Darkmon - Enrich URL
Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
- Pack
- Darkmon
- Tasks
- 5
Inputs
- URL — The URL indicator value to enrich. Defaults to ${URL.Data}.
Outputs
- DBotScore.Indicator — The indicator value.
- DBotScore.Type — The indicator type.
- DBotScore.Vendor — The vendor reporting the score (Darkmon).
- DBotScore.Score — The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).
- DBotScore.Reliability — Source reliability per the Admiralty code.
- URL.Data — The URL value.
- URL.Malicious.Vendor — The vendor that flagged this URL as malicious (Darkmon).
- URL.Malicious.Description — Reason this URL was flagged as malicious.
- Darkmon.SearchResult — Full search result records returned by Darkmon for this indicator.
Commands used
- url