Skip to main content

DarkmonVIPFanOut

This Script is part of the Darkmon Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.8.0 and later).

For each protected email, calls dmontip-get-boardemails three times (accounts, combo-lists, public-breaches), filters new entries, creates incidents.

Script Data#


NameDescription
Script Typepython3
Tagsdarkmon
Cortex XSOAR Version6.5.0

Dependencies#


This script uses the following commands and scripts.

  • Darkmon
  • dmontip-get-boardemails

Used In#


This script is used in the following playbooks and scripts.

  • Darkmon - VIP Email Monitor

Inputs#


Argument NameDescription
itemsItems to process.
id_fieldField name to use as the dedup key.
seen_listName of the XSOAR List storing already-seen IDs.
domain_filter_listOptional - list of customer domains to filter username matches.
domain_match_fieldField on each item to match against domain_filter_list.
allowlistOptional list of usernames/DNs that must NEVER be actioned.
allowlist_match_fieldField to match against the allowlist.
incident_typeIncident type for newly created incidents.
severitySeverity (1=Low, 2=Medium, 3=High, 4=Critical).
name_templateIncident name template (supports ${field} interpolation).
field_mapComma-separated 'fieldCli=sourcePath' pairs.
emailsEmail addresses to fan out per VIP fetch.
domains
brands_list
max_distance
min_cvss
tech_stack_list

Outputs#


PathDescriptionType
NewAccountsunknown
CreatedIncidentsunknown
Countnumber
Typosquatsunknown
FilteredCVEsunknown
VIPCreatednumber