File Enrichment - Virus Total Private API
Deprecated. Use the "File Enrichment - Virus Total v3" playbook instead.
- Pack
- VirusTotal-Private_API
- Tasks
- 13
Inputs
- MD5 — File MD5 to enrich
- SHA256 — File SHA256 to enrich
- SHA1 — File SHA1 to enrich
Outputs
- File — The file's object
- DBotScore.Indicator — The tested indicator
- File.SHA1 — SHA1 hash of the file
- File.SHA256 — SHA256 hash of the file
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- File.MD5 — MD5 hash of the file
- DBotScore — The DBotScore's object
- DBotScore.Type — The type of the indicator
- DBotScore.Vendor — Vendor used to calculate the score
- DBotScore.Score — The actual score
- File.VirusTotal.Scans — the scan object
- File.VirusTotal.Scans.Source — Scan vendor for this hash
- File.VirusTotal.Scans.Detected — Scan detection for this hash (True,False)
- File.VirusTotal.Scans.Result — Scan result for this hash - signature, etc.
Commands used
- vt-private-check-file-behaviour
- vt-private-get-file-report