Entity Enrichment - Generic
Deprecated. Use "Entity Enrichment - Generic v3" playbook instead. Enrich entities using one or more integrations
- Pack
- DeprecatedContent
- Tasks
- 9
Inputs
- IP — The IP addresses to enrich
- InternalRange — The internal range to check against the IPs
- MD5 — File MD5 to enrich
- SHA256 — File SHA256 to enrich
- SHA1 — File SHA1 to enrich
- url — url to enrich
- Email — The email addresses to enrich
- Hostname — The hostname to enrich
- Username — The Username to enrich
- Domain — The domain name to enrich
Outputs
- Account — The Account's object
- Account.ID — The unique Account DN (Distinguished Name)
- Domain — The domain objects
- URL — The URL's object
- URL.Malicious — whether url was detected as malicious
- URL.Vendor — name of vendor who labeled as malicious
- URL.Description — additional info on the url
- URL.Address — The enriched URL
- Account.Email.Address — The Email account full address
- IP — The IP objects
- Account.Email.Domain — The Email account domain
- Account.Email.NetworkType — The Email account NetworkType (could be Internal/External)
- Account.Email.Username — The Email account username
- Account.Email.Distance.Domain — The compared domain
- Account.Email.Distance.Value — The distance between the email domain and the compared domain
- Account.Type — Type of the Account entity
- Account.Username — The Account username
- Account.Email — The email address associated with the Account
- Account.Groups — The groups the Account is part of
- Account.DisplayName — The Account display name
- Account.Manager — The Account's manager
- File — The File's object
- File.MD5 — MD5 hash of the file
- File.SHA1 — SHA1 hash of the file
- File.SHA256 — SHA256 hash of the file
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- Endpoint — The Endpoint's object
- Endpoint.Hostname — The hostname to enrich
- Endpoint.OS — Endpoint OS
- Endpoint.IP — List of endpoint IP addresses
- Endpoint.MAC — List of endpoint MAC addresses
- Endpoint.Domain — Endpoint domain name
- DBotScore — The Indicator's object
- DBotScore.Indicator — The Indicator
- DBotScore.Type — The Indicator Type
- DBotScore.Vendor — The DBot score vendor
- DBotScore.Score — The DBot score