Skip to main content

SpurContextAPI

This Integration is part of the Spur Context API Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

Enrich indicators using the Spur Context API. This integration was integrated and tested with version 2 of SpurContextAPI.

Configure SpurContextAPI on Cortex XSOAR#

  1. Navigate to Settings > Integrations > Servers & Services.

  2. Search for SpurContextAPI.

  3. Click Add instance to create and configure a new integration instance.

    ParameterDescriptionRequired
    Server URL (e.g. https://api.spur.us/)False
    API TokenTrue
    Source ReliabilityReliability of the source providing the intelligence data.False
    Use system proxy settingsFalse
  4. Click Test to validate the URLs, token, and connection.

Commands#

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

spur-context-api-enrich#


Enrich indicators using the Spur Context API.

Base Command#

spur-context-api-enrich

Input#

Argument NameDescriptionRequired
ipIP address to enrich.Required

Context Output#

PathTypeDescription
SpurContextAPI.Context.ipstringIP that was enriched
SpurContextAPI.Context.asobjectAutonomous System details for an IP Address.
SpurContextAPI.Context.organizationstringThe organization using this IP address.
SpurContextAPI.Context.infrastructurestringThe primary infrastructure type that this IP address supports. Common tags are MOBILE and DATACENTER.
SpurContextAPI.Context.locationobjectData-center or IP Hosting location based on MaxMind GeoLite.
SpurContextAPI.Context.servicesarrayThe different types of proxy or VPN services that are running on this IP address
SpurContextAPI.Context.tunnelsarrayDifferent VPN or proxy tunnels that are currently in-use on this IP address
SpurContextAPI.Context.risksarrayRisks that we have determined based on our collection of data.
SpurContextAPI.Context.client_concentrationobjectThe strongest location concentration for clients using this IP address.
SpurContextAPI.Context.client_countriesnumberThe number of countries that we have observed clients located in for this IP address
SpurContextAPI.Context.client_spreadnumberThe total geographic area in kilometers where we have observed users
SpurContextAPI.Context.client_proxiesarrayThe different types of callback proxies we have observed on clients using this IP address.
SpurContextAPI.Context.client_countnumberThe average number of clients we observe on this IP address.
SpurContextAPI.Context.client_behaviorsarrayAn array of behavior tags for an IP Address.
SpurContextAPI.Context.client_typesarrayThe different type of client devices that we have observed on this IP address.

ip#


IP reputation command using the Spur Context API.

Base Command#

ip

Input#

Argument NameDescriptionRequired
ipIP address to enrich.Required

Context Output#

PathTypeDescription
DBotScore.ScorestringThe actual score.
DBotScore.IndicatorstringThe indicator that was tested.
DBotScore.TypestringThe indicator type.
DBotScore.VendorstringThe vendor used to calculate the score.
DBotScore.ReliabilityStringReliability of the source providing the intelligence data.
IP.AddressstringIP address.
IP.ASNstringThe autonomous system name for the IP address, for example: "AS8948".
IP.ASOwnerStringThe autonomous system owner of the IP.
IP.ClientTypesarrayThe organization name.
IP.Geo.CountrystringThe country in which the IP address is located.
IP.Organization.NamestringThe organization name.
IP.RisksarrayRisks that we have determined based on our collection of data.
IP.TunnelsarrayThe different types of proxy or VPN services that are running on this IP address.
SpurContextAPI.Context.ipstringIP that was enriched.
SpurContextAPI.Context.asobjectAutonomous System details for an IP Address.
SpurContextAPI.Context.organizationstringThe organization using this IP address.
SpurContextAPI.Context.infrastructurestringThe primary infracstructure type that this IP address supports. Common tags are MOBILE and DATACENTER.
SpurContextAPI.Context.locationobjectData-center or IP Hosting location based on MaxMind GeoLite.
SpurContextAPI.Context.servicesarrayThe different types of proxy or VPN services that are running on this IP address.
SpurContextAPI.Context.tunnelsarrayDifferent VPN or proxy tunnels that are currently in-use on this IP address.
SpurContextAPI.Context.risksarrayRisks that we have determined based on our collection of data.
SpurContextAPI.Context.client_concentrationobjectThe strongest location concentration for clients using this IP address.
SpurContextAPI.Context.client_countriesnumberThe number of countries that we have observed clients located in for this IP address.
SpurContextAPI.Context.client_spreadnumberThe total geographic area in kilometers where we have observed users.
SpurContextAPI.Context.client_proxiesarrayThe different types of callback proxies we have observed on clients using this IP address.
SpurContextAPI.Context.client_countnumberThe average number of clients we observe on this IP address.
SpurContextAPI.Context.client_behaviorsarrayAn array of behavior tags for an IP Address.
SpurContextAPI.Context.client_typesarrayThe different type of client devices that we have observed on this IP address.