Detonate URL - ThreatStream
Detonates one or more URLs using the Anomali ThreatStream sandbox integration. Returns relevant reports to the War Room and URL reputations to the context data.
Anomali ThreatStream · 7 tasks · 7 inputs · 26 outputs
Details
| ID | Detonate URL - ThreatStream |
|---|---|
| From Version | 5.0.0 |
| Tasks | 7 |
README
Detonates one or more URLs using the Anomali ThreatStream sandbox integration.
Returns relevant reports to the War Room and URL reputations to the context data.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- GenericPolling
Integrations
- AnomaliThreatStreamv3
- Anomali_ThreatStream_v2
Scripts
This playbook does not use any scripts.
Commands
- threatstream-submit-to-sandbox
- threatstream-analysis-report
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| URL | URL to detonate. | URL.Data | Optional |
| Interval | How often to execute polling (in minutes). | 5 | Optional |
| Timeout | The duration after which to stop polling and to resume the playbook (in minutes). | 120 | Optional |
| VM | The VM to use (string) | Optional | |
| SubmissionClassification | Classification of the sandbox submission. | Optional | |
| PremiumSandbox | Specifies if the premium sandbox should be used for detonation. | Optional | |
| Tags | A CSV list of tags applied to this sample. | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| ThreatStream.Analysis.ReportID | The report ID submitted to the sandbox. | string |
| ThreatStream.Analysis.Status | The analysis status. | string |
| ThreatStream.Analysis.Platform | The platform of the submission submitted to the sandbox. | string |
| ThreatStream.Analysis.Category | The report category. | string |
| ThreatStream.Analysis.Started | The detonation start time. | string |
| ThreatStream.Analysis.Completed | The detonation completion time. | string |
| ThreatStream.Analysis.Duration | The duration of the detonation (in seconds). | string |
| ThreatStream.Analysis.VmName | The VM name. | string |
| ThreatStream.Analysis.VmID | The VM ID. | string |
| ThreatStream.Analysis.Verdict | The verdict of the sandbox detonation. | string |
| ThreatStream.Analysis.Network.UdpSource | The UDP source. | string |
| ThreatStream.Analysis.Network.UdpDestination | The UDP destination. | string |
| ThreatStream.Analysis.Network.UdpPort | The UDP port. | number |
| ThreatStream.Analysis.Network.IcmpSource | The ICMP source. | string |
| ThreatStream.Analysis.Network.IcmpDestination | The ICMP destination. | string |
| ThreatStream.Analysis.Network.IcmpPort | The ICMP port. | number |
| ThreatStream.Analysis.Network.TcpSource | The TCP source. | string |
| ThreatStream.Analysis.Network.TcpDestination | The TCP destination. | number |
| ThreatStream.Analysis.Network.TcpPort | The TCP port. | number |
| ThreatStream.Analysis.Network.HttpSource | The source of the HTTP address. | string |
| ThreatStream.Analysis.Network.HttpDestinaton | The destination of the HTTP address. | string |
| ThreatStream.Analysis.Network.HttpPort | The port of the HTTP address. | string |
| ThreatStream.Analysis.Network.HttpsSource | The source of the HTTPS address. | string |
| ThreatStream.Analysis.Network.HttpsDestinaton | The destination of the HTTPS address. | string |
| ThreatStream.Analysis.Network.HttpsPort | The port of the HTTPS address. | string |
| ThreatStream.Analysis.Network.Hosts | The network analysis hosts. | string |
Playbook Image

Inputs
URL— URL to detonate.Interval— How often to execute polling (in minutes).Timeout— The duration after which to stop polling and to resume the playbook (in minutes).VM— The VM to use (string)SubmissionClassification— Classification of the sandbox submission.PremiumSandbox— Specifies if the premium sandbox should be used for detonation.Tags— A CSV list of tags applied to this sample.
Outputs
ThreatStream.Analysis.ReportID— The report ID submitted to the sandbox.ThreatStream.Analysis.Status— The analysis status.ThreatStream.Analysis.Platform— The platform of the submission submitted to the sandbox.ThreatStream.Analysis.Category— The report category.ThreatStream.Analysis.Started— The detonation start time.ThreatStream.Analysis.Completed— The detonation completion time.ThreatStream.Analysis.Duration— The duration of the detonation (in seconds).ThreatStream.Analysis.VmName— The VM name.ThreatStream.Analysis.VmID— The VM ID.ThreatStream.Analysis.Verdict— The verdict of the sandbox detonation.ThreatStream.Analysis.Network.UdpSource— The UDP source.ThreatStream.Analysis.Network.UdpDestination— The UDP destination.ThreatStream.Analysis.Network.UdpPort— The UDP port.ThreatStream.Analysis.Network.IcmpSource— The ICMP source.ThreatStream.Analysis.Network.IcmpDestination— The ICMP destination.ThreatStream.Analysis.Network.IcmpPort— The ICMP port.ThreatStream.Analysis.Network.TcpSource— The TCP source.ThreatStream.Analysis.Network.TcpDestination— The TCP destination.ThreatStream.Analysis.Network.TcpPort— The TCP port.ThreatStream.Analysis.Network.HttpSource— The source of the HTTP address.ThreatStream.Analysis.Network.HttpDestinaton— The destination of the HTTP address.ThreatStream.Analysis.Network.HttpPort— The port of the HTTP address.ThreatStream.Analysis.Network.HttpsSource— The source of the HTTPS address.ThreatStream.Analysis.Network.HttpsDestinaton— The destination of the HTTPS address.ThreatStream.Analysis.Network.HttpsPort— The port of the HTTPS address.ThreatStream.Analysis.Network.Hosts— The network analysis hosts.
Commands used
threatstream-analysis-report
threatstream-submit-to-sandbox
Flowchart
id: Detonate URL - ThreatStream version: -1 name: Detonate URL - ThreatStream fromversion: 5.0.0 description: |- Detonates one or more URLs using the Anomali ThreatStream sandbox integration. Returns relevant reports to the War Room and URL reputations to the context data. starttaskid: "0" tasks: "0": id: "0" taskid: 8de349d2-da6c-44b0-80fa-9ba905fae572 type: start task: id: 8de349d2-da6c-44b0-80fa-9ba905fae572 version: -1 name: "" description: Start iscommand: false brand: "" nexttasks: '#none#': - "7" separatecontext: false view: |- { "position": { "x": 50, "y": 50 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "1": id: "1" taskid: 80a68b3e-8a7e-43bb-8215-918ecde338b6 type: regular task: id: 80a68b3e-8a7e-43bb-8215-918ecde338b6 version: -1 name: ThreatStream Submit URL for Analysis description: Submits a file or URL to the ThreatStream-hosted Sandbox for detonation. script: '|||threatstream-submit-to-sandbox' type: regular iscommand: true brand: "" nexttasks: '#none#': - "2" scriptarguments: detail: complex: root: inputs.Tags premium_sandbox: complex: root: inputs.PremiumSandbox report_platform: complex: root: inputs.VM submission_classification: complex: root: inputs.SubmissionClassification submission_type: simple: url submission_value: complex: root: inputs.URL transformers: - operator: uniq separatecontext: false view: |- { "position": { "x": 275, "y": 545 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "2": id: "2" taskid: 40f7fd76-4554-43f3-8517-7ddb79b601d8 type: playbook task: id: 40f7fd76-4554-43f3-8517-7ddb79b601d8 version: -1 name: GenericPolling description: |- Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete. This playbook implements polling by continuously running the command in Step \#2 until the operation completes. The remote action should have the following structure: 1. Initiate the operation. 2. Poll to check if the operation completed. 3. (optional) Get the results of the operation. playbookName: GenericPolling type: playbook iscommand: false brand: "" nexttasks: '#none#': - "8" scriptarguments: Ids: complex: root: ThreatStream accessor: Analysis.ReportID Interval: complex: root: inputs.Interval PollingCommandArgName: simple: report_id PollingCommandName: simple: threatstream-get-analysis-status Timeout: complex: root: inputs.Timeout dt: simple: ThreatStream.Analysis(val.Status=='processing').ReportID separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 0 view: |- { "position": { "x": 275, "y": 720 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "5": id: "5" taskid: 4cd6fbcd-1b55-40ed-8dfd-c54be310bccf type: title task: id: 4cd6fbcd-1b55-40ed-8dfd-c54be310bccf version: -1 name: Done description: Done type: title iscommand: false brand: "" separatecontext: false view: |- { "position": { "x": 50, "y": 1070 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "6": id: "6" taskid: 6788a219-1746-44bf-8dfe-6b5c0ef9f311 type: condition task: id: 6788a219-1746-44bf-8dfe-6b5c0ef9f311 version: -1 name: Is there a URL to detonate? description: Checks if there is at least one URL to detonate. type: condition iscommand: false brand: "" nexttasks: '#default#': - "5" "yes": - "1" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: inputs.URL iscontext: true view: |- { "position": { "x": 160, "y": 370 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "7": id: "7" taskid: 7fbe1c8e-6a43-4d15-84f1-8ea2b45e0090 type: condition task: id: 7fbe1c8e-6a43-4d15-84f1-8ea2b45e0090 version: -1 name: Is Anomali ThreatStream v2 or v3 enabled? description: Checks if there is an active instance of the Anomali ThreatStream integration enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "5" "yes": - "6" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: Anomali ThreatStream v2 - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active accessor: brand iscontext: true right: value: {} - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: Anomali ThreatStream v3 - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active accessor: brand iscontext: true view: |- { "position": { "x": 50, "y": 195 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "8": id: "8" taskid: 253118c5-9d67-4913-861f-04cf558fe1d9 type: regular task: id: 253118c5-9d67-4913-861f-04cf558fe1d9 version: -1 name: ThreatStream Get Report description: Returns a report of the file or URL that was submitted to the sandbox. script: '|||threatstream-analysis-report' type: regular iscommand: true brand: "" nexttasks: '#none#': - "5" scriptarguments: report_id: complex: root: ThreatStream.Analysis accessor: ReportID separatecontext: false view: |- { "position": { "x": 275, "y": 895 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1085, "width": 605, "x": 50, "y": 50 } } } inputs: - key: URL value: complex: root: URL accessor: Data transformers: - operator: uniq required: false description: URL to detonate. playbookInputQuery: - key: Interval value: simple: "5" required: false description: How often to execute polling (in minutes). playbookInputQuery: - key: Timeout value: simple: "120" required: false description: The duration after which to stop polling and to resume the playbook (in minutes). playbookInputQuery: - key: VM value: {} required: false description: The VM to use (string) playbookInputQuery: - key: SubmissionClassification value: {} required: false description: Classification of the sandbox submission. playbookInputQuery: - key: PremiumSandbox value: {} required: false description: Specifies if the premium sandbox should be used for detonation. playbookInputQuery: - key: Tags value: {} required: false description: A CSV list of tags applied to this sample. playbookInputQuery: outputs: - contextPath: ThreatStream.Analysis.ReportID description: The report ID submitted to the sandbox. type: string - contextPath: ThreatStream.Analysis.Status description: The analysis status. type: string - contextPath: ThreatStream.Analysis.Platform description: The platform of the submission submitted to the sandbox. type: string - contextPath: ThreatStream.Analysis.Category description: The report category. type: string - contextPath: ThreatStream.Analysis.Started description: The detonation start time. type: string - contextPath: ThreatStream.Analysis.Completed description: The detonation completion time. type: string - contextPath: ThreatStream.Analysis.Duration description: The duration of the detonation (in seconds). type: string - contextPath: ThreatStream.Analysis.VmName description: The VM name. type: string - contextPath: ThreatStream.Analysis.VmID description: The VM ID. type: string - contextPath: ThreatStream.Analysis.Verdict description: The verdict of the sandbox detonation. type: string - contextPath: ThreatStream.Analysis.Network.UdpSource description: The UDP source. type: string - contextPath: ThreatStream.Analysis.Network.UdpDestination description: The UDP destination. type: string - contextPath: ThreatStream.Analysis.Network.UdpPort description: The UDP port. type: number - contextPath: ThreatStream.Analysis.Network.IcmpSource description: The ICMP source. type: string - contextPath: ThreatStream.Analysis.Network.IcmpDestination description: The ICMP destination. type: string - contextPath: ThreatStream.Analysis.Network.IcmpPort description: The ICMP port. type: number - contextPath: ThreatStream.Analysis.Network.TcpSource description: The TCP source. type: string - contextPath: ThreatStream.Analysis.Network.TcpDestination description: The TCP destination. type: number - contextPath: ThreatStream.Analysis.Network.TcpPort description: The TCP port. type: number - contextPath: ThreatStream.Analysis.Network.HttpSource description: The source of the HTTP address. type: string - contextPath: ThreatStream.Analysis.Network.HttpDestinaton description: The destination of the HTTP address. type: string - contextPath: ThreatStream.Analysis.Network.HttpPort description: The port of the HTTP address. type: string - contextPath: ThreatStream.Analysis.Network.HttpsSource description: The source of the HTTPS address. type: string - contextPath: ThreatStream.Analysis.Network.HttpsDestinaton description: The destination of the HTTPS address. type: string - contextPath: ThreatStream.Analysis.Network.HttpsPort description: The port of the HTTPS address. type: string - contextPath: ThreatStream.Analysis.Network.Hosts description: The network analysis hosts. type: string tests: - No tests (auto formatted) contentitemexportablefields: contentitemfields: {}