2727 view : |-
2828 {
2929 "position": {
30- "x": 450 ,
31- "y": 61
30+ "x": 459 ,
31+ "y": -77
3232 }
3333 }
3434 note : false
5858 view : |-
5959 {
6060 "position": {
61- "x": 450 ,
62- "y": 173
61+ "x": 459 ,
62+ "y": 35
6363 }
6464 }
6565 note : false
9595 view : |-
9696 {
9797 "position": {
98- "x": 450 ,
99- "y": 276
98+ "x": 459 ,
99+ "y": 138
100100 }
101101 }
102102 note : false
@@ -127,8 +127,8 @@ tasks:
127127 view : |-
128128 {
129129 "position": {
130- "x": 450 ,
131- "y": 394
130+ "x": 459 ,
131+ "y": 256
132132 }
133133 }
134134 note : false
@@ -162,8 +162,8 @@ tasks:
162162 view : |-
163163 {
164164 "position": {
165- "x": 670 ,
166- "y": 1148
165+ "x": 682 ,
166+ "y": 1234
167167 }
168168 }
169169 note : false
@@ -197,8 +197,8 @@ tasks:
197197 view : |-
198198 {
199199 "position": {
200- "x": 670 ,
201- "y": 1011
200+ "x": 682 ,
201+ "y": 1112
202202 }
203203 }
204204 note : false
@@ -222,14 +222,14 @@ tasks:
222222 description : ' '
223223 nexttasks :
224224 ' #none# ' :
225- - " 13 "
225+ - " 43 "
226226 separatecontext : false
227227 continueonerrortype : " "
228228 view : |-
229229 {
230230 "position": {
231- "x": 670 ,
232- "y": 514
231+ "x": 682 ,
232+ "y": 376
233233 }
234234 }
235235 note : false
@@ -260,7 +260,7 @@ tasks:
260260 {
261261 "position": {
262262 "x": 228,
263- "y": 514
263+ "y": 376
264264 }
265265 }
266266 note : false
@@ -297,7 +297,7 @@ tasks:
297297 {
298298 "position": {
299299 "x": 228,
300- "y": 644
300+ "y": 484
301301 }
302302 }
303303 note : false
@@ -349,7 +349,7 @@ tasks:
349349 {
350350 "position": {
351351 "x": 228,
352- "y": 1148
352+ "y": 1127
353353 }
354354 }
355355 note : false
@@ -391,8 +391,8 @@ tasks:
391391 view : |-
392392 {
393393 "position": {
394- "x": 670 ,
395- "y": 644
394+ "x": 682 ,
395+ "y": 606
396396 }
397397 }
398398 note : false
@@ -417,7 +417,7 @@ tasks:
417417 brand : " "
418418 nexttasks :
419419 ' #none# ' :
420- - " 15 "
420+ - " 44 "
421421 scriptarguments :
422422 key :
423423 simple : SuspiciousCommandLines
@@ -451,8 +451,8 @@ tasks:
451451 view : |-
452452 {
453453 "position": {
454- "x": 670 ,
455- "y": 769
454+ "x": 682 ,
455+ "y": 731
456456 }
457457 }
458458 note : false
@@ -486,8 +486,8 @@ tasks:
486486 view : |-
487487 {
488488 "position": {
489- "x": 670 ,
490- "y": 892
489+ "x": 682 ,
490+ "y": 983
491491 }
492492 }
493493 note : false
@@ -671,7 +671,7 @@ tasks:
671671 {
672672 "position": {
673673 "x": 228,
674- "y": 1011
674+ "y": 995
675675 }
676676 }
677677 note : false
@@ -706,7 +706,7 @@ tasks:
706706 {
707707 "position": {
708708 "x": 228,
709- "y": 769
709+ "y": 609
710710 }
711711 }
712712 note : false
@@ -733,8 +733,8 @@ tasks:
733733 view : |-
734734 {
735735 "position": {
736- "x": 28 ,
737- "y": 1274
736+ "x": -55 ,
737+ "y": 1258
738738 }
739739 }
740740 note : false
@@ -751,25 +751,28 @@ tasks:
751751 task :
752752 id : 00147d5b-75bc-4aa5-8c39-089122952851
753753 version : -1
754- name : Extract PFX from ZIP
754+ name : Extract PFX from ZIP using 7zip
755755 description : Unzip a file using fileName or entryID to specify a file. Unzipped files will be loaded to the War Room and names will be put into the context.
756756 scriptName : UnzipFile
757757 type : regular
758758 iscommand : false
759759 brand : " "
760760 nexttasks :
761+ ' #error# ' :
762+ - " 45"
761763 ' #none# ' :
762764 - " 19"
763765 scriptarguments :
764766 entryID :
765767 simple : ${File.EntryID}
766768 separatecontext : false
767- continueonerrortype : " "
769+ continueonerror : true
770+ continueonerrortype : errorPath
768771 view : |-
769772 {
770773 "position": {
771774 "x": 228,
772- "y": 892
775+ "y": 731
773776 }
774777 }
775778 note : false
@@ -1284,27 +1287,150 @@ tasks:
12841287 quietmode : 0
12851288 isoversize : false
12861289 isautoswitchedtoquietmode : false
1290+ " 43 " :
1291+ id : " 43"
1292+ taskid : a5ebfd37-bd9b-4611-9338-a759db5e7452
1293+ type : condition
1294+ task :
1295+ id : a5ebfd37-bd9b-4611-9338-a759db5e7452
1296+ version : -1
1297+ name : ' Is there a command line? '
1298+ description : ' Check if the command line exists. '
1299+ type : condition
1300+ iscommand : false
1301+ brand : " "
1302+ nexttasks :
1303+ ' #default# ' :
1304+ - " 44"
1305+ " yes " :
1306+ - " 13"
1307+ separatecontext : false
1308+ conditions :
1309+ - label : " yes"
1310+ condition :
1311+ - - operator : isNotEmpty
1312+ left :
1313+ value :
1314+ simple : Core.OriginalAlert.event.actor_process_command_line
1315+ iscontext : true
1316+ continueonerrortype : " "
1317+ view : |-
1318+ {
1319+ "position": {
1320+ "x": 682,
1321+ "y": 484
1322+ }
1323+ }
1324+ note : false
1325+ timertriggers : []
1326+ ignoreworker : false
1327+ skipunavailable : false
1328+ quietmode : 0
1329+ isoversize : false
1330+ isautoswitchedtoquietmode : false
1331+ " 44 " :
1332+ id : " 44"
1333+ taskid : 4a936c96-aa51-4132-b4cd-e79ad923ec7c
1334+ type : condition
1335+ task :
1336+ id : 4a936c96-aa51-4132-b4cd-e79ad923ec7c
1337+ version : -1
1338+ name : Does actor process exist?
1339+ type : condition
1340+ iscommand : false
1341+ brand : " "
1342+ description : " Check if process name is exists."
1343+ nexttasks :
1344+ ' #default# ' :
1345+ - " 5"
1346+ " yes " :
1347+ - " 15"
1348+ separatecontext : false
1349+ conditions :
1350+ - label : " yes"
1351+ condition :
1352+ - - operator : isNotEmpty
1353+ left :
1354+ value :
1355+ simple : Core.OriginalAlert.event.actor_process_file_original_name
1356+ iscontext : true
1357+ continueonerrortype : " "
1358+ view : |-
1359+ {
1360+ "position": {
1361+ "x": 682,
1362+ "y": 864
1363+ }
1364+ }
1365+ note : false
1366+ timertriggers : []
1367+ ignoreworker : false
1368+ skipunavailable : false
1369+ quietmode : 0
1370+ isoversize : false
1371+ isautoswitchedtoquietmode : false
1372+ " 45 " :
1373+ id : " 45"
1374+ taskid : e3fd423b-a242-41bd-a5b9-ceecc7e3caa2
1375+ type : regular
1376+ task :
1377+ id : e3fd423b-a242-41bd-a5b9-ceecc7e3caa2
1378+ version : -1
1379+ name : Extract PFX from ZIP using zipfile
1380+ description : Unzip a file using fileName or entryID to specify a file. Unzipped files will be loaded to the War Room and names will be put into the context.
1381+ scriptName : UnzipFile
1382+ type : regular
1383+ iscommand : false
1384+ brand : " "
1385+ nexttasks :
1386+ ' #error# ' :
1387+ - " 21"
1388+ ' #none# ' :
1389+ - " 19"
1390+ scriptarguments :
1391+ entryID :
1392+ simple : ${File.EntryID}
1393+ zipTool :
1394+ simple : zipfile
1395+ separatecontext : false
1396+ continueonerror : true
1397+ continueonerrortype : errorPath
1398+ view : |-
1399+ {
1400+ "position": {
1401+ "x": -55,
1402+ "y": 864
1403+ }
1404+ }
1405+ note : false
1406+ timertriggers : []
1407+ ignoreworker : false
1408+ skipunavailable : false
1409+ quietmode : 0
1410+ isoversize : false
1411+ isautoswitchedtoquietmode : false
12871412view : |-
12881413 {
12891414 "linkLabelsPosition": {
12901415 "17_30_yes": 0.53,
12911416 "18_17_#default#": 0.33,
12921417 "18_41_yes": 0.48,
1293- "19_16_#default#": 0.5,
12941418 "19_9_yes": 0.57,
1419+ "22_45_#error#": 0.54,
12951420 "30_38_No": 0.14,
12961421 "30_41_Yes": 0.34,
12971422 "34_38_No": 0.54,
12981423 "36_38_#default#": 0.49,
12991424 "39_38_#default#": 0.38,
1300- "9_21_#error#": 0.41
1425+ "44_15_yes": 0.3,
1426+ "9_21_#error#": 0.38
13011427 },
13021428 "paper": {
13031429 "dimensions": {
1304- "height": 2750 ,
1305- "width": 1543 ,
1306- "x": 28 ,
1307- "y": 61
1430+ "height": 2888 ,
1431+ "width": 1626 ,
1432+ "x": -55 ,
1433+ "y": -77
13081434 }
13091435 }
13101436 }
0 commit comments