Enrichments
Enrich IP
Enriches IP addresses with reputation and geo-location data.
Enrich IP - Parameters Schema
{
"ip": string | ParamRef (required)
}
Enrich IP - Parameters Detail
ip (string/ParamRef, required): IPv4 address to enrich (must be valid IPv4 format when not using parameter reference)
Enrich IP - Example
{
"type": "Enrich IP",
"name": "Enrich client IP",
"parameters": {
"ip": "{{step['Expert Shell login']['client_ip']}}"
}
}
Enrich URL
Enriches URLs with reputation and analysis data.
Enrich URL - Parameters Schema
{
"url": string | string[] | ParamRef (required)
}
Enrich URL - Parameters Detail
url (string/array/ParamRef, required): URL(s) to enrich (must be valid URL format when not using parameter reference)
Enrich URL - Example
{
"type": "Enrich URL",
"name": "Analyze suspicious URL",
"parameters": {
"url": "{{step['Log Trigger']['requested_url']}}"
}
}
Enrich File
Enriches file hashes with reputation and analysis data.
Enrich File - Parameters Schema
{
"file_hash": string | ParamRef (required)
}
Enrich File - Parameters Detail
file_hash (string/ParamRef, required): File hash to enrich (must be valid MD5, SHA-1, or SHA-256 hash when not using parameter reference)
Enrich File - Example
{
"type": "Enrich File",
"name": "Check file reputation",
"parameters": {
"file_hash": "{{step['Log Trigger']['file_hash']}}"
}
}