Google IP Ranges Feed
Use the Google IP Ranges integration to get GCP and Google global IP ranges.
Data Enrichment & Threat Intelligence · Google IP Ranges Feed · Feed
Details
| ID | Google IP Ranges Feed |
|---|---|
| Provider | |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/py3-tools:1.0.0.10120494 |
| Supported Modules | Agentix XSIAM |
README
Use the Google IP Ranges Feed integration to get GCP and Google global IP ranges
Configure Google IP Ranges Feed in Cortex
| Parameter | Description | Required |
|---|---|---|
| feed | Fetch indicators | False |
| IP Address Ranges | IP Ranges group for the feed to fetch | True |
| feedReputation | Indicator Reputation | False |
| feedReliability | Source Reliability | True |
| tlp_color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlp | False |
| feedExpirationPolicy | False | |
| feedExpirationInterval | False | |
| feedFetchInterval | Feed Fetch Interval | False |
| feedTags | Tags | False |
| feedBypassExclusionList | Bypass exclusion list | False |
| Enrichment Excluded | Select this option to exclude the fetched indicators from the enrichment process. | False |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
IP Address Ranges
The IP Address Ranges Parameter determines the group of IP ranges for the feed to fetch:
- All GCP customer global and regional external IP ranges:
This option will fetch GCP customer global and regional external IP rages from https://www.gstatic.com/ipranges/cloud.json.
This should be used instead of the GCP Whitelist Feed integration. - All available Google IP ranges:
This option will fetch All Google IP ranges from https://www.gstatic.com/ipranges/goog.json.
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
google_ip_rages-get-indicators
Gets indicators from the feed.
Base Command
google-ip-ranges-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. The default value is 10. | Optional |
Context Output
There is no context output for this command.
Command Example
!google-ip-ranges-get-indicators limit=2
Context Example
{}
Human Readable Output
Indicators from GCP Whitelist Feed
| value | type |
|---|---|
| 52.86.122.241/18 | CIDR |
| 52.15.91.198/18 | CIDR |
Configuration parameters
feed— Fetch indicatorsip_ranges— IP Address Ranges (required)feedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedTags— TagsfeedBypassExclusionList— Bypass exclusion listenrichmentExcluded— Enrichment Excludedinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
google-ip-ranges-get-indicatorsGets indicators from the feed.
import demistomock as demisto from pytest_mock import MockerFixture def test_fetch_indicators_main(mocker: MockerFixture): """ Given - indicators response from google ip feed When - Running main flow for fetching indicators command Then - Ensure that all indicators values exist and are not 'None' """ from FeedGoogleIPRanges import main from JSONFeedApiModule import Client mocker.patch.object( demisto, "params", return_value={ "feed": True, "feedBypassExclusionList": False, "feedExpirationInterval": "20160", "feedExpirationPolicy": "suddenDeath", "feedFetchInterval": 1, "feedReliability": "A - Completely reliable", "feedReputation": "None", "feedTags": None, "insecure": True, "ip_ranges": "All available Google IP ranges", "proxy": False, "tlp_color": None, }, ) mocker.patch("FeedGoogleIPRanges.is_demisto_version_ge", return_value=True) mocker.patch.object(demisto, "command", return_value="fetch-indicators") create_indicators_mocker = mocker.patch.object(demisto, "createIndicators") mocker.patch.object( Client, "build_iterator", side_effect=[ ([{"ipv4Prefix": "1.1.1.1"}, {"ipv4Prefix": "1.2.3.4"}, {"ipv6Prefix": "1111:1111::/28"}], True), ([{"ipv4Prefix": "1.1.1.1"}, {"ipv4Prefix": "1.2.3.4"}, {"ipv6Prefix": "1111:1111::/28"}], True), ], ) main() assert create_indicators_mocker.call_args.args[0] == [ {"type": "CIDR", "fields": {"tags": []}, "value": "1.1.1.1", "rawJSON": {"ipv4Prefix": "1.1.1.1"}}, {"type": "CIDR", "fields": {"tags": []}, "value": "1.2.3.4", "rawJSON": {"ipv4Prefix": "1.2.3.4"}}, {"type": "IPv6CIDR", "fields": {"tags": []}, "value": "1111:1111::/28", "rawJSON": {"ipv6Prefix": "1111:1111::/28"}}, ]