Detonate File - ThreatGrid
Deprecated. Use Detonate File - ThreatGrid v2 instead.
- Pack
- ThreatGrid
- Tasks
- 10
Inputs
- File — File object of the file to detonate.
- FileName — Name of the file to detonate.
- VM — The VM to use (string)
- playbook — Name of the Threat Grid playbook to apply to this sample run
- Private — If the value is set to 'False', the sample will not be private. Any value other than 'False' will set the sample to private.
- Source — a string used for identifying the source of the detonation (user defined)
- Tags — A comma-separated list of tags applied to this sample.
- Interval — Polling frequency - how often the polling command should run (minutes)
- Timeout — How much time to wait before a timeout occurs (minutes)
Outputs
- File.Malicious — The File malicious description
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- File.Type — File type e.g. "PE"
- File.Size — File size
- File.MD5 — MD5 hash of the file
- File.Name — Filename
- File.SHA1 — SHA1 hash of the file
- File — The File object
- File.SHA256 — SHA256 hash of the file
- DBotScore — The DBotScore object
- DBotScore.Indicator — The indicator we tested
- DBotScore.Type — The type of the indicator
- DBotScore.Vendor — Vendor used to calculate the score
- DBotScore.Score — The actual score
- ThreatGrid.Sample.State — The sample state.
- ThreatGrid.Sample.ID — The sample ID.
Commands used
- threat-grid-get-samples-state
- threat-grid-upload-sample