Skip to main content

ReliaquestTakedown

This Integration is part of the ReliaQuest Takedown Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.9.0 and later.

This is Reliaquest DRP Takedown integration. It enables xsoar user to create and manage takedowns. This integration was integrated and tested with version 6.9.0 of ReliaquestTakedown.

This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.

Configure ReliaquestTakedown in Cortex#

ParameterDescriptionRequired
DS SearchLight API URLEnter the Digital Shadows SearchLight API URL.True
Account IDAccount ID associated with this account.True
API KeyEnter the API Key for this account.True
API SecretEnter the API Secret for this account.True
Trust any certificate (not secure)Verify certificate.False
First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 2 months, 1 years or datetime in "%Y-%m-%d %H:%M:%S" format)First fetchFalse
Fetch LimitThe maximum number of takedown to fetch.True
TakedownThis controls how often the integration will perform a fetch takwdown command.False
Incident typeFalse
Fetch incidentsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

rq-takedown-create#


Create takedown command takes brand id, type, target and portal shortcode (optional) and returns the created takedown in response.

Base Command#

rq-takedown-create

Input#

Argument NameDescriptionRequired
brand_idBrand Id.Required
typeTakedown Type.Required
targetTarget URL.Required
portal_idPortal shortcode.Optional

Context Output#

There is no context output for this command.

rq-takedown-list-brand#


Returns list of allowed brand details for takedown.

Base Command#

rq-takedown-list-brand

Input#

Argument NameDescriptionRequired

Context Output#

There is no context output for this command.

rq-takedown-create-comment#


Create comment for a takedown.

Base Command#

rq-takedown-create-comment

Input#

Argument NameDescriptionRequired
commentComment for takedown. Default is Investigate the tekedown.Required
takedown_idTakedown id. Default is UUID.Required

Context Output#

There is no context output for this command.

rq-takedown-upload-attachment#


Uploads attachment for takedown.

Base Command#

rq-takedown-upload-attachment

Input#

Argument NameDescriptionRequired
file_idNo description provided.Required
takedown_idNo description provided.Required

Context Output#

There is no context output for this command.

rq-takedown-download-attachment#


Downloads attachment for takedown.

Base Command#

rq-takedown-download-attachment

Input#

Argument NameDescriptionRequired
attachment_idNo description provided.Required

Context Output#

There is no context output for this command.

Incident Mirroring#

You can enable incident mirroring between Cortex XSOAR incidents and ReliaquestTakedown corresponding events (available from Cortex XSOAR version 6.0.0). To set up the mirroring:

  1. Enable Fetching incidents in your instance configuration.

Newly fetched incidents will be mirrored in the chosen direction. However, this selection does not affect existing incidents. Important Note: To ensure the mirroring works as expected, mappers are required, both for incoming and outgoing, to map the expected fields in Cortex XSOAR and ReliaquestTakedown.