BechtleDarkWebScan
Notifies you if login credentials to your company are being sold on the dark web.
Identity and Access Management · Bechtle Dark Web Scan
Details
| ID | BechtleDarkWebScan |
|---|---|
| Provider | Bechtle |
| Category | Identity and Access Management |
| From Version | 6.10.0 |
| Docker Image | demisto/python3:3.12.13.12042988 |
README
The dark web scan integration notifies you if login credentials to your company are being sold on the dark web.
Configure BechtleDarkWebScan in Cortex
| Parameter | Description | Required |
|---|---|---|
| API Key | Your darkwebscan.app API Key | True |
| Additional request headers | Additional request headers | False |
| Fetch incidents | Whether to fetch incidents | False |
| Incidents Fetch Interval | The interval incidents should be fetched | False |
| First fetch time | The first fetch time | False |
| Incident type | The incident type | False |
| Maximum incidents per fetch | Maxmimum amount of incidents per fetch | False |
| Trust any certificate (not secure) | Whether to trust any certificate | False |
| Use system proxy settings | Whether to use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
darkwebscan-getcompanies
Returns a list of all companies associated with your API key.
Base Command
darkwebscan-getcompanies
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.Companies | String | All companies that you have access to. |
darkwebscan-getleaks
Returns leaked credentials for a given company_id.
Base Command
darkwebscan-getleaks
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve leaked credentials for. | Required |
| only_new | Only return leaks not previously seen by this integration instance. Possible values are: true, false. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.LeakedCredentials | String | Leaked credentials for a given company_id. |
darkwebscan-getosint
Returns OSINT information about the associated domain of a given company_id.
Base Command
darkwebscan-getosint
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve OSINT information for. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.OSINT | String | OSINT information (email addresses, subdomains, …) for the associated domain of a given company_id. |
darkwebscan-getemailsecurity
Returns information about the email security for the associated domain of a given company_id.
Base Command
darkwebscan-getemailsecurity
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve email security information for. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.EmailSecurity | String | Email security (SPF, DMARC, DANE, …) for the associated domain of a given company_id. |
darkwebscan-getwaf
Returns Web Application Firewall Status information about the associated domain of a given company_id.
Base Command
darkwebscan-getwaf
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve Web Application Firewall Status information for. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.WAF | String | Web Application Firewall status and product name (if applicable) |
darkwebscan-resetcontext
Resets integration context for the DarkWebScan. May result in many alerts reappearing.
Base Command
darkwebscan-resetcontext
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.ResetContext | String | Returns text whether the reset was successful or not. |
Configuration parameters
apikey— API Key (required)addreqheaders— Additional request headersisFetch— Fetch incidentsincidentFetchInterval— Incidents Fetch Intervalfirst_fetch— First fetch timeincidentType— Incident typemax_fetch— Maximum incidents per fetchinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (6)
-
darkwebscan-getcompaniesReturns a list of all companies associated with your API key.
-
darkwebscan-getemailsecurityReturns information about the email security for the associated domain of a given company_id.
-
darkwebscan-getleaksReturns leaked credentials for a given company_id.
-
darkwebscan-getosintReturns OSINT information about the associated domain of a given company_id.
-
darkwebscan-getwafReturns Web Application Firewall Status information about the associated domain of a given company_id.
-
darkwebscan-resetcontextResets integration context for the DarkWebScan. May result in many alerts reappearing.
## BechtleDarkWebScan ### Prerequisites Active subscription at [www.darkwebscan.app](https://darkwebscan.app?utm_source=cortexhelpmd) ### Setup 1. Retrieve your API key from the settings page of your dashboard at www.darkwebscan.app 2. Paste the API key into the settings of this integration in the field "API Key" 3. (Optional: Add additional request headers in the field "Additional request headers" as key:value pairs, one request header per line) 4. (Optional: If you want incidents to be created automatically out of the retrieved data, activate the checkbox "Fetches issues" in the "Collect" section of the setup) 5. Test the connection 6. If the connection test was successful, click "Save & Exit"