Detonate URL - WildFire v2.1
Deprecated. Use Detonate URL - WildFire v2.2 instead.
- Pack
- Palo_Alto_Networks_WildFire
- Tasks
- 14
Inputs
- URL — URL of the webpage or file URL to detonate. The URL is taken from the context.
- Interval — Duration for executing the polling (in minutes).
- Timeout — The duration after which to stop polling and to resume the playbook (in minutes).
- ReportFileType — The resource type to download. Default is PDF. XML is also possible.
Outputs
- DBotScore — The DBotScore object.
- DBotScore.Score — The actual score.
- File.Size — File size.
- File.MD5 — MD5 hash.
- File.SHA1 — SHA1 hash.
- File.Type — File type e.g. "PE".
- File.SHA256 — SHA256 hash.
- File.EntryID — The Entry ID of the sample.
- File.Malicious.Vendor — For malicious files, the vendor that determined that the file is malicious.
- File.Name — Filename.
- File.Malicious.Description — For malicious files, the reason the vendor determined that the file is malicious.
- DBotScore.Indicator — The indicator we tested.
- DBotScore.Type — The type of indicator.
- DBotScore.Vendor — Vendor used to calculate the score.
- IP.Address — IPs relevant to the sample.
- File — The File object.
- InfoFile — The report file object.
- InfoFile.EntryID — The EntryID of the report file.
- InfoFile.Extension — The extension of the report file.
- InfoFile.Name — The name of the report file.
- InfoFile.Info — The info of the report file.
- InfoFile.Size — The size of the report file.
- InfoFile.Type — The type of the report file.
- File.Malicious — The malicious object.
- WildFire.Report — The submission object.
- WildFire.Report.MD5 — MD5 of the submission.
- WildFire.Report.SHA256 — SHA256 of the submission.
- WildFire.Report.FileType — The type of the submission.
- WildFire.Report.Status — The status of the submission.
- WildFire.Report.Size — The size of the submission.
- WildFire.Report.URL — URL of the submission.
- WildFire.Report.detection_reasons — The detection reasons object.
- WildFire.Report.detection_reasons.description — Reason for the detection verdict.
- WildFire.Report.detection_reasons.name — Name of the detection.
- WildFire.Report.detection_reasons.type — Type of the detection.
- WildFire.Report.detection_reasons.verdict — Verdict of the detection.
- WildFire.Report.detection_reasons.artifacts — Artifacts for the detection reasons.
- WildFire.Report.iocs — Associated IOCs.
Commands used
- wildfire-report
- wildfire-upload-file-url
- wildfire-upload-url