Skip to main content

Detonate File - Trend Micro Deep Discovery Analyzer Beta

This Playbook is part of the TrendAI™ Deep Discovery™ Analyzer Pack.#

Supported versions

Available on Cortex XSOAR and Cortex XSIAM.

beta

This is a beta Integration, which lets you implement and test pre-release software. Since the integration is beta, it might contain bugs. Updates to the integration during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the integration to help us identify issues, fix them, and continually improve.

Detonates a File using the TrendAI™ Deep Discovery™ Analyzer sandbox. Deep Discovery Analyzer(version 6.0.0) supports the following File Types: bat, cell, chm, class, cmd, dll, doc, docx, exe, gul, hta, htm, html, hwp, hwpx, jar, js, jse, jtd, lnk, mov, pdf, ppt, pptx, ps1, pub, rtf, slk, svg, swf, vbe, vbs, wsf, xls, xlsx, xml

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • GenericPolling

Integrations#

  • Trend Micro Deep Discovery Analyzer

Scripts#

  • Set

Commands#

  • trendmicro-dda-check-status
  • trendmicro-dda-get-report
  • trendmicro-dda-upload-file

Playbook Inputs#


NameDescriptionDefault ValueRequired
FileThe file to detonate. File is taken from the context.FileRequired
intervalPolling frequency - how often the polling command should run (minutes)1Optional
timeoutHow much time to wait before a timeout occurs (minutes)15Optional

Playbook Outputs#


PathDescriptionType
DBotScore.TypeThe type of the indicatorstring
DBotScore.VendorVendor used to calculate the scorestring
TrendMicroDDA.Submissions.SHA1SHA1 of the submissionstring
TrendMicroDDA.Submissions.RiskLevelThe Risk Level of the samplenumber
DBotScore.ScoreThe actual scorenumber
TrendMicroDDA.Submissions.isCompletedStating if the detonation was complete or notstring
DBotScore.IndicatorThe indicator we testedstring
TrendMicroDDA.Submissions.statusThe status of the samplestring
InfoFile.MD5MD5 hash of the report filestring
InfoFile.SHA1SHA1 hash of the report filestring
InfoFile.SHA256SHA256 hash of the report filestring
InfoFile.NameReport file namestring
InfoFile.TypeReport file type e.g. "PE"string
InfoFile.SizeReport file sizenumber
File.Malicious.VendorFor malicious files, the vendor that made the decisionstring
File.Malicious.DescriptionFor malicious files, the reason for the vendor to make the decisionstring
IP.AddressIPs relevant to the submissionstring

Playbook Image#


Detonate File - Trend Micro Deep Discovery Analyzer Beta