Darkmon - Enrich URL
Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Darkmon · 5 tasks · 1 input · 9 outputs
Details
| ID | Darkmon - Enrich URL |
|---|---|
| From Version | 6.8.0 |
| Tasks | 5 |
README
Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
- Darkmon
Scripts
This playbook does not use any scripts.
Commands
- url
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| URL | The URL indicator value to enrich. Defaults to ${URL.Data}. | URL.Data | Required |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| DBotScore.Indicator | The indicator value. | string |
| DBotScore.Type | The indicator type. | string |
| DBotScore.Vendor | The vendor reporting the score (Darkmon). | string |
| DBotScore.Score | The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad). | number |
| DBotScore.Reliability | Source reliability per the Admiralty code. | string |
| URL.Data | The URL value. | string |
| URL.Malicious.Vendor | The vendor that flagged this URL as malicious (Darkmon). | string |
| URL.Malicious.Description | Reason this URL was flagged as malicious. | string |
| Darkmon.SearchResult | Full search result records returned by Darkmon for this indicator. | unknown |
Inputs
URL— The URL indicator value to enrich. Defaults to ${URL.Data}.
Outputs
DBotScore.Indicator— The indicator value.DBotScore.Type— The indicator type.DBotScore.Vendor— The vendor reporting the score (Darkmon).DBotScore.Score— The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).DBotScore.Reliability— Source reliability per the Admiralty code.URL.Data— The URL value.URL.Malicious.Vendor— The vendor that flagged this URL as malicious (Darkmon).URL.Malicious.Description— Reason this URL was flagged as malicious.Darkmon.SearchResult— Full search result records returned by Darkmon for this indicator.
Commands used
url
Flowchart
id: Darkmon - Enrich URL version: -1 name: Darkmon - Enrich URL description: Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation. fromversion: 6.8.0 marketplaces: - xsoar - platform starttaskid: '0' tasks: '0': id: '0' taskid: 678d4998-690b-4849-ab6b-67f906082fd4 type: start task: id: 678d4998-690b-4849-ab6b-67f906082fd4 version: -1 name: '' description: '' iscommand: false brand: '' nexttasks: '#none#': - '100' separatecontext: false continueonerrortype: '' view: '{"position": {"x": 50, "y": 50}}' note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '1': id: '1' taskid: dfec3681-47da-4638-8c9a-569d295a2862 type: regular task: id: dfec3681-47da-4638-8c9a-569d295a2862 version: -1 name: Run Darkmon url lookup description: Calls the Darkmon !url reputation command to enrich the URL. script: Darkmon|||url type: regular iscommand: true brand: Darkmon nexttasks: '#none#': - '2' scriptarguments: url: complex: root: inputs.URL separatecontext: false continueonerrortype: '' view: '{"position": {"x": 50, "y": 530}}' note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '2': id: '2' taskid: a4ebb03f-12cb-4177-8f91-ac69c4694406 type: title task: id: a4ebb03f-12cb-4177-8f91-ac69c4694406 version: -1 name: Done description: '' type: title iscommand: false brand: '' separatecontext: false continueonerrortype: '' view: '{"position": {"x": 50, "y": 770}}' note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '100': id: '100' taskid: fff40573-b7b1-4ed8-884e-a0e47407ae11 type: condition task: id: fff40573-b7b1-4ed8-884e-a0e47407ae11 version: -1 name: Is Darkmon integration available? description: Skips the playbook gracefully if the Darkmon integration is not configured in this tenant. Calls the built-in IsIntegrationAvailable script with brandname=Darkmon. scriptName: IsIntegrationAvailable type: condition iscommand: false brand: '' scriptarguments: brandname: simple: Darkmon results: - brandInstances nexttasks: 'yes': - '1' '#default#': - '101' separatecontext: false continueonerrortype: '' view: '{"position": {"x": 50, "y": 290}}' note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 '101': id: '101' taskid: 1afff1a7-2489-4bd0-b868-d91ef93a218d type: title task: id: 1afff1a7-2489-4bd0-b868-d91ef93a218d version: -1 name: Done description: '' type: title iscommand: false brand: '' separatecontext: false continueonerrortype: '' view: '{"position": {"x": -450, "y": 530}}' note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 view: '{"linkLabelsPosition": {"100_1_yes": 0.1, "100_101_#default#": 0.5}, "paper": {"dimensions": {"height": 935, "width": 980, "x": -500, "y": 0}}}' inputs: - key: URL value: complex: root: URL accessor: Data required: true description: The URL indicator value to enrich. Defaults to ${URL.Data}. playbookInputQuery: outputs: - contextPath: DBotScore.Indicator description: The indicator value. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: The vendor reporting the score (Darkmon). type: string - contextPath: DBotScore.Score description: The reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad). type: number - contextPath: DBotScore.Reliability description: Source reliability per the Admiralty code. type: string - contextPath: URL.Data description: The URL value. type: string - contextPath: URL.Malicious.Vendor description: The vendor that flagged this URL as malicious (Darkmon). type: string - contextPath: URL.Malicious.Description description: Reason this URL was flagged as malicious. type: string - contextPath: Darkmon.SearchResult description: Full search result records returned by Darkmon for this indicator. type: unknown tests: - No tests supportedModules: - cloud_posture - cloud - cloud_runtime_security - edr - asm - tim - cloud_appsec - xsiam - exposure_management - agentix - email_security