FortiSOAR Discussions
Anonymous
Not applicable

Reporting a probable issue for Utilities connector action: Extract Artifact from string.

Steps to reproduce.

 

  1. Use Phishing Email solution pack and enable extract attachment option on.
  2. Exchange Mailbox defaults to HTML format for emails.
  3. Create a text file and add a line into it like "https://gumblar.cn"
  4. Attach above text file and send it to the mailbox, which is configured to read emails through Exchange connector.
  5. Observer "03 Enrich - Extract Indicators From Attachment" Playbook.
  6. In "result" key , we will see a value as "https://gumblar.cn/<p>"
  7. "<p>" is getting wrongly appended to the url.
  8. Test Playbook is attached with sample string for testing, please unzip it and import into playbook collection.
  9. Screenshot is attached.

2023-11-28 19_39_33-Extract Artifact from string _ 01 - Drafts _ Collections _ Playbooks — Mozilla F.png

2 Solutions
rkhune
Staff
Staff

 

As a workaround, in "03 - Enrich > Extract Indicator" playbook, (refer to the attached image for a reference)

- goto 'Extract Indicators from Description' PB Step

- Check "Override Extraction Settings"

- and replace value of 'RegEx Expression For URL Extraction:' field with (?:https?|s?ftp):\/\/[^\s/$.?#].[^\s,\"\'<>]*

 

 

 

 

 

View solution in original post

Anonymous
Not applicable

It worked with (?:https?|s?ftp):\/\/[^\s/$.?#].[^\s,\"\'<//>]* .

 

Thanks

View solution in original post

2 REPLIES 2
rkhune
Staff
Staff

 

As a workaround, in "03 - Enrich > Extract Indicator" playbook, (refer to the attached image for a reference)

- goto 'Extract Indicators from Description' PB Step

- Check "Override Extraction Settings"

- and replace value of 'RegEx Expression For URL Extraction:' field with (?:https?|s?ftp):\/\/[^\s/$.?#].[^\s,\"\'<>]*

 

 

 

 

 

Anonymous
Not applicable

It worked with (?:https?|s?ftp):\/\/[^\s/$.?#].[^\s,\"\'<//>]* .

 

Thanks