Darkmon - Enrich URL

Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.

Darkmon · 5 tasks · 1 input · 9 outputs

Details

IDDarkmon - Enrich URL
From Version6.8.0
Tasks5

README

Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

  • Darkmon

Scripts

This playbook does not use any scripts.

Commands

  • url

Playbook Inputs


Name Description Default Value Required
URL The URL indicator value to enrich. Defaults to ${URL.Data}. URL.Data Required

Playbook Outputs


Path Description Type
DBotScore.Indicator The indicator value. string
DBotScore.Type The indicator type. string
DBotScore.Vendor The vendor reporting the score (Darkmon). string
DBotScore.Score The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad). number
DBotScore.Reliability Source reliability per the Admiralty code. string
URL.Data The URL value. string
URL.Malicious.Vendor The vendor that flagged this URL as malicious (Darkmon). string
URL.Malicious.Description Reason this URL was flagged as malicious. string
Darkmon.SearchResult Full search result records returned by Darkmon for this indicator. unknown

Inputs

  • URL — The URL indicator value to enrich. Defaults to ${URL.Data}.

Outputs

  • DBotScore.Indicator — The indicator value.
  • DBotScore.Type — The indicator type.
  • DBotScore.Vendor — The vendor reporting the score (Darkmon).
  • DBotScore.Score — The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).
  • DBotScore.Reliability — Source reliability per the Admiralty code.
  • URL.Data — The URL value.
  • URL.Malicious.Vendor — The vendor that flagged this URL as malicious (Darkmon).
  • URL.Malicious.Description — Reason this URL was flagged as malicious.
  • Darkmon.SearchResult — Full search result records returned by Darkmon for this indicator.

Commands used

url

Flowchart

yes Start Start Run Darkmon url lookup - url Run Darkmon url lookup url Done Done Is Darkmon integration available? - IsIntegrationAvailable Is Darkmon integration av... IsIntegrationAvailable Done Done
id: Darkmon - Enrich URL
version: -1
name: Darkmon - Enrich URL
description: Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
fromversion: 6.8.0
marketplaces:
- xsoar
- platform
starttaskid: '0'
tasks:
  '0':
    id: '0'
    taskid: 678d4998-690b-4849-ab6b-67f906082fd4
    type: start
    task:
      id: 678d4998-690b-4849-ab6b-67f906082fd4
      version: -1
      name: ''
      description: ''
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '100'
    separatecontext: false
    continueonerrortype: ''
    view: '{"position": {"x": 50, "y": 50}}'
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '1':
    id: '1'
    taskid: dfec3681-47da-4638-8c9a-569d295a2862
    type: regular
    task:
      id: dfec3681-47da-4638-8c9a-569d295a2862
      version: -1
      name: Run Darkmon url lookup
      description: Calls the Darkmon !url reputation command to enrich the URL.
      script: Darkmon|||url
      type: regular
      iscommand: true
      brand: Darkmon
    nexttasks:
      '#none#':
      - '2'
    scriptarguments:
      url:
        complex:
          root: inputs.URL
    separatecontext: false
    continueonerrortype: ''
    view: '{"position": {"x": 50, "y": 530}}'
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '2':
    id: '2'
    taskid: a4ebb03f-12cb-4177-8f91-ac69c4694406
    type: title
    task:
      id: a4ebb03f-12cb-4177-8f91-ac69c4694406
      version: -1
      name: Done
      description: ''
      type: title
      iscommand: false
      brand: ''
    separatecontext: false
    continueonerrortype: ''
    view: '{"position": {"x": 50, "y": 770}}'
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '100':
    id: '100'
    taskid: fff40573-b7b1-4ed8-884e-a0e47407ae11
    type: condition
    task:
      id: fff40573-b7b1-4ed8-884e-a0e47407ae11
      version: -1
      name: Is Darkmon integration available?
      description: Skips the playbook gracefully if the Darkmon integration is not configured in this tenant. Calls the built-in IsIntegrationAvailable script with brandname=Darkmon.
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ''
    scriptarguments:
      brandname:
        simple: Darkmon
    results:
    - brandInstances
    nexttasks:
      'yes':
      - '1'
      '#default#':
      - '101'
    separatecontext: false
    continueonerrortype: ''
    view: '{"position": {"x": 50, "y": 290}}'
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  '101':
    id: '101'
    taskid: 1afff1a7-2489-4bd0-b868-d91ef93a218d
    type: title
    task:
      id: 1afff1a7-2489-4bd0-b868-d91ef93a218d
      version: -1
      name: Done
      description: ''
      type: title
      iscommand: false
      brand: ''
    separatecontext: false
    continueonerrortype: ''
    view: '{"position": {"x": -450, "y": 530}}'
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
view: '{"linkLabelsPosition": {"100_1_yes": 0.1, "100_101_#default#": 0.5}, "paper": {"dimensions": {"height": 935, "width": 980, "x": -500, "y": 0}}}'
inputs:
- key: URL
  value:
    complex:
      root: URL
      accessor: Data
  required: true
  description: The URL indicator value to enrich. Defaults to ${URL.Data}.
  playbookInputQuery:
outputs:
- contextPath: DBotScore.Indicator
  description: The indicator value.
  type: string
- contextPath: DBotScore.Type
  description: The indicator type.
  type: string
- contextPath: DBotScore.Vendor
  description: The vendor reporting the score (Darkmon).
  type: string
- contextPath: DBotScore.Score
  description: The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).
  type: number
- contextPath: DBotScore.Reliability
  description: Source reliability per the Admiralty code.
  type: string
- contextPath: URL.Data
  description: The URL value.
  type: string
- contextPath: URL.Malicious.Vendor
  description: The vendor that flagged this URL as malicious (Darkmon).
  type: string
- contextPath: URL.Malicious.Description
  description: Reason this URL was flagged as malicious.
  type: string
- contextPath: Darkmon.SearchResult
  description: Full search result records returned by Darkmon for this indicator.
  type: unknown
tests:
- No tests
supportedModules:
- cloud_posture
- cloud
- cloud_runtime_security
- edr
- asm
- tim
- cloud_appsec
- xsiam
- exposure_management
- agentix
- email_security