FeedSOCRadarThreatFeed

Retrieve indicators provided by collections via SOCRadar Threat Intelligence Feeds.

Data Enrichment & Threat Intelligence · SOCRadar ThreatFeed · Feed

Details

IDFeedSOCRadarThreatFeed
ProviderSOCRadar
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/python3:3.12.13.11879924
Supported ModulesAgentix XSIAM

README

Retrieve indicators provided by collections via SOCRadar Threat Intelligence Feeds.
This integration was integrated and tested with v21.11 of SOCRadar.

Configure SOCRadar Threat Feed on Cortex XSOAR

  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for SOCRadarThreatFeed.
  3. Click Add instance to create and configure a new integration instance.

    Parameter Description Required
    API Key The API Key to use for connection to SOCRadar ThreatFusion API. True
    insecure Trust any certificate (not secure). False
    proxy Whether to use XSOAR’s system proxy settings to connect to the API. False
    Feed Name The feed name(s) to fetch. True
    Fetch indicators Whether to fetch indicators. False
    Indicator Reputation Indicators from this integration instance will be marked with this reputation. False
    Traffic Light Protocol Color The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. False
    Tags Supports CSV values. False
    Source Reliability Reliability of the source providing the intelligence data. True
    Feed Fetch Interval The feed fetch interval. False
    Bypass exclusion list When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. False
  4. Click Test to validate API key and connection to SOCRadar Threat Feeds/IOC API.

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

How to obtain SOCRadar Threat Feeds/IOC API key?

Every company has a unique API key in SOCRadar platform. This API key can be used to benefit from
various API endpoints that SOCRadar provides.

For the information about the SOCRadar API keys and how to obtain them, please see SOCRadar API documentation.

socradar-get-indicators


Retrieves SOCRadar Recommended Threat Intelligences Collections.

Base Command

socradar-get-indicators

Input

Argument Name Description Required
collections_to_fetch Names of the collections that intended to be retrieved indicators from. Required
limit The maximum number of indicators to retrieve. Optional

Context Output

Path Type Description
SOCRadarThreatFeed.Indicators[0].Indicator String The value of the indicator.
SOCRadarThreatFeed.Indicators[0].Indicator Type String The type of the indicator.
SOCRadarThreatFeed.Indicators[0].Feed Maintainer Name String Name of the maintainer that the indicator found from.
SOCRadarThreatFeed.Indicators[0].First Seen Date Date The date that the indicator was in SOCRadar collections for the first time.
SOCRadarThreatFeed.Indicators[0].Last Seen Date Date The latest date that the indicator was seen in SOCRadar collections.
SOCRadarThreatFeed.Indicators[0].Seen Count Number The feed description.
SOCRadarThreatFeed.Indicators[0].rawJSON JSON Raw JSON object that contains the value and type of the indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.ASN Number ASN field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.AsnCode Number ASN code field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.AsnName String ASN name field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.Cidr String CIDR field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.CityName String City name field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.CountryCode String Country code field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.CountryName String Country name field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.Latitude Number Latitude field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.Longitude Number Longitude field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.RegionName String Region name field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.Timezone String Timezone field Geographical location information of the IP type indicator.
SOCRadarThreatFeed.Indicators[0].Geo Location.ZipCode String Zip code field Geographical location information of the IP type indicator.

Command Example

!socradar-get-indicators collections_to_fetch="SOCRadar-APT-Recommended-Block-Domain" limit=2

Context Example

{
    "SOCRadarThreatFeed": {
        "Indicators": [
            {
              "Feed Maintainer Name": "SOCRadar-APT Feed",
              "First Seen Date": "2021-07-15 07:04:29",
              "Indicator": "dump-indicator.domain", 
              "Indicator Type": "Domain", 
              "Last Seen Date": "2021-07-16 07:04:49",
              "Seen Count": 2,
              "rawJSON": {
                   "value": "dump-indicator.domain",
                   "type": "Domain"  
              }   
            },
            {
              "Feed Maintainer Name": "SOCRadar-APT Feed",
              "First Seen Date": "2021-07-15 07:04:29",
              "Indicator": "yet-another-dump-indicator.domain", 
              "Indicator Type": "Domain", 
              "Last Seen Date": "2021-07-16 07:04:49",
              "Seen Count": 2,
              "rawJSON": {
                   "value": "yet-another-dump-indicator.domain",
                   "type": "Domain"  
              }   
            }
        ]
    }
}

Human Readable Output

Indicators from SOCRadar ThreatFeed Collections (SOCRadar-APT-Recommended-Block-Domain)

Feed Maintainer Name First Seen Date Indicator Indicator Type Last Seen Date Seen Count
SOCRadar-APT Feed 2021-07-15 07:04:29 dump-indicator.domain Domain 2021-07-16 07:04:49 2
SOCRadar-APT Feed 2021-07-15 07:04:29 yet-another-dump-indicator.domain Domain 2021-07-16 07:04:49 2

socradar-reset-fetch-indicators


Resets the indicator fetch history.

Base Command

socradar-reset-fetch-indicators

Input

There are no input arguments for this command.

Context Output

There is no context output for this command.

Command Example

!socradar-reset-fetch-indicators

Human Readable Output

Fetch history has been successfully deleted!

Configuration parameters

  • apikey — API Key (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • collections_to_fetch — Feed Name (required)
  • feed — Fetch indicators
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • feedBypassExclusionList — Bypass exclusion list
  • tlp_color — Traffic Light Protocol Color
  • feedTags — Tags
  • feedIncremental — Incremental Feed

Commands (2)

  • socradar-get-indicators

    Retrieves SOCRadar Recommended Threat Intelligences Collections.

  • socradar-reset-fetch-indicators

    Resets the indicator fetch history.

category: Data Enrichment & Threat Intelligence
provider: SOCRadar
commonfields:
  id: FeedSOCRadarThreatFeed
  version: -1
configuration:
- additionalinfo: The API Key to use for connection
  display: API Key
  name: apikey
  required: true
  type: 4
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
- display: Feed Name
  name: collections_to_fetch
  options:
  - ALL
  - SOCRadar-Attackers-Recommended-Block-Hash
  - SOCRadar-Attackers-Recommended-Block-IP
  - SOCRadar-Attackers-Recommended-Block-Domain
  - SOCRadar-Recommended-Ransomware-Hash
  - SOCRadar-Recommended-Phishing-Global
  - SOCRadar-Recommended-Block-Hash
  - SOCRadar-Recommended-Phishing-Local
  - SOCRadar-APT-Recommended-Block-IP
  - SOCRadar-APT-Recommended-Block-Domain
  - SOCRadar-APT-Recommended-Block-Hash
  - SOCRadar-Botnet C&C - Block-Domain
  - SOCRadar-Botnet C&C - Block-IP
  required: true
  type: 16
- defaultvalue: 'true'
  display: Fetch indicators
  name: feed
  type: 8
  required: false
- additionalinfo: Indicators from this integration instance will be marked with this reputation.
  defaultvalue: Good
  display: Indicator Reputation
  name: feedReputation
  options:
  - None
  - Good
  - Suspicious
  - Bad
  type: 18
  required: false
- additionalinfo: Reliability of the source providing the intelligence data.
  defaultvalue: A - Completely reliable
  display: Source Reliability
  name: feedReliability
  options:
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  required: true
  type: 15
- name: feedExpirationPolicy
  display: ''
  options:
  - never
  - interval
  - indicatorType
  type: 17
  required: false
- defaultvalue: '20160'
  name: feedExpirationInterval
  display: ''
  type: 1
  required: false
- defaultvalue: '1440'
  display: Feed Fetch Interval
  name: feedFetchInterval
  type: 19
  required: false
- additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.
  display: Bypass exclusion list
  name: feedBypassExclusionList
  type: 8
  required: false
- additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed.
  defaultvalue: GREEN
  display: Traffic Light Protocol Color
  name: tlp_color
  options:
  - RED
  - AMBER
  - GREEN
  - WHITE
  type: 15
  required: false
- additionalinfo: Supports CSV values.
  display: Tags
  name: feedTags
  type: 0
  required: false
- additionalinfo: Incremental feeds pull only new or modified indicators that have been sent from the integration. As the determination if the indicator is new or modified happens on the 3rd-party vendor's side, and only indicators that are new or modified are sent to Cortex XSOAR, all indicators coming from these feeds are labeled new or modified.
  display: Incremental Feed
  name: feedIncremental
  defaultvalue: 'true'
  type: 8
  hidden: true
  required: false
description: Retrieve indicators provided by collections via SOCRadar Threat Intelligence Feeds.
display: SOCRadar Threat Feed
name: FeedSOCRadarThreatFeed
script:
  commands:
  - arguments:
    - description: The maximum number of indicators to be retrieved.
      name: limit
    - auto: PREDEFINED
      defaultValue: ALL
      description: Names of the collections that intended to be retrieved indicators from.
      name: collections_to_fetch
      predefined:
      - ALL
      - SOCRadar-Attackers-Recommended-Block-Hash
      - SOCRadar-Attackers-Recommended-Block-IP
      - SOCRadar-Attackers-Recommended-Block-Domain
      - SOCRadar-Recommended-Ransomware-Hash
      - SOCRadar-Recommended-Phishing-Global
      - SOCRadar-Recommended-Block-Hash
      - SOCRadar-Recommended-Phishing-Local
      - SOCRadar-APT-Recommended-Block-IP
      - SOCRadar-APT-Recommended-Block-Domain
      - SOCRadar-APT-Recommended-Block-Hash
      - SOCRadar-Botnet C&C - Block-Domain
      - SOCRadar-Botnet C&C - Block-IP
    description: Retrieves SOCRadar Recommended Threat Intelligences Collections.
    name: socradar-get-indicators
    outputs:
    - contextPath: SOCRadarThreatFeed.Indicators[0].Indicator
      description: The value of the indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Indicator Type
      description: The type of the indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Feed Maintainer Name
      description: Name of the maintainer that the indicator found from.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].First Seen Date
      description: The date that the indicator was in SOCRadar collections for the first time.
      type: Date
    - contextPath: SOCRadarThreatFeed.Indicators[0].Last Seen Date
      description: The latest date that the indicator was seen in SOCRadar collections.
      type: Date
    - contextPath: SOCRadarThreatFeed.Indicators[0].Seen Count
      description: The feed description.
      type: Number
    - contextPath: SOCRadarThreatFeed.Indicators[0].rawJSON
      description: Raw JSON object that contains the value and type of the indicator.
      type: JSON
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.ASN
      description: ASN field Geographical location information of the IP type indicator.
      type: Number
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.AsnCode
      description: ASN code field Geographical location information of the IP type indicator.
      type: Number
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.AsnName
      description: ASN name field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.Cidr
      description: CIDR field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.CityName
      description: City name field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.CountryCode
      description: Country code field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.CountryName
      description: Country name field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.Latitude
      description: Latitude field Geographical location information of the IP type indicator.
      type: Number
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.Longitude
      description: Longitude field Geographical location information of the IP type indicator.
      type: Number
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.RegionName
      description: Region name field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.Timezone
      description: Timezone field Geographical location information of the IP type indicator.
      type: String
    - contextPath: SOCRadarThreatFeed.Indicators[0].Geo Location.ZipCode
      description: Zip code field Geographical location information of the IP type indicator.
      type: String
  - description: Resets the indicator fetch history.
    name: socradar-reset-fetch-indicators
  dockerimage: demisto/python3:3.12.13.11879924
  feed: true
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- FeedSOCRadarThreatFeed-Test
fromversion: 6.0.0