Intel471 Watcher Alerts
Intel 471's watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.
Data Enrichment & Threat Intelligence · Intel471 Feed
Details
| ID | Intel471 Watcher Alerts |
|---|---|
| Provider | Intel 471 |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/py3-tools:1.0.0.8544956 |
| Supported Modules | Agentix XSIAM |
README
Intel 471’s watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.
Configure Intel471 Watcher Alerts in Cortex
| Parameter | Description | Required |
|---|---|---|
| Fetches incidents | False | |
| Username | API username | False |
| Password | API key | False |
| Intel 471 backend | Intel 471 backend selection | True |
| Maximum number of incidents per fetch | False | |
| Traffic Light Protocol Color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed | False |
| Incidents Fetch Interval | False | |
| Watcher group UID(s) | The UID(s) of the watcher group(s) for which alerts should be fetched | False |
| First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) | How far back in time to go when performing the first fetch. | False |
| Use system proxy settings | False | |
| Trust any certificate (not secure) | False |
Fetched Incidents Data
Returns the Intel 471 Watcher Alerts. Creates incidents in Cortex XSOAR and populate the incident details field
with the alert content.
Configuration parameters
intel471_backend— Intel 471 backend (required)isFetch— Fetch incidentsincidentType— Incident typeincidentFetchInterval— Incidents Fetch Intervalmax_fetch— Maximum number of incidents per fetchcredentials— Usernametlp_color— Traffic Light Protocol Colorfirst_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)watcher_group_uids— Watcher group UID(s)proxy— Use system proxy settingsinsecure— Trust any certificate (not secure)
Commands (0)
This integration defines no commands.
Fetch watcher alerts from the Intel 471 Alerts Stream feed. Use the **Intel 471 backend** integration parameter to choose the API: * **TITAN** — Titan API (`api.intel471.com`) for old Titan based alerts. * **Verity471** — Verity471 API (`api.intel471.cloud`) for Verity471 based alerts. **Credentials** * **Username** — API username * **Password** — API key Depends on selected backend: * **TITAN:** obtain your API key from [Titan API settings](https://titan.intel471.com/). * **Verity471:** request API credentials through the [Intel471 Developer Portal](https://developer.intel471.com/) (organization SSO sign-up / login). Set **Intel 471 backend** and credentials so they match the same provisioning path (Titan vs Verity471).