diff --git a/playbooks/malware_hunt_and_contain.json b/playbooks/malware_hunt_and_contain.json new file mode 100644 index 0000000000..ab2ede583c --- /dev/null +++ b/playbooks/malware_hunt_and_contain.json @@ -0,0 +1,11686 @@ +{ + "blockly": false, + "blockly_xml": "", + "category": "Use Cases", + "coa": { + "data": { + "clean": true, + "code_block": "\"\"\"Malicous file detected on endpoint\"\"\"", + "description": "This playbook investigates and remediates malware infections on the endpoint.", + "hash": "d1af271dc2c9e67bf0393c4503368436c574f31a", + "joint": { + "cells": [ + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "5ad21936-f8c5-45e3-ab48-4aa74d2185b3", + "router": { + "name": "metro" + }, + "source": { + "id": "4c86e34b-13d5-4884-b1d2-53d1f3448f91", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "3c5abd70-80e5-46b8-908e-4eeb0ae4cef5", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 14 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "c168d4c9-945d-4742-a662-6e4abbc945da", + "router": { + "name": "metro" + }, + "source": { + "id": "3c5abd70-80e5-46b8-908e-4eeb0ae4cef5", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "8c9518d8-506f-4750-9e8e-2094bd14d431", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 651 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "3949529c-aff6-4401-90d8-a70c288b74d5", + "router": { + "name": "metro" + }, + "source": { + "id": "b9591115-e22e-48e0-952d-47c76448f051", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "0444efd4-6363-4dea-acca-b0c02ce9f973", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1290 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "9b55f239-b39d-4fe3-adda-f6168661b33a", + "router": { + "name": "metro" + }, + "source": { + "id": "72f13962-4d43-44be-9710-d2ed60cbbf00", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "0444efd4-6363-4dea-acca-b0c02ce9f973", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1558 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "9c84c8ba-08f4-4cec-acfd-c4dbccbbc66e", + "router": { + "name": "metro" + }, + "source": { + "id": "4fb5d51d-3f89-4408-88c4-4af8f22feb5a", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "a44f44e3-b4cb-4409-a495-8afedb2754e4", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 1694 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "b415fd2a-3939-4c18-a92e-efa93d32b1c6", + "router": { + "name": "metro" + }, + "source": { + "id": "a2d2bac8-c4c2-41b2-9c94-5e958b32684f", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "a44f44e3-b4cb-4409-a495-8afedb2754e4", + "port": "in", + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1706 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "961848a5-5fd4-4e3b-8b7b-6ef40ea4d007", + "router": { + "name": "metro" + }, + "source": { + "id": "34bd4b5e-7b04-43a8-9fa7-dff28adb98dc", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "a44f44e3-b4cb-4409-a495-8afedb2754e4", + "port": "in", + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1710 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "1649dbd5-f0bf-43ec-951b-5ad008365d1d", + "router": { + "name": "metro" + }, + "source": { + "id": "a44f44e3-b4cb-4409-a495-8afedb2754e4", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "b9591115-e22e-48e0-952d-47c76448f051", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1718 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "0db3fd7f-4779-44c3-8ea3-694bad0388d9", + "router": { + "name": "metro" + }, + "source": { + "id": "8c9518d8-506f-4750-9e8e-2094bd14d431", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "0fe35225-af74-44fa-b1a4-433a9c00cadb", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1886 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "88f69577-f71a-4ee0-8386-9ab6bcd33e28", + "router": { + "name": "metro" + }, + "source": { + "id": "0fe35225-af74-44fa-b1a4-433a9c00cadb", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "f8ca6cc8-63fc-4ccf-b4cb-1a5ed1941c4d", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1892 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "48627df2-9bc5-40fa-858e-426631c72ab9", + "router": { + "name": "metro" + }, + "source": { + "id": "8c9518d8-506f-4750-9e8e-2094bd14d431", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "91866693-2720-43a1-a437-f65f19382b9a", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1903 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "fbce023e-da26-4df2-829b-99d0a167cdd0", + "router": { + "name": "metro" + }, + "source": { + "id": "8c9518d8-506f-4750-9e8e-2094bd14d431", + "port": "out-2", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(2) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "6f5751ac-efaa-4f6e-97cf-29c88c78b381", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 1968 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "509e0e96-ee20-4dd7-8a04-e5a9b8f1db85", + "router": { + "name": "metro" + }, + "source": { + "id": "6f5751ac-efaa-4f6e-97cf-29c88c78b381", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "34bd4b5e-7b04-43a8-9fa7-dff28adb98dc", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1982 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "f5d00299-537c-4bf8-b86b-a500fa1c2258", + "router": { + "name": "metro" + }, + "source": { + "id": "6f5751ac-efaa-4f6e-97cf-29c88c78b381", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "4fb5d51d-3f89-4408-88c4-4af8f22feb5a", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1988 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "ee268141-044c-48e5-b1ad-29803892a264", + "router": { + "name": "metro" + }, + "source": { + "id": "6f5751ac-efaa-4f6e-97cf-29c88c78b381", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "a2d2bac8-c4c2-41b2-9c94-5e958b32684f", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 1992 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "0a60f02d-fb84-4d21-af04-0adc070f3ccf", + "router": { + "name": "metro" + }, + "source": { + "id": "8c9518d8-506f-4750-9e8e-2094bd14d431", + "port": "out-2", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(2) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "e6a1a311-5337-4d44-b8d3-58d8a6cf8be1", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 2050 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "562f6e73-5fb8-4722-b99b-7b2b91109a37", + "router": { + "name": "metro" + }, + "source": { + "id": "6f5751ac-efaa-4f6e-97cf-29c88c78b381", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "4aa9e1f2-fc69-4439-ae54-3eb215adec8f", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 2324 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "14967b49-8e3a-4a08-8c66-53f7e7b5b4b2", + "router": { + "name": "metro" + }, + "source": { + "id": "4aa9e1f2-fc69-4439-ae54-3eb215adec8f", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "a44f44e3-b4cb-4409-a495-8afedb2754e4", + "port": "in", + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 2339 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "d580f77a-9877-4c13-9a40-308797deca8d", + "router": { + "name": "metro" + }, + "source": { + "id": "f8ca6cc8-63fc-4ccf-b4cb-1a5ed1941c4d", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "e9a5e63f-becb-4040-914b-bdaeb8278d88", + "selector": ".port-body[type=\"input\"]" + }, + "type": "link", + "z": 2544 + }, + { + "attrs": { + ".connection": { + "stroke": "#6C7A89", + "stroke-width": 2 + }, + ".marker-target": { + "d": "M 10 0 L 0 5 L 10 10 z", + "fill": "#6a6c8a", + "stroke": "#6a6c8a" + }, + ".tool-remove": { + "position": 0.5 + } + }, + "connector": { + "args": { + "radius": 5 + }, + "name": "rounded" + }, + "endDirections": [ + "left" + ], + "id": "c2f5849d-4fa9-4a35-93df-7570b63d2304", + "router": { + "name": "metro" + }, + "source": { + "id": "e9a5e63f-becb-4040-914b-bdaeb8278d88", + "port": "out-1", + "selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)" + }, + "startDirections": [ + "right" + ], + "target": { + "id": "72f13962-4d43-44be-9710-d2ed60cbbf00", + "port": null, + "selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)" + }, + "type": "link", + "z": 2557 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 3 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_3() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"file_reputation_1:action_result.summary.positives\", \">\", 5],\n [\"file_reputation_1:action_result.summary.positives\", \"<=\", 10],\n ],\n logical_operator='and',\n name=\"filter_3:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n create_ticket_3(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": false, + "connection_name": "block hash 2", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "e9a5e63f-becb-4040-914b-bdaeb8278d88", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 44, + "line_start": 24, + "name": "filter", + "notes": "", + "number": 3, + "order": 2, + "outPorts": [ + "out-1" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": ">", + "data_type": "", + "param": "file_reputation_1:action_result.summary.positives", + "value": "5" + }, + { + "comparison": "<=", + "data_type": "", + "param": "file_reputation_1:action_result.summary.positives", + "value": "10" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1080, + "y": 80 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_3", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 2590 + }, + { + "action": "shutdown system", + "action_type": "contain", + "active": false, + "active_keys": {}, + "active_values": { + "ip_hostname": "hunt_file_2:action_result.data.*.process.results.*.hostname", + "message": "", + "wait_time": "" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "ip_hostname": "hunt_file_2:action_result.data.*.process.results.*.hostname", + "message": "", + "ph": "", + "wait_time": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "domainctrl1", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.wait_time", + "data_type": "numeric" + }, + { + "data_path": "action_result.parameter.message", + "data_type": "string" + }, + { + "column_name": "Machine Ip Name", + "column_order": 0, + "contains": [ + "ip", + "host name" + ], + "data_path": "action_result.parameter.ip_hostname", + "data_type": "string" + }, + { + "column_name": "Message", + "column_order": 1, + "data_path": "action_result.message", + "data_type": "string" + }, + { + "column_name": "Total Objects", + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "column_name": "Total Objects Successful", + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "shutdown system" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Contain" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_contain.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def shutdown_system_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('shutdown_system_1() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'shutdown_system_1' call\n results_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:action_result.data.*.process.results.*.hostname', 'hunt_file_2:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'shutdown_system_1' call\n for results_item_1 in results_data_1:\n parameters.append({\n 'ph': \"\",\n 'message': \"\",\n 'wait_time': \"\",\n 'ip_hostname': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"shutdown system\", parameters=parameters, assets=['domainctrl1'], callback=join_filter_2, name=\"shutdown_system_1\", parent_action=action)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#3D9959", + "connected_to_start": false, + "connection_name": "hunt file 2", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "a2d2bac8-c4c2-41b2-9c94-5e958b32684f", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 69, + "line_start": 44, + "message": "Configuring now", + "name": "shutdown system", + "notes": "", + "number": 1, + "order": 3, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 840, + "y": 760 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "shutdown_system_1", + "required_params": {}, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Contain", + "type": "coa.Action", + "warn": false, + "z": 2794 + }, + { + "action": "create ticket", + "action_type": "generic", + "active": false, + "active_keys": {}, + "active_values": { + "description": "", + "fields": "", + "short_description": "Virus Detected" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "description": "", + "fields": "", + "short_description": "Virus Detected", + "table": "", + "vault_id": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "servicenow", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.short_description", + "data_type": "string" + }, + { + "contains": [ + "servicenow table" + ], + "data_path": "action_result.parameter.table", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.fields", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.description", + "data_type": "string" + }, + { + "contains": [ + "servicenow ticket id" + ], + "data_path": "action_result.summary.created_ticket_id", + "data_type": "string" + }, + { + "contains": [ + "vault id" + ], + "data_path": "action_result.parameter.vault_id", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_updated_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_updated_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.escalation", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.watch_list", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.follow_up", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.made_sla", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.delivery_task", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sla_due", + "data_type": "string" + }, + { + "column_name": "Number", + "column_order": 0, + "data_path": "action_result.data.*.number", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.caller_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.correlation_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_mod_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.notify", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.resolved_by", + "data_type": "string" + }, + { + "column_name": "Closed On", + "column_order": 6, + "data_path": "action_result.data.*.closed_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_tags", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.cmdb_ci", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.subcategory", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.category", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.close_notes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.expected_start", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.knowledge", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.opened_by.link", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.opened_by.value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.impact", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.calendar_stc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.caused_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.comments", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.problem_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.activity_due", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.state", + "data_type": "string" + }, + { + "column_name": "ID", + "column_order": 4, + "contains": [ + "servicenow ticket id" + ], + "data_path": "action_result.data.*.sys_id", + "data_type": "string" + }, + { + "column_name": "Opened On", + "column_order": 5, + "data_path": "action_result.data.*.opened_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.child_incidents", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_notes", + "data_type": "string" + }, + { + "column_name": "Short Description", + "column_order": 0, + "data_path": "action_result.data.*.short_description", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.comments_and_work_notes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.time_worked", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_created_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.upon_reject", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.reassignment_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.business_stc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.due_date", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_class_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.delivery_plan", + "data_type": "string" + }, + { + "column_name": "Description", + "column_order": 1, + "data_path": "action_result.data.*.description", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.parent", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.business_duration", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.rfc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.company", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.assigned_to", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.approval_history", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.user_input", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_start", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_domain.link", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_domain.value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.resolved_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.calendar_duration", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.group_list", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.active", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.approval", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.parent_incident", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_domain_path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.closed_by", + "data_type": "string" + }, + { + "column_name": "Severity", + "column_order": 2, + "data_path": "action_result.data.*.severity", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.upon_approval", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.incident_state", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.reopen_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.contact_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_end", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_notes_list", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_created_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.location", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.correlation_display", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.close_code", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.assignment_group", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.approval_set", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.order", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.urgency", + "data_type": "string" + }, + { + "column_name": "Priority", + "column_order": 2, + "data_path": "action_result.data.*.priority", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.hold_reason", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.business_service", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_tags", + "data_type": "string" + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.attachment_details.*.file_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.compressed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.size_bytes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.table_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.image_width", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.content_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.image_height", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.table_sys_id", + "data_type": "string" + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.attachment_details.*.download_link", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_mod_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_created_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_created_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_updated_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_updated_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.size_compressed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.average_image_color", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.additional_assignee_list", + "data_type": "string" + }, + { + "data_path": "action_result.summary.attachment_id", + "data_type": "string" + }, + { + "data_path": "action_result.summary.attachment_added", + "data_type": "boolean" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "ticketing" + } + ], + "attrs": { + ".action": { + "text": "create ticket 2" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Utilities" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_generic.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#5094D4", + "connected_to_start": false, + "connection_name": "logoff user, shutdown system, disable user, block hash 3", + "connection_type": "action", + "custom_callback": "", + "custom_code": "def create_ticket_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'create_ticket_2' call\n\n disabled_users = set(phantom.collect2(datapath='disable_user_1:action_result.parameter.username'))\n blocked_hashes = set(phantom.collect2(datapath='block_hash_3:action_result.parameter.hash'))\n loggedoff_users = set(phantom.collect2(datapath='logoff_user_1:action_result.parameter.username'))\n shutdown_systems = set(phantom.collect2(datapath='shutdown_system_1:action_result.parameter.ip_hostname'))\n file_reputation = phantom.collect2(datapath=['file_reputation_1:filtered-action_result.parameter.hash', \n 'file_reputation_1:filtered-action_result.summary.positives'])\n detected_users = set(phantom.collect2(datapath='hunt_file_2:action_result.data.*.process.results.*.username'))\n detected_systems = set(phantom.collect2(datapath='hunt_file_2:action_result.data.*.process.results.*.hostname'))\n \n title = \"Virus Detected on {0} devices\".format(len(detected_systems))\n \n description = \"Hashes sumbitted with detections:\\n{0}\\n\\n\".format(\", \".join([\"{0} ({1})\".format(*fr) for fr in file_reputation]))\n description += \"File was found on {0} devices:\\n{1}\\n\\n\".format(len(detected_systems), ', '.join(detected_systems))\n description += \"This impacts at least {0} users:\\n{1}\\n\\n\".format(len(detected_users), ', '.join(detected_users))\n if len(blocked_hashes):\n description += \"{0} hashes were submitted for blocking:\\n{1}\\n\\n\".format(len(blocked_hashes), \", \".join(blocked_hashes))\n if len(loggedoff_users):\n description += \"{0} users were forced to logoff:\\n{1}\\n\\n\".format(len(loggedoff_users), \", \".join(loggedoff_users))\n if len(disabled_users):\n description += \"{0} user accounts were disabled:\\n{1}\\n\\n\".format(len(disabled_users), \", \".join(disabled_users))\n if len(shutdown_systems):\n description += \"{0} systems were shutdown:\\n{1}\\n\\n\".format(len(shutdown_systems), \", \".join(shutdown_systems))\n\n parameters = []\n \n # build parameters list for 'create_ticket_2' call\n parameters.append({\n 'short_description': title,\n 'description': description,\n 'fields': \"\",\n })\n\n if parameters:\n phantom.act(\"create ticket\", parameters=parameters, assets=['servicenow'], name=\"create_ticket_2\", parent_action=action) \n else:\n phantom.error(\"'create_ticket_2' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "b9591115-e22e-48e0-952d-47c76448f051", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 114, + "line_start": 69, + "message": "Configuring now", + "name": "create ticket", + "notes": "", + "number": 2, + "order": 4, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1220, + "y": 340 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "create_ticket_2", + "required_params": {}, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Utilities", + "type": "coa.Action", + "warn": false, + "z": 2825 + }, + { + "action": "logoff user", + "action_type": "contain", + "active": false, + "active_keys": {}, + "active_values": { + "ip_hostname": "hunt_file_2:action_result.data.*.process.results.*.hostname", + "username": "" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "ip_hostname": "hunt_file_2:action_result.data.*.process.results.*.hostname", + "username": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "domainctrl1", + "output": [ + { + "column_name": "Username", + "column_order": 0, + "contains": [ + "user name" + ], + "data_path": "action_result.parameter.username", + "data_type": "string" + }, + { + "column_name": "Message", + "column_order": 1, + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "contains": [ + "ip", + "host name" + ], + "data_path": "action_result.parameter.ip_hostname", + "data_type": "string" + }, + { + "column_name": "Total Objects", + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "column_name": "Total Objects Successful", + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "logoff user" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Contain" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_contain.svg" + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def logoff_user_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('logoff_user_1() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'logoff_user_1' call\n results_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:action_result.data.*.process.results.*.hostname', 'hunt_file_2:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'logoff_user_1' call\n for results_item_1 in results_data_1:\n parameters.append({\n 'username': \"\",\n 'ip_hostname': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"logoff user\", parameters=parameters, assets=['domainctrl1'], callback=join_filter_2, name=\"logoff_user_1\", parent_action=action)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#3D9959", + "connected_to_start": false, + "connection_name": "hunt file 2", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "4fb5d51d-3f89-4408-88c4-4af8f22feb5a", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 166, + "line_start": 143, + "message": "Configuring now", + "name": "logoff user", + "notes": "", + "number": 1, + "order": 6, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 840, + "y": 620 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "logoff_user_1", + "required_params": {}, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Contain", + "type": "coa.Action", + "warn": false, + "z": 2827 + }, + { + "0": "S", + "1": "T", + "2": "A", + "3": "R", + "4": "T", + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "ref-x": 33, + "ref-y": 8, + "text": "START" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "ref-x": 13, + "xlink:href": "/inc/coa/img/block_icon_start.svg" + }, + "g.notes": { + "display": "block" + } + }, + "block_code": "def on_start(container):\n phantom.debug('on_start() called')\n \n # call 'file_reputation_1' block\n file_reputation_1(container=container)\n\n return", + "callback_code": "# read-only block view not available", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "", + "connection_type": "", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "4c86e34b-13d5-4884-b1d2-53d1f3448f91", + "inPorts": [], + "join_code": "# read-only block view not available", + "join_optional": [], + "join_start": 1, + "line_end": 24, + "line_start": 16, + "name": "", + "notes": "", + "number": 0, + "order": 1, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 80, + "y": 100 + }, + "previous_function": "", + "previous_name": "", + "show_number": true, + "size": { + "height": 54, + "width": 80 + }, + "status": "", + "title": "START", + "type": "coa.StartEnd", + "warn": false, + "z": 2895 + }, + { + "0": "E", + "1": "N", + "2": "D", + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".title": { + "text": "END" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_end.svg" + }, + "g.notes": { + "display": "block" + } + }, + "block_code": "def on_finish(container, summary):\n phantom.debug('on_finish() called')\n # This function is called after all actions are completed.\n # summary of all the action and/or all details of actions\n # can be collected here.\n\n # summary_json = phantom.get_summary()\n # if 'result' in summary_json:\n # for action_result in summary_json['result']:\n # if 'action_run_id' in action_result:\n # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False)\n # phantom.debug(action_results)\n\n return", + "callback_code": "# read-only block view not available", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "create ticket 2, create ticket 3", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "0444efd4-6363-4dea-acca-b0c02ce9f973", + "inPorts": [ + "in" + ], + "join_code": "# read-only block view not available", + "join_optional": [], + "join_start": 1, + "line_end": 456, + "line_start": 443, + "name": "", + "notes": "", + "number": 0, + "order": 17, + "outPorts": [], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1460, + "y": 100 + }, + "previous_function": "", + "previous_name": "", + "show_number": true, + "size": { + "height": 54, + "width": 80 + }, + "status": "", + "title": "END", + "type": "coa.StartEnd", + "warn": false, + "z": 2901 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 1 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + ".outPorts>.port-1": { + "port": { + "id": "out-2", + "type": "out" + }, + "ref-x": 41, + "ref-y": 82 + }, + ".outPorts>.port-1>.port-body": { + "port": { + "id": "out-2", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_1() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"file_reputation_1:action_result.summary.positives\", \">\", 5],\n [\"file_reputation_1:action_result.summary.positives\", \"<=\", 10],\n ],\n logical_operator='and',\n name=\"filter_1:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n hunt_file_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n get_file_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n # collect filtered artifact ids for 'if' condition 2\n matched_artifacts_2, matched_results_2 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"file_reputation_1:action_result.summary.positives\", \">\", 10],\n ],\n name=\"filter_1:condition_2\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_2 or matched_results_2:\n hunt_file_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_2, filtered_results=matched_results_2)\n get_file_3(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_2, filtered_results=matched_results_2)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "8c9518d8-506f-4750-9e8e-2094bd14d431", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 201, + "line_start": 166, + "name": "filter", + "notes": "", + "number": 1, + "order": 7, + "outPorts": [ + "out-1", + "out-2" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": ">", + "data_type": "", + "param": "file_reputation_1:action_result.summary.positives", + "value": "5" + }, + { + "comparison": "<=", + "data_type": "", + "param": "file_reputation_1:action_result.summary.positives", + "value": "10" + } + ], + "display": "If", + "logic": "and", + "type": "if" + }, + { + "conditions": [ + { + "comparison": ">", + "data_type": "", + "param": "file_reputation_1:action_result.summary.positives", + "value": "10" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 460, + "y": 80 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_1", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 2941 + }, + { + "action": "hunt file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash", + "range": "", + "type": "" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "hash": "filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash", + "range": "", + "type": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7", + "13ded573464ba7f43fe640479b309e09", + "9bf50324444c46997c2492d505b47f2d", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.parameter.range", + "data_type": "string", + "example_values": [ + "0-10", + "0-2", + "5-8" + ] + }, + { + "contains": [ + "carbon black query type" + ], + "data_path": "action_result.parameter.type", + "data_type": "string", + "example_values": [ + "process", + "binary" + ] + }, + { + "data_path": "action_result.data.*.binary.elapsed", + "data_type": "numeric", + "example_values": [ + 0.1120398044586182, + 0.04952096939086914, + 0.1234798431396484, + 0.05507302284240723, + 0.05384993553161621 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.alliance_score_virustotal.*.name", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.alliance_score_virustotal.*.value", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.name", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_sign_time.*.name", + "data_type": "string", + "example_values": [ + "2018-10-01T00:00:00Z", + "2015-01-01T00:00:00Z", + "2013-11-01T00:00:00Z" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_sign_time.*.value", + "data_type": "numeric", + "example_values": [ + 1, + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.name", + "data_type": "string", + "example_values": [ + "16.0.10827.20181", + "4.7.0205.0", + "6.1.7600.16385 (win7_rtm.090713-1255)" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.name", + "data_type": "string", + "example_values": [ + "default group" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.host_count.*.name", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.host_count.*.value", + "data_type": "numeric", + "example_values": [ + 1, + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.name", + "data_type": "string", + "example_values": [ + "CB-TEST-02", + "WIN7-CLIENT1", + "ACCOUNTING-PC" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.ratio", + "data_type": "string", + "example_values": [ + "100.0", + "16.7" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.name", + "data_type": "string", + "example_values": [ + "c:\\program files\\common files\\microsoft shared\\clicktorun\\updates\\16.0.10827.20181\\officeclicktorun.exe", + "c:\\program files\\microsoft security client\\nissrv.exe", + "C:\\Windows\\system32\\ping.exe" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0", + "50.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.name", + "data_type": "string", + "example_values": [ + "Microsoft Office", + "Microsoft Malware Protection" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.server_added_timestamp.*.name", + "data_type": "string", + "example_values": [ + "2018-10-19T00:00:00Z", + "2018-09-29T00:00:00Z", + "2018-10-02T00:00:00Z" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.server_added_timestamp.*.value", + "data_type": "numeric", + "example_values": [ + 1, + 0 + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.binary.highlights.*.ids", + "data_type": "string", + "example_values": [ + "13DED573464BA7F43FE640479B309E09", + "9BF50324444C46997C2492D505B47F2D", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.data.*.binary.highlights.*.name", + "data_type": "string", + "example_values": [ + "PREPREPRE13DED573464BA7F43FE640479B309E09POSTPOSTPOST", + "PREPREPRE9BF50324444C46997C2492D505B47F2DPOSTPOSTPOST", + "PREPREPRE5FB30FE90736C7FC77DE637021B1CE7CPOSTPOSTPOST" + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.binary.results.*.alliance_data_srstrust", + "data_type": "string", + "example_values": [ + "5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.binary.results.*.alliance_link_srstrust", + "data_type": "string", + "example_values": [ + "https://services.bit9.com/Services/extinfo.aspx?ak=b8b4e631d4884ad1c56f50e4a5ee9279&sg=0313e1735f6cec221b1d686bd4de23ee&md5=5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.alliance_score_srstrust", + "data_type": "numeric", + "example_values": [ + -100 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.alliance_updated_srstrust", + "data_type": "string", + "example_values": [ + "2018-02-07T02:37:28Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.cb_version", + "data_type": "numeric", + "example_values": [ + 610, + 510, + 511 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.company_name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.copied_mod_len", + "data_type": "numeric", + "example_values": [ + 9683736, + 366512, + 16896 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_issuer", + "data_type": "string", + "example_values": [ + "Microsoft Code Signing PCA" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_prog_name", + "data_type": "string", + "example_values": [ + "Microsoft Office", + "Microsoft Corp." + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_publisher", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_result", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_result_code", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_sign_time", + "data_type": "string", + "example_values": [ + "2018-10-14T20:23:00Z", + "2015-01-30T19:14:00Z", + "2009-07-14T10:17:00Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_subject", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.endpoint", + "data_type": "string", + "example_values": [ + "CB-TEST-02|27", + "WIN7-CLIENT1|15", + "DC1|19" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.event_partition_id", + "data_type": "numeric", + "example_values": [ + 100972684312576, + 100955696070656 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.facet_id", + "data_type": "numeric", + "example_values": [ + 883737, + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.file_desc", + "data_type": "string", + "example_values": [ + "Microsoft Office Click-to-Run (SxS)", + "Microsoft Network Realtime Inspection Service", + "TCP/IP Ping Command" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.file_version", + "data_type": "string", + "example_values": [ + "16.0.10827.20181", + "4.7.0205.0", + "6.1.7600.16385 (win7_rtm.090713-1255)" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.group", + "data_type": "string", + "example_values": [ + "Default Group" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.host_count", + "data_type": "numeric", + "example_values": [ + 1, + 6 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.internal_name", + "data_type": "string", + "example_values": [ + "OfficeClickToRun.exe", + "NisSrv.exe", + "ping.exe" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.is_64bit", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.is_executable_image", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.last_seen", + "data_type": "string", + "example_values": [ + "2018-10-28T10:06:02.456Z", + "2018-10-28T10:06:42.455Z", + "2018-10-26T00:01:41.224Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.legal_copyright", + "data_type": "string", + "example_values": [ + "Microsoft Corporation. All rights reserved." + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.binary.results.*.md5", + "data_type": "string", + "example_values": [ + "13DED573464BA7F43FE640479B309E09", + "9BF50324444C46997C2492D505B47F2D", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.observed_filename", + "data_type": "string", + "example_values": [ + "c:\\program files\\common files\\microsoft shared\\clicktorun\\updates\\16.0.10827.20181\\officeclicktorun.exe", + "c:\\program files\\microsoft security client\\nissrv.exe", + "c:\\windows\\system32\\ping.exe" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.orig_mod_len", + "data_type": "numeric", + "example_values": [ + 9683736, + 366512, + 16896 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.original_filename", + "data_type": "string", + "example_values": [ + "OfficeClickToRun.exe", + "NisSrv.exe", + "ping.exe.mui" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.os_type", + "data_type": "string", + "example_values": [ + "Windows" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.product_name", + "data_type": "string", + "example_values": [ + "Microsoft Office", + "Microsoft Malware Protection" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.product_version", + "data_type": "string", + "example_values": [ + "16.0.10827.20181", + "4.7.0205.0", + "6.1.7600.16385" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.server_added_timestamp", + "data_type": "string", + "example_values": [ + "2018-10-19T17:04:47.906Z", + "2015-07-01T02:12:21.783Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "column_name": "Signed", + "column_order": 1, + "data_path": "action_result.data.*.binary.results.*.signed", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.timestamp", + "data_type": "string", + "example_values": [ + "2018-10-19T17:04:47.906Z", + "2015-07-01T02:12:21.783Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.watchlists.*.value", + "data_type": "string", + "example_values": [ + "2015-07-01T02:20:02.062Z", + "2015-05-15T07:30:02.843Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.watchlists.*.wid", + "data_type": "string", + "example_values": [ + "5" + ] + }, + { + "data_path": "action_result.data.*.binary.start", + "data_type": "numeric", + "example_values": [ + 0, + 5 + ] + }, + { + "data_path": "action_result.data.*.binary.terms", + "data_type": "string", + "example_values": [ + "md5:13ded573464ba7f43fe640479b309e09", + "md5:9bf50324444c46997c2492d505b47f2d", + "md5:5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.data.*.binary.total_results", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.process.all_segments", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.comprehensive_search", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.elapsed", + "data_type": "numeric", + "example_values": [ + 0.2200779914855957 + ] + }, + { + "data_path": "action_result.data.*.process.facets.day_of_week.*.name", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.day_of_week.*.value", + "data_type": "numeric", + "example_values": [ + 1566 + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.name", + "data_type": "string", + "example_values": [ + "default group" + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.value", + "data_type": "numeric", + "example_values": [ + 10128 + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.name", + "data_type": "string", + "example_values": [ + "domain_controller" + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.value", + "data_type": "numeric", + "example_values": [ + 10123 + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.name", + "data_type": "string", + "example_values": [ + "dc2" + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.ratio", + "data_type": "string", + "example_values": [ + "51.2" + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.value", + "data_type": "numeric", + "example_values": [ + 5185 + ] + }, + { + "data_path": "action_result.data.*.process.facets.hour_of_day.*.name", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.hour_of_day.*.value", + "data_type": "numeric", + "example_values": [ + 411 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.process.facets.parent_name.*.name", + "data_type": "string", + "example_values": [ + "svchost.exe" + ] + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.process.facets.path_full.*.name", + "data_type": "string", + "example_values": [ + "c:\\windows\\syswow64\\wbem\\wmiprvse.exe" + ] + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.process.facets.process_md5.*.name", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.process.facets.process_name.*.name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "data_path": "action_result.data.*.process.facets.start.*.name", + "data_type": "string", + "example_values": [ + "2018-02-24T00:00:00Z" + ] + }, + { + "data_path": "action_result.data.*.process.facets.start.*.value", + "data_type": "numeric", + "example_values": [ + 324 + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.name", + "data_type": "string", + "example_values": [ + "LOCAL SERVICE" + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.ratio", + "data_type": "string", + "example_values": [ + "98.4" + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.value", + "data_type": "numeric", + "example_values": [ + 9966 + ] + }, + { + "data_path": "action_result.data.*.process.incomplete_results", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.process.results.*.alliance_data_srstrust", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.process.results.*.alliance_link_srstrust", + "data_type": "string", + "example_values": [ + "https://services.bit9.com/Services/extinfo.aspx?ak=b8b4e631d4884ad1c56f50e4a5ee9279&sg=0313e1735f6cec221b1d686bd4de23ee&md5=4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.alliance_score_srstrust", + "data_type": "numeric", + "example_values": [ + -100 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.alliance_updated_srstrust", + "data_type": "string", + "example_values": [ + "2018-02-07T02:37:28Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.childproc_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "contains": [ + "file path" + ], + "data_path": "action_result.data.*.process.results.*.cmdline", + "data_type": "string", + "example_values": [ + "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -Embedding" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.comms_ip", + "data_type": "numeric", + "example_values": [ + 168886572 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.crossproc_count", + "data_type": "numeric", + "example_values": [ + 2 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.emet_config", + "data_type": "string", + "example_values": [ + "" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.emet_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.filemod_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.filtering_known_dlls", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.results.*.group", + "data_type": "string", + "example_values": [ + "default group" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.host_type", + "data_type": "string", + "example_values": [ + "workstation" + ] + }, + { + "contains": [ + "host name" + ], + "data_path": "action_result.data.*.process.results.*.hostname", + "data_type": "string", + "example_values": [ + "win7-client1" + ] + }, + { + "contains": [ + "carbon black process id" + ], + "data_path": "action_result.data.*.process.results.*.id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0688-01d3-27738c9b4243" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.interface_ip", + "data_type": "numeric", + "example_values": [ + 168886572 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.last_server_update", + "data_type": "string", + "example_values": [ + "2018-03-22T09:21:32.332Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.last_update", + "data_type": "string", + "example_values": [ + "2017-09-07T00:52:15.82Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.modload_count", + "data_type": "numeric", + "example_values": [ + 43 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.netconn_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.os_type", + "data_type": "string", + "example_values": [ + "windows" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0258-01d1-ec51b545a19b" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_md5", + "data_type": "string", + "example_values": [ + "000000000000000000000000000000" + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.process.results.*.parent_name", + "data_type": "string", + "example_values": [ + "svchost.exe" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_pid", + "data_type": "numeric", + "example_values": [ + 600 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_unique_id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0258-01d1-ec51b545a19b-000000000001" + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.process.results.*.path", + "data_type": "string", + "example_values": [ + "c:\\windows\\syswow64\\wbem\\wmiprvse.exe" + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.process.results.*.process_md5", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "contains": [ + "process name", + "file name" + ], + "data_path": "action_result.data.*.process.results.*.process_name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe" + ] + }, + { + "contains": [ + "pid" + ], + "data_path": "action_result.data.*.process.results.*.process_pid", + "data_type": "numeric", + "example_values": [ + 1672 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.processblock_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.regmod_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.segment_id", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.data.*.process.results.*.sensor_id", + "data_type": "numeric", + "example_values": [ + 15 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.start", + "data_type": "string", + "example_values": [ + "2017-09-07T00:52:15.758Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.terminated", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.results.*.unique_id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0688-01d3-27738c9b4243-000000000001" + ] + }, + { + "contains": [ + "user name" + ], + "data_path": "action_result.data.*.process.results.*.username", + "data_type": "string", + "example_values": [ + "SYSTEM" + ] + }, + { + "data_path": "action_result.data.*.process.start", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.terms", + "data_type": "string", + "example_values": [ + "md5:4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "data_path": "action_result.data.*.process.total_results", + "data_type": "numeric", + "example_values": [ + 32404 + ] + }, + { + "data_path": "action_result.summary.device_count", + "data_type": "numeric", + "example_values": [ + 32404, + 1 + ] + }, + { + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "Displaying 10 'process' results of total 32404", + "Displaying 1 'binary' results of total 1", + "Displaying 0 'binary' results of total 1" + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "hunt file 2" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def hunt_file_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('hunt_file_2() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'hunt_file_2' call\n filtered_results_data_1 = phantom.collect2(container=container, datapath=[\"filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash\", \"filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.context.artifact_id\"])\n\n parameters = []\n \n # build parameters list for 'hunt_file_2' call\n for filtered_results_item_1 in filtered_results_data_1:\n if filtered_results_item_1[0]:\n parameters.append({\n 'hash': filtered_results_item_1[0],\n 'type': \"\",\n 'range': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_results_item_1[1]},\n })\n\n phantom.act(action=\"hunt file\", parameters=parameters, assets=['carbonblack'], callback=hunt_file_2_callback, name=\"hunt_file_2\")\n\n return", + "callback_code": "def hunt_file_2_callback(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None):\n phantom.debug('hunt_file_2_callback() called')\n \n disable_user_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function)\n logoff_user_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function)\n shutdown_system_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function)\n block_hash_3(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function)\n\n return", + "callback_start": 226, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "6f5751ac-efaa-4f6e-97cf-29c88c78b381", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 236, + "line_start": 201, + "message": "Configuring now", + "name": "hunt file", + "notes": "", + "number": 2, + "order": 8, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 600, + "y": 340 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "hunt_file_2", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 2944 + }, + { + "action": "get file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "file_source": "", + "get_count": "", + "hash": "filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash", + "offset": "", + "ph_0": "", + "sensor_id": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "contains": [ + "file path" + ], + "data_path": "action_result.parameter.file_source", + "data_type": "string", + "example_values": [ + "C:\\\\Windows\\\\CarbonBlack\\\\Sensor.LOG" + ] + }, + { + "data_path": "action_result.parameter.get_count", + "data_type": "numeric", + "example_values": [ + 1024 + ] + }, + { + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "75E683BC8284D99F998500162BE4CFE2", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.parameter.offset", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.parameter.sensor_id", + "data_type": "numeric", + "example_values": [ + 27 + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.file_details.alliance_data_srstrust", + "data_type": "string", + "example_values": [ + "5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.file_details.alliance_link_srstrust", + "data_type": "string", + "example_values": [ + "https://services.bit9.com/Services/extinfo.aspx?ak=b8b4e631d4884ad1c56f50e4a5ee9279&sg=0313e1735f6cec221b1d686bd4de23ee&md5=5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "data_path": "action_result.data.*.file_details.alliance_score_srstrust", + "data_type": "numeric", + "example_values": [ + -100 + ] + }, + { + "data_path": "action_result.data.*.file_details.alliance_updated_srstrust", + "data_type": "string", + "example_values": [ + "2018-02-07T02:37:28Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.cb_version", + "data_type": "numeric", + "example_values": [ + 610, + 511 + ] + }, + { + "data_path": "action_result.data.*.file_details.company_name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.file_details.copied_mod_len", + "data_type": "numeric", + "example_values": [ + 489984, + 16896 + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_publisher", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_result", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_result_code", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_sign_time", + "data_type": "string", + "example_values": [ + "2018-02-12T10:14:00Z", + "2009-07-14T10:17:00Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.endpoint", + "data_type": "string", + "example_values": [ + "WIN10-TEST-EP|28", + "DC1|19" + ] + }, + { + "data_path": "action_result.data.*.file_details.event_partition_id", + "data_type": "numeric", + "example_values": [ + 99742385111040, + 100955696070656 + ] + }, + { + "data_path": "action_result.data.*.file_details.facet_id", + "data_type": "numeric", + "example_values": [ + 241095, + 0 + ] + }, + { + "data_path": "action_result.data.*.file_details.file_desc", + "data_type": "string", + "example_values": [ + "WMI Provider Host", + "TCP/IP Ping Command" + ] + }, + { + "data_path": "action_result.data.*.file_details.file_version", + "data_type": "string", + "example_values": [ + "10.0.16299.248 (WinBuild.160101.0800)", + "6.1.7600.16385 (win7_rtm.090713-1255)" + ] + }, + { + "data_path": "action_result.data.*.file_details.group", + "data_type": "string", + "example_values": [ + "Default Group" + ] + }, + { + "data_path": "action_result.data.*.file_details.host_count", + "data_type": "numeric", + "example_values": [ + 2, + 6 + ] + }, + { + "data_path": "action_result.data.*.file_details.icon", + "data_type": "string", + "example_values": [ + "iVBORw0KGgoAAAANSUhEUgAAADAAAAAwCAYAAABXAvmHAAAAAXNSR0IArs4c6QAAAARnQU1BAACx\njwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAAzoSURBVGhD1ZhXcFzlFccNPJBg8pIJY554JOGB\nzCQPhMwkDN3JJA6BkECSwYCFe5MtyepdWvW60kpa9dVKK61WWvXed9Ulq3fLEjZ2jCxjGxtcsPnn\nnKO98qp47GGIRM7M8S2r3fv/ne+U73oL/s9t0wASExPF8/JybXfub/n5+cu+2jYcwGDQy5GFT05O\nijNIUFCQ3F/PjEYjLFbr5gOw+OioCNsVRDQDDA8PIzs7+74QDDA5OYGUlBTbnXu2YQDzc58iMyMN\nJ/v7lyFYMPvs7CyuXr0KlWrperUxwJkzn6772YYB5BvyMDo6ugKAjUUNDg4KAIMwREKC2vbpkjHA\npUuX4OzsbLtzzzYMoKDAgPPnz+Py5cvQapOXISIjwmGxtAmAAuHu7iafKcYAvb292L17t+3OPdtw\ngIWFBQxRxBUIq9WyLP7ixYtYXFxERMS9FWIzmUw/DACO7vz8vAiPCA9DS3OTiFacxd+5c+eHCxAa\nGirCLW2tuHLl8grxvDIsfmZmZk2xbirA8PC4RDw8LFSE24tW/ObNm7h+/bqIt1K/D/D3t317yTYF\nQBHOvlr4lStXJNos7MaNGyJcEc+rtLqINwXA08MNNTU16wrv7OzEgQMHsGPHDhHNXllZKe7p4bFG\n6KalEEPwlGXxinAnJycRvtSBrEhKSloWHxgYSPkfYPv2PdvUGmChDHH69Oll4d3d3SJKWYXCwkLE\nxsauK55tUwHYWLRWq10jnO/zBk2lUt1XPNumA7A5OjoKhCKcU+dhxLP9zwG2bNmCRx55RI6PPvqo\nOJ+z25sCoezt+Vyj0dg+vb99JwD/qAQExycjOC4ZIWototN0SMjKQ7LeiKjUbMRn5cK8/Q1sfeyx\nJYAntmLbM8/gp9u24RfPPYdtTz+Nx+gzBYbtHad8vPaxdoXzvQfZQwOw6KDYJBEckZyBdGMJylu7\nYBmeQGP/CMrbupBf3YjMonKosw1IzMnHj378Y7z02pt470MH7Nx7CI8//ji2bt2KZwjml88/j58/\n+yyefPJJWaEdR/QIyj8pHmhYOh5LbLE9/f72UABRKVkIS0xDqsGM0uYOtI1Mo2N8FtaxU2gbnUbr\n0CRahiZQ1zuIuEw9zi0skrCf4Pevvg5dSRUyiysQk54DVXwKfCPi4BkSBbegcDgcOoafPfUUtj7x\nBN4+bhDRTbOXxRWA9dLN3h4IkKQzQEMRbSFxI/Pn0TP9KdonTsMyegqtI1MkfBLNg+M2HxMAh8NO\n+NULLyKt0CxQJS3tKG6ywFjXgtyKWqSbyqDRFyI6VUdA8bIq77oYRXiWZQ4uKVa8+lHK97MC5uoG\n9A2P4Zs7d3H7m7u4fuMmLl65hrnPFzE6fw49UwQzMonGgVHU9w2jtmcQZW2dKKhpQmF9C8otXTA3\nW2BqaKF7jcitrIOurFpWJa2wDNkl1fj1b36Lf3oUo2HmC0SYh8UVAJ/wWPFQjVZErbYHAmSbqzBw\n6iwmP1vA/MIXWLh6DV9+dQNf37pNfkuAFuneGUqb8fmz6J2cgWVoDFXtPQJQ1NRG4lsp+s0wMACt\nQHZpFTKoVrQFZqQWlmL7W3/HTr9SWM9eQ5hpSFwBCIxOQmCMBgHRict1GKZJI6BUeIerHwKgtIby\nnaI8Nkt+Cu2U+91Tcxg8fRZTZy/g7MVLWPzyGq59TVA3b8nx4uWrmDt/AYPTs2jpG6Bib4fRTrxE\n31SKlPxiqHXU76kxfBxUjp4LXyG44KS4AuAXmQjfMDV8wuIREJkA79BYHDzhiz3HPXDI3f/BADll\ntZL3HRNzsJJ4hmilIm4enoJ1YpaKeEpSyEreO3EKI7PzmDl7HmcuLODcxUUp6Llz/8Hw9ClY+gZR\nQemURymUZjRLtwrTpEOVkAqHkCoMLt6Ef24v/PU9dgAc9WS4+Idhn5MXdh0+AYejblL0XDNFveeg\nbZjBLlUl/uVpxu/eTxDxbAKgzs5HfKYBGaYKKkQuxpXOLZS9gbymewDVnX3itV19aOg5idb+IXRS\nSvWNTaJ/fAo9I+Noo1WpplUprKpHJqVQEhX0J6HVGLlyG97ZXeIKgBdFfL+LNz465IxPHN2wx8kT\n++iaAez9lQ+TxdcAcOG1UHfhPq+jgovNyBV3OeYozucM0Do8KR2HxVdYu1Ha2kmA3Hko92k+5FXW\nw0AFXEBNwVTbRN4IE50b6X4etVpegbGr38AjvUNcARDhx9yx19mLhPvggKsfDrr546hnkAh3Trbg\nffciOX/hnSgRrpgA6DmFpubRNX0aXVOz4iy6yGyCnl4FuQDjMvKoyJJowGXRADMiy1wpQ40BuJAN\nVQ3UeWrofgVSaQCq6W8Sc02Iy8qX78am67EruAJT1+/AVWsVVwD2UtrsP+FDov1w2D0AR72C4ewX\nAiefYBGd3jwLx4QWgbCPPpsAZBVVossu/9upoBmA7dT8nAC0j01RYVPBUqpUWLugL6+VtPMMiZUu\nEp6USdsL2moYimi7UQB1Rs6yhySkIZj8o8ByTH91F05JbeIKwCGK9mGPQDh6q6QOjnsHyW6gpNm6\nBuClf2tWDD05yzCVy9RtG52RCWyhIwNkZWoRGkRR2e2ABur/PAPqe4fQeHKYUm6UpvQkurkL0XlZ\nW4dM5CitbkX6uQVHIig+VZzb6OyNb9cAOHqx8HA4+6rgoYqilW2Q2cHfWQ3A37Gf3PJvWkEp7Xem\naMrSxB2YQNPAuIiobKwXZ4Cqjl7xktYOFDdaYapvRT4NsjxKHU6hUrpf09UvMJxq9ukXQh3I0SsI\nH/iWYP424JbaLq4AuAaGS7ok55noty006Q0IScygzpWxBuCNT9KXAcQZQGsoRguJru/nSTtCk3aI\n+nglkpPU4i5+4Sim/ZG5pYMGVhuMtZTzlP/6ijrq+dU0sCqgpbxPyitCAuU+A7Ap6VdHnaqThh+3\nwDN3sKILHVU3EyClC3WslIISRKToEKnNkaNzYMoagD/sy8LLb/usBOAWV987TN1lAJXt/ZTjfSiz\n9CylAonPJaFFFPUC2ucYqprouh46Gn6ZVMhptOdJyTdDk0vidQVUtAYBsE8/3gt5RySIgPPfAr45\nPeIMcDiuUYqfRUenU/ej6LPHZBjwt31qAeChxwDsfP3KexErAdTUKVh4aWs3RbmLOksHCW6HiUTz\nkhrrWilVOOL1MrV5ddIKeZtwL+rcbWJIQGRqjgDYpx8XuhdN2X+4FmKBAEILB8UZYH9UPUU7WwSr\ndYV2bsRfjuol+nxk8fbXKwBiqMWVNHdSLrPYNhTUtlKKNNtEc3usRRYVVTp1q1RjGXWaEom4OqdQ\nhHPkWHg4CQnVZAqAkn4fH3SBe0gc3FWxshu9RABxFePiDLAnvEYinpBjorZbJL+r+J8O5ohgPjKA\n/fUKgEh6cCEJ11c0Iqeco0yCzTWU21W0ESun3Cwl0WZ5QAKJjs8ukIcqwsNYOLVRVUI6AuO18I+l\n1KB+zuK9w+LgpoqBa1CUvH19TgAp9dPiDMDDLVFvopUsRhLVIj8nyeac70l103JkAPtrFs8m/3Kf\nDiMBUWm5snT8Y/xDktci2JYitMzRaXoSrado6+g7WQjRZEiPD4xLFeF+FH3viER40S7SPZTEBy+J\ndwmIxFuOufjsLqBrnxNnAJ4NGkpD5ZlcT+x8zh0ntmxUjgxgf62YAPhGqmXy8dbVJ0JND4+HD+0Q\nA+K0BJeBsGQdIqjIwpI50iSaWlwwRTtIbRMeQ29hJNwnSkPfTYAn5bs75b1rcDRO2MQ7U59fD4Bb\n60qAEhtAsXyuMg7IkQHsrxVbWodVplLzPjwenrTJcldFUxTJKQ04qr6RGhKcLHB+inC6x13Gkz73\n4KhTvov4QBYfASc/mq6+ofJOfPoW1VzZmDgL4ZccDW05lgCWnBtDMkHw1OV2y0cGsL9WbF2A1ca7\nxRMB4TTqg0WQM527kLNIN4o0pwoL52J1JVCJeiBHfUn8MZ9QOPqopPg48vxewM4A3JkSKU01VAdL\nxWui7lYqw4z3PfzqyUcGsL9W7KEAVpvDERcqUn8cdPWV/QtH97hfqIjlVHFil6iz+BD5myO0Qfvj\n/mzEli9Fn4/sXNgJVHfcivkdWkuR9wyNxl/f34kX340R4esdFftOAKvtw/3H6AXEVV5GeB9/hLbB\nvKNkd5RjEN0LxPa9mSJaWQE+57rg95FEEh+VqsO+4+54efsO+V3eOrPg9Y6KfS8Aq83h6Ans3OdI\nK3WCoDxlm8yvhm/uyRDhh+j6AG2f+fzPh/QCwO/CB1w8bb+wZJsGsNoY5oO9R/Hm7iWA3fTycoDe\nefmc02q/syd27j1i++t7tj+yTsTazwG+5u2HYhsCoBgD8H9msXB2Pue0up+98V4IXt9FO1kSrzhf\n833FNhSAH8ydx97txaxnCoTiq/9+QwG+fwP+CyGRvQpx7eyKAAAAAElFTkSuQmCC\n", + "iVBORw0KGgoAAAANSUhEUgAAACUAAAAlCAYAAADFniADAAAAAXNSR0IArs4c6QAAAARnQU1BAACx\njwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAAAlwSFlz\nAAAewgAAHsIBbtB1PgAAAjJJREFUWEftWEFrGkEYVQIqGtFTjrmF/IEYWLzEgOQQiBCIEPaiEATb\n9CA0eKiFlgqlBw9CI9Yl1kjjIhYPNSgpSkuN4kXPXgr+k9f5Ju7SYoNDaY2UGXh833z7vuHxdnbZ\nHYtFDkEH0un0zbIgEoncMNmXFiYIlUoFtVoNiUSCI5VK8Ui1YrHI83g8jmw2a9aoTjA4lFMfxXK5\n/EudOAaPYjKZRKFQ4DUDmqaBiQIT9Z2L6nQ6SKe72N1N4uAgg729FyaoRtjffw1V/cDrNKd4ePgW\nx8fvcXT0zqzRNZqfnn7jHOqLRutm38nJNedSjTgGzs6qs6K2t78wlc8ZOtNIOeHNNGo/5VR7yvCK\n4Wp6nXKjh9a469vYyEJRPmJt7RG83ifw+z9hc/MZVlYeY2vrGjs7X7G+fgGf7+V9omgxUZCI+dzz\n81v0+33EYjEEg0Get1otuFwulEolPldVlYny/Q1R8wWR6EymjXa7zW5XFIFAgOf1eh1OpxP5fJ7P\nw+HwYkWtrvrZbfPC4XDAZrPx3OPxwGq1wu1287ndbv+9KF2/hab9C1yxdbW5oCd75unTdX1uo8ji\nf8JpNBr81TAjKpfLoVqtotvtLhy9Xu9+UcPhEA8xJpOJFCVkvHRKyCZGkk5Jp0QdEOXJPSWdEnVA\nlCf3lHRK1AFRntxT/6dTzWYTg8EA4/F44RiNRrPf6MZJCZ2WPBTob8r8xQqFQlgWKIpydxTExucl\nw6Xged9iaT8A6ipWINQO9M4AAAAASUVORK5CYII=\n" + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.file_details.internal_name", + "data_type": "string", + "example_values": [ + "Wmiprvse.exe", + "ping.exe" + ] + }, + { + "data_path": "action_result.data.*.file_details.is_64bit", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.file_details.is_executable_image", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.file_details.last_seen", + "data_type": "string", + "example_values": [ + "2018-03-25T06:49:27.776Z", + "2018-10-26T00:01:41.224Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.legal_copyright", + "data_type": "string", + "example_values": [ + "Microsoft Corporation. All rights reserved." + ] + }, + { + "column_name": "MD5", + "column_order": 0, + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.data.*.file_details.md5", + "data_type": "string", + "example_values": [ + "75E683BC8284D99F998500162BE4CFE2", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.file_details.observed_filename", + "data_type": "string", + "example_values": [ + "c:\\windows\\system32\\wbem\\wmiprvse.exe", + "c:\\windows\\system32\\ping.exe" + ] + }, + { + "data_path": "action_result.data.*.file_details.orig_mod_len", + "data_type": "numeric", + "example_values": [ + 489984, + 16896 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.file_details.original_filename", + "data_type": "string", + "example_values": [ + "Wmiprvse.exe", + "ping.exe.mui" + ] + }, + { + "data_path": "action_result.data.*.file_details.os_type", + "data_type": "string", + "example_values": [ + "Windows" + ] + }, + { + "data_path": "action_result.data.*.file_details.product_name", + "data_type": "string", + "example_values": [ + "Microsoft Windows Operating System" + ] + }, + { + "data_path": "action_result.data.*.file_details.product_version", + "data_type": "string", + "example_values": [ + "10.0.16299.248", + "6.1.7600.16385" + ] + }, + { + "data_path": "action_result.data.*.file_details.server_added_timestamp", + "data_type": "string", + "example_values": [ + "2018-02-15T01:48:13.517Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.signed", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.file_details.timestamp", + "data_type": "string", + "example_values": [ + "2018-02-15T01:48:13.517Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.watchlists.*.value", + "data_type": "string", + "example_values": [ + "2015-05-15T07:30:02.843Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.watchlists.*.wid", + "data_type": "string", + "example_values": [ + "5" + ] + }, + { + "data_path": "action_result.data.*.file_id", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "contains": [ + "file name", + "file path" + ], + "data_path": "action_result.data.*.name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe", + "C:\\Windows\\CarbonBlack\\Sensor.LOG", + "ping.exe" + ] + }, + { + "data_path": "action_result.data.*.session_id", + "data_type": "numeric", + "example_values": [ + 101 + ] + }, + { + "column_name": "Vault ID", + "column_order": 1, + "contains": [ + "vault id", + "sha1" + ], + "data_path": "action_result.data.*.vault_id", + "data_type": "string", + "example_values": [ + "08f57fd06bbd8063d5b828521654225952a8155e", + "41c4e1e9abe08b218f5ea60d8ae41a5f523e7534" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.summary.cb_url", + "data_type": "string", + "example_values": [ + "https://192.168.0.245/#/binary/75E683BC8284D99F998500162BE4CFE2", + "https://10.1.16.170/#/binary/5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.summary.file_type", + "data_type": "string", + "example_values": [ + "pe file" + ] + }, + { + "contains": [ + "file name", + "file path" + ], + "data_path": "action_result.summary.name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe", + "C:\\Windows\\CarbonBlack\\Sensor.LOG", + "ping.exe" + ] + }, + { + "contains": [ + "vault id", + "sha1" + ], + "data_path": "action_result.summary.vault_id", + "data_type": "string", + "example_values": [ + "08f57fd06bbd8063d5b828521654225952a8155e", + "41c4e1e9abe08b218f5ea60d8ae41a5f523e7534" + ] + }, + { + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "File type: pe file\nVault id: 08f57fd06bbd8063d5b828521654225952a8155e\nName: wmiprvse.exe\nCb url: https://192.168.0.245/#/binary/75E683BC8284D99F998500162BE4CFE2", + "Vault id: cefbc5c62d7e1f90d250ddcd35bc388a7b01f4d4, Name: C:\\Windows\\CarbonBlack\\Sensor.LOG", + "File type: pe file, Vault id: 41c4e1e9abe08b218f5ea60d8ae41a5f523e7534, Name: ping.exe, Cb url: https://10.1.16.170/#/binary/5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "get file 3" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def get_file_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('get_file_3() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'get_file_3' call\n filtered_results_data_1 = phantom.collect2(container=container, datapath=[\"filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash\", \"filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.context.artifact_id\"])\n\n parameters = []\n \n # build parameters list for 'get_file_3' call\n for filtered_results_item_1 in filtered_results_data_1:\n parameters.append({\n 'hash': filtered_results_item_1[0],\n 'ph_0': \"\",\n 'offset': \"\",\n 'get_count': \"\",\n 'sensor_id': \"\",\n 'file_source': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_results_item_1[1]},\n })\n\n phantom.act(action=\"get file\", parameters=parameters, assets=['carbonblack'], name=\"get_file_3\")\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "e6a1a311-5337-4d44-b8d3-58d8a6cf8be1", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 263, + "line_start": 236, + "message": "Configuring now", + "name": "get file", + "notes": "", + "number": 3, + "order": 9, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 600, + "y": 900 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "get_file_3", + "required_params": {}, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 2945 + }, + { + "action": "get file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "file_source": "", + "get_count": "", + "hash": "filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash", + "offset": "", + "ph_0": "", + "sensor_id": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "contains": [ + "file path" + ], + "data_path": "action_result.parameter.file_source", + "data_type": "string", + "example_values": [ + "C:\\\\Windows\\\\CarbonBlack\\\\Sensor.LOG" + ] + }, + { + "data_path": "action_result.parameter.get_count", + "data_type": "numeric", + "example_values": [ + 1024 + ] + }, + { + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "75E683BC8284D99F998500162BE4CFE2", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.parameter.offset", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.parameter.sensor_id", + "data_type": "numeric", + "example_values": [ + 27 + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.file_details.alliance_data_srstrust", + "data_type": "string", + "example_values": [ + "5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.file_details.alliance_link_srstrust", + "data_type": "string", + "example_values": [ + "https://services.bit9.com/Services/extinfo.aspx?ak=b8b4e631d4884ad1c56f50e4a5ee9279&sg=0313e1735f6cec221b1d686bd4de23ee&md5=5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "data_path": "action_result.data.*.file_details.alliance_score_srstrust", + "data_type": "numeric", + "example_values": [ + -100 + ] + }, + { + "data_path": "action_result.data.*.file_details.alliance_updated_srstrust", + "data_type": "string", + "example_values": [ + "2018-02-07T02:37:28Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.cb_version", + "data_type": "numeric", + "example_values": [ + 610, + 511 + ] + }, + { + "data_path": "action_result.data.*.file_details.company_name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.file_details.copied_mod_len", + "data_type": "numeric", + "example_values": [ + 489984, + 16896 + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_publisher", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_result", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_result_code", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.file_details.digsig_sign_time", + "data_type": "string", + "example_values": [ + "2018-02-12T10:14:00Z", + "2009-07-14T10:17:00Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.endpoint", + "data_type": "string", + "example_values": [ + "WIN10-TEST-EP|28", + "DC1|19" + ] + }, + { + "data_path": "action_result.data.*.file_details.event_partition_id", + "data_type": "numeric", + "example_values": [ + 99742385111040, + 100955696070656 + ] + }, + { + "data_path": "action_result.data.*.file_details.facet_id", + "data_type": "numeric", + "example_values": [ + 241095, + 0 + ] + }, + { + "data_path": "action_result.data.*.file_details.file_desc", + "data_type": "string", + "example_values": [ + "WMI Provider Host", + "TCP/IP Ping Command" + ] + }, + { + "data_path": "action_result.data.*.file_details.file_version", + "data_type": "string", + "example_values": [ + "10.0.16299.248 (WinBuild.160101.0800)", + "6.1.7600.16385 (win7_rtm.090713-1255)" + ] + }, + { + "data_path": "action_result.data.*.file_details.group", + "data_type": "string", + "example_values": [ + "Default Group" + ] + }, + { + "data_path": "action_result.data.*.file_details.host_count", + "data_type": "numeric", + "example_values": [ + 2, + 6 + ] + }, + { + "data_path": "action_result.data.*.file_details.icon", + "data_type": "string", + "example_values": [ + "iVBORw0KGgoAAAANSUhEUgAAADAAAAAwCAYAAABXAvmHAAAAAXNSR0IArs4c6QAAAARnQU1BAACx\njwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAAzoSURBVGhD1ZhXcFzlFccNPJBg8pIJY554JOGB\nzCQPhMwkDN3JJA6BkECSwYCFe5MtyepdWvW60kpa9dVKK61WWvXed9Ulq3fLEjZ2jCxjGxtcsPnn\nnKO98qp47GGIRM7M8S2r3fv/ne+U73oL/s9t0wASExPF8/JybXfub/n5+cu+2jYcwGDQy5GFT05O\nijNIUFCQ3F/PjEYjLFbr5gOw+OioCNsVRDQDDA8PIzs7+74QDDA5OYGUlBTbnXu2YQDzc58iMyMN\nJ/v7lyFYMPvs7CyuXr0KlWrperUxwJkzn6772YYB5BvyMDo6ugKAjUUNDg4KAIMwREKC2vbpkjHA\npUuX4OzsbLtzzzYMoKDAgPPnz+Py5cvQapOXISIjwmGxtAmAAuHu7iafKcYAvb292L17t+3OPdtw\ngIWFBQxRxBUIq9WyLP7ixYtYXFxERMS9FWIzmUw/DACO7vz8vAiPCA9DS3OTiFacxd+5c+eHCxAa\nGirCLW2tuHLl8grxvDIsfmZmZk2xbirA8PC4RDw8LFSE24tW/ObNm7h+/bqIt1K/D/D3t317yTYF\nQBHOvlr4lStXJNos7MaNGyJcEc+rtLqINwXA08MNNTU16wrv7OzEgQMHsGPHDhHNXllZKe7p4bFG\n6KalEEPwlGXxinAnJycRvtSBrEhKSloWHxgYSPkfYPv2PdvUGmChDHH69Oll4d3d3SJKWYXCwkLE\nxsauK55tUwHYWLRWq10jnO/zBk2lUt1XPNumA7A5OjoKhCKcU+dhxLP9zwG2bNmCRx55RI6PPvqo\nOJ+z25sCoezt+Vyj0dg+vb99JwD/qAQExycjOC4ZIWototN0SMjKQ7LeiKjUbMRn5cK8/Q1sfeyx\nJYAntmLbM8/gp9u24RfPPYdtTz+Nx+gzBYbtHad8vPaxdoXzvQfZQwOw6KDYJBEckZyBdGMJylu7\nYBmeQGP/CMrbupBf3YjMonKosw1IzMnHj378Y7z02pt470MH7Nx7CI8//ji2bt2KZwjml88/j58/\n+yyefPJJWaEdR/QIyj8pHmhYOh5LbLE9/f72UABRKVkIS0xDqsGM0uYOtI1Mo2N8FtaxU2gbnUbr\n0CRahiZQ1zuIuEw9zi0skrCf4Pevvg5dSRUyiysQk54DVXwKfCPi4BkSBbegcDgcOoafPfUUtj7x\nBN4+bhDRTbOXxRWA9dLN3h4IkKQzQEMRbSFxI/Pn0TP9KdonTsMyegqtI1MkfBLNg+M2HxMAh8NO\n+NULLyKt0CxQJS3tKG6ywFjXgtyKWqSbyqDRFyI6VUdA8bIq77oYRXiWZQ4uKVa8+lHK97MC5uoG\n9A2P4Zs7d3H7m7u4fuMmLl65hrnPFzE6fw49UwQzMonGgVHU9w2jtmcQZW2dKKhpQmF9C8otXTA3\nW2BqaKF7jcitrIOurFpWJa2wDNkl1fj1b36Lf3oUo2HmC0SYh8UVAJ/wWPFQjVZErbYHAmSbqzBw\n6iwmP1vA/MIXWLh6DV9+dQNf37pNfkuAFuneGUqb8fmz6J2cgWVoDFXtPQJQ1NRG4lsp+s0wMACt\nQHZpFTKoVrQFZqQWlmL7W3/HTr9SWM9eQ5hpSFwBCIxOQmCMBgHRict1GKZJI6BUeIerHwKgtIby\nnaI8Nkt+Cu2U+91Tcxg8fRZTZy/g7MVLWPzyGq59TVA3b8nx4uWrmDt/AYPTs2jpG6Bib4fRTrxE\n31SKlPxiqHXU76kxfBxUjp4LXyG44KS4AuAXmQjfMDV8wuIREJkA79BYHDzhiz3HPXDI3f/BADll\ntZL3HRNzsJJ4hmilIm4enoJ1YpaKeEpSyEreO3EKI7PzmDl7HmcuLODcxUUp6Llz/8Hw9ClY+gZR\nQemURymUZjRLtwrTpEOVkAqHkCoMLt6Ef24v/PU9dgAc9WS4+Idhn5MXdh0+AYejblL0XDNFveeg\nbZjBLlUl/uVpxu/eTxDxbAKgzs5HfKYBGaYKKkQuxpXOLZS9gbymewDVnX3itV19aOg5idb+IXRS\nSvWNTaJ/fAo9I+Noo1WpplUprKpHJqVQEhX0J6HVGLlyG97ZXeIKgBdFfL+LNz465IxPHN2wx8kT\n++iaAez9lQ+TxdcAcOG1UHfhPq+jgovNyBV3OeYozucM0Do8KR2HxVdYu1Ha2kmA3Hko92k+5FXW\nw0AFXEBNwVTbRN4IE50b6X4etVpegbGr38AjvUNcARDhx9yx19mLhPvggKsfDrr546hnkAh3Trbg\nffciOX/hnSgRrpgA6DmFpubRNX0aXVOz4iy6yGyCnl4FuQDjMvKoyJJowGXRADMiy1wpQ40BuJAN\nVQ3UeWrofgVSaQCq6W8Sc02Iy8qX78am67EruAJT1+/AVWsVVwD2UtrsP+FDov1w2D0AR72C4ewX\nAiefYBGd3jwLx4QWgbCPPpsAZBVVossu/9upoBmA7dT8nAC0j01RYVPBUqpUWLugL6+VtPMMiZUu\nEp6USdsL2moYimi7UQB1Rs6yhySkIZj8o8ByTH91F05JbeIKwCGK9mGPQDh6q6QOjnsHyW6gpNm6\nBuClf2tWDD05yzCVy9RtG52RCWyhIwNkZWoRGkRR2e2ABur/PAPqe4fQeHKYUm6UpvQkurkL0XlZ\nW4dM5CitbkX6uQVHIig+VZzb6OyNb9cAOHqx8HA4+6rgoYqilW2Q2cHfWQ3A37Gf3PJvWkEp7Xem\naMrSxB2YQNPAuIiobKwXZ4Cqjl7xktYOFDdaYapvRT4NsjxKHU6hUrpf09UvMJxq9ukXQh3I0SsI\nH/iWYP424JbaLq4AuAaGS7ok55noty006Q0IScygzpWxBuCNT9KXAcQZQGsoRguJru/nSTtCk3aI\n+nglkpPU4i5+4Sim/ZG5pYMGVhuMtZTzlP/6ijrq+dU0sCqgpbxPyitCAuU+A7Ap6VdHnaqThh+3\nwDN3sKILHVU3EyClC3WslIISRKToEKnNkaNzYMoagD/sy8LLb/usBOAWV987TN1lAJXt/ZTjfSiz\n9CylAonPJaFFFPUC2ucYqprouh46Gn6ZVMhptOdJyTdDk0vidQVUtAYBsE8/3gt5RySIgPPfAr45\nPeIMcDiuUYqfRUenU/ej6LPHZBjwt31qAeChxwDsfP3KexErAdTUKVh4aWs3RbmLOksHCW6HiUTz\nkhrrWilVOOL1MrV5ddIKeZtwL+rcbWJIQGRqjgDYpx8XuhdN2X+4FmKBAEILB8UZYH9UPUU7WwSr\ndYV2bsRfjuol+nxk8fbXKwBiqMWVNHdSLrPYNhTUtlKKNNtEc3usRRYVVTp1q1RjGXWaEom4OqdQ\nhHPkWHg4CQnVZAqAkn4fH3SBe0gc3FWxshu9RABxFePiDLAnvEYinpBjorZbJL+r+J8O5ohgPjKA\n/fUKgEh6cCEJ11c0Iqeco0yCzTWU21W0ESun3Cwl0WZ5QAKJjs8ukIcqwsNYOLVRVUI6AuO18I+l\n1KB+zuK9w+LgpoqBa1CUvH19TgAp9dPiDMDDLVFvopUsRhLVIj8nyeac70l103JkAPtrFs8m/3Kf\nDiMBUWm5snT8Y/xDktci2JYitMzRaXoSrado6+g7WQjRZEiPD4xLFeF+FH3viER40S7SPZTEBy+J\ndwmIxFuOufjsLqBrnxNnAJ4NGkpD5ZlcT+x8zh0ntmxUjgxgf62YAPhGqmXy8dbVJ0JND4+HD+0Q\nA+K0BJeBsGQdIqjIwpI50iSaWlwwRTtIbRMeQ29hJNwnSkPfTYAn5bs75b1rcDRO2MQ7U59fD4Bb\n60qAEhtAsXyuMg7IkQHsrxVbWodVplLzPjwenrTJcldFUxTJKQ04qr6RGhKcLHB+inC6x13Gkz73\n4KhTvov4QBYfASc/mq6+ofJOfPoW1VzZmDgL4ZccDW05lgCWnBtDMkHw1OV2y0cGsL9WbF2A1ca7\nxRMB4TTqg0WQM527kLNIN4o0pwoL52J1JVCJeiBHfUn8MZ9QOPqopPg48vxewM4A3JkSKU01VAdL\nxWui7lYqw4z3PfzqyUcGsL9W7KEAVpvDERcqUn8cdPWV/QtH97hfqIjlVHFil6iz+BD5myO0Qfvj\n/mzEli9Fn4/sXNgJVHfcivkdWkuR9wyNxl/f34kX340R4esdFftOAKvtw/3H6AXEVV5GeB9/hLbB\nvKNkd5RjEN0LxPa9mSJaWQE+57rg95FEEh+VqsO+4+54efsO+V3eOrPg9Y6KfS8Aq83h6Ans3OdI\nK3WCoDxlm8yvhm/uyRDhh+j6AG2f+fzPh/QCwO/CB1w8bb+wZJsGsNoY5oO9R/Hm7iWA3fTycoDe\nefmc02q/syd27j1i++t7tj+yTsTazwG+5u2HYhsCoBgD8H9msXB2Pue0up+98V4IXt9FO1kSrzhf\n833FNhSAH8ydx97txaxnCoTiq/9+QwG+fwP+CyGRvQpx7eyKAAAAAElFTkSuQmCC\n", + "iVBORw0KGgoAAAANSUhEUgAAACUAAAAlCAYAAADFniADAAAAAXNSR0IArs4c6QAAAARnQU1BAACx\njwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAAAlwSFlz\nAAAewgAAHsIBbtB1PgAAAjJJREFUWEftWEFrGkEYVQIqGtFTjrmF/IEYWLzEgOQQiBCIEPaiEATb\n9CA0eKiFlgqlBw9CI9Yl1kjjIhYPNSgpSkuN4kXPXgr+k9f5Ju7SYoNDaY2UGXh833z7vuHxdnbZ\nHYtFDkEH0un0zbIgEoncMNmXFiYIlUoFtVoNiUSCI5VK8Ui1YrHI83g8jmw2a9aoTjA4lFMfxXK5\n/EudOAaPYjKZRKFQ4DUDmqaBiQIT9Z2L6nQ6SKe72N1N4uAgg729FyaoRtjffw1V/cDrNKd4ePgW\nx8fvcXT0zqzRNZqfnn7jHOqLRutm38nJNedSjTgGzs6qs6K2t78wlc8ZOtNIOeHNNGo/5VR7yvCK\n4Wp6nXKjh9a469vYyEJRPmJt7RG83ifw+z9hc/MZVlYeY2vrGjs7X7G+fgGf7+V9omgxUZCI+dzz\n81v0+33EYjEEg0Get1otuFwulEolPldVlYny/Q1R8wWR6EymjXa7zW5XFIFAgOf1eh1OpxP5fJ7P\nw+HwYkWtrvrZbfPC4XDAZrPx3OPxwGq1wu1287ndbv+9KF2/hab9C1yxdbW5oCd75unTdX1uo8ji\nf8JpNBr81TAjKpfLoVqtotvtLhy9Xu9+UcPhEA8xJpOJFCVkvHRKyCZGkk5Jp0QdEOXJPSWdEnVA\nlCf3lHRK1AFRntxT/6dTzWYTg8EA4/F44RiNRrPf6MZJCZ2WPBTob8r8xQqFQlgWKIpydxTExucl\nw6Xged9iaT8A6ipWINQO9M4AAAAASUVORK5CYII=\n" + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.file_details.internal_name", + "data_type": "string", + "example_values": [ + "Wmiprvse.exe", + "ping.exe" + ] + }, + { + "data_path": "action_result.data.*.file_details.is_64bit", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.file_details.is_executable_image", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.file_details.last_seen", + "data_type": "string", + "example_values": [ + "2018-03-25T06:49:27.776Z", + "2018-10-26T00:01:41.224Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.legal_copyright", + "data_type": "string", + "example_values": [ + "Microsoft Corporation. All rights reserved." + ] + }, + { + "column_name": "MD5", + "column_order": 0, + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.data.*.file_details.md5", + "data_type": "string", + "example_values": [ + "75E683BC8284D99F998500162BE4CFE2", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.file_details.observed_filename", + "data_type": "string", + "example_values": [ + "c:\\windows\\system32\\wbem\\wmiprvse.exe", + "c:\\windows\\system32\\ping.exe" + ] + }, + { + "data_path": "action_result.data.*.file_details.orig_mod_len", + "data_type": "numeric", + "example_values": [ + 489984, + 16896 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.file_details.original_filename", + "data_type": "string", + "example_values": [ + "Wmiprvse.exe", + "ping.exe.mui" + ] + }, + { + "data_path": "action_result.data.*.file_details.os_type", + "data_type": "string", + "example_values": [ + "Windows" + ] + }, + { + "data_path": "action_result.data.*.file_details.product_name", + "data_type": "string", + "example_values": [ + "Microsoft Windows Operating System" + ] + }, + { + "data_path": "action_result.data.*.file_details.product_version", + "data_type": "string", + "example_values": [ + "10.0.16299.248", + "6.1.7600.16385" + ] + }, + { + "data_path": "action_result.data.*.file_details.server_added_timestamp", + "data_type": "string", + "example_values": [ + "2018-02-15T01:48:13.517Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.signed", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.file_details.timestamp", + "data_type": "string", + "example_values": [ + "2018-02-15T01:48:13.517Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.watchlists.*.value", + "data_type": "string", + "example_values": [ + "2015-05-15T07:30:02.843Z" + ] + }, + { + "data_path": "action_result.data.*.file_details.watchlists.*.wid", + "data_type": "string", + "example_values": [ + "5" + ] + }, + { + "data_path": "action_result.data.*.file_id", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "contains": [ + "file name", + "file path" + ], + "data_path": "action_result.data.*.name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe", + "C:\\Windows\\CarbonBlack\\Sensor.LOG", + "ping.exe" + ] + }, + { + "data_path": "action_result.data.*.session_id", + "data_type": "numeric", + "example_values": [ + 101 + ] + }, + { + "column_name": "Vault ID", + "column_order": 1, + "contains": [ + "vault id", + "sha1" + ], + "data_path": "action_result.data.*.vault_id", + "data_type": "string", + "example_values": [ + "08f57fd06bbd8063d5b828521654225952a8155e", + "41c4e1e9abe08b218f5ea60d8ae41a5f523e7534" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.summary.cb_url", + "data_type": "string", + "example_values": [ + "https://192.168.0.245/#/binary/75E683BC8284D99F998500162BE4CFE2", + "https://10.1.16.170/#/binary/5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.summary.file_type", + "data_type": "string", + "example_values": [ + "pe file" + ] + }, + { + "contains": [ + "file name", + "file path" + ], + "data_path": "action_result.summary.name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe", + "C:\\Windows\\CarbonBlack\\Sensor.LOG", + "ping.exe" + ] + }, + { + "contains": [ + "vault id", + "sha1" + ], + "data_path": "action_result.summary.vault_id", + "data_type": "string", + "example_values": [ + "08f57fd06bbd8063d5b828521654225952a8155e", + "41c4e1e9abe08b218f5ea60d8ae41a5f523e7534" + ] + }, + { + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "File type: pe file\nVault id: 08f57fd06bbd8063d5b828521654225952a8155e\nName: wmiprvse.exe\nCb url: https://192.168.0.245/#/binary/75E683BC8284D99F998500162BE4CFE2", + "Vault id: cefbc5c62d7e1f90d250ddcd35bc388a7b01f4d4, Name: C:\\Windows\\CarbonBlack\\Sensor.LOG", + "File type: pe file, Vault id: 41c4e1e9abe08b218f5ea60d8ae41a5f523e7534, Name: ping.exe, Cb url: https://10.1.16.170/#/binary/5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "get file 2" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def get_file_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('get_file_2() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'get_file_2' call\n filtered_results_data_1 = phantom.collect2(container=container, datapath=[\"filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash\", \"filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.context.artifact_id\"])\n\n parameters = []\n \n # build parameters list for 'get_file_2' call\n for filtered_results_item_1 in filtered_results_data_1:\n parameters.append({\n 'hash': filtered_results_item_1[0],\n 'ph_0': \"\",\n 'offset': \"\",\n 'get_count': \"\",\n 'sensor_id': \"\",\n 'file_source': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_results_item_1[1]},\n })\n\n phantom.act(action=\"get file\", parameters=parameters, assets=['carbonblack'], name=\"get_file_2\")\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "91866693-2720-43a1-a437-f65f19382b9a", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 290, + "line_start": 263, + "message": "Configuring now", + "name": "get file", + "notes": "", + "number": 2, + "order": 10, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 600, + "y": 200 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "get_file_2", + "required_params": {}, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 2947 + }, + { + "action": "create ticket", + "action_type": "generic", + "active": false, + "active_keys": {}, + "active_values": { + "description": "block_hash_2:action_result.message", + "fields": "block_hash_2:action_result.message", + "short_description": "block_hash_2:action_result.message" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "description": "block_hash_2:action_result.message", + "fields": "block_hash_2:action_result.message", + "short_description": "block_hash_2:action_result.message", + "table": "", + "vault_id": "" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "servicenow", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.short_description", + "data_type": "string" + }, + { + "contains": [ + "servicenow table" + ], + "data_path": "action_result.parameter.table", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.fields", + "data_type": "string" + }, + { + "data_path": "action_result.parameter.description", + "data_type": "string" + }, + { + "contains": [ + "servicenow ticket id" + ], + "data_path": "action_result.summary.created_ticket_id", + "data_type": "string" + }, + { + "contains": [ + "vault id" + ], + "data_path": "action_result.parameter.vault_id", + "data_type": "string" + }, + { + "data_path": "action_result.message", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_updated_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_updated_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.escalation", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.watch_list", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.follow_up", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.made_sla", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.delivery_task", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sla_due", + "data_type": "string" + }, + { + "column_name": "Number", + "column_order": 0, + "data_path": "action_result.data.*.number", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.caller_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.correlation_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_mod_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.notify", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.resolved_by", + "data_type": "string" + }, + { + "column_name": "Closed On", + "column_order": 6, + "data_path": "action_result.data.*.closed_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_tags", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.cmdb_ci", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.subcategory", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.category", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.close_notes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.expected_start", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.knowledge", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.opened_by.link", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.opened_by.value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.impact", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.calendar_stc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.caused_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.comments", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.problem_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.activity_due", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.state", + "data_type": "string" + }, + { + "column_name": "ID", + "column_order": 4, + "contains": [ + "servicenow ticket id" + ], + "data_path": "action_result.data.*.sys_id", + "data_type": "string" + }, + { + "column_name": "Opened On", + "column_order": 5, + "data_path": "action_result.data.*.opened_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.child_incidents", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_notes", + "data_type": "string" + }, + { + "column_name": "Short Description", + "column_order": 0, + "data_path": "action_result.data.*.short_description", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.comments_and_work_notes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.time_worked", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_created_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.upon_reject", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.reassignment_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.business_stc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.due_date", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_class_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.delivery_plan", + "data_type": "string" + }, + { + "column_name": "Description", + "column_order": 1, + "data_path": "action_result.data.*.description", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.parent", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.business_duration", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.rfc", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.company", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.assigned_to", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.approval_history", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.user_input", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_start", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_domain.link", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_domain.value", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.resolved_at", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.calendar_duration", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.group_list", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.active", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.approval", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.parent_incident", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_domain_path", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.closed_by", + "data_type": "string" + }, + { + "column_name": "Severity", + "column_order": 2, + "data_path": "action_result.data.*.severity", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.upon_approval", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.incident_state", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.reopen_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.contact_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_end", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.work_notes_list", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.sys_created_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.location", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.correlation_display", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.close_code", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.assignment_group", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.approval_set", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.order", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.urgency", + "data_type": "string" + }, + { + "column_name": "Priority", + "column_order": 2, + "data_path": "action_result.data.*.priority", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.hold_reason", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.business_service", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_id", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_tags", + "data_type": "string" + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.attachment_details.*.file_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.compressed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.size_bytes", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.table_name", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.image_width", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.content_type", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.image_height", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.table_sys_id", + "data_type": "string" + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.attachment_details.*.download_link", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_mod_count", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_created_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_created_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_updated_by", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.sys_updated_on", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.size_compressed", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.attachment_details.*.average_image_color", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.additional_assignee_list", + "data_type": "string" + }, + { + "data_path": "action_result.summary.attachment_id", + "data_type": "string" + }, + { + "data_path": "action_result.summary.attachment_added", + "data_type": "boolean" + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric" + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric" + } + ], + "product_name": "", + "product_vendor": "", + "type": "ticketing" + } + ], + "attrs": { + ".action": { + "text": "create ticket 3" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Utilities" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1, + "xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg" + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_generic.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "# read-only block view not available", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#5094D4", + "connected_to_start": false, + "connection_name": "block hash 2", + "connection_type": "action", + "custom_callback": "", + "custom_code": "def create_ticket_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'create_ticket_2' call\n\n file_reputation = phantom.collect2(datapath=['file_reputation_1:filtered-action_result.parameter.hash', \n 'file_reputation_1:filtered-action_result.summary.positives'])\n blocked_hashes = set(phantom.collect2(datapath='block_hash_2:action_result.parameter.hash'))\n detected_users = set(phantom.collect2(datapath='hunt_file_1:action_result.data.*.process.results.*.username'))\n detected_systems = set(phantom.collect2(datapath='hunt_file_1:action_result.data.*.process.results.*.hostname'))\n \n title = \"Virus Detected on {0} devices\".format(len(detected_systems))\n \n description = \"Hashes sumbitted with detections:\\n{0}\\n\\n\".format(\", \".join([\"{0} ({1})\".format(*fr) for fr in file_reputation]))\n description += \"File was found on {0} devices:\\n{1}\\n\\n\".format(len(detected_systems), ', '.join(detected_systems))\n description += \"This impacts at least {0} users:\\n{1}\\n\\n\".format(len(detected_users), ', '.join(detected_users))\n if len(blocked_hashes):\n description += \"{0} hashes were submitted for blocking:\\n{1}\\n\\n\".format(len(blocked_hashes), \", \".join(blocked_hashes))\n\n parameters = []\n \n # build parameters list for 'create_ticket_2' call\n parameters.append({\n 'short_description': title,\n 'description': description,\n 'fields': \"\",\n })\n\n if parameters:\n phantom.act(\"create ticket\", parameters=parameters, assets=['servicenow'], name=\"create_ticket_3\", parent_action=action) \n else:\n phantom.error(\"'create_ticket_3' will not be executed due to lack of parameters\")\n \n return", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": true, + "has_custom_block": true, + "has_custom_callback": false, + "has_custom_join": false, + "id": "72f13962-4d43-44be-9710-d2ed60cbbf00", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 326, + "line_start": 290, + "message": "Configuring now", + "name": "create ticket", + "notes": "", + "number": 3, + "order": 11, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1220, + "y": 80 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "create_ticket_3", + "required_params": {}, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Utilities", + "type": "coa.Action", + "warn": false, + "z": 2948 + }, + { + "action": "disable user", + "action_type": "contain", + "active": false, + "active_keys": {}, + "active_values": { + "username": "hunt_file_2:action_result.data.*.process.results.*.username" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "username": "hunt_file_2:action_result.data.*.process.results.*.username" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "domainctrl1", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success", + "failed" + ] + }, + { + "column_name": "Username", + "column_order": 0, + "contains": [ + "user name", + "ldap distinguished name" + ], + "data_path": "action_result.parameter.username", + "data_type": "string", + "example_values": [ + "test_user3" + ] + }, + { + "data_path": "action_result.data", + "data_type": "string" + }, + { + "data_path": "action_result.summary", + "data_type": "string" + }, + { + "column_name": "Message", + "column_order": 1, + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "User state changed" + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "directory service" + } + ], + "attrs": { + ".action": { + "text": "disable user" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Contain" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_contain.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def disable_user_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('disable_user_1() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'disable_user_1' call\n results_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:action_result.data.*.process.results.*.username', 'hunt_file_2:action_result.parameter.context.artifact_id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'disable_user_1' call\n for results_item_1 in results_data_1:\n if results_item_1[0]:\n parameters.append({\n 'username': results_item_1[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': results_item_1[1]},\n })\n\n phantom.act(action=\"disable user\", parameters=parameters, assets=['domainctrl1'], callback=join_filter_2, name=\"disable_user_1\", parent_action=action)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#3D9959", + "connected_to_start": false, + "connection_name": "hunt file 2", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "34bd4b5e-7b04-43a8-9fa7-dff28adb98dc", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 349, + "line_start": 326, + "message": "Configuring now", + "name": "disable user", + "notes": "", + "number": 1, + "order": 12, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 840, + "y": 480 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "disable_user_1", + "required_params": { + "username": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Contain", + "type": "coa.Action", + "warn": false, + "z": 2949 + }, + { + "action": "hunt file", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash", + "range": "", + "type": "binary" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "hash": "filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash", + "range": "", + "type": "binary" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7", + "13ded573464ba7f43fe640479b309e09", + "9bf50324444c46997c2492d505b47f2d", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.parameter.range", + "data_type": "string", + "example_values": [ + "0-10", + "0-2", + "5-8" + ] + }, + { + "contains": [ + "carbon black query type" + ], + "data_path": "action_result.parameter.type", + "data_type": "string", + "example_values": [ + "process", + "binary" + ] + }, + { + "data_path": "action_result.data.*.binary.elapsed", + "data_type": "numeric", + "example_values": [ + 0.1120398044586182, + 0.04952096939086914, + 0.1234798431396484, + 0.05507302284240723, + 0.05384993553161621 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.alliance_score_virustotal.*.name", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.alliance_score_virustotal.*.value", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.company_name_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_publisher_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.name", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_result.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_sign_time.*.name", + "data_type": "string", + "example_values": [ + "2018-10-01T00:00:00Z", + "2015-01-01T00:00:00Z", + "2013-11-01T00:00:00Z" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.digsig_sign_time.*.value", + "data_type": "numeric", + "example_values": [ + 1, + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.name", + "data_type": "string", + "example_values": [ + "16.0.10827.20181", + "4.7.0205.0", + "6.1.7600.16385 (win7_rtm.090713-1255)" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.file_version_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.name", + "data_type": "string", + "example_values": [ + "default group" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.group.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.host_count.*.name", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.host_count.*.value", + "data_type": "numeric", + "example_values": [ + 1, + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.name", + "data_type": "string", + "example_values": [ + "CB-TEST-02", + "WIN7-CLIENT1", + "ACCOUNTING-PC" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.ratio", + "data_type": "string", + "example_values": [ + "100.0", + "16.7" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.hostname.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.name", + "data_type": "string", + "example_values": [ + "c:\\program files\\common files\\microsoft shared\\clicktorun\\updates\\16.0.10827.20181\\officeclicktorun.exe", + "c:\\program files\\microsoft security client\\nissrv.exe", + "C:\\Windows\\system32\\ping.exe" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0", + "50.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.observed_filename_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.name", + "data_type": "string", + "example_values": [ + "Microsoft Office", + "Microsoft Malware Protection" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.product_name_facet.*.value", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.binary.facets.server_added_timestamp.*.name", + "data_type": "string", + "example_values": [ + "2018-10-19T00:00:00Z", + "2018-09-29T00:00:00Z", + "2018-10-02T00:00:00Z" + ] + }, + { + "data_path": "action_result.data.*.binary.facets.server_added_timestamp.*.value", + "data_type": "numeric", + "example_values": [ + 1, + 0 + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.binary.highlights.*.ids", + "data_type": "string", + "example_values": [ + "13DED573464BA7F43FE640479B309E09", + "9BF50324444C46997C2492D505B47F2D", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.data.*.binary.highlights.*.name", + "data_type": "string", + "example_values": [ + "PREPREPRE13DED573464BA7F43FE640479B309E09POSTPOSTPOST", + "PREPREPRE9BF50324444C46997C2492D505B47F2DPOSTPOSTPOST", + "PREPREPRE5FB30FE90736C7FC77DE637021B1CE7CPOSTPOSTPOST" + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.binary.results.*.alliance_data_srstrust", + "data_type": "string", + "example_values": [ + "5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.binary.results.*.alliance_link_srstrust", + "data_type": "string", + "example_values": [ + "https://services.bit9.com/Services/extinfo.aspx?ak=b8b4e631d4884ad1c56f50e4a5ee9279&sg=0313e1735f6cec221b1d686bd4de23ee&md5=5fb30fe90736c7fc77de637021b1ce7c" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.alliance_score_srstrust", + "data_type": "numeric", + "example_values": [ + -100 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.alliance_updated_srstrust", + "data_type": "string", + "example_values": [ + "2018-02-07T02:37:28Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.cb_version", + "data_type": "numeric", + "example_values": [ + 610, + 510, + 511 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.company_name", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.copied_mod_len", + "data_type": "numeric", + "example_values": [ + 9683736, + 366512, + 16896 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_issuer", + "data_type": "string", + "example_values": [ + "Microsoft Code Signing PCA" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_prog_name", + "data_type": "string", + "example_values": [ + "Microsoft Office", + "Microsoft Corp." + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_publisher", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_result", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_result_code", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_sign_time", + "data_type": "string", + "example_values": [ + "2018-10-14T20:23:00Z", + "2015-01-30T19:14:00Z", + "2009-07-14T10:17:00Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.digsig_subject", + "data_type": "string", + "example_values": [ + "Microsoft Corporation" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.endpoint", + "data_type": "string", + "example_values": [ + "CB-TEST-02|27", + "WIN7-CLIENT1|15", + "DC1|19" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.event_partition_id", + "data_type": "numeric", + "example_values": [ + 100972684312576, + 100955696070656 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.facet_id", + "data_type": "numeric", + "example_values": [ + 883737, + 0 + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.file_desc", + "data_type": "string", + "example_values": [ + "Microsoft Office Click-to-Run (SxS)", + "Microsoft Network Realtime Inspection Service", + "TCP/IP Ping Command" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.file_version", + "data_type": "string", + "example_values": [ + "16.0.10827.20181", + "4.7.0205.0", + "6.1.7600.16385 (win7_rtm.090713-1255)" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.group", + "data_type": "string", + "example_values": [ + "Default Group" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.host_count", + "data_type": "numeric", + "example_values": [ + 1, + 6 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.internal_name", + "data_type": "string", + "example_values": [ + "OfficeClickToRun.exe", + "NisSrv.exe", + "ping.exe" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.is_64bit", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.is_executable_image", + "data_type": "boolean", + "example_values": [ + false, + true + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.last_seen", + "data_type": "string", + "example_values": [ + "2018-10-28T10:06:02.456Z", + "2018-10-28T10:06:42.455Z", + "2018-10-26T00:01:41.224Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.legal_copyright", + "data_type": "string", + "example_values": [ + "Microsoft Corporation. All rights reserved." + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.binary.results.*.md5", + "data_type": "string", + "example_values": [ + "13DED573464BA7F43FE640479B309E09", + "9BF50324444C46997C2492D505B47F2D", + "5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.observed_filename", + "data_type": "string", + "example_values": [ + "c:\\program files\\common files\\microsoft shared\\clicktorun\\updates\\16.0.10827.20181\\officeclicktorun.exe", + "c:\\program files\\microsoft security client\\nissrv.exe", + "c:\\windows\\system32\\ping.exe" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.orig_mod_len", + "data_type": "numeric", + "example_values": [ + 9683736, + 366512, + 16896 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.binary.results.*.original_filename", + "data_type": "string", + "example_values": [ + "OfficeClickToRun.exe", + "NisSrv.exe", + "ping.exe.mui" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.os_type", + "data_type": "string", + "example_values": [ + "Windows" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.product_name", + "data_type": "string", + "example_values": [ + "Microsoft Office", + "Microsoft Malware Protection" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.product_version", + "data_type": "string", + "example_values": [ + "16.0.10827.20181", + "4.7.0205.0", + "6.1.7600.16385" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.server_added_timestamp", + "data_type": "string", + "example_values": [ + "2018-10-19T17:04:47.906Z", + "2015-07-01T02:12:21.783Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "column_name": "Signed", + "column_order": 1, + "data_path": "action_result.data.*.binary.results.*.signed", + "data_type": "string", + "example_values": [ + "Signed" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.timestamp", + "data_type": "string", + "example_values": [ + "2018-10-19T17:04:47.906Z", + "2015-07-01T02:12:21.783Z", + "2015-05-15T07:23:54.846Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.watchlists.*.value", + "data_type": "string", + "example_values": [ + "2015-07-01T02:20:02.062Z", + "2015-05-15T07:30:02.843Z" + ] + }, + { + "data_path": "action_result.data.*.binary.results.*.watchlists.*.wid", + "data_type": "string", + "example_values": [ + "5" + ] + }, + { + "data_path": "action_result.data.*.binary.start", + "data_type": "numeric", + "example_values": [ + 0, + 5 + ] + }, + { + "data_path": "action_result.data.*.binary.terms", + "data_type": "string", + "example_values": [ + "md5:13ded573464ba7f43fe640479b309e09", + "md5:9bf50324444c46997c2492d505b47f2d", + "md5:5FB30FE90736C7FC77DE637021B1CE7C" + ] + }, + { + "data_path": "action_result.data.*.binary.total_results", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.process.all_segments", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.comprehensive_search", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.elapsed", + "data_type": "numeric", + "example_values": [ + 0.2200779914855957 + ] + }, + { + "data_path": "action_result.data.*.process.facets.day_of_week.*.name", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.day_of_week.*.value", + "data_type": "numeric", + "example_values": [ + 1566 + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.name", + "data_type": "string", + "example_values": [ + "default group" + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.group.*.value", + "data_type": "numeric", + "example_values": [ + 10128 + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.name", + "data_type": "string", + "example_values": [ + "domain_controller" + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.ratio", + "data_type": "string", + "example_values": [ + "100.0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.host_type.*.value", + "data_type": "numeric", + "example_values": [ + 10123 + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.name", + "data_type": "string", + "example_values": [ + "dc2" + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.ratio", + "data_type": "string", + "example_values": [ + "51.2" + ] + }, + { + "data_path": "action_result.data.*.process.facets.hostname.*.value", + "data_type": "numeric", + "example_values": [ + 5185 + ] + }, + { + "data_path": "action_result.data.*.process.facets.hour_of_day.*.name", + "data_type": "string", + "example_values": [ + "0" + ] + }, + { + "data_path": "action_result.data.*.process.facets.hour_of_day.*.value", + "data_type": "numeric", + "example_values": [ + 411 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.process.facets.parent_name.*.name", + "data_type": "string", + "example_values": [ + "svchost.exe" + ] + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.parent_name.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.process.facets.path_full.*.name", + "data_type": "string", + "example_values": [ + "c:\\windows\\syswow64\\wbem\\wmiprvse.exe" + ] + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.path_full.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.process.facets.process_md5.*.name", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_md5.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.process.facets.process_name.*.name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.ratio", + "data_type": "string", + "example_values": [ + "98.5" + ] + }, + { + "data_path": "action_result.data.*.process.facets.process_name.*.value", + "data_type": "numeric", + "example_values": [ + 9971 + ] + }, + { + "data_path": "action_result.data.*.process.facets.start.*.name", + "data_type": "string", + "example_values": [ + "2018-02-24T00:00:00Z" + ] + }, + { + "data_path": "action_result.data.*.process.facets.start.*.value", + "data_type": "numeric", + "example_values": [ + 324 + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.name", + "data_type": "string", + "example_values": [ + "LOCAL SERVICE" + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.percent", + "data_type": "numeric", + "example_values": [ + 100 + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.ratio", + "data_type": "string", + "example_values": [ + "98.4" + ] + }, + { + "data_path": "action_result.data.*.process.facets.username_full.*.value", + "data_type": "numeric", + "example_values": [ + 9966 + ] + }, + { + "data_path": "action_result.data.*.process.incomplete_results", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.process.results.*.alliance_data_srstrust", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.process.results.*.alliance_link_srstrust", + "data_type": "string", + "example_values": [ + "https://services.bit9.com/Services/extinfo.aspx?ak=b8b4e631d4884ad1c56f50e4a5ee9279&sg=0313e1735f6cec221b1d686bd4de23ee&md5=4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.alliance_score_srstrust", + "data_type": "numeric", + "example_values": [ + -100 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.alliance_updated_srstrust", + "data_type": "string", + "example_values": [ + "2018-02-07T02:37:28Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.childproc_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "contains": [ + "file path" + ], + "data_path": "action_result.data.*.process.results.*.cmdline", + "data_type": "string", + "example_values": [ + "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -Embedding" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.comms_ip", + "data_type": "numeric", + "example_values": [ + 168886572 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.crossproc_count", + "data_type": "numeric", + "example_values": [ + 2 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.emet_config", + "data_type": "string", + "example_values": [ + "" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.emet_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.filemod_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.filtering_known_dlls", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.results.*.group", + "data_type": "string", + "example_values": [ + "default group" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.host_type", + "data_type": "string", + "example_values": [ + "workstation" + ] + }, + { + "contains": [ + "host name" + ], + "data_path": "action_result.data.*.process.results.*.hostname", + "data_type": "string", + "example_values": [ + "win7-client1" + ] + }, + { + "contains": [ + "carbon black process id" + ], + "data_path": "action_result.data.*.process.results.*.id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0688-01d3-27738c9b4243" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.interface_ip", + "data_type": "numeric", + "example_values": [ + 168886572 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.last_server_update", + "data_type": "string", + "example_values": [ + "2018-03-22T09:21:32.332Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.last_update", + "data_type": "string", + "example_values": [ + "2017-09-07T00:52:15.82Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.modload_count", + "data_type": "numeric", + "example_values": [ + 43 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.netconn_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.os_type", + "data_type": "string", + "example_values": [ + "windows" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0258-01d1-ec51b545a19b" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_md5", + "data_type": "string", + "example_values": [ + "000000000000000000000000000000" + ] + }, + { + "contains": [ + "file name" + ], + "data_path": "action_result.data.*.process.results.*.parent_name", + "data_type": "string", + "example_values": [ + "svchost.exe" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_pid", + "data_type": "numeric", + "example_values": [ + 600 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.parent_unique_id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0258-01d1-ec51b545a19b-000000000001" + ] + }, + { + "contains": [ + "file path", + "file name" + ], + "data_path": "action_result.data.*.process.results.*.path", + "data_type": "string", + "example_values": [ + "c:\\windows\\syswow64\\wbem\\wmiprvse.exe" + ] + }, + { + "contains": [ + "md5" + ], + "data_path": "action_result.data.*.process.results.*.process_md5", + "data_type": "string", + "example_values": [ + "4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "contains": [ + "process name", + "file name" + ], + "data_path": "action_result.data.*.process.results.*.process_name", + "data_type": "string", + "example_values": [ + "wmiprvse.exe" + ] + }, + { + "contains": [ + "pid" + ], + "data_path": "action_result.data.*.process.results.*.process_pid", + "data_type": "numeric", + "example_values": [ + 1672 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.processblock_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.regmod_count", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.segment_id", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "contains": [ + "carbon black sensor id" + ], + "data_path": "action_result.data.*.process.results.*.sensor_id", + "data_type": "numeric", + "example_values": [ + 15 + ] + }, + { + "data_path": "action_result.data.*.process.results.*.start", + "data_type": "string", + "example_values": [ + "2017-09-07T00:52:15.758Z" + ] + }, + { + "data_path": "action_result.data.*.process.results.*.terminated", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.process.results.*.unique_id", + "data_type": "string", + "example_values": [ + "0000000f-0000-0688-01d3-27738c9b4243-000000000001" + ] + }, + { + "contains": [ + "user name" + ], + "data_path": "action_result.data.*.process.results.*.username", + "data_type": "string", + "example_values": [ + "SYSTEM" + ] + }, + { + "data_path": "action_result.data.*.process.start", + "data_type": "numeric", + "example_values": [ + 0 + ] + }, + { + "data_path": "action_result.data.*.process.terms", + "data_type": "string", + "example_values": [ + "md5:4fb491ac8d46aaf22ba8bc5c73dabef7" + ] + }, + { + "data_path": "action_result.data.*.process.total_results", + "data_type": "numeric", + "example_values": [ + 32404 + ] + }, + { + "data_path": "action_result.summary.device_count", + "data_type": "numeric", + "example_values": [ + 32404, + 1 + ] + }, + { + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "Displaying 10 'process' results of total 32404", + "Displaying 1 'binary' results of total 1", + "Displaying 0 'binary' results of total 1" + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "hunt file 1" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def hunt_file_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('hunt_file_1() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'hunt_file_1' call\n filtered_results_data_1 = phantom.collect2(container=container, datapath=[\"filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash\", \"filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.context.artifact_id\"])\n\n parameters = []\n \n # build parameters list for 'hunt_file_1' call\n for filtered_results_item_1 in filtered_results_data_1:\n if filtered_results_item_1[0]:\n parameters.append({\n 'hash': filtered_results_item_1[0],\n 'type': \"binary\",\n 'range': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': filtered_results_item_1[1]},\n })\n\n phantom.act(action=\"hunt file\", parameters=parameters, assets=['carbonblack'], callback=block_hash_2, name=\"hunt_file_1\")\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "file reputation", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "0fe35225-af74-44fa-b1a4-433a9c00cadb", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 398, + "line_start": 373, + "message": "Configuring now", + "name": "hunt file", + "notes": "", + "number": 1, + "order": 14, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 600, + "y": 80 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "hunt_file_1", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 2955 + }, + { + "action": "block hash", + "action_type": "contain", + "active": false, + "active_keys": {}, + "active_values": { + "comment": "", + "hash": "hunt_file_1:artifact:*.cef.fileHash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "comment": "", + "hash": "hunt_file_1:artifact:*.cef.fileHash" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "data_path": "action_result.parameter.comment", + "data_type": "string", + "example_values": [ + "Sample comment" + ] + }, + { + "column_name": "Hash", + "column_order": 0, + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "180469AE0B239E31DB4C65F02FD70BC1" + ] + }, + { + "data_path": "action_result.data", + "data_type": "string" + }, + { + "data_path": "action_result.summary", + "data_type": "string" + }, + { + "column_name": "Message", + "column_order": 1, + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "Block hash action succeeded. It might take some time for blacklisting to take effect." + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "block hash 2" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Contain" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_contain.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def block_hash_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_hash_2() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'block_hash_2' call\n inputs_data_1 = phantom.collect2(container=container, datapath=['hunt_file_1:artifact:*.cef.fileHash', 'hunt_file_1:artifact:*.id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'block_hash_2' call\n for inputs_item_1 in inputs_data_1:\n if inputs_item_1[0]:\n parameters.append({\n 'hash': inputs_item_1[0],\n 'comment': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': inputs_item_1[1]},\n })\n\n phantom.act(action=\"block hash\", parameters=parameters, assets=['carbonblack'], callback=filter_3, name=\"block_hash_2\", parent_action=action)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#3D9959", + "connected_to_start": false, + "connection_name": "hunt file 1", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "f8ca6cc8-63fc-4ccf-b4cb-1a5ed1941c4d", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 422, + "line_start": 398, + "message": "Configuring now", + "name": "block hash", + "notes": "", + "number": 2, + "order": 15, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 840, + "y": 80 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "block_hash_2", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": true, + "show_delay": false, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Contain", + "type": "coa.Action", + "warn": false, + "z": 2956 + }, + { + "action": "file reputation", + "action_type": "investigate", + "active": false, + "active_keys": {}, + "active_values": { + "hash": "artifact:*.cef.fileHash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "file reputation", + "active": true, + "app_name": "VirusTotal", + "app_version": "1.2.40", + "appid": "", + "asset_name": "virustotal", + "config_type": "asset", + "count": 0, + "fields": { + "hash": "artifact:*.cef.fileHash" + }, + "has_app": true, + "id": 142, + "loaded": false, + "missing": false, + "name": "virustotal", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "contains": [ + "hash", + "sha256", + "sha1", + "md5" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "6c1948f7edf115cd1f13cd170b882077930be150" + ] + }, + { + "contains": [ + "hash", + "md5" + ], + "data_path": "action_result.data.*.md5", + "data_type": "string", + "example_values": [ + "494303294715f5ffad7ad3f43b73b00b" + ] + }, + { + "contains": [ + "url" + ], + "data_path": "action_result.data.*.permalink", + "data_type": "string", + "example_values": [ + "https://www.test.com/file/27ce020f7cdb4b775b80bd6e3ef1d16079401e0d45cfd28ffbd8c63ff2ddf7d7/analysis/1548112684/" + ] + }, + { + "data_path": "action_result.data.*.positives", + "data_type": "numeric", + "example_values": [ + 64 + ] + }, + { + "contains": [ + "sha1" + ], + "data_path": "action_result.data.*.resource", + "data_type": "string", + "example_values": [ + "6c1948f7edf115cd1f13cd170b882077930be150" + ] + }, + { + "data_path": "action_result.data.*.response_code", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "action_result.data.*.scan_date", + "data_type": "string", + "example_values": [ + "2019-01-21 23:18:04" + ] + }, + { + "contains": [ + "virustotal scan id" + ], + "data_path": "action_result.data.*.scan_id", + "data_type": "string", + "example_values": [ + "27ce020f7cdb4b775b80bd6e3ef1d16079401e0d45cfd28ffbd8c63ff2ddf7d7-1548112684" + ] + }, + { + "data_path": "action_result.data.*.scans.*.detected", + "data_type": "boolean" + }, + { + "data_path": "action_result.data.*.scans.*.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.*.update", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.*.version", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.ALYac.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.ALYac.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.ALYac.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.ALYac.version", + "data_type": "string", + "example_values": [ + "1.1.1.5" + ] + }, + { + "data_path": "action_result.data.*.scans.AVG.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.AVG.result", + "data_type": "string", + "example_values": [ + "Win32:Parite" + ] + }, + { + "data_path": "action_result.data.*.scans.AVG.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.AVG.version", + "data_type": "string", + "example_values": [ + "18.4.3895.0" + ] + }, + { + "data_path": "action_result.data.*.scans.AVware.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.AVware.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.b (v)" + ] + }, + { + "data_path": "action_result.data.*.scans.AVware.update", + "data_type": "string", + "example_values": [ + "20180925" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.AVware.version", + "data_type": "string", + "example_values": [ + "1.6.0.52" + ] + }, + { + "data_path": "action_result.data.*.scans.Acronis.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Acronis.result", + "data_type": "string", + "example_values": [ + "suspicious" + ] + }, + { + "data_path": "action_result.data.*.scans.Acronis.update", + "data_type": "string", + "example_values": [ + "20190119" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Acronis.version", + "data_type": "string", + "example_values": [ + "1.0.1.37" + ] + }, + { + "data_path": "action_result.data.*.scans.Ad-Aware.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Ad-Aware.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Ad-Aware.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Ad-Aware.version", + "data_type": "string", + "example_values": [ + "3.0.5.370" + ] + }, + { + "data_path": "action_result.data.*.scans.AegisLab.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.AegisLab.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.AegisLab.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.AegisLab.version", + "data_type": "string", + "example_values": [ + "4.2" + ] + }, + { + "data_path": "action_result.data.*.scans.AhnLab-V3.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.AhnLab-V3.result", + "data_type": "string", + "example_values": [ + "Win32/Parite" + ] + }, + { + "data_path": "action_result.data.*.scans.AhnLab-V3.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.AhnLab-V3.version", + "data_type": "string", + "example_values": [ + "3.14.1.22785" + ] + }, + { + "data_path": "action_result.data.*.scans.Alibaba.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Alibaba.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.Alibaba.update", + "data_type": "string", + "example_values": [ + "20180921" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Alibaba.version", + "data_type": "string", + "example_values": [ + "0.1.0.2" + ] + }, + { + "data_path": "action_result.data.*.scans.Antiy-AVL.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Antiy-AVL.result", + "data_type": "string", + "example_values": [ + "Virus/Win32.Parite.c" + ] + }, + { + "data_path": "action_result.data.*.scans.Antiy-AVL.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Antiy-AVL.version", + "data_type": "string", + "example_values": [ + "3.0.0.1" + ] + }, + { + "data_path": "action_result.data.*.scans.Arcabit.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Arcabit.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Arcabit.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Arcabit.version", + "data_type": "string", + "example_values": [ + "1.0.0.837" + ] + }, + { + "data_path": "action_result.data.*.scans.Avast-Mobile.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Avast-Mobile.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.Avast-Mobile.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Avast-Mobile.version", + "data_type": "string", + "example_values": [ + "190121-00" + ] + }, + { + "data_path": "action_result.data.*.scans.Avast.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Avast.result", + "data_type": "string", + "example_values": [ + "Win32:Parite" + ] + }, + { + "data_path": "action_result.data.*.scans.Avast.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Avast.version", + "data_type": "string", + "example_values": [ + "18.4.3895.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Avira.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Avira.result", + "data_type": "string", + "example_values": [ + "W32/Parite" + ] + }, + { + "data_path": "action_result.data.*.scans.Avira.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Avira.version", + "data_type": "string", + "example_values": [ + "8.3.3.8" + ] + }, + { + "data_path": "action_result.data.*.scans.Babable.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Babable.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.Babable.update", + "data_type": "string", + "example_values": [ + "20180918" + ] + }, + { + "data_path": "action_result.data.*.scans.Babable.version", + "data_type": "string", + "example_values": [ + "9107201" + ] + }, + { + "data_path": "action_result.data.*.scans.Baidu.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Baidu.result", + "data_type": "string", + "example_values": [ + "Win32.Virus.Parite.d" + ] + }, + { + "data_path": "action_result.data.*.scans.Baidu.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Baidu.version", + "data_type": "string", + "example_values": [ + "1.0.0.2" + ] + }, + { + "data_path": "action_result.data.*.scans.BitDefender.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.BitDefender.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.BitDefender.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.BitDefender.version", + "data_type": "string", + "example_values": [ + "7.2" + ] + }, + { + "data_path": "action_result.data.*.scans.Bkav.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Bkav.result", + "data_type": "string", + "example_values": [ + "W32.Pinfi.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Bkav.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Bkav.version", + "data_type": "string", + "example_values": [ + "1.3.0.9899" + ] + }, + { + "data_path": "action_result.data.*.scans.CAT-QuickHeal.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.CAT-QuickHeal.result", + "data_type": "string", + "example_values": [ + "W32.Perite.A" + ] + }, + { + "data_path": "action_result.data.*.scans.CAT-QuickHeal.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.CAT-QuickHeal.version", + "data_type": "string", + "example_values": [ + "14.00" + ] + }, + { + "data_path": "action_result.data.*.scans.CMC.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.CMC.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Parite.b!O" + ] + }, + { + "data_path": "action_result.data.*.scans.CMC.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.CMC.version", + "data_type": "string", + "example_values": [ + "1.1.0.977" + ] + }, + { + "data_path": "action_result.data.*.scans.ClamAV.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.ClamAV.result", + "data_type": "string", + "example_values": [ + "Heuristics.W32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.ClamAV.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.ClamAV.version", + "data_type": "string", + "example_values": [ + "0.101.1.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Comodo.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Comodo.result", + "data_type": "string", + "example_values": [ + "Malware@#1b1651nqd7ivb" + ] + }, + { + "data_path": "action_result.data.*.scans.Comodo.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Comodo.version", + "data_type": "string", + "example_values": [ + "30310" + ] + }, + { + "data_path": "action_result.data.*.scans.CrowdStrike.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.CrowdStrike.result", + "data_type": "string", + "example_values": [ + "malicious_confidence_100% (W)" + ] + }, + { + "data_path": "action_result.data.*.scans.CrowdStrike.update", + "data_type": "string", + "example_values": [ + "20181023" + ] + }, + { + "data_path": "action_result.data.*.scans.CrowdStrike.version", + "data_type": "string", + "example_values": [ + "1.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Cybereason.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Cybereason.result", + "data_type": "string", + "example_values": [ + "malicious.94715f" + ] + }, + { + "data_path": "action_result.data.*.scans.Cybereason.update", + "data_type": "string", + "example_values": [ + "20190109" + ] + }, + { + "data_path": "action_result.data.*.scans.Cybereason.version", + "data_type": "string", + "example_values": [ + "1.2.27" + ] + }, + { + "data_path": "action_result.data.*.scans.Cylance.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Cylance.result", + "data_type": "string", + "example_values": [ + "Unsafe" + ] + }, + { + "data_path": "action_result.data.*.scans.Cylance.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Cylance.version", + "data_type": "string", + "example_values": [ + "2.3.1.101" + ] + }, + { + "data_path": "action_result.data.*.scans.Cyren.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Cyren.result", + "data_type": "string", + "example_values": [ + "W32/Virut.E.gen!Eldorado" + ] + }, + { + "data_path": "action_result.data.*.scans.Cyren.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Cyren.version", + "data_type": "string", + "example_values": [ + "6.2.0.1" + ] + }, + { + "data_path": "action_result.data.*.scans.DrWeb.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.DrWeb.result", + "data_type": "string", + "example_values": [ + "Trojan.DownLoader20.25948" + ] + }, + { + "data_path": "action_result.data.*.scans.DrWeb.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.DrWeb.version", + "data_type": "string", + "example_values": [ + "7.0.34.11020" + ] + }, + { + "data_path": "action_result.data.*.scans.ESET-NOD32.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.ESET-NOD32.result", + "data_type": "string", + "example_values": [ + "Win32/Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.ESET-NOD32.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.ESET-NOD32.version", + "data_type": "string", + "example_values": [ + "18744" + ] + }, + { + "data_path": "action_result.data.*.scans.Emsisoft.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Emsisoft.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B (B)" + ] + }, + { + "data_path": "action_result.data.*.scans.Emsisoft.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Emsisoft.version", + "data_type": "string", + "example_values": [ + "2018.4.0.1029" + ] + }, + { + "data_path": "action_result.data.*.scans.Endgame.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Endgame.result", + "data_type": "string", + "example_values": [ + "malicious (high confidence)" + ] + }, + { + "data_path": "action_result.data.*.scans.Endgame.update", + "data_type": "string", + "example_values": [ + "20181108" + ] + }, + { + "data_path": "action_result.data.*.scans.Endgame.version", + "data_type": "string", + "example_values": [ + "3.0.2" + ] + }, + { + "data_path": "action_result.data.*.scans.F-Prot.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.F-Prot.result", + "data_type": "string", + "example_values": [ + "W32/Virut.E.gen!Eldorado" + ] + }, + { + "data_path": "action_result.data.*.scans.F-Prot.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.F-Prot.version", + "data_type": "string", + "example_values": [ + "4.7.1.166" + ] + }, + { + "data_path": "action_result.data.*.scans.F-Secure.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.F-Secure.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.F-Secure.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.F-Secure.version", + "data_type": "string", + "example_values": [ + "11.0.19100.45" + ] + }, + { + "data_path": "action_result.data.*.scans.Fortinet.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Fortinet.result", + "data_type": "string", + "example_values": [ + "W32/Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Fortinet.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Fortinet.version", + "data_type": "string", + "example_values": [ + "5.4.247.0" + ] + }, + { + "data_path": "action_result.data.*.scans.GData.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.GData.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.GData.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.GData.version", + "data_type": "string", + "example_values": [ + "A:25.20275B:25.14197" + ] + }, + { + "data_path": "action_result.data.*.scans.Ikarus.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Ikarus.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Virut" + ] + }, + { + "data_path": "action_result.data.*.scans.Ikarus.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Ikarus.version", + "data_type": "string", + "example_values": [ + "0.1.5.2" + ] + }, + { + "data_path": "action_result.data.*.scans.Invincea.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Invincea.result", + "data_type": "string", + "example_values": [ + "heuristic" + ] + }, + { + "data_path": "action_result.data.*.scans.Invincea.update", + "data_type": "string", + "example_values": [ + "20181128" + ] + }, + { + "data_path": "action_result.data.*.scans.Invincea.version", + "data_type": "string", + "example_values": [ + "6.3.6.26157" + ] + }, + { + "data_path": "action_result.data.*.scans.Jiangmin.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Jiangmin.result", + "data_type": "string", + "example_values": [ + "Win32/Parite.b" + ] + }, + { + "data_path": "action_result.data.*.scans.Jiangmin.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Jiangmin.version", + "data_type": "string", + "example_values": [ + "16.0.100" + ] + }, + { + "data_path": "action_result.data.*.scans.K7AntiVirus.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.K7AntiVirus.result", + "data_type": "string", + "example_values": [ + "Virus ( 00001b711 )" + ] + }, + { + "data_path": "action_result.data.*.scans.K7AntiVirus.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.K7AntiVirus.version", + "data_type": "string", + "example_values": [ + "11.24.29740" + ] + }, + { + "data_path": "action_result.data.*.scans.K7GW.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.K7GW.result", + "data_type": "string", + "example_values": [ + "Virus ( 00001b711 )" + ] + }, + { + "data_path": "action_result.data.*.scans.K7GW.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.K7GW.version", + "data_type": "string", + "example_values": [ + "11.24.29740" + ] + }, + { + "data_path": "action_result.data.*.scans.Kaspersky.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Kaspersky.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Parite.b" + ] + }, + { + "data_path": "action_result.data.*.scans.Kaspersky.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Kaspersky.version", + "data_type": "string", + "example_values": [ + "15.0.1.13" + ] + }, + { + "data_path": "action_result.data.*.scans.Kingsoft.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Kingsoft.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.b.5756" + ] + }, + { + "data_path": "action_result.data.*.scans.Kingsoft.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.Kingsoft.version", + "data_type": "string", + "example_values": [ + "2013.8.14.323" + ] + }, + { + "data_path": "action_result.data.*.scans.MAX.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.MAX.result", + "data_type": "string", + "example_values": [ + "malware (ai score=100)" + ] + }, + { + "data_path": "action_result.data.*.scans.MAX.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.MAX.version", + "data_type": "string", + "example_values": [ + "2018.9.12.1" + ] + }, + { + "data_path": "action_result.data.*.scans.Malwarebytes.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Malwarebytes.result", + "data_type": "string", + "example_values": [ + "Trojan.Agent.QQ" + ] + }, + { + "data_path": "action_result.data.*.scans.Malwarebytes.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.Malwarebytes.version", + "data_type": "string", + "example_values": [ + "2.1.1.1115" + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee-GW-Edition.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee-GW-Edition.result", + "data_type": "string", + "example_values": [ + "BehavesLike.Win32.Pate.hh" + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee-GW-Edition.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee-GW-Edition.version", + "data_type": "string", + "example_values": [ + "v2017.3010" + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee.result", + "data_type": "string", + "example_values": [ + "W32/Pate.b" + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.McAfee.version", + "data_type": "string", + "example_values": [ + "6.0.6.653" + ] + }, + { + "data_path": "action_result.data.*.scans.MicroWorld-eScan.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.MicroWorld-eScan.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.MicroWorld-eScan.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.MicroWorld-eScan.version", + "data_type": "string", + "example_values": [ + "14.0.297.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Microsoft.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Microsoft.result", + "data_type": "string", + "example_values": [ + "Virus:Win32/Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Microsoft.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Microsoft.version", + "data_type": "string", + "example_values": [ + "1.1.15500.2" + ] + }, + { + "data_path": "action_result.data.*.scans.NANO-Antivirus.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.NANO-Antivirus.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Parite.bgvo" + ] + }, + { + "data_path": "action_result.data.*.scans.NANO-Antivirus.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.NANO-Antivirus.version", + "data_type": "string", + "example_values": [ + "1.0.134.24576" + ] + }, + { + "data_path": "action_result.data.*.scans.Paloalto.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Paloalto.result", + "data_type": "string", + "example_values": [ + "generic.ml" + ] + }, + { + "data_path": "action_result.data.*.scans.Paloalto.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.Paloalto.version", + "data_type": "string", + "example_values": [ + "1.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Panda.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Panda.result", + "data_type": "string", + "example_values": [ + "W32/Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Panda.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Panda.version", + "data_type": "string", + "example_values": [ + "4.6.4.2" + ] + }, + { + "data_path": "action_result.data.*.scans.Qihoo-360.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Qihoo-360.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Parite.H" + ] + }, + { + "data_path": "action_result.data.*.scans.Qihoo-360.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.Qihoo-360.version", + "data_type": "string", + "example_values": [ + "1.0.0.1120" + ] + }, + { + "data_path": "action_result.data.*.scans.Rising.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Rising.result", + "data_type": "string", + "example_values": [ + "Virus.Parite!1.9B80 (CLOUD)" + ] + }, + { + "data_path": "action_result.data.*.scans.Rising.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Rising.version", + "data_type": "string", + "example_values": [ + "25.0.0.24" + ] + }, + { + "data_path": "action_result.data.*.scans.SUPERAntiSpyware.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.SUPERAntiSpyware.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.SUPERAntiSpyware.update", + "data_type": "string", + "example_values": [ + "20190116" + ] + }, + { + "data_path": "action_result.data.*.scans.SUPERAntiSpyware.version", + "data_type": "string", + "example_values": [ + "5.6.0.1032" + ] + }, + { + "data_path": "action_result.data.*.scans.SentinelOne.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.SentinelOne.result", + "data_type": "string", + "example_values": [ + "static engine - malicious" + ] + }, + { + "data_path": "action_result.data.*.scans.SentinelOne.update", + "data_type": "string", + "example_values": [ + "20190118" + ] + }, + { + "data_path": "action_result.data.*.scans.SentinelOne.version", + "data_type": "string", + "example_values": [ + "1.0.21.268" + ] + }, + { + "data_path": "action_result.data.*.scans.Sophos.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Sophos.result", + "data_type": "string", + "example_values": [ + "W32/Parite-B" + ] + }, + { + "data_path": "action_result.data.*.scans.Sophos.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Sophos.version", + "data_type": "string", + "example_values": [ + "4.98.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Symantec.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Symantec.result", + "data_type": "string", + "example_values": [ + "Trojan.Gen.6" + ] + }, + { + "data_path": "action_result.data.*.scans.Symantec.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Symantec.version", + "data_type": "string", + "example_values": [ + "1.8.0.0" + ] + }, + { + "data_path": "action_result.data.*.scans.TACHYON.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.TACHYON.result", + "data_type": "string", + "example_values": [ + "Virus/W32.Parite.C" + ] + }, + { + "data_path": "action_result.data.*.scans.TACHYON.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.TACHYON.version", + "data_type": "string", + "example_values": [ + "2019-01-21.02" + ] + }, + { + "data_path": "action_result.data.*.scans.Tencent.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Tencent.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Dropper.c" + ] + }, + { + "data_path": "action_result.data.*.scans.Tencent.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Tencent.version", + "data_type": "string", + "example_values": [ + "1.0.0.1" + ] + }, + { + "data_path": "action_result.data.*.scans.TheHacker.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.TheHacker.result", + "data_type": "string", + "example_values": [ + "W32/Pate.B" + ] + }, + { + "data_path": "action_result.data.*.scans.TheHacker.update", + "data_type": "string", + "example_values": [ + "20190118" + ] + }, + { + "data_path": "action_result.data.*.scans.TheHacker.version", + "data_type": "string", + "example_values": [ + "6.8.0.5.3962" + ] + }, + { + "data_path": "action_result.data.*.scans.TotalDefense.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.TotalDefense.result", + "data_type": "string", + "example_values": [ + "Win32/Pinfi.A" + ] + }, + { + "data_path": "action_result.data.*.scans.TotalDefense.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.TotalDefense.version", + "data_type": "string", + "example_values": [ + "37.1.62.1" + ] + }, + { + "data_path": "action_result.data.*.scans.Trapmine.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Trapmine.result", + "data_type": "string", + "example_values": [ + "malicious.high.ml.score" + ] + }, + { + "data_path": "action_result.data.*.scans.Trapmine.update", + "data_type": "string", + "example_values": [ + "20190103" + ] + }, + { + "data_path": "action_result.data.*.scans.Trapmine.version", + "data_type": "string", + "example_values": [ + "3.0.34.707" + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro-HouseCall.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro-HouseCall.result", + "data_type": "string", + "example_values": [ + "PE_PARITE.A" + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro-HouseCall.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro-HouseCall.version", + "data_type": "string", + "example_values": [ + "10.0.0.1040" + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro.result", + "data_type": "string", + "example_values": [ + "PE_PARITE.A" + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.TrendMicro.version", + "data_type": "string", + "example_values": [ + "10.0.0.1040" + ] + }, + { + "data_path": "action_result.data.*.scans.Trustlook.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Trustlook.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.Trustlook.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.Trustlook.version", + "data_type": "string", + "example_values": [ + "1.0" + ] + }, + { + "data_path": "action_result.data.*.scans.VBA32.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.VBA32.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Parite.b" + ] + }, + { + "data_path": "action_result.data.*.scans.VBA32.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.VBA32.version", + "data_type": "string", + "example_values": [ + "3.35.1" + ] + }, + { + "data_path": "action_result.data.*.scans.VIPRE.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.VIPRE.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.b (v)" + ] + }, + { + "data_path": "action_result.data.*.scans.VIPRE.update", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.VIPRE.version", + "data_type": "string", + "example_values": [ + "None" + ] + }, + { + "data_path": "action_result.data.*.scans.ViRobot.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.ViRobot.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.A" + ] + }, + { + "data_path": "action_result.data.*.scans.ViRobot.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.ViRobot.version", + "data_type": "string", + "example_values": [ + "2014.3.20.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Webroot.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Webroot.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.Webroot.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.Webroot.version", + "data_type": "string", + "example_values": [ + "1.0.0.403" + ] + }, + { + "data_path": "action_result.data.*.scans.Yandex.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Yandex.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Yandex.update", + "data_type": "string", + "example_values": [ + "20190120" + ] + }, + { + "contains": [ + "ip" + ], + "data_path": "action_result.data.*.scans.Yandex.version", + "data_type": "string", + "example_values": [ + "5.5.1.3" + ] + }, + { + "data_path": "action_result.data.*.scans.Zillya.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Zillya.result", + "data_type": "string", + "example_values": [ + "Virus.Parite.Win32.9" + ] + }, + { + "data_path": "action_result.data.*.scans.Zillya.update", + "data_type": "string", + "example_values": [ + "20190118" + ] + }, + { + "data_path": "action_result.data.*.scans.Zillya.version", + "data_type": "string", + "example_values": [ + "2.0.0.3733" + ] + }, + { + "data_path": "action_result.data.*.scans.ZoneAlarm.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.ZoneAlarm.result", + "data_type": "string", + "example_values": [ + "Virus.Win32.Parite.b" + ] + }, + { + "data_path": "action_result.data.*.scans.ZoneAlarm.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.ZoneAlarm.version", + "data_type": "string", + "example_values": [ + "1.0" + ] + }, + { + "data_path": "action_result.data.*.scans.Zoner.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.Zoner.result", + "data_type": "string", + "example_values": [ + "Win32.Parite.B" + ] + }, + { + "data_path": "action_result.data.*.scans.Zoner.update", + "data_type": "string", + "example_values": [ + "20190121" + ] + }, + { + "data_path": "action_result.data.*.scans.Zoner.version", + "data_type": "string", + "example_values": [ + "1.0" + ] + }, + { + "data_path": "action_result.data.*.scans.eGambit.detected", + "data_type": "boolean", + "example_values": [ + true, + false + ] + }, + { + "data_path": "action_result.data.*.scans.eGambit.result", + "data_type": "string" + }, + { + "data_path": "action_result.data.*.scans.eGambit.update", + "data_type": "string", + "example_values": [ + "20190122" + ] + }, + { + "data_path": "action_result.data.*.scans.eGambit.version", + "data_type": "string", + "example_values": [ + "v4.3.5" + ] + }, + { + "contains": [ + "hash", + "sha1" + ], + "data_path": "action_result.data.*.sha1", + "data_type": "string", + "example_values": [ + "6c1948f7edf115cd1f13cd170b882077930be150" + ] + }, + { + "contains": [ + "hash", + "sha256" + ], + "data_path": "action_result.data.*.sha256", + "data_type": "string", + "example_values": [ + "27ce020f7cdb4b775b80bd6e3ef1d16079401e0d45cfd28ffbd8c63ff2ddf7d7" + ] + }, + { + "data_path": "action_result.data.*.total", + "data_type": "numeric", + "example_values": [ + 72 + ] + }, + { + "data_path": "action_result.data.*.verbose_msg", + "data_type": "string", + "example_values": [ + "Scan finished, information embedded" + ] + }, + { + "data_path": "action_result.summary.positives", + "data_type": "numeric", + "example_values": [ + 64 + ] + }, + { + "data_path": "action_result.summary.total_scans", + "data_type": "numeric", + "example_values": [ + 72 + ] + }, + { + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "Positives: 64, Total scans: 72" + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_positives", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "parameters": { + "hash": { + "contains": [ + "hash", + "sha256", + "sha1", + "md5" + ], + "data_type": "string", + "default": null, + "description": "File hash to query", + "key": "hash", + "order": 0, + "primary": true, + "required": true + } + }, + "product_name": "VirusTotal", + "product_vendor": "VirusTotal", + "targets": "34", + "type": "" + } + ], + "attrs": { + ".action": { + "text": "file reputation" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Investigate" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.error image": { + "xlink:href": "/inc/coa/img/block_icon_warn.svg" + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_investigate.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def file_reputation_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('file_reputation_1() called')\n\n # collect data for 'file_reputation_1' call\n container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.fileHash', 'artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'file_reputation_1' call\n for container_item in container_data:\n if container_item[0]:\n parameters.append({\n 'hash': container_item[0],\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n\n phantom.act(action=\"file reputation\", parameters=parameters, assets=['virustotal'], callback=filter_1, name=\"file_reputation_1\")\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#654796", + "connected_to_start": true, + "connection_name": "", + "connection_type": "", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "3c5abd70-80e5-46b8-908e-4eeb0ae4cef5", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 443, + "line_start": 422, + "message": "Configuring now", + "name": "file reputation", + "notes": "", + "number": 1, + "order": 16, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 220, + "y": 80 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "file_reputation_1", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": false, + "show_number": false, + "size": { + "height": 112, + "width": 168 + }, + "state": "action_assets", + "status": "", + "title": "Investigate", + "type": "coa.Action", + "warn": false, + "z": 2957 + }, + { + "action": "block hash", + "action_type": "contain", + "active": false, + "active_keys": {}, + "active_values": { + "comment": "", + "hash": "hunt_file_2:artifact:*.cef.fileHash" + }, + "angle": 0, + "app": "", + "approver": "", + "assets": [ + { + "action": "", + "active": true, + "app_name": "", + "app_version": "", + "appid": "", + "config_type": "asset", + "fields": { + "comment": "", + "hash": "hunt_file_2:artifact:*.cef.fileHash" + }, + "has_app": true, + "id": "-", + "loaded": false, + "missing": false, + "name": "carbonblack", + "output": [ + { + "data_path": "action_result.status", + "data_type": "string", + "example_values": [ + "success" + ] + }, + { + "data_path": "action_result.parameter.comment", + "data_type": "string", + "example_values": [ + "Sample comment" + ] + }, + { + "column_name": "Hash", + "column_order": 0, + "contains": [ + "md5", + "hash" + ], + "data_path": "action_result.parameter.hash", + "data_type": "string", + "example_values": [ + "180469AE0B239E31DB4C65F02FD70BC1" + ] + }, + { + "data_path": "action_result.data", + "data_type": "string" + }, + { + "data_path": "action_result.summary", + "data_type": "string" + }, + { + "column_name": "Message", + "column_order": 1, + "data_path": "action_result.message", + "data_type": "string", + "example_values": [ + "Block hash action succeeded. It might take some time for blacklisting to take effect." + ] + }, + { + "data_path": "summary.total_objects", + "data_type": "numeric", + "example_values": [ + 1 + ] + }, + { + "data_path": "summary.total_objects_successful", + "data_type": "numeric", + "example_values": [ + 1 + ] + } + ], + "product_name": "", + "product_vendor": "", + "type": "endpoint" + } + ], + "attrs": { + ".action": { + "text": "block hash 3" + }, + ".background": { + "fill": "#000000", + "stroke": "#5C6773" + }, + ".border": { + "height": 88 + }, + ".color-band": { + "fill": "#3C444D" + }, + ".inPorts>.port-in": { + "ref": ".background", + "ref-x": 0.5 + }, + ".inPorts>.port-in>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".message": { + "fill": "#FFFFFF", + "font-size": 12, + "font-weight": 300, + "opacity": 0, + "ref": ".background", + "ref-x": 5, + "ref-y": 105, + "text": "Configuring now" + }, + ".outPorts>.port-out": { + "ref": ".background", + "ref-x": 0.5 + }, + ".outPorts>.port-out>.port-body": { + "port": { + "id": "out", + "type": "out" + } + }, + ".title": { + "text": "Contain" + }, + "g.approver image": { + "opacity": 1 + }, + "g.code image": { + "opacity": 1 + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.icon image": { + "xlink:href": "/inc/coa/img/block_icon_contain.svg" + }, + "g.notes": { + "display": "block", + "opacity": 1 + }, + "g.notes image": { + "opacity": 1 + }, + "g.timer image": { + "opacity": 1 + }, + "rect.warn-background": { + "fill": "#FFFFFF" + }, + "text.icon": { + "fill": "#FFFFFF" + } + }, + "block_code": "def block_hash_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('block_hash_3() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n # collect data for 'block_hash_3' call\n inputs_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:artifact:*.cef.fileHash', 'hunt_file_2:artifact:*.id'], action_results=results)\n\n parameters = []\n \n # build parameters list for 'block_hash_3' call\n for inputs_item_1 in inputs_data_1:\n if inputs_item_1[0]:\n parameters.append({\n 'hash': inputs_item_1[0],\n 'comment': \"\",\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': inputs_item_1[1]},\n })\n\n phantom.act(action=\"block hash\", parameters=parameters, assets=['carbonblack'], callback=join_filter_2, name=\"block_hash_3\", parent_action=action)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": true, + "color": "#3D9959", + "connected_to_start": false, + "connection_name": "hunt file 2", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "delay": "0", + "description": "", + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "4aa9e1f2-fc69-4439-ae54-3eb215adec8f", + "inPorts": [ + "in" + ], + "join_code": "", + "join_optional": [], + "join_start": 1, + "line_end": 373, + "line_start": 349, + "message": "Configuring now", + "name": "block hash", + "notes": "", + "number": 3, + "order": 13, + "outPorts": [ + "out" + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 840, + "y": 340 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "block_hash_3", + "required_params": { + "hash": true + }, + "reviewer": "", + "showNumber": true, + "show_number": true, + "size": { + "height": 112, + "width": 168 + }, + "state": "asset", + "status": "", + "title": "Contain", + "type": "coa.Action", + "warn": false, + "z": 2958 + }, + { + "active": false, + "angle": 0, + "attrs": { + ".background": { + "fill": "#000000", + "stroke": "#5C6773", + "transform": "rotate(45 30 70)" + }, + ".border": { + "transform": "rotate(45 30 70)" + }, + ".inPorts>.port-0>.port-body": { + "port": { + "id": "in", + "type": "in" + } + }, + ".number": { + "text": 2 + }, + ".outPorts>.port-0": { + "port": { + "id": "out-1", + "type": "out" + }, + "ref-x": 83, + "ref-y": 40 + }, + ".outPorts>.port-0>.port-body": { + "port": { + "id": "out-1", + "type": "out" + } + }, + "g.delete": { + "display": "none" + }, + "g.error": { + "opacity": 0 + }, + "g.notes": { + "display": "block" + }, + "g.notes image": { + "opacity": 1 + } + }, + "block_code": "def filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('filter_2() called')\n\n # collect filtered artifact ids for 'if' condition 1\n matched_artifacts_1, matched_results_1 = phantom.condition(\n container=container,\n action_results=results,\n conditions=[\n [\"file_reputation_1:action_result.summary.positives\", \">\", 10],\n ],\n name=\"filter_2:condition_1\")\n\n # call connected blocks if filtered artifacts or results\n if matched_artifacts_1 or matched_results_1:\n create_ticket_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1)\n\n return", + "callback_code": "", + "callback_start": 1, + "callsback": false, + "connected_to_start": false, + "connection_name": "logoff user, shutdown system, disable user, block hash 3", + "connection_type": "action", + "custom_callback": "", + "custom_code": "", + "custom_join": "", + "custom_name": "", + "description": "", + "hasElse": false, + "has_custom": false, + "has_custom_block": false, + "has_custom_callback": false, + "has_custom_join": false, + "id": "a44f44e3-b4cb-4409-a495-8afedb2754e4", + "inPorts": [ + "in" + ], + "join_code": "def join_filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None):\n phantom.debug('join_filter_2() called')\n\n # check if all connected incoming playbooks, actions, or custom functions are done i.e. have succeeded or failed\n if phantom.completed(action_names=['logoff_user_1', 'shutdown_system_1', 'disable_user_1', 'block_hash_3']):\n \n # call connected block \"filter_2\"\n filter_2(container=container, handle=handle)\n \n return", + "join_optional": [], + "join_start": 132, + "line_end": 143, + "line_start": 114, + "name": "filter", + "notes": "", + "number": 2, + "order": 5, + "outPorts": [ + "out-1" + ], + "outputs": [ + { + "conditions": [ + { + "comparison": ">", + "data_type": "", + "param": "file_reputation_1:action_result.summary.positives", + "value": "10" + } + ], + "display": "If", + "logic": "and", + "type": "if" + } + ], + "ports": { + "groups": { + "in": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "left" + } + }, + "position": { + "name": "left" + } + }, + "out": { + "attrs": { + ".port-body": { + "fill": "#fff", + "magnet": true, + "r": 10, + "stroke": "#000" + }, + ".port-label": { + "fill": "#000" + } + }, + "label": { + "position": { + "args": { + "y": 10 + }, + "name": "right" + } + }, + "position": { + "name": "right" + } + } + } + }, + "position": { + "x": 1080, + "y": 340 + }, + "previous_block_type": "", + "previous_function": "", + "previous_name": "filter_2", + "show_number": true, + "size": { + "height": 82, + "width": 82 + }, + "state": "filter", + "status": "", + "type": "coa.Filter", + "warn": false, + "z": 2959 + } + ] + }, + "notes": "" + }, + "python_version": "3", + "schema": 4, + "version": "4.10.0.40961" + }, + "create_time": "2021-01-21T21:31:52.515480+00:00", + "draft_mode": false, + "labels": [ + "events" + ], + "tags": [], + "misc": { + "apps_list": [ + "LDAP", + "ServiceNow", + "Carbon Black Response", + "VirusTotal" + ] + } +} \ No newline at end of file diff --git a/playbooks/malware_hunt_and_contain.png b/playbooks/malware_hunt_and_contain.png new file mode 100644 index 0000000000..784fcde3ab Binary files /dev/null and b/playbooks/malware_hunt_and_contain.png differ diff --git a/playbooks/malware_hunt_and_contain.py b/playbooks/malware_hunt_and_contain.py new file mode 100644 index 0000000000..eb7e2f484f --- /dev/null +++ b/playbooks/malware_hunt_and_contain.py @@ -0,0 +1,456 @@ +""" +This playbook investigates and remediates malware infections on the endpoint. +""" + +import phantom.rules as phantom +import json +from datetime import datetime, timedelta +############################## +# Start - Global Code Block + +"""Malicous file detected on endpoint""" + +# End - Global Code block +############################## + +def on_start(container): + phantom.debug('on_start() called') + + # call 'file_reputation_1' block + file_reputation_1(container=container) + + return + +def filter_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('filter_3() called') + + # collect filtered artifact ids for 'if' condition 1 + matched_artifacts_1, matched_results_1 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["file_reputation_1:action_result.summary.positives", ">", 5], + ["file_reputation_1:action_result.summary.positives", "<=", 10], + ], + logical_operator='and', + name="filter_3:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + create_ticket_3(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + return + +def shutdown_system_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('shutdown_system_1() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'shutdown_system_1' call + results_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:action_result.data.*.process.results.*.hostname', 'hunt_file_2:action_result.parameter.context.artifact_id'], action_results=results) + + parameters = [] + + # build parameters list for 'shutdown_system_1' call + for results_item_1 in results_data_1: + parameters.append({ + 'ph': "", + 'message': "", + 'wait_time': "", + 'ip_hostname': results_item_1[0], + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': results_item_1[1]}, + }) + + phantom.act(action="shutdown system", parameters=parameters, assets=['domainctrl1'], callback=join_filter_2, name="shutdown_system_1", parent_action=action) + + return + +def create_ticket_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'create_ticket_2' call + + disabled_users = set(phantom.collect2(datapath='disable_user_1:action_result.parameter.username')) + blocked_hashes = set(phantom.collect2(datapath='block_hash_3:action_result.parameter.hash')) + loggedoff_users = set(phantom.collect2(datapath='logoff_user_1:action_result.parameter.username')) + shutdown_systems = set(phantom.collect2(datapath='shutdown_system_1:action_result.parameter.ip_hostname')) + file_reputation = phantom.collect2(datapath=['file_reputation_1:filtered-action_result.parameter.hash', + 'file_reputation_1:filtered-action_result.summary.positives']) + detected_users = set(phantom.collect2(datapath='hunt_file_2:action_result.data.*.process.results.*.username')) + detected_systems = set(phantom.collect2(datapath='hunt_file_2:action_result.data.*.process.results.*.hostname')) + + title = "Virus Detected on {0} devices".format(len(detected_systems)) + + description = "Hashes sumbitted with detections:\n{0}\n\n".format(", ".join(["{0} ({1})".format(*fr) for fr in file_reputation])) + description += "File was found on {0} devices:\n{1}\n\n".format(len(detected_systems), ', '.join(detected_systems)) + description += "This impacts at least {0} users:\n{1}\n\n".format(len(detected_users), ', '.join(detected_users)) + if len(blocked_hashes): + description += "{0} hashes were submitted for blocking:\n{1}\n\n".format(len(blocked_hashes), ", ".join(blocked_hashes)) + if len(loggedoff_users): + description += "{0} users were forced to logoff:\n{1}\n\n".format(len(loggedoff_users), ", ".join(loggedoff_users)) + if len(disabled_users): + description += "{0} user accounts were disabled:\n{1}\n\n".format(len(disabled_users), ", ".join(disabled_users)) + if len(shutdown_systems): + description += "{0} systems were shutdown:\n{1}\n\n".format(len(shutdown_systems), ", ".join(shutdown_systems)) + + parameters = [] + + # build parameters list for 'create_ticket_2' call + parameters.append({ + 'short_description': title, + 'description': description, + 'fields': "", + }) + + if parameters: + phantom.act("create ticket", parameters=parameters, assets=['servicenow'], name="create_ticket_2", parent_action=action) + else: + phantom.error("'create_ticket_2' will not be executed due to lack of parameters") + + return + +def filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('filter_2() called') + + # collect filtered artifact ids for 'if' condition 1 + matched_artifacts_1, matched_results_1 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["file_reputation_1:action_result.summary.positives", ">", 10], + ], + name="filter_2:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + create_ticket_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + return + +def join_filter_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None): + phantom.debug('join_filter_2() called') + + # check if all connected incoming playbooks, actions, or custom functions are done i.e. have succeeded or failed + if phantom.completed(action_names=['logoff_user_1', 'shutdown_system_1', 'disable_user_1', 'block_hash_3']): + + # call connected block "filter_2" + filter_2(container=container, handle=handle) + + return + +def logoff_user_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('logoff_user_1() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'logoff_user_1' call + results_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:action_result.data.*.process.results.*.hostname', 'hunt_file_2:action_result.parameter.context.artifact_id'], action_results=results) + + parameters = [] + + # build parameters list for 'logoff_user_1' call + for results_item_1 in results_data_1: + parameters.append({ + 'username': "", + 'ip_hostname': results_item_1[0], + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': results_item_1[1]}, + }) + + phantom.act(action="logoff user", parameters=parameters, assets=['domainctrl1'], callback=join_filter_2, name="logoff_user_1", parent_action=action) + + return + +def filter_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('filter_1() called') + + # collect filtered artifact ids for 'if' condition 1 + matched_artifacts_1, matched_results_1 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["file_reputation_1:action_result.summary.positives", ">", 5], + ["file_reputation_1:action_result.summary.positives", "<=", 10], + ], + logical_operator='and', + name="filter_1:condition_1") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_1 or matched_results_1: + hunt_file_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + get_file_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_1, filtered_results=matched_results_1) + + # collect filtered artifact ids for 'if' condition 2 + matched_artifacts_2, matched_results_2 = phantom.condition( + container=container, + action_results=results, + conditions=[ + ["file_reputation_1:action_result.summary.positives", ">", 10], + ], + name="filter_1:condition_2") + + # call connected blocks if filtered artifacts or results + if matched_artifacts_2 or matched_results_2: + hunt_file_2(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_2, filtered_results=matched_results_2) + get_file_3(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function, filtered_artifacts=matched_artifacts_2, filtered_results=matched_results_2) + + return + +def hunt_file_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('hunt_file_2() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'hunt_file_2' call + filtered_results_data_1 = phantom.collect2(container=container, datapath=["filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash", "filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.context.artifact_id"]) + + parameters = [] + + # build parameters list for 'hunt_file_2' call + for filtered_results_item_1 in filtered_results_data_1: + if filtered_results_item_1[0]: + parameters.append({ + 'hash': filtered_results_item_1[0], + 'type': "", + 'range': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': filtered_results_item_1[1]}, + }) + + phantom.act(action="hunt file", parameters=parameters, assets=['carbonblack'], callback=hunt_file_2_callback, name="hunt_file_2") + + return + +def hunt_file_2_callback(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None): + phantom.debug('hunt_file_2_callback() called') + + disable_user_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function) + logoff_user_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function) + shutdown_system_1(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function) + block_hash_3(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function) + + return + +def get_file_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('get_file_3() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'get_file_3' call + filtered_results_data_1 = phantom.collect2(container=container, datapath=["filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.hash", "filtered-data:filter_1:condition_2:file_reputation_1:action_result.parameter.context.artifact_id"]) + + parameters = [] + + # build parameters list for 'get_file_3' call + for filtered_results_item_1 in filtered_results_data_1: + parameters.append({ + 'hash': filtered_results_item_1[0], + 'ph_0': "", + 'offset': "", + 'get_count': "", + 'sensor_id': "", + 'file_source': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': filtered_results_item_1[1]}, + }) + + phantom.act(action="get file", parameters=parameters, assets=['carbonblack'], name="get_file_3") + + return + +def get_file_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('get_file_2() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'get_file_2' call + filtered_results_data_1 = phantom.collect2(container=container, datapath=["filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash", "filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.context.artifact_id"]) + + parameters = [] + + # build parameters list for 'get_file_2' call + for filtered_results_item_1 in filtered_results_data_1: + parameters.append({ + 'hash': filtered_results_item_1[0], + 'ph_0': "", + 'offset': "", + 'get_count': "", + 'sensor_id': "", + 'file_source': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': filtered_results_item_1[1]}, + }) + + phantom.act(action="get file", parameters=parameters, assets=['carbonblack'], name="get_file_2") + + return + +def create_ticket_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'create_ticket_2' call + + file_reputation = phantom.collect2(datapath=['file_reputation_1:filtered-action_result.parameter.hash', + 'file_reputation_1:filtered-action_result.summary.positives']) + blocked_hashes = set(phantom.collect2(datapath='block_hash_2:action_result.parameter.hash')) + detected_users = set(phantom.collect2(datapath='hunt_file_1:action_result.data.*.process.results.*.username')) + detected_systems = set(phantom.collect2(datapath='hunt_file_1:action_result.data.*.process.results.*.hostname')) + + title = "Virus Detected on {0} devices".format(len(detected_systems)) + + description = "Hashes sumbitted with detections:\n{0}\n\n".format(", ".join(["{0} ({1})".format(*fr) for fr in file_reputation])) + description += "File was found on {0} devices:\n{1}\n\n".format(len(detected_systems), ', '.join(detected_systems)) + description += "This impacts at least {0} users:\n{1}\n\n".format(len(detected_users), ', '.join(detected_users)) + if len(blocked_hashes): + description += "{0} hashes were submitted for blocking:\n{1}\n\n".format(len(blocked_hashes), ", ".join(blocked_hashes)) + + parameters = [] + + # build parameters list for 'create_ticket_2' call + parameters.append({ + 'short_description': title, + 'description': description, + 'fields': "", + }) + + if parameters: + phantom.act("create ticket", parameters=parameters, assets=['servicenow'], name="create_ticket_3", parent_action=action) + else: + phantom.error("'create_ticket_3' will not be executed due to lack of parameters") + + return + +def disable_user_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('disable_user_1() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'disable_user_1' call + results_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:action_result.data.*.process.results.*.username', 'hunt_file_2:action_result.parameter.context.artifact_id'], action_results=results) + + parameters = [] + + # build parameters list for 'disable_user_1' call + for results_item_1 in results_data_1: + if results_item_1[0]: + parameters.append({ + 'username': results_item_1[0], + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': results_item_1[1]}, + }) + + phantom.act(action="disable user", parameters=parameters, assets=['domainctrl1'], callback=join_filter_2, name="disable_user_1", parent_action=action) + + return + +def block_hash_3(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('block_hash_3() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'block_hash_3' call + inputs_data_1 = phantom.collect2(container=container, datapath=['hunt_file_2:artifact:*.cef.fileHash', 'hunt_file_2:artifact:*.id'], action_results=results) + + parameters = [] + + # build parameters list for 'block_hash_3' call + for inputs_item_1 in inputs_data_1: + if inputs_item_1[0]: + parameters.append({ + 'hash': inputs_item_1[0], + 'comment': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': inputs_item_1[1]}, + }) + + phantom.act(action="block hash", parameters=parameters, assets=['carbonblack'], callback=join_filter_2, name="block_hash_3", parent_action=action) + + return + +def hunt_file_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('hunt_file_1() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'hunt_file_1' call + filtered_results_data_1 = phantom.collect2(container=container, datapath=["filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.hash", "filtered-data:filter_1:condition_1:file_reputation_1:action_result.parameter.context.artifact_id"]) + + parameters = [] + + # build parameters list for 'hunt_file_1' call + for filtered_results_item_1 in filtered_results_data_1: + if filtered_results_item_1[0]: + parameters.append({ + 'hash': filtered_results_item_1[0], + 'type': "binary", + 'range': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': filtered_results_item_1[1]}, + }) + + phantom.act(action="hunt file", parameters=parameters, assets=['carbonblack'], callback=block_hash_2, name="hunt_file_1") + + return + +def block_hash_2(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('block_hash_2() called') + + #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED'))) + + # collect data for 'block_hash_2' call + inputs_data_1 = phantom.collect2(container=container, datapath=['hunt_file_1:artifact:*.cef.fileHash', 'hunt_file_1:artifact:*.id'], action_results=results) + + parameters = [] + + # build parameters list for 'block_hash_2' call + for inputs_item_1 in inputs_data_1: + if inputs_item_1[0]: + parameters.append({ + 'hash': inputs_item_1[0], + 'comment': "", + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': inputs_item_1[1]}, + }) + + phantom.act(action="block hash", parameters=parameters, assets=['carbonblack'], callback=filter_3, name="block_hash_2", parent_action=action) + + return + +def file_reputation_1(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs): + phantom.debug('file_reputation_1() called') + + # collect data for 'file_reputation_1' call + container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.fileHash', 'artifact:*.id']) + + parameters = [] + + # build parameters list for 'file_reputation_1' call + for container_item in container_data: + if container_item[0]: + parameters.append({ + 'hash': container_item[0], + # context (artifact id) is added to associate results with the artifact + 'context': {'artifact_id': container_item[1]}, + }) + + phantom.act(action="file reputation", parameters=parameters, assets=['virustotal'], callback=filter_1, name="file_reputation_1") + + return + +def on_finish(container, summary): + phantom.debug('on_finish() called') + # This function is called after all actions are completed. + # summary of all the action and/or all details of actions + # can be collected here. + + # summary_json = phantom.get_summary() + # if 'result' in summary_json: + # for action_result in summary_json['result']: + # if 'action_run_id' in action_result: + # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False) + # phantom.debug(action_results) + + return \ No newline at end of file diff --git a/playbooks/malware_hunt_and_contain.yml b/playbooks/malware_hunt_and_contain.yml new file mode 100644 index 0000000000..1264b08be1 --- /dev/null +++ b/playbooks/malware_hunt_and_contain.yml @@ -0,0 +1,22 @@ +name: Malware Hunt and Contain +id: fb3edc76-ff2b-43c0-5f6f-63da4483fd63 +version: 1 +date: '2021-01-21' +author: Philip Royer, Splunk +type: Response +description: This playbook investigates and remediates malware infections on the endpoint. +playbook: malware_hunt_and_contain +how_to_implement: "Be sure to update asset naming to reflect the asset names configured in your environment." +references: [] +app_list: +- "LDAP" +- "ServiceNow" +- "CarbonBlack Response" +- "VirusTotal" +tags: + platform_tags: + - Response + playbook_fields: + - FileHash + product: + - Splunk SOAR \ No newline at end of file