Darkmon - Enrich File
Sub-playbook that calls the Darkmon !file command and returns DBotScore + Common.File for the input File indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
- Pack
- Darkmon
- Tasks
- 5
Inputs
- File — The File indicator value to enrich. Defaults to ${File.MD5}.
Outputs
- DBotScore.Indicator — The indicator value.
- DBotScore.Type — The indicator type.
- DBotScore.Vendor — The vendor reporting the score (Darkmon).
- DBotScore.Score — The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).
- DBotScore.Reliability — Source reliability per the Admiralty code.
- File.MD5 — The File value.
- File.Malicious.Vendor — The vendor that flagged this File as malicious (Darkmon).
- File.Malicious.Description — Reason this File was flagged as malicious.
- Darkmon.SearchResult — Full search result records returned by Darkmon for this indicator.
Commands used
- file