Recorded Future Threat Assessment
Threat Assessment using the Recorded Future SOAR Triage API and the context Phishing.
- Pack
- RecordedFuture
- Tasks
- 7
Inputs
- CVE — CVE ID to check if it is related to the C2 context.
- IP — IP Address to check if it is related to the C2 context.
- URL — URL to check if it is related to the C2 context.
- MD5 — MD5 to check if it is related to the C2 context.
- SHA1 — SHA-1 to check if it is related to the C2 context.
- SHA256 — SHA-256 to check if it is related to the C2 context.
- Domain — Domain to check if it is related to the C2 context.
- threat-assessment-context — Context to use for assessment. This is used by Recorded Future to calculate the relevant score and verdict. Valid values are "c2", "malware" and "phishing".
- filter — Makes sure that we filter out values that are zero in score from the threat assessment api.
Outputs
- DBotScore.Indicator — The indicator that was tested
- DBotScore.Type — Indicator type
- DBotScore.Vendor — Vendor used to calculate the score
- DBotScore.Score — The actual score
- File.SHA256 — SHA-256
- File.SHA512 — SHA-512
- File.SHA1 — SHA-1
- File.MD5 — MD5
- File.CRC32 — CRC32
- File.CTPH — CTPH
- IP.Address — IP address
- IP.ASN — ASN
- IP.Geo.Country — IP Geolocation Country
- Domain.Name — Domain name
- URL.Data — URL name
- CVE.ID — Vulnerability name
- RecordedFuture.verdict — Recorded Future verdict
- RecordedFuture.context — Threat Assessment Context
- RecordedFuture.riskScore — Recorded Future Max Score
- RecordedFuture.Entities.id — Entity ID
- RecordedFuture.Entities.name — Entity Name
- RecordedFuture.Entities.type — Entity Type
- RecordedFuture.Entities.score — Entity Score
- RecordedFuture.Entities.Evidence.ruleid — Recorded Future Risk Rule ID
- RecordedFuture.Entities.Evidence.timestamp — Recorded Future Evidence Timestamp
- RecordedFuture.Entities.Evidence.mitigation — Recorded Future Evidence Mitigation
- RecordedFuture.Entities.Evidence.description — Recorded Future Evidence Description
- RecordedFuture.Entities.Evidence.rule — Recorded Future Risk Rule
- RecordedFuture.Entities.Evidence.level — Recorded Future Risk Rule Level
Commands used
- recordedfuture-threat-assessment
- setIndicator