Skip to content

Instantly share code, notes, and snippets.

@mbrownnycnyc
Created June 24, 2020 19:05
Show Gist options
  • Save mbrownnycnyc/a867da75e5950ef01852b1f84f07c95a to your computer and use it in GitHub Desktop.
Save mbrownnycnyc/a867da75e5950ef01852b1f84f07c95a to your computer and use it in GitHub Desktop.
for phantom lab
{"phases": [], "container": {"node_guid": null, "in_case": false, "sensitivity": "amber", "create_time": "2019-06-13T18:28:36.836633Z", "tenant_id": 0, "role_id": null, "id": 105, "custom_fields": {}, "asset_id": null, "close_time": null, "open_time": "2019-06-13T18:30:53.840601Z", "status_id": 2, "container_type": "default", "closing_owner_id": null, "current_phase_id": null, "due_time": "2019-06-14T06:27:45.276000Z", "version": 1, "workflow_name": "", "owner_id": 1, "status": "open", "owner_name": null, "hash": "9e4458b9791d28101e5b3c1788fce582", "description": "A file download has been detected by network scan", "tags": [], "start_time": "2019-06-13T18:28:36.846066Z", "severity_id": "medium", "kill_chain": null, "artifact_update_time": "2019-06-13T18:32:15.408501Z", "artifact_count": 5, "parent_container_id": null, "data": {}, "name": "File Downloaded by HTTP", "ingest_app_id": null, "label": "events", "source_data_identifier": "e76431b6-c725-4981-9703-d27e0374693c", "end_time": null, "closing_rule_run_id": null, "container_update_time": "2019-06-13T18:32:15.522544Z"}, "attachments": [], "artifacts": [{"in_case": false, "create_time": "2019-06-13T18:29:21.915230Z", "id": 130, "parent_artifact_id": null, "label": "hash", "version": 1, "has_note": false, "type": null, "owner_id": 1, "cef": {"fileHash": "2d75cc1bf8e57872781f9cd04a529256"}, "update_time": "2019-06-13T18:29:21.916119Z", "hash": "4bbfdde6cde89269d0d109c61b5ff5a0", "description": null, "tags": [], "cef_types": {}, "start_time": "2019-06-13T18:29:21.919225Z", "container_id": 105, "severity_id": "medium", "kill_chain": null, "playbook_run_id": null, "parent_container_id": null, "data": {}, "name": "Hash", "ingest_app_id": null, "source_data_identifier": "5f828ac0-ba50-426a-bae2-e509254c77b0", "end_time": null}, {"in_case": false, "create_time": "2019-06-13T18:30:53.703483Z", "id": 131, "parent_artifact_id": null, "label": "domain", "version": 1, "has_note": false, "type": null, "owner_id": 1, "cef": {"sourceDnsDomain": "www.google.com"}, "update_time": "2019-06-13T18:30:53.704399Z", "hash": "2de79bd32bad82bb950e650556b1cfb4", "description": null, "tags": [], "cef_types": {}, "start_time": "2019-06-13T18:30:53.707599Z", "container_id": 105, "severity_id": "medium", "kill_chain": null, "playbook_run_id": null, "parent_container_id": null, "data": {}, "name": "Source URL", "ingest_app_id": null, "source_data_identifier": "c75ff3b9-695f-490c-a30f-b8dcebcda4a7", "end_time": null}, {"in_case": false, "create_time": "2019-06-13T18:31:20.670608Z", "id": 132, "parent_artifact_id": null, "label": "ip", "version": 1, "has_note": false, "type": null, "owner_id": 1, "cef": {"destinationAddress": "127.0.0.1"}, "update_time": "2019-06-13T18:31:20.671737Z", "hash": "ea97a1e0b2c040569c1d73af04a46705", "description": null, "tags": [], "cef_types": {}, "start_time": "2019-06-13T18:31:20.674831Z", "container_id": 105, "severity_id": "medium", "kill_chain": null, "playbook_run_id": null, "parent_container_id": null, "data": {}, "name": "Destination", "ingest_app_id": null, "source_data_identifier": "91e442b2-b9b6-4f88-99c4-78a0d810074b", "end_time": null}, {"in_case": false, "create_time": "2019-06-13T18:31:53.178115Z", "id": 133, "parent_artifact_id": null, "label": "ip", "version": 1, "has_note": false, "type": null, "owner_id": 1, "cef": {"sourceAddress": "8.8.8.8"}, "update_time": "2019-06-13T18:31:53.178993Z", "hash": "ef7484915ce1935a290b95057692127c", "description": null, "tags": [], "cef_types": {}, "start_time": "2019-06-13T18:31:53.182034Z", "container_id": 105, "severity_id": "medium", "kill_chain": null, "playbook_run_id": null, "parent_container_id": null, "data": {}, "name": "Source Address", "ingest_app_id": null, "source_data_identifier": "8cceebed-ff1b-4ef5-b97d-f598f3c47135", "end_time": null}, {"in_case": false, "create_time": "2019-06-13T18:32:15.373580Z", "id": 134, "parent_artifact_id": null, "label": "path", "version": 1, "has_note": false, "type": null, "owner_id": 1, "cef": {"filePath": "/home/user/results"}, "update_time": "2019-06-13T18:32:15.374490Z", "hash": "77d87a12512738555e1921717cd662aa", "description": null, "tags": [], "cef_types": {}, "start_time": "2019-06-13T18:32:15.378003Z", "container_id": 105, "severity_id": "medium", "kill_chain": null, "playbook_run_id": null, "parent_container_id": null, "data": {}, "name": "File Path", "ingest_app_id": null, "source_data_identifier": "fc740748-179c-4221-bb47-9abbd6d5d6e6", "end_time": null}], "vault_documents": [], "notes": [], "comments": [], "evidence": []}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment