Skip to main content

ZeroFox Key Incidents

This Integration is part of the ZeroFox Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.1.0 and later.

Cloud-based SaaS to detect risks found on social media and digital channels. This integration was integrated and tested with version 1.4.0 of ZeroFoxKey.

Configure ZeroFox Key Incidents in Cortex#

ParameterRequired
URL (e.g., https://api.zerofox.com/)True
Fetch incidentsFalse
UsernameTrue
PasswordTrue
First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)False
Incident typeFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

zerofox-get-key-incident-attachment#


Fetches a Key Incident Attachment by ID and uploads it to the current investigation War Room.

Base Command#

zerofox-get-key-incident-attachment

Input#

Argument NameDescriptionRequired
attachment_idThe ID of the Key Incident Attachment.Required

Context Output#

PathTypeDescription
File.SizeNumberThe size of the file.
File.SHA1StringThe SHA1 hash of the file.
File.SHA256StringThe SHA256 hash of the file.
File.SHA512StringThe SHA512 hash of the file.
File.NameStringThe name of the file.
File.SSDeepStringThe SSDeep hash of the file.
File.EntryIDStringThe entry ID of the file.
File.InfoStringFile information.
File.TypeStringThe file type.
File.MD5StringThe MD5 hash of the file.
File.ExtensionStringThe file extension.

Incident Mirroring#

You can enable incident mirroring between Cortex XSOAR incidents and ZeroFox Key Incidents corresponding events (available from Cortex XSOAR version 6.0.0). To set up the mirroring:

  1. Enable Fetching incidents in your instance configuration.

Newly fetched incidents will be mirrored in the chosen direction. However, this selection does not affect existing incidents. Important Note: To ensure the mirroring works as expected, mappers are required, both for incoming and outgoing, to map the expected fields in Cortex XSOAR and ZeroFox Key Incidents.