DHS Feed

The Cybersecurity and Infrastructure Security Agency’s (CISA’s) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community.

Data Enrichment & Threat Intelligence · DHS Feed · Feed

Details

IDDHS Feed
ProviderDHS
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/xml-feed:1.0.0.10133006
Supported ModulesAgentix XSIAM

README

The Cybersecurity and Infrastructure Security Agency’s (CISA’s) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community.
Use this version if your certificate supports TAXII 1 protocol.

Configure DHS Feed in Cortex

Parameter Description Required
Base URL   True
Key File as Text For more information, visit https://us-cert.cisa.gov/ais. True
Certificate File as Text For more information, visit https://us-cert.cisa.gov/ais. True
Feed Type   True
Filter by Traffic Light Protocol Color The Traffic Light Protocol (TLP) fetch from feed. False
Indicator Reputation Indicators from this integration instance will be marked with this reputation. False
Source Reliability Reliability of the source providing the intelligence data. True
Tags Supports CSV values. False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

dhs-get-indicators


Get the indicators.

Base Command

dhs-get-indicators

Input

Argument Name Description Required
limit The maximum number of indicators to return. Default is 20. Default is 20. Required
tlp_color The TLP color by which to filter the results. Possible values: “RED”, “AMBER”, “GREEN”, “WHITE”. Possible values are: RED, AMBER, GREEN, WHITE. Optional

Context Output

Path Type Description
DHS.type String The indicator type (e.g., IP, Domain, Email, URL, File).
DHS.value string The indicator.
DHS.tlp string The traffic light protocol.

Command Example

!dhs-get-indicators limit=2 tlp_color=GREEN

Configuration parameters

  • feed — Fetch indicators
  • base_url — Base URL (required)
  • key — Key File as Text
  • key_creds
  • crt — Certificate File as Text
  • crt_creds
  • collection — Feed Type (required)
  • tlp_color — Filter by Traffic Light Protocol Color
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • first_fetch — First fetch time
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • feedBypassExclusionList — Bypass exclusion list
  • feedTags — Tags
  • feedIncremental — Incremental feed

Commands (1)

  • dhs-get-indicators

    Get the indicators.

category: Data Enrichment & Threat Intelligence
provider: DHS
commonfields:
  id: DHS Feed
  version: -1
configuration:
- defaultvalue: 'true'
  display: Fetch indicators
  name: feed
  type: 8
  required: false
- defaultvalue: 'https://taxii.dhs.gov:8443'
  display: Base URL
  name: base_url
  required: true
  type: 0
- additionalinfo: 'For more information, visit https://us-cert.cisa.gov/ais.'
  display: Key File as Text
  name: key
  type: 4
  hidden: true
  required: false
- name: key_creds
  type: 9
  displaypassword: Key File as Text
  hiddenusername: true
  additionalinfo: 'For more information, visit https://us-cert.cisa.gov/ais.'
  required: false
- display: Certificate File as Text
  name: crt
  hidden: true
  type: 12
  additionalinfo: For more information, visit https://us-cert.cisa.gov/ais.
  required: false
- name: crt_creds
  type: 9
  displaypassword: Certificate File as Text
  hiddenusername: true
  additionalinfo: For more information, visit https://us-cert.cisa.gov/ais.
  required: false
- display: Feed Type
  name: collection
  options:
  - AIS
  - CISCP
  required: true
  type: 15
- additionalinfo: The Traffic Light Protocol (TLP) fetch from feed.
  display: Filter by Traffic Light Protocol Color
  name: tlp_color
  options:
  - RED
  - AMBER
  - GREEN
  - WHITE
  type: 15
  required: false
- additionalinfo: Indicators from this integration instance will be marked with this reputation.
  defaultvalue: Bad
  display: Indicator Reputation
  name: feedReputation
  options:
  - None
  - Good
  - Suspicious
  - Bad
  type: 18
  required: false
- defaultvalue: F - Reliability cannot be judged
  display: 'Source Reliability'
  name: feedReliability
  options:
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  required: true
  type: 15
  additionalinfo: Reliability of the source providing the intelligence data.
- defaultvalue: 'indicatorType'
  display: ''
  name: feedExpirationPolicy
  type: 17
  options:
  - never
  - interval
  - indicatorType
  required: false
- defaultvalue: '20160'
  display: ''
  name: feedExpirationInterval
  type: 1
  required: false
- defaultvalue: '240'
  display: Feed Fetch Interval
  name: feedFetchInterval
  type: 19
  required: false
- display: First fetch time
  name: first_fetch
  type: 0
  defaultvalue: 1 day
  required: false
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
- additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.
  display: Bypass exclusion list
  name: feedBypassExclusionList
  type: 8
  required: false
- additionalinfo: Supports CSV values.
  display: Tags
  name: feedTags
  type: 0
  required: false
- additionalinfo: Incremental feeds pull only new or modified indicators that have been sent from the integration. The determination if the indicator is new or modified happens on the 3rd-party vendor's side, so only indicators that are new or modified are sent to Cortex XSOAR. Therefore, all indicators coming from these feeds are labeled new or modified.
  defaultvalue: 'true'
  display: Incremental feed
  hidden: true
  name: feedIncremental
  type: 8
  required: false
description: The Cybersecurity and Infrastructure Security Agency’s (CISA’s) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community.
display: 'DHS Feed'
name: 'DHS Feed'
script:
  commands:
  - arguments:
    - defaultValue: 20
      default: true
      description: The maximum number of indicators to return. Default is 20.
      name: limit
      required: true
    - auto: PREDEFINED
      predefined:
      - RED
      - AMBER
      - GREEN
      - WHITE
      description: 'The TLP color by which to filter the results. Possible values: "RED", "AMBER", "GREEN", "WHITE".'
      name: tlp_color
    description: Get the indicators.
    name: dhs-get-indicators
    outputs:
    - contextPath: DHS.type
      description: The indicator type (e.g., IP, Domain, Email, URL, File).
      type: String
    - contextPath: DHS.value
      description: The indicator.
      type: string
    - contextPath: DHS.tlp
      description: The traffic light protocol.
      type: string
  dockerimage: demisto/xml-feed:1.0.0.10133006
  feed: true
  runonce: false
  script: '-'
  subtype: python3
  type: python
fromversion: 5.5.0
tests:
- No tests