Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 20 additions & 1 deletion Packs/ReversingLabs_Titanium_Cloud/.secrets-ignore
Original file line number Diff line number Diff line change
Expand Up @@ -83,4 +83,23 @@ https://eclipse.org
142.250.186.110
142.250.186.131
34.104.35.123
142.250.181.227
142.250.181.227
https://images-na.ssl-images-amazon.com
52.204.132.63
https://slyb.app.link
142.250.179.206
216.58.214.3
http://www.imdb.com
142.250.179.142
http://ogp.me
54.192.87.100
67.220.240.31
142.251.39.106
142.250.179.131
142.251.36.36
108.156.69.18
65.9.86.10
18.239.24.188
13.227.211.55
52.94.225.248
18.239.38.222
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,10 @@ starttaskid: "0"
tasks:
"0":
id: "0"
taskid: 01bb6b67-07d0-457f-84c9-4ffeabc2c6c4
taskid: 02062e9f-0a5f-4059-859a-57c0c5d9719d
type: start
task:
id: 01bb6b67-07d0-457f-84c9-4ffeabc2c6c4
id: 02062e9f-0a5f-4059-859a-57c0c5d9719d
version: -1
name: ""
iscommand: false
Expand All @@ -37,10 +37,10 @@ tasks:
isautoswitchedtoquietmode: false
"1":
id: "1"
taskid: 07c255c5-0665-4cfd-8428-72df1211000a
taskid: 85a1f9a1-6ca0-4803-8df1-4f57efc0de40
type: condition
task:
id: 07c255c5-0665-4cfd-8428-72df1211000a
id: 85a1f9a1-6ca0-4803-8df1-4f57efc0de40
version: -1
name: Is ReversingLabs TitaniumCloud v2 enabled?
type: condition
Expand Down Expand Up @@ -98,10 +98,10 @@ tasks:
isautoswitchedtoquietmode: false
"3":
id: "3"
taskid: bca91921-a4f3-4b2a-8b90-a519ec676464
taskid: e20cfbc9-74e5-45a3-8cf6-e1f13bb45809
type: title
task:
id: bca91921-a4f3-4b2a-8b90-a519ec676464
id: e20cfbc9-74e5-45a3-8cf6-e1f13bb45809
version: -1
name: done
type: title
Expand All @@ -126,10 +126,10 @@ tasks:
isautoswitchedtoquietmode: false
"4":
id: "4"
taskid: 90a93e32-8589-470a-8399-7ce1cf8a0683
taskid: f2d96fa4-72d7-43e7-8d36-8adf648f27ea
type: condition
task:
id: 90a93e32-8589-470a-8399-7ce1cf8a0683
id: f2d96fa4-72d7-43e7-8d36-8adf648f27ea
version: -1
name: Is there a file hash to analyze?
type: condition
Expand Down Expand Up @@ -168,10 +168,10 @@ tasks:
isautoswitchedtoquietmode: false
"5":
id: "5"
taskid: 556cb7ef-3d6c-4319-87aa-3e733cbfc3ca
taskid: 7db41591-379a-4e27-8e48-4a8ad0bebfe2
type: regular
task:
id: 556cb7ef-3d6c-4319-87aa-3e733cbfc3ca
id: 7db41591-379a-4e27-8e48-4a8ad0bebfe2
version: -1
name: ReversingLabs - Get file reputation
description: Retrieve File Reputation data from TitaniumCloud.
Expand Down Expand Up @@ -203,10 +203,10 @@ tasks:
isautoswitchedtoquietmode: false
"6":
id: "6"
taskid: 203ee9ee-e755-43b2-84b1-cd2256ca066b
taskid: 7e943e0f-ed92-4387-8309-9584efad3b61
type: condition
task:
id: 203ee9ee-e755-43b2-84b1-cd2256ca066b
id: 7e943e0f-ed92-4387-8309-9584efad3b61
version: -1
name: What is the sample's classification?
type: condition
Expand Down Expand Up @@ -281,10 +281,10 @@ tasks:
isautoswitchedtoquietmode: false
"17":
id: "17"
taskid: d87238d4-4447-45d9-8aab-18de009a0b50
taskid: 492798eb-33eb-41bd-8c1a-9b144268eb75
type: regular
task:
id: d87238d4-4447-45d9-8aab-18de009a0b50
id: 492798eb-33eb-41bd-8c1a-9b144268eb75
version: -1
name: Label for manual inspection by "Analyst"
description: This indicator needs to be manually inspected by a SOC engineer.
Expand Down Expand Up @@ -320,10 +320,10 @@ tasks:
isautoswitchedtoquietmode: false
"18":
id: "18"
taskid: 80429df7-3328-4e13-88f6-bc64844b7198
taskid: 49d989b1-bd69-49e6-817e-db35be60cf3f
type: regular
task:
id: 80429df7-3328-4e13-88f6-bc64844b7198
id: 49d989b1-bd69-49e6-817e-db35be60cf3f
version: -1
name: Increase incident severity to CRITICAL
description: Optionally increases the incident severity to the new value if
Expand Down Expand Up @@ -356,10 +356,10 @@ tasks:
isautoswitchedtoquietmode: false
"19":
id: "19"
taskid: 14d042c4-75c0-448f-819a-17361979b5c6
taskid: 8cb507a1-9b5e-473f-8356-45b3f7946e4c
type: playbook
task:
id: 14d042c4-75c0-448f-819a-17361979b5c6
id: 8cb507a1-9b5e-473f-8356-45b3f7946e4c
version: -1
name: Isolate Endpoint
description: |-
Expand Down Expand Up @@ -398,10 +398,10 @@ tasks:
isautoswitchedtoquietmode: false
"21":
id: "21"
taskid: 49f3c414-236d-4f25-89be-2378f37694ce
taskid: ed92a9e5-ce56-43b6-85ae-e5bc5e90f81d
type: regular
task:
id: 49f3c414-236d-4f25-89be-2378f37694ce
id: ed92a9e5-ce56-43b6-85ae-e5bc5e90f81d
version: -1
name: ReversingLabs - Upload file to TitaniumCloud
description: Upload a file using a byte stream with a SHA1 hash of the file
Expand Down Expand Up @@ -434,14 +434,14 @@ tasks:
isautoswitchedtoquietmode: false
"22":
id: "22"
taskid: 5121fba3-af32-42c8-863f-aa3398aa65f0
taskid: 28fa023d-3bb0-400c-89b0-c270c8199c52
type: regular
task:
id: 5121fba3-af32-42c8-863f-aa3398aa65f0
id: 28fa023d-3bb0-400c-89b0-c270c8199c52
version: -1
name: ReversingLabs - Submit file for dynamic analysis
description: Submit an existing sample for dynamic analysis.
script: '|||reversinglabs-titaniumcloud-submit-for-dynamic-analysis'
script: '|||reversinglabs-titaniumcloud-submit-sample-for-dynamic-analysis'
type: regular
iscommand: true
brand: ""
Expand Down Expand Up @@ -476,14 +476,14 @@ tasks:
isautoswitchedtoquietmode: false
"23":
id: "23"
taskid: aeb6a5b0-2666-4b68-86ce-700bc60dab47
taskid: c707914f-51c0-4676-8f33-14a7ab92f41d
type: regular
task:
id: aeb6a5b0-2666-4b68-86ce-700bc60dab47
id: c707914f-51c0-4676-8f33-14a7ab92f41d
version: -1
name: ReversingLabs - Get dynamic analysis results
description: Retrieve dynamic analysis results.
script: '|||reversinglabs-titaniumcloud-get-dynamic-analysis-results'
description: Retrieve dynamic analysis results for a sample.
script: '|||reversinglabs-titaniumcloud-get-sample-dynamic-analysis-results'
type: regular
iscommand: true
brand: ""
Expand Down Expand Up @@ -515,10 +515,10 @@ tasks:
isautoswitchedtoquietmode: false
"24":
id: "24"
taskid: fd982bbe-7f87-4f06-8562-d0ff2d2d07fb
taskid: 499f8647-f601-4032-8eda-312f4540628b
type: condition
task:
id: fd982bbe-7f87-4f06-8562-d0ff2d2d07fb
id: 499f8647-f601-4032-8eda-312f4540628b
version: -1
name: Is there a classification for the sample?
type: condition
Expand Down Expand Up @@ -559,10 +559,10 @@ tasks:
isautoswitchedtoquietmode: false
"25":
id: "25"
taskid: b9470efe-bf5d-47c2-8880-91b801ec1dc7
taskid: 76c133ce-7f90-49bb-8413-fcbc8e5e8dae
type: regular
task:
id: b9470efe-bf5d-47c2-8880-91b801ec1dc7
id: 76c133ce-7f90-49bb-8413-fcbc8e5e8dae
version: -1
name: Indicator - Set FalsePositive tag and Benign verdict
description: Change the properties of an indicator
Expand Down Expand Up @@ -598,10 +598,10 @@ tasks:
isautoswitchedtoquietmode: false
"26":
id: "26"
taskid: 000fb11c-802d-4128-817e-1c59d888590f
taskid: 6d657e14-d591-4d66-860a-75d8d180e318
type: regular
task:
id: 000fb11c-802d-4128-817e-1c59d888590f
id: 6d657e14-d591-4d66-860a-75d8d180e318
version: -1
name: Set incident severity to LOW
description: Change the properties of an incident
Expand Down Expand Up @@ -633,10 +633,10 @@ tasks:
isautoswitchedtoquietmode: false
"28":
id: "28"
taskid: 44fd457e-aa10-4784-866a-f0990735838c
taskid: 7e0e387a-52bb-4a51-835b-c5c0ddcdaeb1
type: regular
task:
id: 44fd457e-aa10-4784-866a-f0990735838c
id: 7e0e387a-52bb-4a51-835b-c5c0ddcdaeb1
version: -1
name: Indicator - Set verdict to Suspicious
description: Change the properties of an indicator
Expand Down Expand Up @@ -670,10 +670,10 @@ tasks:
isautoswitchedtoquietmode: false
"29":
id: "29"
taskid: 8c4810a3-cd46-42c9-8f3f-87dc1177c0e5
taskid: 51dd286b-c5eb-49b1-8292-b0f143228a9e
type: regular
task:
id: 8c4810a3-cd46-42c9-8f3f-87dc1177c0e5
id: 51dd286b-c5eb-49b1-8292-b0f143228a9e
version: -1
name: Indicator - Set verdict to Malicious
description: Change the properties of an indicator
Expand Down Expand Up @@ -707,10 +707,10 @@ tasks:
isautoswitchedtoquietmode: false
"30":
id: "30"
taskid: 3a8706b9-3b8d-4188-81b2-88aeebe07393
taskid: d882a045-2dc7-42f0-87d2-e6c831828a0c
type: regular
task:
id: 3a8706b9-3b8d-4188-81b2-88aeebe07393
id: d882a045-2dc7-42f0-87d2-e6c831828a0c
version: -1
name: Label for manual inspection by "Analyst"
description: This indicator needs to be manually inspected by a SOC engineer.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,12 @@ This playbook uses the following sub-playbooks, integrations, and scripts.

### Commands

* reversinglabs-titaniumcloud-file-reputation
* reversinglabs-titaniumcloud-get-dynamic-analysis-results
* setIndicator
* reversinglabs-titaniumcloud-file-upload
* setIncident
* reversinglabs-titaniumcloud-submit-for-dynamic-analysis
* reversinglabs-titaniumcloud-file-upload
* reversinglabs-titaniumcloud-get-sample-dynamic-analysis-results
* reversinglabs-titaniumcloud-submit-sample-for-dynamic-analysis
* reversinglabs-titaniumcloud-file-reputation

## Playbook Inputs

Expand Down