ReliaQuest GreyMatter DRP Incidents
ReliaQuest GreyMatter DR monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web.
Data Enrichment & Threat Intelligence · ReliaQuest Digital Risk Protection
Details
| ID | ReliaQuest GreyMatter DRP Incidents |
|---|---|
| Provider | ReliaQuest |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
ReliaQuest GreyMatter DR monitors and manages an organization’s digital risk across the widest range of data sources within the open, deep, and dark web.
This integration was integrated and tested with version v1 of ReliaQuest GreyMatter DRP Incidents.
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
Configure ReliaQuest GreyMatter DRP Incidents in Cortex
| Parameter | Description | Required |
|---|---|---|
| Fetch incidents | Start fetching incidents | False |
| DS SearchLight API URL | Enter the Digital Shadows SearchLight API URL | True |
| Account ID | Account ID associated with this account. | True |
| API Key | Enter the API Key for this account. | True |
| API Secret | Enter the API Secret for this account. | True |
| Trust any certificate (not secure) | Verify certificate | False |
| Risk Types | Remove all if you don’t want to select all risk types, and then select specifically | True |
| Risk Level | Remove all if you don’t want to select all risk types, and then select specifically | False |
| Ingest Closed / Auto-rejected Alerts | If you don’t want to ingest rejected/resolved/closed incidents then set it to False. Otherwise incidents will ingested with auto-closed=True | False |
| Fetch Limit | The maximum number of incidents to fetch | True |
| Incidents Fetch Interval | This controls how often the integration will perform a fetch_incidents command | False |
| Start date | Since when want to fetch the data with given format(%Y-%m-%dT%H:%M:%SZ) | True |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
ds-search
Perform a general search against incidents, threats closed sources, etc.
Base Command
ds-search
Input
| Argument Name | Description | Required |
|---|---|---|
| query | No description provided. | Required |
Context Output
There is no context output for this command.
Configuration parameters
searchLightUrl— DS SearchLight API URL (required)accountId— Account ID (required)apiKey— (required)apiSecret— (required)insecure— Trust any certificate (not secure)first_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 2 months, 1 years or datetime in "%Y-%m-%d %H:%M:%S" format)riskTypes— Risk Types (required)riskLevel— Risk LevelingestClosedIncidents— Ingest Closed / Auto-rejected Alertsmax_fetch— Fetch Limit (required)incidentFetchInterval— Incidents Fetch IntervalincidentType— Incident typeisFetch— Fetch incidents
Commands (1)
-
ds-searchPerform a general search against incidents, threats closed sources, etc.
ReliaQuest GreyMatter DRP Incidents minimize digital risk by identifying unwanted exposure and protecting against external threats. The award-winning ReliaQuest GreyMatter DRP solution provides ongoing monitoring of a customer's unique assets and exposure across the open, deep, and dark web. This enables clients to detect data loss, brand impersonation, infrastructure risks, cyber threats, and much more. This integration fetches event items which can be either incident/alerts, for more information, see [here](https://portal-digitalshadows.com/learn/searchlight-api/key-words/triage). ## ReliaQuest GreyMatter DRP Incidents EventCollector Authentication Requests to all operation endpoints require HTTP Basic authentication, using dedicated (high entropy) API credentials. These normally consist of a six character key, and a 32 character 'secret'. Note that you will not be able to use your normal email/password login details with the HTTP Basic authentication mechanism. Contact your ReliaQuest GreyMatter DRP representative to obtain API credentials. To authenticate the integration, you must have a username, password and account ID. To get the account ID, see [here](https://portal-digitalshadows.com/api/stored-objects/portal/searchlight-api-docs/SearchLightAPI_APIKey_AccountId2.pdf). ## Limitations Increasing the Maximum number of events per fetch parameter to high numbers can cause rate-limits, however The integration will recover from those rate-limits automatically. For more information about rate-limits, see [here](https://portal-digitalshadows.com/learn/searchlight-api/overview/rate-limiting). ## Configuration Guide ## Request Digital Shadows API Credentials To use the application you will need to request an API Key and secret from Digital Shadows Support. Email support@digitalshadows.com stating that you would like to utilize the Digital Shadows Cortex XSOAR Integration and your SearchLightTM account details to have a new API Key created and assigned to you. To find your SearchLightTM account details; in the SearchLightTM portal please navigate to: - ‘Learn’ > ‘API Documentation’ - Use the left hand filter to select ‘Keywords’ - Scroll down to ‘Account’ and the ID is displayed ## Configuration To configure the Digital Shadows Integration with Cortex XSOAR, from your XSOAR instance, navigate to: - Left navigation panel - ‘Settings’ - Type ‘ReliaQuest GreyMatter DRP’ in the search bar - Click on the gear icon Here you can give your settings a custom name and set up several settings: Input: - ‘Classifier’ - Recommended to select ‘ReliaQuest GreyMatter DRP Incidents Classifier’ - ‘Mapper’ - Recommended to select ‘Reliaquest GreyMatter DRP Incidents Mapper’ - ‘Server URL’ - API URL for calling, is https://api.searchlight.app - accountId – Account ID obtained from Digital Shadows Portal - ‘API Key’ and ‘Secret’ - Obtained from Digital Shadows - Risk Types – ‘All’ is the default. These can also be selected individually. - ‘Risk Level’ – ‘All’ is the default. These can also be selected individually. - ‘Ingest Rejected/Resolved/Closed Incidents’ – This is an optional check box. - ‘Fetch Limit’ – The maximum number of Incidents to Fetch - ‘Incidents Fetch Interval’ - Scheduled time frame between polling Digital Shadows for data - ‘Start Date’ – Initial Date to start pulling data from. (Historical incidents) - ‘Log Level’ – ‘Verbose’, ‘Debug’, or ‘Off’ Click on the ‘Test results’ tab and click ‘Run test’ . If you receive a ‘Success’ message then the integration is configured and will begin populating the ‘Investigation’ > ‘Incidents’ dashboard Note: TAXII feeds can be set up in order to receive IOCs from Digital Shadows.