category: Data Enrichment & Threat Intelligence provider: Broadcom commonfields: id: Symantec Deepsight Intelligence version: -1 configuration: - defaultvalue: https://deepsightapi.accenture.com/v1 display: Base URL name: url required: true type: 0 - display: API Key name: apikey required: true type: 4 - display: Use system proxy settings name: proxy type: 8 required: false - display: Trust any certificate (not secure) name: unsecure type: 8 required: false description: Deprecated. Use ACTI Vulnerability Query instead. display: Accenture Deepsight Intelligence (Deprecated) name: Symantec Deepsight Intelligence script: commands: - arguments: - default: true description: ip to be enriched. name: ip required: true description: Enrich an IP address from Symantec Deepsight Intelligence name: ip outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: IP.Address description: The IP Address type: string - contextPath: Deepsight.IP.Address description: The IP Address type: string - contextPath: IP.ASN description: The IP's ASN type: number - contextPath: Deepsight.IP.ASN description: The IP's ASN type: number - contextPath: IP.Geo.Country description: The IP's country type: string - contextPath: Deepsight.IP.Geo.Country description: The IP's country type: string - contextPath: IP.Geo.City description: The IP's city type: string - contextPath: Deepsight.IP.Geo.City description: The IP's city type: string - contextPath: IP.Geo.Location description: The IP's latitude and longtitude type: string - contextPath: Deepsight.IP.Geo.Location description: The IP's latitude and longtitude type: string - contextPath: Deepsight.IP.Whitelisted description: Is the IP on allow list type: boolean - contextPath: Deepsight.IP.FirstSeen description: When was the IP first seen type: date - contextPath: Deepsight.IP.LastSeen description: When was the IP last seen type: date - contextPath: Deepsight.IP.ProxyType description: The type of the IP's proxy type: string - contextPath: Deepsight.IP.Behaviours description: Behaviours of the IP type: Unknown - contextPath: Deepsight.IP.Domain description: The domain associated with the IP address type: string - contextPath: Deepsight.IP.TargetCountries description: Three-letter ISO3 code representing a country associated with the IP address's activity type: Unknown - contextPath: Deepsight.IP.Report.ID description: The MATI report identification number type: string - contextPath: Deepsight.IP.Report.Title description: The MATI report identification title type: string - contextPath: Deepsight.IP.Report.Date description: The MATI report identification date type: date - contextPath: Deepsight.IP.ReputationValues.Reputation description: A value that combines an item's behaviors exhibited, confidence in the listing, hostility of the item, consecutive listings and listing ratio; values range from 1 to 10 with higher values representing a worse reputation type: number - contextPath: Deepsight.IP.ReputationValues.Confidence description: Shows our confidence on whether the listing is correct or a false positive with values ranging from 1 to 5 with higher values representing more confidence in the listing type: number - contextPath: Deepsight.IP.ReputationValues.Hostility description: Enumerates the IP address hostility level with values ranging from 1 to 5 with higher values representing a more hostile item type: number - contextPath: IP.Malicious.Description description: Description of the malicious IP type: string - contextPath: Deepsight.IP.Malicious.Description description: Description of the malicious IP type: string - contextPath: IP.Malicious.Vendor description: Vendor of the data about the malicious IP type: string - contextPath: Deepsight.IP.Malicious.Vendor description: Vendor of the data about the malicious IP type: string - arguments: - default: true description: Domain to enrich name: domain required: true description: Enrich a domain from Symantec Deepsight intelligence name: domain outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: Domain.Name description: The domain itself type: string - contextPath: Deepsight.Domain.Name description: The domain itself type: string - contextPath: Domain.WHOIS.CreationDate description: The creation date of the domain type: date - contextPath: Deepsight.Domain.WHOIS.CreationDate description: The creation date of the domain type: date - contextPath: Domain.WHOIS.UpdatedDate description: The last update date of the domain type: date - contextPath: Deepsight.Domain.WHOIS.UpdatedDate description: The last update date of the domain type: date - contextPath: Domain.WHOIS.ExpirationDate description: The expiration date of the domain type: date - contextPath: Deepsight.Domain.WHOIS.ExpirationDate description: The expiration date of the domain type: date - contextPath: Domain.WHOIS.NameServers description: An array of name servers associated with the registered person in the whois record type: string - contextPath: Deepsight.Domain.WHOIS.NameServers description: An array of name servers associated with the registered person in the whois record type: string - contextPath: Domain.WHOIS.Registrar.Name description: The name of the domain's registrar type: string - contextPath: Deepsight.Domain.WHOIS.Registrar.Name description: The name of the domain's registrar type: string - contextPath: Domain.WHOIS.Registrant.Name description: The name of the domain's registrant type: string - contextPath: Deepsight.Domain.WHOIS.Registrant.Name description: The name of the domain's registrant type: string - contextPath: Domain.WHOIS.Registrant.Email description: The email of the domain's registrant type: string - contextPath: Deepsight.Domain.WHOIS.Registrant.Email description: The email of the domain's registrant type: string - contextPath: Deepsight.Domain.Whitelisted description: Indicates whether the domain is on allow list type: boolean - contextPath: Deepsight.Domain.FirstSeen description: The time and date that the domain first appeared in the database type: date - contextPath: Deepsight.Domain.LastSeen description: The time and date that the domain last appeared in the database type: date - contextPath: Deepsight.Domain.ReputationValues.Reputation description: A value that combines an item's behaviors exhibited, confidence in the listing, hostility of the item, consecutive listings and listing ratio; values range from 1 to 10 with higher values representing a worse reputation type: number - contextPath: Deepsight.Domain.ReputationValues.Confidence description: Shows our confidence on whether the listing is correct or a false positive with values ranging from 1 to 5 with higher values representing more confidence in the listing type: number - contextPath: Deepsight.Domain.ReputationValues.Hostility description: 'Enumerates the IP address hostility level with values ranging from 1 to 5 with higher values representing a more hostile item' type: string - contextPath: Deepsight.Domain.Domain description: The domain itself type: string - contextPath: Deepsight.Domain.TargetCountries description: Three-letter ISO3 code representing a country associated with the domain's activity type: unknown - contextPath: Deepsight.Domain.Report.ID description: The MATI report identification number type: number - contextPath: Deepsight.Domain.Report.Title description: The MATI report title type: string - contextPath: Deepsight.Domain.Report.Date description: The MATI report creation date type: date - contextPath: Deepsight.Domain.Behaviour.Type description: A subcategory of behaviour type: string - contextPath: Deepsight.Domain.Behaviour.Behaviour description: 'Indicates that the domain has been observed as part of a specific activity: Attack, Bot, CnC, Fraud, Malware, Phish_host, or Spam' type: string - contextPath: Deepsight.Domain.Behaviour.Description description: A description of the activity observed type: Unknown - contextPath: Domain.Malicious.Description description: Description of the malicious domain type: string - contextPath: Deepsight.Domain.Malicious.Description description: Description of the malicious domain type: string - contextPath: Domain.Malicious.Vendor description: Vendor of the malicious domain type: string - contextPath: Deepsight.Domain.Malicious.Vendor description: Vendor of the malicious domain type: string - arguments: - default: true description: sha256 or md5 hash only name: file required: true description: Enrich a file from Symantec Deepsight Intelligence name: file outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: File.MD5 description: The MD5 hash string type: string - contextPath: Deepsight.File.MD5 description: The MD5 hash string type: string - contextPath: File.SHA256 description: The SHA256 hash string type: string - contextPath: Deepsight.File.SHA256 description: The SHA256 hash string type: string - contextPath: Deepsight.File.Report.ID description: ' The MATI report ID' type: string - contextPath: Deepsight.File.Report.Title description: ' The MATI report title' type: string - contextPath: Deepsight.File.Report.Date description: ' The MATI report date' type: date - contextPath: File.Malicious.Description description: The description of the malicious file, including it's reputation (if found in Deepsight data) type: string - contextPath: Deepsight.File.Malicious.Description description: The description of the malicious file, including it's reputation (if found in Deepsight data) type: string - contextPath: File.Malicious.Vendor description: The vendor of the data about the malicious file type: string - contextPath: Deepsight.File.Malicious.Vendor description: The vendor of the data about the malicious file type: string - arguments: - default: true description: URL to enrich, Should contain HTTP(S):// name: url required: true description: Enrich an URL from Symantec Deepsight Intelligence name: url outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: URL.Data description: The URL itself type: string - contextPath: Deepsight.URL.Data description: The URL itself type: string - contextPath: URL.Malicious.Description description: Description of the malicious URL type: string - contextPath: Deepsight.URL.Malicious.Description description: Description of the malicious URL type: string - contextPath: URL.Malicious.Vendor description: The vendor of the data about the malicious URL type: string - contextPath: Deepsight.URL.Malicious.Vendor description: The vendor of the data about the malicious URL type: string - description: Get API Usage status for current license period name: deepsight-get-request-status dockerimage: demisto/python:2.7.18.24398 runonce: false script: '-' subtype: python2 type: python tests: - No test beta: true fromversion: 5.0.0 deprecated: true