category: Forensics & Malware Analysis provider: Fortinet commonfields: id: FortiSandbox version: -1 deprecated: true configuration: - additionalinfo: URL of the Fortisandbox server. display: Server URL name: server required: true type: 0 - display: Credentials name: credentials required: true type: 9 - additionalinfo: By default SSL certification validation is enabled. defaultvalue: "true" display: Trust any certificate (not secure) name: secure type: 8 required: false description: FortiSandbox integration is used to submit files to FortiSandbox for malware analysis and retrieving the report of the analysis. It can also provide file rating based on hashes for already scanned files. Deprecated. Use FortiSandboxv2 instead. display: FortiSandbox (Deprecated) name: FortiSandbox script: commands: - arguments: - description: SHA-256 Checksum to check the rating name: checksum required: true description: Get file rating of SHA-256 Checksum name: fortisandbox-simple-file-rating-sha256 - arguments: - description: SHA-1 Checksum to check the rating name: checksum required: true description: Get File Rating of SHA-1 checksum name: fortisandbox-simple-file-rating-sha1 - arguments: - description: Comma separated URLs to get url rating name: url required: true description: Get URL Rating from FortiSandbox name: fortisandbox-url-rating - arguments: - description: Checksum value to query name: checksum required: true - auto: PREDEFINED description: Type of checksum - sha1 or sha256 name: checksum_type predefined: - sha1 - sha256 required: true description: Query file's verdict through its checksum (returns JSON) name: fortisandbox-get-file-verdict-detailed - arguments: - description: Entry ID of the file to upload name: file_entry_id required: true - description: Password for archived/zipped files name: archive_password - description: VMs to scan the File on, comma seperated. (Ex.WIN7X86VM,WINXPVM) name: vm_csv_list - description: Do not use this parameter if no step to skip. 1 = Skip AV, 2= Skip Cloud, 4= Skip sandboxing, 8= Skip Static Scan. name: skip_steps - defaultValue: "0" description: Set the value as "1" to require to add the sample to malware package if it satisfy the malware critia. By default, the value is "0". name: malpkg - description: File SHA-256 used to get scan report name: sha256 required: true description: Upload file (on-demand submit) name: fortisandbox-upload-file outputs: - contextPath: FortiSandbox.Upload.SubmissionId description: Submission ID of file submission type: string - contextPath: FortiSandbox.Upload.FileName description: File Uploaded type: string - contextPath: FortiSandbox.Upload.SHA256 description: SHA256 of uploaded file used for getting report type: string - contextPath: FortiSandbox.Upload.Status description: Scan status type: string - arguments: - description: Scan Job ID for file name: job_id required: true description: Query File Scan verdict from FortiSandbox based on Job ID name: fortisandbox-query-job-verdict - arguments: - description: Submission ID of uploaded file to scan name: submission_id required: true description: Get Job IDs from an uploaded Submission using the submission ID name: fortisandbox-jobid-from-submission outputs: - contextPath: FortiSandbox.Upload.Status description: scan status type: string - contextPath: FortiSandbox.Upload.JobIds description: job ids for submission type: string - arguments: - auto: PREDEFINED description: Select query method - job ID or sha256 name: query_type predefined: - jid - sha256 required: true - description: Enter query value - job ID value or Sha256 hash of the file name: query_value required: true description: Get PDF Report of scanned item name: fortisandbox-get-pdf-report - arguments: - description: Comma seperated url values name: urls required: true description: Upload CSV URLs name: fortisandbox-upload-urls dockerimage: demisto/python3:3.10.12.63474 runonce: true script: '' subtype: python3 type: python fromversion: 6.0.0 tests: - No tests (auto formatted)