Lastline Analyst
The Lastline Analyst connector enables automated malware analysis and threat intelligence gathering directly within security workflows.
Lastline Analyst is a renowned platform for advanced malware analysis, providing detailed insights into emerging threats. The Lastline Analyst Connector for Swimlane Turbine enables users to automate the creation of Indicators of Compromise (IOCs), retrieve IOC metadata, analyze files and URLs, and track detailed analysis results. This integration empowers security teams to enhance their threat detection and response capabilities, streamline analysis workflows, and rapidly identify and mitigate potential security risks within their digital environment.
Prerequisites
To effectively utilize the Lastline Analyst connector with Turbine, ensure you have the following prerequisites:
- HTTP Basic Authentication with these parameters:
- URL: The endpoint URL for the Lastline Analyst API.
- API Key: Your unique API key provided by Lastline Analyst for authentication.
- API Token: A token paired with your API key to establish a secure connection.
Capabilities
The VMWare Lastline Analyst connector has the following capabilities:
- Submit URL
- Submit File
- Get URL Results
- Get File Results
- Get IOC
- Create IOC
Configurations
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | API Key | string | Required |
password | API Token | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create IOC From Result
Generates an Indicator of Compromise (IOC) from a specified result using the provided data body in Lastline Analyst.
Endpoint
- URL: /analysis/ioc/create_ioc_from_result
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.uuid | string | Required | Response data |
data_body.report_uuid | string | Required | Response data |
data_body.report_version | string | Required | Response data |
Input Example
{"data_body":{"uuid":"uuid","report_uuid":"report_uuid","report_version":"report_version"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | number | Whether the operation was successful |
error_code | number | Error message if any |
error | string | Error message if any |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 20 Jun 2023 17:12:33 GMT","Content-Type":"application/json; charset=utf-8","Content-Length":"65","Strict-Transport-Security":"max-age=15724800; includeSubDomains","Server":"ingress-nginx","Via":"1.1 google","Alt-Svc":"h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000"},"reason":"OK","json_body":{"success":0,"error_code":122,"error":"Missing Credentials"}}
Get IOC Metadata
Retrieve metadata for a specified Indicator of Compromise (IOC) in Lastline Analyst using the unique IOC UUID.
Endpoint
- URL: analysis/ioc/get_ioc_metadata
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ioc_uuid | string | Required | Parameters for the Get IOC Metadata action |
Input Example
{"parameters":{"ioc_uuid":"ca46fd1072644e7cb1ff0b1633c6b537"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | number | Whether the operation was successful |
error_code | number | Error message if any |
error | string | Error message if any |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 20 Jun 2023 15:12:14 GMT","Content-Type":"application/json; charset=utf-8","Content-Length":"65","Strict-Transport-Security":"max-age=15724800; includeSubDomains","Server":"ingress-nginx","Via":"1.1 google","Alt-Svc":"h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000"},"reason":"OK","json_body":{"success":0,"error_code":122,"error":"Missing Credentials"}}
Get Results
Retrieve detailed analysis results from Lastline Analyst using the provided unique identifier (UUID).
Endpoint
- URL: /analysis/get
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.uuid | string | Required | Parameters for the Get Results action |
Input Example
{"parameters":{"uuid":"ca46fd1072644e7cb1ff0b1633c6b537"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | number | Whether the operation was successful |
error_code | number | Error message if any |
error | string | Error message if any |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 20 Jun 2023 18:24:24 GMT","Content-Type":"application/json; charset=utf-8","Content-Length":"65","Strict-Transport-Security":"max-age=15724800; includeSubDomains","Server":"ingress-nginx","Via":"1.1 google","Alt-Svc":"h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000"},"reason":"OK","json_body":{"success":0,"error_code":122,"error":"Missing Credentials"}}
Submit File
Submits a file to Lastline Analyst for analysis, providing a unique identifier for submission tracking.
Endpoint
- URL: /analysis/submit/file
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.md5 | string | Optional | Response data |
data_body.sha1 | string | Optional | Response data |
data_body.sha256 | string | Optional | Response data |
Input Example
{"data_body":{"md5":"ca46fd1072644e7cb1ff0b1633c6b537","sha1":"ca46fd1072644e7cb1ff0b1633c6b537","sha256":"ca46fd1072644e7cb1ff0b1633c6b537"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | number | Whether the operation was successful |
error_code | number | Error message if any |
error | string | Error message if any |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 20 Jun 2023 20:40:17 GMT","Content-Type":"application/json; charset=utf-8","Content-Length":"65","Strict-Transport-Security":"max-age=15724800; includeSubDomains","Server":"ingress-nginx","Via":"1.1 google","Alt-Svc":"h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000"},"reason":"OK","json_body":{"success":0,"error_code":122,"error":"Missing Credentials"}}
Submit URL
Submit a URL to Lastline Analyst for threat analysis and obtain a comprehensive report on detected security risks.
Endpoint
- URL: /analysis/submit/url
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.url | string | Required | Response data |
Input Example
{"data_body":{"url":"https://www.google.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | number | Whether the operation was successful |
error_code | number | Error message if any |
error | string | Error message if any |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 20 Jun 2023 17:53:14 GMT","Content-Type":"application/json; charset=utf-8","Content-Length":"65","Strict-Transport-Security":"max-age=15724800; includeSubDomains","Server":"ingress-nginx","Via":"1.1 google","Alt-Svc":"h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000"},"reason":"OK","json_body":{"success":0,"error_code":122,"error":"Missing Credentials"}}
Response Headers
Header | Description | Example |
|---|---|---|
Alt-Svc | HTTP response header: Alt-Svc | h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 |
Content-Length | The length of the response body in bytes | 65 |
Content-Type | The media type of the resource | application/json; charset=utf-8 |
Date | The date and time at which the message was originated | Tue, 20 Jun 2023 17:12:33 GMT |
Server | Information about the software used by the origin server | ingress-nginx |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=15724800; includeSubDomains |
Via | HTTP response header: Via | 1.1 google |