6437c006-1d86-4cdc-89d5-23305f207e3a

PhishUp prevents phishing attacks, protects your staff and your brand with AI.

Data Enrichment & Threat Intelligence · PhishUp

Details

ID6437c006-1d86-4cdc-89d5-23305f207e3a
ProviderProofpoint
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

PhishUp prevents phishing attacks, protects your staff and your brand with AI

If you don’t have PhishUp Api Key please create an account on PhishUp and get a free Api Key.
Also you can visit and test PhishUp Web Demo.

If you have any question feel free to concat us: info@phishup.com

Configure PhishUp in Cortex

Parameter Description Required
API KEY   True
Incident type   False
Trust any certificate (not secure)   False
Use system proxy settings   False
PhishUp Playbook Actions If there is any Phishing activity in mail, what should PhishUp do? True

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

url


PhishUp Url investigation

Base Command

url

Input

Argument Name Description Required
Url URL for phishup investigation. Required

Context Output

Path Type Description
PhishUp.Url String Incoming Url
PhishUp.Result String response types “Clean”, “Phish”
PhishUp.Score Number Phishup Engine Url Score
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.
URL.Data String The URL

Base Command

phishup-get-chosen-action

Input

There are no input arguments for this command.

Context Output

Path Type Description
PhishUp.Action String Chosen action from PhishUp instance

Base Command

phishup-evaluate-response

Input

There are no input arguments for this command.

Context Output

Path Type Description
PhishUp.Evaluation String Evaluating PhishUp Results and Return Phish If There is an Phish Website

Configuration parameters

  • credentials — (required)
  • incidentType — Incident type
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • phishup-playbook-action — PhishUp Playbook Actions (required)
  • integrationReliability — Source Reliability
  • feedExpirationPolicy
  • feedExpirationInterval

Commands (3)

  • phishup-evaluate-response

    Evaluation PhishUp URLs Response.

  • phishup-get-chosen-action

    Get chosen action from PhishUp instance.

  • url

    Url for PhishUp Reputation Investigation.

 ## PhishUp Real Time Cyber Threat Analytics

If you don't have [PhishUp](https://phishup.co) Api Key please create an account on PhishUp and get a free Api Key. 
Also you can visit and test [PhishUp Web Demo](https://phishup.co).

If you have any question feel free to concat us: [info@phishup.com](info@phishup.co)

------
## Configure PhishUp on Cortex XSOAR

1. PhishUp Integration Requirements.

| **Parameter**           | **Required** | **Description**            |
|-------------------------|--------------|----------------------------|
| API Key                 | True         | Enter your PhishUp Api Key |
| PhishUp Playbook Action | True         | PhishUp Playbook Mail Action |

2. Click **Test** to Api Key and connection.