DBot Create Phishing Classifier Deprecated Hidden
Deprecated. Use "DBot Create Phishing Classifier V2" playbook instead. Create a phishing classifier using machine learning technique, based on email content
Deprecated Content (Deprecated) · 8 tasks · 11 inputs · 3 outputs
Details
| ID | DBotCreatePhishingClassifier |
|---|---|
| From Version | 5.0.0 |
| Tasks | 8 |
README
DEPRECATED. Use “DBot Create Phishing Classifier V2” playbook instead. Creates a phishing classifier using machine learning technique, based on the email content.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
- DBotPredictPhishingEvaluation
- DBotTrainTextClassifier
- DBotPreparePhishingData
- Base64ListToFile
Commands
This playbook does not use any commands.
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| modelListStoreName | The name of the Cortex XSOAR list to store the model. | phishing_model | Optional |
| emailTextKey | The incident key to extract email body text. | details | Optional |
| emailSubjectKey | The incident key to extract email subject. | emailsubject | Optional |
| emailTagKey | The incident key expression to extract email tag. | closeReason | Optional |
| phishingLabels | The CSV list of email tags values and mapping. The script going to consider only the tags specified in this field. You can map label to another value by using this format: LABEL:MAPPED_LABEL. For example: let’s say we have 4 values in email tag: malicious, credentials harvesting, inner communitcation, external legit email, unclassified. While training, we want to ignore “unclassified” tag, and refer to “credentials harvesting” as “malicious” too. Also, we want to merge “inner communitcation” and “external legit email” to one tag called “non-malicious”. The input will be: malicious, credentials harvesting:malicious, inner communitcation:non-malicious, external legit email:non-malicious. | * | Optional |
| incidentsTrainingQuery | The incidents query to fetch the training data for the model. | type:Phishing and created:>=”180 days ago” and created:<”7 days ago” | Optional |
| incidentsEvaluationQuery | The incidents query to fetch the test data for the model. | type:Phishing and created:>=”7 days ago” | Optional |
| maxIncidentsToFetchOnTraining | The maximum number of incidents to fetch while training the model. | 2000 | Optional |
| isContextNeeded | Wether the context data needed to get email text\subject\tag value? | no | Optional |
| historicalDataFileListName | The name of Cortex XSOAR list contains historical data samples for the algorithm. | - | Optional |
| hashData | The preform hash function to the words (to anonymize the data). Choose “yes” or “no”. | no | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| DBotPredictPhishingEvaluation.F1 | The F1 score (0-1). | number |
| DBotPredictPhishingEvaluation.Precision | The precision score (0-1). | number |
| DBotTextClassifier.ListName | The model list name in Cortex XSOAR. | unknown |
Playbook Image

Inputs
modelListStoreName— The name of Demisto list to store the modelemailTextKey— Incident key to extract email body textemailSubjectKey— Incident key to extract email subjectemailTagKey— Incident key expression to extract email tagphishingLabels— Comma-separated values of email tags values and mapping. The script going to consider only the tags specify in this field. You can map label to another value by using this format: LABEL:MAPPED_LABEL. For example: let's say we have 4 values in email tag: malicious, credentials harvesting, inner communitcation, external legit email, unclassified. While training, we want to ignore "unclassified" tag, and refer to "credentials harvesting" as "malicious" too. Also, we want to merge "inner communitcation" and "external legit email" to one tag called "non-malicious". The input will be: malicious, credentials harvesting:malicious, inner communitcation:non-malicious, external legit email:non-maliciousincidentsTrainingQuery— The incidents query to fetch the training data for the modelincidentsEvaluationQuery— The incidents query to fetch the test data for the modelmaxIncidentsToFetchOnTraining— Maximum number of incidents to fetch while training the modelisContextNeeded— Is context data needed to get email text\subject\tag value?historicalDataFileListName— The name of demisto list contains historical data samples for the algorithmhashData— Preform hash function to the words (to anonymize the data). Choose between yes/no
Outputs
DBotPredictPhishingEvaluation.F1— F1 score (0-1)DBotPredictPhishingEvaluation.Precision— Precision score (0-1)DBotTextClassifier.ListName— Model list name in Demisto
Flowchart
id: DBotCreatePhishingClassifierJob version: -1 name: DBot Create Phishing Classifier Job description: Deprecated. Use "DBot Create Phishing Classifier V2" playbook instead. Train the phishing machine learning model. This playbook should be used as job, to run repeatedly, for example every week. starttaskid: "0" hidden: true tasks: "0": id: "0" taskid: 3f296bee-5970-4a35-819b-30ace9905ff7 type: start task: id: 3f296bee-5970-4a35-819b-30ace9905ff7 version: -1 name: "" iscommand: false brand: "" description: "" nexttasks: '#none#': - "4" separatecontext: false view: |- { "position": { "x": 50, "y": 50 } } note: false timertriggers: [] "1": id: "1" taskid: 831b0954-1008-49f0-84e1-43dc7c585ec0 type: playbook task: id: 831b0954-1008-49f0-84e1-43dc7c585ec0 version: -1 name: DBotCreatePhishingClassifier description: Create a phishing classifier using machine learning technique, based on email content playbookName: DBot Create Phishing Classifier type: playbook iscommand: false brand: "" nexttasks: '#none#': - "3" scriptarguments: modelListStoreName: simple: phishing_model emailSubjectKey: simple: name emailTagKey: simple: closeReason emailTextKey: simple: details hashData: simple: "no" historicalDataFileListName: {} incidentsEvaluationQuery: simple: type:Phishing and created:>="180 days ago" and created:<"7 days ago" incidentsTrainingQuery: simple: type:Phishing and created:>="7 days ago" isContextNeeded: simple: "no" maxIncidentsToFetchOnTraining: simple: "3000" phishingLabels: simple: malicious,other separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 view: |- { "position": { "x": 50, "y": 370 } } note: false timertriggers: [] "2": id: "2" taskid: f2153861-94b2-4de6-8883-546b3e4dc5b9 type: title task: id: f2153861-94b2-4de6-8883-546b3e4dc5b9 version: -1 name: Done type: title iscommand: false brand: "" description: "" separatecontext: false view: |- { "position": { "x": 50, "y": 720 } } note: false timertriggers: [] "3": id: "3" taskid: a0577456-3576-460d-8ede-15c6569f611a type: regular task: id: a0577456-3576-460d-8ede-15c6569f611a version: -1 name: Close incident description: Close the investigation - we want to close the incident if the playbook successfully finished. script: Builtin|||closeInvestigation type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "2" scriptarguments: assetid: {} closeNotes: {} closeReason: {} id: {} separatecontext: false view: |- { "position": { "x": 50, "y": 545 } } note: false timertriggers: [] "4": id: "4" taskid: cd901cee-98fa-416b-8e39-519218a516ea type: regular task: id: cd901cee-98fa-416b-8e39-519218a516ea version: -1 name: Clean context description: Clear all context data scriptName: DeleteContext type: regular iscommand: false brand: "" nexttasks: '#none#': - "1" scriptarguments: all: simple: "yes" index: {} key: {} keysToKeep: {} subplaybook: {} separatecontext: false view: |- { "position": { "x": 50, "y": 195 } } note: false timertriggers: [] view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 735, "width": 380, "x": 50, "y": 50 } } } inputs: [] outputs: [] fromversion: 5.0.0 tests: - No tests deprecated: true