id: IP Enrichment - External - Generic v2 version: -1 name: IP Enrichment - External - Generic v2 fromversion: 5.0.0 description: |- Enrich IP addresses using one or more integrations. - Resolve IP addresses to hostnames (DNS). - Provide threat information. - IP address reputation using !ip command. - Separate internal and external addresses. starttaskid: "0" tasks: "0": id: "0" taskid: 6635b28b-bdf1-42cf-88bc-14ad75e9ebe0 type: start task: id: 6635b28b-bdf1-42cf-88bc-14ad75e9ebe0 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "47" separatecontext: false view: |- { "position": { "x": 550, "y": 39 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "15": id: "15" taskid: c8d8906f-cbf4-4ddd-84e6-1e55570d00a0 type: condition task: id: c8d8906f-cbf4-4ddd-84e6-1e55570d00a0 version: -1 name: Is there an external IP address? description: Checks whether the "InRange" attribute is set to "no". type: condition iscommand: false brand: "" nexttasks: '#default#': - "39" "yes": - "34" scriptarguments: value: complex: root: IP filters: - - operator: isEqualString left: value: simple: IP.InRange iscontext: true right: value: simple: "no" accessor: Address separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: IP filters: - - operator: isEqualString left: value: simple: IP.InRange iscontext: true right: value: simple: "no" ignorecase: true accessor: Address iscontext: true ignorecase: true view: |- { "position": { "x": 552.5, "y": 670 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "24": id: "24" taskid: 8149db7c-af8d-41e2-85ee-c9fe2efd5040 type: title task: id: 8149db7c-af8d-41e2-85ee-c9fe2efd5040 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": 110, "y": 1970 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "27": id: "27" taskid: 1734f24b-0b27-431e-81b6-89997f08894c type: title task: id: 1734f24b-0b27-431e-81b6-89997f08894c version: -1 name: Enrich external IP addresses type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "36" - "44" separatecontext: false view: |- { "position": { "x": 100, "y": 1240 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "29": id: "29" taskid: ae5e40bb-17cb-4470-84bc-4801e67b1cae type: regular task: id: ae5e40bb-17cb-4470-84bc-4801e67b1cae version: -1 name: Determine whether the IP address is internal or external description: "Checks if the IP address is in the internal IP address ranges.\nIf internal, sets the \"InRange\" attribute to \"yes\".\nIf external, sets the \"InRange\" attribute to \"no\". " scriptName: IsIPInRanges type: regular iscommand: false brand: "" nexttasks: '#none#': - "15" scriptarguments: ip: complex: root: inputs.IP transformers: - operator: uniq ipRanges: complex: root: inputs.InternalRange ignore-outputs: simple: "false" reputationcalc: 1 separatecontext: false view: |- { "position": { "x": 552.5, "y": 505 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "34": id: "34" taskid: 607dafbe-8ee1-47ad-810a-dacf03842673 type: condition task: id: 607dafbe-8ee1-47ad-810a-dacf03842673 version: -1 name: Resolve the IP address? description: Checks whether the "ResolveIP" parameter is set to "True". type: condition iscommand: false brand: "" nexttasks: '#default#': - "27" "yes": - "35" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: simple: inputs.ResolveIP iscontext: true right: value: simple: "True" ignorecase: true view: |- { "position": { "x": 550, "y": 870 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "35": id: "35" taskid: 9a9092a5-a173-4c8d-8a0c-f63960c42451 type: regular task: id: 9a9092a5-a173-4c8d-8a0c-f63960c42451 version: -1 name: IP to Hostname (DNS) description: Convert the IP address to a hostname using DNS query. scriptName: IPToHost type: regular iscommand: false brand: "" nexttasks: '#none#': - "27" scriptarguments: ip: complex: root: IP filters: - - operator: isEqualString left: value: simple: IP.InRange iscontext: true right: value: simple: "no" - - operator: containsGeneral left: value: simple: IP.Address iscontext: true right: value: simple: inputs.IP iscontext: true accessor: Address transformers: - operator: uniq reputationcalc: 2 continueonerror: true separatecontext: false view: |- { "position": { "x": 750, "y": 1055 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "36": id: "36" taskid: 22f7b81d-ea1a-44b3-8b73-c628afaf5cfc type: title task: id: 22f7b81d-ea1a-44b3-8b73-c628afaf5cfc version: -1 name: Enrich Using VirusTotal Private API type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "37" separatecontext: false view: |- { "position": { "x": 550, "y": 1420 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "37": id: "37" taskid: 0df4420b-8119-4731-8cb3-4745fd044913 type: condition task: id: 0df4420b-8119-4731-8cb3-4745fd044913 version: -1 name: Is VirusTotal Private API enabled? description: Checks if there is an active instance of the VirusTotal Private API integration enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "24" "yes": - "38" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: VirusTotal - Private API ignorecase: true - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active ignorecase: true accessor: brand iscontext: true ignorecase: true view: |- { "position": { "x": 550, "y": 1553 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "38": id: "38" taskid: bf0fa0db-39d0-4074-8878-c38077334c7a type: regular task: id: bf0fa0db-39d0-4074-8878-c38077334c7a version: -1 name: Get IP report from VirusTotal Private API description: | Retrieves a report for a given IP address. script: VirusTotal - Private API|||vt-private-get-ip-report type: regular iscommand: true brand: VirusTotal - Private API nexttasks: '#none#': - "24" scriptarguments: ip: complex: root: . transformers: - operator: uniq - operator: If-Then-Else args: condition: value: simple: lhs==rhs conditionB: {} conditionInBetween: {} else: value: simple: ${IP(val.InRange=="no").Address} iscontext: true equals: {} lhs: value: simple: inputs.ExecutedFromParent iscontext: true lhsB: {} options: {} optionsB: {} rhs: value: simple: "True" rhsB: {} then: value: simple: inputs.IP iscontext: true - operator: uniq reputationcalc: 1 separatecontext: false view: |- { "position": { "x": 550, "y": 1730 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "39": id: "39" taskid: 67d938bf-2bd3-4dfd-885f-8dd190cd0b93 type: title task: id: 67d938bf-2bd3-4dfd-885f-8dd190cd0b93 version: -1 name: No External IP Address type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "24" separatecontext: false view: |- { "position": { "x": 1270, "y": 1240 } } note: false timertriggers: [] ignoreworker: false continueonerrortype: "" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "44": id: "44" taskid: 9bda4dfe-35b9-40ac-8d8c-c6973b2d1d40 type: title task: id: 9bda4dfe-35b9-40ac-8d8c-c6973b2d1d40 version: -1 name: Check Reputation Using All Available Integrations type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "46" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -340, "y": 1420 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "45": id: "45" taskid: 6495e988-b3a2-44ca-866d-8a847c7914f9 type: regular task: id: 6495e988-b3a2-44ca-866d-8a847c7914f9 version: -1 name: Check Reputation description: Checks the reputation of an IP address using all available integrations. script: '|||ip' type: regular iscommand: true brand: "" nexttasks: '#none#': - "24" scriptarguments: ip: complex: root: . transformers: - operator: If-Then-Else args: condition: value: simple: lhs==rhs conditionB: {} conditionInBetween: {} else: value: simple: ${IP(val.InRange=="no").Address} iscontext: true equals: {} lhs: value: simple: inputs.ExecutedFromParent iscontext: true lhsB: {} options: {} optionsB: {} rhs: value: simple: "True" rhsB: {} then: value: simple: inputs.IP iscontext: true - operator: uniq extended_data: complex: root: inputs.extended_data threat_model_association: complex: root: inputs.threat_model_association separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -340, "y": 1730 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "46": id: "46" taskid: c55e9651-e6f5-48ec-8bbc-995c4e87808b type: condition task: id: c55e9651-e6f5-48ec-8bbc-995c4e87808b version: -1 name: Should use !IP command? description: Should use !IP command? type: condition iscommand: false brand: "" nexttasks: '#default#': - "24" "yes": - "45" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: simple: inputs.UseReputationCommand iscontext: true right: value: simple: "True" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": -340, "y": 1553 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "47": id: "47" taskid: ea6c64c9-4852-47c9-8cfd-d6d6907037cf type: condition task: id: ea6c64c9-4852-47c9-8cfd-d6d6907037cf version: -1 name: Are the IPs already classified? description: Checks whether the playbook's input contains at least one IP address. type: condition iscommand: false brand: "" nexttasks: '#default#': - "39" "No": - "48" "Yes": - "27" separatecontext: false conditions: - label: "Yes" condition: - - operator: isNotEmpty left: value: simple: inputs.IP iscontext: true right: value: {} - - operator: isEqualString left: value: simple: inputs.ExecutedFromParent iscontext: true right: value: simple: "True" ignorecase: true - label: "No" condition: - - operator: isNotEmpty left: value: complex: root: inputs.IP iscontext: true continueonerrortype: "" view: |- { "position": { "x": 550, "y": 170 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "48": id: "48" taskid: 2e4dbc75-e8f0-4478-8b16-523ba22e1621 type: title task: id: 2e4dbc75-e8f0-4478-8b16-523ba22e1621 version: -1 name: Classify & Resolve IPs type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "29" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 552.5, "y": 370 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": { "15_34_yes": 0.58, "15_39_#default#": 0.29, "34_27_#default#": 0.49, "34_35_yes": 0.53, "37_24_#default#": 0.28, "37_38_yes": 0.52, "46_24_#default#": 0.68, "46_45_yes": 0.56, "47_39_#default#": 0.3 }, "paper": { "dimensions": { "height": 1996, "width": 1990, "x": -340, "y": 39 } } } inputs: - key: IP value: complex: root: IP accessor: Address transformers: - operator: uniq required: false description: The IP address to enrich. playbookInputQuery: - key: InternalRange value: complex: root: lists accessor: PrivateIPs transformers: - operator: RegexExtractAll args: error_if_no_match: {} ignore_case: {} multi_line: {} period_matches_newline: {} regex: value: simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2}) unpack_matches: {} - operator: join args: separator: value: simple: ',' required: false description: 'A comma-separated list of IP address ranges (in CIDR notation). Use this list to check if an IP address is found within a set of IP address ranges. For example: "172.16.0.0/12,10.0.0.0/8,192.168.0.0/16" (without quotes).' playbookInputQuery: - key: ResolveIP value: simple: "True" required: true description: |- Whether to convert the IP address to a hostname using a DNS query (True/False). The default value is true. playbookInputQuery: - key: UseReputationCommand value: simple: "False" required: true description: |- Define if you would like to use the !IP command. Note: This input should be used whenever there is no auto-extract enabled in the investigation flow. Possible values: True / False. The default value is false. playbookInputQuery: - key: extended_data value: simple: "False" required: false description: |- Define whether you want the generic reputation command to return extended data (last_analysis_results). Possible values: True / False. The default value is false. playbookInputQuery: - key: threat_model_association value: simple: "False" required: false description: |- Define whether you wish to enhance generic reputation command to include additional information such as Threat Bulletins, Attack patterns, Actors, Campaigns, TTPs, vulnerabilities, etc. Note: If set to true, additional 6 API calls will be performed. Possible values: True / False. The default value is false. playbookInputQuery: - key: ExecutedFromParent value: simple: "False" required: false description: |- Whether to execute common logic, like the classification of IP addresses to ranges and resolving, in the the main (IP Enrichment - Generic v2) enrichment playbook, instead of in the sub-playbooks. Possible values are: True, False. Setting this to True and using the parent playbook will execute the relevant commands in the main playbook instead of executing them in both sub-playbooks, improving the performance of the playbook and reducing the overfall size of the incident. playbookInputQuery: outputs: - contextPath: IP description: The IP address objects. type: unknown - contextPath: DBotScore description: Indicator, Score, Type, and Vendor. type: unknown - contextPath: Endpoint description: The endpoint's object. type: unknown - contextPath: Endpoint.Hostname description: The hostname to enrich. type: string - contextPath: Endpoint.IP description: A list of endpoint IP addresses. type: string - contextPath: IP.Address description: The IP Address. type: string - contextPath: IP.InRange description: Is the IP in the input ranges? (could be 'yes' or 'no). type: string - contextPath: DBotScore.Indicator description: The indicator that was tested. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: string - contextPath: IP.ASN description: The Autonomous System (AS) number associated with the indicator. type: string - contextPath: IP.Tags description: List of IP tags. type: string - contextPath: IP.ThreatTypes description: Threat types associated with the IP. type: string - contextPath: IP.Geo.Country description: The country associated with the indicator. type: string - contextPath: IP.Geo.Location description: The longitude and latitude of the IP address. type: string - contextPath: IP.Malicious.Vendor description: The vendor that reported the indicator as malicious. type: string - contextPath: IP.Malicious.Description description: For malicious IPs, the reason that the vendor made the decision. type: string - contextPath: IP.VirusTotal.DownloadedHashes description: Latest files that are detected by at least one antivirus solution and were downloaded by VirusTotal from the IP address. type: string - contextPath: IP.VirusTotal.UnAVDetectedDownloadedHashes description: Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided. type: string - contextPath: IP.VirusTotal.DetectedURLs description: Latest URLs hosted in this IP address detected by at least one URL scanner. type: string - contextPath: IP.VirusTotal.CommunicatingHashes description: Latest detected files that communicate with this IP address. type: string - contextPath: IP.VirusTotal.UnAVDetectedCommunicatingHashes description: Latest undetected files that communicate with this IP address. type: string - contextPath: IP.VirusTotal.Resolutions.hostname description: The following domains resolved to the given IP. type: string - contextPath: IP.VirusTotal.ReferrerHashes description: Latest detected files that embed this IP address in their strings. type: string - contextPath: IP.VirusTotal.UnAVDetectedReferrerHashes description: Latest undetected files that embed this IP address in their strings. type: string - contextPath: IP.VirusTotal.Resolutions.last_resolved description: The last time the following domains resolved to the given IP. type: string tests: - IP Enrichment - Generic v2 - Test contentitemexportablefields: contentitemfields: {} system: true