Supported Cortex XSOAR versions: 6.2.0 and later.
CIRCL hash lookup is a public API to lookup hash values against known database of files. NSRL RDS database is included and many others are also included. The API is accessible via HTTP ReST API and the API is also described as an OpenAPI. The service is free and served as a best-effort basis. This integration was integrated and tested with online version of CIRCLEHashlookup
Navigate to Settings > Integrations > Servers & Services.
Search for CIRCLEHashlookup.
Click Add instance to create and configure a new integration instance.
Parameter Description Required Server URL (e.g. https://hashlookup.circl.lu) True Trust any certificate (not secure) False Use system proxy settings False Source Reliability Reliability of the source providing the intelligence data. True Create relationships Create relationships between indicators as part of Enrichment. False
Click Test to validate the URLs, token, and connection.
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
Get information about the hash lookup database
|Circl.Info||string||Info about the hashlookup database|
Bulk search of MD5 hashes
|md5_list||List of MD5s to query.||Required|
|Circl.MD5||string||Results of bulk MD5 query|
Bulk search of SHA1 hashes
|sha1_list||List of SHA1 to search.||Required|
|Circl.SHA1||string||Results of bulk SHA1 query|
Checks the file reputation of the specified hash.
|file||Hash to query.||Required|
|File.Name||string||Name of the file|
|File.Size||number||Size of the file|
|File.MD5||string||MD5 hash of the file|
|File.SHA1||string||SHA1 hash of the file|
|File.SHA256||string||SHA256 hash of the file|
|File.SHA512||string||SHA512 hash of the file|
|File.SSDeep||string||SSDeep of the file|
|DbotScore.Indicator||string||The indicator value.|
|DbotScore.Reliability||string||The reliability of the source providing the intelligence data|
|DbotScore.Score||number||An integer regarding the status of the indicator|
|DbotScore.Type||string||The indicator type|
|DbotScore.Vendor||string||The vendor used to calculate the score|
Return the top 100 of most queried values.
|Circl.Top||string||The top 100 of most queried values|