Skip to main content

DarkmonFilterUnseen

This Script is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

Filters items by ID against an XSOAR List (state) and optionally by domain match or allowlist. Updates the List with new IDs. Outputs NewAccounts.

Script Data#


NameDescription
Script Typepython3
Tagsdarkmon
Cortex XSOAR Version6.5.0

Used In#


This script is used in the following playbooks and scripts.

  • Darkmon - Critical CVE Pipeline
  • Darkmon - Ransomware Mentions Watch
  • Darkmon - Brand-Targeted NRD Watch
  • Darkmon - Compromised Employee Auto-Disable
  • Darkmon - Compromised Credentials Sweep
  • Darkmon - Ransomware Victim Response

Inputs#


Argument NameDescription
itemsItems to process.
id_fieldField name to use as the dedup key.
seen_listName of the XSOAR List storing already-seen IDs.
domain_filter_listOptional - list of customer domains to filter username matches.
domain_match_fieldField on each item to match against domain_filter_list.
allowlistOptional list of usernames/DNs that must NEVER be actioned.
allowlist_match_fieldField to match against the allowlist.
incident_typeIncident type for newly created incidents.
severitySeverity (1=Low, 2=Medium, 3=High, 4=Critical).
name_templateIncident name template (supports ${field} interpolation).
field_mapComma-separated 'fieldCli=sourcePath' pairs.
emailsEmail addresses to fan out per VIP fetch.
domains
brands_list
max_distance
min_cvss
tech_stack_list

Outputs#


PathDescriptionType
NewAccountsunknown
CreatedIncidentsunknown
Countnumber
Typosquatsunknown
FilteredCVEsunknown
VIPCreatednumber