Detonate URL - Generic Deprecated

Deprecated. Use Detonate URL - Generic v1.5 playbook instead. Detonate URL through active integrations that support URL detonation.

Common Playbooks · 21 tasks · 1 input · 138 outputs

Details

IDdetonate_url_-_generic
From Version5.0.0
Tasks21

README

Detonate URL through active integrations that support URL detonation.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Detonate URL - JoeSecurity
  • Detonate URL - Hybrid Analysis
  • Detonate URL - Lastline v2
  • Detonate URL - ThreatGrid
  • Detonate URL - WildFire v2.1
  • Detonate URL - McAfee ATD
  • Detonate URL - ANYRUN
  • Detonate URL - Group-IB TDS Polygon
  • Detonate URL - CrowdStrike Falcon Intelligence Sandbox
  • Detonate URL - VirusTotal (API v3)
  • Detonate URL - Hatching Triage
  • Detonate URL - FireEye AX
  • Detonate URL - Cuckoo
  • Detonate URL - SecneurX Analysis
  • Detonate URL - VMRay
  • Detonate URL - ThreatStream

Integrations

  • CrowdStrike Falcon Sandbox V2
  • OPSWAT Filescan

Scripts

This playbook does not use any scripts.

Commands

  • cs-falcon-sandbox-submit-url
  • opswat-filescan-scan-url

Playbook Inputs


Name Description Default Value Required
URL The URL object of the URL to be detonated. URL Optional

Playbook Outputs


Path Description Type
File The file’s object. string
File.Name The file name. string
File.Size The file size. number
File.Type The file type, for example “PE” (only for report type=json). string
File.SHA256 The SHA256 hash of the file. string
File.SHA1 The SHA1 hash of the file. string
File.MD5 The MD5 hash of the file. string
File.Malicious.Vendor The vendor that decided the file is malicious. string
File.Malicious.Description The reason the vendor decided the file is malicious. string
DBotScore The indicator’s object. string
DBotScore.Type The indicator type. string
DBotScore.Indicator The indicator that was tested. string
DBotScore.Vendor The vendor used to calculate the score. string
DBotScore.Score The actual score. number
Joe.Analysis.WebID The Joe Analysis-related web ID. string
Joe.Analysis.Status The Joe Analysis-related status. string
Joe.Analysis.Comments The Joe Analysis-related comments. string
Joe.Analysis.Time The Joe Analysis-related submitted time. date
Joe.Analysis.Runs The Joe Analysis-related sub-analysis information. string
Joe.Analysis.Result The Joe Analysis-related results. string
Joe.Analysis.Errors The Joe Analysis-related errors raised during sampling. string
Joe.Analysis.Systems The Joe Analysis-related operating systems. string
Joe.Analysis.MD5 The MD5 hash of the Joe Analysis-related sample. string
Joe.Analysis.SHA1 The SHA1 hash of the Joe Analysis-related sample. string
Joe.Analysis.SHA256 The SHA256 hash of the Joe Analysis-related sample. string
Joe.Analysis.SampleName The Joe Analysis-related sample data name. Can be a file name or a URL. string
InfoFile.Name The file name. string
InfoFile.EntryID The EntryID of the sample. string
InfoFile.Size The file size. number
InfoFile.Type The file type, for example “PE”. string
InfoFile.Info The file basic information. string
Sample.State The sample state. string
Sample.ID The sample ID. string
IP.Address The IP addresses relevant to the sample. string
InfoFile The report file’s object. string
Cuckoo.Task.Category The Cuckoo-related task category. unknown
Cuckoo.Task.Machine The Cuckoo-related task machine. unknown
Cuckoo.Task.Errors The Cuckoo-related task errors. unknown
Cuckoo.Task.Target The Cuckoo-related task target. unknown
Cuckoo.Task.Package The Cuckoo-related task package. unknown
Cuckoo.Task.SampleID The Cuckoo-related task sample ID. unknown
Cuckoo.Task.Guest The Cuckoo-related task guest. unknown
Cuckoo.Task.Custom The Cuckoo-related task custom values. unknown
Cuckoo.Task.Owner The Cuckoo-related task owner. unknown
Cuckoo.Task.Priority The Cuckoo-related task priority. unknown
Cuckoo.Task.Platform The Cuckoo-related task platform. unknown
Cuckoo.Task.Options The Cuckoo-related task options. unknown
Cuckoo.Task.Status The Cuckoo-related task status. unknown
Cuckoo.Task.EnforceTimeout Whether the Cuckoo-related task timeout is enforced. unknown
Cuckoo.Task.Timeout The Cuckoo-related task timeout. unknown
Cuckoo.Task.Memory The Cuckoo-related task memory. unknown
Cuckoo.Task.Tags The Cuckoo-related task tags. unknown
Cuckoo.Task.ID The Cuckoo-related task ID. unknown
Cuckoo.Task.AddedOn The date the Cuckoo-related task was added. unknown
Cuckoo.Task.CompletedOn The date the Cuckoo-related task was completed. unknown
Cuckoo.Task.Score The reported Cuckoo-related task score. unknown
Cuckoo.Task.Monitor The reported Cuckoo-related task monitor. unknown
ANYRUN.Task.AnalysisDate The date and time the ANY.RUN analysis was executed. String
ANYRUN.Task.Behavior.Category The ANY.RUN behavior category. String
ANYRUN.Task.Behavior.Action The actions performed by an ANY.RUN behavior. String
ANYRUN.Task.Behavior.ThreatLevel The threat score associated with an ANY.RUN behavior. Number
ANYRUN.Task.Behavior.ProcessUUID The ANY.RUN unique ID of the process whose behaviors are profiled. String
ANYRUN.Task.Connection.Reputation The ANY.RUN connection reputation. String
ANYRUN.Task.Connection.ProcessUUID The ANY.RUN UUID of the process that created the connection. String
ANYRUN.Task.Connection.ASN The ANY.RUN connection autonomous system network. String
ANYRUN.Task.Connection.Country The ANY.RUN connection country. String
ANYRUN.Task.Connection.Protocol The ANY.RUN connection protocol. String
ANYRUN.Task.Connection.Port The ANY.RUN connection port number. Number
ANYRUN.Task.Connection.IP The ANY.RUN connection IP address. String
ANYRUN.Task.DnsRequest.Reputation The ANY.RUN process reputation of the DNS request. String
ANYRUN.Task.DnsRequest.IP The ANY.RUN IP addresses associated with a DNS request. string
ANYRUN.Task.DnsRequest.Domain The ANY.RUN domain resolution of a DNS request. String
ANYRUN.Task.Threat.ProcessUUID The unique ANY.RUN UUID of the process that originated the threat. String
ANYRUN.Task.Threat.Msg The ANY.RUN threat message. String
ANYRUN.Task.Threat.Class The ANY.RUN threat class. String
ANYRUN.Task.Threat.SrcPort The ANY.RUN port on which the threat originated. Number
ANYRUN.Task.Threat.DstPort The ANY.RUN threat destination port. Number
ANYRUN.Task.Threat.SrcIP The ANY.RUN source IP address where the threat originated. String
ANYRUN.Task.Threat.DstIP The ANY.RUN threat destination IP address. String
ANYRUN.Task.HttpRequest.Reputation The ANY.RUN HTTP request reputation. String
ANYRUN.Task.HttpRequest.Country The ANY.RUN HTTP request country. String
ANYRUN.Task.HttpRequest.ProcessUUID The ANY.RUN UUID of the process making the HTTP request. String
ANYRUN.Task.HttpRequest.Body The ANY.RUN HTTP request body parameters and details. string
ANYRUN.Task.HttpRequest.HttpCode The ANY.RUN HTTP request response code. Number
ANYRUN.Task.HttpRequest.Status The ANY.RUN status of the HTTP request. String
ANYRUN.Task.HttpRequest.ProxyDetected Whether the ANY.RUN HTTP request was made through a proxy. Boolean
ANYRUN.Task.HttpRequest.Port The ANY.RUN HTTP request port. Number
ANYRUN.Task.HttpRequest.IP The ANY.RUN HTTP request IP address. String
ANYRUN.Task.HttpRequest.URL The ANY.RUN HTTP request URL. String
ANYRUN.Task.HttpRequest.Host The ANY.RUN HTTP request host. String
ANYRUN.Task.HttpRequest.Method The ANY.RUN HTTP request method type. String
ANYRUN.Task.FileInfo The ANY.RUN submitted file details. String
ANYRUN.Task.OS The ANY.RUN operating system of the sandbox in which the file was analyzed. String
ANYRUN.Task.ID The unique ANY.RUN task ID. String
ANYRUN.Task.MIME The ANY.RUN MIME of the file submitted for analysis. String
ANYRUN.Task.Verdict The ANY.RUN verdict for the maliciousness of the submitted file or URL. String
ANYRUN.Task.Process.FileName The ANY.RUN process file name. String
ANYRUN.Task.Process.PID The ANY.RUN process identification number. Number
ANYRUN.Task.Process.PPID The ANY.RUN process parent process identification number. Number
ANYRUN.Task.Process.ProcessUUID The unique ANY.RUN process UUID. String
ANYRUN.Task.Process.CMD The ANY.RUN process command. String
ANYRUN.Task.Process.Path The path of the executed ANY.RUN process command. String
ANYRUN.Task.Process.User The user who executed the ANY.RUN process command. String
ANYRUN.Task.Process.IntegrityLevel The ANY.RUN process integrity level. String
ANYRUN.Task.Process.ExitCode The ANY.RUN process exit code. Number
ANYRUN.Task.Process.MainProcess Whether the ANY.RUN process is the main process. Boolean
ANYRUN.Task.Process.Version.Company The company responsible for the executed ANY.RUN process program. String
ANYRUN.Task.Process.Version.Description The description of the ANY.RUN process program type. String
ANYRUN.Task.Process.Version.Version The version of the executed program. String
URL.Data The URL data. String
URL.Malicious.Vendor The vendor that decided the URL is malicious. String
URL.Malicious.Description The reason the vendor decided the URL is malicious. String
ANYRUN.Task.Status The task analysis status. String
FireEyeAX.Submissions.Key The submission key unknown
FireEyeAX.Submissions.Severity The severity level of the file unknown
FireEyeAX.Submissions.InfoLevel The info level of the report. unknown
DBotScore.Score The actual score. unknown
DBotScore.Indicator The indicator that was tested. unknown
DBotScore.Vendor The vendor used to calculate the score. unknown
Triage.sample-summaries.completed The date the sample analysis was completed. unknown
Triage.sample-summaries.created The date the analysis report was created. unknown
Triage.sample-summaries.custom The custom sample analysis. unknown
Triage.sample-summaries.owner The owner of the sample summaries. unknown
Triage.sample-summaries.sample The unique identifier of the sample. unknown
Triage.sample-summaries.score The score of the sample on a scale of 0 to 10. unknown
Triage.sample-summaries.sha256 The SHA256 of the sample. unknown
Triage.sample-summaries.status The status of the analysis. unknown
Triage.sample-summaries.target The target for the analysis. unknown
Triage.sample-summaries.tasks The tasks performed in the analysis. unknown
HybridAnalysis.URL.Scanner.Name The URL scanner name. unknown
HybridAnalysis.URL.Scanner.Positives The number of positive scanners. unknown
HybridAnalysis.URL.Scanner.Status The status of the scanning. unknown
HybridAnalysis.URL.Scanner The place holder for the scanner data. unknown
SecneurXAnalysis.Report.SHA256 SHA256 value of the analyzed sample string
SecneurXAnalysis.Report.Verdict Summary result of the analyzed sample string
SecneurXAnalysis.Report.Tags More details of the analyzed sample string
SecneurXAnalysis.Report.IOC List of IOC’s observed in the analyzed sample string
SecneurXAnalysis.Report.Status Analysis queued sample state String

Playbook Image


Detonate URL - Generic

Inputs

  • URL — The URL object of the URL to be detonated.

Outputs

  • File — The file's object.
  • File.Name — The file name.
  • File.Size — The file size.
  • File.Type — The file type, for example "PE" (only for report type=json).
  • File.SHA256 — The SHA256 hash of the file.
  • File.SHA1 — The SHA1 hash of the file.
  • File.MD5 — The MD5 hash of the file.
  • File.Malicious.Vendor — The vendor that decided the file is malicious.
  • File.Malicious.Description — The reason the vendor decided the file is malicious.
  • DBotScore — The indicator's object.
  • DBotScore.Type — The indicator type.
  • DBotScore.Indicator — The indicator that was tested.
  • DBotScore.Vendor — The vendor used to calculate the score.
  • DBotScore.Score — The actual score.
  • Joe.Analysis.WebID — The Joe Analysis-related web ID.
  • Joe.Analysis.Status — The Joe Analysis-related status.
  • Joe.Analysis.Comments — The Joe Analysis-related comments.
  • Joe.Analysis.Time — The Joe Analysis-related submitted time.
  • Joe.Analysis.Runs — The Joe Analysis-related sub-analysis information.
  • Joe.Analysis.Result — The Joe Analysis-related results.
  • Joe.Analysis.Errors — The Joe Analysis-related errors raised during sampling.
  • Joe.Analysis.Systems — The Joe Analysis-related operating systems.
  • Joe.Analysis.MD5 — The MD5 hash of the Joe Analysis-related sample.
  • Joe.Analysis.SHA1 — The SHA1 hash of the Joe Analysis-related sample.
  • Joe.Analysis.SHA256 — The SHA256 hash of the Joe Analysis-related sample.
  • Joe.Analysis.SampleName — The Joe Analysis-related sample data name. Can be a file name or a URL.
  • InfoFile.Name — The file name.
  • InfoFile.EntryID — The EntryID of the sample.
  • InfoFile.Size — The file size.
  • InfoFile.Type — The file type, for example "PE".
  • InfoFile.Info — The file basic information.
  • Sample.State — The sample state.
  • Sample.ID — The sample ID.
  • IP.Address — The IP addresses relevant to the sample.
  • InfoFile — The report file's object.
  • Cuckoo.Task.Category — The Cuckoo-related task category.
  • Cuckoo.Task.Machine — The Cuckoo-related task machine.
  • Cuckoo.Task.Errors — The Cuckoo-related task errors.
  • Cuckoo.Task.Target — The Cuckoo-related task target.
  • Cuckoo.Task.Package — The Cuckoo-related task package.
  • Cuckoo.Task.SampleID — The Cuckoo-related task sample ID.
  • Cuckoo.Task.Guest — The Cuckoo-related task guest.
  • Cuckoo.Task.Custom — The Cuckoo-related task custom values.
  • Cuckoo.Task.Owner — The Cuckoo-related task owner.
  • Cuckoo.Task.Priority — The Cuckoo-related task priority.
  • Cuckoo.Task.Platform — The Cuckoo-related task platform.
  • Cuckoo.Task.Options — The Cuckoo-related task options.
  • Cuckoo.Task.Status — The Cuckoo-related task status.
  • Cuckoo.Task.EnforceTimeout — Whether the Cuckoo-related task timeout is enforced.
  • Cuckoo.Task.Timeout — The Cuckoo-related task timeout.
  • Cuckoo.Task.Memory — The Cuckoo-related task memory.
  • Cuckoo.Task.Tags — The Cuckoo-related task tags.
  • Cuckoo.Task.ID — The Cuckoo-related task ID.
  • Cuckoo.Task.AddedOn — The date the Cuckoo-related task was added.
  • Cuckoo.Task.CompletedOn — The date the Cuckoo-related task was completed.
  • Cuckoo.Task.Score — The reported Cuckoo-related task score.
  • Cuckoo.Task.Monitor — The reported Cuckoo-related task monitor.
  • ANYRUN.Task.AnalysisDate — The date and time the ANY.RUN analysis was executed.
  • ANYRUN.Task.Behavior.Category — The ANY.RUN behavior category.
  • ANYRUN.Task.Behavior.Action — The actions performed by an ANY.RUN behavior.
  • ANYRUN.Task.Behavior.ThreatLevel — The threat score associated with an ANY.RUN behavior.
  • ANYRUN.Task.Behavior.ProcessUUID — The ANY.RUN unique ID of the process whose behaviors are profiled.
  • ANYRUN.Task.Connection.Reputation — The ANY.RUN connection reputation.
  • ANYRUN.Task.Connection.ProcessUUID — The ANY.RUN UUID of the process that created the connection.
  • ANYRUN.Task.Connection.ASN — The ANY.RUN connection autonomous system network.
  • ANYRUN.Task.Connection.Country — The ANY.RUN connection country.
  • ANYRUN.Task.Connection.Protocol — The ANY.RUN connection protocol.
  • ANYRUN.Task.Connection.Port — The ANY.RUN connection port number.
  • ANYRUN.Task.Connection.IP — The ANY.RUN connection IP address.
  • ANYRUN.Task.DnsRequest.Reputation — The ANY.RUN process reputation of the DNS request.
  • ANYRUN.Task.DnsRequest.IP — The ANY.RUN IP addresses associated with a DNS request.
  • ANYRUN.Task.DnsRequest.Domain — The ANY.RUN domain resolution of a DNS request.
  • ANYRUN.Task.Threat.ProcessUUID — The unique ANY.RUN UUID of the process that originated the threat.
  • ANYRUN.Task.Threat.Msg — The ANY.RUN threat message.
  • ANYRUN.Task.Threat.Class — The ANY.RUN threat class.
  • ANYRUN.Task.Threat.SrcPort — The ANY.RUN port on which the threat originated.
  • ANYRUN.Task.Threat.DstPort — The ANY.RUN threat destination port.
  • ANYRUN.Task.Threat.SrcIP — The ANY.RUN source IP address where the threat originated.
  • ANYRUN.Task.Threat.DstIP — The ANY.RUN threat destination IP address.
  • ANYRUN.Task.HttpRequest.Reputation — The ANY.RUN HTTP request reputation.
  • ANYRUN.Task.HttpRequest.Country — The ANY.RUN HTTP request country.
  • ANYRUN.Task.HttpRequest.ProcessUUID — The ANY.RUN UUID of the process making the HTTP request.
  • ANYRUN.Task.HttpRequest.Body — The ANY.RUN HTTP request body parameters and details.
  • ANYRUN.Task.HttpRequest.HttpCode — The ANY.RUN HTTP request response code.
  • ANYRUN.Task.HttpRequest.Status — The ANY.RUN status of the HTTP request.
  • ANYRUN.Task.HttpRequest.ProxyDetected — Whether the ANY.RUN HTTP request was made through a proxy.
  • ANYRUN.Task.HttpRequest.Port — The ANY.RUN HTTP request port.
  • ANYRUN.Task.HttpRequest.IP — The ANY.RUN HTTP request IP address.
  • ANYRUN.Task.HttpRequest.URL — The ANY.RUN HTTP request URL.
  • ANYRUN.Task.HttpRequest.Host — The ANY.RUN HTTP request host.
  • ANYRUN.Task.HttpRequest.Method — The ANY.RUN HTTP request method type.
  • ANYRUN.Task.FileInfo — The ANY.RUN submitted file details.
  • ANYRUN.Task.OS — The ANY.RUN operating system of the sandbox in which the file was analyzed.
  • ANYRUN.Task.ID — The unique ANY.RUN task ID.
  • ANYRUN.Task.MIME — The ANY.RUN MIME of the file submitted for analysis.
  • ANYRUN.Task.Verdict — The ANY.RUN verdict for the maliciousness of the submitted file or URL.
  • ANYRUN.Task.Process.FileName — The ANY.RUN process file name.
  • ANYRUN.Task.Process.PID — The ANY.RUN process identification number.
  • ANYRUN.Task.Process.PPID — The ANY.RUN process parent process identification number.
  • ANYRUN.Task.Process.ProcessUUID — The unique ANY.RUN process UUID.
  • ANYRUN.Task.Process.CMD — The ANY.RUN process command.
  • ANYRUN.Task.Process.Path — The path of the executed ANY.RUN process command.
  • ANYRUN.Task.Process.User — The user who executed the ANY.RUN process command.
  • ANYRUN.Task.Process.IntegrityLevel — The ANY.RUN process integrity level.
  • ANYRUN.Task.Process.ExitCode — The ANY.RUN process exit code.
  • ANYRUN.Task.Process.MainProcess — Whether the ANY.RUN process is the main process.
  • ANYRUN.Task.Process.Version.Company — The company responsible for the executed ANY.RUN process program.
  • ANYRUN.Task.Process.Version.Description — The description of the ANY.RUN process program type.
  • ANYRUN.Task.Process.Version.Version — The version of the executed program.
  • URL.Data — The URL data.
  • URL.Malicious.Vendor — The vendor that decided the URL is malicious.
  • URL.Malicious.Description — The reason the vendor decided the URL is malicious.
  • ANYRUN.Task.Status — The task analysis status.
  • FireEyeAX.Submissions.Key — The submission key
  • FireEyeAX.Submissions.Severity — The severity level of the file
  • FireEyeAX.Submissions.InfoLevel — The info level of the report.
  • DBotScore.Score — The actual score.
  • DBotScore.Indicator — The indicator that was tested.
  • DBotScore.Vendor — The vendor used to calculate the score.
  • Triage.sample-summaries.completed — The date the sample analysis was completed.
  • Triage.sample-summaries.created — The date the analysis report was created.
  • Triage.sample-summaries.custom — The custom sample analysis.
  • Triage.sample-summaries.owner — The owner of the sample summaries.
  • Triage.sample-summaries.sample — The unique identifier of the sample.
  • Triage.sample-summaries.score — The score of the sample on a scale of 0 to 10.
  • Triage.sample-summaries.sha256 — The SHA256 of the sample.
  • Triage.sample-summaries.status — The status of the analysis.
  • Triage.sample-summaries.target — The target for the analysis.
  • Triage.sample-summaries.tasks — The tasks performed in the analysis.
  • HybridAnalysis.URL.Scanner.Name — The URL scanner name.
  • HybridAnalysis.URL.Scanner.Positives — The number of positive scanners.
  • HybridAnalysis.URL.Scanner.Status — The status of the scanning.
  • HybridAnalysis.URL.Scanner — The place holder for the scanner data.
  • SecneurXAnalysis.Report.SHA256 — SHA256 value of the analyzed sample
  • SecneurXAnalysis.Report.Verdict — Summary result of the analyzed sample
  • SecneurXAnalysis.Report.Tags — More details of the analyzed sample
  • SecneurXAnalysis.Report.IOC — List of IOC's observed in the analyzed sample
  • SecneurXAnalysis.Report.Status — Analysis queued sample state

Commands used

cs-falcon-sandbox-submit-url

Flowchart

yes Start Start Done Done Detonate URL - ThreatGrid - Detonate URL - ThreatGrid Detonate URL - ThreatGrid Detonate URL - ThreatGrid Detonate URL - McAfee ATD - Detonate URL - McAfee ATD Detonate URL - McAfee ATD Detonate URL - McAfee ATD Detonate URL - JoeSecurity - Detonate URL - JoeSecurity Detonate URL - JoeSecurity Detonate URL - JoeSecurity Detonate URL - Lastline v2 - Detonate URL - Lastline v2 Detonate URL - Lastline v2 Detonate URL - Lastline v2 Detonate URL - Cuckoo - Detonate URL - Cuckoo Detonate URL - Cuckoo Detonate URL - Cuckoo Detonate URL - ANYRUN - Detonate URL - ANYRUN Detonate URL - ANYRUN Detonate URL - ANYRUN Detonate URL - Group-IB TDS Polygon - Detonate URL - Group-IB TDS Polygon Detonate URL - Group-IB T... Detonate URL - Group-IB TDS P... Detonate URL - CrowdStrike Falcon Intelligence Sandbox - cs-falcon-sandbox-submit-url Detonate URL - CrowdStrik... cs-falcon-sandbox-submit-url Detonate URL - WildFire v2.1 - Detonate URL - WildFire v2.1 Detonate URL - WildFire v2.1 Detonate URL - WildFire v2.1 Detonate URL - VirusTotal (API v3) - Detonate URL - VirusTotal (API v3) Detonate URL - VirusTotal... Detonate URL - VirusTotal (AP... Detonate URL - VMRay - Detonate URL - VMRay Detonate URL - VMRay Detonate URL - VMRay Detonate URL - ThreatStream - Detonate URL - ThreatStream Detonate URL - ThreatStream Detonate URL - ThreatStream Detonate URL - Hybrid Analysis - Detonate URL - Hybrid Analysis Detonate URL - Hybrid Ana... Detonate URL - Hybrid Analysis Detonate URL - FireEye AX - Detonate URL - FireEye AX Detonate URL - FireEye AX Detonate URL - FireEye AX Detonate URL - Hatching Triage - Detonate URL - Hatching Triage Detonate URL - Hatching T... Detonate URL - Hatching Triage Detonate URL - SecneurX Analysis - Detonate URL - SecneurX Analysis Detonate URL - SecneurX A... Detonate URL - SecneurX Analysis Detonate URL - CrowdStrike Falcon Intelligence Sandbox - Detonate URL - CrowdStrike Falcon Intelligence Sandbox Detonate URL - CrowdStrik... Detonate URL - CrowdStrike Fa... Check if URL exists Check if URL exists Detonate URL - MetaDefender Sandbox Detonate URL - MetaDefend...
id: detonate_url_-_generic
version: -1
deprecated: true
name: Detonate URL - Generic
description: Deprecated. Use Detonate URL - Generic v1.5 playbook instead. Detonate URL through active integrations that support URL detonation.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: ab416b1d-600a-47a5-89dc-64d0f0002db6
    type: start
    task:
      id: ab416b1d-600a-47a5-89dc-64d0f0002db6
      version: -1
      name: ""
      description: Playbook start point
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "11"
      - "13"
      - "12"
      - "15"
      - "16"
      - "17"
      - "18"
      - "19"
      - "20"
      - "21"
      - "23"
      - "24"
      - "25"
      - "26"
      - "27"
      - "28"
      - "29"
      - "31"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 3705,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "3":
    id: "3"
    taskid: 91ee56ee-91ac-4199-89fe-50ad796c6b02
    type: title
    task:
      id: 91ee56ee-91ac-4199-89fe-50ad796c6b02
      version: -1
      name: Done
      description: Done
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 4135,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "11":
    id: "11"
    taskid: 754e447b-20d7-4ab6-8713-97409910d090
    type: playbook
    task:
      id: 754e447b-20d7-4ab6-8713-97409910d090
      version: -1
      name: Detonate URL - ThreatGrid
      description: Detonates one or more URLs using the Threat Grid integration. This playbook returns relevant reports to the War Room and URL reputations to the context data.
      playbookName: Detonate URL - ThreatGrid
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 50,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "12":
    id: "12"
    taskid: 237ce1af-7984-4df7-8eea-e6577bf59c4a
    type: playbook
    task:
      id: 237ce1af-7984-4df7-8eea-e6577bf59c4a
      version: -1
      name: Detonate URL - McAfee ATD
      description: Detonates a URL using the McAfee Advanced Threat Defense sandbox integration.
      playbookName: Detonate URL - McAfee ATD
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 480,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "13":
    id: "13"
    taskid: 22124bae-451b-432b-88e6-1a9affb9ee16
    type: playbook
    task:
      id: 22124bae-451b-432b-88e6-1a9affb9ee16
      version: -1
      name: Detonate URL - JoeSecurity
      description: |-
        Detonates one or more URLs using the Joe Security sandbox integration.
        Returns relevant reports to the War Room and URL reputations to the context data.
      playbookName: Detonate URL - JoeSecurity
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 910,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "15":
    id: "15"
    taskid: 481f79ec-f360-4b69-8881-98b67f23eedb
    type: playbook
    task:
      id: 481f79ec-f360-4b69-8881-98b67f23eedb
      version: -1
      name: Detonate URL - Lastline v2
      description: Detonates a URL using the Lastline sandbox integration.
      playbookName: Detonate URL - Lastline v2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 1340,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "16":
    id: "16"
    taskid: bf269b42-9e68-4fe8-8ae1-f197a0678116
    type: playbook
    task:
      id: bf269b42-9e68-4fe8-8ae1-f197a0678116
      version: -1
      name: Detonate URL - Cuckoo
      description: Detonating URL with Cuckoo
      playbookName: Detonate URL - Cuckoo
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
      interval:
        simple: "1"
      timeout:
        simple: "10"
    separatecontext: false
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 1770,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "17":
    id: "17"
    taskid: 527c7883-aab3-4641-87a1-296c5bc10806
    type: playbook
    task:
      id: 527c7883-aab3-4641-87a1-296c5bc10806
      version: -1
      name: Detonate URL - ANYRUN
      description: Detonates a URL using the ANYRUN sandbox.
      playbookName: Detonate URL - ANYRUN
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 2200,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "18":
    id: "18"
    taskid: ae8130db-d640-476c-8509-caa0a3318d69
    type: playbook
    task:
      id: ae8130db-d640-476c-8509-caa0a3318d69
      version: -1
      name: Detonate URL - Group-IB TDS Polygon
      playbookName: Detonate URL - Group-IB TDS Polygon
      type: playbook
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      Interval:
        simple: "1"
      Timeout:
        simple: "60"
      url:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 2630,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "19":
    id: "19"
    taskid: 0ff5715e-873b-4d67-87da-2080cd4e5f34
    type: regular
    task:
      id: 0ff5715e-873b-4d67-87da-2080cd4e5f34
      version: -1
      name: Detonate URL - CrowdStrike Falcon Intelligence Sandbox
      description: Submits a URL for analysis.
      script: '|||cs-falcon-sandbox-submit-url'
      type: regular
      iscommand: true
      brand: CrowdStrike Falcon Sandbox V2
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      environmentID:
        simple: "100"
      polling:
        simple: "true"
      url:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3060,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: 2ad2429a-91b6-4728-820f-d782e7b3a42d
    type: playbook
    task:
      id: 2ad2429a-91b6-4728-820f-d782e7b3a42d
      version: -1
      name: Detonate URL - WildFire v2.1
      description: |-
        Detonate a webpage or remote file using the WildFire integration. This playbook returns relevant reports to the War Room and file reputations to the context data.
        The detonation supports the following file types:
        APK, JAR, DOC, DOCX, RTF, OOXLS, XLSX, PPT, PPTX, XML, PE32, PDF, DMG, PKG, RAR, 7Z, JS.
      playbookName: Detonate URL - WildFire v2.1
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      Interval:
        simple: "1"
      Timeout:
        simple: "60"
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 3490,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "21":
    id: "21"
    taskid: 035deb07-590a-485a-8500-2b5b553efec4
    type: playbook
    task:
      id: 035deb07-590a-485a-8500-2b5b553efec4
      version: -1
      name: Detonate URL - VirusTotal (API v3)
      description: Detonate URL through VirusTotal (API v3) integration.
      playbookName: Detonate URL - VirusTotal (API v3)
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 3920,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "23":
    id: "23"
    taskid: c1bbd5a6-59c4-4c09-8399-2e2ae4abd2df
    type: playbook
    task:
      id: c1bbd5a6-59c4-4c09-8399-2e2ae4abd2df
      version: -1
      name: Detonate URL - VMRay
      playbookName: Detonate URL - VMRay
      type: playbook
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          accessor: Data
      interval:
        simple: "1"
      timeout:
        simple: "10"
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 4350,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "24":
    id: "24"
    taskid: 28a9d2ed-ee25-4a25-87f5-a19dd30e6b45
    type: playbook
    task:
      id: 28a9d2ed-ee25-4a25-87f5-a19dd30e6b45
      version: -1
      name: Detonate URL - ThreatStream
      playbookName: Detonate URL - ThreatStream
      type: playbook
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      "#none#":
      - "3"
    scriptarguments:
      Interval:
        simple: "5"
      Timeout:
        simple: "120"
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 4780,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "25":
    id: "25"
    taskid: 5535b892-f1b1-42d6-8f7e-c673377dff5c
    type: playbook
    task:
      id: 5535b892-f1b1-42d6-8f7e-c673377dff5c
      version: -1
      name: Detonate URL - Hybrid Analysis
      playbookName: Detonate URL - Hybrid Analysis
      type: playbook
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      "#none#":
      - "3"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 5210,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "26":
    id: "26"
    taskid: 538c5113-5469-4692-89b2-c1570b74aaef
    type: playbook
    task:
      id: 538c5113-5469-4692-89b2-c1570b74aaef
      version: -1
      name: Detonate URL - FireEye AX
      playbookName: Detonate URL - FireEye AX
      type: playbook
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      "#none#":
      - "3"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 5640,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "27":
    id: "27"
    taskid: 13bebc22-497e-48e6-85f0-41f6ee62fef1
    type: playbook
    task:
      id: 13bebc22-497e-48e6-85f0-41f6ee62fef1
      version: -1
      name: Detonate URL - Hatching Triage
      playbookName: Detonate URL - Hatching Triage
      type: playbook
      iscommand: false
      brand: ""
      description: ""
    nexttasks:
      "#none#":
      - "3"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 6070,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "28":
    id: "28"
    taskid: ca1a3f90-8330-4eac-885c-eec86c8b8885
    type: playbook
    task:
      id: ca1a3f90-8330-4eac-885c-eec86c8b8885
      version: -1
      name: Detonate URL - SecneurX Analysis
      description: Detonates a file using the SecneurX Analysis Integration. Returns relevant reports to the War Room and file reputations to the context data.
      playbookName: Detonate URL - SecneurX Analysis
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      Priority:
        simple: High
      Reboot:
        simple: "False"
      ReportFormat:
        simple: json
      URL:
        complex:
          root: URL
          filters:
          - - operator: isExists
              left:
                value:
                  simple: URL.Data
                iscontext: true
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 6500,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "29":
    id: "29"
    taskid: b12fdeb4-9952-416d-8e01-39eef0662454
    type: playbook
    task:
      id: b12fdeb4-9952-416d-8e01-39eef0662454
      version: -1
      name: Detonate URL - CrowdStrike Falcon Intelligence Sandbox
      playbookName: Detonate URL - CrowdStrike Falcon Intelligence Sandbox
      description: 'Detonate one or more files using the CrowdStrike Falcon Intelligence Sandbox integration.'
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      Interval:
        simple: "1"
      Timeout:
        simple: "60"
      URL:
        complex:
          root: inputs.URL
          accessor: Data
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 6930,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "31":
    id: "31"
    taskid: 1abb6283-2a97-4409-8344-027a49c5ef5e
    type: condition
    task:
      id: 1abb6283-2a97-4409-8344-027a49c5ef5e
      version: -1
      name: Check if URL exists
      description: Checks if there is a URL to detonate.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "3"
      "yes":
      - "32"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              simple: inputs.URL
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 7390,
          "y": 360
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "32":
    id: "32"
    taskid: 2fee63e9-6482-4101-8272-d42cf3a950aa
    type: regular
    task:
      id: 2fee63e9-6482-4101-8272-d42cf3a950aa
      version: -1
      name: Detonate URL - MetaDefender Sandbox
      description: Detonates a URL using the MetaDefender Sandbox Integration. Returns relevant reports to the War Room and URL reputations to the context data.
      script: metadefender-sandbox-scan-url
      type: regular
      iscommand: true
      brand: MetaDefender Sandbox
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      url:
        simple: ${inputs.URL.Data}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 7502.5,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 735,
        "width": 7832.5,
        "x": 50,
        "y": 50
      }
    }
  }
inputs:
- key: URL
  value:
    complex:
      root: URL
  required: false
  description: The URL object of the URL to be detonated.
  playbookInputQuery:
outputs:
- contextPath: File
  description: The file's object.
  type: string
- contextPath: File.Name
  description: The file name.
  type: string
- contextPath: File.Size
  description: The file size.
  type: number
- contextPath: File.Type
  description: The file type, for example "PE" (only for report type=json).
  type: string
- contextPath: File.SHA256
  description: The SHA256 hash of the file.
  type: string
- contextPath: File.SHA1
  description: The SHA1 hash of the file.
  type: string
- contextPath: File.MD5
  description: The MD5 hash of the file.
  type: string
- contextPath: File.Malicious.Vendor
  description: The vendor that decided the file is malicious.
  type: string
- contextPath: File.Malicious.Description
  description: The reason the vendor decided the file is malicious.
  type: string
- contextPath: DBotScore
  description: The indicator's object.
  type: string
- contextPath: DBotScore.Type
  description: The indicator type.
  type: string
- contextPath: DBotScore.Indicator
  description: The indicator that was tested.
  type: string
- contextPath: DBotScore.Vendor
  description: The vendor used to calculate the score.
  type: string
- contextPath: DBotScore.Score
  description: The actual score.
  type: number
- contextPath: Joe.Analysis.WebID
  description: The Joe Analysis-related web ID.
  type: string
- contextPath: Joe.Analysis.Status
  description: The Joe Analysis-related status.
  type: string
- contextPath: Joe.Analysis.Comments
  description: The Joe Analysis-related comments.
  type: string
- contextPath: Joe.Analysis.Time
  description: The Joe Analysis-related submitted time.
  type: date
- contextPath: Joe.Analysis.Runs
  description: The Joe Analysis-related sub-analysis information.
  type: string
- contextPath: Joe.Analysis.Result
  description: The Joe Analysis-related results.
  type: string
- contextPath: Joe.Analysis.Errors
  description: The Joe Analysis-related errors raised during sampling.
  type: string
- contextPath: Joe.Analysis.Systems
  description: The Joe Analysis-related operating systems.
  type: string
- contextPath: Joe.Analysis.MD5
  description: The MD5 hash of the Joe Analysis-related sample.
  type: string
- contextPath: Joe.Analysis.SHA1
  description: The SHA1 hash of the Joe Analysis-related sample.
  type: string
- contextPath: Joe.Analysis.SHA256
  description: The SHA256 hash of the Joe Analysis-related sample.
  type: string
- contextPath: Joe.Analysis.SampleName
  description: The Joe Analysis-related sample data name. Can be a file name or a URL.
  type: string
- contextPath: InfoFile.Name
  description: The file name.
  type: string
- contextPath: InfoFile.EntryID
  description: The EntryID of the sample.
  type: string
- contextPath: InfoFile.Size
  description: The file size.
  type: number
- contextPath: InfoFile.Type
  description: The file type, for example "PE".
  type: string
- contextPath: InfoFile.Info
  description: The file basic information.
  type: string
- contextPath: Sample.State
  description: The sample state.
  type: string
- contextPath: Sample.ID
  description: The sample ID.
  type: string
- contextPath: IP.Address
  description: The IP addresses relevant to the sample.
  type: string
- contextPath: InfoFile
  description: The report file's object.
  type: string
- contextPath: Cuckoo.Task.Category
  description: The Cuckoo-related task category.
- contextPath: Cuckoo.Task.Machine
  description: The Cuckoo-related task machine.
- contextPath: Cuckoo.Task.Errors
  description: The Cuckoo-related task errors.
- contextPath: Cuckoo.Task.Target
  description: The Cuckoo-related task target.
- contextPath: Cuckoo.Task.Package
  description: The Cuckoo-related task package.
- contextPath: Cuckoo.Task.SampleID
  description: The Cuckoo-related task sample ID.
- contextPath: Cuckoo.Task.Guest
  description: The Cuckoo-related task guest.
- contextPath: Cuckoo.Task.Custom
  description: The Cuckoo-related task custom values.
- contextPath: Cuckoo.Task.Owner
  description: The Cuckoo-related task owner.
- contextPath: Cuckoo.Task.Priority
  description: The Cuckoo-related task priority.
- contextPath: Cuckoo.Task.Platform
  description: The Cuckoo-related task platform.
- contextPath: Cuckoo.Task.Options
  description: The Cuckoo-related task options.
- contextPath: Cuckoo.Task.Status
  description: The Cuckoo-related task status.
- contextPath: Cuckoo.Task.EnforceTimeout
  description: Whether the Cuckoo-related task timeout is enforced.
- contextPath: Cuckoo.Task.Timeout
  description: The Cuckoo-related task timeout.
- contextPath: Cuckoo.Task.Memory
  description: The Cuckoo-related task memory.
- contextPath: Cuckoo.Task.Tags
  description: The Cuckoo-related task tags.
- contextPath: Cuckoo.Task.ID
  description: The Cuckoo-related task ID.
- contextPath: Cuckoo.Task.AddedOn
  description: The date the Cuckoo-related task was added.
- contextPath: Cuckoo.Task.CompletedOn
  description: The date the Cuckoo-related task was completed.
- contextPath: Cuckoo.Task.Score
  description: The reported Cuckoo-related task score.
- contextPath: Cuckoo.Task.Monitor
  description: The reported Cuckoo-related task monitor.
- contextPath: ANYRUN.Task.AnalysisDate
  description: The date and time the ANY.RUN analysis was executed.
  type: String
- contextPath: ANYRUN.Task.Behavior.Category
  description: The ANY.RUN behavior category.
  type: String
- contextPath: ANYRUN.Task.Behavior.Action
  description: The actions performed by an ANY.RUN behavior.
  type: String
- contextPath: ANYRUN.Task.Behavior.ThreatLevel
  description: The threat score associated with an ANY.RUN behavior.
  type: Number
- contextPath: ANYRUN.Task.Behavior.ProcessUUID
  description: The ANY.RUN unique ID of the process whose behaviors are profiled.
  type: String
- contextPath: ANYRUN.Task.Connection.Reputation
  description: The ANY.RUN connection reputation.
  type: String
- contextPath: ANYRUN.Task.Connection.ProcessUUID
  description: The ANY.RUN UUID of the process that created the connection.
  type: String
- contextPath: ANYRUN.Task.Connection.ASN
  description: The ANY.RUN connection autonomous system network.
  type: String
- contextPath: ANYRUN.Task.Connection.Country
  description: The ANY.RUN connection country.
  type: String
- contextPath: ANYRUN.Task.Connection.Protocol
  description: The ANY.RUN connection protocol.
  type: String
- contextPath: ANYRUN.Task.Connection.Port
  description: The ANY.RUN connection port number.
  type: Number
- contextPath: ANYRUN.Task.Connection.IP
  description: The ANY.RUN connection IP address.
  type: String
- contextPath: ANYRUN.Task.DnsRequest.Reputation
  description: The ANY.RUN process reputation of the DNS request.
  type: String
- contextPath: ANYRUN.Task.DnsRequest.IP
  description: The ANY.RUN IP addresses associated with a DNS request.
  type: string
- contextPath: ANYRUN.Task.DnsRequest.Domain
  description: The ANY.RUN domain resolution of a DNS request.
  type: String
- contextPath: ANYRUN.Task.Threat.ProcessUUID
  description: The unique ANY.RUN UUID of the process that originated the threat.
  type: String
- contextPath: ANYRUN.Task.Threat.Msg
  description: The ANY.RUN threat message.
  type: String
- contextPath: ANYRUN.Task.Threat.Class
  description: The ANY.RUN threat class.
  type: String
- contextPath: ANYRUN.Task.Threat.SrcPort
  description: The ANY.RUN port on which the threat originated.
  type: Number
- contextPath: ANYRUN.Task.Threat.DstPort
  description: The ANY.RUN threat destination port.
  type: Number
- contextPath: ANYRUN.Task.Threat.SrcIP
  description: The ANY.RUN source IP address where the threat originated.
  type: String
- contextPath: ANYRUN.Task.Threat.DstIP
  description: The ANY.RUN threat destination IP address.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.Reputation
  description: The ANY.RUN HTTP request reputation.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.Country
  description: The ANY.RUN HTTP request country.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.ProcessUUID
  description: The ANY.RUN UUID of the process making the HTTP request.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.Body
  description: The ANY.RUN HTTP request body parameters and details.
  type: string
- contextPath: ANYRUN.Task.HttpRequest.HttpCode
  description: The ANY.RUN HTTP request response code.
  type: Number
- contextPath: ANYRUN.Task.HttpRequest.Status
  description: The ANY.RUN status of the HTTP request.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.ProxyDetected
  description: Whether the ANY.RUN HTTP request was made through a proxy.
  type: Boolean
- contextPath: ANYRUN.Task.HttpRequest.Port
  description: The ANY.RUN HTTP request port.
  type: Number
- contextPath: ANYRUN.Task.HttpRequest.IP
  description: The ANY.RUN HTTP request IP address.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.URL
  description: The ANY.RUN HTTP request URL.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.Host
  description: The ANY.RUN HTTP request host.
  type: String
- contextPath: ANYRUN.Task.HttpRequest.Method
  description: The ANY.RUN HTTP request method type.
  type: String
- contextPath: ANYRUN.Task.FileInfo
  description: The ANY.RUN submitted file details.
  type: String
- contextPath: ANYRUN.Task.OS
  description: The ANY.RUN operating system of the sandbox in which the file was analyzed.
  type: String
- contextPath: ANYRUN.Task.ID
  description: The unique ANY.RUN task ID.
  type: String
- contextPath: ANYRUN.Task.MIME
  description: The ANY.RUN MIME of the file submitted for analysis.
  type: String
- contextPath: ANYRUN.Task.Verdict
  description: The ANY.RUN verdict for the maliciousness of the submitted file or URL.
  type: String
- contextPath: ANYRUN.Task.Process.FileName
  description: The ANY.RUN process file name.
  type: String
- contextPath: ANYRUN.Task.Process.PID
  description: The ANY.RUN process identification number.
  type: Number
- contextPath: ANYRUN.Task.Process.PPID
  description: The ANY.RUN process parent process identification number.
  type: Number
- contextPath: ANYRUN.Task.Process.ProcessUUID
  description: The unique ANY.RUN process UUID.
  type: String
- contextPath: ANYRUN.Task.Process.CMD
  description: The ANY.RUN process command.
  type: String
- contextPath: ANYRUN.Task.Process.Path
  description: The path of the executed ANY.RUN process command.
  type: String
- contextPath: ANYRUN.Task.Process.User
  description: The user who executed the ANY.RUN process command.
  type: String
- contextPath: ANYRUN.Task.Process.IntegrityLevel
  description: The ANY.RUN process integrity level.
  type: String
- contextPath: ANYRUN.Task.Process.ExitCode
  description: The ANY.RUN process exit code.
  type: Number
- contextPath: ANYRUN.Task.Process.MainProcess
  description: Whether the ANY.RUN process is the main process.
  type: Boolean
- contextPath: ANYRUN.Task.Process.Version.Company
  description: The company responsible for the executed ANY.RUN process program.
  type: String
- contextPath: ANYRUN.Task.Process.Version.Description
  description: The description of the ANY.RUN process program type.
  type: String
- contextPath: ANYRUN.Task.Process.Version.Version
  description: The version of the executed program.
  type: String
- contextPath: URL.Data
  description: The URL data.
  type: String
- contextPath: URL.Malicious.Vendor
  description: The vendor that decided the URL is malicious.
  type: String
- contextPath: URL.Malicious.Description
  description: The reason the vendor decided the URL is malicious.
  type: String
- contextPath: ANYRUN.Task.Status
  description: The task analysis status.
  type: String
- contextPath: FireEyeAX.Submissions.Key
  description: The submission key
- contextPath: FireEyeAX.Submissions.Severity
  description: The severity level of the file
- contextPath: FireEyeAX.Submissions.InfoLevel
  description: The info level of the report.
- contextPath: DBotScore.Score
  description: The actual score.
  type: unknown
- contextPath: DBotScore.Indicator
  description: The indicator that was tested.
  type: unknown
- contextPath: DBotScore.Vendor
  description: The vendor used to calculate the score.
  type: unknown
- contextPath: Triage.sample-summaries.completed
  description: The date the sample analysis was completed.
- contextPath: Triage.sample-summaries.created
  description: The date the analysis report was created.
- contextPath: Triage.sample-summaries.custom
  description: The custom sample analysis.
- contextPath: Triage.sample-summaries.owner
  description: The owner of the sample summaries.
  type: unknown
- contextPath: Triage.sample-summaries.sample
  description: The unique identifier of the sample.
  type: unknown
- contextPath: Triage.sample-summaries.score
  description: The score of the sample on a scale of 0 to 10.
  type: unknown
- contextPath: Triage.sample-summaries.sha256
  description: The SHA256 of the sample.
  type: unknown
- contextPath: Triage.sample-summaries.status
  description: The status of the analysis.
  type: unknown
- contextPath: Triage.sample-summaries.target
  description: The target for the analysis.
  type: unknown
- contextPath: Triage.sample-summaries.tasks
  description: The tasks performed in the analysis.
  type: unknown
- contextPath: HybridAnalysis.URL.Scanner.Name
  description: The URL scanner name.
- contextPath: HybridAnalysis.URL.Scanner.Positives
  description: The number of positive scanners.
- contextPath: HybridAnalysis.URL.Scanner.Status
  description: The status of the scanning.
- contextPath: HybridAnalysis.URL.Scanner
  description: The place holder for the scanner data.
  type: unknown
- contextPath: SecneurXAnalysis.Report.SHA256
  description: SHA256 value of the analyzed sample
  type: string
- contextPath: SecneurXAnalysis.Report.Verdict
  description: Summary result of the analyzed sample
  type: string
- contextPath: SecneurXAnalysis.Report.Tags
  description: More details of the analyzed sample
  type: string
- contextPath: SecneurXAnalysis.Report.IOC
  description: List of IOC's observed in the analyzed sample
  type: string
- contextPath: SecneurXAnalysis.Report.Status
  description: Analysis queued sample state
  type: String
fromversion: 5.0.0
tests:
- No tests (auto formatted)
contentitemexportablefields:
  contentitemfields: {}