Intel471 Watcher Alerts

Intel 471's watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.

Data Enrichment & Threat Intelligence · Intel471 Feed

Details

IDIntel471 Watcher Alerts
ProviderIntel 471
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/py3-tools:1.0.0.8544956
Supported ModulesAgentix XSIAM

README

Intel 471’s watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.

Configure Intel471 Watcher Alerts in Cortex

Parameter Description Required
Fetches incidents   False
Username API username False
Password API key False
Intel 471 backend Intel 471 backend selection True
Maximum number of incidents per fetch   False
Traffic Light Protocol Color The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed False
Incidents Fetch Interval   False
Watcher group UID(s) The UID(s) of the watcher group(s) for which alerts should be fetched False
First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) How far back in time to go when performing the first fetch. False
Use system proxy settings   False
Trust any certificate (not secure)   False

Fetched Incidents Data


Returns the Intel 471 Watcher Alerts. Creates incidents in Cortex XSOAR and populate the incident details field
with the alert content.

Configuration parameters

  • intel471_backend — Intel 471 backend (required)
  • isFetch — Fetch incidents
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • max_fetch — Maximum number of incidents per fetch
  • credentials — Username
  • tlp_color — Traffic Light Protocol Color
  • first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  • watcher_group_uids — Watcher group UID(s)
  • proxy — Use system proxy settings
  • insecure — Trust any certificate (not secure)

Commands (0)

This integration defines no commands.