SearchIndicator
Searches Cortex XSOAR Indicators. Search for XSOAR Indicators and returns the id, indicator_type, value, and score/verdict. You can add additional fields from the indicators using the add_field_to_context argument.
- Type
- javascript
- Pack
- CommonScripts
Source
var res = executeCommand('findIndicators', {
query: args.query,
size: args.size
});
if (!isValidRes(res)) {
if (res[0].Contents) {
return {
ContentsFormat: formats.markdown,
Type: entryTypes.error,
Contents: res[0].Contents
};
}
}
var filteredIndicators = []
if (
res &&
res[0] &&
res[0].Contents
) {
filteredIndicators = []
fields = ["id", "indicator_type", "value", "score"]
if (args.add_fields_to_context) {
fields = fields.concat(args.add_fields_to_context.split(","));
fields = fields.map(x => x.trim()); // clear out whitespace
}
for (var indicator of res[0].Contents) {
var styleIndicator = {};
for (var field of fields) {
styleIndicator[field] =
indicator[field] !== undefined ? indicator[field] :
(indicator.CustomFields && indicator.CustomFields[field] !== undefined ?
indicator.CustomFields[field] :
"n/a");
}
styleIndicator["verdict"] = scoreToReputation(styleIndicator["score"])
filteredIndicators.push(styleIndicator);
}
var headers = fields.concat(["verdict"]);
}
var ec = {
'foundIndicators(val.id && val.id == obj.id)': filteredIndicators
};
return {
Type: entryTypes.note,
ReadableContentsFormat: formats.markdown,
Contents: filteredIndicators,
ContentsFormat: formats.json,
HumanReadable: tableToMarkdown("Indicators Found", filteredIndicators, headers),
EntryContext: ec,
IgnoreAutoExtract: true
};
README
Searches Cortex XSOAR Indicators.
Search for XSOAR Indicators and returns the id, indicator_type, value, and score/verdict.
You can add additional fields from the indicators using the add_field_to_context argument.
Script Data
| Name | Description |
|---|---|
| Script Type | javascript |
| Tags | Utility |
Inputs
| Argument Name | Description |
|---|---|
| query | Query to use to find the Indicators, same as you’d use on the Threat Intel page. |
| size | The number of indicators to return, defaults to a max of 25. |
| add_fields_to_context | A comma seperated list of fields to return to the context, (default: id,indicator_type,value,score,verdict)) |
Outputs
| Path | Description | Type |
|---|---|---|
| foundIndicators.id | The id of the indicator in the XSOAR database. | Unknown |
| foundIndicators.indicator_type | The type of Indicator (i.e. IP, Domain, URL, etc) | Unknown |
| foundIndicators.value | The value of the Indicator | Unknown |
| foundIndicators.score | The numeric score of the indicator (0 = Unknown, 1 = Good, 2 = Suspicious, 3 = Malicious) | Unknown |
| foundIndicators.verdict | The human readable score/verdict of the Indicator. | Unknown |