Skip to main content

IsItPhishing

This Integration is part of the IsItPhishing Pack.#

Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage.

Configure IsItPhishing in Cortex#

ParameterDescriptionRequired
Server URL (e.g. https://192.168.0.1)False
Customer's nameTrue
Customer's LicenseTrue
Use system proxy settingsFalse
Trust any certificate (not secure)False
Source ReliabilityReliability of the source providing the intelligence data.False

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

url#


Checks if URL is phishing

Base Command#

url

Input#

Argument NameDescriptionRequired
urlURL to be checked if phishing.Required
forceSet true to analyze URL, or false to check whether URL may cause collateral damage to the end user. Default is false.Optional
smartSet true to force checks on URLs that may cause collateral damage to the end user, or false to ignore the argument. Default is true.Optional
areaThe regional area to force using a proxy.Optional
timeoutTimeout in milliseconds. Default value set to 10000, with a minimum value of 1000. Once timeout is reached, TIMEOUT response is returned.Optional

Context Output#

PathTypeDescription
URL.StatusunknownURL identification result.
URL.UrlunknownThe URL that was tested.
URL.Malicious.VendorunknownFor malicious URLs, the vendor that made the decision.
URL.Malicious.DescriptionunknownFor malicious URLs, the reason for the vendor to make the decision.
DBotScore.IndicatorunknownThe indicator that was tested.
DBotScore.TypeunknownThe indicator type.
DBotScore.VendorunknownThe vendor used to calculate the score.
DBotScore.ScoreunknownThe actual score.