Skip to main content

DeCYFIR

This Integration is part of the DeCYFIR Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.5.0 and later.

DeCYFIR API's provides External Threat Landscape Management insights. This integration was integrated and tested with version v2 of decyfir

Configure DeCYFIR in Cortex#

ParameterDescriptionRequired
Incident typeFalse
DeCYFIR Server URL (e.g. https://decyfir.cyfirma.com)True
DeCYFIR API KeyTrue
Fetch incidentsFalse
Trust any certificate (not secure)False
Use system proxy settingsFalse
How much time before the first fetch to retrieve incidentsFalse
Maximum number of incidents per fetchThe maximum number of incidents to fetch per sub-category.False

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

decyfir-takedown-initiate#


Initiate a take down request.

Base Command#

decyfir-takedown-initiate

Input#

Argument NameDescriptionRequired
alert_idThe ID of the alert for which to initiate the take down request.Required

Context Output#

There is no context output for this command.

Command example#

!decyfir-takedown-initiate alert_id=123

Human Readable Output#

The take down request was initiated successfully.

decyfir-takedown-list#


Get take down list.

Base Command#

decyfir-takedown-list

Input#

Argument NameDescriptionRequired
sub_categoryThe sub-category for which to retrieve the take down list. If not provided, the take down list for all sub-categories will be retrieved.Optional
sizeThe number of records to retrieve. Default is 100.Optional
pageThe page number to retrieve. Default is 0.Optional

Context Output#

There is no context output for this command.

Command example#

!decyfir-takedown-list

Human Readable Output#

The take down list retrieved successfully..