check_threat_intel
Query threat intelligence databases using a file hash to identify known malicious files in an investigation.
Instructions
Queries threat intelligence databases (with safe offline fixture fallback) for a file hash.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| case_id | No | CASE-DEFAULT | |
| file_hash | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |