Skip to main content

Darkmon - Enrich URL

This Playbook is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

Sub-playbook that calls the Darkmon !url command and returns DBotScore + Common.URL for the input URL indicator. Designed to be invoked from a parent playbook; does not auto-run on indicator creation.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Darkmon

Scripts#

This playbook does not use any scripts.

Commands#

  • url

Playbook Inputs#


NameDescriptionDefault ValueRequired
URLThe URL indicator value to enrich. Defaults to ${URL.Data}.URL.DataRequired

Playbook Outputs#


PathDescriptionType
DBotScore.IndicatorThe indicator value.string
DBotScore.TypeThe indicator type.string
DBotScore.VendorThe vendor reporting the score (Darkmon).string
DBotScore.ScoreThe reputation score (0=Unknown, 1=Good, 2=Suspicious, 3=Bad).number
DBotScore.ReliabilitySource reliability per the Admiralty code.string
URL.DataThe URL value.string
URL.Malicious.VendorThe vendor that flagged this URL as malicious (Darkmon).string
URL.Malicious.DescriptionReason this URL was flagged as malicious.string
Darkmon.SearchResultFull search result records returned by Darkmon for this indicator.unknown