Skip to main content

Detonate URL - ThreatGrid

This Playbook is part of the Cisco Secure Malware Analytics Pack.#


Use Detonate URL - ThreatGrid v2 instead.

Detonates one or more URLs using the ThreatGrid integration. This playbook returns relevant reports to the War Room and URL reputations to the context data.


This playbook uses the following sub-playbooks, integrations, and scripts.


  • GenericPolling


  • Threat Grid


This playbook does not use any scripts.


  • threat-grid-url-to-file
  • threat-grid-get-samples-state
  • threat-grid-upload-sample

Playbook Inputs#

NameDescriptionDefault ValueSourceRequired
URLThe URL of the sites to detonate.DataURLOptional
FileNameThe name of the file to detonate.file-detonated-via-demisto-Optional
VMThe VM to use (string).--Optional
PlaybookThe name of the Threat Grid playbook to apply to this sample run.default-Optional
PrivateThe sample is marked private if this is present. If it is set to any other value then it will not be private.--Optional
SourceThe string used for identifying the source of the detonation (user defined).--Optional
TagsA comma-separated list of tags applied to the sample.--Optional
IntervalThe polling frequency. How often the polling command should run (in minutes).1-Optional
TimeoutHow much time to wait before a timeout occurs (in minutes).15-Optional

Playbook Outputs#

File.SHA256The SHA256 hash of the file.string
File.MaliciousThe File malicious descriptionunknown
File.TypeThe file type. For example, "PE".string
File.SizeTHe file size.number
File.MD5The MD5 hash of the file.string
File.NameThe filename.string
File.SHA1The SHA1 hash of the file.string
FileThe file object.unknown
File.Malicious.VendorThe vendor that made the decision that the file is malicious.string
DBotScoreThe DBotScore object.unknown
DBotScore.IndicatorThe indicator that was tested.string
DBotScore.TypeThe type of the indicator.string
DBotScore.VendorThe vendor used to calculate the score.string
DBotScore.ScoreThe actual score.number
Sample.StateThe sample state.unknown
Sample.IDThe sample ID.unknown

Playbook Image#