Recorded Future File Reputation
File reputation using Recorded Future SOAR enrichment
- Pack
- RecordedFuture
- Tasks
- 11
Inputs
- MD5 — MD5 hash for which to get the reputation.
- SHA256 — SHA-256 hash for which to get the reputation.
- SHA1 — SHA-1 hash for which to get reputation.
Outputs
- DBotScore.Indicator — The indicator that was tested
- DBotScore.Type — Indicator type
- DBotScore.Vendor — Vendor used to calculate the score
- DBotScore.Score — The actual score
- File.SHA256 — File SHA-256
- File.SHA512 — File SHA-512
- File.SHA1 — File SHA-1
- File.MD5 — File MD5
- File.CRC32 — File CRC32
- File.CTPH — File CTPH
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- File.Malicious.Description — For malicious files, the reason that the vendor made the decision
- RecordedFuture.File.riskScore — Recorded Future Hash Risk Score
- RecordedFuture.File.riskLevel — Recorded Future Hash Risk Level
- RecordedFuture.File.Evidence.rule — Recorded Future Risk Rule Name
- RecordedFuture.File.Evidence.mitigation — Recorded Future Risk Rule Mitigation
- RecordedFuture.File.Evidence.description — Recorded Future Risk Rule description
- RecordedFuture.File.Evidence.timestamp — Recorded Future Risk Rule timestamp
- RecordedFuture.File.Evidence.level — Recorded Future Risk Rule Level
- RecordedFuture.File.Evidence.ruleid — Recorded Future Risk Rule ID
- RecordedFuture.File.name — Hash
- RecordedFuture.File.maxRules — Maximum count of Recorded Future Hash Risk Rules
- RecordedFuture.File.ruleCount — Number of triggered Recorded Future Hash Risk Rules
Commands used
- file
- setIndicator