IsInternalHostName
Checks if the supplied hostnames match either the organization's internal naming convention or the domain suffix.
- Type
- python
- Pack
- CommonScripts
Source
import re
import demistomock as demisto
from CommonServerPython import *
def main():
args = demisto.args()
internalregex = args.get("internalRegex")
domainName = args.get("domainName")
hostName = argToList(args.get("hostName"))
human_readable = []
context_entry = []
for element in hostName:
if element:
if internalregex:
internalRegexMatch = re.match(internalregex, element)
else:
internalRegexMatch = None
internalDomainMatch = re.match(r".*\." + domainName + "$", element)
context_entry.append({"Hostname": element, "IsInternal": bool(internalRegexMatch or internalDomainMatch)})
if context_entry[-1]["IsInternal"]:
readable = element + " is internal"
else:
readable = element + " is external"
human_readable.append(readable)
return_outputs("\n".join(human_readable), {"Endpoint": context_entry})
if __name__ in ("builtins", "__builtin__"):
main()
README
Checks if the supplied hostnames match either the organization’s internal naming convention or the domain suffix.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | Utility |
| Cortex XSOAR Version | 5.0.0 |
Used In
This script is used in the following playbooks and scripts.
- Logz.io Indicator Hunting
- Palo Alto Networks - Hunting And Threat Detection
- Splunk Indicator Hunting
Inputs
| Argument Name | Description |
|---|---|
| hostName | A comma-separated list of hostnames to check. |
| internalRegex | The regex pattern for the organization’s hostname for example \w\w\w\d$|\w\w\w$. for hosts that look like pcx1 or pcx. |
| domainName | The domain name for the organization. For a single domain use this format: “bla.com”. For multiple domains use this format: (bla.com|blabla.com), where the pipe and the brackets are the OR condition for regex. |
Outputs
| Path | Description | Type |
|---|---|---|
| Endpoint.Hostname | The hostname. | string |
| Endpoint.IsInternal | Whether the supplied hostnames match the organization’s naming convention. Can be “true” or “false”. | string |