Skip to main content

Darkmon - Enrich Email

This Playbook is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

Sub-playbook that calls the Darkmon !email command and returns DBotScore + Common.Account.Email for the input Email indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Darkmon

Scripts#

This playbook does not use any scripts.

Commands#

  • email

Playbook Inputs#


NameDescriptionDefault ValueRequired
EmailThe Email indicator value to enrich. Defaults to ${Email.Address}.Email.AddressRequired

Playbook Outputs#


PathDescriptionType
DBotScore.IndicatorThe indicator value.string
DBotScore.TypeThe indicator type.string
DBotScore.VendorThe vendor reporting the score (Darkmon).string
DBotScore.ScoreThe reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).number
DBotScore.ReliabilitySource reliability per the Admiralty code.string
Account.Email.AddressThe Email value.string
Account.Email.Malicious.VendorThe vendor that flagged this Email as malicious (Darkmon).string
Account.Email.Malicious.DescriptionReason this Email was flagged as malicious.string
Darkmon.SearchResultFull search result records returned by Darkmon for this indicator.unknown