F6 XDR REST API Python Bindings
Project description
Python bindings for F6 XDR REST API
Latest Version: 1.1.0
Description
The F6 XDR Python Client enables you to fully integrate F6 XDR MDP into your malware analysis framework. F6 XDR MDP is a Malware Detonation & Research platform designed for deep dynamic analysis and enhanced indicators extraction.
You can use this library with
- F6 XDR Cloud — our Cloud hosted instance
- On-premise installations of F6 XDR — for even more power and privacy
License
The code is written in Python and licensed under MIT.
Requirements
- python 3.6 or higher
Getting Started
Installation
pip install pyxdr
For upgrading pyxdr to a more recent version, use
pip install --upgrade pyxdr
API Key
In order to perform any queries via the API, you will need to get the API token for your F6 XDR user.
- Open F6 XDR web interface.
- Navigate to "Profile" and click "Generate Auth Token".
- Copy this token. This is your API Key.
Sample Code
- Let's start by sending some file ("sample.exe") for analysis:
from pyxdr import MDP
mdp = MDP("MY_API_KEY")
analysis = mdp.upload_file(open("sample.exe", "rb"))
- If you want to detonate some URL, use the next method:
analysis = mdp.upload_url("https://very-malicious-url.com")
Now we have the analysis object.
To update analysis status and get info about it, use the next method:
info = analysis.get_info(extended=True)
Notice: parameter extended allows you to get full or short info about analysis process. The short version of the information is as follows:
{
"status": "IN PROGRESS" | "FINISHED" | "FAILED",
"verdict": None | True | False,
"report_url": "https://...",
"error": "Some error" # optional field only for "FAILED" status
}
If the "verdict" is True then object is malicious.
Notice: XDR need some time to generate the report url. Until it happens, the response will not contain this field.
- You can get full report as a dictionary:
report = analysis.get_report()
- There is a way to download some detonation artifacts and the report:
archived_report = analysis.export_report() # Export report as .tar.
pdf_report = analysis.export_pdf_report() # Export report as PDF
pcap = analysis.export_pcap() # Export all network activity as .pcap file.
screen_video = analysis.export_video() # Export the screen-video of the detonation process.
Notice: If there is no artifact, all this methods raise ObjectNotFoundError.
- You can check some hash reputation with this method:
reputation = mdp.get_hash_reputation("md5", "ac55cf33c4691f863bfb3af8c06a7244")
You can get reputation for md5, sha1, sha256 hash types.
The method returns a dict object:
{
"found": true | false,
"verdict": true | false,
"malware_families": [],
"score": float in [0; 100]
}
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pyxdr-1.1.0.tar.gz.
File metadata
- Download URL: pyxdr-1.1.0.tar.gz
- Upload date:
- Size: 12.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
da59094046e2f0f731c7366430d57806bbff64fc23ab41ca9cb856eaba05d435
|
|
| MD5 |
22e79353f2f5338285d6b3996523e377
|
|
| BLAKE2b-256 |
6eb843f32e675903bd4b70a7f1db5e311c305242f7a53f8887ac651ee8a16485
|
File details
Details for the file pyxdr-1.1.0-py3-none-any.whl.
File metadata
- Download URL: pyxdr-1.1.0-py3-none-any.whl
- Upload date:
- Size: 11.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e93afad2fa6db38c764c4a0952c9c5a5a19a1e8d46c9f9aa7b28e969ebd9f853
|
|
| MD5 |
5cc97f0619e4761b19913e00b21dae2a
|
|
| BLAKE2b-256 |
6213493e99d28a3ceb931afd128c48105951ecf68e18b32cf436e6da36fc9ab9
|