Intel471 Actors Feed Deprecated
Deprecated. To be replaced by use case centric functionality. No available replacement.
Data Enrichment & Threat Intelligence · Intel471 Feed · Feed
Details
| ID | Intel471 Actors Feed |
|---|---|
| Provider | Intel 471 |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/py3-tools:1.0.0.47433 |
| Supported Modules | Agentix XSIAM |
README
“Intel 471’s Actors feed is an actor-centric intelligence feature.
It combines both a field-based intelligence collection and a headquartered-based intelligence analysis component.
This feed allows getting data out of closed sources (typically referred to as the deep and dark web) where threat actors collaborate, communicate, and plan cyber attacks.”
Configure Intel471 Actors Feed in Cortex
| Parameter | Description | Required |
|---|---|---|
| credentials | Username | True |
| feed | Fetch indicators | False |
| feedReputation | Indicator Reputation | False |
| feedReliability | Source Reliability | True |
| tlp_color | Traffic Light Protocol Color | False |
| feedExpirationPolicy | False | |
| feedExpirationInterval | False | |
| feedFetchInterval | Feed Fetch Interval | False |
| actor | Free text actor search (all fields included) | False |
| fetch_time | First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) |
False |
| feedTags | Tags | |
| feedBypassExclusionList | Bypass exclusion list | False |
| proxy | Use system proxy settings | False |
| insecure | Trust any certificate (not secure) | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
intel471-actors-get-indicators
Gets the feed indicators.
Base Command
intel471-actors-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. Default is 50. | Optional |
Context Output
There is no context output for this command.
Command Example
!intel471-actors-get-indicators limit=10
Indicators
value type rawJSON h.m.15 STIX Threat Actor lastUpdated: 1611219975088
handles: h.m.15
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “h.m.15”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1078774740000
activeUntil: 1078774740000
uid: 7d1da0f4f0b26f3fb777fdd662c5cc68bradleykins STIX Threat Actor lastUpdated: 1611219676493
handles: bradleykins
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “bradleykins”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1080079020000
activeUntil: 1080079020000
uid: b6c4bf36d66d7892244bd56572704982Eleethal STIX Threat Actor lastUpdated: 1611299774949
handles: Eleethal
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “Eleethal”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 502}
activeFrom: 1090467720000
activeUntil: 1090467720000
uid: 482c379b7a0bda6574bf0b5ca63532e6jag4life STIX Threat Actor lastUpdated: 1611214277667
handles: jag4life
links: {“forums”: [{“name”: “unknowncheats”, “actorHandle”: “jag4life”, “uid”: “4671aeaf49c792689533b00664a5c3ef”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1098304440000
activeUntil: 1098304440000
uid: 0e6cee474206abe743b748ca36fc62ebice-killer STIX Threat Actor lastUpdated: 1611246675557
handles: ice-killer
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “ice-killer”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 28}
activeFrom: 1099041900000
activeUntil: 1099041900000
uid: bf012aa908bd8d4464c9ab52cf088d3fGobLin STIX Threat Actor lastUpdated: 1611246675557
handles: GobLin
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “GobLin”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 10}
activeFrom: 1099423620000
activeUntil: 1099423620000
uid: 09a6110f39478e39eda6c95138d7e723SveSTevN STIX Threat Actor lastUpdated: 1611252975381
handles: SveSTevN
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “SveSTevN”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 13}
activeFrom: 1099443060000
activeUntil: 1099443060000
uid: debbb920e2f6a94f875c6384af99ec35Thomas STIX Threat Actor lastUpdated: 1611253575408
handles: Thomas
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “Thomas”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 1}
activeFrom: 1099781940000
activeUntil: 1099781940000
uid: 2b9b3d1530d0cb2364053cce822297ebPetrovich STIX Threat Actor lastUpdated: 1611252674936
handles: Petrovich
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “Petrovich”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 3}
activeFrom: 1099939140000
activeUntil: 1099939140000
uid: db1aa88e2f0c2d120d3f0930a0a2e9edPoFigisT STIX Threat Actor lastUpdated: 1611252675579
handles: PoFigisT
links: {“forums”: [{“name”: “mazafaka”, “actorHandle”: “PoFigisT”, “uid”: “fc221309746013ac554571fbd180e1c8”}], “forumTotalCount”: 1, “instantMessageChannelTotalCount”: 0, “forumPrivateMessageTotalCount”: 0, “reportTotalCount”: 0, “instantMessageTotalCount”: 0, “instantMessageServerTotalCount”: 0, “forumPostTotalCount”: 17}
activeFrom: 1100332920000
activeUntil: 1100332920000
uid: 9c16382ba5454e06919e087959046f12
Configuration parameters
credentials— Username (required)feed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch Intervalactor— Free text actor search (all fields included)fetch_time— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)feedTags— TagsfeedBypassExclusionList— Bypass exclusion listproxy— Use system proxy settingsinsecure— Trust any certificate (not secure)
Commands (1)
-
intel471-actors-get-indicatorsGets the feed indicators.
category: Data Enrichment & Threat Intelligence provider: Intel 471 deprecated: true commonfields: id: Intel471 Actors Feed version: -1 configuration: - display: Username name: credentials required: true type: 9 - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: Suspicious display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: B - Usually reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - defaultvalue: indicatorType display: '' name: feedExpirationPolicy options: - never - interval - indicatorType - suddenDeath type: 17 required: false - defaultvalue: '20160' display: '' name: feedExpirationInterval type: 1 required: false - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false - display: Free text actor search (all fields included) name: actor type: 0 defaultvalue: '*' required: false - additionalinfo: How far back in time to go when performing the first fetch. defaultvalue: '7 days' display: First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) name: fetch_time type: 0 required: false - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false - display: Trust any certificate (not secure) name: insecure type: 8 required: false description: Deprecated. To be replaced by use case centric functionality. No available replacement. display: Intel471 Actors Feed (Deprecated) name: Intel471 Actors Feed script: commands: - arguments: - defaultValue: '50' description: The maximum number of results to return. name: limit description: Gets the feed indicators. name: intel471-actors-get-indicators dockerimage: demisto/py3-tools:1.0.0.47433 feed: true runonce: false script: '-' subtype: python3 type: python tests: - No tests fromversion: 5.5.0