<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Postman API development tool to experience SandBlast API in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Using-Postman-API-development-tool-to-experience-SandBlast-API/m-p/107957#M5492</link>
    <description>&lt;P&gt;i tried this and i worked. but the files is not shown in smartcenter. ist this correct?&lt;/P&gt;&lt;P&gt;What format ist the full report?&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jan 2021 17:14:44 GMT</pubDate>
    <dc:creator>David_T</dc:creator>
    <dc:date>2021-01-15T17:14:44Z</dc:date>
    <item>
      <title>Using Postman API development tool to experience SandBlast API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Using-Postman-API-development-tool-to-experience-SandBlast-API/m-p/40582#M2729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;another easy way to test and experience the SandBlast API is via a API development tool called &lt;A class="link-titled" href="https://www.getpostman.com/" title="https://www.getpostman.com/"&gt;Postman | API Development Environment&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can store API samples in collections in the left of the interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="71364" class="image-1 jive-image" height="333" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71364_pastedImage_2.png" width="274" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) File upload to single image&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Create a post request to your appliance´s API address for file upload:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="71372" class="image-5 jive-image" height="85" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71372_pastedImage_14.png" width="452" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Populate the request body:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="71370" class="image-3 jive-image" height="211" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71370_pastedImage_5.png" width="861" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;"request" to emulate on Win7/Office 2013 image only (you can omit the "extraction" feature if you want but it does not hurt here :-):&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #505050; background-color: #ffffff; font-weight: normal; font-size: 12px;"&gt;&lt;SPAN data-offset-key="7ds4i-0-0"&gt;&lt;SPAN data-text="true"&gt;{"request" :{ "features":[ "te", "extraction"],"te": {"reports": ["xml", "pdf"], "images":[{"id": "5e5de275-a103-4f67-b55b-47532918fa59","revision":1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-offset-key="7ds4i-1-0" style="color: #505050; background-color: #ffffff; font-weight: normal; font-size: 12px;"&gt;&lt;SPAN data-text="true"&gt;}]}}}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN data-offset-key="7ds4i-1-0" style="color: #505050; background-color: #ffffff; font-weight: normal; font-size: 12px;"&gt;&lt;SPAN data-text="true"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="background-color: #ffffff; color: #3d3d3d; font-weight: normal; font-size: 15px;"&gt;On "file" you simply need to specify the file you want to upload.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN data-offset-key="7ds4i-1-0" style="color: #505050; background-color: #ffffff; font-weight: normal; font-size: 15px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN data-offset-key="7ds4i-1-0" style="color: #505050; background-color: #ffffff; font-weight: normal; font-size: 15px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2)&amp;nbsp;Request result after emulation&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;To request the current status of emulation and the final verdict you need to query for the file´s hash via:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG __jive_id="71373" class="image-6 jive-image" height="92" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71373_pastedImage_15.png" width="461" /&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Just create the following raw body and adjust the file sha1 hash:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG __jive_id="71374" class="image-7 jive-image" height="112" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71374_pastedImage_16.png" width="602" /&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;As a result you get something like:&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 13px;"&gt;{&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "response" : [&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "features" : [ "te" ],&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "file_type" : "doc",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "md5" : "764f4cc91ebd096a1908934c32fc7984",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px; color: #0000ff;"&gt; "sha1" : "0be4329cb4b4eeb4ebc58e7cc2a05b0945af1458",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "sha256" : "bf79ad4cbb4b3c41ecda0dbc34bb799fa3157572",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "status" : {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "code" : 1006,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "label" : "PARTIALLY_FOUND",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "message" : "The request has been partially served"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; },&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "te" : {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "combined_verdict" : "Malicious",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "confidence" : 3,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "images" : [&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "id" : "5e5de275-a103-4f67-b55b-47532918fa59",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "report" : {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "full_report" : "",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "report_version" : 1,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "verdict" : "Malicious",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px; color: #0000ff;"&gt; "xml_report" : "64845505-20CF-4C4B-8F18-10B173517DB1"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; },&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "revision" : 1,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; "status" : "found"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; },&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;For getting the report XML you need to note the "xml_report" ID from this output.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding: 0px;"&gt;&lt;STRONG&gt;3)&amp;nbsp;Get XML report for malicious file&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;To&amp;nbsp;get the XML report data use the "xml_report" ID&amp;nbsp;you get via the previous file hash query:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG __jive_id="71375" class="jive-image image-8" height="81" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71375_pastedImage_20.png" width="692" /&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG __jive_id="71376" class="image-9 jive-image" height="111" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71376_pastedImage_21.png" width="676" /&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Expected result:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 13px;"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;&amp;lt;report&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;reportDate&amp;gt;Wed Jul 11 13:07:10 2018&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;&amp;lt;/reportDate&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;CPULevelDetection&amp;gt;false&amp;lt;/CPULevelDetection&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;System&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Osname&amp;gt;Windows 7&amp;lt;/Osname&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;OsInfo&amp;gt;Microsoft Windows 7 32 bit, Office 2013, Adobe Acrobat Reader 11.0, Adobe Flash Player 12, Java SE 1.7.0&amp;lt;/OsInfo&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;OsUID&amp;gt;5e5de275-a103-4f67-b55b-47532918fa59&amp;lt;/OsUID&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;OsRev&amp;gt;234&amp;lt;/OsRev&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;/System&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;ScreenShotsNames&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;ScreenShot&amp;gt;ScreenShot1.bmp&amp;lt;/ScreenShot&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;ScreenShot&amp;gt;ScreenShot2.bmp&amp;lt;/ScreenShot&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;ScreenShot&amp;gt;ScreenShot3.bmp&amp;lt;/ScreenShot&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;ScreenShot&amp;gt;ScreenShot4.bmp&amp;lt;/ScreenShot&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;/ScreenShotsNames&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Activities&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Command&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;CommandName&amp;gt;ProcessEvent&amp;lt;/CommandName&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;ID&amp;gt;8&amp;lt;/ID&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Time&amp;gt;00:00:09&amp;lt;/Time&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Src&amp;gt;C:\Program Files\Microsoft Office\Office15\WINWORD.EXE&amp;lt;/Src&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Dst&amp;gt;C:\Windows\System32\calc.exe&amp;lt;/Dst&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Action&amp;gt;Create&amp;lt;/Action&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;/Command&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;Command&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt; &amp;lt;CommandName&amp;gt;RegistryEvent&amp;lt;/CommandName&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 13px;"&gt;[...]&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Attached you can find the samples as an export from my Postman collections which you can simply import to your Postman installation:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;IMG __jive_id="71378" class="jive-image image-10" height="203" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71378_pastedImage_27.png" width="248" /&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;So have fun with SandBlast API.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Regards Thomas&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 08:19:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Using-Postman-API-development-tool-to-experience-SandBlast-API/m-p/40582#M2729</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2018-10-12T08:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using Postman API development tool to experience SandBlast API</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Using-Postman-API-development-tool-to-experience-SandBlast-API/m-p/107957#M5492</link>
      <description>&lt;P&gt;i tried this and i worked. but the files is not shown in smartcenter. ist this correct?&lt;/P&gt;&lt;P&gt;What format ist the full report?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 17:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Using-Postman-API-development-tool-to-experience-SandBlast-API/m-p/107957#M5492</guid>
      <dc:creator>David_T</dc:creator>
      <dc:date>2021-01-15T17:14:44Z</dc:date>
    </item>
  </channel>
</rss>

