mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
32 lines
856 B
YAML
32 lines
856 B
YAML
name: VirusTotal V3 Dynamic Analysis
|
|
id: 388ed434-a498-4d55-8de4-b2657825cb67
|
|
version: 1
|
|
date: '2023-03-23'
|
|
author: Teoderick Contreras, Splunk
|
|
type: Investigation
|
|
description: "Accepts a url link, domain or vault_id (hash) to be detonated using Virustotal V3 connector."
|
|
playbook: VirusTotal_v3_Dynamic_Analysis
|
|
how_to_implement: This input playbook requires the Virustotal V3 API connector to be configured.
|
|
It is designed to work in conjunction with the Dynamic Attribute Lookup playbook or other playbooks in the same style.
|
|
references: []
|
|
app_list:
|
|
- VirusTotal v3
|
|
tags:
|
|
platform_tags:
|
|
- url
|
|
- domain
|
|
- sandbox
|
|
- ip
|
|
- file_hash
|
|
- virustotal_v3
|
|
playbook_type: Input
|
|
vpe_type: Modern
|
|
playbook_fields: []
|
|
product:
|
|
- Splunk SOAR
|
|
use_cases:
|
|
- Enrichment
|
|
- Phishing
|
|
- Endpoint
|
|
defend_technique_id: D3-DA
|