FeedMISPThreatActors
Fetches the MISP threat actor galaxy and builds it into Threat Actor indicators in Cortex Threat Intel Management (TIM).
Data Enrichment & Threat Intelligence · MISP Threat Actors · Feed
Details
| ID | FeedMISPThreatActors |
|---|---|
| Provider | Open Source |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.10.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
MISP Threat Actors Feed Integration
Overview
This integration fetches threat actor information from the MISP Threat Actors Galaxy and creates indicators in Cortex TIM. It provides valuable threat intelligence about various threat actors, including their aliases, targets, origin countries, and related information.
Use Cases
- Fetch and update threat actor information regularly.
- Enrich your threat intelligence with detailed information about known threat actors.
- Create relationships between threat actors and their targets or aliases.
Configuration
- Navigate to Settings > Integrations > Instances.
- Search for MISP Threat Actors Feed.
- Click Add instance to create and configure a new integration instance.
- Name: A meaningful name for the integration instance.
- URL: The URL to fetch the MISP Threat Actors Galaxy file (default: https://raw.githubusercontent.com/MISP/misp-galaxy/main/galaxies/threat-actor.json)
- Feed Fetch Interval: How often the feed should be fetched and indicators created or updated.
- Reliability: Reliability of the feed source.
- TLP Color: Traffic Light Protocol color for the indicators.
- Feed Tags: Tags to be added to each indicator fetched from the feed.
- Bypass exclusion list: Whether to bypass the exclusion list when creating indicators.
- Click Test to validate the URLs and connection.
- Save and exit the integration instance.
Commands
This integration works in the background to fetch indicators and does not have any specific commands to execute manually.
fetch-indicators
This command runs in the background at the specified feed fetch interval to create and update threat actor indicators.
Additional Information
- The integration fetches the latest version of the MISP Threat Actors Galaxy file and only processes new updates.
- Indicators are created with rich metadata, including descriptions, aliases, targeted sectors and countries, and origin information when available.
- The integration creates relationships between threat actors and their aliases, targets, and attributed countries.
Troubleshooting
- If the integration fails to fetch data, ensure the provided URL is accessible and the network settings (including proxy if used) are correctly configured.
- Check the integration logs for any error messages or debugging information.
Configuration parameters
feed— Fetch indicatorsurl— MISP Threat actor galaxy raw address (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)feedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedBypassExclusionList— Bypass exclusion listtlp_color— Traffic Light Protocol ColorfeedTags— Tags
Commands (1)
-
mispthreatactors-get-indicatorsRetrieves indicators from Threat Vault.
# MISP Threat Actors Feed Integration ## Overview The MISP Threat Actors Feed integration allows you to retrieve and ingest threat actor information from the MISP threat actor galaxy into Cortex Threat Intel Management (TIM). ## Configuring the Integration **Fetch Interval**: Set how often the integration should fetch new data. ## Usage Once configured, this integration will automatically fetch new threat actor data based on your specified interval.