AlienVault OTX TAXII Feed
This integration fetches indicators from AlienVault OTX using a TAXII client.
Data Enrichment & Threat Intelligence · AlienVault Feed · Feed
Details
| ID | AlienVault OTX TAXII Feed |
|---|---|
| Provider | AT&T Cybersecurity |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/taxii:1.0.0.10133006 |
| Supported Modules | Agentix XSIAM |
README
Use the AlienVault OTX integration to fetch indicators using a TAXII client.
This integration can only fetch indicators from active collections. Active collections are those which contain at least one indicator.
Configure AlienVault OTX TAXII Feed in Cortex
| Parameter | Description | Required |
|---|---|---|
| feed | The fetch indicators. | False |
| feedReputation | The indicator reputation. | False |
| feedReliability | The source’s reliability. | True |
| tlp_color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlp | False |
| feedExpirationPolicy | The feed’s expiration policy. | False |
| feedExpirationInterval | The interval after which the feed expires. | False |
| feedFetchInterval | The feed fetch interval. | False |
| feedBypassExclusionList | Whether to bypass exclusion list. | False |
| api_key | The AlienVault OTX API key. | True |
| all_collections | Whether to get all active collections - if selected the integration will run on all active collections regardless of the collections supplied in the collections parameter. Inactive collections will not return indicators. | False |
| collections | The collections to fetch from. | False |
| insecure | Whether to trust any certificate (not secure). | False |
| proxy | Whether to use the system proxy settings. | False |
If you do not know which collections are available - do not set the Collections and All Collections parameters. The resulting error message will list all the accessible collections.
Note: not all listed collections are active.
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
Get indicators
Gets the indicators from AlienVault OTX.
Base Command
alienvaultotx-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of indicators to return. The default value is 10. | Required |
Context Output
There is no context output for this command.
Command Example
!alienvaultotx-get-indicators limit=3
Human Readable Output
Indicators from AlienVault OTX TAXII
| value | type |
|---|---|
| 1.2.3.4 | IP |
| https:/<span>/demisto.com | URL |
| demisto<span>.com | Domain |
Video Demo
Sorry, your browser doesn't support embedded videos. You can download the video at: https://github.com/demisto/content-assets/blob/7982404664dc68c2035b7c701d093ec026628802/Assets/FeedAlienVault/AlienVault_OTX_Feed_Demo.mp4Configuration parameters
feed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedTags— TagsfeedBypassExclusionList— Bypass exclusion listcredentials—api_key— API Keyall_collections— Get All Active Collectionscollections— Collections to Fetch Frominitial_interval— First Fetch Timeinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
alienvaultotx-get-indicatorsGets the indicators from AlienVault OTX.
import copy from dateutil.parser import parse from FeedAlienVaultOTXTaxii import get_latest_indicator_time, parse_indicators TEST_DATA = [ { "indicator": "http://demsito.demisto.com/", "type": "URL", "stix_title": "URL - http://demsito.demisto.com/", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/111", "stix_package_information_source": "Alienvault OTX", "added_time": "2020-02-23T12:03:31Z", }, { "indicator": "39eb39ad9fad2710be03c18de6985c20", "htype": "md5", "type": "File", "stix_title": "FileHash-MD5 - 39eb39ad9fad2710be03c18de6985c20", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "stix_package_information_source": "Alienvault OTX", "added_time": "2020-02-23T12:03:31Z", }, { "indicator": "demisto.com", "type": "Domain", "stix_title": "hostname - demisto.com", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "stix_package_information_source": "Alienvault OTX", "added_time": "2020-02-23T12:03:31Z", }, { "indicator": "1.2.3.4", "type": "IP", "stix_title": "IP - 1.2.3.4", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "stix_package_information_source": "Alienvault OTX", "added_time": "2020-02-23T12:03:31Z", }, { "indicator": "1.2.3.4/24", "type": "CIDR", "stix_title": "CIDR - 1.2.3.4/24", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "stix_package_information_source": "Alienvault OTX", "added_time": "2020-02-23T12:03:31Z", }, ] RESULT_PARSED_INDICATORS = [ { "type": "URL", "stix_title": "URL - http://demsito.demisto.com/", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/111", "stix_package_information_source": "Alienvault OTX", "added_time": "2020-02-23T12:03:31Z", "value": "http://demsito.demisto.com/", "fields": { "description": "https://otx.alienvault.com/pulse/111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, "rawJSON": { "indicator": "http://demsito.demisto.com/", "type": "URL", "stix_title": "URL - http://demsito.demisto.com/", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/111", "stix_package_information_source": "Alienvault OTX", "value": "http://demsito.demisto.com/", "added_time": "2020-02-23T12:03:31Z", "fields": { "description": "https://otx.alienvault.com/pulse/111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, }, }, { "htype": "md5", "type": "File", "stix_title": "FileHash-MD5 - 39eb39ad9fad2710be03c18de6985c20", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "added_time": "2020-02-23T12:03:31Z", "stix_package_information_source": "Alienvault OTX", "value": "39eb39ad9fad2710be03c18de6985c20", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, "rawJSON": { "indicator": "39eb39ad9fad2710be03c18de6985c20", "htype": "md5", "type": "File", "stix_title": "FileHash-MD5 - 39eb39ad9fad2710be03c18de6985c20", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "added_time": "2020-02-23T12:03:31Z", "stix_package_information_source": "Alienvault OTX", "value": "39eb39ad9fad2710be03c18de6985c20", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, }, }, { "type": "Domain", "stix_title": "hostname - demisto.com", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "added_time": "2020-02-23T12:03:31Z", "stix_package_information_source": "Alienvault OTX", "value": "demisto.com", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, "rawJSON": { "indicator": "demisto.com", "type": "Domain", "stix_title": "hostname - demisto.com", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "added_time": "2020-02-23T12:03:31Z", "stix_package_information_source": "Alienvault OTX", "value": "demisto.com", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "firstseenbysource": "2020-02-23T12:03:31Z", "tags": ["tag1", "tag2"], }, }, }, { "type": "IP", "stix_title": "IP - 1.2.3.4", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "stix_package_information_source": "Alienvault OTX", "value": "1.2.3.4", "added_time": "2020-02-23T12:03:31Z", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, "rawJSON": { "indicator": "1.2.3.4", "type": "IP", "stix_title": "IP - 1.2.3.4", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "added_time": "2020-02-23T12:03:31Z", "stix_package_information_source": "Alienvault OTX", "value": "1.2.3.4", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, }, }, { "type": "CIDR", "stix_title": "CIDR - 1.2.3.4/24", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "stix_package_information_source": "Alienvault OTX", "value": "1.2.3.4/24", "added_time": "2020-02-23T12:03:31Z", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, "rawJSON": { "indicator": "1.2.3.4/24", "type": "CIDR", "stix_title": "CIDR - 1.2.3.4/24", "stix_package_title": "demisto", "stix_package_description": "", "stix_package_short_description": "https://otx.alienvault.com/pulse/1111", "added_time": "2020-02-23T12:03:31Z", "stix_package_information_source": "Alienvault OTX", "value": "1.2.3.4/24", "fields": { "description": "https://otx.alienvault.com/pulse/1111", "tags": ["tag1", "tag2"], "firstseenbysource": "2020-02-23T12:03:31Z", }, }, }, ] RESULT_ONLY_INDICATORS_LIST = [ "http://demsito.demisto.com/", "39eb39ad9fad2710be03c18de6985c20", "demisto.com", "1.2.3.4", "1.2.3.4/24", ] def test_parse_indicators(): # parse_indicators is deleting the indicator key, so deep copying the test data test_data = copy.deepcopy(TEST_DATA) parsed_list, only_indicator_list = parse_indicators(test_data, [], tags=["tag1", "tag2"], tlp_color=None) assert parsed_list == RESULT_PARSED_INDICATORS assert only_indicator_list == RESULT_ONLY_INDICATORS_LIST def test_parse_indicators_with_tlp(): for indicator in RESULT_PARSED_INDICATORS: indicator["fields"]["trafficlightprotocol"] = "RED" indicator["rawJSON"]["fields"]["trafficlightprotocol"] = "RED" # parse_indicators is deleting the indicator key, so deep copying the test data test_data = copy.deepcopy(TEST_DATA) parsed_list, only_indicator_list = parse_indicators(test_data, [], tags=["tag1", "tag2"], tlp_color="RED") assert parsed_list == RESULT_PARSED_INDICATORS assert only_indicator_list == RESULT_ONLY_INDICATORS_LIST def test_get_latest_indicator_time(): indicators_list = [ {"added_time": "2020-02-23T12:03:31Z"}, {"added_time": "2020-02-23T13:13:31Z"}, {"added_time": "2020-02-23T13:03:31Z"}, ] assert get_latest_indicator_time(indicators_list) == parse("2020-02-23T13:13:31Z")