ReversingLabs TitaniumCore A1000
The A1000 Malware Analysis Platform supports advanced hunting and investigations through the TitaniumCore high-speed automated static analysis engine. It is integrated with file reputation services to provide in-depth rich context and threat classification on over 8 billion files and across all file types.
Connect ReversingLabs TitaniumCore A1000 with Devo SOAR
Navigate to Automations > Integrations.
Search for ReversingLabs TitaniumCore A1000.
Click Details, then the + icon. Enter the required information in the following fields.
Label: Enter a connection name.
Reference Values: Define variables here to templatize integration connections and actions. For example, you can use https://www.{{hostname}}.com where, hostname is a variable defined in this input. For more information on how to add data, see 'Add Data' Input Type for Integrations.
Verify SSL: Select option to verify connecting server's SSL certificate (Default is Verify SSL Certificate).
Remote Agent: Run this integration using the Devo SOAR Remote Agent.
Server URL: Base URL of your Reversinglab Titaniumcore A1000 instance.
Token: Token to use for authenticating requests for your Reversinglab Titaniumcore A1000 instance.
After you've entered all the details, click Connect.
Actions for ReversingLabs TitaniumCore A1000
Upload File
Upload a file to A1000 to analyze.
Input Field
Choose a connection that you have previously created and then fill in the necessary information in the following input fields to complete the connection.
Input Name | Description | Required |
---|---|---|
File Name Column | Column name from parent table to lookup filename. | Required |
Comment Column | Column name from parent table to lookup comment to add to the file. | Required |
Tags Column | Column name from parent table to lookup tags for the file. | Required |
Cloud Analyze | Select option to send file to TitaniumCloud for Analysis. (Default is 'False'). | Required |
Download File
Download an analyzed file sample.
Input Field
Choose a connection that you have previously created and then fill in the necessary information in the following input fields to complete the connection.
Input Name | Description | Required |
---|---|---|
File Hash Column | Column name from parent table to lookup file hash (md5, sha1, sha256, sha512). | Required |
File Reputation
Get the reputation of a file from A1000.
Input Field
Choose a connection that you have previously created and then fill in the necessary information in the following input fields to complete the connection.
Input Name | Description | Required |
---|---|---|
File Hash Column | Column name from parent table to lookup file hash (md5, sha1, sha256, sha512). | Required |
Release Notes
v2.0.0
- Updated architecture to support IO via filesystemv1.0.8
- Added documentation link in the automation library.