Recorded Future URL Reputation
URL reputation using Recorded Future SOAR enrichment
- Pack
- RecordedFuture
- Tasks
- 7
Inputs
- URL — URL to get reputation of.
Outputs
- DBotScore.Indicator — The indicator that was tested
- DBotScore.Type — Indicator type
- DBotScore.Vendor — Vendor used to calculate the score
- DBotScore.Score — The actual score
- URL.Malicious.Vendor — For malicious URLs, the vendor that made the decision
- URL.Malicious.Description — For malicious URLs, the reason that the vendor made the decision
- URL.Data — URL name
- RecordedFuture.URL.riskScore — Recorded Future URL Risk Score
- RecordedFuture.URL.riskLevel — Recorded Future URL Risk Level
- RecordedFuture.URL.Evidence.rule — Recorded Future Risk Rule Name
- RecordedFuture.URL.Evidence.mitigation — Recorded Future Risk Rule Mitigation
- RecordedFuture.URL.Evidence.description — Recorded Future Risk Rule description
- RecordedFuture.URL.Evidence.timestamp — Recorded Future Risk Rule timestamp
- RecordedFuture.URL.Evidence.level — Recorded Future Risk Rule Level
- RecordedFuture.URL.Evidence.ruleid — Recorded Future Risk Rule ID
- RecordedFuture.URL.name — URL
- RecordedFuture.URL.maxRules — Maximum count of Recorded Future URL Risk Rules
- RecordedFuture.URL.ruleCount — Number of triggered Recorded Future URL Risk Rules
Commands used
- setIndicator
- url