| @@ -0,0 +1,1133 @@ | ||
| { | ||
| "definitionVersion" : "1.0.0", | ||
| "name" : "BIF Signature Generator", | ||
| "type" : "Standard", | ||
| "panX" : -521.6224, | ||
| "panY" : -45.1676, | ||
| "logLevel" : "WARN", | ||
| "description" : "Generates Bro Intelligence Framework signatures from an indicator.", | ||
| "jobList" : [ { | ||
| "id" : 18782, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Format Sig w/ Description", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bro.sig\",\"value\":\"#App:18829:merged.indicator!String\\t#App:18829:merged.bif_type!String\\tThreatConnect\\t#App:18834:tc.indicator.description!String\\t#Trigger:1887:trg.action.weblink!String\"}]" | ||
| } ], | ||
| "locationLeft" : 2380.0, | ||
| "locationTop" : -140.0, | ||
| "outputVariables" : "[{\"name\":\"bro.sig\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18795, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SignatureCreate v1.0", | ||
| "displayName" : "Create ThreatConnect Signature", | ||
| "programVersion" : "1.0.18" | ||
| }, | ||
| "name" : "Create BIF Signature", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "tags" | ||
| } | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "signature_file_data" | ||
| }, | ||
| "value" : "#App:18799:uncompress.data!Binary" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "attributes_all" | ||
| }, | ||
| "value" : "true" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "signature_file_type" | ||
| }, | ||
| "value" : "Bro" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "labels" | ||
| } | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "associations" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.entity!TCEntity" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "attributes" | ||
| }, | ||
| "value" : "[]" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "fail_on_error" | ||
| }, | ||
| "value" : "true" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "resource_name" | ||
| }, | ||
| "value" : "#App:18851:new_title!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "signature_file_name" | ||
| }, | ||
| "value" : "sig.bro" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "resource_type" | ||
| }, | ||
| "value" : "Signature" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "labels_all" | ||
| }, | ||
| "value" : "true" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "tags_all" | ||
| }, | ||
| "value" : "true" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "owner" | ||
| }, | ||
| "value" : "Research Labs" | ||
| } ], | ||
| "locationLeft" : 3880.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"tc.signature.web_link\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18798, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - CompressFile v1.0", | ||
| "displayName" : "Compress File", | ||
| "programVersion" : "1.0.7" | ||
| }, | ||
| "name" : "Compress File", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "file_name" | ||
| }, | ||
| "value" : "something" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "algorithm" | ||
| }, | ||
| "value" : "ZIP" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "content" | ||
| }, | ||
| "value" : "#App:18802:bro.sig!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "password" | ||
| } | ||
| } ], | ||
| "locationLeft" : 2780.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"compress.data\",\"type\":\"Binary\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18799, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - UncompressFile v1.0", | ||
| "displayName" : "Uncompress File", | ||
| "programVersion" : "1.0.7" | ||
| }, | ||
| "name" : "Uncompress File", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "content" | ||
| }, | ||
| "value" : "#App:18798:compress.data!Binary" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "algorithm" | ||
| }, | ||
| "value" : "ZIP" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "password" | ||
| } | ||
| } ], | ||
| "locationLeft" : 3000.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"uncompress.data\",\"type\":\"Binary\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18800, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "Description?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "null" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "not equals" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#App:18834:tc.indicator.description!String" | ||
| } ], | ||
| "locationLeft" : 2220.0, | ||
| "locationTop" : -100.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18801, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Format Sig w/o Description", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bro.sig\",\"value\":\"#App:18829:merged.indicator!String\\t#App:18829:merged.bif_type!String\\tThreatConnect\\tNo Description\\t#Trigger:1887:trg.action.weblink!String\"}]" | ||
| } ], | ||
| "locationLeft" : 2380.0, | ||
| "locationTop" : -40.0, | ||
| "outputVariables" : "[{\"name\":\"bro.sig\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18802, | ||
| "appCatalogItem" : { | ||
| "programName" : "Merge", | ||
| "displayName" : "Merge", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "Merge Sigs", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "output_array" | ||
| }, | ||
| "value" : "[{\"key\":\"bro.sig\",\"value\":\"#App:18782:bro.sig!String\"},{\"key\":\"bro.sig\",\"value\":\"#App:18801:bro.sig!String\"}]" | ||
| } ], | ||
| "locationLeft" : 2630.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"bro.sig\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18803, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "Address?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "equals" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "Address" | ||
| } ], | ||
| "locationLeft" : -110.0, | ||
| "locationTop" : -70.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18806, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Set Address Variables", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bif_type\",\"value\":\"Intel::ADDR\"},{\"key\":\"indicator\",\"value\":\"#Trigger:1887:trg.action.item!String\"}]" | ||
| } ], | ||
| "locationLeft" : 60.0, | ||
| "locationTop" : -100.0, | ||
| "outputVariables" : "[{\"name\":\"indicator\",\"type\":\"String\"},{\"name\":\"bif_type\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18819, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "Host?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "equals" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "Host" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| } ], | ||
| "locationLeft" : 80.0, | ||
| "locationTop" : 20.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18820, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "EmailAddr?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "EmailAddress" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "equals" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| } ], | ||
| "locationLeft" : 270.0, | ||
| "locationTop" : 100.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18821, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "URL?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "URL" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "equals" | ||
| } ], | ||
| "locationLeft" : 460.0, | ||
| "locationTop" : 190.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18822, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "CIDR?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "CIDR" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "equals" | ||
| } ], | ||
| "locationLeft" : 650.0, | ||
| "locationTop" : 290.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18823, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "File?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "equals" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "File" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| } ], | ||
| "locationLeft" : 830.0, | ||
| "locationTop" : 390.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18824, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Set Host Variables", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bif_type\",\"value\":\"Intel::DOMAIN\"},{\"key\":\"indicator\",\"value\":\"#Trigger:1887:trg.action.item!String\"}]" | ||
| } ], | ||
| "locationLeft" : 250.0, | ||
| "locationTop" : -10.0, | ||
| "outputVariables" : "[{\"name\":\"bif_type\",\"type\":\"String\"},{\"name\":\"indicator\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18825, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Set Email Address Variables", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bif_type\",\"value\":\"Intel::EMAIL\"},{\"key\":\"indicator\",\"value\":\"#Trigger:1887:trg.action.item!String\"}]" | ||
| } ], | ||
| "locationLeft" : 440.0, | ||
| "locationTop" : 80.0, | ||
| "outputVariables" : "[{\"name\":\"indicator\",\"type\":\"String\"},{\"name\":\"bif_type\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18826, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Set URL Variables", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bif_type\",\"value\":\"Intel::URL\"}]" | ||
| } ], | ||
| "locationLeft" : 630.0, | ||
| "locationTop" : 170.0, | ||
| "outputVariables" : "[{\"name\":\"bif_type\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18827, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Set CIDR Variables", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bif_type\",\"value\":\"Intel::SUBNET\"},{\"key\":\"indicator\",\"value\":\"#Trigger:1887:trg.action.item!String\"}]" | ||
| } ], | ||
| "locationLeft" : 810.0, | ||
| "locationTop" : 270.0, | ||
| "outputVariables" : "[{\"name\":\"bif_type\",\"type\":\"String\"},{\"name\":\"indicator\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18828, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Set File Variables", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"bif_type\",\"value\":\"Intel::FILE_HASH\"}]" | ||
| } ], | ||
| "locationLeft" : 990.0, | ||
| "locationTop" : 370.0, | ||
| "outputVariables" : "[{\"name\":\"bif_type\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18829, | ||
| "appCatalogItem" : { | ||
| "programName" : "Merge", | ||
| "displayName" : "Merge", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "Merge Data", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "output_array" | ||
| }, | ||
| "value" : "[{\"key\":\"merged.bif_type\",\"value\":\"#App:18806:bif_type!String\"},{\"key\":\"merged.bif_type\",\"value\":\"#App:18824:bif_type!String\"},{\"key\":\"merged.bif_type\",\"value\":\"#App:18825:bif_type!String\"},{\"key\":\"merged.bif_type\",\"value\":\"#App:18826:bif_type!String\"},{\"key\":\"merged.bif_type\",\"value\":\"#App:18827:bif_type!String\"},{\"key\":\"merged.bif_type\",\"value\":\"#App:18828:bif_type!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18806:indicator!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18824:indicator!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18825:indicator!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18841:stripped_url!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18827:indicator!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18846:indicator!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18847:indicator!String\"},{\"key\":\"merged.indicator\",\"value\":\"#App:18848:indicator!String\"}]" | ||
| } ], | ||
| "locationLeft" : 2050.0, | ||
| "locationTop" : -100.0, | ||
| "outputVariables" : "[{\"name\":\"merged.bif_type\",\"type\":\"String\"},{\"name\":\"merged.indicator\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18834, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - IndicatorRetrieveByValue v1.1", | ||
| "displayName" : "Get ThreatConnect Indicator by Value", | ||
| "programVersion" : "1.1.17" | ||
| }, | ||
| "name" : "Get Indicator", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "output_variable" | ||
| }, | ||
| "value" : "indicator" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "values" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.item!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "owner" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.owner!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "resource_type" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.type!String" | ||
| } ], | ||
| "locationLeft" : -370.0, | ||
| "locationTop" : -70.0, | ||
| "outputVariables" : "[{\"name\":\"tc.indicator.description\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18840, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - RegexExtract v1.0", | ||
| "displayName" : "Regex Extract", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Strip Scheme", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "strip_nulls" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "regex_pattern_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"raw_data\",\"value\":\"(?:https?|s?ftp):\\\\/\\\\/(.+)\"}]" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "capture_groups" | ||
| }, | ||
| "value" : "true" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "input_content" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.item!String" | ||
| } ], | ||
| "locationLeft" : 850.0, | ||
| "locationTop" : 170.0, | ||
| "outputVariables" : "[{\"name\":\"raw_data\",\"type\":\"StringArray\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18841, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - JoinArray v1.0", | ||
| "displayName" : "Join Array", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Join URL", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "array_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"stripped_url\",\"value\":\"#App:18840:raw_data!StringArray\"}]" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "delimiter" | ||
| }, | ||
| "value" : "," | ||
| } ], | ||
| "locationLeft" : 1070.0, | ||
| "locationTop" : 170.0, | ||
| "outputVariables" : "[{\"name\":\"stripped_url\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18842, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "SHA256?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "null" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#App:18843:tc.file.sha256!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "not equals" | ||
| } ], | ||
| "locationLeft" : 1470.0, | ||
| "locationTop" : 370.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18843, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - FileRetrieveByValue v1.1", | ||
| "displayName" : "Get ThreatConnect File by Value", | ||
| "programVersion" : "1.1.17" | ||
| }, | ||
| "name" : "Get File", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "owner" | ||
| }, | ||
| "value" : "Research Labs" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "values" | ||
| }, | ||
| "value" : "#Trigger:1887:trg.action.entity!TCEntity" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "resource_type" | ||
| }, | ||
| "value" : "File" | ||
| } ], | ||
| "locationLeft" : 1220.0, | ||
| "locationTop" : 370.0, | ||
| "outputVariables" : "[{\"name\":\"tc.file.md5\",\"type\":\"String\"},{\"name\":\"tc.file.sha256\",\"type\":\"String\"},{\"name\":\"tc.file.sha1\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18844, | ||
| "appCatalogItem" : { | ||
| "programName" : "If / Else", | ||
| "displayName" : "If / Else", | ||
| "programVersion" : "1.0.0" | ||
| }, | ||
| "name" : "SHA1?", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_1" | ||
| }, | ||
| "value" : "#App:18843:tc.file.sha1!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operator" | ||
| }, | ||
| "value" : "not equals" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "match_case" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "operand_2" | ||
| }, | ||
| "value" : "null" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "as_numeric" | ||
| }, | ||
| "value" : "false" | ||
| } ], | ||
| "locationLeft" : 1640.0, | ||
| "locationTop" : 470.0, | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18846, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "SHA256", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"indicator\",\"value\":\"#App:18843:tc.file.sha256!String\"}]" | ||
| } ], | ||
| "locationLeft" : 1620.0, | ||
| "locationTop" : 350.0, | ||
| "outputVariables" : "[{\"name\":\"indicator\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18847, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "SHA1", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"indicator\",\"value\":\"#App:18843:tc.file.sha1!String\"}]" | ||
| } ], | ||
| "locationLeft" : 1800.0, | ||
| "locationTop" : 450.0, | ||
| "outputVariables" : "[{\"name\":\"indicator\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18848, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "MD5", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"indicator\",\"value\":\"#App:18843:tc.file.md5!String\"}]" | ||
| } ], | ||
| "locationLeft" : 1800.0, | ||
| "locationTop" : 560.0, | ||
| "outputVariables" : "[{\"name\":\"indicator\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18849, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - RegexExtract v1.0", | ||
| "displayName" : "Regex Extract", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Truncate Title", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "strip_nulls" | ||
| }, | ||
| "value" : "false" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "capture_groups" | ||
| }, | ||
| "value" : "true" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "input_content" | ||
| }, | ||
| "value" : "#App:18850:raw_data!String" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "regex_pattern_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"truncated_title\",\"value\":\"(.{1,100})+?.*\"}]" | ||
| } ], | ||
| "locationLeft" : 3440.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"truncated_title\",\"type\":\"StringArray\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18850, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - SetVariable v1.0", | ||
| "displayName" : "Set Variable", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Format Title", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "variable_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"raw_data\",\"value\":\"BIF: #App:18829:merged.indicator!String\"}]" | ||
| } ], | ||
| "locationLeft" : 3220.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"raw_data\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| }, { | ||
| "id" : 18851, | ||
| "appCatalogItem" : { | ||
| "programName" : "TCPB - JoinArray v1.0", | ||
| "displayName" : "Join Array", | ||
| "programVersion" : "1.0.5" | ||
| }, | ||
| "name" : "Join Title", | ||
| "jobParameterList" : [ { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "array_mapping" | ||
| }, | ||
| "value" : "[{\"key\":\"new_title\",\"value\":\"#App:18849:truncated_title!StringArray\"}]" | ||
| }, { | ||
| "appCatalogItemParameter" : { | ||
| "paramName" : "delimiter" | ||
| }, | ||
| "value" : "," | ||
| } ], | ||
| "locationLeft" : 3660.0, | ||
| "locationTop" : -80.0, | ||
| "outputVariables" : "[{\"name\":\"new_title\",\"type\":\"String\"}]", | ||
| "playbookRetryEnabled" : false | ||
| } ], | ||
| "playbookConnectionList" : [ { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18798, | ||
| "targetJobId" : 18799 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18800, | ||
| "targetJobId" : 18782 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18800, | ||
| "targetJobId" : 18801 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18782, | ||
| "targetJobId" : 18802 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18802, | ||
| "targetJobId" : 18798 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18801, | ||
| "targetJobId" : 18802 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18803, | ||
| "targetJobId" : 18806 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18803, | ||
| "targetJobId" : 18819 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18819, | ||
| "targetJobId" : 18820 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18820, | ||
| "targetJobId" : 18821 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18821, | ||
| "targetJobId" : 18822 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18822, | ||
| "targetJobId" : 18823 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18819, | ||
| "targetJobId" : 18824 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18820, | ||
| "targetJobId" : 18825 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18821, | ||
| "targetJobId" : 18826 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18822, | ||
| "targetJobId" : 18827 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18823, | ||
| "targetJobId" : 18828 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18806, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18824, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18825, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18827, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18829, | ||
| "targetJobId" : 18800 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : true, | ||
| "sourceJobId" : 18795, | ||
| "targetTriggerId" : 1887 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "targetJobId" : 18834, | ||
| "sourceTriggerId" : 1887 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18834, | ||
| "targetJobId" : 18803 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18826, | ||
| "targetJobId" : 18840 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18840, | ||
| "targetJobId" : 18841 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18841, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18828, | ||
| "targetJobId" : 18843 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18843, | ||
| "targetJobId" : 18842 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18842, | ||
| "targetJobId" : 18844 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18842, | ||
| "targetJobId" : 18846 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18844, | ||
| "targetJobId" : 18847 | ||
| }, { | ||
| "type" : "Fail", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18844, | ||
| "targetJobId" : 18848 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18846, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18847, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18848, | ||
| "targetJobId" : 18829 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18799, | ||
| "targetJobId" : 18850 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18850, | ||
| "targetJobId" : 18849 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18849, | ||
| "targetJobId" : 18851 | ||
| }, { | ||
| "type" : "Pass", | ||
| "isCircularOnTarget" : false, | ||
| "sourceJobId" : 18851, | ||
| "targetJobId" : 18795 | ||
| } ], | ||
| "playbookTriggerList" : [ { | ||
| "id" : 1887, | ||
| "name" : "Generate BIF Signature", | ||
| "type" : "UserAction", | ||
| "eventType" : "External", | ||
| "locationLeft" : -370.0, | ||
| "locationTop" : -320.0, | ||
| "httpBasicAuthEnable" : false, | ||
| "httpResponseHeader" : "[]", | ||
| "httpResponseBody" : "<a href=\"#App:18795:tc.signature.web_link!String\">Signature Generated</a>", | ||
| "anyOrg" : true, | ||
| "orFilters" : false, | ||
| "fireOnDuplicate" : false, | ||
| "userActionTypes" : "Address,Adversary,CIDR,EmailAddress,File,Host,URL", | ||
| "renderBodyAsTip" : true, | ||
| "outputVariables" : "[{\"name\":\"trg.action.entity\",\"type\":\"TCEntity\"},{\"name\":\"trg.action.type\",\"type\":\"String\"},{\"name\":\"trg.action.weblink\",\"type\":\"String\"},{\"name\":\"trg.action.owner\",\"type\":\"String\"},{\"name\":\"trg.action.item\",\"type\":\"String\"}]" | ||
| } ], | ||
| "exportablePipes" : [ ], | ||
| "dateExported" : "6/6/18 7:19 PM" | ||
| } |