Bitdefender Cloud Sandbox
This connector integrates Bitdefender Cloud Sandbox with Turbine.
Capabilities
This connector provides the following capabilities:
- Upload URL
- Upload Files
- Get Result
- Get Report
- Download IOC
Asset Setup
This connector supports the API Key Authentication. API Key is required for the authentication.
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
APIKey | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Download IOC
The Download IOC API to request IOC data regarding the detonation of a file or url.
Endpoint
- URL: /downloads/ioc
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.job_id | string | Required | The ID of the request you wish to get information on. |
parameters.format | string | Required | Specify the format of the response. Possible values (openioc,stix,raw) |
Input Example
{"parameters":{"job_id":"gcp_1698727498_44976851_43de3a417d75f4818c5a553268b80ce3a5805109a3bbc6b605e9fb0b8f50b485","format":"openioc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
netstat | object | Output field: netstat |
netstat.72.21.81.240 | object | Output field: netstat.72.21.81.240 |
netstat.72.21.81.240.tcp | array | Output field: netstat.72.21.81.240.tcp |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 31 Oct 2023 15:12:25 GMT","Content-Type":"application/json","Content-Length":"46","Connection":"keep-alive","Via":"1.1 google","Strict-Transport-Security":"max-age=31536000;","CF-Cache-Status":"DYNAMIC","Server":"cloudflare","CF-RAY":"81ecd60cbf416c03-SIN"},"reason":"OK","json_body":{"netstat":{"72.21.81.240":{}}}}
Get Report
Get report API to generate an extensive report which contains all the details.
Endpoint
- URL: /report
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.job_id | string | Required | Parameters for the Get Report action |
parameters.logos | string | Optional | Parameters for the Get Report action |
parameters.format | string | Optional | Parameters for the Get Report action |
parameters.summary | boolean | Optional | Parameters for the Get Report action |
Input Example
{"parameters":{"job_id":"gcp_1698727498_44976851_43de3a417d75f4818c5a553268b80ce3a5805109a3bbc6b605e9fb0b8f50b485","logos":"main","format":"HTML","summary":false}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 31 Oct 2023 15:16:37 GMT","Content-Type":"text/html; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Via":"1.1 google","Strict-Transport-Security":"max-age=31536000;","CF-Cache-Status":"DYNAMIC","Server":"cloudflare","CF-RAY":"81ecdc33feb6882c-SIN","Content-Encoding":"gzip"},"reason":"OK","response_text":"<!doctype html><html><head><meta content=\"text/html;charset=utf-8\" http-equiv=\"C..."}
Get Result
Get result from API to check the status of a job and get the scan results.
Endpoint
- URL: /result
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.job_id | string | Required | The ID of the job you wish to get information on. |
Input Example
{"parameters":{"job_id":"gcp_1698727498_44976851_43de3a417d75f4818c5a553268b80ce3a5805109a3bbc6b605e9fb0b8f50b485"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
verdict | string | Output field: verdict |
reason_details | string | Response reason phrase |
processing_duration_in_seconds | number | Output field: processing_duration_in_seconds |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 31 Oct 2023 09:46:29 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Via":"1.1 google","Strict-Transport-Security":"max-age=31536000;","CF-Cache-Status":"DYNAMIC","Server":"cloudflare","CF-RAY":"81eaf8991d7d4afe-HYD","Content-Encoding":"gzip"},"reason":"OK","json_body":{"status":"done","verdict":"clean","reason":"not_malicious","reason_details":"No malicious activity has been observed during execu...
Upload Files
Upload files API to submit files to the Bitdefender Sandbox Service.
Endpoint
- URL: /upload
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.archive.password | string | Optional | Parameters for the Upload Files action |
parameters.file.tlp | string | Optional | Parameters for the Upload Files action |
parameters.prefilter | string | Optional | Parameters for the Upload Files action |
parameters.force_detonation | boolean | Optional | Parameters for the Upload Files action |
form_data | object | Required | Response data |
form_data.upload_file | object | Required | File to be uploaded. |
form_data.upload_file.file | string | Required | Response data |
form_data.upload_file.file_name | string | Required | Response data |
Input Example
{"parameters":{"archive.password":"achive password","file.tlp":"AMBER","prefilter":"all","force_detonation":false}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 31 Oct 2023 15:12:25 GMT","Content-Type":"application/json","Content-Length":"46","Connection":"keep-alive","Via":"1.1 google","Strict-Transport-Security":"max-age=31536000;","CF-Cache-Status":"DYNAMIC","Server":"cloudflare","CF-RAY":"81ecd60cbf416c03-SIN"},"reason":"OK","json_body":{"success":true}}
Upload URL
The URL API to submit a URL for investigation.
Endpoint
- URL: /url
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.engine.urlstatus | string | Optional | Parameters for the Upload URL action |
url_to_scan | string | Optional | URL endpoint for the request |
Input Example
{"parameters":{"engine.urlstatus":"except_original"},"json_body":{"url_to_scan":"1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
job_id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 31 Oct 2023 15:01:31 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Via":"1.1 google","Strict-Transport-Security":"max-age=31536000;","CF-Cache-Status":"DYNAMIC","Server":"cloudflare","CF-RAY":"81ecc613ef7b8519-BOM","Content-Encoding":"gzip"},"reason":"OK","json_body":{"status":"submitted","job_id":"gcp_1698764491_45170024_833290316ff9f3ed1eca768bebd606c10124e191c50c73056f9b7adb..."}}
Response Headers
Header | Description | Example |
|---|---|---|
CF-Cache-Status | HTTP response header: CF-Cache-Status | DYNAMIC |
CF-RAY | HTTP response header: CF-RAY | 81ecc613ef7b8519-BOM |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Length | The length of the response body in bytes | 46 |
Content-Type | The media type of the resource | text/html; charset=utf-8 |
Date | The date and time at which the message was originated | Tue, 31 Oct 2023 15:12:25 GMT |
Server | Information about the software used by the origin server | cloudflare |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Via | HTTP response header: Via | 1.1 google |