CheckPhish
CheckPhish Pack.#
This Integration is part of theCheck any URL to detect supsicious behavior.
#
Configure CheckPhish in CortexParameter | Description | Required |
---|---|---|
CheckPhish API URL | False | |
API Token | True | |
Good Dispositions (CheckPhish labels for non-phishing URLs. Default is "clean") | False | |
Suspicious dispositions (CheckPhish labels for suspicious phishing URLs). Default is "drug_spam", "gambling", "hacked_website", "streaming", "suspicious" | False | |
Bad dispositions (CheckPhish labels for phishing URLs). Defaults are "cryptojacking", "phish", "likely_phish", "scam". | False | |
Source Reliability | Reliability of the source providing the intelligence data. | True |
Trust any certificate (not secure) | False | |
Use system proxy settings | False |
#
CommandsYou can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
#
CheckPhish-check-urlsChecks URLs against the CheckPhish database and returns the results.
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
#
Base CommandCheckPhish-check-urls
#
InputArgument Name | Description | Required |
---|---|---|
url | A CSV list of URLs to check. | Required |
#
Context OutputPath | Type | Description |
---|---|---|
CheckPhish.URL.url | String | URL that was submitted. |
CheckPhish.URL.status | String | CheckPhish job status of the URL. |
CheckPhish.URL.jobID | String | CheckPhish jobID that was assigned to the URL when it was submitted. |
CheckPhish.URL.disposition | String | The CheckPhish category (disposition) of the URL. |
CheckPhish.URL.brand | String | The brand (attack target) countered by the URL. |
DBotScore.Indicator | String | The indicator that was tested. |
DBotScore.Type | String | The indicator type. |
DBotScore.Vendor | String | The vendor used to calculate the score. |
DBotScore.Score | Number | The actual score. |
DBotScore.Reliability | String | Reliability of the source providing the intelligence data. |
URL.Data | String | URL that was submitted. |
URL.Malicious.Vendor | String | CheckPhish. |
URL.Malicious.Description | String | The brand (attack target) countered by the URL. |
#
Command Example!CheckPhish-check-urls url=`test.com
#
Context Example#
Human Readable Outputhttp://test.com/#
CheckPhish reputation for
url disposition brand status jobID http://test.com/ clean unknown DONE 49a3a20b-ec4b-4581-9a55-56716d9e0c6e
#
urlRetrieves URL information from CheckPhish.
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
#
Base Commandurl
#
InputArgument Name | Description | Required |
---|---|---|
url | URL to query. | Required |
#
Context OutputPath | Type | Description |
---|---|---|
CheckPhish.URL.url | String | URL that was submitted. |
CheckPhish.URL.status | String | CheckPhish job status of the URL. |
CheckPhish.URL.jobID | String | CheckPhish jobID that was assigned to the URL when it was submitted. |
CheckPhish.URL.disposition | String | The CheckPhish category (disposition) of the URL. |
CheckPhish.URL.brand | String | The brand (attack target) countered by the URL. |
DBotScore.Indicator | String | The indicator that was tested. |
DBotScore.Type | String | The indicator type. |
DBotScore.Vendor | String | The vendor used to calculate the score. |
DBotScore.Score | Number | The actual score. |
DBotScore.Reliability | String | Reliability of the source providing the intelligence data. |
URL.Data | String | URL that was submitted. |
URL.Malicious.Vendor | String | CheckPhish. |
URL.Malicious.Description | String | The brand (attack target) countered by the URL. |
DBotScore.Indicator | String | The indicator that was tested. |
DBotScore.Type | String | The indicator type. |
DBotScore.Vendor | String | The vendor used to calculate the score. |
DBotScore.Score | Number | The actual score. |
DBotScore.Reliability | String | Reliability of the source providing the intelligence data. |
#
Command Example!url url=test.com
#
Context Example#
Human Readable Outputhttp://test.com/#
CheckPhish reputation for
url disposition brand status jobID http://test.com/ clean unknown DONE 6df1ebef-3be3-48a9-8970-c5afeda8d58d