CreateIndicatorsFromSTIX
Creates indicators from the submitted STIX file. Supports STIX 1.0 and STIX 2.x. This automation creates indicators and adds an indicator's relationships if available.
python · Common Scripts
Details
| ID | CreateIndicatorsFromSTIX |
|---|---|
| Language | python |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10404775 |
| Tags | stix ioc |
README
Creates indicators from the submitted STIX file. Supports STIX 1.0 and STIX 2.x.
Wrapper for the StixParser automation. This automation creates indicators and adds an indicator’s relationships if available.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | stix, ioc |
| Cortex XSOAR Version | 5.0.0 |
Inputs
| Argument Name | Description |
|---|---|
| entry_id | The entry ID of the STIX file. |
| add_context | Adds indicators to context. |
| tags | A comma-separated list of tags to add to indicators. |
Outputs
| Path | Description | Type |
|---|---|---|
| StixIndicators.type | Type of the indicator. | String |
| StixIndicators.value | Value of the indicator. | String |
| StixIndicators.tags | Tags of the indicator. | Unknown |
from CreateIndicatorsFromSTIX import * def test_create_indicators_loop_wo_args(mocker): """ Given: - A collection of indicators in XSOAR Format When: - Parsing stix indicators. Then: - Validate the indicators extract without errors. """ args = {} with open("test_data/expected_result_example3.json") as json_f: indicators = json.load(json_f) mocker.patch.object(demisto, "executeCommand", return_value=[None]) results, errors = create_indicators_loop(args, indicators) assert errors == [] assert results.readable_output == "Create Indicators From STIX: 2 indicators were created." def test_create_indicators_loop_w_args(mocker): """ Given: - A collection of indicators in XSOAR Format When: - Parsing stix indicators. Then: - Validate the indicators extract without errors. """ args = {"add_context": "true", "tags": "tag1,tag2"} with open("test_data/expected_result_example3.json") as json_f: indicators = json.load(json_f) mocker.patch.object(demisto, "executeCommand", return_value=[None]) results, errors = create_indicators_loop(args, indicators) assert errors == [] assert results.readable_output == "Create Indicators From STIX: 2 indicators were created." assert results.outputs[0]["tags"] == ["tag1", "tag2"] def test_parse_indicators_using_stix_parser(mocker): """ Given: - A collection of indicators in STIX Format When: - Parsing stix indicators using STIXParserV2. Then: - Validate the indicators extract without errors. """ with open("test_data/expected_result_example3.json") as json_f: expected_res = json_f.read() mocker.patch.object(demisto, "executeCommand", return_value=[{"Contents": expected_res, "Type": 1}]) mocker.patch("CommonServerPython.is_error", False) indicators = parse_indicators_using_stix_parser("entry_id") assert json.loads(expected_res) == indicators