I'm trying to add a comment to a jira ticket with a variable that contains all results of .match
Using the result from a http get to virustotal, I was able to build a smart variable that contains this data. I did this first because each vendor (PrecisionSec,PhishLabs,SecureBrain) has a unique dot walk, so I needed to hardcode the names, one by one to get the result.
{{webResponse.body.data.attributes.last_analysis_results.PrecisionSec.category}}
My issue is, when I use .match against the resulting data, I'm only getting one "*vendor*:harmless" added to the comment or audit log. This will be changed to malicious once I can validate everything is working as expected. If I need to convert to a list, or iterate over it as an array some other way, I'm not sure how.
https://regex101.com/r/xra4Xb/1
Regex I'm using:
(\*\w+:\*\s+harmless)+
Data:
VTDomainMalVendors: *Antiy-AVL*: malicious, *Kaspersky:* harmless, *Avira:* harmless, *Bkav:* undetected, *CMC Threat Intelligence:* harmless, *Snort IP sample list:* harmless, *0xSI_f33d:* undetected, *ViriBack:* harmless, *PhishLabs:* undetected, *K7AntiVirus:* harmless, *CINS Army.:* harmless, *Quttera:* harmless, *PrecisionSec:* undetected, *OpenPhish:* harmless, *VX Vault:* harmless, *ArcSight Threat Intelligence:* undetected, *AlienVault:* harmless, *Sophos:* harmless, *Phishtank:* harmless, *Cyan:* undetected, *Spam404:* harmless, *SecureBrain:* harmless, *CRDF:* harmless, *Fortinet:* harmless, *alphaMountain.ai:* , *Lionic:* harmless, *Cyble:* harmless, *Seclookup:* harmless, *Xcitium Verdict Cloud:* harmless, *Google Safebrowsing:* harmless, *SafeToOpen:* undetected, *ADMINUSLabs:* harmless, *ESTsecurity:* harmless, *Juniper Networks:* harmless, *Heimdal Security:* harmless, *AutoShun:* undetected, *Trustwave:* harmless, *AICC (MONITORAPP:* harmless, *CyRadar:* harmless, *Dr.Web:* , *Emsisoft:* harmless, *Abusix:* harmless, *Webroot:* harmless, *securolytics:* harmless, *AlphaSOC:* undetected, *Acronis:* harmless, *Quick Heal:* harmless, *URLQuery:* undetected, *Viettel Threat Intelligence* harmless, *DNS8:* harmless, *benkow.cc* , *EmergingThreats:* harmless, *Chong Lua Dao:* harmless, *Yandex Safebrowsing:* harmless, *Lumu:* undetected, *zvelo:* undetected, *Bfore.Ai PreCrime:* , *BitDefender:* harmless, *Blueliv:* harmless, *Certego:* harmless, *desenmascara.me:* , *ESET:* harmless, *Forcepoint ThreatSeeker:* harmless, *G-Data:* harmless, *GreenSnow:* harmless, *IPsum:* harmless, *Malwared:* harmless, *MalwarePatrol:* harmless, *malwares.com URL checker:* , *Phishing Database:* harmless, *PREBYTES:* harmless, *Scantitan:* harmless, *SCUMWARE.org:* , *SOCRadar:* harmless, *StopForumSpam:* harmless, *Sucuri SiteCheck:* harmless, *ThreatHive:* harmless, *Threatsourcing:* harmless, *URLhaus:* harmless, *ZeroCERT:* harmless, *Cluster25:* undetected, *Criminal IP:* undetected, *CrowdSec:* undetected, *Netcraft:* undetected, *PhishFort:* undetected, *Segasec:* undetected, *VIPRE:* undetected
The result is one capture group and multiple matches. How do I display the multiple matches in one comment?
Thank you kindly.