Skip to content

Forensics/Utility custom functions - #227

Open
ccl0utier wants to merge 1 commit into
phantomcyber:7.1from
ccl0utier:7.1
Open

ccl0utier wants to merge 1 commit into
phantomcyber:7.1from
ccl0utier:7.1

Conversation

@ccl0utier

Copy link
Copy Markdown
Contributor

Add 26 new forensics/utility custom functions:

  • extract_strings_from_vault_file
  • generate_uuid_v4
  • list_to_html
  • list_to_markdown
  • regex_extract_ipv6
  • string_analyze_cidr
  • string_base32
  • string_base85
  • string_caesar_shift
  • string_entropy
  • string_hex_decode
  • string_hex_encode
  • string_html_entities_decode
  • string_html_entities_encode
  • string_luhn
  • string_md5_hash
  • string_punycode_encode
  • string_replace
  • string_rot13
  • string_sha1_hash
  • string_sha256_hash
  • string_timestamp_to_epoch
  • string_unix_to_unix
  • string_uri_encode
  • string_xor
  • strings_similarity

@gdollasigns

Copy link
Copy Markdown
Collaborator

Thanks for contributing these forensics/utility custom functions, @ccl0utier! The overall quality is high — well-documented, consistent structure, and good edge case handling throughout. We've reviewed all 26 functions against the existing community functions and confirmed there are no duplicates, so everything is genuinely additive. A few issues to address before this is ready to merge:

1. Targets outdated 7.1 branch (High)
This PR targets 7.1, which is quite old. Please retarget to 8.6, which is the current default branch. The JSON files should also be updated from python_version: "3" to python_version: "3.13" to match all other custom functions in the repo.

2. string_xor output will fail JSON serialization for bytes input (High)
When input_data is of type bytes, the function correctly returns bytes — but then the assert json.dumps(outputs) check at the end will raise a TypeError since bytes is not JSON-serializable. The function should always return a string (e.g. hex-encoded) when given bytes input, or handle the serialization explicitly.

3. verify=False in REST calls in extract_strings_from_vault_file (Medium)
Two phantom.requests.get() calls use verify=False, disabling TLS certificate verification. Even for internal SOAR API calls this is a security concern. Please use the platform's cert bundle or the appropriate verified request pattern.

4. host_range returned as a tuple in string_analyze_cidr (Medium)
The host_range field is returned as a Python tuple (first_usable, last_usable). While json.dumps will serialize it as a list, consumers expecting a tuple will be surprised. It's cleaner to return it explicitly as a list or as two separate fields (first_usable_host, last_usable_host).

5. Missing null/non-string guard in strings_similarity (Minor)
If either input_string1 or input_string2 is None, calling len() on it will raise a TypeError. The other functions in this PR have input validation — please add the same here.

Please address items 1 and 2 before this is merged — items 3–5 are important quality improvements but not hard blockers. Happy to re-review once updated!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants