File Enrichment - Generic
Deprecated. Use "File Enrichment - Generic v2" playbook instead. Enrich a file using one or more integrations. File enrichment includes: * File history * Threat information * File reputation
- Pack
- DeprecatedContent
- Tasks
- 10
Inputs
- MD5 — File MD5 hash to enrich.
- SHA256 — File SHA-256 hash to enrich.
- SHA1 — File SHA-1 hash to enrich.
Outputs
- DBotScore.Indicator — The tested indicator
- DBotScore.Type — The type of the indicator
- File.SHA1 — SHA1 hash of the file
- File.SHA256 — SHA256 hash of the file
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- File.MD5 — MD5 hash of the file
- DBotScore — The DBotScore's object
- File — The file's object
- DBotScore.Vendor — Vendor used to calculate the score
- DBotScore.Score — The actual score
- File.VirusTotal.Scans — the scan object
- File.VirusTotal.Scans.Source — Scan vendor for this hash
- File.VirusTotal.Scans.Detected — Scan detection for this hash (True,False)
- File.VirusTotal.Scans.Result — Scan result for this hash - signature, etc.
Commands used
- cylance-protect-get-threat