RiskIQPassiveTotalSSLScript
PassiveTotal Pack.#
This Script is part of theEnhancement script to enrich SSL information for Email, File SHA-1 and RiskIQSerialNumber type of indicators. It can be set by following these steps:
- Settings > ADVANCED > Indicator Type
- Edit Email, File SHA-1 and RiskIQSerialNumber Indicator one by one
- Add this script into Enhancement Scripts
#
Script DataName | Description |
---|---|
Script Type | python3 |
Tags | enhancement |
Cortex XSOAR Version | 5.0.0 |
#
DependenciesThis script uses the following commands and scripts.
- pt-ssl-cert-search
#
InputsArgument Name | Description |
---|---|
indicator_value | Email, File SHA-1 and RiskIQSerialNumber indicator value that need to enrich |
#
OutputsThere are no outputs for this script.
#
Script Example!RiskIQPassiveTotalSSLScript indicator_value=61135c80f8ed28d2
#
Context Example#
Human Readable Output#
Total Retrieved Record(s): 2#
SSL certificate(s)
Sha1 Serial Number Issued (GMT) Expires (GMT) SSL Version First Seen (GMT) Last Seen (GMT) Issuer Common Name Subject Common Name Subject Alternative Names Issuer Organization Name Subject Organization Name Subject Locality Name Subject State/Province Name Issuer Country Subject Country 8848e868b190d0fdcb6f39c37b5382c87e0976b0 6995036355238373586 Jan 15 13:15:00 2019 GMT Apr 09 13:15:00 2019 GMT 3 2019-01-15 13:40:31 2019-01-16 03:00:34 Google Internet Authority G3 www.google.com www.google.com Google Trust Services Google LLC Mountain View California US US 995b005f44be53bf3e5921901d79a98e54afd329 6995036355238373586 Jan 15 13:15:00 2019 GMT Apr 09 13:15:00 2019 GMT 3 2019-01-25 22:34:01 2019-02-07 20:39:43 Google Internet Authority G3 www.google.com www.google.com Google Trust Services Google LLC Mountain View California US US