Detonate URL - Generic Deprecated

Deprecated. Use Detonate URL - Generic v1.5 playbook instead. Detonate URL through active integrations that support URL detonation.

Common Playbooks · 21 tasks · 1 input · 138 outputs

Details

IDdetonate_url_-_generic
From Version5.0.0
Tasks21

README

Detonate URL through active integrations that support URL detonation.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Detonate URL - JoeSecurity
  • Detonate URL - Hybrid Analysis
  • Detonate URL - Lastline v2
  • Detonate URL - ThreatGrid
  • Detonate URL - WildFire v2.1
  • Detonate URL - McAfee ATD
  • Detonate URL - ANYRUN
  • Detonate URL - Group-IB TDS Polygon
  • Detonate URL - CrowdStrike Falcon Intelligence Sandbox
  • Detonate URL - VirusTotal (API v3)
  • Detonate URL - Hatching Triage
  • Detonate URL - FireEye AX
  • Detonate URL - Cuckoo
  • Detonate URL - SecneurX Analysis
  • Detonate URL - VMRay
  • Detonate URL - ThreatStream

Integrations

  • CrowdStrike Falcon Sandbox V2
  • OPSWAT Filescan

Scripts

This playbook does not use any scripts.

Commands

  • cs-falcon-sandbox-submit-url
  • opswat-filescan-scan-url

Playbook Inputs


Name Description Default Value Required
URL The URL object of the URL to be detonated. URL Optional

Playbook Outputs


Path Description Type
File The file’s object. string
File.Name The file name. string
File.Size The file size. number
File.Type The file type, for example “PE” (only for report type=json). string
File.SHA256 The SHA256 hash of the file. string
File.SHA1 The SHA1 hash of the file. string
File.MD5 The MD5 hash of the file. string
File.Malicious.Vendor The vendor that decided the file is malicious. string
File.Malicious.Description The reason the vendor decided the file is malicious. string
DBotScore The indicator’s object. string
DBotScore.Type The indicator type. string
DBotScore.Indicator The indicator that was tested. string
DBotScore.Vendor The vendor used to calculate the score. string
DBotScore.Score The actual score. number
Joe.Analysis.WebID The Joe Analysis-related web ID. string
Joe.Analysis.Status The Joe Analysis-related status. string
Joe.Analysis.Comments The Joe Analysis-related comments. string
Joe.Analysis.Time The Joe Analysis-related submitted time. date
Joe.Analysis.Runs The Joe Analysis-related sub-analysis information. string
Joe.Analysis.Result The Joe Analysis-related results. string
Joe.Analysis.Errors The Joe Analysis-related errors raised during sampling. string
Joe.Analysis.Systems The Joe Analysis-related operating systems. string
Joe.Analysis.MD5 The MD5 hash of the Joe Analysis-related sample. string
Joe.Analysis.SHA1 The SHA1 hash of the Joe Analysis-related sample. string
Joe.Analysis.SHA256 The SHA256 hash of the Joe Analysis-related sample. string
Joe.Analysis.SampleName The Joe Analysis-related sample data name. Can be a file name or a URL. string
InfoFile.Name The file name. string
InfoFile.EntryID The EntryID of the sample. string
InfoFile.Size The file size. number
InfoFile.Type The file type, for example “PE”. string
InfoFile.Info The file basic information. string
Sample.State The sample state. string
Sample.ID The sample ID. string
IP.Address The IP addresses relevant to the sample. string
InfoFile The report file’s object. string
Cuckoo.Task.Category The Cuckoo-related task category. unknown
Cuckoo.Task.Machine The Cuckoo-related task machine. unknown
Cuckoo.Task.Errors The Cuckoo-related task errors. unknown
Cuckoo.Task.Target The Cuckoo-related task target. unknown
Cuckoo.Task.Package The Cuckoo-related task package. unknown
Cuckoo.Task.SampleID The Cuckoo-related task sample ID. unknown
Cuckoo.Task.Guest The Cuckoo-related task guest. unknown
Cuckoo.Task.Custom The Cuckoo-related task custom values. unknown
Cuckoo.Task.Owner The Cuckoo-related task owner. unknown
Cuckoo.Task.Priority The Cuckoo-related task priority. unknown
Cuckoo.Task.Platform The Cuckoo-related task platform. unknown
Cuckoo.Task.Options The Cuckoo-related task options. unknown
Cuckoo.Task.Status The Cuckoo-related task status. unknown
Cuckoo.Task.EnforceTimeout Whether the Cuckoo-related task timeout is enforced. unknown
Cuckoo.Task.Timeout The Cuckoo-related task timeout. unknown
Cuckoo.Task.Memory The Cuckoo-related task memory. unknown
Cuckoo.Task.Tags The Cuckoo-related task tags. unknown
Cuckoo.Task.ID The Cuckoo-related task ID. unknown
Cuckoo.Task.AddedOn The date the Cuckoo-related task was added. unknown
Cuckoo.Task.CompletedOn The date the Cuckoo-related task was completed. unknown
Cuckoo.Task.Score The reported Cuckoo-related task score. unknown
Cuckoo.Task.Monitor The reported Cuckoo-related task monitor. unknown
ANYRUN.Task.AnalysisDate The date and time the ANY.RUN analysis was executed. String
ANYRUN.Task.Behavior.Category The ANY.RUN behavior category. String
ANYRUN.Task.Behavior.Action The actions performed by an ANY.RUN behavior. String
ANYRUN.Task.Behavior.ThreatLevel The threat score associated with an ANY.RUN behavior. Number
ANYRUN.Task.Behavior.ProcessUUID The ANY.RUN unique ID of the process whose behaviors are profiled. String
ANYRUN.Task.Connection.Reputation The ANY.RUN connection reputation. String
ANYRUN.Task.Connection.ProcessUUID The ANY.RUN UUID of the process that created the connection. String
ANYRUN.Task.Connection.ASN The ANY.RUN connection autonomous system network. String
ANYRUN.Task.Connection.Country The ANY.RUN connection country. String
ANYRUN.Task.Connection.Protocol The ANY.RUN connection protocol. String
ANYRUN.Task.Connection.Port The ANY.RUN connection port number. Number
ANYRUN.Task.Connection.IP The ANY.RUN connection IP address. String
ANYRUN.Task.DnsRequest.Reputation The ANY.RUN process reputation of the DNS request. String
ANYRUN.Task.DnsRequest.IP The ANY.RUN IP addresses associated with a DNS request. string
ANYRUN.Task.DnsRequest.Domain The ANY.RUN domain resolution of a DNS request. String
ANYRUN.Task.Threat.ProcessUUID The unique ANY.RUN UUID of the process that originated the threat. String
ANYRUN.Task.Threat.Msg The ANY.RUN threat message. String
ANYRUN.Task.Threat.Class The ANY.RUN threat class. String
ANYRUN.Task.Threat.SrcPort The ANY.RUN port on which the threat originated. Number
ANYRUN.Task.Threat.DstPort The ANY.RUN threat destination port. Number
ANYRUN.Task.Threat.SrcIP The ANY.RUN source IP address where the threat originated. String
ANYRUN.Task.Threat.DstIP The ANY.RUN threat destination IP address. String
ANYRUN.Task.HttpRequest.Reputation The ANY.RUN HTTP request reputation. String
ANYRUN.Task.HttpRequest.Country The ANY.RUN HTTP request country. String
ANYRUN.Task.HttpRequest.ProcessUUID The ANY.RUN UUID of the process making the HTTP request. String
ANYRUN.Task.HttpRequest.Body The ANY.RUN HTTP request body parameters and details. string
ANYRUN.Task.HttpRequest.HttpCode The ANY.RUN HTTP request response code. Number
ANYRUN.Task.HttpRequest.Status The ANY.RUN status of the HTTP request. String
ANYRUN.Task.HttpRequest.ProxyDetected Whether the ANY.RUN HTTP request was made through a proxy. Boolean
ANYRUN.Task.HttpRequest.Port The ANY.RUN HTTP request port. Number
ANYRUN.Task.HttpRequest.IP The ANY.RUN HTTP request IP address. String
ANYRUN.Task.HttpRequest.URL The ANY.RUN HTTP request URL. String
ANYRUN.Task.HttpRequest.Host The ANY.RUN HTTP request host. String
ANYRUN.Task.HttpRequest.Method The ANY.RUN HTTP request method type. String
ANYRUN.Task.FileInfo The ANY.RUN submitted file details. String
ANYRUN.Task.OS The ANY.RUN operating system of the sandbox in which the file was analyzed. String
ANYRUN.Task.ID The unique ANY.RUN task ID. String
ANYRUN.Task.MIME The ANY.RUN MIME of the file submitted for analysis. String
ANYRUN.Task.Verdict The ANY.RUN verdict for the maliciousness of the submitted file or URL. String
ANYRUN.Task.Process.FileName The ANY.RUN process file name. String
ANYRUN.Task.Process.PID The ANY.RUN process identification number. Number
ANYRUN.Task.Process.PPID The ANY.RUN process parent process identification number. Number
ANYRUN.Task.Process.ProcessUUID The unique ANY.RUN process UUID. String
ANYRUN.Task.Process.CMD The ANY.RUN process command. String
ANYRUN.Task.Process.Path The path of the executed ANY.RUN process command. String
ANYRUN.Task.Process.User The user who executed the ANY.RUN process command. String
ANYRUN.Task.Process.IntegrityLevel The ANY.RUN process integrity level. String
ANYRUN.Task.Process.ExitCode The ANY.RUN process exit code. Number
ANYRUN.Task.Process.MainProcess Whether the ANY.RUN process is the main process. Boolean
ANYRUN.Task.Process.Version.Company The company responsible for the executed ANY.RUN process program. String
ANYRUN.Task.Process.Version.Description The description of the ANY.RUN process program type. String
ANYRUN.Task.Process.Version.Version The version of the executed program. String
URL.Data The URL data. String
URL.Malicious.Vendor The vendor that decided the URL is malicious. String
URL.Malicious.Description The reason the vendor decided the URL is malicious. String
ANYRUN.Task.Status The task analysis status. String
FireEyeAX.Submissions.Key The submission key unknown
FireEyeAX.Submissions.Severity The severity level of the file unknown
FireEyeAX.Submissions.InfoLevel The info level of the report. unknown
DBotScore.Score The actual score. unknown
DBotScore.Indicator The indicator that was tested. unknown
DBotScore.Vendor The vendor used to calculate the score. unknown
Triage.sample-summaries.completed The date the sample analysis was completed. unknown
Triage.sample-summaries.created The date the analysis report was created. unknown
Triage.sample-summaries.custom The custom sample analysis. unknown
Triage.sample-summaries.owner The owner of the sample summaries. unknown
Triage.sample-summaries.sample The unique identifier of the sample. unknown
Triage.sample-summaries.score The score of the sample on a scale of 0 to 10. unknown
Triage.sample-summaries.sha256 The SHA256 of the sample. unknown
Triage.sample-summaries.status The status of the analysis. unknown
Triage.sample-summaries.target The target for the analysis. unknown
Triage.sample-summaries.tasks The tasks performed in the analysis. unknown
HybridAnalysis.URL.Scanner.Name The URL scanner name. unknown
HybridAnalysis.URL.Scanner.Positives The number of positive scanners. unknown
HybridAnalysis.URL.Scanner.Status The status of the scanning. unknown
HybridAnalysis.URL.Scanner The place holder for the scanner data. unknown
SecneurXAnalysis.Report.SHA256 SHA256 value of the analyzed sample string
SecneurXAnalysis.Report.Verdict Summary result of the analyzed sample string
SecneurXAnalysis.Report.Tags More details of the analyzed sample string
SecneurXAnalysis.Report.IOC List of IOC’s observed in the analyzed sample string
SecneurXAnalysis.Report.Status Analysis queued sample state String

Playbook Image


Detonate URL - Generic

Inputs

  • URL — The URL object of the URL to be detonated.

Outputs

  • File — The file's object.
  • File.Name — The file name.
  • File.Size — The file size.
  • File.Type — The file type, for example "PE" (only for report type=json).
  • File.SHA256 — The SHA256 hash of the file.
  • File.SHA1 — The SHA1 hash of the file.
  • File.MD5 — The MD5 hash of the file.
  • File.Malicious.Vendor — The vendor that decided the file is malicious.
  • File.Malicious.Description — The reason the vendor decided the file is malicious.
  • DBotScore — The indicator's object.
  • DBotScore.Type — The indicator type.
  • DBotScore.Indicator — The indicator that was tested.
  • DBotScore.Vendor — The vendor used to calculate the score.
  • DBotScore.Score — The actual score.
  • Joe.Analysis.WebID — The Joe Analysis-related web ID.
  • Joe.Analysis.Status — The Joe Analysis-related status.
  • Joe.Analysis.Comments — The Joe Analysis-related comments.
  • Joe.Analysis.Time — The Joe Analysis-related submitted time.
  • Joe.Analysis.Runs — The Joe Analysis-related sub-analysis information.
  • Joe.Analysis.Result — The Joe Analysis-related results.
  • Joe.Analysis.Errors — The Joe Analysis-related errors raised during sampling.
  • Joe.Analysis.Systems — The Joe Analysis-related operating systems.
  • Joe.Analysis.MD5 — The MD5 hash of the Joe Analysis-related sample.
  • Joe.Analysis.SHA1 — The SHA1 hash of the Joe Analysis-related sample.
  • Joe.Analysis.SHA256 — The SHA256 hash of the Joe Analysis-related sample.
  • Joe.Analysis.SampleName — The Joe Analysis-related sample data name. Can be a file name or a URL.
  • InfoFile.Name — The file name.
  • InfoFile.EntryID — The EntryID of the sample.
  • InfoFile.Size — The file size.
  • InfoFile.Type — The file type, for example "PE".
  • InfoFile.Info — The file basic information.
  • Sample.State — The sample state.
  • Sample.ID — The sample ID.
  • IP.Address — The IP addresses relevant to the sample.
  • InfoFile — The report file's object.
  • Cuckoo.Task.Category — The Cuckoo-related task category.
  • Cuckoo.Task.Machine — The Cuckoo-related task machine.
  • Cuckoo.Task.Errors — The Cuckoo-related task errors.
  • Cuckoo.Task.Target — The Cuckoo-related task target.
  • Cuckoo.Task.Package — The Cuckoo-related task package.
  • Cuckoo.Task.SampleID — The Cuckoo-related task sample ID.
  • Cuckoo.Task.Guest — The Cuckoo-related task guest.
  • Cuckoo.Task.Custom — The Cuckoo-related task custom values.
  • Cuckoo.Task.Owner — The Cuckoo-related task owner.
  • Cuckoo.Task.Priority — The Cuckoo-related task priority.
  • Cuckoo.Task.Platform — The Cuckoo-related task platform.
  • Cuckoo.Task.Options — The Cuckoo-related task options.
  • Cuckoo.Task.Status — The Cuckoo-related task status.
  • Cuckoo.Task.EnforceTimeout — Whether the Cuckoo-related task timeout is enforced.
  • Cuckoo.Task.Timeout — The Cuckoo-related task timeout.
  • Cuckoo.Task.Memory — The Cuckoo-related task memory.
  • Cuckoo.Task.Tags — The Cuckoo-related task tags.
  • Cuckoo.Task.ID — The Cuckoo-related task ID.
  • Cuckoo.Task.AddedOn — The date the Cuckoo-related task was added.
  • Cuckoo.Task.CompletedOn — The date the Cuckoo-related task was completed.
  • Cuckoo.Task.Score — The reported Cuckoo-related task score.
  • Cuckoo.Task.Monitor — The reported Cuckoo-related task monitor.
  • ANYRUN.Task.AnalysisDate — The date and time the ANY.RUN analysis was executed.
  • ANYRUN.Task.Behavior.Category — The ANY.RUN behavior category.
  • ANYRUN.Task.Behavior.Action — The actions performed by an ANY.RUN behavior.
  • ANYRUN.Task.Behavior.ThreatLevel — The threat score associated with an ANY.RUN behavior.
  • ANYRUN.Task.Behavior.ProcessUUID — The ANY.RUN unique ID of the process whose behaviors are profiled.
  • ANYRUN.Task.Connection.Reputation — The ANY.RUN connection reputation.
  • ANYRUN.Task.Connection.ProcessUUID — The ANY.RUN UUID of the process that created the connection.
  • ANYRUN.Task.Connection.ASN — The ANY.RUN connection autonomous system network.
  • ANYRUN.Task.Connection.Country — The ANY.RUN connection country.
  • ANYRUN.Task.Connection.Protocol — The ANY.RUN connection protocol.
  • ANYRUN.Task.Connection.Port — The ANY.RUN connection port number.
  • ANYRUN.Task.Connection.IP — The ANY.RUN connection IP address.
  • ANYRUN.Task.DnsRequest.Reputation — The ANY.RUN process reputation of the DNS request.
  • ANYRUN.Task.DnsRequest.IP — The ANY.RUN IP addresses associated with a DNS request.
  • ANYRUN.Task.DnsRequest.Domain — The ANY.RUN domain resolution of a DNS request.
  • ANYRUN.Task.Threat.ProcessUUID — The unique ANY.RUN UUID of the process that originated the threat.
  • ANYRUN.Task.Threat.Msg — The ANY.RUN threat message.
  • ANYRUN.Task.Threat.Class — The ANY.RUN threat class.
  • ANYRUN.Task.Threat.SrcPort — The ANY.RUN port on which the threat originated.
  • ANYRUN.Task.Threat.DstPort — The ANY.RUN threat destination port.
  • ANYRUN.Task.Threat.SrcIP — The ANY.RUN source IP address where the threat originated.
  • ANYRUN.Task.Threat.DstIP — The ANY.RUN threat destination IP address.
  • ANYRUN.Task.HttpRequest.Reputation — The ANY.RUN HTTP request reputation.
  • ANYRUN.Task.HttpRequest.Country — The ANY.RUN HTTP request country.
  • ANYRUN.Task.HttpRequest.ProcessUUID — The ANY.RUN UUID of the process making the HTTP request.
  • ANYRUN.Task.HttpRequest.Body — The ANY.RUN HTTP request body parameters and details.
  • ANYRUN.Task.HttpRequest.HttpCode — The ANY.RUN HTTP request response code.
  • ANYRUN.Task.HttpRequest.Status — The ANY.RUN status of the HTTP request.
  • ANYRUN.Task.HttpRequest.ProxyDetected — Whether the ANY.RUN HTTP request was made through a proxy.
  • ANYRUN.Task.HttpRequest.Port — The ANY.RUN HTTP request port.
  • ANYRUN.Task.HttpRequest.IP — The ANY.RUN HTTP request IP address.
  • ANYRUN.Task.HttpRequest.URL — The ANY.RUN HTTP request URL.
  • ANYRUN.Task.HttpRequest.Host — The ANY.RUN HTTP request host.
  • ANYRUN.Task.HttpRequest.Method — The ANY.RUN HTTP request method type.
  • ANYRUN.Task.FileInfo — The ANY.RUN submitted file details.
  • ANYRUN.Task.OS — The ANY.RUN operating system of the sandbox in which the file was analyzed.
  • ANYRUN.Task.ID — The unique ANY.RUN task ID.
  • ANYRUN.Task.MIME — The ANY.RUN MIME of the file submitted for analysis.
  • ANYRUN.Task.Verdict — The ANY.RUN verdict for the maliciousness of the submitted file or URL.
  • ANYRUN.Task.Process.FileName — The ANY.RUN process file name.
  • ANYRUN.Task.Process.PID — The ANY.RUN process identification number.
  • ANYRUN.Task.Process.PPID — The ANY.RUN process parent process identification number.
  • ANYRUN.Task.Process.ProcessUUID — The unique ANY.RUN process UUID.
  • ANYRUN.Task.Process.CMD — The ANY.RUN process command.
  • ANYRUN.Task.Process.Path — The path of the executed ANY.RUN process command.
  • ANYRUN.Task.Process.User — The user who executed the ANY.RUN process command.
  • ANYRUN.Task.Process.IntegrityLevel — The ANY.RUN process integrity level.
  • ANYRUN.Task.Process.ExitCode — The ANY.RUN process exit code.
  • ANYRUN.Task.Process.MainProcess — Whether the ANY.RUN process is the main process.
  • ANYRUN.Task.Process.Version.Company — The company responsible for the executed ANY.RUN process program.
  • ANYRUN.Task.Process.Version.Description — The description of the ANY.RUN process program type.
  • ANYRUN.Task.Process.Version.Version — The version of the executed program.
  • URL.Data — The URL data.
  • URL.Malicious.Vendor — The vendor that decided the URL is malicious.
  • URL.Malicious.Description — The reason the vendor decided the URL is malicious.
  • ANYRUN.Task.Status — The task analysis status.
  • FireEyeAX.Submissions.Key — The submission key
  • FireEyeAX.Submissions.Severity — The severity level of the file
  • FireEyeAX.Submissions.InfoLevel — The info level of the report.
  • DBotScore.Score — The actual score.
  • DBotScore.Indicator — The indicator that was tested.
  • DBotScore.Vendor — The vendor used to calculate the score.
  • Triage.sample-summaries.completed — The date the sample analysis was completed.
  • Triage.sample-summaries.created — The date the analysis report was created.
  • Triage.sample-summaries.custom — The custom sample analysis.
  • Triage.sample-summaries.owner — The owner of the sample summaries.
  • Triage.sample-summaries.sample — The unique identifier of the sample.
  • Triage.sample-summaries.score — The score of the sample on a scale of 0 to 10.
  • Triage.sample-summaries.sha256 — The SHA256 of the sample.
  • Triage.sample-summaries.status — The status of the analysis.
  • Triage.sample-summaries.target — The target for the analysis.
  • Triage.sample-summaries.tasks — The tasks performed in the analysis.
  • HybridAnalysis.URL.Scanner.Name — The URL scanner name.
  • HybridAnalysis.URL.Scanner.Positives — The number of positive scanners.
  • HybridAnalysis.URL.Scanner.Status — The status of the scanning.
  • HybridAnalysis.URL.Scanner — The place holder for the scanner data.
  • SecneurXAnalysis.Report.SHA256 — SHA256 value of the analyzed sample
  • SecneurXAnalysis.Report.Verdict — Summary result of the analyzed sample
  • SecneurXAnalysis.Report.Tags — More details of the analyzed sample
  • SecneurXAnalysis.Report.IOC — List of IOC's observed in the analyzed sample
  • SecneurXAnalysis.Report.Status — Analysis queued sample state

Commands used

cs-falcon-sandbox-submit-url

Flowchart

yes Start Start Done Done Detonate URL - ThreatGrid - Detonate URL - ThreatGrid Detonate URL - ThreatGrid Detonate URL - ThreatGrid Detonate URL - McAfee ATD - Detonate URL - McAfee ATD Detonate URL - McAfee ATD Detonate URL - McAfee ATD Detonate URL - JoeSecurity - Detonate URL - JoeSecurity Detonate URL - JoeSecurity Detonate URL - JoeSecurity Detonate URL - Lastline v2 - Detonate URL - Lastline v2 Detonate URL - Lastline v2 Detonate URL - Lastline v2 Detonate URL - Cuckoo - Detonate URL - Cuckoo Detonate URL - Cuckoo Detonate URL - Cuckoo Detonate URL - ANYRUN - Detonate URL - ANYRUN Detonate URL - ANYRUN Detonate URL - ANYRUN Detonate URL - Group-IB TDS Polygon - Detonate URL - Group-IB TDS Polygon Detonate URL - Group-IB T... Detonate URL - Group-IB TDS P... Detonate URL - CrowdStrike Falcon Intelligence Sandbox - cs-falcon-sandbox-submit-url Detonate URL - CrowdStrik... cs-falcon-sandbox-submit-url Detonate URL - WildFire v2.1 - Detonate URL - WildFire v2.1 Detonate URL - WildFire v2.1 Detonate URL - WildFire v2.1 Detonate URL - VirusTotal (API v3) - Detonate URL - VirusTotal (API v3) Detonate URL - VirusTotal... Detonate URL - VirusTotal (AP... Detonate URL - VMRay - Detonate URL - VMRay Detonate URL - VMRay Detonate URL - VMRay Detonate URL - ThreatStream - Detonate URL - ThreatStream Detonate URL - ThreatStream Detonate URL - ThreatStream Detonate URL - Hybrid Analysis - Detonate URL - Hybrid Analysis Detonate URL - Hybrid Ana... Detonate URL - Hybrid Analysis Detonate URL - FireEye AX - Detonate URL - FireEye AX Detonate URL - FireEye AX Detonate URL - FireEye AX Detonate URL - Hatching Triage - Detonate URL - Hatching Triage Detonate URL - Hatching T... Detonate URL - Hatching Triage Detonate URL - SecneurX Analysis - Detonate URL - SecneurX Analysis Detonate URL - SecneurX A... Detonate URL - SecneurX Analysis Detonate URL - CrowdStrike Falcon Intelligence Sandbox - Detonate URL - CrowdStrike Falcon Intelligence Sandbox Detonate URL - CrowdStrik... Detonate URL - CrowdStrike Fa... Check if URL exists Check if URL exists Detonate URL - MetaDefender Sandbox Detonate URL - MetaDefend...
id: Detonate URL - Generic v1.5
version: -1
contentitemexportablefields:
  contentitemfields: {}
name: Detonate URL - Generic v1.5
description: |-
  Detonate URL through one or more active integrations that support URL detonation.
  Supported integrations:
  - SecneurX Analysis
  - ANY.RUN Cloud Sandbox
  - McAfee Advanced Threat Defense
  - WildFire
  - Lastline
  - Cuckoo Sandbox
  - Cisco Secure Malware Analytics (ThreatGrid)
  - JoeSecurity
  - CrowdStrike Falcon Sandbox
  - FireEye AX
  - VMRay Analyzer
  - Polygon
  - CrowdStrike Falcon Intelligence Sandbox
  - OPSWAT Filescan
  - VirusTotal
  - Anomali ThreatStream
  - Hatching Triage
  - ThreatGrid 
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 649023ff-9594-4e23-8799-143e96e8650d
    type: start
    task:
      id: 649023ff-9594-4e23-8799-143e96e8650d
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3060,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 7631e811-c7ae-4c2b-895b-793922894b45
    type: condition
    task:
      id: 7631e811-c7ae-4c2b-895b-793922894b45
      version: -1
      name: Check if URL exists
      description: Checks if there is a URL to detonate.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "20"
      "yes":
      - "22"
      - "12"
      - "13"
      - "14"
      - "15"
      - "16"
      - "17"
      - "21"
      - "19"
      - "9"
      - "7"
      - "6"
      - "4"
      - "23"
      - "24"
      - "25"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.URL
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3060,
          "y": 210
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: f880c851-c874-4f45-8e30-a31dcd6bd034
    type: playbook
    task:
      id: f880c851-c874-4f45-8e30-a31dcd6bd034
      version: -1
      name: Detonate URL - McAfee ATD
      description: Detonates a URL using the McAfee Advanced Threat Defense sandbox integration.
      playbookName: Detonate URL - McAfee ATD
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Interval:
        simple: "1"
      Timeout:
        simple: "15"
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 50,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: 20b9f2f5-0bf3-4990-8035-75e2ee5576f7
    type: playbook
    task:
      id: 20b9f2f5-0bf3-4990-8035-75e2ee5576f7
      version: -1
      name: Detonate URL - Lastline v2
      description: Detonates a URL using the Lastline sandbox integration.
      playbookName: Detonate URL - Lastline v2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Interval:
        simple: "1"
      Timeout:
        simple: "15"
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 480,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: 36274297-5bc4-4f17-8f71-eace307e6ffd
    type: playbook
    task:
      id: 36274297-5bc4-4f17-8f71-eace307e6ffd
      version: -1
      name: Detonate URL - Cuckoo
      description: Detonate a URL with Cuckoo.
      playbookName: Detonate URL - Cuckoo
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
      interval:
        simple: "1"
      timeout:
        simple: "10"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 910,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: e96e1ea1-83b9-45e7-8838-4417978b24d5
    type: playbook
    task:
      id: e96e1ea1-83b9-45e7-8838-4417978b24d5
      version: -1
      name: Detonate URL - Group-IB TDS Polygon
      description: Detonate URL using Group-IB THF Polygon integration.
      playbookName: Detonate URL - Group-IB TDS Polygon
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Interval:
        simple: "1"
      Timeout:
        simple: "60"
      url:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1340,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: 3868d472-e5f4-4714-8c58-5c8f95d6b626
    type: playbook
    task:
      id: 3868d472-e5f4-4714-8c58-5c8f95d6b626
      version: -1
      name: Detonate URL - VirusTotal (API v3)
      description: Detonate URL through VirusTotal (API v3) integration.
      playbookName: Detonate URL - VirusTotal (API v3)
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1770,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: bf8eaa1a-576f-4ab3-89b7-e383180a536c
    type: playbook
    task:
      id: bf8eaa1a-576f-4ab3-89b7-e383180a536c
      version: -1
      name: Detonate URL - VMRay
      description: Detonates a URL using the VMRay sandbox integration.
      playbookName: Detonate URL - VMRay
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
      interval:
        simple: "1"
      timeout:
        simple: "10"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 2200,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "14":
    id: "14"
    taskid: d1eb756a-f615-40b1-80fe-88179b28a4ac
    type: playbook
    task:
      id: d1eb756a-f615-40b1-80fe-88179b28a4ac
      version: -1
      name: Detonate URL - ThreatStream
      description: |-
        Detonates one or more URLs using the Anomali ThreatStream v2 sandbox integration.
        Returns relevant reports to the War Room and URL reputations to the context data.
      playbookName: Detonate URL - ThreatStream
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Interval:
        simple: "5"
      Timeout:
        simple: "120"
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 2630,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "15":
    id: "15"
    taskid: aaaae5ac-95e9-4542-81c2-a3f634f13437
    type: playbook
    task:
      id: aaaae5ac-95e9-4542-81c2-a3f634f13437
      version: -1
      name: Detonate URL - FireEye AX
      description: Detonates a URL with FireEye AX.
      playbookName: Detonate URL - FireEye AX
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
      interval:
        simple: "1"
      timeout:
        simple: "30"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 3060,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "16":
    id: "16"
    taskid: bd03837d-6714-4e64-8afb-99aa81aeb6b5
    type: playbook
    task:
      id: bd03837d-6714-4e64-8afb-99aa81aeb6b5
      version: -1
      name: Detonate URL - Hatching Triage
      description: Detonates a URL with Hatching Triage.
      playbookName: Detonate URL - Hatching Triage
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
      interval:
        simple: "1"
      timeout:
        simple: "10"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 3490,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 8139a6d0-05e9-4633-8c60-b840a51c7e11
    type: playbook
    task:
      id: 8139a6d0-05e9-4633-8c60-b840a51c7e11
      version: -1
      name: Detonate URL - SecneurX Analysis
      description: Detonates a URL using the SecneurX Analysis integration. Returns relevant reports to the War Room and file reputations to the context data.
      playbookName: Detonate URL - SecneurX Analysis
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Duration:
        simple: "120"
      Interval:
        simple: "1"
      Priority:
        simple: High
      Reboot:
        simple: "False"
      ReportFormat:
        simple: json
      Timeout:
        simple: "15"
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 3920,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "19":
    id: "19"
    taskid: c54ae675-b7ba-48fb-8669-1a220aeacbed
    type: regular
    task:
      id: c54ae675-b7ba-48fb-8669-1a220aeacbed
      version: -1
      name: Detonate URL - OPSWAT
      description: Scan URL resource.
      script: '|||opswat-filescan-scan-url'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      url:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4350,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: d52344a0-57e4-45ea-8b33-1ad8c3b7484f
    type: title
    task:
      id: d52344a0-57e4-45ea-8b33-1ad8c3b7484f
      version: -1
      name: Done
      description: Done
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3705,
          "y": 890
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: 60bd5acb-bfa4-411c-89bb-c07a71574ebf
    type: playbook
    task:
      id: 60bd5acb-bfa4-411c-89bb-c07a71574ebf
      version: -1
      name: Detonate URL - CrowdStrike Falcon Intelligence Sandbox v2
      description: Detonate one or more URLs using the CrowdStrike Falcon Intelligence Sandbox integration. This playbook returns relevant reports to the War Room and file reputations to the context data.
      playbookName: Detonate URL - CrowdStrike Falcon Intelligence Sandbox v2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Full Report:
        simple: "True"
      Interval:
        simple: "1"
      Timeout:
        simple: "10"
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 4780,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: d2b682c2-7df5-4ebd-855a-8949333649fb
    type: playbook
    task:
      id: d2b682c2-7df5-4ebd-855a-8949333649fb
      version: -1
      name: Detonate URL - WildFire v2.2
      description: |-
        Detonate a webpage or remote file using the WildFire v2 integration. This playbook returns relevant reports to the War Room and file reputations to the context data.
        The detonation supports the following file types:
        APK, JAR, DOC, DOCX, RTF, OOXLS, XLSX, PPT, PPTX, XML, PE32, PDF, DMG, PKG, RAR, 7Z, JS.
      playbookName: Detonate URL - WildFire v2.2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      Interval:
        simple: "60"
      Timeout:
        simple: "600"
      URL:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 5210,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 156ee7d3-6235-4011-85fe-32e8d2154de1
    type: regular
    task:
      id: 156ee7d3-6235-4011-85fe-32e8d2154de1
      version: -1
      name: Detonate URL - JoeSecurity
      description: Submit a URL for sandbox analysis.
      script: '|||joe-submit-url'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      url:
        complex:
          root: inputs.URL
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 5640,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "24":
    id: "24"
    taskid: 79a510af-3640-415e-85bd-b9cf42ace798
    type: playbook
    task:
      id: 79a510af-3640-415e-85bd-b9cf42ace798
      version: -1
      name: Detonate URL - ThreatGrid v2
      playbookName: Detonate URL - ThreatGrid v2
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "20"
    separatecontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 6070,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "25":
    id: "25"
    taskid: df46af7d-b2ae-4a77-8fd9-901ff7e65a18
    type: condition
    task:
      id: df46af7d-b2ae-4a77-8fd9-901ff7e65a18
      version: -1
      name: Check the correctness of the ANY.RUN parameters
      description: Check the correctness of the ANY.RUN parameters
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "20"
      "yes":
      - "29"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              simple: inputs.anyrun_os
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 6622.5,
          "y": 380
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: 10486b13-661b-4d9e-89e2-8222ac5b53a9
    type: playbook
    task:
      id: 10486b13-661b-4d9e-89e2-8222ac5b53a9
      description: This playbook submits a URL extracted from an indicator to the ANY.RUN cloud sandbox for dynamic analysis in an Linux environment. It automates the analysis of potentially malicious URLs on Ubuntu OS.
      version: -1
      name: ANYRUN Detonate Url Linux
      playbookName: ANYRUN Detonate Url Linux
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    separatecontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 6520,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: cfadc723-4213-43ae-80ba-522a1a7fb2db
    type: playbook
    task:
      id: cfadc723-4213-43ae-80ba-522a1a7fb2db
      description: This playbook submits a URL extracted from an indicator to the ANY.RUN cloud sandbox for dynamic analysis in an Windows environment. It automates the analysis of potentially malicious URLs on Windows OS.
      version: -1
      name: ANYRUN Detonate Url Windows
      playbookName: ANYRUN Detonate Url Windows
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    separatecontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 6950,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "29":
    id: "29"
    taskid: bb167fe2-8643-4a93-9ee6-f9b7b52c5d50
    type: condition
    task:
      id: bb167fe2-8643-4a93-9ee6-f9b7b52c5d50
      version: -1
      name: Select ANY.RUN playbook
      description: Select ANY.RUN playbook
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      Android:
      - "30"
      Linux:
      - "27"
      Windows:
      - "28"
    separatecontext: false
    conditions:
    - label: Windows
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.anyrun_os
            iscontext: true
          right:
            value:
              simple: windows
    - label: Android
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.anyrun_os
            iscontext: true
          right:
            value:
              simple: android
    - label: Linux
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.anyrun_os
            iscontext: true
          right:
            value:
              simple: linux
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 6950,
          "y": 550
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "30":
    id: "30"
    taskid: adea056d-65aa-49f2-8e38-29a06b05bd03
    type: playbook
    task:
      id: adea056d-65aa-49f2-8e38-29a06b05bd03
      description: This playbook submits a URL extracted from an indicator to the ANY.RUN cloud sandbox for dynamic analysis in an Android environment. It automates the analysis of potentially malicious URLs on Android OS.
      version: -1
      name: ANYRUN Detonate Url Android
      playbookName: ANYRUN Detonate Url Android
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    separatecontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 7380,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
system: true
view: |-
  {
    "linkLabelsPosition": {
      "1_12_yes": 0.51,
      "1_13_yes": 0.71,
      "1_14_yes": 0.82,
      "1_15_yes": 0.86,
      "1_16_yes": 0.88,
      "1_17_yes": 0.9,
      "1_19_yes": 0.9,
      "1_21_yes": 0.9,
      "1_23_yes": 0.9,
      "1_24_yes": 0.9,
      "1_4_yes": 0.89,
      "1_6_yes": 0.84,
      "1_7_yes": 0.83,
      "1_9_yes": 0.57
    },
    "paper": {
      "dimensions": {
        "height": 900,
        "width": 7710,
        "x": 50,
        "y": 50
      }
    }
  }
inputs:
- key: URL
  value:
    complex:
      root: URL.Data
  required: false
  description: The URL object of the URL to be detonated.
  playbookInputQuery:
- key: anyrun_os
  value:
    simple: windows
  required: false
  description: 'Specify ANY.RUN operation system type. Supports: windows, linux, android'
  playbookInputQuery:
inputSections:
- inputs:
  - URL
  name: General (Inputs group)
  description: Generic group for inputs
- inputs:
  - anyrun_os
  name: ANY.RUN
  description: ANY.RUN group for inputs
outputs:
- contextPath: ThreatGrid.Sample.id
  description: The sample id.
  type: string
- contextPath: ThreatGrid.Sample.filename
  description: The sample filename.
  type: string
- contextPath: ThreatGrid.Sample.state
  description: The state of the sample, one of a stable set of strings "wait, prep, run, proc, succ, fail".
  type: string
- contextPath: ThreatGrid.Sample.status
  description: The sample status.
  type: string
- contextPath: ThreatGrid.Sample.md5
  description: The sample md5.
  type: string
- contextPath: ThreatGrid.Sample.sha1
  description: The sample sha1.
  type: string
- contextPath: ThreatGrid.Sample.sha256
  description: The sample sha256.
  type: string
- contextPath: ThreatGrid.Sample.os
  description: The sample os.
  type: string
- contextPath: ThreatGrid.Sample.submitted_at
  description: The sample submission time.
  type: string
- contextPath: ATD.Task.taskId
  description: The task ID of the sample uploaded.
  type: string
- contextPath: ATD.Task.jobId
  description: The job ID of the sample uploaded.
  type: string
- contextPath: ATD.Task.messageId
  description: The message Id relevant to the sample uploaded.
  type: string
- contextPath: ATD.Task.url
  description: The URL detonated.
  type: string
- contextPath: ATD.Task.srcIp
  description: Source IPv4 address.
  type: string
- contextPath: ATD.Task.destIp
  description: Destination IPv4 address.
  type: string
- contextPath: ATD.Task.MD5
  description: MD5 of the sample uploaded.
  type: string
- contextPath: ATD.Task.SHA1
  description: SHA1 of the sample uploaded.
  type: string
- contextPath: ATD.Task.SHA256
  description: SHA256 of the sample uploaded.
  type: string
- contextPath: File.Name
  description: Filename (only in case of report type=json).
  type: string
- contextPath: File.Type
  description: File type e.g. "PE" (only in case of report type=json).
  type: string
- contextPath: File.MD5
  description: MD5 hash of the file (only in case of report type=json).
  type: string
- contextPath: File.SHA1
  description: SHA1 hash of the file (only in case of report type=json).
  type: string
- contextPath: File.SHA256
  description: SHA256 hash of the file (only in case of report type=json).
  type: string
- contextPath: File.EntryID
  description: The Entry ID of the sample.
  type: string
- contextPath: File.Malicious
  description: File Malicious object.
  type: unknown
- contextPath: DBotScore.Indicator
  description: The indicator we tested (only in case of report type=json).
  type: string
- contextPath: DBotScore.Type
  description: The type of the indicator (only in case of report type=json).
  type: string
- contextPath: DBotScore.Vendor
  description: Vendor used to calculate the score (only in case of report type=json).
  type: string
- contextPath: DBotScore.Score
  description: The actual score (only in case of report type=json).
  type: number
- contextPath: IP.Address
  description: IP's relevant to the sample.
  type: string
- contextPath: InfoFile.EntryID
  description: The EntryID of the report file.
  type: string
- contextPath: InfoFile.Extension
  description: The extension of the report file.
  type: string
- contextPath: InfoFile.Name
  description: The name of the report file.
  type: string
- contextPath: InfoFile.Info
  description: The info of the report file.
  type: string
- contextPath: InfoFile.Size
  description: The size of the report file.
  type: number
- contextPath: InfoFile.Type
  description: The type of the report file.
  type: string
- contextPath: URL.Malicious
  description: URL Malicious object.
  type: string
- contextPath: DBotScore.Reliability
  description: The reliability of the source providing the intelligence data.
  type: string
- contextPath: URL.Data
  description: The URL.
  type: string
- contextPath: Joe.Analysis.AnalysisID
  description: The analysis ID.
  type: string
- contextPath: Joe.Analysis.Classification
  description: The classification.
  type: string
- contextPath: Joe.Analysis.Comments
  description: The comments.
  type: string
- contextPath: Joe.Analysis.detection
  description: The detection.
  type: string
- contextPath: Joe.Analysis.duration
  description: The duration.
  type: string
- contextPath: Joe.Analysis.encrypted
  description: True if the analysis data is encrypted.
  type: string
- contextPath: Joe.Analysis.filename
  description: The filename.
  type: string
- contextPath: Joe.Analysis.score
  description: The score.
  type: string
- contextPath: Joe.Analysis.scriptname
  description: The script name.
  type: string
- contextPath: Joe.Analysis.status
  description: The status.
  type: string
- contextPath: Joe.Analysis.threatname
  description: The threat name.
  type: string
- contextPath: Joe.Analysis.time
  description: The time.
  type: string
- contextPath: Joe.Analysis.webid
  description: The web ID.
  type: string
- contextPath: Joe.Analysis.runs.detection
  description: The detection.
  type: string
- contextPath: Joe.Analysis.runs.error
  description: The error.
  type: string
- contextPath: Joe.Analysis.runs.score
  description: The score.
  type: string
- contextPath: Joe.Analysis.runs.sigma
  description: The sigma.
  type: string
- contextPath: Joe.Analysis.runs.snort
  description: The snort.
  type: string
- contextPath: Joe.Analysis.runs.system
  description: The system.
  type: string
- contextPath: Joe.Analysis.runs.yara
  description: The YARA.
  type: string
- contextPath: Joe.Submission.most_relevant_analysis.detection
  description: The detection.
  type: string
- contextPath: Joe.Submission.most_relevant_analysis.score
  description: The submission score.
  type: string
- contextPath: Joe.Submission.most_relevant_analysis.webid
  description: The submission web ID.
  type: string
- contextPath: Joe.Submission.name
  description: The submission name.
  type: string
- contextPath: Joe.Submission.status
  description: The submission status.
  type: string
- contextPath: Joe.Submission.submission_id
  description: The submission ID.
  type: string
- contextPath: Joe.Submission.time
  description: The submission time.
  type: string
- contextPath: File.Size
  description: File size (only in case of report type=json).
  type: number
- contextPath: File.Malicious.Vendor
  description: The vendor that determined that a file is malicious.
  type: string
- contextPath: File.Malicious.Description
  description: The reason that the vendor determined that the file is malicious.
  type: string
- contextPath: File.Malicious.Score
  description: The score that the malicious file received from the vendor.
  type: number
- contextPath: URL.Malicious.Vendor
  description: The vendor that determined that a URL is malicious.
  type: string
- contextPath: URL.Malicious.Description
  description: The reason that the vendor determined that the URL is malicious.
  type: string
- contextPath: URL.Malicious.Score
  description: The score that the malicious URL received from the vendor.
  type: number
- contextPath: Lastline.Submission.Status
  description: Status of the submission.
  type: string
- contextPath: Lastline.Submission.DNSqueries
  description: List of DNS queries done by the analysis subject.
  type: string
- contextPath: Lastline.Submission.NetworkConnections
  description: List of network connections done by the analysis subject.
  type: string
- contextPath: Lastline.Submission.DownloadedFiles
  description: List of files that were downloaded using the Microsoft Windows file-download API functions. Each element is a tuple of file-origin URL and a File element.
  type: string
- contextPath: Lastline.Submission.UUID
  description: ID of the submission.
  type: string
- contextPath: Lastline.Submission.YaraSignatures.name
  description: Yara signatures name.
  type: string
- contextPath: Lastline.Submission.YaraSignatures.score
  description: The score according to the yara signatures. from 0 to 100.
  type: number
- contextPath: Lastline.Submission.YaraSignatures.internal
  description: True if the signature is only for internal use.
  type: boolean
- contextPath: Lastline.Submission.Process.arguments
  description: Argument of the process.
  type: string
- contextPath: Lastline.Submission.Process.process_id
  description: The process ID.
  type: string
- contextPath: Lastline.Submission.Process.executable.abs_path
  description: Absolute path of the executable of the process.
  type: string
- contextPath: Lastline.Submission.Process.executable.filename
  description: Filename of the executable.
  type: string
- contextPath: Lastline.Submission.Process.executable.yara_signature_hits
  description: Yara signature of the executable of the process.
  type: string
- contextPath: Cuckoo.Task.Category
  description: Category of task.
  type: string
- contextPath: Cuckoo.Task.Machine
  description: Machine of task.
  type: string
- contextPath: Cuckoo.Task.Errors
  description: Errors of task.
  type: string
- contextPath: Cuckoo.Task.Traget
  description: Traget of task.
  type: string
- contextPath: Cuckoo.Task.Package
  description: Package of task.
  type: string
- contextPath: Cuckoo.Task.SampleID
  description: Sample ID of task.
  type: string
- contextPath: Cuckoo.Task.Guest
  description: Task guest.
  type: string
- contextPath: Cuckoo.Task.Custom
  description: Custom values of task.
  type: string
- contextPath: Cuckoo.Task.Owner
  description: Task owner.
  type: string
- contextPath: Cuckoo.Task.Priority
  description: Priority of task.
  type: string
- contextPath: Cuckoo.Task.Platform
  description: Platform of task.
  type: string
- contextPath: Cuckoo.Task.Options
  description: Task options.
  type: string
- contextPath: Cuckoo.Task.Status
  description: Task status.
  type: string
- contextPath: Cuckoo.Task.EnforceTimeout
  description: Is timeout of task enforced.
  type: string
- contextPath: Cuckoo.Task.Timeout
  description: Task timeout.
  type: string
- contextPath: Cuckoo.Task.Memory
  description: Task memory.
  type: string
- contextPath: Cuckoo.Task.Tags
  description: Task tags.
  type: string
- contextPath: Cuckoo.Task.ID
  description: ID of task.
  type: string
- contextPath: Cuckoo.Task.AddedOn
  description: Date on which the task was added.
  type: string
- contextPath: Cuckoo.Task.CompletedOn
  description: Date on which the task was completed.
  type: string
- contextPath: Cuckoo.Task.Score
  description: Reported score of the the task.
  type: string
- contextPath: Cuckoo.Task.Monitor
  description: Monitor of the reported task.
  type: string
- contextPath: Domain.Name
  description: The Domain name.
  type: string
- contextPath: Domain.DNS
  description: A list of IP objects resolved by DNS.
  type: string
- contextPath: RegistryKey.Path
  description: The path to the registry key.
  type: string
- contextPath: RegistryKey.Value
  description: The value at the given RegistryKey.
  type: string
- contextPath: Process.Name
  description: Process name.
  type: string
- contextPath: Process.PID
  description: Process PID.
  type: number
- contextPath: Process.CommandLine
  description: Process Command Line.
  type: string
- contextPath: Process.Path
  description: Process path.
  type: string
- contextPath: Process.StartTime
  description: Process start time.
  type: date
- contextPath: Process.EndTime
  description: Process end time.
  type: date
- contextPath: Polygon.Analysis.ID
  description: Analysis ID in THF.
  type: number
- contextPath: Polygon.Analysis.Name
  description: File Name.
  type: string
- contextPath: Polygon.Analysis.Size
  description: File Size.
  type: number
- contextPath: Polygon.Analysis.Started
  description: Analysis start timestamp.
  type: date
- contextPath: Polygon.Analysis.Analyzed
  description: Analysis finish timestamp.
  type: date
- contextPath: Polygon.Analysis.MD5
  description: Analyzed file MD5 hash.
  type: string
- contextPath: Polygon.Analysis.SHA1
  description: Analyzed file SHA1 hash.
  type: string
- contextPath: Polygon.Analysis.SHA256
  description: Analyzed file SHA256.
  type: string
- contextPath: Polygon.Analysis.Result
  description: Analysis verdict.
  type: string
- contextPath: Polygon.Analysis.Status
  description: The analysis status.
  type: string
- contextPath: Polygon.Analysis.Verdict
  description: Analysis verdict.
  type: boolean
- contextPath: Polygon.Analysis.Probability
  description: Verdict probability.
  type: string
- contextPath: Polygon.Analysis.Families
  description: Malware families.
  type: string
- contextPath: Polygon.Analysis.Score
  description: Polygon score.
  type: number
- contextPath: Polygon.Analysis.Internet-connection
  description: Internet availability.
  type: string
- contextPath: Polygon.Analysis.Type
  description: File type.
  type: string
- contextPath: Polygon.Analysis.DumpExists
  description: Network activity dump exists.
  type: boolean
- contextPath: Polygon.Analysis.File
  description: The information about files in analysis.
  type: string
- contextPath: Polygon.Analysis.URL
  description: The information about URL indicators.
  type: string
- contextPath: Polygon.Analysis.IP
  description: The information about IP indicators.
  type: string
- contextPath: Polygon.Analysis.Domain
  description: The information about Domain indicators.
  type: string
- contextPath: Polygon.Analysis.RegistryKey
  description: The information about registry keys which were modified during the analysis.
  type: string
- contextPath: Polygon.Analysis.Process
  description: The information about processes started during the analysis.
  type: string
- contextPath: CrowdStrike.Submit.job_id
  description: The The submitted report job ID.
  type: string
- contextPath: CrowdStrike.Submit.submission_type
  description: The type of the submission.
  type: string
- contextPath: CrowdStrike.Submit.submission_id
  description: The submission ID.
  type: string
- contextPath: CrowdStrike.Submit.environment_id
  description: The submission environment ID.
  type: string
- contextPath: CrowdStrike.Submit.sha256
  description: The SHA256 hash of the file.
  type: string
- contextPath: CrowdStrike.Report.job_id
  description: The report job ID.
  type: string
- contextPath: CrowdStrike.Report.environment_id
  description: The report environment ID.
  type: string
- contextPath: CrowdStrike.Report.environment_description
  description: The environment description.
  type: string
- contextPath: CrowdStrike.Report.size
  description: The file size.
  type: string
- contextPath: CrowdStrike.Report.type
  description: The file type.
  type: string
- contextPath: CrowdStrike.Report.type_short
  description: The short description of the file type.
  type: string
- contextPath: CrowdStrike.Report.target_url
  description: The target url.
  type: string
- contextPath: CrowdStrike.Report.state
  description: The report state.
  type: string
- contextPath: CrowdStrike.Report.error_type
  description: The error type.
  type: string
- contextPath: CrowdStrike.Report.error_origin
  description: The error origin.
  type: string
- contextPath: CrowdStrike.Report.submit_name
  description: The file name when submitted.
  type: string
- contextPath: CrowdStrike.Report.md5
  description: The MD5 hash of the file.
  type: string
- contextPath: CrowdStrike.Report.sha1
  description: The SHA1 hash of the file.
  type: string
- contextPath: CrowdStrike.Report.sha256
  description: The SHA256 hash of the file.
  type: string
- contextPath: CrowdStrike.Report.sha512
  description: The SHA512 hash of the file.
  type: string
- contextPath: CrowdStrike.Report.ssdeep
  description: The SSDeep hash of the file.
  type: string
- contextPath: CrowdStrike.Report.imphash
  description: The imphash hash of the file.
  type: string
- contextPath: CrowdStrike.Report.av_detect
  description: The AV Multiscan range, for example 50-70 (min 0, max 100).
  type: string
- contextPath: CrowdStrike.Report.vx_family
  description: The file malware famil.
  type: string
- contextPath: CrowdStrike.Report.url_analysis
  description: Whether this report is url analysis.
  type: string
- contextPath: CrowdStrike.Report.analysis_start_time
  description: The start time of the analysis.
  type: string
- contextPath: CrowdStrike.Report.threat_score
  description: The file threat score.
  type: string
- contextPath: CrowdStrike.Report.interesting
  description: Whether the file was found to be interesting.
  type: string
- contextPath: CrowdStrike.Report.threat_level
  description: The file threat level.
  type: string
- contextPath: CrowdStrike.Report.verdict
  description: The file verdict.
  type: string
- contextPath: CrowdStrike.Report.total_network_connections
  description: The total number of network connections.
  type: number
- contextPath: CrowdStrike.Report.total_processes
  description: The total number of processes.
  type: number
- contextPath: CrowdStrike.Report.total_signatures
  description: The total number of signatures.
  type: number
- contextPath: CrowdStrike.Report.file_metadata
  description: The file metadata.
  type: string
- contextPath: CrowdStrike.Report.network_mode
  description: The network mode.
  type: string
- contextPath: CrowdStrike.Report.submissions.submission_id
  description: The submission ID.
  type: string
- contextPath: CrowdStrike.Report.submissions.filename
  description: The name of the file.
  type: string
- contextPath: CrowdStrike.Report.submissions.url
  description: The url.
  type: string
- contextPath: CrowdStrike.Report.submissions.created_at
  description: When the submission was created.
  type: string
- contextPath: File.MalwareFamily
  description: The file family classification.
  type: string
- contextPath: WildFire.Report.MD5
  description: MD5 of the submission.
  type: string
- contextPath: WildFire.Report.SHA256
  description: SHA256 of the report.
  type: string
- contextPath: WildFire.Report.Status
  description: The status of the submission.
  type: string
- contextPath: WildFire.Report.URL
  description: URL of the submission.
  type: string
- contextPath: WildFire.Report.iocs
  description: Associated IOCs.
  type: string
- contextPath: WildFire.Report.verdict
  description: The verdict of the report.
  type: string
- contextPath: WildFire.Report.Platform
  description: The platform of the report.
  type: string
- contextPath: WildFire.Report.Software
  description: The software of the report.
  type: string
- contextPath: File.DigitalSignature.Publisher
  description: The entity that signed the file for authenticity purposes.
  type: string
- contextPath: WildFire.Report.NetworkInfo.URL.Host
  description: The submission related hosts.
  type: string
- contextPath: WildFire.Report.NetworkInfo.URL.Method
  description: The submission related method.
  type: string
- contextPath: WildFire.Report.NetworkInfo.URL.URI
  description: The submission related URI.
  type: string
- contextPath: WildFire.Report.NetworkInfo.URL.UserAgent
  description: The submission related user agent.
  type: string
- contextPath: WildFire.Report.NetworkInfo.UDP.IP
  description: The submission related IPs, in UDP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.UDP.Port
  description: The submission related ports, in UDP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.UDP.JA3
  description: The submission related JA3s, in UDP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.UDP.JA3S
  description: The submission related JA3Ss, in UDP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.UDP.Country
  description: The submission related countries, in UDP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.TCP.IP
  description: The submission related IPs, in TCP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.TCP.JA3
  description: The submission related JA3s, in TCP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.TCP.JA3S
  description: The submission related JA3Ss, in TCP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.TCP.Country
  description: The submission related Countries, in TCP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.TCP.Port
  description: The submission related ports, in TCP protocol.
  type: string
- contextPath: WildFire.Report.NetworkInfo.DNS.Query
  description: The submission DNS queries.
  type: string
- contextPath: WildFire.Report.NetworkInfo.DNS.Response
  description: The submission DNS responses.
  type: string
- contextPath: WildFire.Report.NetworkInfo.DNS.Type
  description: The submission DNS Types.
  type: string
- contextPath: WildFire.Report.Evidence.md5
  description: The submission evidence MD5 hash.
  type: string
- contextPath: WildFire.Report.Evidence.Text
  description: The submission evidence text.
  type: string
- contextPath: WildFire.Report.detection_reasons.description
  description: Reason for the detection verdict.
  type: string
- contextPath: WildFire.Report.detection_reasons.name
  description: Name of the detection.
  type: string
- contextPath: WildFire.Report.detection_reasons.type
  description: Type of the detection.
  type: string
- contextPath: WildFire.Report.detection_reasons.verdict
  description: Verdict of the detection.
  type: string
- contextPath: WildFire.Report.detection_reasons.artifacts
  description: Artifacts of the detection reasons.
  type: string
- contextPath: WildFire.Report.ProcessList.Service
  description: The process service.
  type: string
- contextPath: WildFire.Report.ProcessList.ProcessCommand
  description: The process command.
  type: string
- contextPath: WildFire.Report.ProcessList.ProcessName
  description: The process name.
  type: string
- contextPath: WildFire.Report.ProcessList.ProcessPid
  description: The process pid.
  type: string
- contextPath: WildFire.Report.ProcessList.ProcessFile
  description: Lists files that started a child processes, including the process name and the action the process performed.
  type: string
- contextPath: WildFire.Report.ProcessTree.ProcessName
  description: The process name.
  type: string
- contextPath: WildFire.Report.ProcessTree.ProcessPid
  description: The process pid.
  type: string
- contextPath: WildFire.Report.ProcessTree.ProcessText
  description: The action the process performed.
  type: string
- contextPath: WildFire.Report.ProcessTree.Process.ChildName
  description: The child process name.
  type: string
- contextPath: WildFire.Report.ProcessTree.Process.ChildPid
  description: The child process pid.
  type: string
- contextPath: WildFire.Report.ProcessTree.Process.ChildText
  description: The action the child process performed.
  type: string
- contextPath: WildFire.Report.ExtractedURL.URL
  description: The extracted URL.
  type: string
- contextPath: WildFire.Report.ExtractedURL.Verdict
  description: The extracted verdict.
  type: string
- contextPath: WildFire.Report.Summary.Text
  description: The summary of the report.
  type: string
- contextPath: WildFire.Report.Summary.Details
  description: The details summary of the report.
  type: string
- contextPath: WildFire.Report.Summary.Behavior
  description: The behavior summary of the report.
  type: string
- contextPath: WildFire.Report.ELF.ShellCommands
  description: The shell commands.
  type: string
- contextPath: VirusTotal.Analysis.data.attributes.stats.harmless
  description: Number of engines found the indicator harmless.
  type: number
- contextPath: VirusTotal.Analysis.data.attributes.stats.malicious
  description: Number of engines found the indicator malicious.
  type: number
- contextPath: VirusTotal.Analysis.data.attributes.stats.suspicious
  description: Number of engines found the indicator suspicious.
  type: number
- contextPath: VirusTotal.Analysis.data.attributes.stats.timeout
  description: Number of engines found the indicator timeout.
  type: number
- contextPath: VirusTotal.Analysis.data.attributes.stats.undetected
  description: Number of engines found the indicator undetected.
  type: number
- contextPath: VirusTotal.Analysis.data.attributes.date
  description: Date of the analysis in epoch.
  type: number
- contextPath: VirusTotal.Analysis.data.attributes.status
  description: Status of the analysis.
  type: string
- contextPath: VirusTotal.Analysis.data.id
  description: ID of the analysis.
  type: string
- contextPath: VirusTotal.Analysis.data.type
  description: Type of object (analysis).
  type: string
- contextPath: VirusTotal.Analysis.meta.url_info.id
  description: ID of the url.
  type: string
- contextPath: VirusTotal.Analysis.meta.url_info.url
  description: The URL.
  type: string
- contextPath: VirusTotal.Analysis.id
  description: The analysis ID.
  type: string
- contextPath: VMRay.Job.JobID
  description: The ID of a new job.
  type: number
- contextPath: VMRay.Job.SampleID
  description: The ID of sample.
  type: number
- contextPath: VMRay.Job.Created
  description: The timestamp of the created job.
  type: date
- contextPath: VMRay.Job.VMName
  description: The name of virtual machine.
  type: string
- contextPath: VMRay.Job.VMID
  description: The ID of virtual machine.
  type: number
- contextPath: VMRay.Sample.SampleID
  description: The sample ID of the task.
  type: number
- contextPath: VMRay.Sample.Created
  description: The timestamp of the created sample.
  type: date
- contextPath: VMRay.Sample.FileName
  description: The file name of the sample.
  type: string
- contextPath: VMRay.Sample.MD5
  description: The MD5 hash of the sample.
  type: string
- contextPath: VMRay.Sample.SHA1
  description: The SHA1 hash of the sample.
  type: string
- contextPath: VMRay.Sample.SHA256
  description: The SHA256 hash of the sample.
  type: string
- contextPath: VMRay.Sample.SSDeep
  description: The SSDeep of the sample.
  type: string
- contextPath: VMRay.Sample.Verdict
  description: Verdict for the sample (Malicious, Suspicious, Clean, Not Available).
  type: String
- contextPath: VMRay.Sample.VerdictReason
  description: Description of the Verdict Reason.
  type: String
- contextPath: VMRay.Sample.Severity
  description: Severity of the sample (Malicious, Suspicious, Good, Blacklisted, Whitelisted, Unknown). Deprecated.
  type: string
- contextPath: VMRay.Sample.Type
  description: The file type.
  type: string
- contextPath: VMRay.Sample.Classifications
  description: The classifications of the sample.
  type: string
- contextPath: VMRay.Submission.SubmissionID
  description: The submission ID.
  type: number
- contextPath: VMRay.Submission.HadErrors
  description: Whether there are any errors in the submission.
  type: boolean
- contextPath: VMRay.Submission.IsFinished
  description: The status of submission. Can be, "true" or "false".
  type: boolean
- contextPath: VMRay.Submission.MD5
  description: The MD5 hash of the sample in submission.
  type: string
- contextPath: VMRay.Submission.SHA1
  description: The SHA1 hash of the sample in submission.
  type: string
- contextPath: VMRay.Submission.SHA256
  description: The SHA256 hash of the sample in submission.
  type: string
- contextPath: VMRay.Submission.Verdict
  description: Verdict for the sample (Malicious, Suspicious, Clean, Not Available).
  type: String
- contextPath: VMRay.Submission.VerdictReason
  description: Description of the Verdict Reason.
  type: String
- contextPath: VMRay.Submission.Severity
  description: Severity of the sample (Malicious, Suspicious, Good, Blacklisted, Whitelisted, Unknown). Deprecated.
  type: string
- contextPath: VMRay.Submission.SSDeep
  description: The SSDeep hash of the sample in submission.
  type: string
- contextPath: VMRay.Submission.SampleID
  description: The ID of the sample in submission.
  type: string
- contextPath: VMRay.Sample.IOC.URL.AnalysisID
  description: The IDs of the other analyses that contain the given URL.
  type: string
- contextPath: VMRay.Sample.IOC.URL.URL
  description: The URL.
  type: string
- contextPath: VMRay.Sample.IOC.URL.Operation
  description: The operation of the specified URL.
  type: string
- contextPath: VMRay.Sample.IOC.URL.ID
  description: The ID of the URL.
  type: string
- contextPath: VMRay.Sample.IOC.URL.Type
  description: The type of the URL.
  type: string
- contextPath: VMRay.Sample.IOC.Domain.AnalysisID
  description: The IDs of the other analyses that contain the given domain.
  type: string
- contextPath: VMRay.Sample.IOC.Domain.Domain
  description: The domain.
  type: string
- contextPath: VMRay.Sample.IOC.Domain.ID
  description: The ID of the domain.
  type: string
- contextPath: VMRay.Sample.IOC.Domain.Type
  description: The type of the domain.
  type: string
- contextPath: VMRay.Sample.IOC.IP.AnalysisID
  description: The IDs of the other analyses that contain the given IP address.
  type: string
- contextPath: VMRay.Sample.IOC.IP.IP
  description: The IP address.
  type: string
- contextPath: VMRay.Sample.IOC.IP.Operation
  description: The operation of the given IP address.
  type: string
- contextPath: VMRay.Sample.IOC.IP.ID
  description: The ID of the IP address.
  type: string
- contextPath: VMRay.Sample.IOC.IP.Type
  description: The type of the IP address.
  type: string
- contextPath: VMRay.Sample.IOC.Mutex.AnalysisID
  description: The IDs of other analyses that contain the given IP address.
  type: string
- contextPath: VMRay.Sample.IOC.Mutex.Name
  description: The name of the mutex.
  type: string
- contextPath: VMRay.Sample.IOC.Mutex.Operation
  description: The operation of the given mutex.
  type: string
- contextPath: VMRay.Sample.IOC.Mutex.ID
  description: The ID of the mutex.
  type: string
- contextPath: VMRay.Sample.IOC.Mutex.Type
  description: The type of the mutex.
  type: string
- contextPath: VMRay.Sample.IOC.File.AnalysisID
  description: The IDs of other analyses that contain the given file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Name
  description: The name of the file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Operation
  description: The operation of the given file.
  type: string
- contextPath: VMRay.Sample.IOC.File.ID
  description: The ID of the file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Type
  description: The type of the file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Hashes.MD5
  description: The MD5 hash of the given file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Hashes.SSDeep
  description: The SSDeep hash of the given file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Hashes.SHA256
  description: The SHA256 hash of the given file.
  type: string
- contextPath: VMRay.Sample.IOC.File.Hashes.SHA1
  description: The SHA1 hash of the given file.
  type: string
- contextPath: VMRay.ThreatIndicator.AnalysisID
  description: The list of connected analysis IDs.
  type: string
- contextPath: VMRay.ThreatIndicator.Category
  description: The category of threat indicators.
  type: string
- contextPath: VMRay.ThreatIndicator.Classification
  description: The classifications of threat indicators.
  type: string
- contextPath: VMRay.ThreatIndicator.ID
  description: The ID of the threat indicator.
  type: string
- contextPath: VMRay.ThreatIndicator.Operation
  description: The operation that caused the indicators.
  type: string
- contextPath: ThreatStream.Analysis.ReportID
  description: The report ID submitted to the sandbox.
  type: string
- contextPath: ThreatStream.Analysis.Status
  description: The analysis status.
  type: string
- contextPath: ThreatStream.Analysis.Platform
  description: The platform of the submission submitted to the sandbox.
  type: string
- contextPath: ThreatStream.Analysis.Category
  description: The report category.
  type: string
- contextPath: ThreatStream.Analysis.Started
  description: The detonation start time.
  type: string
- contextPath: ThreatStream.Analysis.Completed
  description: The detonation completion time.
  type: string
- contextPath: ThreatStream.Analysis.Duration
  description: The duration of the detonation (in seconds).
  type: string
- contextPath: ThreatStream.Analysis.VmName
  description: The VM name.
  type: string
- contextPath: ThreatStream.Analysis.VmID
  description: The VM ID.
  type: string
- contextPath: ThreatStream.Analysis.Verdict
  description: The verdict of the sandbox detonation.
  type: string
- contextPath: ThreatStream.Analysis.Network.UdpSource
  description: The UDP source.
  type: string
- contextPath: ThreatStream.Analysis.Network.UdpDestination
  description: The UDP destination.
  type: string
- contextPath: ThreatStream.Analysis.Network.UdpPort
  description: The UDP port.
  type: number
- contextPath: ThreatStream.Analysis.Network.IcmpSource
  description: The ICMP source.
  type: string
- contextPath: ThreatStream.Analysis.Network.IcmpDestination
  description: The ICMP destination.
  type: string
- contextPath: ThreatStream.Analysis.Network.IcmpPort
  description: The ICMP port.
  type: number
- contextPath: ThreatStream.Analysis.Network.TcpSource
  description: The TCP source.
  type: string
- contextPath: ThreatStream.Analysis.Network.TcpDestination
  description: The TCP destination.
  type: string
- contextPath: ThreatStream.Analysis.Network.TcpPort
  description: The TCP port.
  type: number
- contextPath: ThreatStream.Analysis.Network.HttpSource
  description: The source of the HTTP address.
  type: string
- contextPath: ThreatStream.Analysis.Network.HttpDestinaton
  description: The destination of the HTTP address.
  type: string
- contextPath: ThreatStream.Analysis.Network.HttpPort
  description: The port of the HTTP address.
  type: string
- contextPath: ThreatStream.Analysis.Network.HttpsSource
  description: The source of the HTTPS address.
  type: string
- contextPath: ThreatStream.Analysis.Network.HttpsDestinaton
  description: The destination of the HTTPS address.
  type: string
- contextPath: ThreatStream.Analysis.Network.HttpsPort
  description: The port of the HTTPS address.
  type: string
- contextPath: ThreatStream.Analysis.Network.Hosts
  description: The network analysis hosts.
  type: string
- contextPath: FireEyeAX.Submissions.URL.Key
  description: The submission key.
  type: string
- contextPath: FireEyeAX.Submissions.Severity
  description: The severity level of the file.
  type: string
- contextPath: FireEyeAX.Submissions.InfoLevel
  description: The info level of the report.
  type: string
- contextPath: Triage.sample-summaries.completed
  description: Date the sample analysis was completed.
  type: date
- contextPath: Triage.sample-summaries.created
  description: Date the analysis report was created.
  type: date
- contextPath: Triage.sample-summaries.custom
  description: Custom sample analysis.
  type: string
- contextPath: Triage.sample-summaries.owner
  description: Owner of the sample analysis.
  type: string
- contextPath: Triage.sample-summaries.sample
  description: Unique identifier of the sample,.
  type: string
- contextPath: Triage.sample-summaries.score
  description: Score of the sample on a scale of 0 to 10.
  type: number
- contextPath: Triage.sample-summaries.sha256
  description: SHA256 hash of the sample.
  type: string
- contextPath: Triage.sample-summaries.status
  description: Status of the analysis.
  type: string
- contextPath: Triage.sample-summaries.target
  description: Target for the analysis.
  type: string
- contextPath: Triage.sample-summaries.tasks
  description: Tasks performed in the analysis.
  type: string
- contextPath: SecneurXAnalysis.Report.SHA256
  description: SHA256 value of the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.Platform
  description: Platform of the analyzed sample.
  type: String
- contextPath: SecneurXAnalysis.Report.Verdict
  description: Summary result of the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.Tags
  description: More details of the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.DnsRequests
  description: List of DNS data observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.HttpRequests
  description: List of HTTP data observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.JA3Digests
  description: List of JA3 data observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.ProcessCreated
  description: Process behaviour data observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.RegistrySet
  description: List of Registry creations observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.RegistryDeleted
  description: List of Registry deletions observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.FileCreated
  description: List of File creations observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.FileDropped
  description: List of File drops observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.FileDeleted
  description: List of File deletions observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.FileModified
  description: List of File changes observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.IOC
  description: List of IOC's observed in the analyzed sample.
  type: string
- contextPath: SecneurXAnalysis.Report.Status
  description: Analysis queued sample state.
  type: String
- contextPath: csfalconx.resource.id
  description: Analysis ID.
  type: String
- contextPath: csfalconx.resource.verdict
  description: Analysis verdict.
  type: String
- contextPath: csfalconx.resource.created_timestamp
  description: Analysis start time.
  type: String
- contextPath: csfalconx.resource.environment_id
  description: Environment ID.
  type: String
- contextPath: csfalconx.resource.environment_description
  description: Environment description.
  type: String
- contextPath: csfalconx.resource.threat_score
  description: Score of the threat.
  type: Int
- contextPath: csfalconx.resource.submit_url
  description: URL submitted for analysis.
  type: String
- contextPath: csfalconx.resource.submission_type
  description: Type of submitted artifact, for example file, URL, etc.
  type: String
- contextPath: csfalconx.resource.sha256
  description: SHA256 hash of the submitted file.
  type: String
- contextPath: csfalconx.resource.ioc_report_strict_csv_artifact_id
  description: ID of the IOC pack to download (CSV).
  type: String
- contextPath: csfalconx.resource.ioc_report_broad_csv_artifact_id
  description: ID of the IOC pack to download (CSV).
  type: String
- contextPath: csfalconx.resource.ioc_report_strict_json_artifact_id
  description: ID of the IOC pack to download (JSON).
  type: Int
- contextPath: csfalconx.resource.ioc_report_broad_json_artifact_id
  description: ID of the IOC pack to download (JSON).
  type: String
- contextPath: csfalconx.resource.ioc_report_strict_stix_artifact_id
  description: ID of the IOC pack to download (STIX).
  type: String
- contextPath: csfalconx.resource.ioc_report_broad_stix_artifact_id
  description: ID of the IOC pack to download (STIX).
  type: Int
- contextPath: csfalconx.resource.ioc_report_strict_maec_artifact_id
  description: ID of the IOC pack to download (MAEC).
  type: String
- contextPath: csfalconx.resource.ioc_report_broad_maec_artifact_id
  description: ID of the IOC pack to download (MAEC).
  type: String
- contextPath: OPSWAT.Filescan.Submission.flow_id
  description: The flow ID.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.finalVerdict.verdict
  description: The final verdict.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.allTags
  description: All tags.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.overallState
  description: Overall state of the scan.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.subtaskReferences
  description: Status of scan subtasks.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.allSignalGroups
  description: All signal groups.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.resources
  description: Resources.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.name
  description: Name of the main scan task.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.additionalInfo
  description: Additional informations about the main scan task.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.ID
  description: ID of the main scan task.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.state
  description: State of the main scan task.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.resourceReference
  description: Resource reference of the main scan task.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.opcount
  description: Counter.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.taskReference.processTime
  description: processTime.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.file.name
  description: The name of the file.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.file.hash
  description: The SHA256 of the file.
  type: string
- contextPath: OPSWAT.Filescan.Analysis.file.type
  description: The type of the submission.
  type: string
- contextPath: ANYRUN.SandboxAnalysis.mitre.name
  description: 'MITRE Technic text description.'
  type: String
- contextPath: ANYRUN.SandboxAnalysis.mitre.phases
  description: "MITRE Technic phases."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.mitre.id
  description: "MITRE Technic identifier."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.debugStrings
  type: Unknown
  description: "Analysis debug information."
- contextPath: ANYRUN.SandboxAnalysis.incidents.process
  description: "Analysis process."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.time
  type: Date
  description: "Event time."
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.cmdline
  description: "Event command line."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.image
  description: "Event image."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.mitre.v
  description: "MITRE version."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.mitre.sid
  description: "SID."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.mitre.tid
  description: "TID."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.count
  description: "Count of related incidents."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.firstSeen
  type: Date
  description: "Incident first seen date."
- contextPath: ANYRUN.SandboxAnalysis.incidents.source
  description: "Incident source."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.desc
  description: "Incident description."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.title
  description: "Incident title."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.threatLevel
  description: "Incident threat level."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.typeValue
  description: "Event type value."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.key
  description: "Event key."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.value
  description: "Event value."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.name
  description: "Event name."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.operation
  description: "Even operation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.cmdParent
  description: "Event parent cmd."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.incidents.events.cmdChild
  description: "Event child cmd."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.registry.time
  type: Date
  description: "Registry time."
- contextPath: ANYRUN.SandboxAnalysis.modified.registry.process
  description: "Registry process."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.registry.operation
  description: "Registry operation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.registry.value
  description: "Registry value."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.registry.name
  description: "Registry name."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.registry.key
  description: "Registry key."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.process
  description: "File process."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.size
  description: "File size."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.filename
  description: "Filename."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.time
  type: Date
  description: "File creating time."
- contextPath: ANYRUN.SandboxAnalysis.modified.files.info.mime
  description: "File MIME type."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.info.file
  description: "File content."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.permanentUrl
  description: "File url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.hashes.ssdeep
  description: "File SSDeep."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.hashes.sha256
  description: "File sha256 hash."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.hashes.sha1
  description: "File sha1 hash."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.hashes.md5
  description: "File md5 hash."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.threatLevel
  description: "File threat level."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.modified.files.type
  description: "File type."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.threats
  type: Unknown
  description: "Analysis network threats."
- contextPath: ANYRUN.SandboxAnalysis.network.connections.reputation
  description: "Network connection reputation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.tlsFingerprint.ja3SFullstring
  description: "Network connection ja3S."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.tlsFingerprint.ja3S
  description: "Network connection ja3S."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.tlsFingerprint.ja3Fullstring
  description: "Network connection ja3F."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.tlsFingerprint.ja3
  description: "Network connection ja3F."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.time
  type: Date
  description: "Network connection time."
- contextPath: ANYRUN.SandboxAnalysis.network.connections.asn
  description: "Network connection ASN."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.country
  description: "Network connection country."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.protocol
  description: "Network connection protocol."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.port
  description: "Network connection port."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.ip
  description: "Network connection ip."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.process
  description: "Network connection processes."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.connections.tlsFingerprint.jarm
  description: "Network connection jarm."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.country
  description: "HTTP Request country."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.reputation
  description: "HTTP Request reputation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.process
  description: "HTTP Request related process."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.httpCode
  description: "HTTP Request status code."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.status
  description: "HTTP Request status."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.user-agent
  description: "HTTP Request User-Agent header value."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.proxyDetected
  description: "HTTP Request is proxy detected."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.port
  description: "HTTP Request port."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.ip
  description: "HTTP Request ip."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.url
  description: "HTTP Request url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.host
  description: "HTTP Request host."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.method
  description: "HTTP Request method."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.httpRequests.time
  type: Date
  description: "HTTP Request time estimate."
- contextPath: ANYRUN.SandboxAnalysis.network.dnsRequests.reputationNumber
  description: "DNS Request reputation number."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.dnsRequests.reputation
  description: "DNS Request reputation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.dnsRequests.ips
  description: "DNS Request IPs."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.dnsRequests.domain
  description: "DNS Request domain."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.network.dnsRequests.time
  type: Date
  description: "DNS Request time estimate."
- contextPath: ANYRUN.SandboxAnalysis.malconf
  type: Unknown
  description: "Analysis malconf."
- contextPath: ANYRUN.SandboxAnalysis.processes.synchronization
  type: Unknown
  description: "Analysis processes synchronization."
- contextPath: ANYRUN.SandboxAnalysis.processes.modules
  type: Unknown
  description: "Analysis processes modules."
- contextPath: ANYRUN.SandboxAnalysis.processes.hasMalwareConfig
  description: "Process has malware config."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.parentUUID
  description: "Process parent UUID."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.status
  description: "Process status."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.malwareConfig
  description: "Process malware config."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.privEscalation
  description: "Process priv escalation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.stealing
  description: "Process stealing."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.networkLoader
  description: "Process network loader."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.network
  description: "Process network."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.lowAccess
  description: "Process low access."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.knownThreat
  description: "Process known threat."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.injects
  description: "Process inject."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.exploitable
  description: "Process exploitable."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.executableDropped
  description: "Process executable dropped."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.debugOutput
  description: "Process debug output."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.crashedApps
  description: "Process crashed apps."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.specs.autoStart
  description: "Process auto start."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.loadsSusp
  description: "Process loads susp."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.injected
  description: "Process injected."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.dropped
  description: "Process dropped."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.verdict.threatLevelText
  description: "Process threat level text."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.verdict.threatLevel
  description: "Process threat level."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.verdict.score
  description: "Process score."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.context.userName
  description: "Process context username."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.context.integrityLevel
  description: "Process context integrity level."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.context.rebootNumber
  description: "Process context reboot number."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.versionInfo.version
  description: "Process version."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.versionInfo.description
  description: "Process description."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.versionInfo.company
  description: "Process company."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.mainProcess
  description: "Process main process."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.fileType
  description: "Process file type."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.fileName
  description: "Process filename."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.commandLine
  description: "Process cmd."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.image
  description: "Process image."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.uuid
  description: "Process uuid."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.ppid
  description: "Process PPID."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.important
  description: "Process important."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.pid
  description: "Process PID."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.exitCode
  description: "Process exit code."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.times.terminate
  type: Date
  description: "Process time terminate."
- contextPath: ANYRUN.SandboxAnalysis.processes.times.start
  type: Date
  description: "Process time start."
- contextPath: ANYRUN.SandboxAnalysis.processes.resolvedCOM.title
  description: "Process resolved COM title."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.synchronization.operation
  description: "Process sync operation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.synchronization.type
  description: "Process sync type."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.synchronization.name
  description: "Process sync name."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.synchronization.time
  type: Date
  description: "Process sync time."
- contextPath: ANYRUN.SandboxAnalysis.processes.modules.image
  description: "Process module image."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.modules.time
  type: Date
  description: "Process module time."
- contextPath: ANYRUN.SandboxAnalysis.processes.scores.monitoringReason
  description: "Process monitoring reason."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.processes.times.monitoringSince
  type: Date
  description: "Process monitoring since."
- contextPath: ANYRUN.SandboxAnalysis.counters.synchronization.type.event
  description: "Process sync event."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.synchronization.type.mutex
  description: "Process sync mutex."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.synchronization.operation.create
  description: "Process sync operation create."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.synchronization.operation.open
  description: "Process sync operation open."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.synchronization.total
  description: "Process sync total."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.registry.delete
  description: "Registry delete."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.registry.write
  description: "Registry write."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.registry.read
  description: "Registry reed."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.registry.total
  description: "Registry total."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.files.malicious
  description: "File malicious count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.files.suspicious
  description: "File suspicious count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.files.text
  description: "File text."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.files.unknown
  description: "File unknown count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.network.threats
  description: "Network threats count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.network.dns
  description: "Network dns count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.network.connections
  description: "Network connections count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.network.http
  description: "Network networks count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.processes.malicious
  description: "Malicious processes count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.processes.suspicious
  description: "Suspicious processes count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.processes.monitored
  description: "Monitored processes count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.counters.processes.total
  description: "Total processes count."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.hotfixes.title
  description: "Environment hotfixes title."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.software.version
  description: "Environment software version."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.software.title
  description: "Environment software title."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.internetExplorer.kbnum
  description: "Environment Internet Explorer KBNUM."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.internetExplorer.version
  description: "Environment Internet Explorer version."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.bitness
  description: "Environment OS version."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.softSet
  description: "Environment OS software set."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.servicePack
  description: "Environment OS service pack."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.major
  description: "Environment OS major version."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.productType
  description: "Environment OS product type."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.variant
  description: "Environment OS variant."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.product
  description: "Environment OS product."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.build
  description: "Environment OS build."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.environments.os.title
  description: "Environment OS title."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.dumps
  type: Unknown
  description: "Content dumps."
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.screenshots.thumbnailUrl
  description: "Screenshots thumbnail url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.screenshots.permanentUrl
  description: "Screenshots permanent url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.screenshots.time
  description: "Screenshots time."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.screenshots.uuid
  description: "Screenshots uuid."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.sslkeys.present
  description: "SSL keys present."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.pcap.permanentUrl
  description: "Pcap dump permanent url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.pcap.present
  description: "Pcap present."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.video.permanentUrl
  description: "Video permanent url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.video.present
  description: "Video present."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.mainObject.hashes.ssdeep
  description: "Main object ssdeep."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.mainObject.hashes.sha256
  description: "Main object sha256."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.mainObject.hashes.sha1
  description: "Main object sha1."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.mainObject.hashes.md5
  description: "Main object md5."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.mainObject.url
  description: "Main object url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.content.mainObject.type
  description: "Main object type."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.knownThreat
  description: "Specs known threat."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.malwareConfig
  description: "Specs malware Config."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.notStarted
  description: "Specs not started."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.privEscalation
  description: "Specs priv escalation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.torUsed
  description: "Specs TOR used."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.suspStruct
  description: "Specs susp structure."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.stealing
  description: "Specs stealing."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.staticDetections
  description: "Specs static detections."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.spam
  description: "Specs spam."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.serviceLauncher
  description: "Specs service launcher."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.rebooted
  description: "Specs rebooted."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.networkThreats
  description: "Specs network threats."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.networkLoader
  description: "Specs network loader."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.multiprocessing
  description: "Specs multiprocessing."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.memOverrun
  description: "Specs memory overrun."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.lowAccess
  description: "Specs low access."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.exploitable
  description: "Specs exploitable."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.executableDropped
  description: "Specs executable dropped."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.debugOutput
  description: "Specs debug output."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.crashedTask
  description: "Specs crashed task."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.crashedApps
  description: "Specs crashed apps."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.cpuOverrun
  description: "Specs CPU overrun."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.autoStart
  description: "Specs suto start."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.specs.injects
  description: "Specs injects."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.verdict.threatLevelText
  description: "Verdict threat level text."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.verdict.threatLevel
  description: "Verdict threat level."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.scores.verdict.score
  description: "Verdict score."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.automatization.uac
  description: "Options automatization UAC."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.privateSample
  description: "Options private sample."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.privacy
  description: "Options privacy."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.network
  description: "Options network."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.hideSource
  description: "Options hide source."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.video
  description: "Options video."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.presentation
  description: "Options presentation."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.tor.used
  description: "Options tor used."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.mitm
  description: "Options MITM proxy."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.heavyEvasion
  description: "Options kernel heavy evasion."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.fakeNet
  description: "Options fake network."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.additionalTime
  description: "Options additions time."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.options.timeout
  description: "Options timeout."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.tags
  type: Unknown
  description: "Analysis tags."
- contextPath: ANYRUN.SandboxAnalysis.analysis.stopExecText
  type: Date
  description: "Analysis stopExecText."
- contextPath: ANYRUN.SandboxAnalysis.analysis.stopExec
  type: Date
  description: "Analysis creation stopExec."
- contextPath: ANYRUN.SandboxAnalysis.analysis.creationText
  type: Date
  description: "Analysis creation creation text."
- contextPath: ANYRUN.SandboxAnalysis.analysis.creation
  type: Date
  description: "Analysis creation date."
- contextPath: ANYRUN.SandboxAnalysis.analysis.duration
  description: "Analysis duration."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.sandbox.plan.name
  description: "Analysis sandbox user plan name."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.sandbox.name
  description: "Analysis sandbox name."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.reports.graph
  description: "Analysis reports graph."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.reports.STIX
  description: "Analysis STIX report url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.reports.HTML
  description: "Analysis HTML report url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.reports.MISP
  description: "Analysis MISP report url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.reports.IOC
  description: "Analysis IOC report url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.permanentUrl
  description: "Analysis permanent url."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.analysis.uuid
  description: "Analysis uuid."
  type: String
- contextPath: ANYRUN.SandboxAnalysis.status
  description: "Analysis status."
  type: String
- contextPath: ANYRUN.SandboxAnalysisReportVerdict
  description: "The analysis verdict."
  type: String
- contextPath: ANYRUN_DetonateUrlAndroid.TaskID
  description: 'Task UUID.'
  type: String
- contextPath: ANYRUN_DetonateUrlLinux.TaskID
  description: 'Task UUID.'
  type: String
- contextPath: ANYRUN_DetonateUrlWindows.TaskID
  description: 'Task UUID.'
  type: String
tests:
- No tests (auto formatted)
fromversion: 6.8.0