← Files CrowdStrike Falcon FusionARCHIVED FILE

skills/authoring/examples/threat-intel/enrich-ip-virustotal-llm-email.yaml

7.08 KB · Oct 2, 2026 · 00:31 UTC

↓ Download file

# Example: Enrich an IP with VirusTotal, summarize with Charlotte AI, email the report
# Category: threat-intel
# Source: Authored with these skills and verified live end-to-end against a CID
#   (import + release + on-demand execution). On-demand trigger takes an `ip`
#   parameter; the Cloud HTTP Request enriches it with VirusTotal, an UpdateVariable
#   stores the REAL response fields, Charlotte AI summarizes them, and Send email
#   delivers the report.
#
# Two schema blocks matter here and are easy to confuse:
#   - http_transaction._cs_inline_output_schema — lets downstream actions RESOLVE
#     ${data['<Action>.data...']} references at RELEASE time.
#   - inline_configuration.output_schema — the shape the response is VALIDATED
#     against at RUNTIME. If it omits/mistypes a field the API returns, the action
#     fails with a 406 ("script output does not validate against the output JSON
#     schema") that no local check, import, or release catches. Capture the real
#     shape in the console: attach the credential, click Test, then Schema builder.
#
# Credential-less by design: no definition_id. The action imports with
# Authentication = "None"; attach the VirusTotal API key in the console after
# deploy (open the action -> Authentication -> Create new -> API key -> secret key
# -> location Header -> header name x-apikey -> Test -> Schema builder -> Save).
name: 'Enrich IP with VirusTotal and email an AI summary'
description: 'On demand: enrich a supplied IP with VirusTotal, store the real response fields in a variable, summarize with Charlotte AI, and email an HTML report.'
trigger:
    next:
        - CreateVariable
    name: On demand
    parameters:
        $schema: https://json-schema.org/draft-07/schema
        properties:
            ip:
                type: string
                title: IP address
                description: IP address to enrich with VirusTotal
            notify_email:
                type: string
                title: Notify email
                description: Recipient for the enrichment report (a Falcon user or CID-approved domain)
        required:
            - ip
            - notify_email
        type: object
    type: On demand
actions:
    CreateVariable:
        id: 702d15788dbbffdf0b68d8e2f3599aa4
        class: CreateVariable
        name: Create variable - Initialize enrichment results
        next:
            - CloudHTTPRequestVirusTotalIPEnrichment
        properties:
            variable_schema:
                properties:
                    ip_enrichment:
                        type: string
                type: object
        version_constraint: ~1
    CloudHTTPRequestVirusTotalIPEnrichment:
        id: 1ba474f407d9228fc8fa02cdce8ae8ef
        class: Inline.HTTPRequest
        name: Cloud HTTP Request - VirusTotal IP Enrichment
        next:
            - UpdateVariableIP
        inline_configuration:
            output_schema:
                $schema: https://json-schema.org/draft-07/schema
                properties:
                    data:
                        properties:
                            attributes:
                                properties:
                                    as_owner:
                                        type: string
                                    country:
                                        type: string
                                    last_analysis_stats:
                                        properties:
                                            harmless:
                                                type: integer
                                            malicious:
                                                type: integer
                                            suspicious:
                                                type: integer
                                            undetected:
                                                type: integer
                                        type: object
                                    reputation:
                                        type: integer
                                type: object
                            id:
                                type: string
                        type: object
                type: object
        properties:
            http_transaction:
                request_http_method: GET
                request_url: "https://www.virustotal.com/api/v3/ip_addresses/${data['ip']}"
                request_content_type: NONE
                request_headers: {}
                request_body: '{}'
                _cs_inline_output_schema: '{"$schema":"https://json-schema.org/draft-07/schema","properties":{"data":{"properties":{"attributes":{"properties":{"last_analysis_stats":{"properties":{"malicious":{"type":"integer"},"suspicious":{"type":"integer"},"harmless":{"type":"integer"},"undetected":{"type":"integer"}},"type":"object"},"reputation":{"type":"integer"},"country":{"type":"string"},"as_owner":{"type":"string"}},"type":"object"},"id":{"type":"string"}},"type":"object"}},"type":"object"}'
        version_constraint: ~1
    UpdateVariableIP:
        id: 6c6eab39063fa3b72d98c82af60deb8a
        class: UpdateVariable
        name: Update variable - Store IP enrichment
        next:
            - SummarizeEnrichment
        properties:
            WorkflowCustomVariable:
                ip_enrichment: "IP: ${data['ip']} | Malicious: ${data['CloudHTTPRequestVirusTotalIPEnrichment.data.attributes.last_analysis_stats.malicious']} | Suspicious: ${data['CloudHTTPRequestVirusTotalIPEnrichment.data.attributes.last_analysis_stats.suspicious']} | Reputation: ${data['CloudHTTPRequestVirusTotalIPEnrichment.data.attributes.reputation']} | Country: ${data['CloudHTTPRequestVirusTotalIPEnrichment.data.attributes.country']} | Owner: ${data['CloudHTTPRequestVirusTotalIPEnrichment.data.attributes.as_owner']}"
        version_constraint: ~1
    SummarizeEnrichment:
        id: bdfecafafdb44919a458fcf51d6b93a7_98dec86072334d24b37dd798098cfd63
        name: Charlotte AI - LLM Completion - Summarize TI enrichment
        next:
            - SendEmail
        properties:
            data_to_include:
                - ${data['WorkflowCustomVariable.ip_enrichment']}
            model_name: Claude Sonnet 4
            temperature: 0
            user_prompt: "You are a CrowdStrike threat analyst. Summarize the VirusTotal enrichment result for the IP below: reputation, malicious/suspicious verdict counts, country, and owner. Give an overall risk assessment and recommended next steps. Be concise and actionable. Respond with raw HTML only (headings, lists, bold) — do NOT wrap the response in markdown code fences such as ```html."
        version_constraint: ~0
    SendEmail:
        id: 07413ef9ba7c47bf5a242799f59902cc
        name: Send email - TI enrichment summary
        properties:
            to:
                - ${data['notify_email']}
            subject: "[Falcon Fusion] VirusTotal IP Enrichment Report - ${data['ip']}"
            msg: "<html><body>${data['SummarizeEnrichment.FaaS.nlpassistantapi.llminvocator_handler.completion']}</body></html>"
            msg_type: html
        version_constraint: ~1
output_fields: []

SHA-256: 1b0591149a3e7b13a8d356061f1f52a76ab0337be41fc2850cff71a85fc83cd9