BrandImpersonationDetection Deprecated

Analyzes the forensic data to detect brand impersonation attacks. This script uses the HMRC brand as an example, please modify the attributes associated with your company’s brand.

python · SlashNext Phishing Incident Response - Annual Subscription (Direct Subscription) (Deprecated)

Details

IDBrandImpersonationDetection
Languagepython
From Version6.0.0
Docker Imagedemisto/python3:3.12.8.3296088
Tagsphishing

README

Analyzes the forensic data to detect brand impersonation attacks. This script uses the HRMC brand as an example, please modify the attributes associated with your company’s brand.

import re

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401

# Scipt result
res = False
# Mandatory arguments
file_entry_ids = demisto.args()["ForensicFileEntry"]
forensic_files = file_entry_ids if isinstance(file_entry_ids, list) else file_entry_ids.split(",")

try:
    for entry in forensic_files:
        files_info = demisto.getFilePath(id=entry)
        with open(files_info["path"]) as file_handle:
            file_content = file_handle.read()

            result = re.findall("hm rеvеnuе & custоms", file_content, re.IGNORECASE)  # noqa: RUF001
            if len(result):
                res = True

            result = re.findall("GOV.UK", file_content)
            if len(result):
                res = True

            result1 = re.findall("hmrc", file_content, re.IGNORECASE)
            result2 = re.findall("gov.uk", file_content, re.IGNORECASE)
            if len(result1) and len(result2):
                res = True

            result1 = re.findall("tax refund", file_content, re.IGNORECASE)
            result2 = re.findall("gov.uk", file_content, re.IGNORECASE)
            if len(result1) and len(result2):
                res = True

            ec = {"SlashNext.PhishingBrand": "HMRC" if res else "Unknown"}

            ioc_cont = {"PhishingBrand": "HMRC" if res else "Unknown"}

            md = tableToMarkdown("HMRC Targeted Phishing Detection", ioc_cont, ["PhishingBrand"])

            return_outputs(md, ec, ioc_cont)

except Exception as ex:
    return_error(f"Exception Occurred, {ex!s}")