ThreatZone
ThreatZone malware analysis sandboxing.
- Category
- Forensics & Malware Analysis
- Pack
- ThreatZone
Configuration parameters
- url — Server URL (e.g. https://app.threat.zone) (required)
- apikey — (required)
- integrationReliability — Source Reliability
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (44)
- tz-cdr-upload-sample — Submits a sample to ThreatZone for CDR.
- tz-check-limits — Check the plan limits from ThreatZone API.
- tz-download-artifact — Downloads an extracted artifact to the War Room.
- tz-download-html-report — Downloads the HTML report for a submission and uploads it to the War Room.
- tz-download-media-file — Downloads a submission media file to the War Room.
- tz-download-pcap — Downloads the network capture to the War Room.
- tz-download-sample — Downloads the original submitted sample to the War Room.
- tz-download-static-scan-strings — Downloads the static scan strings JSON to the War Room.
- tz-download-url-screenshot — Downloads the URL analysis screenshot to the War Room.
- tz-download-yara-rule — Polls for and downloads the generated YARA rule file to the War Room.
- tz-get-artifact-result — Retrieves analysis artifacts for a submission from ThreatZone.
- tz-get-behaviours — Retrieves one bounded page of behaviour telemetry.
- tz-get-cdr-result — Retrieves the CDR transformation result for a submission.
- tz-get-config-result — Retrieves configuration extractor results for a submission from ThreatZone.
- tz-get-dns-queries — Retrieves a bounded window of DNS queries.
- tz-get-eml-analysis — Retrieves parsed EML analysis results.
- tz-get-environments — Retrieves available ThreatZone sandbox environments.
- tz-get-http-requests — Retrieves a bounded window of HTTP request hosts.
- tz-get-indicator-result — Retrieves dynamic behaviour indicators for a submission from ThreatZone.
- tz-get-ioc-result — Retrieves Indicators of Compromise for a submission from ThreatZone.
- tz-get-metafields — Retrieves available ThreatZone metafields, optionally filtered by scan type.
- tz-get-mitre-techniques — Retrieves MITRE ATT&CK techniques matched during analysis.
- tz-get-network-summary — Retrieves aggregate network activity counts.
- tz-get-network-threats — Retrieves a bounded window of Suricata network threats.
- tz-get-overview-summary — Retrieves aggregate analysis counts for a submission.
- tz-get-process-tree — Retrieves the process tree captured during dynamic analysis.
- tz-get-processes — Retrieves processes captured during dynamic analysis.
- tz-get-result — Retrieve the analysis result from ThreatZone.
- tz-get-sanitized — Downloads a sanitized file from the ThreatZone API and uploads it to the War Room.
- tz-get-signature-check-result — Retrieves authenticode and signature-check results.
- tz-get-static-scan-result — Retrieves the static scan result for a submission.
- tz-get-syscalls — Retrieves one bounded page of syscall telemetry.
- tz-get-tcp-connections — Retrieves a bounded window of TCP connections.
- tz-get-udp-connections — Retrieves a bounded window of UDP connections.
- tz-get-url-analysis-result — Retrieves the full URL analysis report.
- tz-get-yara-result — Retrieves YARA rules matched during analysis. Use tz-download-yara-rule for the generated rule file.
- tz-list-media-files — Lists screenshots and videos available for a submission.
- tz-list-network-configs — Lists network configurations available to the current ThreatZone workspace.
- tz-list-submissions — Lists ThreatZone submissions with optional filters.
- tz-open-in-browser — Creates a ThreatZone open-in-browser submission.
- tz-sandbox-upload-sample — Submits a sample to ThreatZone for sandbox analysis.
- tz-search-submissions-by-sha256 — Searches ThreatZone submissions by SHA256 hash.
- tz-static-upload-sample — Submits a sample to ThreatZone for static analysis.
- tz-url-analysis — Submits a URL to ThreatZone for analysis.