ReliaQuest GreyMatter DRP Incidents

ReliaQuest GreyMatter DR monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web.

Data Enrichment & Threat Intelligence · ReliaQuest Digital Risk Protection

Details

IDReliaQuest GreyMatter DRP Incidents
ProviderReliaQuest
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

ReliaQuest GreyMatter DR monitors and manages an organization’s digital risk across the widest range of data sources within the open, deep, and dark web.
This integration was integrated and tested with version v1 of ReliaQuest GreyMatter DRP Incidents.

This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.

Configure ReliaQuest GreyMatter DRP Incidents in Cortex

Parameter Description Required
Fetch incidents Start fetching incidents False
DS SearchLight API URL Enter the Digital Shadows SearchLight API URL True
Account ID Account ID associated with this account. True
API Key Enter the API Key for this account. True
API Secret Enter the API Secret for this account. True
Trust any certificate (not secure) Verify certificate False
Risk Types Remove all if you don’t want to select all risk types, and then select specifically True
Risk Level Remove all if you don’t want to select all risk types, and then select specifically False
Ingest Closed / Auto-rejected Alerts If you don’t want to ingest rejected/resolved/closed incidents then set it to False. Otherwise incidents will ingested with auto-closed=True False
Fetch Limit The maximum number of incidents to fetch True
Incidents Fetch Interval This controls how often the integration will perform a fetch_incidents command False
Start date Since when want to fetch the data with given format(%Y-%m-%dT%H:%M:%SZ) True

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

ds-search


Perform a general search against incidents, threats closed sources, etc.

Base Command

ds-search

Input

Argument Name Description Required
query No description provided. Required

Context Output

There is no context output for this command.

Configuration parameters

  • searchLightUrl — DS SearchLight API URL (required)
  • accountId — Account ID (required)
  • apiKey — (required)
  • apiSecret — (required)
  • insecure — Trust any certificate (not secure)
  • first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 2 months, 1 years or datetime in "%Y-%m-%d %H:%M:%S" format)
  • riskTypes — Risk Types (required)
  • riskLevel — Risk Level
  • ingestClosedIncidents — Ingest Closed / Auto-rejected Alerts
  • max_fetch — Fetch Limit (required)
  • incidentFetchInterval — Incidents Fetch Interval
  • incidentType — Incident type
  • isFetch — Fetch incidents

Commands (1)

  • ds-search

    Perform a general search against incidents, threats closed sources, etc.

ReliaQuest GreyMatter DRP Incidents minimize digital risk by identifying unwanted exposure and protecting against external threats. The award-winning ReliaQuest GreyMatter DRP solution provides ongoing monitoring of a customer's unique assets and exposure across the open, deep, and dark web. This enables clients to detect data loss, brand impersonation, infrastructure risks, cyber threats, and much more.

This integration fetches event items which can be either incident/alerts, for more information, see [here](https://portal-digitalshadows.com/learn/searchlight-api/key-words/triage).

## ReliaQuest GreyMatter DRP Incidents EventCollector Authentication
Requests to all operation endpoints require HTTP Basic authentication, using dedicated (high entropy) API credentials. These normally consist of a six character key, and a 32 character 'secret'. Note that you will not be able to use your normal email/password login details with the HTTP Basic authentication mechanism.

Contact your ReliaQuest GreyMatter DRP representative to obtain API credentials.

To authenticate the integration, you must have a username, password and account ID. To get the account ID, see [here](https://portal-digitalshadows.com/api/stored-objects/portal/searchlight-api-docs/SearchLightAPI_APIKey_AccountId2.pdf).

## Limitations
Increasing the Maximum number of events per fetch parameter to high numbers can cause rate-limits, however The integration will recover from those rate-limits automatically. For more information about rate-limits, see [here](https://portal-digitalshadows.com/learn/searchlight-api/overview/rate-limiting).

## Configuration Guide

## Request Digital Shadows API Credentials

To use the application you will need to request an API Key and secret from Digital Shadows Support. Email support@digitalshadows.com stating that you would like to utilize the Digital Shadows Cortex XSOAR Integration and your SearchLightTM account details to have a new API Key created and assigned to you. 

To find your SearchLightTM  account details; in the SearchLightTM  portal please navigate to: 
- ‘Learn’ > ‘API Documentation’  
- Use the left hand filter to select ‘Keywords’   
- Scroll down to ‘Account’ and the ID is displayed

## Configuration

To configure the Digital Shadows Integration with Cortex XSOAR, from your XSOAR instance, navigate to:
- Left navigation panel 
- ‘Settings’
- Type ‘ReliaQuest GreyMatter DRP’ in the search bar 
- Click on the gear icon 

Here you can give your settings a custom name and set up several settings: 

Input: 
- ‘Classifier’ - Recommended to select ‘ReliaQuest GreyMatter DRP Incidents Classifier’ 
- ‘Mapper’ - Recommended to select ‘Reliaquest GreyMatter DRP Incidents Mapper’ 
- ‘Server URL’ - API URL for calling, is https://api.searchlight.app
- accountId – Account ID obtained from Digital Shadows Portal 
- ‘API Key’ and ‘Secret’ - Obtained from Digital Shadows 
- Risk Types – ‘All’ is the default. These can also be selected individually.
- ‘Risk Level’ – ‘All’ is the default. These can also be selected individually. 
- ‘Ingest Rejected/Resolved/Closed Incidents’ – This is an optional check box.
- ‘Fetch Limit’ – The maximum number of Incidents to Fetch 
- ‘Incidents Fetch Interval’ - Scheduled time frame between polling Digital Shadows for data 
- ‘Start Date’ – Initial Date to start pulling data from. (Historical incidents)
- ‘Log Level’ – ‘Verbose’, ‘Debug’, or ‘Off’  

Click on the ‘Test results’ tab and click ‘Run test’ 
. If you receive a ‘Success’ message then the integration is configured and will begin populating the ‘Investigation’ > ‘Incidents’ dashboard 

Note: TAXII feeds can be set up in order to receive IOCs from Digital Shadows.