Intel471 Watcher Alerts
Intel 471's watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.
Data Enrichment & Threat Intelligence · Intel471 Feed
Details
| ID | Intel471 Watcher Alerts |
|---|---|
| Provider | Intel 471 |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/py3-tools:1.0.0.8544956 |
| Supported Modules | Agentix XSIAM |
README
Intel 471’s watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.
Configure Intel471 Watcher Alerts in Cortex
| Parameter | Description | Required |
|---|---|---|
| Fetches incidents | False | |
| Username | API username | False |
| Password | API key | False |
| Intel 471 backend | Intel 471 backend selection | True |
| Maximum number of incidents per fetch | False | |
| Traffic Light Protocol Color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed | False |
| Incidents Fetch Interval | False | |
| Watcher group UID(s) | The UID(s) of the watcher group(s) for which alerts should be fetched | False |
| First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) | How far back in time to go when performing the first fetch. | False |
| Use system proxy settings | False | |
| Trust any certificate (not secure) | False |
Fetched Incidents Data
Returns the Intel 471 Watcher Alerts. Creates incidents in Cortex XSOAR and populate the incident details field
with the alert content.
Configuration parameters
intel471_backend— Intel 471 backend (required)isFetch— Fetch incidentsincidentType— Incident typeincidentFetchInterval— Incidents Fetch Intervalmax_fetch— Maximum number of incidents per fetchcredentials— Usernametlp_color— Traffic Light Protocol Colorfirst_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)watcher_group_uids— Watcher group UID(s)proxy— Use system proxy settingsinsecure— Trust any certificate (not secure)
Commands (0)
This integration defines no commands.