CrowdStrike Falcon Hybrid Analysis
The CrowdStrike Falcon Hybrid Analysis connector facilitates the submission and analysis of threats, offering detailed reports and threat intelligence directly within the integrated platform.
CrowdStrike Falcon Hybrid Analysis is a cutting-edge platform for comprehensive threat intelligence and malware analysis. This connector enables Swimlane Turbine users to automate the retrieval of detailed threat information, such as hash overviews, report states, and submission summaries. By integrating with CrowdStrike Falcon Hybrid Analysis, users can enhance their security automation workflows, rapidly assess potential threats, and streamline the threat investigation process. The connector's actions facilitate the submission of URLs for analysis and the search for specific terms or hashes, providing actionable insights and enabling proactive defense strategies.
Prerequisites
To effectively utilize the CrowdStrike Falcon Hybrid Analysis connector, ensure you have the following prerequisites:
- API Key Authentication:
- URL: The endpoint URL for the CrowdStrike Falcon Hybrid Analysis API.
- API Key: A valid API key provided by CrowdStrike to authenticate requests.
Capabilities
The CrowdStrike Falcon Hybrid Analysis bundle has the following capabilities:
- Search for Hash
- Get Hash Overview
- Submit File
- Get Status of Submission
- Get Report
- Perform Quick Scan of file
- Search for terms such as IPs, Domains, or URLs
Notes
For more information about the API and its capabilities:
This plugin was last tested against product version: v2 API
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
api-key | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Hash Overview
Retrieve a comprehensive overview for a specified SHA256 hash using CrowdStrike Falcon Hybrid Analysis, requiring the sha256 path parameter.
Endpoint
- URL: overview/{{sha256}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sha256 | string | Required | Parameters for the Hash Overview action |
Input Example
{"path_parameters":{"sha256":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
sha256 | string | Output field: sha256 |
last_file_name | string | Name of the resource |
other_file_name | array | Name of the resource |
threat_score | object | Score value |
verdict | string | Output field: verdict |
url_analysis | boolean | URL endpoint for the request |
size | number | Output field: size |
type | string | Type of the resource |
type_short | array | Type of the resource |
analysis_start_time | string | Time value |
last_multi_scan | string | Output field: last_multi_scan |
tags | array | Output field: tags |
tags.file_name | string | Name of the resource |
tags.file | string | Output field: tags.file |
architecture | object | Output field: architecture |
multiscan_result | number | Result of the operation |
scanners | array | Output field: scanners |
scanners.name | string | Name of the resource |
scanners.status | string | Status value |
scanners.error_message | object | Response message |
scanners.progress | number | Output field: scanners.progress |
scanners.total | number | Output field: scanners.total |
scanners.positives | number | Output field: scanners.positives |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 08 Nov 2022 15:29:19 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Api-Limits":"{\"limits\":{\"minute\":200,\"hour\":2000},\"used\":{\"minute\":2,\"hour\":4},\"limit_reached...","Api-Version":"2.20.0","Webservice-Version":"16.2.2-60346862a","Cache-Control":"no-cache, no-store, must-revalidate","Pragma":"no-cache","Expires":"Wed, 11 Jan 1984 05:00:00 GMT","X-Content-Type-Options":"nosniff","Conte...
Report State
Retrieve the current state of a specific submission in CrowdStrike Falcon Hybrid Analysis using the provided submission ID.
Endpoint
- URL: report/{{id}}/state
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Report State action |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
state | string | Output field: state |
error_type | string | Type of the resource |
error_origin | string | Error message if any |
error | string | Error message if any |
related_reports | array | Output field: related_reports |
related_reports.file_name | string | Name of the resource |
related_reports.file | string | Output field: related_reports.file |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 08 Nov 2022 16:06:17 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Api-Limits":"{\"limits\":{\"minute\":200,\"hour\":2000},\"used\":{\"minute\":1,\"hour\":7},\"limit_reached...","Api-Version":"2.20.0","Webservice-Version":"16.2.2-60346862a","Cache-Control":"no-cache, no-store, must-revalidate","Pragma":"no-cache","Expires":"Wed, 11 Jan 1984 05:00:00 GMT","X-Content-Type-Options":"nosniff","Conte...
Report Summary
Retrieve a concise summary of a submission in CrowdStrike Falcon Hybrid Analysis using the provided submission ID.
Endpoint
- URL: report/{{id}}/summary
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Report Summary action |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
classification_tags | array | Output field: classification_tags |
classification_tags.file_name | string | Name of the resource |
classification_tags.file | string | Output field: classification_tags.file |
tags | array | Output field: tags |
submissions | array | Output field: submissions |
submissions.submission_id | string | Unique identifier |
submissions.filename | object | Name of the resource |
submissions.url | string | URL endpoint for the request |
submissions.created_at | string | Output field: submissions.created_at |
machine_learning_models | array | Output field: machine_learning_models |
machine_learning_models.file_name | string | Name of the resource |
machine_learning_models.file | string | Output field: machine_learning_models.file |
job_id | string | Unique identifier |
environment_id | number | Unique identifier |
environment_description | string | Output field: environment_description |
size | object | Output field: size |
type | object | Type of the resource |
type_short | array | Type of the resource |
type_short.file_name | string | Name of the resource |
type_short.file | string | Type of the resource |
target_url | object | URL endpoint for the request |
state | string | Output field: state |
error_type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 08 Nov 2022 16:10:44 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Api-Limits":"{\"limits\":{\"minute\":200,\"hour\":2000},\"used\":{\"minute\":1,\"hour\":8},\"limit_reached...","Api-Version":"2.20.0","Webservice-Version":"16.2.2-60346862a","Cache-Control":"no-cache, no-store, must-revalidate","Pragma":"no-cache","Expires":"Wed, 11 Jan 1984 05:00:00 GMT","X-Content-Type-Options":"nosniff","Conte...
Search Hash
Locate a specific hash in CrowdStrike Falcon Hybrid Analysis to assess potential threats. Requires a hash parameter.
Endpoint
- URL: search/hash
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.hash | string | Required | Parameters for the Search Hash action |
Input Example
{"parameters":{"hash":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
sha256s | array | Output field: sha256s |
reports | array | Output field: reports |
reports.id | string | Unique identifier |
reports.environment_id | number | Unique identifier |
reports.environment_description | string | Output field: reports.environment_description |
reports.state | string | Output field: reports.state |
reports.error_type | string | Type of the resource |
reports.error_origin | string | Error message if any |
reports.verdict | string | Output field: reports.verdict |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 08 Nov 2022 15:57:49 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Api-Limits":"{\"limits\":{\"minute\":200,\"hour\":2000},\"used\":{\"minute\":1,\"hour\":6},\"limit_reached...","Api-Version":"2.20.0","Webservice-Version":"16.2.2-60346862a","Cache-Control":"no-cache, no-store, must-revalidate","Pragma":"no-cache","Expires":"Wed, 11 Jan 1984 05:00:00 GMT","X-Content-Type-Options":"nosniff","Conte...
Search Terms
Retrieve relevant data from CrowdStrike Falcon Hybrid Analysis by using specified search terms.
Endpoint
- URL: search/terms
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Data Body |
data_body.filename | string | Optional | Response data |
data_body.filetype | string | Optional | Response data |
data_body.filetype_desc | string | Optional | Response data |
data_body.env_id | string | Optional | Response data |
data_body.country | string | Optional | Response data |
data_body.verdict | number | Optional | Response data |
data_body.av_detect | string | Optional | Response data |
data_body.vx_family | string | Optional | Response data |
data_body.tag | string | Optional | Response data |
data_body.date_from | string | Optional | Response data |
data_body.date_to | string | Optional | Response data |
data_body.port | number | Optional | Response data |
data_body.host | string | Optional | Response data |
data_body.domain | string | Optional | Response data |
data_body.url | string | Optional | Response data |
data_body.similar_to | string | Optional | Response data |
data_body.context | string | Optional | Response data |
data_body.imp_hash | string | Optional | Response data |
data_body.ssdeep | string | Optional | Response data |
data_body.autentihash | string | Optional | Response data |
data_body.uses_tactic | string | Optional | Response data |
data_body.uses_technique | string | Optional | Response data |
Input Example
{"data_body":{"filename":"Example Name","filetype":"string","filetype_desc":"string","env_id":"string","country":"string","verdict":123,"av_detect":"string","vx_family":"string","tag":"string","date_from":"string","date_to":"string","port":123,"host":"string","domain":"string","url":"https://example.com/api/resource","similar_to":"string","context":"string","imp_hash":"string","ssdeep":"string","autentihash":"string","uses_tactic":"string","uses_technique":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
search_terms | array | Output field: search_terms |
search_terms.id | string | Unique identifier |
search_terms.value | string | Value for the parameter |
count | number | Count value |
result | array | Result of the operation |
result.verdict | string | Result of the operation |
result.av_detect | string | Result of the operation |
result.threat_score | object | Result of the operation |
result.vx_family | object | Result of the operation |
result.job_id | string | Unique identifier |
result.sha256 | string | Result of the operation |
result.environment_id | object | Unique identifier |
result.analysis_start_time | string | Result of the operation |
result.submit_name | string | Name of the resource |
result.environment_description | string | Result of the operation |
result.size | number | Result of the operation |
result.type | object | Type of the resource |
result.type_short | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 08 Nov 2022 16:59:53 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Api-Limits":"{\"limits\":{\"minute\":200,\"hour\":2000},\"used\":{\"minute\":1,\"hour\":3},\"limit_reached...","Api-Version":"2.20.0","Webservice-Version":"16.2.2-60346862a","Cache-Control":"no-cache, no-store, must-revalidate","Pragma":"no-cache","Expires":"Wed, 11 Jan 1984 05:00:00 GMT","X-Content-Type-Options":"nosniff","Conte...
Submit URL
Submit a URL to CrowdStrike Falcon Hybrid Analysis for detailed threat analysis, requiring a data body input.
Endpoint
- URL: submit/url
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Data Body |
data_body.url | string | Required | Response data |
data_body.environment_id | number | Required | Response data |
data_body.no_share_third_party | boolean | Optional | Response data |
data_body.allow_community_access | boolean | Optional | Response data |
data_body.no_hash_lookup | boolean | Optional | Response data |
data_body.action_script | string | Optional | Response data |
data_body.hybrid_analysis | boolean | Optional | Response data |
data_body.experimental_anti_evasion | boolean | Optional | Set all experimental anti-evasion options of the Kernelmode Monitor. |
data_body.script_logging | boolean | Optional | Set the in-depth script logging engine of the Kernelmode Monitor |
data_body.input_sample_tampering | boolean | Optional | When set to 'true', will allow experimental anti-evasion options of the Kernelmode Monitor that tamper with the input sample. |
data_body.tor_enabled_analysis | boolean | Optional | When set to 'true', will route the network traffic for the analysis via TOR (if properly configured on the server). |
data_body.network_settings | string | Optional | Network settings, by the default, fully operating network is set. |
data_body.email | string | Optional | Optional E-Mail address that may be associated with the submission for notification |
data_body.comment | string | Optional | Optional comment text that may be associated with the submission/sample (Note, you can use #tags here) |
data_body.custom_date_time | string | Optional | Optional custom date/time that can be set for the analysis system. Expected format is yyyy-MM-dd HH:mm |
data_body.custom_cmd_line | string | Optional | Optional commandline that should be passed to the analysis file |
data_body.custom_run_time | integer | Optional | Optional runtime duration (in seconds) |
data_body.submit_name | string | Optional | Optional 'submission name' field that will be used for file type detection and analysis. Ignored unless url contains a file |
data_body.priority | integer | Optional | Optional priority value between 1 (lowest) and 10 (highest), by default all samples run with highest priority |
data_body.document_password | string | Optional | Optional document password that will be used to fill-in Adobe/Office password prompts. Ignored unless url contains a file |
data_body.environment_variable | string | Optional | Optional system environment value. The value is provided in the format name=value |
Input Example
{"data_body":{"url":"https://example.com/api/resource","environment_id":123,"no_share_third_party":true,"allow_community_access":true,"no_hash_lookup":true,"action_script":"string","hybrid_analysis":true,"experimental_anti_evasion":true,"script_logging":true,"input_sample_tampering":true,"tor_enabled_analysis":true,"network_settings":"default","email":"[email protected]","comment":"string","custom_date_time":"string","custom_cmd_line":"string","custom_run_time":123,"submit_name":"Example Name","priority":123,"document_password":"string","environment_variable":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
submission_type | string | Type of the resource |
job_id | string | Unique identifier |
submission_id | string | Unique identifier |
environment_id | number | Unique identifier |
sha256 | string | Output field: sha256 |
Output Example
{"status_code":201,"response_headers":{"Date":"Tue, 08 Nov 2022 21:51:03 GMT","Content-Type":"application/json","Content-Length":"206","Connection":"keep-alive","Api-Limits":"{\"limits\":{\"minute\":200,\"hour\":2000},\"used\":{\"minute\":2,\"hour\":2},\"limit_reached...","Api-Version":"2.20.0","Webservice-Version":"16.2.2-60346862a","Submission-Limits":"{\"apikey\":{\"quota\":{\"day\":100},\"used\":{\"day\":1},\"available\":{\"day\":99},\"quota_re...","Cache-Control":"no-cache, no-store, must-r...
Response Headers
Header | Description | Example |
|---|---|---|
Api-Limits | HTTP response header: Api-Limits | {"limits":{"minute":200,"hour":2000},"used":{"minute":1,"hour":8},"limit_reached":false} |
Api-Version | HTTP response header: Api-Version | 2.20.0 |
Cache-Control | Directives for caching mechanisms | no-cache, no-store, must-revalidate |
CF-Cache-Status | HTTP response header: CF-Cache-Status | DYNAMIC |
CF-RAY | HTTP response header: CF-RAY | 767187106946a793-EZE |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Length | The length of the response body in bytes | 206 |
Content-Security-Policy | HTTP response header: Content-Security-Policy | default-src 'none'; connect-src 'self' *.twitter.com; script-src 'self' *.google.com *.gstatic.com *.google-analytics.com *.twitter.com *.twimg.com cdn.inspectlet.com frontend.id-visitors.com 'unsafe-inline'; font-src 'self' data: fonts.googleapis.com; child-src 'self' data: *.google.com *.gstatic.com *.twitter.com; img-src 'self' data: *.gstatic.com *.google.com *.google-analytics.com stats.g.doubleclick.net *.twitter.com *.twimg.com *.paypalobjects.com cartodb-basemaps-a.global.ssl.fastly.net cartodb-basemaps-b.global.ssl.fastly.net cartodb-basemaps-c.global.ssl.fastly.net; style-src 'self' *.google.com *.twitter.com *.twimg.com 'unsafe-inline'; object-src 'self'; frame-ancestors 'none' |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Tue, 08 Nov 2022 16:59:53 GMT |
Expires | The date/time after which the response is considered stale | Wed, 11 Jan 1984 05:00:00 GMT |
Pragma | HTTP response header: Pragma | no-cache |
Server | Information about the software used by the origin server | cloudflare |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; includeSubdomains |
Submission-Limits | HTTP response header: Submission-Limits | {"apikey":{"quota":{"day":100},"used":{"day":1},"available":{"day":99},"quota_reached":false},"quota_reached":false} |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Webservice-Version | HTTP response header: Webservice-Version | 16.2.2-60346862a |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
x-frame-options | HTTP response header: x-frame-options | SAMEORIGIN, SAMEORIGIN |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 1; mode=block |