CBPFindRule

Find the rule state for a hash value in CBEP/Bit9.

python · Carbon Black Enterprise Protection

Details

IDCBPFindRule
Languagepython
From Version5.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Tagscarbon-black-protection bit9 enhancement

README

Finds the rule state for a hash value in CBEP/Bit9.

Script Data


Name Description
Script Type python
Tags carbon-black-protection, bit9, enhancement

Dependencies


This script uses the following commands and scripts.

  • cbp-fileRule-search

Inputs


Argument Name Description
hash The hash value(s) to check.

Outputs


There are no outputs for this script.

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401


def test_cbp_find_rule(mocker):
    from CBPFindRule import cbp_find_rule

    args = {"hash": "some_hash"}
    rule = [{"Type": 3, "Contents": [{"hash": "some_hash", "fileState": 1}]}]
    mocker.patch.object(demisto, "executeCommand", return_value=rule)
    mocker.patch.object(demisto, "results")
    cbp_find_rule(args)
    res = demisto.results
    content = res.call_args[0][0]
    expected_res = [
        {"Type": 1, "ContentsFormat": "markdown", "Contents": "Hash some_hash is in state **Unapproved**\n"},
        {"Type": 1, "ContentsFormat": "table", "Contents": [{"hash": "some_hash", "fileState": 1}]},
    ]
    assert expected_res == content