Skip to main content

Recorded Future File Intelligence

This Playbook is part of the Recorded Future Intelligence Pack.#

File Enrichment using Recorded Future Intelligence

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts. Depends on the recorded futures indicator field; risk rules.

Sub-playbooks#

This playbook does not use any sub-playbooks.

Integrations#

  • Recorded Future v2

Scripts#

This playbook does not use any scripts.

Commands#

  • recordedfuture-intelligence

Playbook Inputs#


NameDescriptionDefault ValueRequired
MD5File MD5 hash to enrich.File.MD5Optional
SHA256File SHA-256 hash to enrich.File.SHA256Optional
SHA1File SHA-1 hash to enrich.File.SHA1Optional

Playbook Outputs#


PathDescriptionType
DBotScore.IndicatorThe indicator that was testedstring
DBotScore.TypeIndicator typestring
DBotScore.VendorVendor used to calculate the scorestring
DBotScore.ScoreThe actual scorenumber
File.SHA256File SHA-256string
File.SHA512File SHA-512string
File.SHA1File SHA-1string
File.MD5File MD5string
File.CRC32File CRC32string
File.CTPHFile CTPHstring
RecordedFuture.File.criticalityRisk Criticalitynumber
RecordedFuture.File.criticalityLabelRisk Criticality Labelstring
RecordedFuture.File.riskStringRisk Stringstring
RecordedFuture.File.riskSummaryRisk Summarystring
RecordedFuture.File.rulesRisk Rulesstring
RecordedFuture.File.scoreRisk Scorenumber
RecordedFuture.File.firstSeenEvidence First Seendate
RecordedFuture.File.lastSeenEvidence Last Seendate
RecordedFuture.File.intelCardRecorded Future Intelligence Card URLstring
RecordedFuture.File.hashAlgorithmHash Algorithmstring
RecordedFuture.File.typeEntity Typestring
RecordedFuture.File.nameEntitystring
RecordedFuture.File.idRecorded Future Entity IDstring
RecordedFuture.File.metrics.typeRecorded Future Metrics Typestring
RecordedFuture.File.metrics.valueRecorded Future Metrics Valuenumber
RecordedFuture.File.threatLists.descriptionRecorded Future Threat List Descriptionstring
RecordedFuture.File.threatLists.idRecorded Future Threat List IDstring
RecordedFuture.File.threatLists.nameRecorded Future Threat List Namestring
RecordedFuture.File.threatLists.typeRecorded Future Threat List Typestring
RecordedFuture.File.relatedEntities.RelatedAttacker.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedAttacker.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedAttacker.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedAttacker.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedTarget.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedTarget.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedTarget.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedTarget.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedThreatActor.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedThreatActor.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedThreatActor.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedThreatActor.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedMalware.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedMalware.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedMalware.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedMalware.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedCyberVulnerability.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedCyberVulnerability.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedCyberVulnerability.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedCyberVulnerability.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedIpAddress.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedIpAddress.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedIpAddress.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedIpAddress.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedInternetDomainName.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedInternetDomainName.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedInternetDomainName.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedInternetDomainName.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedProduct.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedProduct.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedProduct.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedProduct.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedCountries.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedCountries.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedCountries.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedCountries.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedHash.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedHash.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedHash.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedHash.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedTechnology.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedTechnology.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedTechnology.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedTechnology.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedEmailAddress.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedEmailAddress.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedEmailAddress.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedEmailAddress.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedAttackVector.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedAttackVector.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedAttackVector.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedAttackVector.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedMalwareCategory.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedMalwareCategory.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedMalwareCategory.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedMalwareCategory.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedOperations.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedOperations.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedOperations.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedOperations.typeRecorded Future Related Typestring
RecordedFuture.File.relatedEntities.RelatedCompany.countRecorded Future Related Countnumber
RecordedFuture.File.relatedEntities.RelatedCompany.idRecorded Future Related IDstring
RecordedFuture.File.relatedEntities.RelatedCompany.nameRecorded Future Related Namestring
RecordedFuture.File.relatedEntities.RelatedCompany.typeRecorded Future Related Typestring

Playbook Image#


Recorded Future File Intelligence