Google Safe Browsing v2
Google Safe Browsing Pack.#
This Integration is part of theSupported versions
Supported Cortex XSOAR versions: 5.5.0 and later.
Search Safe Browsing v4
#
Configure GoogleSafeBrowsing on Cortex XSOARNavigate to Settings > Integrations > Servers & Services.
Search for GoogleSafeBrowsing.
Click Add instance to create and configure a new integration instance.
Parameter Description Required API Key True Client ID True Client Version True Base URL True Source Reliability Reliability of the source providing the intelligence data. True Use system proxy settings False Trust any certificate (not secure) False Click Test to validate the URLs, token, and connection.
#
CommandsYou can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
#
urlCheck URL Reputation
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
#
Base Commandurl
#
InputArgument Name | Description | Required |
---|---|---|
url | URL to check. | Required |
#
Context OutputPath | Type | Description |
---|---|---|
DBotScore.Indicator | string | The indicator that was tested. |
DBotScore.Type | string | The indicator type. |
DBotScore.Vendor | string | The vendor used to calculate the score. |
DBotScore.Score | int | The actual score. |
DBotScore.Reliability | string | Reliability of the source providing the intelligence data. |
GoogleSafeBrowsing.URL.cacheDuration | string | The URL cache duration time. |
GoogleSafeBrowsing.URL.threatType | string | The URL threat type. |
GoogleSafeBrowsing.URL.threatEntryType | string | The URL threat entry type. |
GoogleSafeBrowsing.URL.platformType | string | The URL platform type. |
URL.Data | string | Bad URLs found |
URL.Malicious.Vendor | string | For malicious URLs, the vendor that made the decision |
URL.Malicious.Description | string | For malicious URLs, the reason for the vendor to make the decision |
#
Command Example!url url="http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"
#
Context Example#
Human Readable Output#
Google Safe Browsing APIs - URL Query
http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/#
Found matches for URL
cacheDuration platformType threat threatEntryType threatType 300s ANY_PLATFORM {"url":"http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"} URL MALWARE 300s WINDOWS {"url":"http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"} URL MALWARE 300s LINUX {"url":"http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"} URL MALWARE 300s ALL_PLATFORMS {"url":"http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"} URL MALWARE 300s OSX {"url":"http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"} URL MALWARE 300s CHROME {"url":"http://testsafebrowsing.appspot.com/apiv4/ANY_PLATFORM/MALWARE/URL/"} URL MALWARE