Skip to main content

Cyberint Takedowns

This Integration is part of the Cyberint Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.9.0 and later.

Use the Cyberint Takedowns integration to manage takedowns requests

Configure Cyberint Takedowns on Cortex XSOAR#

  1. Navigate to Settings > Integrations > Servers & Services.

  2. Search for Cyberint Takedowns.

  3. Click Add instance to create and configure a new integration instance.

    ParameterDescriptionRequired
    Cyberint API URLExample: https://yourcompany.cyberint.ioTrue
    Company NameTrue
    API access tokenTrue
    Trust any certificate (not secure)False
    Use system proxy settingsFalse
  4. Click Test to validate the URLs, token, and connection.

Commands#

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

cyberint-retrieve-takedowns#


Retrieve takedowns requests.

Base Command#

cyberint-retrieve-takedowns

Input#

Argument NameDescriptionRequired
customer_idCustomer ID.True
reasonReason for the takedown request.True
urlURL for the takedown request.True
original_urlOriginal URL.Optional
customerCustomer.Optional
statusStatus.Optional
brandBrand.Optional
alert_ref_idAlert reference ID.Optional
alert_idAlert ID.Optional
hosting_providersHosting providers.Optional
name_serversName servers.Optional
escalation_actionsEscalation actions.Optional
last_escalation_dateLast escalation date.Optional
last_status_change_dateLast status change date.Optional
last_seen_dateLast seen date.Optional
created_dateCreated date.Optional
status_reasonStatus reason.Optional
idTakedown request ID.Optional

Context Output#

PathTypeDescription
Cyberint.takedowns_list.reasonStringReason for the takedown request.
Cyberint.takedowns_list.urlStringURL for the takedown request.
Cyberint.takedowns_list.original_urlStringOriginal URL.
Cyberint.takedowns_list.customerStringCustomer.
Cyberint.takedowns_list.statusStringStatus.
Cyberint.takedowns_list.brandStringBrand.
Cyberint.takedowns_list.alert_ref_idStringAlert reference ID.
Cyberint.takedowns_list.alert_idNumberAlert ID.
Cyberint.takedowns_list.hosting_providersArrayList of hosting providers.
Cyberint.takedowns_list.name_serversArrayList of name servers.
Cyberint.takedowns_list.escalation_actionsArrayList of escalation actions.
Cyberint.takedowns_list.last_escalation_dateStringLast escalation date (ISO 8601).
Cyberint.takedowns_list.last_status_change_dateStringLast status change date.
Cyberint.takedowns_list.last_seen_dateStringLast seen date.
Cyberint.takedowns_list.created_dateStringCreated date.
Cyberint.takedowns_list.status_reasonStringStatus reason.
Cyberint.takedowns_list.idStringTakedown request ID (UUID).

Command example#

!cyberint-retrieve-takedowns customer_id=Cyberint reason=phishing url=http://hacking.enterprises original_url=https://cyberint.com brand=Cyberint

Context Example#

{
"Cyberint.takedowns": [
{
"data": {
"takedown_requests": [
{
"reason": "phishing",
"url": "string",
"original_url": "string",
"customer": "string",
"status": "pending",
"brand": "string",
"alert_ref_id": "string",
"alert_id": 0,
"hosting_providers": [
"string"
],
"name_servers": [
"string"
],
"escalation_actions": [
"string"
],
"last_escalation_date": "2019-08-24T14:15:22Z",
"last_status_change_date": "2019-08-24T14:15:22Z",
"last_seen_date": "2019-08-24T14:15:22Z",
"created_date": "2019-08-24T14:15:22Z",
"status_reason": "string",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08"
}
]
}
}
]
}

Human Readable Output#

Takedowns#
NameTypeDescription
reasonStringReason for the takedown request.
urlStringURL for the takedown request.
original_urlStringOriginal URL.
customerStringCustomer.
statusStringStatus.
brandStringBrand.
alert_ref_idStringAlert reference ID.
alert_idNumberAlert ID.
hosting_providersArrayList of hosting providers.
name_serversArrayList of name servers.
escalation_actionsArrayList of escalation actions.
last_escalation_dateStringLast escalation date (ISO 8601).
last_status_change_dateStringLast status change date.
last_seen_dateStringLast seen date.
created_dateStringCreated date.
status_reasonStringStatus reason.
idStringTakedown request ID (UUID).

cyberint-takedown-url#


Submit takedown request.

Base Command#

cyberint-takedown-url

Input#

Argument NameDescriptionRequired
customerCustomer.True
reasonReason for the takedown request.Required
urlURL for the takedown request.Required
brandBrand.Optional
original_urlOriginal URL.Optional
alert_idAlert ID.Optional
noteNote.Optional

Context Output#

PathTypeDescription
Cyberint.takedowns_submit.reasonStringReason for the takedown request.
Cyberint.takedowns_submit.urlStringURL for the takedown request.
Cyberint.takedowns_submit.original_urlStringOriginal URL.
Cyberint.takedowns_submit.customerStringCustomer.
Cyberint.takedowns_submit.statusStringStatus.
Cyberint.takedowns_submit.brandStringBrand.
Cyberint.takedowns_submit.alert_ref_idStringAlert reference ID.
Cyberint.takedowns_submit.alert_idNumberAlert ID.
Cyberint.takedowns_submit.hosting_providersArrayList of hosting providers.
Cyberint.takedowns_submit.name_serversArrayList of name servers.
Cyberint.takedowns_submit.escalation_actionsArrayList of escalation actions.
Cyberint.takedowns_submit.last_escalation_dateStringLast escalation date (ISO 8601).
Cyberint.takedowns_submit.last_status_change_dateStringLast status change date.
Cyberint.takedowns_submit.last_seen_dateStringLast seen date.
Cyberint.takedowns_submit.created_dateStringCreated date.
Cyberint.takedowns_submit.status_reasonStringStatus reason.
Cyberint.takedowns_submit.idStringTakedown request ID (UUID).

Command example#

!cyberint-takedown-url customer=Cyberint reason=Description url=http://hacking.enterprises

Context Example#

{
"Cyberint.takedowns": [
{
"customer": "string",
"reason": "phishing",
"url": "string",
"brand": "string",
"original_url": "string",
"alert_id": 0,
"note": "string"
}
]
}

Human Readable Output#

Takedown submit response#
NameTypeDescription
reasonStringReason for the takedown request.
urlStringURL for the takedown request.
original_urlStringOriginal URL.
customerStringCustomer.
statusStringStatus.
brandStringBrand.
alert_ref_idStringAlert reference ID.
alert_idNumberAlert ID.
hosting_providersArrayList of hosting providers.
name_serversArrayList of name servers.
escalation_actionsArrayList of escalation actions.
last_escalation_dateStringLast escalation date (ISO 8601).
last_status_change_dateStringLast status change date (ISO 8601).
last_seen_dateStringLast seen date (ISO 8601).
created_dateStringCreated date (ISO 8601).
status_reasonStringStatus reason.
idStringTakedown request ID (UUID).