address.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the indicator score.

Command Example

!socradar-score-ip ip="1.1.1.1"

Context Example

{
    "SOCRadarThreatFusion": {
        "Reputation": {
            "IP": {
                "DBotScore": {
                    "Indicator": "1.1.1.1",
                    "Score": 1,
                    "Type": "ip",
                    "Vendor": "SOCRadar ThreatFusion"
                },
                "DNS Details": {
                    "PTR": [
                        "one.one.one.one"
                    ]
                },
                "Geo Location": {
                    "ASN": "[13335] CLOUDFLARENET, US",
                    "AsnCode": 13335,
                    "AsnName": "CloudFlare Inc",
                    "Cidr": "1.1.1.0/24",
                    "CityName": "Los Angeles",
                    "CountryCode": "US",
                    "CountryName": "United States of America",
                    "Latitude": 0.0,
                    "Longitude": 0.0,
                    "RegionName": "California",
                    "Timezone": "-07:00",
                    "ZipCode": "90001"
                },
                "IP": "1.1.1.1",
                "Risk Score (Out of 1000)": 0,
                "Score Details": {},
                "Total Encounters": 0,
                "Whois Details": {
                    "asn": "13335",
                    "asn_cidr": "1.1.1.0/24",
                    "asn_country_code": "AU",
                    "asn_date": "2011-08-11",
                    "asn_description": "CLOUDFLARENET, US",
                    "asn_registry": "apnic",
                    "nets": [
                        {
                            "address": "PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia",
                            "cidr": "1.1.1.0/24",
                            "city": null,
                            "country": "AU",
                            "created": null,
                            "description": "APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs",
                            "emails": [
                                "resolver-abuse@cloudflare.com"
                            ],
                            "handle": "AA1412-AP",
                            "name": "APNIC-LABS",
                            "postal_code": null,
                            "range": "1.1.1.0 - 1.1.1.255",
                            "state": null,
                            "updated": null
                        },
                        {
                            "address": null,
                            "cidr": "1.1.1.0/24",
                            "city": null,
                            "country": null,
                            "created": null,
                            "description": "APNIC Research and Development\n                6 Cordelia St",
                            "emails": null,
                            "handle": null,
                            "name": null,
                            "postal_code": null,
                            "range": "1.1.1.0 - 1.1.1.255",
                            "state": null,
                            "updated": null
                        }
                    ],
                    "nir": null,
                    "query": "1.1.1.1",
                    "raw_referral": null,
                    "referral": null
                }
            }
        }
    }
}

Human Readable Output

SOCRadar - Analysis results for IP: 1.1.1.1

DNS Details Geo Location IP Risk Score (Out of 1000) Score Details Total Encounters Whois Details
PTR: one.one.one.one AsnCode: 13335
AsnName: CloudFlare Inc
Cidr: 1.1.1.0/24
CityName: Los Angeles
CountryCode: US
CountryName: United States of America
ASN: [13335] CLOUDFLARENET, US
Latitude: 0.0
Longitude: 0.0
RegionName: California
Timezone: -07:00
ZipCode: 90001
1.1.1.1 0   0 asn: 13335
asn_cidr: 1.1.1.0/24
asn_country_code: AU
asn_date: 2011-08-11
asn_description: CLOUDFLARENET, US
asn_registry: apnic
nets: {‘address’: ‘PO Box 3646\nSouth Brisbane, QLD 4101\nAustralia’, ‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘country’: ‘AU’, ‘created’: None, ‘description’: ‘APNIC and Cloudflare DNS Resolver project\nRouted globally by AS13335/Cloudflare\nResearch prefix for APNIC Labs’, ‘emails’: [‘resolver-abuse@cloudflare.com’], ‘handle’: ‘AA1412-AP’, ‘name’: ‘APNIC-LABS’, ‘postal_code’: None, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘updated’: None},
{‘address’: None, ‘cidr’: ‘1.1.1.0/24’, ‘city’: None, ‘country’: None, ‘created’: None, ‘description’: ‘APNIC Research and Development\n 6 Cordelia St’, ‘emails’: None, ‘handle’: None, ‘name’: None, ‘postal_code’: None, ‘range’: ‘1.1.1.0 - 1.1.1.255’, ‘state’: None, ‘updated’: None}
nir: null
query: 1.1.1.1
raw_referral: null
referral: null

socradar-score-domain


Scores provided domain entity’s reputation in SOCRadar ThreatFusion.

Base Command

socradar-score-domain

Input

Argument Name Description Required
domain Domain entity to score. Required

Context Output

Path Type Description
SOCRadarThreatFusion.Reputation.Domain.Risk Score Number Reputation score of queried domain.
SOCRadarThreatFusion.Reputation.IP.Score Details JSON Risk score details of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Total Encounters Number Number of times that SOCRadar has encountered with the queried domain in its threat sources.
SOCRadarThreatFusion.Reputation.Domain.Domain String Queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.org String Org field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.city String City field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.name String Name field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.state String State field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.dnssec String Dnssec field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.emails String Emails field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.status String Status field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.address String Address field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.country String Country field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.zipcode Number Zip code field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.registrar String Registrar field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.domain_name String Domain name field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.name_servers String Name servers field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.referral_url String Referral URL field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.updated_date Date Updated date field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.whois_server String Whois server field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.creation_date Date Creation date field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.Whois Details.expiration_date Date Expiration date field Whois information of queried domain.
SOCRadarThreatFusion.Reputation.Domain.DNS Details String DNS information of queried domain.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the indicator score.

Command Example

!socradar-score-domain domain="paloaltonetworks.com"

Context Example

{
    "SOCRadarThreatFusion": {
        "Reputation": {
            "Domain": {
                "DBotScore": {
                    "Indicator": "paloaltonetworks.com",
                    "Score": 1,
                    "Type": "domain",
                    "Vendor": "SOCRadar ThreatFusion"
                },
                "DNS Details": {
                    "A": [
                        "1.1.1.1"
                    ],
                    "MX": [
                        "mx record"
                    ],
                    "NS": [
                        "ns record"
                    ],
                    "SOA": [
                        "domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600"
                    ],
                    "TXT": [
                        "txt record"
                    ]
                },
                "Domain": "paloaltonetworks.com",
                "Risk Score (Out of 1000)": 0,
                "Score Details": {},
                "Subdomains": [],
                "Total Encounters": 0,
                "Whois Details": {
                    "address": null,
                    "city": null,
                    "country": "US",
                    "creation_date": "Mon, 21 Feb 2005 02:42:10 GMT",
                    "dnssec": "signedDelegation",
                    "domain_name": "PALOALTONETWORKS.COM",
                    "emails": [
                        "abusecomplaints@markmonitor.com",
                        "whoisrequest@markmonitor.com"
                    ],
                    "expiration_date": "Wed, 21 Feb 2024 02:42:10 GMT",
                    "name": null,
                    "name_servers": [
                        "ns record"
                    ],
                    "org": "Palo Alto Networks, Inc.",
                    "referral_url": null,
                    "registrar": "MarkMonitor Inc.",
                    "state": "CA",
                    "status": [
                        "clientTransferProhibited https://icann.org/epp#clientTransferProhibited",
                        "clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited)",
                        "clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited)",
                        "clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited",
                        "clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)",
                        "clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited"
                    ],
                    "updated_date": "Thu, 01 Jul 2021 00:32:38 GMT",
                    "whois_server": "whois.markmonitor.com",
                    "zipcode": null
                }
            }
        }
    }
}

Human Readable Output

SOCRadar - Analysis results for domain: paloaltonetworks.com

DNS Details Domain Risk Score (Out of 1000) Score Details Subdomains Total Encounters Whois Details
A: 1.1.1.1
MX: mx record
NS: ns record
SOA: domains.paloaltonetworks.com. 1627343953 3600 600 604800 3600
TXT: txt record
paloaltonetworks.com 0     0 org: Palo Alto Networks, Inc.
city: null
name: null
state: CA
dnssec: signedDelegation
emails: abusecomplaints@markmonitor.com,
whoisrequest@markmonitor.com
status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited,
clientTransferProhibited https://icann.org/epp#clientTransferProhibited,
clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited,
clientTransferProhibited (https://www.icann.org/epp#clientTransferProhibited),
clientUpdateProhibited (https://www.icann.org/epp#clientUpdateProhibited),
clientDeleteProhibited (https://www.icann.org/epp#clientDeleteProhibited)
address: null
country: US
zipcode: null
registrar: MarkMonitor Inc.
domain_name: PALOALTONETWORKS.COM
name_servers: ns record
referral_url: null
updated_date: Thu, 01 Jul 2021 00:32:38 GMT
whois_server: whois.markmonitor.com
creation_date: Mon, 21 Feb 2005 02:42:10 GMT
expiration_date: Wed, 21 Feb 2024 02:42:10 GMT

socradar-score-hash


Scores provided hash entity’s reputation in SOCRadar ThreatFusion.

Base Command

socradar-score-hash

Input

Argument Name Description Required
hash Hash entity to score. (MD5 or SHA1). Required

Context Output

Path Type Description
SOCRadarThreatFusion.Reputation.Hash.Risk Score Number Reputation score of queried hash.
SOCRadarThreatFusion.Reputation.Hash.Score Details JSON Risk score details of queried hash.
SOCRadarThreatFusion.Reputation.Hash.Total Encounters Number Number of times that SOCRadar has encountered with the queried hash in its threat sources.
SOCRadarThreatFusion.Reputation.Hash.File String Queried hash.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Score Number The actual score.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the indicator score.

Command Example

!socradar-score-hash hash="3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"

Context Example

{
    "SOCRadarThreatFusion": {
        "Reputation": {
            "Hash": {
                "DBotScore": {
                    "Indicator": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
                    "Score": 1,
                    "Type": "file",
                    "Vendor": "SOCRadar ThreatFusion"
                },
                "File": "3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792",
                "Risk Score (Out of 1000)": 360,
                "Score Details": {
                    "Maldatabase": 360
                },
                "Total Encounters": 1
            }
        }
    }
}

Human Readable Output

SOCRadar - Analysis results for hash: 3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792

File Risk Score (Out of 1000) Score Details Total Encounters
3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792 360.0 Maldatabase: 360.0 1

Configuration parameters

  • apikey — API Key (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • integrationReliability — Source Reliability
  • feedExpirationPolicy
  • feedExpirationInterval

Commands (6)

  • domain

    Scores provided domain entities' reputation in SOCRadar ThreatFusion.

  • file

    Scores provided hash entities' reputation in SOCRadar ThreatFusion.

  • ip

    Scores provided IP entities' reputation in SOCRadar ThreatFusion.

  • socradar-score-domain

    Scores provided domain entity's reputation in SOCRadar ThreatFusion.

  • socradar-score-hash

    Scores provided hash entity's reputation in SOCRadar ThreatFusion.

  • socradar-score-ip

    Scores provided IP entity's reputation in SOCRadar ThreatFusion.

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401
from json.decoder import JSONDecodeError

from CommonServerUserPython import *  # noqa

import urllib3
import traceback
from typing import Any

# Disable insecure warnings
urllib3.disable_warnings()  # pylint: disable=no-member


""" CONSTANTS """

SOCRADAR_API_ENDPOINT = "https://platform.socradar.com/api"
MESSAGES: dict[str, str] = {
    "BAD_REQUEST_ERROR": "An error occurred while fetching the data.",
    "AUTHORIZATION_ERROR": "Authorization Error: make sure API Key is correctly set.",
    "RATE_LIMIT_EXCEED_ERROR": "Rate limit has been exceeded. Please make sure your your API key's rate limit is adequate.",
}
INTEGRATION_NAME = "SOCRadar ThreatFusion"

""" CLIENT CLASS """


class Client(BaseClient):
    """
    Client class to interact with the SOCRadar API
    """

    def __init__(self, base_url, api_key, verify, proxy):
        super().__init__(base_url, verify=verify, proxy=proxy)
        self.api_key = api_key

    def get_entity_score(self, entity):
        suffix = "/threat/analysis"
        api_params = {"key": self.api_key, "entity": entity}
        response = self._http_request(
            method="GET",
            url_suffix=suffix,
            params=api_params,
            timeout=60,
            error_handler=self.handle_error_response,
        )
        return response

    def check_auth(self):
        suffix = "/threat/analysis/check/auth"
        api_params = {"key": self.api_key}
        response = self._http_request(
            method="GET",
            url_suffix=suffix,
            params=api_params,
            error_handler=self.handle_error_response,
        )

        return response

    @staticmethod
    def handle_error_response(response) -> None:
        """Handles API response to display descriptive error messages based on status code

        :param response: SOCRadar API response.
        :return: DemistoException for particular error code.
        """

        error_reason = ""
        try:
            json_resp = response.json()
            error_reason = json_resp.get("error") or json_resp.get("message")
        except JSONDecodeError:
            pass

        status_code_messages = {
            400: f"{MESSAGES['BAD_REQUEST_ERROR']} Reason: {error_reason}",
            401: MESSAGES["AUTHORIZATION_ERROR"],
            404: f"{MESSAGES['BAD_REQUEST_ERROR']} Reason: {error_reason}",
            429: MESSAGES["RATE_LIMIT_EXCEED_ERROR"],
        }

        if response.status_code in status_code_messages:
            demisto.debug(f"Response Code: {response.status_code}, Reason: {status_code_messages[response.status_code]}")
            raise DemistoException(status_code_messages[response.status_code])
        else:
            raise DemistoException(response.raise_for_status())


""" HELPER FUNCTIONS """


def calculate_dbot_score(score: int) -> int:
    """Transforms cyber risk score (reputation) from SOCRadar API to DBot Score and using threshold.

    Args:
        score: Cyber risk score (reputation) from SOCRadar API

    Returns:
        Score representation in DBot
    """
    return_score = 0
    # Malicious
    if score > 800:
        return_score = 3
    # Suspicious
    elif score > 400:
        return_score = 2
    # Good
    elif score > 0:
        return_score = 1
    # Unknown
    return return_score


class Validator:
    @staticmethod
    def validate_domain(domain_to_validate):
        if not isinstance(domain_to_validate, str) or len(domain_to_validate) > 255:
            return False
        if domain_to_validate.endswith("."):
            domain_to_validate = domain_to_validate[:-1]
        domain_regex = re.compile(r"(?!-)[A-Z\d-]{1,63}(?<!-)$", re.IGNORECASE)
        return all(domain_regex.match(x) for x in domain_to_validate.split("."))

    @staticmethod
    def validate_ipv4(ip_to_validate):
        return is_ip_valid(ip_to_validate)

    @staticmethod
    def validate_ipv6(ip_to_validate):
        return is_ipv6_valid(ip_to_validate)

    @staticmethod
    def validate_hash(hash_to_validate):
        return get_hash_type(hash_to_validate) != "Unknown"

    @staticmethod
    def raise_if_ip_not_valid(ip: str):
        """Raises an error if ip is not valid

        Args:
            ip: ip

        Raises:
            ValueError: if ip is not type of ipv4 or ipv6

        Examples:
            >>> Validator.raise_if_ip_not_valid('not an ip')
            Traceback (most recent call last):
             ...
            ValueError: IP "not an ip" is not a type of IPv4 or IPv6
            >>> Validator.raise_if_ip_not_valid('1.1.1.1')
        """
        if not Validator.validate_ipv4(ip) and not Validator.validate_ipv6(ip):
            raise ValueError(f'IP "{ip}" is not a type of IPv4 or IPv6')

    @staticmethod
    def raise_if_domain_not_valid(domain: str):
        """Raises an error if domain is not valid

        Args:
            domain: domain

        Raises:
            ValueError: if domain is not a valid domain address

        Examples:
            >>> Validator.raise_if_domain_not_valid('not a domain')
            Traceback (most recent call last):
             ...
            ValueError: Domain "not a domain" is not a valid domain address
            >>> Validator.raise_if_hash_not_valid('not a domain')
        """
        if not Validator.validate_domain(domain):
            raise ValueError(f'Domain "{domain}" is not a valid domain address')

    @staticmethod
    def raise_if_hash_not_valid(file_hash: str):
        """Raises an error if file_hash is not valid

        Args:
            file_hash: file hash

        Raises:
            ValueError: if hash is not of type SHA-1 or MD5

        Examples:
            >>> Validator.raise_if_hash_not_valid('not a hash')
            Traceback (most recent call last):
             ...
            ValueError: Hash "not a hash" is not of type SHA-1 or MD5
            >>> Validator.raise_if_hash_not_valid('7e641f6b9706d860baf09fe418b6cc87')
        """
        if not Validator.validate_hash(file_hash):
            raise ValueError(f'Hash "{file_hash}" is not of type SHA-1 or MD5')


def verify_entity_type(entity_to_control_list: list, entity_type: str):
    """Verify intended entity type. Raise exception if the provided entity type is not expected.

    :type entity_to_control_list: ``list``
    :param entity_to_control_list: Intended entity list to be verified.

    :type entity_type: ``str``
    :param entity_type: Intended entity type to be verified.
    """
    control_dict = {
        "ip": Validator.raise_if_ip_not_valid,
        "domain": Validator.raise_if_domain_not_valid,
        "hash": Validator.raise_if_hash_not_valid,
    }
    for entity_to_control in entity_to_control_list:
        control_dict[entity_type](entity_to_control)


def map_indicator_type(socradar_indicator_type: str) -> Optional[str]:
    """Map SOCRadar indicator type to XSOAR indicator type

    :type socradar_indicator_type: ``str``
    :param socradar_indicator_type: The SOCRadar indicator type

    :return: XSOAR indicator type
    :rtype: ``Optional[str]``
    """
    indicator_map = {
        "ipv4": FeedIndicatorType.IP,
        "ipv6": FeedIndicatorType.IPv6,
        "hash": FeedIndicatorType.File,
        "hostname": FeedIndicatorType.Domain,
    }

    return indicator_map.get(socradar_indicator_type)


def build_entry_context(results: Union[dict, List], indicator_type: str):
    """Formatting results from SOCRadar API to Demisto Context

    :type results: ``Union[Dict, List]``
    :param results: Raw results obtained from SOCRadar API.

    :type indicator_type: ``str``
    :param results: Type of indicator to be used in context creation.
    """

    if isinstance(results, list):
        return [build_entry_context(entry, indicator_type) for entry in results]  # pragma: no cover

    result_data = results.get("data", {})
    return_context = {
        "Risk Score (Out of 100)": result_data.get("score"),
        "Score Details": result_data.get("score_details"),
        "Total Encounters": len(result_data.get("findings", [])),
        map_indicator_type(result_data.get("classification")): result_data.get("value"),
    }

    if indicator_type == "domain":
        return_context["Subdomains"] = result_data.get("subdomains", [])

    if indicator_type != "hash":
        return_context["Whois Details"] = {}
        for key, value in result_data.get("whois", {}).items():
            # Exclude raw whois
            if key == "raw":
                continue
            if value and type(value) is list and key in ("creation_date", "expiration_date", "updated_date", "registrar"):
                value = value[0]
            return_context["Whois Details"][key] = value
        return_context["DNS Details"] = result_data.get("dns_info", {})

    if indicator_type == "ip":
        geo_location_dict = {}
        if result_data.get("geo_location", []):
            geo_location = result_data["geo_location"][0]
            geo_location_dict = {key: value for key, value in geo_location.items() if key.lower() != "ip"}

        asn_code = result_data.get("whois", {}).get("asn", "")
        if not asn_code:
            asn_code = geo_location_dict.get("AsnCode", "")
        asn_description = result_data.get("whois", {}).get("asn_description", "")
        if not asn_description:
            asn_description = geo_location_dict.get("AsnName", "")
        asn = f"[{asn_code}] {asn_description}"
        geo_location_dict["ASN"] = asn
        return_context["Geo Location"] = geo_location_dict

    return return_context


""" COMMAND FUNCTIONS """


def test_module(client: Client) -> str:
    """Tests API connectivity and authentication'

    Returning 'ok' indicates that the integration works like it is supposed to.
    Connection to the service is successful.
    Raises exceptions if something goes wrong.

    :type client: ``Client``
    :param client: client to use

    :return: 'ok' if test passed, anything else will fail the test.
    :rtype: ``str``
    """
    client.check_auth()
    return "ok"


def ip_command(client: Client, args: dict[str, Any]) -> List[CommandResults]:
    """Returns SOCRadar reputation details for the given IP entities.

    :type client: ``Client``
    :param client: client to use

    :type args: Dict[str, Any]
    :param args: contains all arguments for ip_command

    :return:
        List of ``CommandResults`` objects that is then passed to ``return_results``
    :rtype: ``List[CommandResults]``
    """

    ip_addresses = args.get("ip", "")
    ip_list: list = argToList(ip_addresses)
    verify_entity_type(ip_list, "ip")

    command_results_list: List[CommandResults] = []

    for ip_to_score in ip_list:
        raw_response = client.get_entity_score(ip_to_score)

        if raw_response.get("is_success"):
            if raw_response.get("data", {}).get("is_whitelisted"):
                score = 1
            elif (score := raw_response.get("data", {}).get("score", 0)) is not None:
                score = calculate_dbot_score(score)
            title = f"SOCRadar - Analysis results for IP: {ip_to_score}"

            context_entry = build_entry_context(raw_response, "ip")
            human_readable = tableToMarkdown(title, context_entry)

            dbot_score = Common.DBotScore(
                indicator=ip_to_score,
                indicator_type=DBotScoreType.IP,
                integration_name=INTEGRATION_NAME,
                score=score,
                reliability=demisto.params().get("integrationReliability"),
            )

            ip_object = Common.IP(
                ip=ip_to_score,
                dbot_score=dbot_score,
                asn=context_entry["Geo Location"].get("ASN"),
                geo_country=context_entry["Geo Location"].get("CountryCode"),
                geo_latitude=context_entry["Geo Location"].get("Latitude"),
                geo_longitude=context_entry["Geo Location"].get("Longitude"),
                region=context_entry["Geo Location"].get("RegionName"),
            )

            command_results_list.append(
                CommandResults(
                    outputs_prefix="SOCRadarThreatFusion.Reputation.IP",
                    outputs_key_field="IP",
                    readable_output=human_readable,
                    raw_response=raw_response,
                    outputs=context_entry,
                    indicator=ip_object,
                )
            )
        else:
            message = (
                f"Error at scoring IP {ip_to_score} while getting API response. "
                f"SOCRadar ThreatFusion API Response: {raw_response.get('message', '')}"
            )
            command_results_list.append(CommandResults(readable_output=message))
    if not command_results_list:
        command_results_list = [CommandResults("SOCRadar ThreatFusion could not find any results for the given IP address(es).")]
    return command_results_list


def domain_command(client: Client, args: dict[str, Any]) -> List[CommandResults]:
    """Returns SOCRadar reputation details for the given domain entities.

    :type client: ``Client``
    :param client: client to use

    :type args: Dict[str, Any]
    :param args: contains all arguments for domain_command

    :return:
        List of ``CommandResults`` objects that is then passed to ``return_results``
    :rtype: ``List[CommandResults]``
    """
    domains = args.get("domain", "")
    domains_list: list = argToList(domains)
    verify_entity_type(domains_list, "domain")

    command_results_list: List[CommandResults] = []

    for domain_to_score in domains_list:
        raw_response = client.get_entity_score(domain_to_score)

        if raw_response.get("is_success"):
            if raw_response.get("data", {}).get("is_whitelisted"):
                score = 1
            elif (score := raw_response.get("data", {}).get("score", 0)) is not None:
                score = calculate_dbot_score(score)
            title = f"SOCRadar - Analysis results for domain: {domain_to_score}"

            context_entry = build_entry_context(raw_response, "domain")
            human_readable = tableToMarkdown(title, context_entry)

            dbot_score = Common.DBotScore(
                indicator=domain_to_score,
                indicator_type=DBotScoreType.DOMAIN,
                integration_name=INTEGRATION_NAME,
                score=score,
                reliability=demisto.params().get("integrationReliability"),
            )

            domain_object = Common.Domain(
                domain=domain_to_score,
                dbot_score=dbot_score,
                dns=", ".join(context_entry["DNS Details"].get("A", [])),
                creation_date=context_entry["Whois Details"].get("creation_date"),
                expiration_date=context_entry["Whois Details"].get("expiration_date"),
                updated_date=context_entry["Whois Details"].get("updated_date"),
                registrant_country=context_entry["Whois Details"].get("registrant_country"),
                registrant_name=context_entry["Whois Details"].get("registrant_name")
                or context_entry["Whois Details"].get("name"),
                registrar_name=context_entry["Whois Details"].get("registrar"),
                organization=context_entry["Whois Details"].get("org"),
                geo_country=context_entry["Whois Details"].get("country"),
                sub_domains=context_entry["Subdomains"],
                name_servers=context_entry["DNS Details"].get("NS") or context_entry["Whois Details"].get("name_servers"),
            )

            command_results_list.append(
                CommandResults(
                    outputs_prefix="SOCRadarThreatFusion.Reputation.Domain",
                    outputs_key_field="Domain",
                    readable_output=human_readable,
                    raw_response=raw_response,
                    outputs=context_entry,
                    indicator=domain_object,
                )
            )
        else:
            message = (
                f"Error at scoring domain {domain_to_score} while getting API response. "
                f"SOCRadar ThreatFusion API Response: {raw_response.get('message', '')}"
            )
            command_results_list.append(CommandResults(readable_output=message))
    if not command_results_list:
        command_results_list = [CommandResults("SOCRadar ThreatFusion could not find any results for the given domain(s).")]

    return command_results_list


def file_command(client: Client, args: dict[str, Any]) -> List[CommandResults]:
    """Returns SOCRadar reputation details for the given hash entities.

    :type client: ``Client``
    :param client: client to use

    :type args: Dict[str, Any]
    :param args: contains all arguments for hash_command

    :return:
        List of ``CommandResults`` objects that is then passed to ``return_results``
    :rtype: ``List[CommandResults]``
    """
    file_hashes = args.get("file", "")
    file_hash_list: list = argToList(file_hashes)
    verify_entity_type(file_hash_list, "hash")

    command_results_list: List[CommandResults] = []

    for hash_to_score in file_hash_list:
        hash_type = get_hash_type(hash_to_score)

        raw_response = client.get_entity_score(hash_to_score)

        if raw_response.get("is_success"):
            if raw_response.get("data", {}).get("is_whitelisted"):
                score = 1
            elif (score := raw_response.get("data", {}).get("score", 0)) is not None:
                score = calculate_dbot_score(score)
            title = f"SOCRadar - Analysis results for hash: {hash_to_score}"

            context_entry = build_entry_context(raw_response, "hash")
            human_readable = tableToMarkdown(title, context_entry)

            dbot_score = Common.DBotScore(
                indicator=hash_to_score,
                indicator_type=DBotScoreType.FILE,
                integration_name=INTEGRATION_NAME,
                score=score,
                reliability=demisto.params().get("integrationReliability"),
            )

            file_object = Common.File(dbot_score=dbot_score)
            # hash_type can either be 'sha-1' or 'md5' at this point.
            if hash_type == "sha-1":
                file_object.sha1 = hash_to_score
            else:
                file_object.md5 = hash_to_score

            command_results_list.append(
                CommandResults(
                    outputs_prefix="SOCRadarThreatFusion.Reputation.Hash",
                    outputs_key_field="File",
                    readable_output=human_readable,
                    raw_response=raw_response,
                    outputs=context_entry,
                    indicator=file_object,
                )
            )
        else:
            message = (
                f"Error at scoring file hash {hash_to_score} while getting API response. "
                f"SOCRadar ThreatFusion API Response: {raw_response.get('message', '')}"
            )
            command_results_list.append(CommandResults(readable_output=message))
    if not command_results_list:
        command_results_list = [CommandResults("SOCRadar ThreatFusion could not find any results for the given file hash(es).")]

    return command_results_list


def score_ip_command(client: Client, args: dict[str, Any]) -> CommandResults:
    """Returns SOCRadar reputation details for the given IP entity.

    :type client: ``Client``
    :param client: client to use

    :type args: Dict[str, Any]
    :param args: contains all arguments for list-detections command

    :return:
        A ``CommandResults`` object that is then passed to ``return_results``
    :rtype: ``CommandResults``
    """
    ip_to_score = args.get("ip", "")
    verify_entity_type([ip_to_score], "ip")

    raw_response = client.get_entity_score(ip_to_score)
    if raw_response.get("is_success"):
        if raw_response.get("data", {}).get("is_whitelisted"):
            score = 1
        elif (score := raw_response.get("data", {}).get("score", 0)) is not None:
            score = calculate_dbot_score(score)
        title = f"SOCRadar - Analysis results for IP: {ip_to_score}"
        context_entry = build_entry_context(raw_response, "ip")
        dbot_entry = build_dbot_entry(ip_to_score, DBotScoreType.IP, "SOCRadar ThreatFusion", score)
        human_readable = tableToMarkdown(title, context_entry)
        context_entry.update(dbot_entry)
    else:
        message = f"Error while getting API response. SOCRadar API Response: {raw_response.get('message', '')}"
        raise DemistoException(message=message)

    return CommandResults(
        outputs_prefix="SOCRadarThreatFusion.Reputation.IP",
        outputs_key_field="IP",
        readable_output=human_readable,
        raw_response=raw_response,
        outputs=context_entry,
    )


def score_domain_command(client: Client, args: dict[str, Any]) -> CommandResults:
    """Returns SOCRadar reputation details for the given domain entity.

    :type client: ``Client``
    :param client: client to use

    :type args: Dict[str, Any]
    :param args: contains all arguments for list-detections command

    :return:
        A ``CommandResults`` object that is then passed to ``return_results``
    :rtype: ``CommandResults``
    """
    domain_to_score = args.get("domain", "")
    verify_entity_type([domain_to_score], "domain")

    raw_response = client.get_entity_score(domain_to_score)
    if raw_response.get("is_success"):
        if raw_response.get("data", {}).get("is_whitelisted"):
            score = 1
        elif (score := raw_response.get("data", {}).get("score", 0)) is not None:
            score = calculate_dbot_score(score)
        title = f"SOCRadar - Analysis results for domain: {domain_to_score}"
        context_entry = build_entry_context(raw_response, "domain")
        dbot_entry = build_dbot_entry(domain_to_score, DBotScoreType.DOMAIN, "SOCRadar ThreatFusion", score)
        human_readable = tableToMarkdown(title, context_entry)
        context_entry.update(dbot_entry)
    else:
        message = f"Error while getting API response. SOCRadar API Response: {raw_response.get('message', '')}"
        raise DemistoException(message=message)

    return CommandResults(
        outputs_prefix="SOCRadarThreatFusion.Reputation.Domain",
        outputs_key_field="Domain",
        readable_output=human_readable,
        raw_response=raw_response,
        outputs=context_entry,
    )


def score_hash_command(client: Client, args: dict[str, Any]) -> CommandResults:
    """Returns SOCRadar reputation details for the given hash entity.

    :type client: ``Client``
    :param client: client to use

    :type args: Dict[str, Any]
    :param args: contains all arguments for list-detections command

    :return:
        A ``CommandResults`` object that is then passed to ``return_results``
    :rtype: ``CommandResults``
    """
    hash_to_score = args.get("hash", "")
    verify_entity_type([hash_to_score], "hash")
    hash_type = get_hash_type(hash_to_score)

    raw_response = client.get_entity_score(hash_to_score)
    if raw_response.get("is_success"):
        if raw_response.get("data", {}).get("is_whitelisted"):
            score = 1
        elif (score := raw_response.get("data", {}).get("score", 0)) is not None:
            score = calculate_dbot_score(score)
        title = f"SOCRadar - Analysis results for hash: {hash_to_score}"
        context_entry = build_entry_context(raw_response, "hash")
        dbot_entry = build_dbot_entry(hash_to_score, hash_type, "SOCRadar ThreatFusion", score)
        human_readable = tableToMarkdown(title, context_entry)
        context_entry.update(dbot_entry)
    else:
        message = f"Error while getting API response. SOCRadar API Response: {raw_response.get('message', '')}"
        raise DemistoException(message=message)

    return CommandResults(
        outputs_prefix="SOCRadarThreatFusion.Reputation.Hash",
        outputs_key_field="File",
        readable_output=human_readable,
        raw_response=raw_response,
        outputs=context_entry,
    )


""" MAIN FUNCTION """


def main() -> None:
    """main function, parses params and runs command functions

    :return:
    :rtype:
    """

    api_key = demisto.params().get("apikey")
    base_url = SOCRADAR_API_ENDPOINT
    verify_certificate = not demisto.params().get("insecure", False)
    proxy = demisto.params().get("proxy", False)

    demisto.debug(f"Command being called is {demisto.command()}")
    try:
        client = Client(base_url=base_url, api_key=api_key, verify=verify_certificate, proxy=proxy)
        command = demisto.command()

        commands = {
            "ip": ip_command,
            "domain": domain_command,
            "file": file_command,
            "socradar-score-ip": score_ip_command,
            "socradar-score-domain": score_domain_command,
            "socradar-score-hash": score_hash_command,
        }
        if command == "test-module":
            return_results(test_module(client))
        else:
            command_function = commands.get(command)
            if command_function:
                return_results(command_function(client, demisto.args()))

    except Exception as e:
        demisto.error(traceback.format_exc())
        return_error(f"Failed to execute {demisto.command()} command.\nError:\n{str(e)}")


""" ENTRY POINT """


if __name__ in ("__main__", "__builtin__", "builtins"):
    main()