Skip to main content

QutteraWebsiteMalwareScanner

This Integration is part of the Quttera Website Malware Scanner Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.0.0 and later) and Cortex XSIAM.

Quttera Website Malware Scanner This integration was integrated and tested with version v3 of QutteraWebsiteMalwareScanner

Configure QutteraWebsiteMalwareScanner in Cortex#

ParameterRequired
API KeyTrue
Quttera Scanner URLTrue

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

quttera-scan-start#


Start to scan a given domain

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command#

quttera-scan-start

Input#

Argument NameDescriptionRequired
domainThe name of the domain to scan.Required

Context Output#

PathTypeDescription
QutteraWebsiteMalwareScanning.Start.errorNumberHTTP response from the scanner
QutteraWebsiteMalwareScanning.Start.errorstrStringStatus of the scan request

quttera-rescan-status#


Retrieve status of submitted domain

Base Command#

quttera-rescan-status

Input#

Argument NameDescriptionRequired
domainThe name of the domain to retrieve its status.Required

Context Output#

PathTypeDescription
QutteraWebsiteMalwareScanning.Status.errorNumberScan result request status
QutteraWebsiteMalwareScanning.Status.errorstrStringScan result request description
QutteraWebsiteMalwareScanning.Status.status.blacklistedStringIs the domain blacklisted
QutteraWebsiteMalwareScanning.Status.status.filesNumberAmount of scanned files
QutteraWebsiteMalwareScanning.Status.status.scanner_resultStringScan result
QutteraWebsiteMalwareScanning.Status.status.sensitivityStringSensitivity
QutteraWebsiteMalwareScanning.Status.status.stateStringIs scanning done
QutteraWebsiteMalwareScanning.Status.status.timeStringTime
QutteraWebsiteMalwareScanning.Status.status.urlStringScanned URL

quttera-scan-report#


Retrieve report of submitted domain

Base Command#

quttera-scan-report

Input#

Argument NameDescriptionRequired
domainThe name of the domain to retrieve its report.Required

Context Output#

PathTypeDescription
QutteraWebsiteMalwareScanning.report.errorNumberRetrieving domain scan return code
QutteraWebsiteMalwareScanning.report.errorstrStringRetrieving domain scan report state
QutteraWebsiteMalwareScanning.report.statusDictDetailed domain scan report
QutteraWebsiteMalwareScanning.report.status.blacklistedStringIs domain blacklisted
QutteraWebsiteMalwareScanning.report.status.filesNumberHow many files were scanned
QutteraWebsiteMalwareScanning.report.status.scanner_resultStringScanner result
QutteraWebsiteMalwareScanning.report.status.sensitivityStringDomain sensitivity
QutteraWebsiteMalwareScanning.report.status.stateStringState of the domain
QutteraWebsiteMalwareScanning.report.status.timeStringScan time
QutteraWebsiteMalwareScanning.report.status.urlStringScanned URL

quttera-report-malware#


Retrieve url blacklist and reputation

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command#

quttera-report-malware

Input#

Argument NameDescriptionRequired
urlURL to retrieve its blacklist and reputation.Required

Context Output#

PathTypeDescription
QutteraWebsiteMalwareScanning.reportDictRetrieving url blacklist and reputation

quttera-status-blacklist#


Retrieve domain blacklist and reputation

Base Command#

quttera-status-blacklist

Input#

Argument NameDescriptionRequired
domainThe name of the domain to retrieve its blacklist and reputation.Required

Context Output#

PathTypeDescription
QutteraWebsiteMalwareScanning.reportDictRetrieving domain blacklist and reputation