import demistomock as demisto import Malwarebytes from Malwarebytes import ( REGION_URLS, close_sa_incident, deisolate_endpoint, fetch_incidents, get_sa_activities_command, isolate_desktop, isolate_endpoint, isolate_network, isolate_process, list_all_endpoints, list_endpoint_info, main, nebula_url, open_sa_incident, remediate_sa_incident, scan_and_remediate, scan_and_report, scan_detections, scan_status, ) auth_token = "vATEZGHAxu5AoNzZZSR7URcnREqxaHcxGlZy0_3M8aU.j3KdAUwntnzvcjE4-UdVORUGvnR4eBVITn6KxoblFYc" account_id = "XXX-XXX-XXX-XXXX--XXXX" client_id = "NB-XXX-XXXX1234-1234" MOCK_ENDPOINTS = "https://cloud.threatdown.com/api/v2/endpoints" MOCK_ENDPOINT_MACHINE_ID = "https://cloud.threatdown.com/api/v2/endpoints" USE_SSL = False MOCK_ENDPOINT_MACHINE_ID_RESP = { "aggregations": {}, "machines": [ { "link": "/api/v2/machines/8c9df179-a999-4ca2-9c41-9795ae0b08f5", "agent": { "started_at_offset": 0, "last_user": "WIN-TEN8D4FCOUB\\Administrator", "at": "2020-01-01T04:20:49.784113Z", "account_id": "56db16b7-7bcd-404b-9443-f4ed95044c64", "group_id": "57b6dbcd-8243-4f52-b80a-7c102c6b06d3", "nics": [ { "ips": ["192.168.230.140"], "description": "Intel(R) 82574L Gigabit Network Connection #2", "mac_address": "000C29D7A627", }, { "ips": ["172.16.128.100"], "description": "Intel(R) 82574L Gigabit Network Connection", "mac_address": "000C29D7A631", }, ], "os_info": { "os_type": "Server", "os_version": "6.3.9600", "os_platform": "Windows", "os_architecture": "Amd64", "os_release_name": "Microsoft Windows Server 2012 R2 Standard", }, "host_name": "WIN-TEN8D4FCOUB", "fully_qualified_host_name": "WIN-TEN8D4FCOUB", "plugins": { "asset_manager": {"product_name": "Asset Manager", "plugin_version": "1.2.0.329"}, "endpoint_detection_and_response": { "product_name": "Endpoint Detection and Response", "plugin_version": "1.2.0.282", }, }, "engine_version": "1.2.0.726", "policy_etag": "ae2dccc2e3eaa8b33d10f577f76ddc29", }, "machine": { "id": "8c9df179-a999-4ca2-9c41-9795ae0b08f5", "online": False, "account_id": "56db16b7-7bcd-404b-9443-f4ed95044c64", "group_id": "57b6dbcd-8243-4f52-b80a-7c102c6b06d3", "root_group_id": "57b6dbcd-8243-4f52-b80a-7c102c6b06d3", "group_name": "Asia-Group-ServerEPR", "policy_id": "2336247b-a41a-4f9c-8bf8-2e45e6cd41ff", "policy_name": "Asia-ServerEPR-Policy", "last_day_seen": "2020-01-01T04:03:36.046972Z", "isolated": False, "scan_age_days": 2147483647, "suspicious_activity_count": 55, "infection_count": 0, "reboot_required": 0, "is_deleted": False, }, } ], "total_count": 1, "next_cursor": "", } MOCK_HOSTNAME = "WIN-TEN8D4FCOUB" MOCK_IP = "192.168.1.1" MOCK_MACHINES_DATA = { "machines": [ { "created_at": "2020-02-05T10:12:55.187467Z", "id": "017febb6-ae68-4c15-9918-d911c72d062a", "last_seen_at": "2020-02-26T16:36:17.352342Z", "name": "TA-AZ-CLT1", "online": True, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Pro", }, { "created_at": "2020-02-05T09:50:02.194556Z", "id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "last_seen_at": "2020-03-11T11:00:24.746133Z", "name": "WIN-TEN8D4FCOUB", "online": False, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Enterprise", }, { "created_at": "2019-11-25T19:47:15.833008Z", "id": "b5740188-00a2-434b-a180-5b0fa85cb10b", "last_seen_at": "2020-02-27T15:36:33.68981Z", "name": "DESKTOP-91UJNA1", "online": False, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Pro", }, { "created_at": "2019-10-18T09:26:26.993555Z", "id": "5074ade3-5716-44d8-83c7-5985379c0399", "last_seen_at": "2020-03-05T13:17:15.459352Z", "name": "DESKTOP-664HFM6", "online": False, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Pro", }, ], "total_count": 4, "next_cursor": "", } MOCK_ENDPOINTS_JOBS = "https://cloud.threatdown.com/api/v2" MOCK_POST_JOBS_DATA = { "jobs": [{"machine_id": "8c9df179-a999-4ca2-9c41-9795ae0b08f5", "job_id": "aa104324-6d2f-4023-bfa6-78fc76d67200"}], "total_count": 1, } MOCK_JOBS_MACHINE_ID = "8c9df179-a999-4ca2-9c41-9795ae0b08f5" MOCK_SCAN_ID = "d6d46617-b99c-4758-aad2-0f8235c43d58" MOCK_JOBS_JOB_ID = "aa104324-6d2f-4023-bfa6-78fc76d67200" MOCK_ENDPOINT_JOBS_OUTPUT = { "Malwarebytes.Scan(val.Job_ID == obj.Job_ID)": {"Machine_ID": MOCK_JOBS_MACHINE_ID, "Job_ID": MOCK_JOBS_JOB_ID} } MOCK_GET_JOBS_DATA = { "id": "554e6e03-6a31-4007-aee8-954e88093ef0", "machine_id": "8c9df179-a999-4ca2-9c41-9795ae0b08f5", "machine_name": "DESKTOP-LI4MQ7B", "command": "command.threat.scan", "issued_at": "2020-03-17T14:02:26.562283Z", "issued_by": "54a39a8b-e368-4359-bf74-8358f8d4fc11", "expires_at": "2020-03-20T14:02:26.562285Z", "updated_at": "2020-03-17T14:12:09.230305Z", "state": "COMPLETED", "relay_state": "3fd16624-9d54-4e15-9d07-c222327d19fe", "scan_id": "d6d46617-b99c-4758-aad2-0f8235c43d58", } MOCK_DETECTIONS_PATH = MOCK_ENDPOINT_MACHINE_ID + "/" + MOCK_JOBS_MACHINE_ID + "/scans/" + MOCK_SCAN_ID + "/detections" MOCK_SCAN_DETECTIONS = { "detections": [ { "id": "f21ae327-8987-4d64-a0ed-12ffa5fdd7ba", "scan_id": "74f831d2-2871-4aa5-9030-60ce7247d23a", "machine_id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "machine_name": "WIN-TEN8D4FCOUB", "group_id": "a8fbe175-6b71-443c-b906-f18d06c7faf6", "detection_id_from_endpoint": "0bd77668-5106-11ea-8531-000c29541586", "scanned_at": "2020-02-16T21:39:20Z", "scanned_at_local": "2020-02-16T13:39:20-08:00", "reported_at": "2020-02-16T21:50:02.358811Z", "status": "quarantined", "threat_name": "Trojan.Agent.SVR", "type": ["file"], "path": "C:\\USERS\\WIN-BOX2\\DESKTOP\\711.RAR", "category": "Malware", "ip_address": "", "url": "", "port": "", "affected_application": "", "md5": "", "process_name": "", }, { "id": "f8707f3f-184c-4388-980f-5c2b4639c7ce", "scan_id": "eeb99e04-ae61-47f7-bfbf-8e023fdfffe2", "machine_id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "machine_name": "WIN-TEN8D4FCOUB", "group_id": "a8fbe175-6b71-443c-b906-f18d06c7faf6", "detection_id_from_endpoint": "df7bdca4-503c-11ea-8339-000c29541586", "scanned_at": "2020-02-15T21:39:19Z", "scanned_at_local": "2020-02-15T13:39:19-08:00", "reported_at": "2020-02-15T21:49:44.263558Z", "status": "quarantined", "threat_name": "Trojan.Agent.SVR", "type": ["file"], "path": "C:\\USERS\\WIN-BOX2\\DESKTOP\\711.RAR", "category": "Malware", "ip_address": "", "url": "", "port": "", "affected_application": "", "md5": "", "process_name": "", }, { "id": "6d76ebad-dfa3-47a8-8cac-a717fc09ae6d", "scan_id": "ab4623d7-9c07-46fc-95b1-d0d15c64e72b", "machine_id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "machine_name": "WIN-TEN8D4FCOUB", "group_id": "a8fbe175-6b71-443c-b906-f18d06c7faf6", "detection_id_from_endpoint": "c814b08c-4f73-11ea-9b36-000c29541586", "scanned_at": "2020-02-14T21:39:21Z", "scanned_at_local": "2020-02-14T13:39:21-08:00", "reported_at": "2020-02-14T22:00:57.806491Z", "status": "quarantined", "threat_name": "Trojan.ServStart", "type": ["file"], "path": "C:\\USERS\\WIN-BOX2\\DESKTOP\\518_2.EXE", "category": "Malware", "ip_address": "", "url": "", "port": "", "affected_application": "", "md5": "", "process_name": "", }, ], "total_count": 3, "next_cursor": "", } MOCK_SCAN_DETECTIONS_CLEAR = { "detections": [ { "machine_id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "machine_name": "WIN-TEN8D4FCOUB", "reported_at": "2020-02-16T21:50:02.358811Z", "status": "quarantined", "threat_name": "Trojan.Agent.SVR", "type": ["file"], "path": "C:\\USERS\\WIN-BOX2\\DESKTOP\\711.RAR", "category": "Malware", }, { "machine_id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "machine_name": "WIN-TEN8D4FCOUB", "reported_at": "2020-02-15T21:49:44.263558Z", "status": "quarantined", "threat_name": "Trojan.Agent.SVR", "type": ["file"], "path": "C:\\USERS\\WIN-BOX2\\DESKTOP\\711.RAR", "category": "Malware", }, { "machine_id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "machine_name": "WIN-TEN8D4FCOUB", "reported_at": "2020-02-14T22:00:57.806491Z", "status": "quarantined", "threat_name": "Trojan.ServStart", "type": ["file"], "path": "C:\\USERS\\WIN-BOX2\\DESKTOP\\518_2.EXE", "category": "Malware", }, ], "total_count": 3, "next_cursor": "", } MOCK_SA_CHOICE = "Suspicious Activity (EPR)" MOCK_SA_ENDPOINT = "https://cloud.threatdown.com/api/v2/sa" MOCK_RTP_CHOICE = "RTP Detections (EP)" MOCK_RTP_ENDPOINT = "https://cloud.threatdown.com/api/v2/detections/search" MOCK_SA_DATA = { "sa": [ { "detection_id_list": [34036085], "status": "detected", "timestamp": "2020-03-03T12:27:20.000Z", "path": "C:\\USERS\\ROHIN SAMBATH KUMAR\\DESKTOP\\MA2EZOX5\\EKATI5862.EXE", "pc_hostname": "DESKTOP-664HFM6", "machine_id": "5074ade3-5716-44d8-83c7-5985379c0399", "account_id": "2020bd17-a809-4102-b744-94fe8ad1c591", "level": 2, "detected_by_count": 1, } ], "total_count": 1, "next_cursor": "", } MOCK_SA_MACHINE_ID = "211d8c3e-142c-4849-b1f0-1680b4bd239c" MOCK_SA_DETECTION_ID = "23606836" MOCK_RTP_DETECTIONS_DATA = { "detections": [ { "id": "1ef4503a-a1d3-4072-adc0-a3113c68662b", "type": ["OutboundConnection"], "status": "blocked", "path": "iptest.malwarebytes.com(100.24.169.13:49792)", "group_id": "e61dd210-1fd1-443c-ae6d-6bc9240a562f", "is_root_detection": True, "machine_id": "e7f1475a-7e9a-409b-b7a9-ccf7e6e68779", "account_id": "56db16b7-7bcd-404b-9443-f4ed95044c64", "detection_id": "d0a49ab4-62f6-11ea-8d88-000c29286b23", "scanned_at": "2020-03-10T17:44:39Z", "scanned_at_offset_seconds": 0, "reported_at": "2020-03-10T17:44:40.42176888Z", "threat_name": "Malicious Website", "category": "MWAC", "is_rtp_stream_event": True, "process_name": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe", "cleaned_at": "0001-01-01T00:00:00Z", "machine_name": "Wampa.rebelbase.org", } ], "aggregations": {}, "total_count": 1, "next_cursor": "", } def test_scan_and_remediate_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the scan and remediate command. Then: - A scan job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS, json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") scan_and_remediate(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_scan_and_remediate_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the scan and remediate command. Then: - A scan job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS, json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") scan_and_remediate(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_scan_and_report_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the scan and report command. Then: - A scan job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS, json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") scan_and_report(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_scan_and_report_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the scan and report command. Then: - A scan job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS, json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") scan_and_report(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_endpoint_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the isolate endpoint command. Then: - An isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_endpoint(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_endpoint_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the isolate endpoint command. Then: - An isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_endpoint(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_process_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the isolate process command. Then: - A process isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_process(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_process_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the isolate process command. Then: - A process isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_process(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_desktop_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the isolate desktop command. Then: - A desktop isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_desktop(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_desktop_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the isolate desktop command. Then: - A desktop isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_desktop(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_network_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the isolate network command. Then: - A network isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_network(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_isolate_network_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the isolate network command. Then: - A network isolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/isolate", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") isolate_network(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_deisolate_endpoint_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address that is currently isolated. When: - Running the deisolate endpoint command. Then: - A deisolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/unlock", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") deisolate_endpoint(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_deisolate_endpoint_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname that is currently isolated. When: - Running the deisolate endpoint command. Then: - A deisolation job is created and the correct job output is returned. """ MOCK_ENDPOINT_POST_JOBS = "https://cloud.threatdown.com/api/v2/jobs" # patch the API endpoint requests_mock.post(MOCK_ENDPOINT_MACHINE_ID, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.post(MOCK_ENDPOINT_POST_JOBS + "/endpoints/unlock", json=MOCK_POST_JOBS_DATA, status_code=201) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") deisolate_endpoint(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_JOBS_OUTPUT def test_list_all_endpoints_all(requests_mock, mocker): """ Given: - A request to list all endpoints regardless of status. When: - Running the list endpoints command with endpoint filter set to 'all'. Then: - All endpoints are returned in the output. """ # patch the API endpoint requests_mock.get(MOCK_ENDPOINTS, json=MOCK_MACHINES_DATA) # patch the inputs mocker.patch.object(demisto, "args", return_value={"endpoints": "all"}) # patch the outputs mocker.patch.object(demisto, "results") # run the code endpoint = demisto.args().get("endpoints") list_all_endpoints(account_id, client_id, auth_token, endpoint, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_MACHINES_DATA["machines"]) == str(outputs["Contents"]) def test_list_all_endpoints_online(requests_mock, mocker): """ Given: - A request to list only online endpoints. When: - Running the list endpoints command with endpoint filter set to 'online'. Then: - Only online endpoints are returned in the output. """ MOCK_MACHINES_DATA_ONLINE = { "machines": [ { "created_at": "2020-02-05T10:12:55.187467Z", "id": "017febb6-ae68-4c15-9918-d911c72d062a", "last_seen_at": "2020-02-26T16:36:17.352342Z", "name": "TA-AZ-CLT1", "online": True, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Pro", } ] } # patch the API endpoint requests_mock.get(MOCK_ENDPOINTS, json=MOCK_MACHINES_DATA) # patch the inputs mocker.patch.object(demisto, "args", return_value={"endpoints": "online"}) # patch the outputs mocker.patch.object(demisto, "results") # run the code endpoint = demisto.args().get("endpoints") list_all_endpoints(account_id, client_id, auth_token, endpoint, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_MACHINES_DATA_ONLINE["machines"]) == str(outputs["Contents"]) def test_list_all_endpoints_offline(requests_mock, mocker): """ Given: - A request to list only offline endpoints. When: - Running the list endpoints command with endpoint filter set to 'offline'. Then: - Only offline endpoints are returned in the output. """ MOCK_MACHINES_DATA_OFFLINE = { "machines": [ { "created_at": "2020-02-05T09:50:02.194556Z", "id": "211d8c3e-142c-4849-b1f0-1680b4bd239c", "last_seen_at": "2020-03-11T11:00:24.746133Z", "name": "WIN-TEN8D4FCOUB", "online": False, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Enterprise", }, { "created_at": "2019-11-25T19:47:15.833008Z", "id": "b5740188-00a2-434b-a180-5b0fa85cb10b", "last_seen_at": "2020-02-27T15:36:33.68981Z", "name": "DESKTOP-91UJNA1", "online": False, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Pro", }, { "created_at": "2019-10-18T09:26:26.993555Z", "id": "5074ade3-5716-44d8-83c7-5985379c0399", "last_seen_at": "2020-03-05T13:17:15.459352Z", "name": "DESKTOP-664HFM6", "online": False, "os_architecture": "AMD64", "os_platform": "WINDOWS", "os_release_name": "Microsoft Windows 10 Pro", }, ] } # patch the API endpoint requests_mock.get(MOCK_ENDPOINTS, json=MOCK_MACHINES_DATA) # patch the inputs mocker.patch.object(demisto, "args", return_value={"endpoints": "offline"}) # patch the outputs mocker.patch.object(demisto, "results") # run the code endpoint = demisto.args().get("endpoints") list_all_endpoints(account_id, client_id, auth_token, endpoint, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_MACHINES_DATA_OFFLINE["machines"]) == str(outputs["Contents"]) def test_list_endpoint_info_hostname(requests_mock, mocker): """ Given: - An endpoint identified by hostname. When: - Running the get endpoint info command. Then: - The endpoint asset information is returned correctly. """ MOCK_ASSET_ID = "8c9df179-a999-4ca2-9c41-9795ae0b08f5" MOCK_ASSETS_RESPONSE = { "startups": [ { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Shell", "value": "explorer.exe", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "System", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Taskman", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Userinit", "value": "C:\\Windows\\system32\\userinit.exe,", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run", "name": "VMware User Process", "value": '"C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe" -n vmusr', }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad", "name": "WebCheck", "value": "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}", }, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Authentication Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Notification Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Security Packages"}, { "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders", "name": "SecurityProviders", "value": "credssp.dll, pwdssp.dll", }, ], "os_info": { "os_platform": "Windows", "os_architecture": "Amd64", "os_version": "6.3.9600", "os_release_name": "Microsoft Windows Server 2012 R2 Standard", "os_type": "Server", }, "memory": { "total_virtual": 2549530624, "free_virtual": 765550592, "total_physical": 2147483648, "free_physical": 873046016, }, "computer_info": {"manufacturer": "VMware, Inc.", "model": "VMware Virtual Platform"}, "software_installed": [ { "vendor": "Microsoft Corporation", "product": "Microsoft Help Viewer 2.2", "installed_date": "2019-01-07T16:00:00Z", "version": "2.2.23107", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Console", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 SDK", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51641", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.4148", }, { "vendor": "Microsoft Corporation", "product": "IIS 7.5 Express", "installed_date": "2016-12-04T16:00:00Z", "version": "7.5.1070", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 Policies ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2014 Management Objects ", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2000.8", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50710", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Endpoint Agent", "installed_date": "2019-11-15T16:00:00Z", "version": "1.2.0.717", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2014", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2402.11", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Data-Tier Application Framework (x86)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.4127.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Management Studio - 17.9.1", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23829", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Server", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015 Language Support", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.20", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Browser", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio 2015 Shell (Isolated)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.10", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 (64-bit)", "installed_date": "2016-12-05T16:00:00Z", "version": "", }, { "vendor": "VMware, Inc.", "product": "VMware Tools", "installed_date": "2016-12-04T16:00:00Z", "version": "10.0.10.4301679", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Native Client", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server VSS Writer", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2012 Native Client ", "installed_date": "2019-01-07T16:00:00Z", "version": "11.3.6540.0", }, { "vendor": "Microsoft Corporation", "product": "Active Directory Authentication Library for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.6161", }, { "vendor": "Malwarebytes", "product": "Malwarebytes version 3.8.4.2971", "installed_date": "2019-11-15T16:00:00Z", "version": "3.8.4.2971", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Setup (English)", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft ODBC Driver 13 for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2017", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 T-SQL Language Service ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 Setup Support Files ", "installed_date": "2016-12-05T16:00:00Z", "version": "10.1.2731.0", }, ], "nics": [ { "mac_address": "000C29D7A627", "description": "Intel(R) 82574L Gigabit Network Connection #2", "ips": ["192.168.230.140"], }, { "mac_address": "000C29D7A631", "description": "Intel(R) 82574L Gigabit Network Connection", "ips": ["172.16.128.100"], }, ], "drives": [ { "freespace_available": 47086694400, "volume_label": "", "drive_format": "NTFS", "freespace_total": 47086694400, "name": "C:\\", "total_size": 64422408192, } ], "updates_installed": [{"installed_date": "2019-01-07T19:04:46Z", "title": "Update for Windows (KB2999226)"}], "domain_name": "", "culture": "en-US", "object_sid": "", "dhcp_scope_name": "", "time_zone": "Asia/Shanghai", "host_name": "WIN-TEN8D4FCOUB", "fully_qualified_host_name": "WIN-TEN8D4FCOUB", "object_guid": "", "plugin_version": "1.2.0.329", } MOCK_ENDPOINT_HOSTNAME_OUTPUT = { "Malwarebytes.Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": MOCK_ASSETS_RESPONSE["nics"], "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": MOCK_ASSETS_RESPONSE["nics"][0]["mac_address"], "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), "Assets": MOCK_ASSETS_RESPONSE, }, "Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": MOCK_ASSETS_RESPONSE["nics"][0]["ips"][0], "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": MOCK_ASSETS_RESPONSE["nics"][0]["mac_address"], "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), }, } # patch the API endpoint requests_mock.post(MOCK_ENDPOINTS, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.get(MOCK_ENDPOINTS + "/" + MOCK_ASSET_ID + "/assets", json=MOCK_ASSETS_RESPONSE) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") list_endpoint_info(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_ENDPOINT_HOSTNAME_OUTPUT) == str(outputs["EntryContext"]) def test_list_endpoint_info_ip(requests_mock, mocker): """ Given: - An endpoint identified by IP address. When: - Running the get endpoint info command. Then: - The endpoint asset information is returned correctly. """ MOCK_ASSET_ID = "8c9df179-a999-4ca2-9c41-9795ae0b08f5" MOCK_ASSETS_RESPONSE = { "startups": [ { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Shell", "value": "explorer.exe", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "System", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Taskman", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Userinit", "value": "C:\\Windows\\system32\\userinit.exe,", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run", "name": "VMware User Process", "value": '"C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe" -n vmusr', }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad", "name": "WebCheck", "value": "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}", }, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Authentication Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Notification Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Security Packages"}, { "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders", "name": "SecurityProviders", "value": "credssp.dll, pwdssp.dll", }, ], "os_info": { "os_platform": "Windows", "os_architecture": "Amd64", "os_version": "6.3.9600", "os_release_name": "Microsoft Windows Server 2012 R2 Standard", "os_type": "Server", }, "memory": { "total_virtual": 2549530624, "free_virtual": 765550592, "total_physical": 2147483648, "free_physical": 873046016, }, "computer_info": {"manufacturer": "VMware, Inc.", "model": "VMware Virtual Platform"}, "software_installed": [ { "vendor": "Microsoft Corporation", "product": "Microsoft Help Viewer 2.2", "installed_date": "2019-01-07T16:00:00Z", "version": "2.2.23107", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Console", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 SDK", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51641", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.4148", }, { "vendor": "Microsoft Corporation", "product": "IIS 7.5 Express", "installed_date": "2016-12-04T16:00:00Z", "version": "7.5.1070", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 Policies ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2014 Management Objects ", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2000.8", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50710", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Endpoint Agent", "installed_date": "2019-11-15T16:00:00Z", "version": "1.2.0.717", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2014", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2402.11", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Data-Tier Application Framework (x86)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.4127.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Management Studio - 17.9.1", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23829", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Server", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015 Language Support", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.20", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Browser", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio 2015 Shell (Isolated)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.10", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 (64-bit)", "installed_date": "2016-12-05T16:00:00Z", "version": "", }, { "vendor": "VMware, Inc.", "product": "VMware Tools", "installed_date": "2016-12-04T16:00:00Z", "version": "10.0.10.4301679", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Native Client", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server VSS Writer", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2012 Native Client ", "installed_date": "2019-01-07T16:00:00Z", "version": "11.3.6540.0", }, { "vendor": "Microsoft Corporation", "product": "Active Directory Authentication Library for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.6161", }, { "vendor": "Malwarebytes", "product": "Malwarebytes version 3.8.4.2971", "installed_date": "2019-11-15T16:00:00Z", "version": "3.8.4.2971", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Setup (English)", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft ODBC Driver 13 for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2017", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 T-SQL Language Service ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 Setup Support Files ", "installed_date": "2016-12-05T16:00:00Z", "version": "10.1.2731.0", }, ], "nics": [ { "mac_address": "000C29D7A627", "description": "Intel(R) 82574L Gigabit Network Connection #2", "ips": ["192.168.230.140"], }, { "mac_address": "000C29D7A631", "description": "Intel(R) 82574L Gigabit Network Connection", "ips": ["172.16.128.100"], }, ], "drives": [ { "freespace_available": 47086694400, "volume_label": "", "drive_format": "NTFS", "freespace_total": 47086694400, "name": "C:\\", "total_size": 64422408192, } ], "updates_installed": [{"installed_date": "2019-01-07T19:04:46Z", "title": "Update for Windows (KB2999226)"}], "domain_name": "", "culture": "en-US", "object_sid": "", "dhcp_scope_name": "", "time_zone": "Asia/Shanghai", "host_name": "WIN-TEN8D4FCOUB", "fully_qualified_host_name": "WIN-TEN8D4FCOUB", "object_guid": "", "plugin_version": "1.2.0.329", } MOCK_ENDPOINT_HOSTNAME_OUTPUT = { "Malwarebytes.Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": MOCK_ASSETS_RESPONSE["nics"], "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": MOCK_ASSETS_RESPONSE["nics"][0]["mac_address"], "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), "Assets": MOCK_ASSETS_RESPONSE, }, "Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": MOCK_ASSETS_RESPONSE["nics"][0]["ips"][0], "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": MOCK_ASSETS_RESPONSE["nics"][0]["mac_address"], "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), }, } # patch the API endpoint requests_mock.post(MOCK_ENDPOINTS, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.get(MOCK_ENDPOINTS + "/" + MOCK_ASSET_ID + "/assets", json=MOCK_ASSETS_RESPONSE) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") list_endpoint_info(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_ENDPOINT_HOSTNAME_OUTPUT) == str(outputs["EntryContext"]) def test_list_endpoint_info_hostname_indexerror(requests_mock, mocker): """ Given: - An endpoint identified by hostname with missing NIC data causing an IndexError. When: - Running the get endpoint info command. Then: - The command handles the IndexError gracefully and returns available info. """ MOCK_ASSET_ID = "8c9df179-a999-4ca2-9c41-9795ae0b08f5" MOCK_ASSETS_RESPONSE = { "startups": [ { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Shell", "value": "explorer.exe", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "System", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Taskman", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Userinit", "value": "C:\\Windows\\system32\\userinit.exe,", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run", "name": "VMware User Process", "value": '"C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe" -n vmusr', }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad", "name": "WebCheck", "value": "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}", }, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Authentication Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Notification Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Security Packages"}, { "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders", "name": "SecurityProviders", "value": "credssp.dll, pwdssp.dll", }, ], "os_info": { "os_platform": "Windows", "os_architecture": "Amd64", "os_version": "6.3.9600", "os_release_name": "Microsoft Windows Server 2012 R2 Standard", "os_type": "Server", }, "memory": { "total_virtual": 2549530624, "free_virtual": 765550592, "total_physical": 2147483648, "free_physical": 873046016, }, "computer_info": {"manufacturer": "VMware, Inc.", "model": "VMware Virtual Platform"}, "software_installed": [ { "vendor": "Microsoft Corporation", "product": "Microsoft Help Viewer 2.2", "installed_date": "2019-01-07T16:00:00Z", "version": "2.2.23107", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Console", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 SDK", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51641", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.4148", }, { "vendor": "Microsoft Corporation", "product": "IIS 7.5 Express", "installed_date": "2016-12-04T16:00:00Z", "version": "7.5.1070", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 Policies ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2014 Management Objects ", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2000.8", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50710", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Endpoint Agent", "installed_date": "2019-11-15T16:00:00Z", "version": "1.2.0.717", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2014", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2402.11", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Data-Tier Application Framework (x86)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.4127.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Management Studio - 17.9.1", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23829", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Server", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015 Language Support", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.20", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Browser", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio 2015 Shell (Isolated)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.10", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 (64-bit)", "installed_date": "2016-12-05T16:00:00Z", "version": "", }, { "vendor": "VMware, Inc.", "product": "VMware Tools", "installed_date": "2016-12-04T16:00:00Z", "version": "10.0.10.4301679", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Native Client", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server VSS Writer", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2012 Native Client ", "installed_date": "2019-01-07T16:00:00Z", "version": "11.3.6540.0", }, { "vendor": "Microsoft Corporation", "product": "Active Directory Authentication Library for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.6161", }, { "vendor": "Malwarebytes", "product": "Malwarebytes version 3.8.4.2971", "installed_date": "2019-11-15T16:00:00Z", "version": "3.8.4.2971", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Setup (English)", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft ODBC Driver 13 for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2017", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 T-SQL Language Service ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 Setup Support Files ", "installed_date": "2016-12-05T16:00:00Z", "version": "10.1.2731.0", }, ], "nics": [], "drives": [ { "freespace_available": 47086694400, "volume_label": "", "drive_format": "NTFS", "freespace_total": 47086694400, "name": "C:\\", "total_size": 64422408192, } ], "updates_installed": [{"installed_date": "2019-01-07T19:04:46Z", "title": "Update for Windows (KB2999226)"}], "domain_name": "", "culture": "en-US", "object_sid": "", "dhcp_scope_name": "", "time_zone": "Asia/Shanghai", "host_name": "WIN-TEN8D4FCOUB", "fully_qualified_host_name": "WIN-TEN8D4FCOUB", "object_guid": "", "plugin_version": "1.2.0.329", } MOCK_ENDPOINT_HOSTNAME_OUTPUT = { "Malwarebytes.Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": MOCK_ASSETS_RESPONSE["nics"], "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": None, "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), "Assets": MOCK_ASSETS_RESPONSE, }, "Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": None, "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": None, "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), }, } # patch the API endpoint requests_mock.post(MOCK_ENDPOINTS, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.get(MOCK_ENDPOINTS + "/" + MOCK_ASSET_ID + "/assets", json=MOCK_ASSETS_RESPONSE) # patch the inputs mocker.patch.object(demisto, "args", return_value={"hostname": MOCK_HOSTNAME}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") list_endpoint_info(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_ENDPOINT_HOSTNAME_OUTPUT) == str(outputs["EntryContext"]) def test_list_endpoint_info_ip_indexerror(requests_mock, mocker): """ Given: - An endpoint identified by IP with missing NIC data causing an IndexError. When: - Running the get endpoint info command. Then: - The command handles the IndexError gracefully and returns available info. """ MOCK_ASSET_ID = "8c9df179-a999-4ca2-9c41-9795ae0b08f5" MOCK_ASSETS_RESPONSE = { "startups": [ { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Shell", "value": "explorer.exe", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "System", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Taskman", "value": "", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", "name": "Userinit", "value": "C:\\Windows\\system32\\userinit.exe,", }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run", "name": "VMware User Process", "value": '"C:\\Program Files\\VMware\\VMware Tools\\vmtoolsd.exe" -n vmusr', }, { "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad", "name": "WebCheck", "value": "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}", }, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Authentication Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Notification Packages"}, {"key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa", "name": "Security Packages"}, { "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders", "name": "SecurityProviders", "value": "credssp.dll, pwdssp.dll", }, ], "os_info": { "os_platform": "Windows", "os_architecture": "Amd64", "os_version": "6.3.9600", "os_release_name": "Microsoft Windows Server 2012 R2 Standard", "os_type": "Server", }, "memory": { "total_virtual": 2549530624, "free_virtual": 765550592, "total_physical": 2147483648, "free_physical": 873046016, }, "computer_info": {"manufacturer": "VMware, Inc.", "model": "VMware Virtual Platform"}, "software_installed": [ { "vendor": "Microsoft Corporation", "product": "Microsoft Help Viewer 2.2", "installed_date": "2019-01-07T16:00:00Z", "version": "2.2.23107", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Console", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 SDK", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51641", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.4148", }, { "vendor": "Microsoft Corporation", "product": "IIS 7.5 Express", "installed_date": "2016-12-04T16:00:00Z", "version": "7.5.1070", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 Policies ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2014 Management Objects ", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2000.8", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50710", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Endpoint Agent", "installed_date": "2019-11-15T16:00:00Z", "version": "1.2.0.717", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2014", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.2402.11", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Data-Tier Application Framework (x86)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.4127.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Management Studio - 17.9.1", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23829", }, { "vendor": "Malwarebytes", "product": "Malwarebytes Management Server", "installed_date": "2017-03-26T16:00:00Z", "version": "1.8.0.3431", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.2 Multi-Targeting Pack", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.51209", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio Tools for Applications 2015 Language Support", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.20", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server Browser", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005", "installed_date": "2019-01-07T16:00:00Z", "version": "12.0.21005.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual Studio 2015 Shell (Isolated)", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23107.10", }, { "vendor": "Microsoft Corporation", "product": "Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)", "installed_date": "2019-01-07T16:00:00Z", "version": "4.5.50932", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.23026.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 (64-bit)", "installed_date": "2016-12-05T16:00:00Z", "version": "", }, { "vendor": "VMware, Inc.", "product": "VMware Tools", "installed_date": "2016-12-04T16:00:00Z", "version": "10.0.10.4301679", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Native Client", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server VSS Writer", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2012 Native Client ", "installed_date": "2019-01-07T16:00:00Z", "version": "11.3.6540.0", }, { "vendor": "Microsoft Corporation", "product": "Active Directory Authentication Library for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161", "installed_date": "2016-12-04T16:00:00Z", "version": "9.0.30729.6161", }, { "vendor": "Malwarebytes", "product": "Malwarebytes version 3.8.4.2971", "installed_date": "2019-11-15T16:00:00Z", "version": "3.8.4.2971", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 R2 Setup (English)", "installed_date": "2016-12-05T16:00:00Z", "version": "10.50.1600.1", }, { "vendor": "Microsoft Corporation", "product": "Microsoft ODBC Driver 13 for SQL Server", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft System CLR Types for SQL Server 2017", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.1000.169", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2017 T-SQL Language Service ", "installed_date": "2019-01-07T16:00:00Z", "version": "14.0.17289.0", }, { "vendor": "Microsoft Corporation", "product": "Microsoft SQL Server 2008 Setup Support Files ", "installed_date": "2016-12-05T16:00:00Z", "version": "10.1.2731.0", }, ], "nics": [], "drives": [ { "freespace_available": 47086694400, "volume_label": "", "drive_format": "NTFS", "freespace_total": 47086694400, "name": "C:\\", "total_size": 64422408192, } ], "updates_installed": [{"installed_date": "2019-01-07T19:04:46Z", "title": "Update for Windows (KB2999226)"}], "domain_name": "", "culture": "en-US", "object_sid": "", "dhcp_scope_name": "", "time_zone": "Asia/Shanghai", "host_name": "WIN-TEN8D4FCOUB", "fully_qualified_host_name": "WIN-TEN8D4FCOUB", "object_guid": "", "plugin_version": "1.2.0.329", } MOCK_ENDPOINT_HOSTNAME_OUTPUT = { "Malwarebytes.Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": MOCK_ASSETS_RESPONSE["nics"], "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": None, "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), "Assets": MOCK_ASSETS_RESPONSE, }, "Endpoint(val.Hostname == obj.Hostname)": { "Hostname": MOCK_ASSETS_RESPONSE["host_name"], "IPAddress": None, "Domain": MOCK_ASSETS_RESPONSE.get("domain_name"), "MACAddress": None, "OS": MOCK_ASSETS_RESPONSE["os_info"]["os_platform"], "OSVersion": MOCK_ASSETS_RESPONSE["os_info"]["os_version"], "Model": MOCK_ASSETS_RESPONSE.get("computer_info", {}).get("model"), "Memory": MOCK_ASSETS_RESPONSE.get("memory"), }, } # patch the API endpoint requests_mock.post(MOCK_ENDPOINTS, json=MOCK_ENDPOINT_MACHINE_ID_RESP) requests_mock.get(MOCK_ENDPOINTS + "/" + MOCK_ASSET_ID + "/assets", json=MOCK_ASSETS_RESPONSE) # patch the inputs mocker.patch.object(demisto, "args", return_value={"ip": MOCK_IP}) # patch the outputs mocker.patch.object(demisto, "results") # run the code ip = demisto.args().get("ip") hostname = demisto.args().get("hostname") list_endpoint_info(account_id, client_id, auth_token, ip, hostname, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert str(MOCK_ENDPOINT_HOSTNAME_OUTPUT) == str(outputs["EntryContext"]) def test_scan_detections_job_id(requests_mock, mocker): """ Given: - A completed scan job ID. When: - Running the get scan detections command. Then: - The detections found during the scan are returned. """ MOCK_ENDPOINT_DETECTION_OUTPUT = { "Malwarebytes.Scan(val.Job_ID == obj.Job_ID)": { "Job_ID": MOCK_JOBS_JOB_ID, "Status": "COMPLETED", "Detections": MOCK_SCAN_DETECTIONS_CLEAR["detections"], } } # patch the API endpoint requests_mock.get(MOCK_ENDPOINTS_JOBS + "/jobs/" + MOCK_JOBS_JOB_ID, json=MOCK_GET_JOBS_DATA) requests_mock.get(MOCK_ENDPOINTS_JOBS + "/jobs/" + MOCK_JOBS_JOB_ID, json=MOCK_GET_JOBS_DATA) requests_mock.get(MOCK_ENDPOINTS_JOBS + "/jobs/" + MOCK_JOBS_JOB_ID, json=MOCK_GET_JOBS_DATA) requests_mock.get(MOCK_DETECTIONS_PATH, json=MOCK_SCAN_DETECTIONS) # patch the inputs mocker.patch.object(demisto, "args", return_value={"job_id": MOCK_JOBS_JOB_ID}) # patch the outputs mocker.patch.object(demisto, "results") # run the code job_id = demisto.args().get("job_id") scan_detections(account_id, client_id, auth_token, job_id, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_DETECTION_OUTPUT def test_scan_status_job_id(requests_mock, mocker): """ Given: - A scan job ID. When: - Running the get scan status command. Then: - The current status of the scan job is returned. """ MOCK_ENDPOINT_SCANSTATUS_OUTPUT = { "Malwarebytes.Scan(val.Job_ID == obj.Job_ID)": {"Job_ID": MOCK_JOBS_JOB_ID, "Status": "COMPLETED"} } # patch the API endpoint requests_mock.get(MOCK_ENDPOINTS_JOBS + "/jobs/" + MOCK_JOBS_JOB_ID, json=MOCK_GET_JOBS_DATA) # patch the inputs mocker.patch.object(demisto, "args", return_value={"job_id": MOCK_JOBS_JOB_ID}) # patch the outputs mocker.patch.object(demisto, "results") # run the code job_id = demisto.args().get("job_id") scan_status(account_id, client_id, auth_token, job_id, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_ENDPOINT_SCANSTATUS_OUTPUT def test_fetch_incidents_epr(requests_mock, mocker): """ Given: - The integration is configured to fetch Suspicious Activity (EPR) incidents. When: - Running the fetch incidents flow. Then: - Suspicious activity incidents are created correctly. """ # patch the API endpoint requests_mock.get(MOCK_SA_ENDPOINT, json=MOCK_SA_DATA) # patch the inputs mocker.patch.object( demisto, "args", return_value={"Fetch_Event_List": MOCK_SA_CHOICE, "suspicious_activity_severity": "High"} ) # patch the outputs mocker.patch.object(demisto, "results") # run the code event_list = demisto.params().get("Fetch_Event_List") fetch_incidents(account_id, client_id, auth_token, event_list, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["Contents"] == "[]" def test_fetch_incidents_ep(requests_mock, mocker): """ Given: - The integration is configured to fetch RTP Detections (EP) incidents. When: - Running the fetch incidents flow. Then: - RTP detection incidents are created correctly. """ # patch the API endpoint requests_mock.post(MOCK_RTP_ENDPOINT, json=MOCK_RTP_DETECTIONS_DATA) # patch the inputs mocker.patch.object(demisto, "args", return_value={"Fetch_Event_List": MOCK_RTP_CHOICE, "rtp_threat_category": "Malware"}) # patch the outputs mocker.patch.object(demisto, "results") # run the code event_list = demisto.params().get("Fetch_Event_List") fetch_incidents(account_id, client_id, auth_token, event_list, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["Contents"] == "[]" def test_open_sa_incident(requests_mock, mocker): """ Given: - A suspicious activity detection ID and machine ID. When: - Running the open SA incident command. Then: - The SA incident is opened successfully. """ MOCK_OPEN = MOCK_ENDPOINTS + "/" + MOCK_SA_MACHINE_ID + "/sa/" + MOCK_SA_DETECTION_ID + "/open" MOCK_OPEN_OUTPUT = {"Malwarebytes.SA(val.Machine_ID == obj.Machine_ID)": {"Machine_ID": MOCK_SA_MACHINE_ID}} # patch the API endpoint requests_mock.put(MOCK_OPEN, json={}, status_code=201) # path the inputs mocker.patch.object(demisto, "args", return_value={"machine_id": MOCK_SA_MACHINE_ID, "detection_id": MOCK_SA_DETECTION_ID}) # patch the outputs mocker.patch.object(demisto, "results") # run the code machine_id = demisto.args().get("machine_id") detection_id = demisto.args().get("detection_id") open_sa_incident(account_id, client_id, auth_token, machine_id, detection_id, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_OPEN_OUTPUT def test_remediate_sa_incident(requests_mock, mocker): """ Given: - A suspicious activity detection ID and machine ID. When: - Running the remediate SA incident command. Then: - The SA incident remediation is initiated successfully. """ MOCK_REMEDIATE = MOCK_ENDPOINTS + "/" + MOCK_SA_MACHINE_ID + "/sa/" + MOCK_SA_DETECTION_ID + "/remediate" MOCK_REMEDIATE_OUTPUT = {"Malwarebytes.SA(val.Machine_ID == obj.Machine_ID)": {"Machine_ID": MOCK_SA_MACHINE_ID}} # patch the API endpoint requests_mock.post(MOCK_REMEDIATE, json={}, status_code=201) # path the inputs mocker.patch.object(demisto, "args", return_value={"machine_id": MOCK_SA_MACHINE_ID, "detection_id": MOCK_SA_DETECTION_ID}) # patch the outputs mocker.patch.object(demisto, "results") # run the code machine_id = demisto.args().get("machine_id") detection_id = demisto.args().get("detection_id") remediate_sa_incident(account_id, client_id, auth_token, machine_id, detection_id, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_REMEDIATE_OUTPUT def test_close_sa_incident(requests_mock, mocker): """ Given: - A suspicious activity detection ID and machine ID. When: - Running the close SA incident command. Then: - The SA incident is closed successfully. """ MOCK_CLOSE = MOCK_ENDPOINTS + "/" + MOCK_SA_MACHINE_ID + "/sa/" + MOCK_SA_DETECTION_ID + "/close" MOCK_CLOSE_OUTPUT = {"Malwarebytes.SA(val.Machine_ID == obj.Machine_ID)": {"Machine_ID": MOCK_SA_MACHINE_ID}} # patch the API endpoint requests_mock.put(MOCK_CLOSE, json={}, status_code=201) # path the inputs mocker.patch.object(demisto, "args", return_value={"machine_id": MOCK_SA_MACHINE_ID, "detection_id": MOCK_SA_DETECTION_ID}) # patch the outputs mocker.patch.object(demisto, "results") # run the code machine_id = demisto.args().get("machine_id") detection_id = demisto.args().get("detection_id") close_sa_incident(account_id, client_id, auth_token, machine_id, detection_id, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_CLOSE_OUTPUT def test_get_sa_activities_command_hostname(requests_mock, mocker): """ Given: - A hostname to filter suspicious activities. When: - Running the get SA activities command. Then: - Suspicious activities matching the hostname are returned. """ MOCK_SA_OUTPUT = { "Malwarebytes.Endpoint(val.Suspicious_Activities == obj.Suspicious_Activities)": { "Suspicious_Activities": MOCK_SA_DATA["sa"] } } # patch the API endpoint requests_mock.get(MOCK_SA_ENDPOINT, json=MOCK_SA_DATA) # path the inputs mocker.patch.object(demisto, "args", return_value={"hostname": "DESKTOP-664HFM6"}) # patch the outputs mocker.patch.object(demisto, "results") # run the code hostname = demisto.args().get("hostname") path = demisto.args().get("path") get_sa_activities_command(account_id, client_id, auth_token, hostname, path, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_SA_OUTPUT def test_get_sa_activities_command_path(requests_mock, mocker): """ Given: - A file path to filter suspicious activities. When: - Running the get SA activities command. Then: - Suspicious activities matching the path are returned. """ MOCK_SA_OUTPUT = { "Malwarebytes.Endpoint(val.Suspicious_Activities == obj.Suspicious_Activities)": { "Suspicious_Activities": MOCK_SA_DATA["sa"] } } # patch the API endpoint requests_mock.get(MOCK_SA_ENDPOINT, json=MOCK_SA_DATA) # path the inputs mocker.patch.object( demisto, "args", return_value={"path": "C:\\USERS\\ROHIN SAMBATH KUMAR\\DESKTOP\\MA2EZOX5\\EKATI5862.EXE"} ) # patch the outputs mocker.patch.object(demisto, "results") # run the code hostname = demisto.args().get("hostname") path = demisto.args().get("path") get_sa_activities_command(account_id, client_id, auth_token, hostname, path, USE_SSL) # assert the outputs assert demisto.results.call_count == 1 outputs = demisto.results.call_args[0][0] assert outputs["EntryContext"] == MOCK_SA_OUTPUT # --------------------------------------------------------------------------- # Region support tests # --------------------------------------------------------------------------- US_URL = "https://cloud.threatdown.com" EU_URL = "https://cloud.euc1.threatdown.com" def test_region_urls_mapping(): """ Given: - The REGION_URLS mapping used to resolve the API base URL per region. When: - Looking up the US and EU regions. Then: - Each region resolves to the expected ThreatDown Nebula base URL. """ assert REGION_URLS["US"] == US_URL assert REGION_URLS["EU"] == EU_URL def test_nebula_url_uses_global_url(mocker): """ Given: - The module-level URL is set to a specific region's base URL. When: - Building a path with nebula_url(). Then: - The returned URL is prefixed with the currently configured base URL. """ mocker.patch.object(Malwarebytes, "URL", US_URL) assert nebula_url("/oauth2/token") == f"{US_URL}/oauth2/token" mocker.patch.object(Malwarebytes, "URL", EU_URL) assert nebula_url("/oauth2/token") == f"{EU_URL}/oauth2/token" def test_main_sets_eu_url_for_region(mocker): """ Given: - The integration is configured with the EU region. When: - main() runs. Then: - The module-level URL is set to the EU base URL so all API calls target EU. """ mocker.patch.object( demisto, "params", return_value={ "accountid": account_id, "clientid": client_id, "clientsecret": "secret", "region": "EU", "insecure": False, }, ) mocker.patch.object(demisto, "command", return_value="test-module") mocker.patch.object(demisto, "results") mocker.patch.object(Malwarebytes, "get_token", return_value=auth_token) mocker.patch.object(Malwarebytes, "handle_proxy") mocker.patch.object(Malwarebytes, "send_usage_data") mocker.patch.object(Malwarebytes, "test_connectivity", return_value=True) main() assert Malwarebytes.URL == EU_URL def test_main_defaults_to_us_when_region_missing(mocker): """ Given: - The integration is configured without a region (backward compatibility). When: - main() runs. Then: - The module-level URL defaults to the US base URL. """ mocker.patch.object( demisto, "params", return_value={ "accountid": account_id, "clientid": client_id, "clientsecret": "secret", "insecure": False, }, ) mocker.patch.object(demisto, "command", return_value="test-module") mocker.patch.object(demisto, "results") mocker.patch.object(Malwarebytes, "get_token", return_value=auth_token) mocker.patch.object(Malwarebytes, "handle_proxy") mocker.patch.object(Malwarebytes, "send_usage_data") mocker.patch.object(Malwarebytes, "test_connectivity", return_value=True) main() assert Malwarebytes.URL == US_URL def test_main_eu_region_targets_eu_host(requests_mock, mocker): """ Given: - The integration is configured with the EU region. When: - main() runs the test-module command which calls the endpoints API. Then: - The outbound API request is made against the EU host. """ eu_endpoints = f"{EU_URL}/api/v2/endpoints" adapter = requests_mock.get(eu_endpoints, json={"machines": [], "next_cursor": "", "total_count": 0}) mocker.patch.object( demisto, "params", return_value={ "accountid": account_id, "clientid": client_id, "clientsecret": "secret", "region": "EU", "insecure": False, }, ) mocker.patch.object(demisto, "command", return_value="test-module") mocker.patch.object(demisto, "results") mocker.patch.object(Malwarebytes, "get_token", return_value=auth_token) mocker.patch.object(Malwarebytes, "handle_proxy") mocker.patch.object(Malwarebytes, "send_usage_data") main() assert adapter.called assert adapter.last_request.url.startswith(EU_URL)