sample
turbot/flowpipe-samples/lookup-iocs

Pipeline: Lookup File hash In Different Tools

A composite Flowpipe mod that lookup a file hash in VirusTotal, Urlscan and other tools.

Run the pipeline

To run this pipeline from your terminal:

flowpipe pipeline run lookup_iocs.pipeline.lookup_file_hash \
--arg 'file_hash=<string>'

Use this pipeline

To call this pipeline from your pipeline, use a step:

step "pipeline" "step_name" {
pipeline = lookup_iocs.pipeline.lookup_file_hash
args = {
file_hash = <string>
}
}

Params

NameTypeRequiredDescriptionDefault
virustotal_conn
connection.virustotal
YesName of VirusTotal connection to use. If not provided, the default VirusTotal connection will be used.connection.virustotal.default
urlscan_conn
connection.urlscan
YesName of URL Scan connection to use. If not provided, the default URL Scan connection will be used.connection.urlscan.default
hybrid_analysis_api_key
string
YesAPI key to authenticate requests with Hybrid Analysis.Your_Hybrid_Analysis_API_Key
file_hash
string
YesThe file hash to be scanned.-

Outputs

NameDescription
lookup_file_hash