Cyberint Feed
Cyberint Pack.#
This Integration is part of theSupported versions
Supported Cortex XSOAR versions: 6.9.0 and later.
Use the Cyberint Feed integration to get indicators from the feed.
#
Configure Cyberint Feed on Cortex XSOARNavigate to Settings > Integrations > Servers & Services.
Search for Cyberint Feed.
Click Add instance to create and configure a new integration instance.
Parameter Description Required Cyberint API URL Example: https://yourcompany.cyberint.io
True API access token True Fetch indicators Should be checked (true) False Indicator Type Which indicator types to fetch True Confidence Confidence about the indicator details. The value of confidence to fetch indicators from. The value between 0-100. False Severity Severity about the indicator details. The value of severity to fetch indicators from. The value between 0-100. False Tags Supports CSV values. False Bypass exclusion list When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. False Trust any certificate (not secure) False Use system proxy settings False Click Test to validate the URLs, token, and connection.
#
CommandsYou can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
#
cyberint-get-indicatorsGets indicators from the feed.
#
Base Commandcyberint-get-indicators
#
InputArgument Name | Description | Required |
---|---|---|
limit | The maximum number of results to return. The default value is 10. Default is 10. | Optional |
#
Context OutputPath | Type | Description |
---|---|---|
Cyberint.ioc_value | String | The indicator value. |
Cyberint.ioc_type | String | The indicator type. |
Cyberint.description | String | The feed description. |
Cyberint.detected_activity | String | The feed detected activity. |
Cyberint.observation_date | String | The feed observation date. |
Cyberint.severity_score | String | The feed severity score. |
Cyberint.confidence | String | The feed confidence. |
#
Command example!cyberint-get-indicators limit=10 execution-timeout=700
#
Context Example#
Human Readable Output#
Indicators from Cyberint Feed:
Value Type ioc1 File ioc2 File ioc3 File ioc4 File ioc5 File ioc6 File ioc7 File ioc8 File ioc9 File ioc10 File