Google IP Ranges Feed
Use the Google IP Ranges integration to get GCP and Google global IP ranges.
Data Enrichment & Threat Intelligence · Google IP Ranges Feed · Feed
Details
| ID | Google IP Ranges Feed |
|---|---|
| Provider | |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/py3-tools:1.0.0.10120494 |
| Supported Modules | Agentix XSIAM |
README
Use the Google IP Ranges Feed integration to get GCP and Google global IP ranges
Configure Google IP Ranges Feed in Cortex
| Parameter | Description | Required |
|---|---|---|
| feed | Fetch indicators | False |
| IP Address Ranges | IP Ranges group for the feed to fetch | True |
| feedReputation | Indicator Reputation | False |
| feedReliability | Source Reliability | True |
| tlp_color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlp | False |
| feedExpirationPolicy | False | |
| feedExpirationInterval | False | |
| feedFetchInterval | Feed Fetch Interval | False |
| feedTags | Tags | False |
| feedBypassExclusionList | Bypass exclusion list | False |
| Enrichment Excluded | Select this option to exclude the fetched indicators from the enrichment process. | False |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
IP Address Ranges
The IP Address Ranges Parameter determines the group of IP ranges for the feed to fetch:
- All GCP customer global and regional external IP ranges:
This option will fetch GCP customer global and regional external IP rages from https://www.gstatic.com/ipranges/cloud.json.
This should be used instead of the GCP Whitelist Feed integration. - All available Google IP ranges:
This option will fetch All Google IP ranges from https://www.gstatic.com/ipranges/goog.json.
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
google_ip_rages-get-indicators
Gets indicators from the feed.
Base Command
google-ip-ranges-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. The default value is 10. | Optional |
Context Output
There is no context output for this command.
Command Example
!google-ip-ranges-get-indicators limit=2
Context Example
{}
Human Readable Output
Indicators from GCP Whitelist Feed
| value | type |
|---|---|
| 52.86.122.241/18 | CIDR |
| 52.15.91.198/18 | CIDR |
Configuration parameters
feed— Fetch indicatorsip_ranges— IP Address Ranges (required)feedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedTags— TagsfeedBypassExclusionList— Bypass exclusion listenrichmentExcluded— Enrichment Excludedinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
google-ip-ranges-get-indicatorsGets indicators from the feed.
category: Data Enrichment & Threat Intelligence provider: Google commonfields: id: Google IP Ranges Feed version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - defaultvalue: All GCP customer global and regional external IP ranges display: IP Address Ranges name: ip_ranges options: - All GCP customer global and regional external IP ranges - All available Google IP ranges required: true type: 15 additionalinfo: IP address ranges group to be fetched. See integration help for more information. section: Connect - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: None display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: A - Completely reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false section: Collect - display: "" name: feedExpirationPolicy defaultvalue: suddenDeath type: 17 options: - never - interval - indicatorType - suddenDeath required: false section: Collect advanced: true - defaultvalue: '20160' display: "" name: feedExpirationInterval type: 1 required: false section: Collect advanced: true - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect advanced: true - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false section: Collect advanced: true - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false section: Collect advanced: true - display: Enrichment Excluded name: enrichmentExcluded type: 8 required: false additionalinfo: Select this option to exclude the fetched indicators from the enrichment process. defaultvalue: 'false' hidden: - xsoar_on_prem section: Collect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect advanced: true - display: Use system proxy settings name: proxy type: 8 required: false section: Connect advanced: true description: Use the Google IP Ranges integration to get GCP and Google global IP ranges. display: Google IP Ranges Feed name: Google IP Ranges Feed script: commands: - arguments: - name: limit description: The maximum number of results to return. The default value is 10. defaultValue: "10" description: Gets indicators from the feed. name: google-ip-ranges-get-indicators dockerimage: demisto/py3-tools:1.0.0.10120494 feed: true runonce: false script: '-' subtype: python3 type: python fromversion: 6.0.0 tests: - Fetch Indicators Test sectionorder: - Connect - Collect