file-enrichment

Enriches File indicators with reputation data from multiple integrations and outputs a consolidated FileEnrichment object. This script exclusively supports indicators of type File and will automatically create the indicator in TIM if it is not already exists. Note: The script runs core-get-hash-analytics-prevalence on SHA256 values only.

python · Aggregated Scripts

Details

IDfile-enrichment
Languagepython
From Version8.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Tagsbasescript

README

Enriches File indicators with reputation data from multiple integrations and outputs a consolidated FileEnrichment object. This script exclusively supports indicators of type File and will automatically create the indicator in TIM if it is not already exists. Note: The script runs core-get-hash-analytics-prevalence on SHA256 values only.
Note: This script is supported in Cortex XSOAR 8.0 and later, and in Cortex XSIAM.

Script Data


Name Description
Script Type python3
Tags basescript
Cortex XSOAR Version 8.0.0

Used In


This script is used in the following playbooks and scripts.

  • FileEnrichment - Test

Inputs


Argument Name Description
file_hash A comma-separated list of File hashes to enrich. Supported types are: MD5, SHA1, SHA256, and SHA512.
external_enrichment “Whether to call external integrations for enrichment:
- ‘true’: enrich using all enabled integrations (e.g., VirusTotal (API v3), AlienVault OTX v2).
- ‘false’: Will enrich using only WildFire-v2 if available; skip external integrations.
If the ‘brands’ argument is provided, this flag is ignored and enrichment is run only on the brands provided.”
verbose Retrieve a human-readable entry for each command; if false, only the final result is summarized.
brands A list of integration brands to run enrichment against.
Example: `“AlienVault OTX v2”, “WildFire-v2”`.
- If provided, only the selected brands are used.
- If left empty, the script runs enrichment on all enabled integrations,
depending on the `external_enrichment` flag.
- In order to run core-get-hash-analytics-prevalence, add Cortex Core - IR to the brands list (will run only on SHA256 values).
To see the available brands for the `file` command, run: `!ProvidesCommand command=file`.
additional_fields When set to true, the output includes an `AdditionalFields` object
for each of the indicator results.
`AdditionalFields` contains all fields returned by TIM or the integrations
that are not part of the standard output keys: `MD5`, `SHA1`, `SHA256`, `SHA512`, `CRC32`, `CTPH`, `SSDeep`, `ImpHash`,
`SourceTimeStamp`, `Modified`, `Path`, `Size`, `FileExtension`, `AssociatedFileNames`, `Brand`, `Score`.
When set to false, only the standard keys are returned.

Outputs


Path Description Type
FileEnrichment.Value The File hash from the input Value. String
FileEnrichment.Hashes.MD5 The file MD5 hash if exists. String
FileEnrichment.Hashes.SHA1 The file SHA1 hash if exists. String
FileEnrichment.Hashes.SHA256 The file SHA256 hash if exists. String
FileEnrichment.Hashes.SHA512 The file SHA512 hash if exists. String
FileEnrichment.Hashes.CRC32 The file CRC32 hash if exists. String
FileEnrichment.Hashes.CTPH The file CTPH hash if exists. String
FileEnrichment.Hashes.SSDeep The file SSDeep hash if exists. String
FileEnrichment.Hashes.ImpHash The file ImpHash hash if exists. String
FileEnrichment.MaxScore The max score of all the indicators found. Number
FileEnrichment.MaxVerdict The max verdict of all the indicators found. String
FileEnrichment.Results List of all indicators found for the File. Array
FileEnrichment.TIMScore The TIM score of the File. Number
FileEnrichment.Status The status of the indicator: “Manual” if the score was changed manually, “Fresh” if modified within the last week, “Stale” if modified more than a week ago, and “None” if never modified. String
FileEnrichment.ModifiedTime The time the indicator was last modified. Date
FileEnrichment.Results.Brand The brand of the indicator. String
FileEnrichment.Results.Score The score of the indicator. Number
FileEnrichment.Results.Verdict The verdict of the indicator. String
FileEnrichment.Results.DetectionEngines The detection engines of the indicator. Number
FileEnrichment.Results.PositiveDetections The positive detections of the indicator. Number
FileEnrichment.Results.MD5 The file MD5 hash if exists. String
FileEnrichment.Results.SHA1 The file SHA1 hash if exists. String
FileEnrichment.Results.SHA256 The file SHA256 hash if exists. String
FileEnrichment.Results.SHA512 The file SHA512 hash if exists. String
FileEnrichment.Results.CRC32 The file CRC32 hash if exists. String
FileEnrichment.Results.CTPH The file CTPH hash if exists. String
FileEnrichment.Results.SSDeep The file SSDeep hash if exists. String
FileEnrichment.Results.ImpHash The file ImpHash hash if exists. String
FileEnrichment.Results.Reliability The reliability of the Brand. String
FileEnrichment.Results.AdditionalFields.Name The name of the file including its extension. String
FileEnrichment.Results.AdditionalFields.EntryID The identifier used to locate the file in the Incident War Room. String
FileEnrichment.Results.AdditionalFields.Actor The threat actor associated with the file, if applicable. String
FileEnrichment.Results.AdditionalFields.behavior.details A brief description of the behavior exhibited by the file. String
FileEnrichment.Results.AdditionalFields.behavior.title A brief description of the behavior exhibited by the file. String
FileEnrichment.Results.AdditionalFields.Campaign The identified campaign associated with the file, if applicable. String
FileEnrichment.Results.AdditionalFields.CommunityNotes.note Community-contributed notes regarding observations or findings related to the file. String
FileEnrichment.Results.AdditionalFields.CommunityNotes.timestamp The timestamp when the community note was added. Date
FileEnrichment.Results.AdditionalFields.Company The name of the company that released a binary. String
FileEnrichment.Results.AdditionalFields.DigitalSignature.Publisher The entity that issued the digital signature of the file. String
FileEnrichment.Results.AdditionalFields.Extension The file extension, indicating the type of file format, for example, ‘exe’. String
FileEnrichment.Results.AdditionalFields.FeedRelatedIndicators.value Shows other indicators associated with the file. String
FileEnrichment.Results.AdditionalFields.FeedRelatedIndicators.type Identifies the types of associated indicators. String
FileEnrichment.Results.AdditionalFields.FeedRelatedIndicators.description Describes the associated indicators providing context or relevance. String
FileEnrichment.Results.AdditionalFields.FirstSeenBySource The first time seen by the source brand. Date
FileEnrichment.Results.AdditionalFields.GlobalPrevalence The global prevalence of the file hash. Number
FileEnrichment.Results.AdditionalFields.Hostname The hostname of the device where the file was found. String
FileEnrichment.Results.AdditionalFields.LastSeenBySource The last time seed by the source brand. Date
FileEnrichment.Results.AdditionalFields.Malicious.Vendor Specifies the vendor that identified the file as malicious. String
FileEnrichment.Results.AdditionalFields.Malicious.Description For malicious files, the reason that the vendor made the decision. Unknown
FileEnrichment.Results.AdditionalFields.Malicious.Detections For malicious files, the total number of detections. Unknown
FileEnrichment.Results.AdditionalFields.Malicious.TotalEngines For malicious files, the total number of engines that checked the file hash. Unknown
FileEnrichment.Results.AdditionalFields.VTVendors.EngineDetections Number of VT vendors that flagged the file as malicious. Unknown
FileEnrichment.Results.AdditionalFields.VTVendors.EngineVendors VT vendors who flagged the file as malicious. Unknown
FileEnrichment.Results.AdditionalFields.VTVendors.EngineDetectionNames VT detection names that flagged the file as malicious. Unknown
FileEnrichment.Results.AdditionalFields.MalwareFamily Names the malware family associated with the file, if known. String
FileEnrichment.Results.AdditionalFields.Organization The organization to which the file is attributed. String
FileEnrichment.Results.AdditionalFields.OrganizationFirstSeen The date and time when the indicator was first seen in the organization. Date
FileEnrichment.Results.AdditionalFields.OrganizationLastSeen The date and time when the indicator was last seen in the organization. Date
FileEnrichment.Results.AdditionalFields.OrganizationPrevalence The number of times the indicator is detected in the organization. Number
FileEnrichment.Results.AdditionalFields.ProductName The file product name. String
FileEnrichment.Results.AdditionalFields.Publications.source Identifies the publishing source of an article relating to the file. String
FileEnrichment.Results.AdditionalFields.Publications.title Identifies the publishing source of an article relating to the file. String
FileEnrichment.Results.AdditionalFields.Publications.link Provides a hyperlink to the full article or publication for detailed information. String
FileEnrichment.Results.AdditionalFields.Publications.timestamp Publications.timestamp Date
FileEnrichment.Results.AdditionalFields.Quarantined Indicates whether the file has been quarantined to prevent potential harm. Bool
FileEnrichment.Results.AdditionalFields.Relationships.EntityA The initiating entity in a relationship involving the file. String
FileEnrichment.Results.AdditionalFields.Relationships.EntityB The recipient or target entity in a relationship involving the file. String
FileEnrichment.Results.AdditionalFields.Relationships.Relationship Defines the type or nature of the relationship between entities. String
FileEnrichment.Results.AdditionalFields.Relationships.EntityAType The type or classification of the initiating entity. String
FileEnrichment.Results.AdditionalFields.Relationships.EntityBType The type or classification of the recipient entity. String
FileEnrichment.Results.AdditionalFields.Signature.Authentihash The Authentihash, a cryptographic hash, used for verifying the file’s authenticity. String
FileEnrichment.Results.AdditionalFields.Signature.Description Describes the file signature data relevant to identification. String
FileEnrichment.Results.AdditionalFields.Signature.FileVersion Indicates the version number of the file. String
FileEnrichment.Results.AdditionalFields.Signature.InternalName The internal name of the file as designated by the creators. String
FileEnrichment.Results.AdditionalFields.Signature.OriginalName The original name of the file before any changes or renames. String
FileEnrichment.Results.AdditionalFields.Tags Tags assigned to the file for categorization or identification. Array
FileEnrichment.Results.AdditionalFields.ThreatTypes Threat types associated with the file. Unknown
FileEnrichment.Results.AdditionalFields.TrafficLightProtocol Specifies the TLP color designation suitable for handling the file. String
FileEnrichment.Results.AdditionalFields.Type The file type determined by libmagic. String
Core.AnalyticsPrevalence.Hash.value Whether the hash is prevalent or not. Boolean
Core.AnalyticsPrevalence.Hash.data.global_prevalence.value The global prevalence of the hash. Number
Core.AnalyticsPrevalence.Hash.data.local_prevalence.value The local prevalence of the hash. Number
Core.AnalyticsPrevalence.Hash.data.prevalence.value The prevalence of the hash. Number
args:
- description: 'A comma-separated list of File hashes to enrich. Supported types are: MD5, SHA1, SHA256, and SHA512.'
  name: file_hash
  required: true
  isArray: true
- name: external_enrichment
  description: |
    "Whether to call external integrations for enrichment:
    - 'true': enrich using all enabled integrations (e.g., VirusTotal (API v3), AlienVault OTX v2).
    - 'false': Will enrich using only WildFire-v2 if available; skip external integrations.
    If the 'brands' argument is provided, this flag is ignored and enrichment is run only on the brands provided."
  auto: PREDEFINED
  predefined:
  - 'true'
  - 'false'
  defaultValue: 'false'
  required: false
- name: verbose
  description: Retrieve a human-readable entry for each command; if false, only the final result is summarized.
  auto: PREDEFINED
  predefined:
  - 'true'
  - 'false'
  defaultValue: 'false'
  required: false
- name: brands
  description: |
    A list of integration brands to run enrichment against.  
    Example: `"AlienVault OTX v2", "WildFire-v2"`.  
    - If provided, only the selected brands are used. 
    - If left empty, the script runs enrichment on all enabled integrations,
      depending on the `external_enrichment` flag.
    - In order to run core-get-hash-analytics-prevalence, add Cortex Core - IR to the brands list (will run only on SHA256 values).
    To see the available brands for the `file` command, run: `!ProvidesCommand command=file`.
  isArray: true
  required: false
- name: additional_fields
  description: |
    When set to true, the output includes an `AdditionalFields` object
    for each of the indicator results.  
    `AdditionalFields` contains all fields returned by TIM or the integrations
    that are not part of the standard output keys (see the documentation for the full list of standard keys).
    When set to false, only the standard keys are returned.
  auto: PREDEFINED
  predefined:
  - 'true'
  - 'false'
  required: false
  defaultValue: 'false'
comment: 'Enriches File indicators with reputation data from multiple integrations and outputs a consolidated FileEnrichment object. This script exclusively supports indicators of type File and will automatically create the indicator in TIM if it is not already exists. Note: The script runs core-get-hash-analytics-prevalence on SHA256 values only.'
commonfields:
  id: file-enrichment
  version: -1
enabled: false
name: file-enrichment
outputs:
# FileEnrichment
- contextPath: FileEnrichment.Value
  description: The File hash from the input Value.
  type: String
- contextPath: FileEnrichment.Hashes.MD5
  description: The file MD5 hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.SHA1
  description: The file SHA1 hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.SHA256
  description: The file SHA256 hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.SHA512
  description: The file SHA512 hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.CRC32
  description: The file CRC32 hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.CTPH
  description: The file CTPH hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.SSDeep
  description: The file SSDeep hash if exists.
  type: String
- contextPath: FileEnrichment.Hashes.ImpHash
  description: The file ImpHash hash if exists.
  type: String
- contextPath: FileEnrichment.MaxScore
  description: The max score of all the indicators found.
  type: Number
- contextPath: FileEnrichment.MaxVerdict
  description: The max verdict of all the indicators found.
  type: String
- contextPath: FileEnrichment.Results
  description: List of all indicators found for the File.
  type: Array
- contextPath: FileEnrichment.TIMScore
  description: The TIM score of the File.
  type: Number
- contextPath: FileEnrichment.Status
  description: 'The status of the indicator: "Manual" if the score was changed manually, "Fresh" if modified within the last week, "Stale" if modified more than a week ago, "Error" if enrichment Failed, and "None" if never modified.'
  type: string
- contextPath: FileEnrichment.Message
  description: The error message explaining the reason for the failure (e.g., "Invalid", "createIndicator failed", etc.).
  type: string
- contextPath: FileEnrichment.ModifiedTime
  description: The time the indicator was last modified.
  type: Date
# FileEnrichment Main Keys
- contextPath: FileEnrichment.Results.Brand
  description: The brand of the indicator.
  type: String
- contextPath: FileEnrichment.Results.Score
  description: The score of the indicator.
  type: Number
- contextPath: FileEnrichment.Results.Size
  description: The size of the file, expressed in bytes.
  type: Number
- contextPath: FileEnrichment.Results.Verdict
  description: The verdict of the indicator.
  type: String
- contextPath: FileEnrichment.Results.DetectionEngines
  description: The detection engines of the indicator.
  type: Number
- contextPath: FileEnrichment.Results.PositiveDetections
  description: The positive detections of the indicator.
  type: Number
- contextPath: FileEnrichment.Results.MD5
  description: The file MD5 hash if exists.
  type: String
- contextPath: FileEnrichment.Results.SHA1
  description: The file SHA1 hash if exists.
  type: String
- contextPath: FileEnrichment.Results.SHA256
  description: The file SHA256 hash if exists.
  type: String
- contextPath: FileEnrichment.Results.SHA512
  description: The file SHA512 hash if exists.
  type: String
- contextPath: FileEnrichment.Results.CRC32
  description: The file CRC32 hash if exists.
  type: String
- contextPath: FileEnrichment.Results.CTPH
  description: The file CTPH hash if exists.
  type: String
- contextPath: FileEnrichment.Results.SSDeep
  description: The file SSDeep hash if exists.
  type: String
- contextPath: FileEnrichment.Results.ImpHash
  description: The file ImpHash hash if exists.
  type: String
- contextPath: FileEnrichment.Results.Reliability
  description: The reliability of the Brand.
  type: String
# FileEnrichment Additional Fields
- contextPath: FileEnrichment.Results.AdditionalFields.Name
  description: The name of the file including its extension.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.EntryID
  description: The identifier used to locate the file in the Incident War Room.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Actor
  description: The threat actor associated with the file, if applicable.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.behavior.details
  description: A brief description of the behavior exhibited by the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.behavior.title
  description: A brief description of the behavior exhibited by the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Campaign
  description: The identified campaign associated with the file, if applicable.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.CommunityNotes.note
  description: Community-contributed notes regarding observations or findings related to the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.CommunityNotes.timestamp
  description: The timestamp when the community note was added.
  type: Date
- contextPath: FileEnrichment.Results.AdditionalFields.Company
  description: The name of the company that released a binary.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.DigitalSignature.Publisher
  description: The entity that issued the digital signature of the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Extension
  description: The file extension, indicating the type of file format, for example, 'exe'.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.FeedRelatedIndicators.value
  description: Shows other indicators associated with the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.FeedRelatedIndicators.type
  description: Identifies the types of associated indicators.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.FeedRelatedIndicators.description
  description: Describes the associated indicators providing context or relevance.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.FirstSeenBySource
  description: The first time seen by the source brand.
  type: Date
- contextPath: FileEnrichment.Results.AdditionalFields.GlobalPrevalence
  description: The global prevalence of the file hash.
  type: Number
- contextPath: FileEnrichment.Results.AdditionalFields.Hostname
  description: The hostname of the device where the file was found.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.LastSeenBySource
  description: The last time seed by the source brand.
  type: Date
- contextPath: FileEnrichment.Results.AdditionalFields.Malicious.Vendor
  description: Specifies the vendor that identified the file as malicious.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Malicious.Description
  description: For malicious files, the reason that the vendor made the decision.
- contextPath: FileEnrichment.Results.AdditionalFields.Malicious.Detections
  description: For malicious files, the total number of detections.
- contextPath: FileEnrichment.Results.AdditionalFields.Malicious.TotalEngines
  description: For malicious files, the total number of engines that checked the file hash.
- contextPath: FileEnrichment.Results.AdditionalFields.VTVendors.EngineDetections
  description: Number of VT vendors that flagged the file as malicious.
- contextPath: FileEnrichment.Results.AdditionalFields.VTVendors.EngineVendors
  description: VT vendors who flagged the file as malicious.
- contextPath: FileEnrichment.Results.AdditionalFields.VTVendors.EngineDetectionNames
  description: VT detection names that flagged the file as malicious.
- contextPath: FileEnrichment.Results.AdditionalFields.MalwareFamily
  description: Names the malware family associated with the file, if known.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Organization
  description: The organization to which the file is attributed.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.OrganizationFirstSeen
  description: The date and time when the indicator was first seen in the organization.
  type: Date
- contextPath: FileEnrichment.Results.AdditionalFields.OrganizationLastSeen
  description: The date and time when the indicator was last seen in the organization.
  type: Date
- contextPath: FileEnrichment.Results.AdditionalFields.OrganizationPrevalence
  description:  The number of times the indicator is detected in the organization.
  type: Number
- contextPath: FileEnrichment.Results.AdditionalFields.ProductName
  description: The file product name.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Publications.source
  description: Identifies the publishing source of an article relating to the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Publications.title
  description: Identifies the publishing source of an article relating to the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Publications.link
  description: Provides a hyperlink to the full article or publication for detailed information.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Publications.timestamp
  description: Publications.timestamp
  type: Date
- contextPath: FileEnrichment.Results.AdditionalFields.Quarantined
  description: Indicates whether the file has been quarantined to prevent potential harm.
  type: Bool
- contextPath: FileEnrichment.Results.AdditionalFields.Relationships.EntityA
  description: The initiating entity in a relationship involving the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Relationships.EntityB
  description: The recipient or target entity in a relationship involving the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Relationships.Relationship
  description: Defines the type or nature of the relationship between entities.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Relationships.EntityAType
  description: The type or classification of the initiating entity.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Relationships.EntityBType
  description: The type or classification of the recipient entity.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Signature.Authentihash
  description: The Authentihash, a cryptographic hash, used for verifying the file's authenticity.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Signature.Description
  description: Describes the file signature data relevant to identification.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Signature.FileVersion
  description: Indicates the version number of the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Signature.InternalName
  description: The internal name of the file as designated by the creators.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Signature.OriginalName
  description: The original name of the file before any changes or renames.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Tags
  description: Tags assigned to the file for categorization or identification.
  type: Array
- contextPath: FileEnrichment.Results.AdditionalFields.ThreatTypes
  description: Threat types associated with the file.
  type: Unknown
- contextPath: FileEnrichment.Results.AdditionalFields.TrafficLightProtocol
  description: Specifies the TLP color designation suitable for handling the file.
  type: String
- contextPath: FileEnrichment.Results.AdditionalFields.Type
  description: The file type determined by libmagic.
  type: String
# Core
- contextPath: Core.AnalyticsPrevalence.Hash.value
  description: Whether the hash is prevalent or not.
  type: Boolean
- contextPath: Core.AnalyticsPrevalence.Hash.data.global_prevalence.value
  description: The global prevalence of the hash.
  type: Number
- contextPath: Core.AnalyticsPrevalence.Hash.data.local_prevalence.value
  description: The local prevalence of the hash.
  type: Number
- contextPath: Core.AnalyticsPrevalence.Hash.data.prevalence.value
  description: The prevalence of the hash.
  type: Number
script: '-'
system: false
tags:
- basescript
timeout: '0'
type: python
subtype: python3
marketplaces:
- xsoar_saas
- marketplacev2
- platform
dockerimage: demisto/python3:3.12.13.10116658
fromversion: 8.0.0
tests:
- FileEnrichment - Test