Intel471 Actors Feed Deprecated

Deprecated. To be replaced by use case centric functionality. No available replacement.

Data Enrichment & Threat Intelligence · Intel471 Feed · Feed

Details

IDIntel471 Actors Feed
ProviderIntel 471
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/py3-tools:1.0.0.47433
Supported ModulesAgentix XSIAM

README

“Intel 471’s Actors feed is an actor-centric intelligence feature.
It combines both a field-based intelligence collection and a headquartered-based intelligence analysis component.
This feed allows getting data out of closed sources (typically referred to as the deep and dark web) where threat actors collaborate, communicate, and plan cyber attacks.”

Configure Intel471 Actors Feed in Cortex

Parameter Description Required
credentials Username True
feed Fetch indicators False
feedReputation Indicator Reputation False
feedReliability Source Reliability True
tlp_color Traffic Light Protocol Color False
feedExpirationPolicy   False
feedExpirationInterval   False
feedFetchInterval Feed Fetch Interval False
actor Free text actor search (all fields included) False
fetch_time First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) False
feedTags Tags  
feedBypassExclusionList Bypass exclusion list False
proxy Use system proxy settings False
insecure Trust any certificate (not secure) False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

intel471-actors-get-indicators


Gets the feed indicators.

Base Command

intel471-actors-get-indicators

Input

Argument Name Description Required
limit The maximum number of results to return. Default is 50. Optional

Context Output

There is no context output for this command.

Command Example

!intel471-actors-get-indicators limit=10

Indicators

value type rawJSON
h.m.15 STIX Threat Actor lastUpdated: 1611219975088
handles: h.m.15
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “h.m.15”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1078774740000
activeUntil: 1078774740000
uid: 7d1da0f4f0b26f3fb777fdd662c5cc68
bradleykins STIX Threat Actor lastUpdated: 1611219676493
handles: bradleykins
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “bradleykins”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1080079020000
activeUntil: 1080079020000
uid: b6c4bf36d66d7892244bd56572704982
Eleethal STIX Threat Actor lastUpdated: 1611299774949
handles: Eleethal
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “Eleethal”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 502}
activeFrom: 1090467720000
activeUntil: 1090467720000
uid: 482c379b7a0bda6574bf0b5ca63532e6
jag4life STIX Threat Actor lastUpdated: 1611214277667
handles: jag4life
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “jag4life”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1098304440000
activeUntil: 1098304440000
uid: 0e6cee474206abe743b748ca36fc62eb
ice-killer STIX Threat Actor lastUpdated: 1611246675557
handles: ice-killer
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “ice-killer”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 28}
activeFrom: 1099041900000
activeUntil: 1099041900000
uid: bf012aa908bd8d4464c9ab52cf088d3f
GobLin STIX Threat Actor lastUpdated: 1611246675557
handles: GobLin
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “GobLin”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 10}
activeFrom: 1099423620000
activeUntil: 1099423620000
uid: 09a6110f39478e39eda6c95138d7e723
SveSTevN STIX Threat Actor lastUpdated: 1611252975381
handles: SveSTevN
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “SveSTevN”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 13}
activeFrom: 1099443060000
activeUntil: 1099443060000
uid: debbb920e2f6a94f875c6384af99ec35
Thomas STIX Threat Actor lastUpdated: 1611253575408
handles: Thomas
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “Thomas”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1099781940000
activeUntil: 1099781940000
uid: 2b9b3d1530d0cb2364053cce822297eb
Petrovich STIX Threat Actor lastUpdated: 1611252674936
handles: Petrovich
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “Petrovich”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 3}
activeFrom: 1099939140000
activeUntil: 1099939140000
uid: db1aa88e2f0c2d120d3f0930a0a2e9ed
PoFigisT STIX Threat Actor lastUpdated: 1611252675579
handles: PoFigisT
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “PoFigisT”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 17}
activeFrom: 1100332920000
activeUntil: 1100332920000
uid: 9c16382ba5454e06919e087959046f12

Configuration parameters

  • credentials — Username (required)
  • feed — Fetch indicators
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • tlp_color — Traffic Light Protocol Color
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • actor — Free text actor search (all fields included)
  • fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  • feedTags — Tags
  • feedBypassExclusionList — Bypass exclusion list
  • proxy — Use system proxy settings
  • insecure — Trust any certificate (not secure)

Commands (1)

  • intel471-actors-get-indicators

    Gets the feed indicators.

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401

from JSONFeedApiModule import *  # noqa: E402

SEARCH_PARAMS = {"from": "from", "until": "until", "actor": "actor"}
FEED_URL = "https://api.intel471.com/v1/actors?"
MAPPING = {
    "handles": "stixaliases",
    "lastUpdated": "updateddate",
    "activeFrom": "activefrom",
    "activeUntil": "activeuntil",
    "links_forumTotalCount": "intel471forumtotalcount",
    "links_forumPostTotalCount": "intel471forumposttotalcount",
    "links_reportTotalCount": "intel471reporttotalcount",
    "links_instantMessageTotalCount": "intel471instantmessagetotalcount",
}
DEMISTO_VERSION = demisto.demistoVersion()
CONTENT_PACK = f"Intel471 Feed/{str(get_pack_version())}"
INTEGRATION = "Intel471 Actors Feed"
USER_AGENT = f'XSOAR/{DEMISTO_VERSION["version"]}.{DEMISTO_VERSION["buildNumber"]} - {CONTENT_PACK} - {INTEGRATION}'


def _create_url(**kwargs):
    """
    This function gets parameters and adding the relevant to a url string
    """
    url_suffix = ""
    if "actor" not in kwargs:
        kwargs["actor"] = "*"

    for param in kwargs:
        if param in SEARCH_PARAMS:
            url_suffix += f"&{SEARCH_PARAMS.get(param)}={kwargs.get(param)}"
    return FEED_URL + url_suffix.strip("&")


def custom_build_iterator(client: Client, feed: dict, limit: int = 0, **kwargs) -> list:
    """
    This function replace the build iterator function in JsonFeedApiModule in order to enable paging specific to api.
    Paginf is done using
    """

    url = feed.get("url", client.url)
    fetch_time = feed.get("fetch_time")
    start_date, end_date = parse_date_range(fetch_time, utc=True, to_timestamp=True)
    integration_context = get_integration_context()
    last_fetch = integration_context.get(f"{feed.get('indicator_type')}_fetch_time")

    # sorting and count are used for paging purposes
    params = {"lastUpdatedFrom": last_fetch if last_fetch else start_date, "sort": "earliest", "count": "100"}
    result: list[dict] = []
    should_continue = True
    total_count = 0

    while should_continue:
        r = requests.get(
            url=url, verify=client.verify, auth=client.auth, cert=client.cert, headers=client.headers, params=params, **kwargs
        )
        try:
            r.raise_for_status()
            data = r.json()
            current_result = jmespath.search(expression=feed.get("extractor"), data=data)
            if current_result:
                if not total_count:
                    total_count = limit if limit else data.get("actorTotalCount")
                result = result + current_result
                params["from"] = result[-1].get("activeFrom")

            # gets next page reference and handles paging.
            should_continue = total_count > len(result)

        except ValueError as VE:
            raise ValueError(f"Could not parse returned data to Json. \n\nError massage: {VE}")
        except requests.exceptions.ConnectTimeout as exception:
            err_msg = (
                "Connection Timeout Error - potential reasons might be that the Server URL parameter"
                " is incorrect or that the Server is not accessible from your host."
            )
            raise DemistoException(err_msg, exception)
        except requests.exceptions.SSLError as exception:
            err_msg = (
                "SSL Certificate Verification Failed - try selecting 'Trust any certificate' checkbox in"
                " the integration configuration."
            )
            raise DemistoException(err_msg, exception)
        except requests.exceptions.ProxyError as exception:
            err_msg = (
                "Proxy Error - if the 'Use system proxy' checkbox in the integration configuration is"
                " selected, try clearing the checkbox."
            )
            raise DemistoException(err_msg, exception)
        except requests.exceptions.ConnectionError as exception:
            # Get originating Exception in Exception chain
            error_class = str(exception.__class__)
            err_type = "<" + error_class[error_class.find("'") + 1 : error_class.rfind("'")] + ">"
            err_msg = (
                "Verify that the server URL parameter"
                " is correct and that you have access to the server from your host."
                f"\nError Type: {err_type}\nError Number: [{exception.errno}]\nMessage: {exception.strerror}\n"
            )
            raise DemistoException(err_msg, exception)

    set_integration_context({f"{feed.get('indicator_type')}_fetch_time": str(end_date)})
    return result


def custom_handle_indicator(
    client: Client,
    item: dict,
    feed_config: dict,
    service_name: str,
    indicator_type: str,
    indicator_field: str,
    use_prefix_flat: bool,
    feedTags: list,
    auto_detect: bool,
    mapping_function: Callable,
    create_relationships: bool,  # noqa: F841
    relationships_func: Callable,
) -> list[dict]:  # noqa: F841
    """
    This function adds indicators to indicator lists after specific manipulation.
    :param client: Client (from JsonFeedApiModule
    :param item: Dict describing a specific indicator
    :param feed_config: Dict describing the feed configuration
    :param service_name: name of service
    :param indicator_type: str. Type of the indicator
    :param indicator_field: str. Field name in item which indicator value is taken from
    :param use_prefix_flat: bool. Whether attribute of item should be flattened.
    :param feedTags: list of tags.
    :param auto_detect: bool. Whether to use auto detect. Not in used in customized indicator handler,
    :param indicator_list: list of indicators to add indicator created from item to.
    :param mapping_function: Callable function to match json fields to demisto fields.
    :param create_relationships: bool. Whether to create relationships.
    :param relationships_func: Callable function to handle relationships.
    """
    indicator_list = []
    mapping = feed_config.get("mapping")
    indicator_value = item.get(indicator_field)
    current_indicator_type = determine_indicator_type(indicator_type, auto_detect, indicator_value)

    if not current_indicator_type:
        return []

    indicator: dict = {
        "type": current_indicator_type,
        "fields": {
            "tags": feedTags,
        },
    }

    if client.tlp_color:
        indicator["fields"]["trafficlightprotocol"] = client.tlp_color

    attributes: dict = {"source_name": service_name, "type": current_indicator_type}
    attributes.update(extract_all_fields_from_indicator(item, indicator_field, flat_with_prefix=use_prefix_flat))
    attributes["handles"] = []

    for forum_item in attributes.get(indicator_field, []):
        value = f"{forum_item.get('actorHandle', '')} ({forum_item.get('name', '')})"
        indicator["value"] = forum_item.get("actorHandle", "")
        attributes["handles"].append(value)

        if mapping:
            mapping_function(mapping, indicator, attributes)
        indicator["rawJSON"] = item

        indicator_list.append(indicator)
    return indicator_list


def main():
    params = {k: v for k, v in demisto.params().items() if v is not None}
    params["headers"] = {"user-agent": USER_AGENT}
    url = _create_url(**params)
    params["url"] = url
    params["indicator_type"] = "STIX Threat Actor"
    params["feed_name_to_config"] = {
        "actors": {
            "extractor": "actors[*]",
            "indicator_type": "STIX Threat Actor",
            "indicator": "links_forums",
            "mapping": MAPPING,
            "flat_json_with_prefix": True,
            "custom_build_iterator": custom_build_iterator,
            "fetch_time": params.get("fetch_time", "7 days"),
            "handle_indicator_function": custom_handle_indicator,
        },
    }
    feed_main(params, "Intel471 Actor Feed", "intel471-actors")


if __name__ in ("__main__", "__builtin__", "builtins"):
    main()