Skip to main content

Get File Sample From Path - Generic V3

This Playbook is part of the Common Playbooks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This playbook returns a file sample from a specified path and host that you input in the following playbooks:

  • PS Remote Get File Sample From Path
  • Get File Sample From Path - VMware Carbon Black EDR (Live Response API)
  • CrowdStrike Falcon - Retrieve File
  • MDE - Retrieve File
  • Cortex XDR - Retrieve File V2

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • MDE - Retrieve File
  • CrowdStrike Falcon - Retrieve File
  • Get File Sample From Path - VMware Carbon Black EDR - Live Response API
  • Cortex XDR - Retrieve File v2
  • PS Remote Get File Sample From Path

Integrations#

This playbook does not use any integrations.

Scripts#

This playbook does not use any scripts.

Commands#

This playbook does not use any commands.

Playbook Inputs#


NameDescriptionDefault ValueRequired
HostHostname of the machine on which the file is located, for PS remote it can also be an IP address.Optional
PathThe path of the file to retrieve.
For example:
C:\users\folder\file.txt
Optional
Agent_IDThe ID of the agent, or of the endpoint, in the relevant integration (such as EDR).Optional

Playbook Outputs#


PathDescriptionType
File.SizeThe size of the file.number
File.TypeThe type of the file.string
File.InfoGeneral information of the file.string
File.MD5The MD5 hash of the file.string
File.SHA1The SHA1 hash of the file.string
File.SHA256The SHA256 hash of the file.string
File.SHA512The SHA512 hash of the file.string
File.EntryIDThe file entry ID.string
File.ExtensionThe file extension.string
File.NameThe file name.string
File.SSDeepFile SSDeep.string
AcquiredFileThe acquired file details.Unknown
ExtractedFilesA list of file names that were extracted from the ZIP file.string
NonRetrievedFilesA list of files that were not retrieved.string

Playbook Image#


Get File Sample From Path - Generic V3