Search For Hash In Sandbox - Generic
This playbook searches for a specific hash in the supported sandboxes. If the hash is known, the playbook provides a detailed analysis of the sandbox report. Currently, supported sandboxes are Falcon Intelligence Sandbox, Wildfire and Joe Sandbox.
- Pack
- CommonPlaybooks
- Tasks
- 29
Inputs
- FileSha256 — The SHA256 hash to search for.
Outputs
- AttackPattern — The MITRE Attack pattern information.
- MITREATTACK — Full MITRE data for the attack pattern.
- NonFoundHashes — A list of hashes that are not found in the sandboxes.
- WildFire.Report — The results of the Wildfire report.
- csfalconx.resource.sandbox — The results of the Falcon Intelligence Sandbox report.
- DetectedHashes — A list of hashes that were detected by the sandboxes.
Commands used
- attack-pattern
- cs-fx-find-reports
- cs-fx-get-full-report
- extractIndicators
- joe-download-report
- joe-search
- rasterize-pdf
- wildfire-report