Skip to main content

CrowdStrike Falcon Intelligence Sandbox Detonate and Analyze File

This Playbook is part of the CrowdStrike Falcon Intelligence Sandbox Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

This playbook uploads, detonates, and analyzes files for the CrowdStrike Falcon Intelligence Sandbox.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • CrowdStrikeFalconIntelligenceSandbox

Scripts#

  • IsIntegrationAvailable
  • Set

Commands#

  • cs-fx-upload-file
  • cs-fx-submit-uploaded-file

Playbook Inputs#


NameDescriptionDefault ValueRequired
FileThe details of the file to detonate.Optional
AlertOSThe operating system for which the alert was raised.
Possible values:
Windows
Linux
* Android
${incident.deviceosname}Optional

Playbook Outputs#


PathDescriptionType
csfalconx.resource.tagsThe analysis tags.unknown
csfalconx.resource.sha256The SHA256 hash of the scanned file.unknown
csfalconx.resource.file_nameThe name of the uploaded file.unknown
csfalconx.resource.sandboxThe Falcon Intelligence Sandbox findings results.unknown
csfalconx.resource.intelThe Falcon Intelligence Sandbox intelligence results.unknown

Playbook Image#


Falcon Intelligence Sandbox Detonate and Analyze File