QintelPMI
Qintel’s Patch Management Intelligence (PMI) product simplifies the vulnerability management process by providing vital context around reported Common Vulnerabilities and Exposures. With this integration, users can query PMI to surface CVEs that are known by Qintel to be leveraged by eCrime and Nation State adversaries.
Data Enrichment & Threat Intelligence · Qintel
Details
| ID | QintelPMI |
|---|---|
| Provider | Qintel |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Qintel’s Patch Management Intelligence (PMI) product simplifies the vulnerability management process by providing vital context around reported Common Vulnerabilities and Exposures. With this integration, users can query PMI to surface CVEs that are known by Qintel to be leveraged by eCrime and Nation State adversaries.
This integration was integrated and tested with version 0.16.0 of PMI
Configure QintelPMI in Cortex
| Parameter | Required |
|---|---|
| PMI API URL (optional) | False |
| Qintel Credentials | True |
| Password | True |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
cve
Queries Qintel for CVE intelligence
Base Command
cve
Input
| Argument Name | Description | Required |
|---|---|---|
| cve | List of CVEs. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CVE.ID | String | The ID of the CVE, for example: CVE-2015-1653 |
| CVE.CVSS | String | The CVSS of the CVE, for example: 10.0 |
| CVE.Published | Date | The timestamp of when the CVE was published. |
| CVE.Modified | Date | The timestamp of when the CVE was last modified. |
| CVE.Description | String | A description of the CVE. |
| Qintel.CVE.ID | string | The ID of the CVE |
| Qintel.CVE.AffectedSystem | string | Systems affected by the CVE |
| Qintel.CVE.AffectedVersions | string | Systems affected by the CVE |
| Qintel.CVE.LastObserved | string | Last threat actor observation time |
| Qintel.CVE.Observations | array | List of observations |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
Command Example
!cve cve=CVE-2021-0123
Context Example
{
"CVE": {
"CVSS": "None",
"Description": "None",
"ID": "CVE-2021-0123",
"Modified": "None",
"Published": "None"
},
"DBotScore": {
"Indicator": "CVE-2021-0123",
"Score": 0,
"Type": "cve",
"Vendor": null
},
"Qintel": {
"CVE": {
"AffectedSystem": "Example System",
"AffectedVersions": "1.0, 1.1",
"LastObserved": "2021-04-20 04:00:00",
"Observations": [
{
"actor": "Unattributed Threat Actor",
"actor_type": "other",
"date_observed": "2021-04-20 04:00:00",
"exploit_notes": null,
"exploit_type": "cve"
}
],
"id": "CVE-2021-0123"
}
}
}
Human Readable Output
Qintel vulnerability results for: CVE-2021-0123
Vulnerability in Example System affecting versions: 1.0, 1.1
Last observed: 2021-04-20 04:00:00
actor actor_type exploit_type exploit_notes date_observed Unattributed Threat Actor other cve 2021-04-20 04:00:00
Configuration parameters
remote— PMI API URL (optional)credentials— Qintel Credentials (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
cveQueries Qintel for CVE intelligence.
category: Data Enrichment & Threat Intelligence provider: Qintel commonfields: id: QintelPMI version: -1 configuration: - display: PMI API URL (optional) name: remote type: 0 required: false - display: Qintel Credentials name: credentials required: true type: 9 - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false description: 'Qintel’s Patch Management Intelligence (PMI) product simplifies the vulnerability management process by providing vital context around reported Common Vulnerabilities and Exposures. With this integration, users can query PMI to surface CVEs that are known by Qintel to be leveraged by eCrime and Nation State adversaries.' display: Qintel PMI name: QintelPMI script: commands: - arguments: - default: true description: List of CVEs. isArray: true name: cve required: true description: Queries Qintel for CVE intelligence. name: cve outputs: - contextPath: CVE.ID description: 'The ID of the CVE, for example: CVE-2015-1653.' type: String - contextPath: CVE.CVSS description: 'The CVSS of the CVE, for example: 10.0.' type: String - contextPath: CVE.Published description: The timestamp of when the CVE was published. type: Date - contextPath: CVE.Modified description: The timestamp of when the CVE was last modified. type: Date - contextPath: CVE.Description description: A description of the CVE. type: String - contextPath: Qintel.CVE.ID description: The ID of the CVE. type: string - contextPath: Qintel.CVE.AffectedSystem description: Systems affected by the CVE. type: string - contextPath: Qintel.CVE.AffectedVersions description: Systems affected by the CVE. type: string - contextPath: Qintel.CVE.LastObserved description: Last threat actor observation time. type: string - contextPath: Qintel.CVE.Observations description: List of observations. type: array - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String runonce: false script: '-' type: python subtype: python3 dockerimage: demisto/python3:3.12.13.10116658 fromversion: 6.0.0 tests: - No tests (auto formatted)