|
| 1 | +from unittest.mock import MagicMock, patch |
| 2 | + |
| 3 | +from api_app.analyzers_manager.file_analyzers.cuckoo_scan import CuckooAnalysis |
| 4 | + |
| 5 | +from .base_test_class import BaseFileAnalyzerTest |
| 6 | + |
| 7 | + |
| 8 | +class TestCuckooAnalysis(BaseFileAnalyzerTest): |
| 9 | + analyzer_class = CuckooAnalysis |
| 10 | + |
| 11 | + def get_mocked_response(self): |
| 12 | + # Mock Session and its methods |
| 13 | + mock_session = MagicMock() |
| 14 | + |
| 15 | + # Mock POST response (submit file) |
| 16 | + mock_post_response = MagicMock() |
| 17 | + mock_post_response.status_code = 200 |
| 18 | + mock_post_response.json.return_value = {"task_id": 123} |
| 19 | + mock_session.post.return_value = mock_post_response |
| 20 | + |
| 21 | + # Mock GET for polling -> "reported" status |
| 22 | + mock_poll_response = MagicMock() |
| 23 | + mock_poll_response.json.return_value = {"task": {"status": "reported"}} |
| 24 | + |
| 25 | + # Mock GET for final report |
| 26 | + mock_report_response = MagicMock() |
| 27 | + mock_report_response.json.return_value = { |
| 28 | + "signatures": [], |
| 29 | + "suricata": {"alerts": []}, |
| 30 | + "network": {"http": [], "domains": [], "dns": []}, |
| 31 | + "info": {"score": 5, "machine": {}, "id": "cuckoo123"}, |
| 32 | + "target": {"file": {"type": "exe", "yara": []}}, |
| 33 | + } |
| 34 | + |
| 35 | + # Order of GET calls: first poll, then report |
| 36 | + mock_session.get.side_effect = [mock_poll_response, mock_report_response] |
| 37 | + |
| 38 | + # Patch requests.Session to return our mocked session |
| 39 | + return patch( |
| 40 | + "api_app.analyzers_manager.file_analyzers.cuckoo_scan.requests.Session", |
| 41 | + return_value=mock_session, |
| 42 | + ) |
| 43 | + |
| 44 | + def get_extra_config(self): |
| 45 | + # Create a hardcoded fake session for direct injection |
| 46 | + fake_session = MagicMock() |
| 47 | + fake_post = MagicMock() |
| 48 | + fake_post.status_code = 200 |
| 49 | + fake_post.json.return_value = {"task_id": 123} |
| 50 | + fake_session.post.return_value = fake_post |
| 51 | + |
| 52 | + fake_poll = MagicMock() |
| 53 | + fake_poll.json.return_value = {"task": {"status": "reported"}} |
| 54 | + fake_report = MagicMock() |
| 55 | + fake_report.json.return_value = { |
| 56 | + "signatures": [], |
| 57 | + "suricata": {"alerts": []}, |
| 58 | + "network": {"http": [], "domains": [], "dns": []}, |
| 59 | + "info": {"score": 5, "machine": {}, "id": "cuckoo123"}, |
| 60 | + "target": {"file": {"type": "exe", "yara": []}}, |
| 61 | + } |
| 62 | + fake_session.get.side_effect = [fake_poll, fake_report] |
| 63 | + |
| 64 | + return { |
| 65 | + "_api_key_name": "dummy_key", |
| 66 | + "_url_key_name": "http://fake-cuckoo/", |
| 67 | + "max_post_tries": 1, |
| 68 | + "max_poll_tries": 1, |
| 69 | + "session": fake_session, # 👈 directly attach session |
| 70 | + } |
0 commit comments