IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Cisco Umbrella Rule - "Threatgrid sample information for a hash " not working

    Posted Tue December 19, 2023 02:08 AM

    Hello experts,

    The Cisco Umbrella investigate - Rule "Threadgrid sample information for a hash" is not working when triggered using a artifact hash type - MD5 or SHA1. It seems the python script is breaking for this particular rule. I have tested other rules, and they work fine.

    The Cisco Umbrealla investigate app from ibm app exchange: https://exchange.xforce.ibmcloud.com/api/hub/extensionsNew/d0bf3f6a27742c3deefa1426eab8b4fa/Resilient_Integrations_Function_Guide_for_Cisco_Umbrella_Investigate.pdf

    I converted the rule to playbook, and obtained the below error message.

    Traceback (most recent call last):

      File "/opt/app-root/lib64/python3.9/site-packages/fn_cisco_umbrella_inv/components/umbrella_threat_grid_sample.py", line 151, in _umbrella_threat_grid_sample_function

        rtn = rinv.sample(hash, **params)

      File "/opt/app-root/lib64/python3.9/site-packages/investigate/investigate.py", line 292, in sample

        return self.get_parse(uri, params)

      File "/opt/app-root/lib64/python3.9/site-packages/investigate/investigate.py", line 107, in get_parse

        return self._request_parse(self.get, uri, params)

      File "/opt/app-root/lib64/python3.9/site-packages/investigate/investigate.py", line 100, in _request_parse

        r.raise_for_status()

      File "/opt/app-root/lib64/python3.9/site-packages/requests/models.py", line 1021, in raise_for_status

        raise HTTPError(http_error_msg, response=self)

    requests.exceptions.HTTPError: 400 Client Error: Bad Request for url: https://investigate.umbrella.com/sample/44d88612fea##f######b02f?limit=2&offset=0

    Please I will appreciate if anyone can help here.

    Regards,



    ------------------------------
    benlinux
    ------------------------------


  • 2.  RE: Cisco Umbrella Rule - "Threatgrid sample information for a hash " not working

    Posted Tue December 19, 2023 07:37 AM

    Greetings

    Are you getting the same error with the original rule? If that rule is also failing, it may be best to open a support ticket so we can review further. 

    Regards,

    Mark



    ------------------------------
    Mark Scherfling
    ------------------------------



  • 3.  RE: Cisco Umbrella Rule - "Threatgrid sample information for a hash " not working

    Posted Tue December 19, 2023 08:07 AM

    Hello Mark,

    The original rule does not work as well. I will open a support ticket then.

    Regards,



    ------------------------------
    benlinux
    ------------------------------



  • 4.  RE: Cisco Umbrella Rule - "Threatgrid sample information for a hash " not working

    Posted Tue December 19, 2023 10:44 AM

    Hello Mark,

    Case id : TS015021656

    Please assist.



    ------------------------------
    benlinux
    ------------------------------