Get File Sample From Path - Generic V3
This playbook returns a file sample from a specified path and host that you input in the following playbooks: - PS Remote Get File Sample From Path - Get File Sample From Path - VMware Carbon Black EDR (Live Response API) - CrowdStrike Falcon - Retrieve File - MDE - Retrieve File - Cortex XDR - Retrieve File V2
- Pack
- CommonPlaybooks
- Tasks
- 12
Inputs
- Host — Hostname of the machine on which the file is located, for PS remote it can also be an IP address.
- Path — The path of the file to retrieve. For example: C:\users\folder\file.txt
- Agent_ID — The ID of the agent, or of the endpoint, in the relevant integration (such as EDR).
Outputs
- File.Size — The size of the file.
- File.Type — The type of the file.
- File.Info — General information of the file.
- File.MD5 — The MD5 hash of the file.
- File.SHA1 — The SHA1 hash of the file.
- File.SHA256 — The SHA256 hash of the file.
- File.SHA512 — The SHA512 hash of the file.
- File.EntryID — The file entry ID.
- File.Extension — The file extension.
- File.Name — The file name.
- File.SSDeep — File SSDeep.
- AcquiredFile — The acquired file details.
- ExtractedFiles — A list of file names that were extracted from the ZIP file.
- NonRetrievedFiles — A list of files that were not retrieved.