from CommonServerPython import * from FeedCiscoSecureMalwareAnalytics import Client, create_entity_relationships, fetch_indicators, fetch_indicators_command from test_data.feed_data import banking_dns_response, sinkholed_ip_dns_response def test_fetch_indicators(requests_mock): """Unit test Given - fetch incidents command - feed name - command raw response When - run the fetch indicators command. Then - Validate creates indicators and unifies if they are the same """ first_fetch = arg_to_datetime(arg="today", arg_name="First fetch") client = Client( api_key="1234", verify=False, proxy=False, feed_name=["sinkholed-ip-dns"], first_fetch=first_fetch, tlp_color="", feed_tags="", create_relationships=True, ) requests_mock.get( f"https://panacea.threatgrid.com/api/v3/feeds/sinkholed-ip-dns.json?api_key={client._api_key}", json=sinkholed_ip_dns_response, ) indicators, status = fetch_indicators(client, None) assert len(indicators) == 15 def test_fetch_indicators_command_list(requests_mock, mocker): """Unit test Given - fetch incidents command - list of feed names - command raw response When - run the fetch indicators command with 2 feed names. Then - Validate creates indicators and unifies if they are the same _ Validate that the fields: 'FeedRelatedIndicators' and 'tags' have been updated properly """ first_fetch = arg_to_datetime(arg="today", arg_name="First fetch") client = Client( api_key="1234", verify=False, proxy=False, feed_name=["sinkholed-ip-dns", "banking-dns"], first_fetch=first_fetch, tlp_color="", feed_tags="", create_relationships=True, ) requests_mock.get( f"https://panacea.threatgrid.com/api/v3/feeds/sinkholed-ip-dns.json?api_key={client._api_key}", json=sinkholed_ip_dns_response, ) requests_mock.get( f"https://panacea.threatgrid.com/api/v3/feeds/banking-dns.json?api_key={client._api_key}", json=banking_dns_response, ) a = mocker.patch.object(demisto, "createIndicators") fetch_indicators_command(client) fetch_indicators_command(client) for indicator in a.call_args.args[0]: if indicator["value"] == "Example1.com": assert len(indicator["fields"]["FeedRelatedIndicators"]) == 14 assert len(indicator["relationships"]) == 14 assert len(indicator["fields"]["Tags"]) == 2 if indicator["value"] == "Example3.com": assert len(indicator["fields"]["FeedRelatedIndicators"]) == 4 assert len(indicator["relationships"]) == 4 assert len(indicator["fields"]["Tags"]) == 1 assert len(a.call_args.args[0]) == 28 def test_create_entity_relationships(): """ Given - indicator domain name - related indicators When - run the fetch incidents command Then - Validate created relationships """ domain_name = "test.com" relevant_indicators = [{"type": "IP", "value": "1.1.1.1"}] relationships = create_entity_relationships(relevant_indicators, domain_name) assert relationships[0].get("entityB") == "1.1.1.1" assert relationships[0].get("entityBType") == "IP" assert relationships[0].get("entityA") == "test.com" assert relationships[0].get("entityAType") == "Domain" def test_get_indicators_success(requests_mock): """ Given a Client instance, valid key and a timestamp value When get_indicators is called Then the expected indicators are returned """ client = Client("api_key", False, False, "first_fetch", ["feed"], "", "", False) requests_mock.get("https://panacea.threatgrid.com/api/v3/feeds/feed.json", json={"indicators": ["1.1.1.1"]}) indicators = client.get_indicators("feed", None) assert indicators == {"indicators": ["1.1.1.1"]} def test_get_indicators_with_timestamp(requests_mock): """ Given a Client instance and a timestamp value When get_indicators is called with the timestamp Then the expected indicators are returned """ client = Client("api_key", False, False, "first_fetch", ["feed"], "", "", False) requests_mock.get("https://panacea.threatgrid.com/api/v3/feeds/feed_timestamp.json", json={"indicators": ["1.1.1.1"]}) indicators = client.get_indicators("feed", "timestamp") assert indicators == {"indicators": ["1.1.1.1"]}