Skip to main content

Talos Feed

This Integration is part of the Talos Feed Pack.#

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

Use the Talos Feed integration to get indicators from the feed.

Configure Talos Feed in Cortex#

ParameterDescriptionRequired
feedFetch indicatorsFalse
feedReputationIndicator ReputationFalse
feedReliabilitySource ReliabilityTrue
tlp_colorThe Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlpFalse
feedExpirationPolicyExpiration MethodFalse
feedExpirationIntervalFalse
feedFetchIntervalFeed Fetch IntervalFalse
urlTalos Endpoint URLTrue
feedTagsTagsFalse
feedBypassExclusionListBypass exclusion listFalse
insecureTrust any certificate (not secure)False
proxyUse system proxy settingsFalse
feedFetch indicatorsFalse
feedFetch indicatorsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

talos-get-indicators#


Gets indicators from the feed.

Base Command#

talos-get-indicators

Input#

Argument NameDescriptionRequired
limitThe maximum number of results to return. The default value is 10.Optional

Context Output#

There is no context output for this command.

Command Example#

!talos-get-indicators

Human Readable Output#

valuetype
60.249.23.235IP