BechtleDarkWebScan

Notifies you if login credentials to your company are being sold on the dark web.

Identity and Access Management · Bechtle Dark Web Scan

Details

IDBechtleDarkWebScan
ProviderBechtle
CategoryIdentity and Access Management
From Version6.10.0
Docker Imagedemisto/python3:3.12.13.12042988

README

The dark web scan integration notifies you if login credentials to your company are being sold on the dark web.

Configure BechtleDarkWebScan in Cortex

Parameter Description Required
API Key Your darkwebscan.app API Key True
Additional request headers Additional request headers False
Fetch incidents Whether to fetch incidents False
Incidents Fetch Interval The interval incidents should be fetched False
First fetch time The first fetch time False
Incident type The incident type False
Maximum incidents per fetch Maxmimum amount of incidents per fetch False
Trust any certificate (not secure) Whether to trust any certificate False
Use system proxy settings Whether to use system proxy settings False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

darkwebscan-getcompanies


Returns a list of all companies associated with your API key.

Base Command

darkwebscan-getcompanies

Input

There are no input arguments for this command.

Context Output

Path Type Description
BechtleDarkWebScan.Companies String All companies that you have access to.

darkwebscan-getleaks


Returns leaked credentials for a given company_id.

Base Command

darkwebscan-getleaks

Input

Argument Name Description Required
company_id ID of the company to retrieve leaked credentials for. Required
only_new Only return leaks not previously seen by this integration instance. Possible values are: true, false. Default is false. Optional

Context Output

Path Type Description
BechtleDarkWebScan.LeakedCredentials String Leaked credentials for a given company_id.

darkwebscan-getosint


Returns OSINT information about the associated domain of a given company_id.

Base Command

darkwebscan-getosint

Input

Argument Name Description Required
company_id ID of the company to retrieve OSINT information for. Required

Context Output

Path Type Description
BechtleDarkWebScan.OSINT String OSINT information (email addresses, subdomains, …) for the associated domain of a given company_id.

darkwebscan-getemailsecurity


Returns information about the email security for the associated domain of a given company_id.

Base Command

darkwebscan-getemailsecurity

Input

Argument Name Description Required
company_id ID of the company to retrieve email security information for. Required

Context Output

Path Type Description
BechtleDarkWebScan.EmailSecurity String Email security (SPF, DMARC, DANE, …) for the associated domain of a given company_id.

darkwebscan-getwaf


Returns Web Application Firewall Status information about the associated domain of a given company_id.

Base Command

darkwebscan-getwaf

Input

Argument Name Description Required
company_id ID of the company to retrieve Web Application Firewall Status information for. Required

Context Output

Path Type Description
BechtleDarkWebScan.WAF String Web Application Firewall status and product name (if applicable)

darkwebscan-resetcontext


Resets integration context for the DarkWebScan. May result in many alerts reappearing.

Base Command

darkwebscan-resetcontext

Input

There are no input arguments for this command.

Context Output

Path Type Description
BechtleDarkWebScan.ResetContext String Returns text whether the reset was successful or not.

Configuration parameters

  • apikey — API Key (required)
  • addreqheaders — Additional request headers
  • isFetch — Fetch incidents
  • incidentFetchInterval — Incidents Fetch Interval
  • first_fetch — First fetch time
  • incidentType — Incident type
  • max_fetch — Maximum incidents per fetch
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (6)

  • darkwebscan-getcompanies

    Returns a list of all companies associated with your API key.

  • darkwebscan-getemailsecurity

    Returns information about the email security for the associated domain of a given company_id.

  • darkwebscan-getleaks

    Returns leaked credentials for a given company_id.

  • darkwebscan-getosint

    Returns OSINT information about the associated domain of a given company_id.

  • darkwebscan-getwaf

    Returns Web Application Firewall Status information about the associated domain of a given company_id.

  • darkwebscan-resetcontext

    Resets integration context for the DarkWebScan. May result in many alerts reappearing.

## BechtleDarkWebScan

### Prerequisites
Active subscription at [www.darkwebscan.app](https://darkwebscan.app?utm_source=cortexhelpmd)


### Setup 
1. Retrieve your API key from the settings page of your dashboard at www.darkwebscan.app
2. Paste the API key into the settings of this integration in the field "API Key"
3. (Optional: Add additional request headers in the field "Additional request headers" as key:value pairs, one request header per line)
4. (Optional: If you want incidents to be created automatically out of the retrieved data, activate the checkbox "Fetches issues" in the "Collect" section of the setup)
5. Test the connection
6. If the connection test was successful, click "Save & Exit"