Cortex Core - IOC

The Cortex Core - IOCs integration uses the Cortex API for detection and response, by natively integrating network, endpoint, and cloud data to stop sophisticated attacks.

Data Enrichment & Threat Intelligence · Core

Details

IDCortex Core - IOC
ProviderOpen Source
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/google-cloud-storage:1.0.0.10120494
Supported ModulesExposure Management Cortex Cloud Cloud Runtime Security Agentix Cloud Posture Security XSIAM EDR

README

The Cortex Core - IOCs integration uses the Cortex API for detection and response, by natively integrating network, endpoint, and cloud data to stop sophisticated attacks.

Configure Indicators detection

Parameter Description Required
Cortex XDR Severity Map the severity of each indicator that will be synced to Cortex. True
Tags Supports CSV values. False
Sync Query The query used to collect indicators to sync from Cortex. True
Trust any certificate (not secure)   False
Use system proxy settings   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

core-iocs-sync


Sync your IOC with Cortex and delete the previous version.

Base Command

core-iocs-sync

Input

Argument Name Description Required
firstTime For first sync, set to true.
(do NOT run this twice!). Possible values are: true, false. Default is false.
Optional

Context Output

There is no context output for this command.

core-iocs-push


Push modified IOCs to Cortex.

Base Command

core-iocs-push

Input

Argument Name Description Required
indicator IOCs to push. leave empty to push all recently modified IOCs.the indicators. Optional

Context Output

There is no context output for this command.

Command example

!core-iocs-push indicator='test.com'

Human Readable Output

push done.

core-iocs-set-sync-time


Set sync time manually (Do not use this command unless you unredstandard the consequences).

Base Command

core-iocs-set-sync-time

Input

Argument Name Description Required
time The time of the file creation (use UTC time zone). Required

Context Output

There is no context output for this command.

core-iocs-create-sync-file


Creates the sync file for the manual process. Run this command when instructed by the Cortex support team.

Base Command

core-iocs-create-sync-file

Input

There are no input arguments for this command.

Context Output

There is no context output for this command.

core-iocs-enable


Enables IOCs in the Cortex tenant.

Note: This command applies only to TIM-managed indicators (indicators that were synced/pushed to the Cortex tenant by this integration). Enabling an indicator not managed by TIM has no effect.

Base Command

core-iocs-enable

Input

Argument Name Description Required
indicator The indicator to enable. Only TIM-managed indicators can be enabled; indicators from other sources are not affected. Required

Context Output

There is no context output for this command.

Command example

!core-iocs-enable indicator=1.1.1.1

Human Readable Output

indicators 1.1.1.1 enabled.

core-iocs-disable


Disables IOCs in the Cortex tenant.

Note: This command applies only to TIM-managed indicators (indicators that were synced/pushed to the Cortex tenant by this integration). Disabling an indicator not managed by TIM has no effect.

Base Command

core-iocs-disable

Input

Argument Name Description Required
indicator The indicator to disable. Only TIM-managed indicators can be disabled; indicators from other sources are not affected. Required

Context Output

There is no context output for this command.

Command example

!core-iocs-disable indicator=22.22.22.22

Human Readable Output

indicators 22.22.22.22 disabled.

Configuration parameters

  • url — Server URL (e.g. https://example.net)
  • apikey_id — API Key ID
  • apikey — API Key
  • severity — Cortex Severity
  • query — Sync Query

Commands (6)

  • core-iocs-create-sync-file

    Creates the sync file for the manual process. Run this command when instructed by the Cortex support team.

  • core-iocs-disable

    Disables IOCs in the Cortex server. Applies only to TIM-managed indicators (indicators synced/pushed by this integration); indicators from other sources are not affected.

  • core-iocs-enable

    Enables IOCs in the Cortex tenant. Applies only to TIM-managed indicators (indicators synced/pushed by this integration); indicators from other sources are not affected.

  • core-iocs-push

    Push modified IOCs to Cortex.

  • core-iocs-set-sync-time

    Set sync time manually (Do not use this command unless you unredstandard the consequences).

  • core-iocs-sync

    Sync your IOC with Cortex and delete the previous version.

!core-iocs-sync
!core-iocs-enable indicator=11.11.11.11
!core-iocs-disable indicator=22.22.22.22
!core-iocs-push indicator='test.com'