Skip to main content

Recorded Future Sandbox

This Playbook is part of the Recorded Future Intelligence Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

Template playbook utilizing Hatching.io to sandbox a given file and generate an analysis report. Indicators from the given report are then extracted and enriched with Recorded Future data.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • GenericPolling

Integrations#

  • Hatching Triage
  • Recorded Future v2

Scripts#

This playbook does not use any scripts.

Commands#

  • domain
  • triage-submit-sample
  • recordedfuture-malware-search
  • triage-get-report-triage
  • triage-get-sample-summary
  • ip
  • triage-get-static-report
  • extractIndicators
  • url

Playbook Inputs#


NameDescriptionDefault ValueRequired
FileFile.EntryIDOptional

Playbook Outputs#


PathDescriptionType
DBotScoreThe DBotScore object.unknown
DBotScore.IndicatorTriage analysis targetunknown
DBotScore.TypeThe indicator type - File or URLunknown
DBotScore.VendorThe integration used to generate the indicatorunknown
DBotScore.ScoreAnalysis verdict as score from 1 to 10unknown

Playbook Image#


Recorded Future Sandbox