Skip to main content

File Enrichment - Generic v2

This Playbook is part of the Common Playbooks Pack.#

Enriches a file using one or more integrations.

  • Provide threat information


This playbook uses the following sub-playbooks, integrations, and scripts.


  • File Enrichment - Virus Total Private API


  • Cylance Protect v2


This playbook does not use any scripts.


  • cylance-protect-get-threat

Playbook Inputs#

NameDescriptionDefault ValueSourceRequired
MD5The MD5 hash to enrich.MD5FileOptional
SHA256The SHA256 hash to enrich.SHA256FileOptional
SHA1The SHA1 hash to enrich.SHA1FileOptional

Playbook Outputs#

DBotScore.IndicatorThe indicator that was tested.string
DBotScore.TypeThe indicator type.string
File.SHA1The SHA1 hash of the file.string
File.SHA256The SHA256 hash of the file.string
File.Malicious.VendorThe vendor that made the decision that the file is malicious.string
File.MD5The MD5 hash of the file.string
DBotScoreThe DBotScore object.unknown
FileThe file object.unknown
DBotScore.VendorThe vendor used to calculate the score.string
DBotScore.ScoreThe actual score.number
File.VirusTotal.ScansThe scan object.unknown
File.VirusTotal.Scans.SourceThe vendor that scanned this hash.unknown
File.VirusTotal.Scans.DetectedWhether a scan was detected for this hash. Can be, "True" or "False".unknown
File.VirusTotal.Scans.ResultScan result for this hash. For example, signature, etc.unknown

Playbook Image#