Code42 File Search
This playbook searches for files via Code42 security events by either MD5 or SHA256 hash. The data is output to the Code42.SecurityData context for use.
- Pack
- Code42
- Tasks
- 7
Inputs
- MD5 — MD5 hash to search for
- SHA256 — SHA256 hash to search for
Outputs
- Code42.SecurityData — Returned File Results
- Code42.SecurityData.EventTimestamp — Timestamp for event
- Code42.SecurityData.FileCreated — File creation date
- Code42.SecurityData.EndpointID — Code42 device ID
- Code42.SecurityData.DeviceUsername — Username that device is associated with in Code42
- Code42.SecurityData.EmailFrom — Sender email address for email exfiltration events
- Code42.SecurityData.EmailTo — Recipient email address for email exfiltration events
- Code42.SecurityData.EmailSubject — Email subject line for email exfiltration events
- Code42.SecurityData.EventID — Security Data event ID
- Code42.SecurityData.EventType — Type of Security Data event
- Code42.SecurityData.FileCategory — Type of file as determined by Code42 engine
- Code42.SecurityData.FileOwner — Owner of file
- Code42.SecurityData.FileName — File name
- Code42.SecurityData.FilePath — Path to file
- Code42.SecurityData.FileSize — Size of file in bytes
- Code42.SecurityData.FileModified — File modification date
- Code42.SecurityData.FileMD5 — MD5 hash of file
- Code42.SecurityData.FileHostname — Hostname where file event was captured
- Code42.SecurityData.DevicePrivateIPAddress — Private IP addresses of device where event was captured
- Code42.SecurityData.DevicePublicIPAddress — Public IP address of device where event was captured
- Code42.SecurityData.RemovableMediaType — Type of removable media
- Code42.SecurityData.RemovableMediaCapacity — Total capacity of removable media in bytes
- Code42.SecurityData.RemovableMediaMediaName — Full name of removable media
- Code42.SecurityData.RemovableMediaName — Name of removable media
- Code42.SecurityData.RemovableMediaSerialNumber — Serial number for removable medial device
- Code42.SecurityData.RemovableMediaVendor — Vendor name for removable device
- Code42.SecurityData.FileSHA256 — SHA256 hash of file
- Code42.SecurityData.FileShared — Whether file is shared using cloud file service
- Code42.SecurityData.FileSharedWith — Accounts that file is shared with on cloud file service
- Code42.SecurityData.Source — Source of file event, Cloud or Endpoint
- Code42.SecurityData.ApplicationTabURL — URL associated with application read event
- Code42.SecurityData.ProcessName — Process name for application read event
- Code42.SecurityData.ProcessOwner — Process owner for application read event
- Code42.SecurityData.WindowTitle — Process name for application read event
- Code42.SecurityData.FileURL — URL of file on cloud file service
- Code42.SecurityData.Exposure — Exposure type for event
- Code42.SecurityData.SharingTypeAdded — Type of sharing added to file
- File — The file object.
- File.Name — File name
- File.Path — File path
- File.Size — File size in bytes
- File.MD5 — MD5 hash of file
- File.SHA256 — SHA256 hash of file
- File.Hostname — Hostname where file event was captured
Commands used
- code42-file-events-search