BechtleDarkWebScan
Notifies you if login credentials to your company are being sold on the dark web.
Identity and Access Management · Bechtle Dark Web Scan
Details
| ID | BechtleDarkWebScan |
|---|---|
| Provider | Bechtle |
| Category | Identity and Access Management |
| From Version | 6.10.0 |
| Docker Image | demisto/python3:3.12.13.12042988 |
README
The dark web scan integration notifies you if login credentials to your company are being sold on the dark web.
Configure BechtleDarkWebScan in Cortex
| Parameter | Description | Required |
|---|---|---|
| API Key | Your darkwebscan.app API Key | True |
| Additional request headers | Additional request headers | False |
| Fetch incidents | Whether to fetch incidents | False |
| Incidents Fetch Interval | The interval incidents should be fetched | False |
| First fetch time | The first fetch time | False |
| Incident type | The incident type | False |
| Maximum incidents per fetch | Maxmimum amount of incidents per fetch | False |
| Trust any certificate (not secure) | Whether to trust any certificate | False |
| Use system proxy settings | Whether to use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
darkwebscan-getcompanies
Returns a list of all companies associated with your API key.
Base Command
darkwebscan-getcompanies
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.Companies | String | All companies that you have access to. |
darkwebscan-getleaks
Returns leaked credentials for a given company_id.
Base Command
darkwebscan-getleaks
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve leaked credentials for. | Required |
| only_new | Only return leaks not previously seen by this integration instance. Possible values are: true, false. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.LeakedCredentials | String | Leaked credentials for a given company_id. |
darkwebscan-getosint
Returns OSINT information about the associated domain of a given company_id.
Base Command
darkwebscan-getosint
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve OSINT information for. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.OSINT | String | OSINT information (email addresses, subdomains, …) for the associated domain of a given company_id. |
darkwebscan-getemailsecurity
Returns information about the email security for the associated domain of a given company_id.
Base Command
darkwebscan-getemailsecurity
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve email security information for. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.EmailSecurity | String | Email security (SPF, DMARC, DANE, …) for the associated domain of a given company_id. |
darkwebscan-getwaf
Returns Web Application Firewall Status information about the associated domain of a given company_id.
Base Command
darkwebscan-getwaf
Input
| Argument Name | Description | Required |
|---|---|---|
| company_id | ID of the company to retrieve Web Application Firewall Status information for. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.WAF | String | Web Application Firewall status and product name (if applicable) |
darkwebscan-resetcontext
Resets integration context for the DarkWebScan. May result in many alerts reappearing.
Base Command
darkwebscan-resetcontext
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| BechtleDarkWebScan.ResetContext | String | Returns text whether the reset was successful or not. |
Configuration parameters
apikey— API Key (required)addreqheaders— Additional request headersisFetch— Fetch incidentsincidentFetchInterval— Incidents Fetch Intervalfirst_fetch— First fetch timeincidentType— Incident typemax_fetch— Maximum incidents per fetchinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (6)
-
darkwebscan-getcompaniesReturns a list of all companies associated with your API key.
-
darkwebscan-getemailsecurityReturns information about the email security for the associated domain of a given company_id.
-
darkwebscan-getleaksReturns leaked credentials for a given company_id.
-
darkwebscan-getosintReturns OSINT information about the associated domain of a given company_id.
-
darkwebscan-getwafReturns Web Application Firewall Status information about the associated domain of a given company_id.
-
darkwebscan-resetcontextResets integration context for the DarkWebScan. May result in many alerts reappearing.