Skip to main content

InvestigationSummaryParse

This Script is part of the Malware Investigation and Response Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.2.0 and later.

Retrieves information from previously run reputation commands and aggregates their results.

Script Data#


NameDescription
Script Typepython3
Cortex XSOAR Version6.2.0

Inputs#


There are no inputs for this script.

Outputs#


PathDescriptionType
InvestigationSummary.EvidenceOfPersistence.TacticThe tactic associated with the evidence of persistence finding.String
InvestigationSummary.EvidenceOfPersistence.ResultThe result of the evidence of persistence finding.String
InvestigationSummary.EvidenceOfPersistence.SourcesThe sources by which the evidence of persistence value was set.String
InvestigationSummary.EvidenceOfDefenseEvasion.TacticThe tactic associated with the evidence of defense evasion finding.String
InvestigationSummary.EvidenceOfDefenseEvasion.ResultThe result of the evidence of persistence finding.String
InvestigationSummary.EvidenceOfDefenseEvasion.SourcesThe sources by which the evidence of defense evasion value was set.String
InvestigationSummary.EvidenceOfExecution.TacticThe tactic associated with the evidence of execution finding.String
InvestigationSummary.EvidenceOfExecution.ResultThe result of the evidence of execution finding.String
InvestigationSummary.EvidenceOfExecution.SourcesThe sources by which the evidence of execution value was set.String
InvestigationSummary.EvidenceOfLateralMovement.TacticThe tactic associated with the evidence of lateral movement finding.String
InvestigationSummary.EvidenceOfLateralMovement.ResultThe Result of the evidence of lateral movement finding.String
InvestigationSummary.EvidenceOfLateralMovement.SourcesThe sources by which the evidence of lateral movement value was set.String
InvestigationSummary.EvidenceOfPrivilegeEscalation.TacticThe tactic associated with the evidence of privilege escalation finding.String
InvestigationSummary.EvidenceOfPrivilegeEscalation.ResultThe result of the evidence of privilege escalation finding.String
InvestigationSummary.EvidenceOfPrivilegeEscalation.SourcesThe sources by which the evidence of privilege escalation value was set.String
InvestigationSummary.EvidenceOfCommandAndControl.TacticThe tactic associated with the evidence of command and control finding.String
InvestigationSummary.EvidenceOfCommandAndControl.ResultThe result of the evidence of command and control finding.String
InvestigationSummary.EvidenceOfCommandAndControl.SourcesThe sources by which the evidence of command and control value was set.String