Recorded Future Sandbox
The Recorded Future Sandbox connector enables automated interactions with Recorded Future's malware analysis platform, facilitating the submission and examination of samples, and management of YARA rules.
The Recorded Future Sandbox Connector enables Swimlane Turbine users to automate the analysis and management of malware samples and YARA rules. By integrating with Recorded Future Sandbox, security professionals can create, update, and delete YARA rules, submit samples for analysis, and retrieve comprehensive reports and PCAPs. This integration enhances threat detection and response by providing actionable insights and streamlining the investigation process within the Swimlane Turbine platform.
This Connector integrates Recorded Future Sandbox API with Swimlane Turbine.
Prerequisites
To effectively utilize the Recorded Future Sandbox connector within Swimlane Turbine, ensure you have the following prerequisites:
- HTTP Bearer Authentication with the following parameters:
- URL: Endpoint for Recorded Future Sandbox API access.
- API Token: Unique token for authenticating API requests.
- OAuth 2.0 Client Credentials with the following parameters:
- URL: Endpoint for Recorded Future Sandbox API access.
- Client ID: Identifier for the OAuth client.
- Client Secret: Secret key associated with the OAuth client.
- Token URL: Endpoint for obtaining OAuth 2.0 access tokens.
Capabilities
This connector provides the following capabilities:
- Create a New Yara Rule
- Delete an Existing Yara Rule
- Download Sample
- Get All Resources
- Get All Yara Rules
- Get PCAP of Analysis
- Get Sample by Sample ID
- Get Sample Overview
- Get Samples
- Get Search Samples
- Get Summary by Sample ID
- Post Samples
- Select Profile
- Update an Existing Yara Rule
Use cases
Update an Existing Yara Rule
- When updating a yara rule the compilation can fail. If that is the case the rule name is updated, but the old rule content will remain.
- Both name and rule are always required to be filled, even when changing only one of the attributes.
Notes
- For more information on Authentication, see the link - Recorded Future Sandbox API Authentication Link)
- If you need any further details please visit the Recorded Future Sandbox Support facility - [https://support.recordedfuture.com/hc/en-us]
Configurations
Recorded Future Sandbox Bearer Auth
Authenticates using API Token.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The API key, token, etc. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Recorded Future Sandbox Oauth 2.0 Auth
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | ο»Ώ | string | Required |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create a New Yara Rule
Generates a new YARA rule in Recorded Future Sandbox using the provided data body.
Endpoint
- URL: /api/v0/yara
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.name | string | Required | Response data |
data_body.rule | string | Required | Response data |
Input Example
{"data_body":{"name":"arkei.yara","rule":"rule family_arkei {\n meta:\n author = \"Nikos '\"n0t'\" Totosis\"\n description = \"Arkei Stealer Payload\"\n triage_family = \"arkei\"\n triage_tags = \"stealer\"\n\n strings:\n $c1 = \"/c timeout /t 5 & del /f /q \\\"%s\\\" & exit\" ascii\n $c2 = \"BCDEFGHIJKLMNOPQRSTUVWXYZ1234567890\" ascii\n\n $s1 = \"%dx%d\" ascii\n $s2 = \"%d/%d/%d %d:%d:%d\" ascii\n $s3 = \"%s / %s\" ascii\n $s4 = \"%d MB\" ascii\n $s5 = \"UTC%d\" ascii\n $s6 = \"JohnDoe\" ascii\n $s7 = \"HAL9TH\" ascii\n\n condition:\n 1 of ($c*) and 4 of ($s*)\n}"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Delete an Existing Yara Rule
Removes a specified YARA rule from Recorded Future Sandbox by providing the rule name.
Endpoint
- URL: /api/v0/yara/{{rule_name}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.rule_name | string | Required | Parameters for the Delete an Existing Yara Rule action |
Input Example
{"path_parameters":{"rule_name":"arkei.yara"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Get All Resources
Retrieve a list of all available resources from Recorded Future Sandbox.
Endpoint
- URL: /api/v0/resources
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Get All Yara Rules
Retrieve a list of all YARA rules available to the user in Recorded Future Sandbox.
Endpoint
- URL: /api/v0/yara
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
rules | array | Output field: rules |
rules.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"rules":[{},{}]}}
Download Sample
Downloads the original file submission from Recorded Future Sandbox using the sampleID. Ensure the file has completed processing before downloading.
Endpoint
- URL: /api/v0/samples/{{sampleID}}/sample
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sampleID | string | Required | Sample ID returned at submission (e.g., 251219-tg9s9sfwst). |
Input Example
{"path_parameters":{"sampleID":"251219-tg9s9sfwst"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
body | string | Raw binary content of the originally submitted file. |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/octet-stream"},"reason":"OK"}
Get PCAP of Analysis
Retrieves the packet capture (PCAP) of a specified analysis from Recorded Future Sandbox using sampleID and taskID.
Endpoint
- URL: /api/v0/samples/{{sampleID}}/{{taskID}}/dump.pcap
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sampleID | string | Required | Parameters for the Get PCAP of Analysis action |
path_parameters.taskID | string | Required | Parameters for the Get PCAP of Analysis action |
Input Example
{"path_parameters":{"sampleID":"190724-hakvlwz8cx","taskID":"25507"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Get Sample by ID
Retrieves detailed information for a specific sample by its ID in Recorded Future Sandbox.
Endpoint
- URL: /api/v0/samples/{{sampleID}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sampleID | string | Required | Parameters for the Get Sample by ID action |
Input Example
{"path_parameters":{"sampleID":"190724-hakvlwz8cx"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
status | string | Status value |
kind | string | Output field: kind |
filename | string | Name of the resource |
private | boolean | Output field: private |
submitted | string | Output field: submitted |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"id":"190724-hakvlwz8cx","status":"reported","kind":"file","filename":"evil.bat","private":true,"submitted":"2019-07-24T13:32:07.253524Z"}}
Get Sample Overview
Retrieve a detailed report on a malware sample from Recorded Future Sandbox, including IOCs and MITRE ATT&CK mappings, using the sampleID.
Endpoint
- URL: /api/v0/samples/{{sampleID}}/overview.json
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sampleID | string | Required | Sample ID returned at submission (e.g., 251219-tg9s9sfwst). |
Input Example
{"path_parameters":{"sampleID":"251219-tg9s9sfwst"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Report format version (e.g., 0.2.2) |
sample | object | Sample metadata and file hashes. |
analysis | object | High-level analysis results (score 0-10, family, tags). |
signatures | array | Triggered behavioral and YARA signatures with MITRE ttp. |
targets | array | Per-target analysis results with IOCs. |
extracted | array | Extracted malware configs, C2, ransom notes. |
tasks | object | Analysis tasks keyed by composite ID. |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/json"},"reason":"OK","json_body":{"version":"0.2.2","sample":{"id":"251219-tg9s9sfwst","score":8,"sha256":"05af0cf40590aef24b28fa04c6b4998b7ab3b7f26e60c507adb84f3d837778f2"},"analysis":{"score":8,"family":[],"tags":[]},"signatures":[],"targets":[],"extracted":[],"tasks":{}}}
Get Samples
Retrieve a list of samples submitted by the requester from Recorded Future Sandbox.
Endpoint
- URL: /api/v0/samples
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.subset | string | Optional | Parameters for the Get Samples action |
Input Example
{"parameters":{"subset":"owned"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Get Search Samples
Retrieve analyses for IOCs or file characteristics using filters and queries similar to the Recorded Future Sandbox web interface.
Endpoint
- URL: /api/v0/search
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Required | Parameters for the Get Search Samples action |
Input Example
{"parameters":{"query":"family:emotet"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | string | Response data |
data.status | string | Response data |
data.kind | string | Response data |
data.filename | string | Response data |
data.private | boolean | Response data |
data.submitted | string | Response data |
data.completed | string | Response data |
next | string | Output field: next |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"data":[{}],"next":"2020-10-26T16:51:21.232458Z"}}
Get Summary by Sample ID
Retrieve a concise summary and analysis tasks for a given sample using its unique ID in Recorded Future Sandbox.
Endpoint
- URL: /api/v0/samples/{{sampleID}}/summary
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sampleID | string | Required | Parameters for the Get Summary by Sample ID action |
Input Example
{"path_parameters":{"sampleID":"190724-hakvlwz8cx"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
sample | string | Output field: sample |
status | string | Status value |
custom | string | Output field: custom |
owner | string | Output field: owner |
target | string | Output field: target |
created | string | Output field: created |
completed | string | Output field: completed |
score | number | Score value |
sha256 | string | Output field: sha256 |
tasks | object | Output field: tasks |
tasks.200606-l5dz9871we-behavioral1 | object | Output field: tasks.200606-l5dz9871we-behavioral1 |
tasks.200606-l5dz9871we-behavioral1.kind | string | Output field: tasks.200606-l5dz9871we-behavioral1.kind |
tasks.200606-l5dz9871we-behavioral1.status | string | Status value |
tasks.200606-l5dz9871we-behavioral1.tags | array | Output field: tasks.200606-l5dz9871we-behavioral1.tags |
tasks.200606-l5dz9871we-behavioral1.score | number | Score value |
tasks.200606-l5dz9871we-behavioral1.target | string | Output field: tasks.200606-l5dz9871we-behavioral1.target |
tasks.200606-l5dz9871we-behavioral1.backend | string | Output field: tasks.200606-l5dz9871we-behavioral1.backend |
tasks.200606-l5dz9871we-behavioral1.resource | string | Output field: tasks.200606-l5dz9871we-behavioral1.resource |
tasks.200606-l5dz9871we-behavioral1.platform | string | Output field: tasks.200606-l5dz9871we-behavioral1.platform |
tasks.200606-l5dz9871we-behavioral1.queue_id | number | Unique identifier |
tasks.200606-l5dz9871we-behavioral2 | object | Output field: tasks.200606-l5dz9871we-behavioral2 |
tasks.200606-l5dz9871we-behavioral2.kind | string | Output field: tasks.200606-l5dz9871we-behavioral2.kind |
tasks.200606-l5dz9871we-behavioral2.status | string | Status value |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"sample":"200606-l5dz9871we","status":"reported","custom":"frontend:7de1d1a3-f39b-4dd6-8a8d-b9d6bc0e7c81","owner":"shark2.ams5.hatching.io","target":"05af0cf40590aef24b28fa04c6b4998b7ab3b7f26e60c507adb84f3d837778f2","created":"2020-06-06T00:03:27Z","completed":"2020-06-06T00:06:10Z","score":10,"sha256":"05af0cf40590aef24b28fa04c6b4998b...
Post Samples
Submits a new sample (file or URL) for analysis in Recorded Future Sandbox by specifying the 'kind' field.
Endpoint
- URL: /api/v0/samples
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
form_data | object | Optional | Response data |
form_data.file | array | Optional | The file to upload. |
form_data.file.file | string | Optional | Response data |
form_data.file.file_name | string | Optional | Response data |
kind | string | Optional | One of "file", "url" or "fetch". |
interactive | boolean | Optional | If set to true, the analysis profile must be chosen manually after static analysis has finished. |
password | string | Optional | A password that may be used to decrypt the provided file, usually an archive (zip/rar/etc). |
profiles | array | Optional | A mapping of one or more files to one or more profiles. |
url | string | Optional | The URL to use as sample. Requires kind to be set to "url" or "fetch". |
Input Example
{"form_data":{"file":[{"file":"","file_name":"sample.txt"}],"kind":"file","interactive":false,"password":"password","profiles":["profile"],"url":"http://example.org/"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
status | string | Status value |
kind | string | Output field: kind |
filename | string | Name of the resource |
private | boolean | Output field: private |
submitted | string | Output field: submitted |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"id":"190724-hakvlwz8cx","status":"running","kind":"file","filename":"evil.bat","private":true,"submitted":"2019-07-24T13:32:07.253524Z"}}
Select Profile
Selects an analysis profile for a sample in static_analysis within Recorded Future Sandbox, using one of: auto, pick, or profiles.
Endpoint
- URL: /api/v0/samples/{{sampleID}}/profile
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.sampleID | string | Required | Sample ID returned at submission (e.g., 251219-tg9s9sfwst). |
auto | boolean | Optional | If true, automatically select profiles for all files. |
pick | array | Optional | For archives; list of filenames to run with automatic profile selection. |
profiles | array | Optional | Explicit file-to-profile mappings. |
profiles.pick | string | Optional | Filename within the archive (or 'sample' for the submitted file). |
profiles.profile | string | Optional | Profile ID or name to use for this file. |
Input Example
{"path_parameters":{"sampleID":"251219-tg9s9sfwst"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-type":"application/json"},"reason":"OK","json_body":{}}
Update an Existing Yara Rule
Updates a specified YARA rule in Recorded Future Sandbox using the provided rule name and data body.
Endpoint
- URL: /api/v0/yara/{{rule_name}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.rule_name | string | Required | Specify the current rule name in the query |
data_body | object | Required | Response data |
data_body.name | string | Required | Response data |
data_body.rule | string | Required | Response data |
Input Example
{"path_parameters":{"rule_name":"arkei.yara"},"data_body":{"name":"arkei_new.yara","rule":"rule family_arkei {\n meta:\n author = \"Nikos 'n0t' Totosis\"\n description = \"Arkei Stealer Payload\"\n triage_family = \"arkei\"\n triage_tags = \"stealer\"\n\n strings:\n $c1 = \"/c timeout /t 5 & del /f /q \\\"%s\\\" & exit\" ascii\n $c2 = \"BCDEFGHIJKLMNOPQRSTUVWXYZ1234567890\" ascii\n\n $s1 = \"%dx%d\" ascii\n $s2 = \"%d/%d/%d %d:%d:%d\" ascii\n $s3 = \"%s / %s\" ascii\n $s4 = \"%d MB\" ascii\n $s5 = \"UTC%d\" ascii\n $s6 = \"JohnDoe\" ascii\n $s7 = \"HAL9TH\" ascii\n\n condition:\n 1 of ($c*) and 4 of ($s*)\n}"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 13 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Response Headers
Header | Description | Example |
|---|---|---|
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/octet-stream |
Date | The date and time at which the message was originated | Wed, 13 Dec 2023 20:37:23 GMT |