Skip to main content

Intel471 Watcher Alerts

This Integration is part of the Intel471 Feed Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Intel 471's watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.

Configure Intel471 Watcher Alerts in Cortex#

ParameterDescriptionRequired
Fetches incidentsFalse
UsernameAPI usernameFalse
PasswordAPI keyFalse
Intel 471 backendIntel 471 backend selectionTrue
Maximum number of incidents per fetchFalse
Traffic Light Protocol ColorThe Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feedFalse
Incidents Fetch IntervalFalse
Watcher group UID(s)The UID(s) of the watcher group(s) for which alerts should be fetchedFalse
First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)How far back in time to go when performing the first fetch.False
Use system proxy settingsFalse
Trust any certificate (not secure)False

Fetched Incidents Data#


Returns the Intel 471 Watcher Alerts. Creates incidents in Cortex XSOAR and populate the incident details field with the alert content.