SOCRadarIoCEnrichment
Enrich indicators with deep threat intelligence using SOCRadar IoC Enrichment API. Get categorization, signal strength, confidence levels, and historical data.
Data Enrichment & Threat Intelligence · SOCRadar
Details
| ID | SOCRadarIoCEnrichment |
|---|---|
| Provider | SOCRadar |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 6.10.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
SOCRadar IoC Enrichment Integration
Overview
The SOCRadar IoC Enrichment integration provides deep threat intelligence enrichment for indicators of compromise (IoCs). Get comprehensive data including categorization, signal strength, confidence levels, historical events, threat actor attribution, and campaign associations.
Key Features
- Rich Threat Context: Detailed categorization (CDN, Cloud, Malware, ThreatActor, Tor, VPN, etc.)
- Signal Strength: IoC reliability assessment (Very Strong to Noisy)
- Confidence Levels: Cross-source validation (Very High, High, Medium, Low)
- Historical Data: Timeline of indicator activity across threat feeds
- Threat Attribution: Associated campaigns, threat actors, malware families
- Target Intelligence: Industries and countries targeted
- Performance Optimized: AI insights excluded for fast responses
Configuration
Prerequisites
- SOCRadar API Key with IoC Enrichment access
- Network access to
platform.socradar.com
Setup
- Navigate to Settings → Integrations → Servers & Services
- Search for “SOCRadar IoC Enrichment”
- Click Add Instance
- Configure:
- Name: Instance name
- API Key: Your SOCRadar API key
- Source Reliability: B - Usually reliable (recommended)
- Click Test to validate
- Click Save & Exit
Commands
ip
Enriches IP addresses with threat intelligence data.
Input
| Argument | Description | Required |
|---|---|---|
| ip | IP addresses to enrich (IPv4 or IPv6). Supports multiple IPs (comma-separated). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| SOCRadarIoCEnrichment.IP.Indicator | String | The IP address |
| SOCRadarIoCEnrichment.IP.Score | Number | Threat score (0-100) |
| SOCRadarIoCEnrichment.IP.SignalStrength | String | IoC reliability (Very Strong, Strong, Moderate, Slightly Noisy, Noisy) |
| SOCRadarIoCEnrichment.IP.Confidence | String | Cross-source confidence (Very High, High, Medium, Low) |
| SOCRadarIoCEnrichment.IP.Country | String | Country of origin |
| SOCRadarIoCEnrichment.IP.ASN | String | Autonomous System Name |
| SOCRadarIoCEnrichment.IP.FirstSeen | Date | First observed date |
| SOCRadarIoCEnrichment.IP.LastSeen | Date | Last observed date |
| SOCRadarIoCEnrichment.IP.Categorization | Object | Service categorization flags |
| SOCRadarIoCEnrichment.IP.Categorization.Malware | Boolean | Associated with malware |
| SOCRadarIoCEnrichment.IP.Categorization.ThreatActor | Boolean | Associated with threat actors |
| SOCRadarIoCEnrichment.IP.Categorization.Tor | Boolean | Tor exit node |
| SOCRadarIoCEnrichment.IP.Categorization.VPN | Boolean | VPN service |
| SOCRadarIoCEnrichment.IP.Categorization.CDN | Boolean | Content delivery network |
| SOCRadarIoCEnrichment.IP.Categorization.Cloud | Boolean | Cloud hosting |
| SOCRadarIoCEnrichment.IP.Classifications | Object | Threat classifications |
| SOCRadarIoCEnrichment.IP.Classifications.Campaign | String | Associated campaign name |
| SOCRadarIoCEnrichment.IP.Classifications.Malwares | Array | Associated malware families |
| SOCRadarIoCEnrichment.IP.Classifications.ThreatActors | Array | Associated threat actors |
| SOCRadarIoCEnrichment.IP.Classifications.Industries | Array | Targeted industries |
| SOCRadarIoCEnrichment.IP.Classifications.TargetCountries | Array | Targeted countries |
| SOCRadarIoCEnrichment.IP.History | Array | Historical events (last 10) |
| DBotScore.Score | Number | DBot score (0=Unknown, 1=Good, 2=Suspicious, 3=Malicious) |
Command Example
!ip ip="104.251.122.20"
!ip ip="1.1.1.1,8.8.8.8"
domain
Enriches domains with threat intelligence data.
Input
| Argument | Description | Required |
|---|---|---|
| domain | Domain names to enrich. Supports multiple domains (comma-separated). | Required |
Context Output
Similar to IP command, with SOCRadarIoCEnrichment.Domain.* prefix.
Command Example
!domain domain="malicious-site.com"
!domain domain="example.com,test.net"
url
Enriches URLs with threat intelligence data.
Input
| Argument | Description | Required |
|---|---|---|
| url | URLs to enrich. Supports multiple URLs (comma-separated). | Required |
Context Output
Similar to IP command, with SOCRadarIoCEnrichment.URL.* prefix.
Command Example
!url url="https://malicious-site.com/payload.exe"
!url url="http://phishing.example.com,https://c2.attacker.net"
file
Enriches file hashes with threat intelligence data.
Input
| Argument | Description | Required |
|---|---|---|
| file | File hashes to enrich (MD5, SHA1, SHA256). Supports multiple hashes. | Required |
Context Output
Similar to IP command, with SOCRadarIoCEnrichment.File.* prefix.
Command Example
!file file="44d88612fea8a8f36de82e1278abb02f"
!file file="3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"
DBot Score Interpretation
| DBot Score | Meaning | Criteria |
|---|---|---|
| 3 | Malicious | Score > 80 OR Signal Strength = Very Strong/Strong |
| 2 | Suspicious | Score 40-80 OR Signal Strength = Moderate |
| 1 | Good | Score 1-40 |
| 0 | Unknown | Score = 0 or NULL |
Use Cases
1. Incident Investigation
# Enrich suspicious IP from logs
!ip ip="192.168.1.100"
# Check associated domain
!domain domain="suspicious-domain.com"
# Investigate related hash
!file file="abc123def456..."
Output: Get complete threat context including campaigns, threat actors, target industries, and historical activity.
2. Threat Hunting
# Enrich multiple indicators
!ip ip="1.1.1.1,2.2.2.2,3.3.3.3"
Output: Batch enrichment with categorization flags to identify Tor nodes, VPNs, malware C2s, etc.
3. Playbook Enrichment
- id: "1"
task: Enrich Incident IOCs
command: ip
args:
ip: ${incident.sourceip}
- id: "2"
task: Check Signal Strength
condition: ${SOCRadarIoCEnrichment.IP.SignalStrength} == "Very Strong"
nexttasks:
"true":
- Block IP
4. Threat Intelligence Analysis
# Get detailed classification
!ip ip="203.0.113.45"
Output:
- Signal Strength: Very Strong
- Confidence: Very High
- Campaign: APT28 Infrastructure
- Threat Actors: [“APT28”, “Fancy Bear”]
- Target Industries: [“Government”, “Defense”]
- Malwares: [“CHOPSTICK”, “SOURFACE”]
Signal Strength Explained
| Level | Description | Recommended Action |
|---|---|---|
| Very Strong | High-confidence malicious indicator, low false positive rate | Block immediately |
| Strong | Reliable malicious indicator | Block with review |
| Moderate | Potentially malicious, moderate confidence | Monitor/investigate |
| Slightly Noisy | Some legitimate use cases exist | Investigate context |
| Noisy | High false positive rate | Review carefully before action |
Confidence Levels
| Level | Description |
|---|---|
| Very High | Validated across multiple high-quality sources |
| High | Confirmed by multiple sources |
| Medium | Moderate source validation |
| Low | Limited source validation |
Categorization Flags
| Flag | Meaning |
|---|---|
| Malware | Associated with malware distribution/C2 |
| ThreatActor | Attributed to known threat actor |
| Tor | Tor network node |
| VPN | VPN service endpoint |
| Proxy | Proxy service |
| CDN | Content delivery network |
| Cloud | Cloud hosting (AWS, Azure, GCP, etc.) |
| Hosting | Web hosting service |
| Honeypot | Honeypot/research environment |
| Cryptocurrency | Crypto mining/wallet |
| Scanner | Port/vulnerability scanner |
Performance Notes
- AI Insights Excluded: For optimal performance, AI-generated insights are not requested
- Fields Requested: indicator_details, indicator_history, indicator_relations
- Response Time: Typically < 2 seconds per indicator
- Rate Limits: Check your API key’s rate limit with SOCRadar
Troubleshooting
Test Module Fails
Error: “Authorization Error”
- Solution: Verify API key is correct and has IoC Enrichment access
Error: “Connection failed”
- Solution: Check network connectivity to platform.socradar.com
No Data Returned
Issue: Empty response for valid indicator
- Cause: Indicator not in SOCRadar database
- Note: No data doesn’t mean indicator is safe, just unknown to SOCRadar
Rate Limit Exceeded
Error: “Rate limit has been exceeded”
- Solution: Contact SOCRadar to increase rate limit or wait for reset
Best Practices
- Enrich All IOCs: Run enrichment on all indicators during investigation
- Trust Signal Strength: Use signal strength for automated blocking decisions
- Check Categorization: Validate if indicator is CDN/Cloud before blocking
- Review History: Examine historical events for pattern analysis
- Combine with Other Sources: Use alongside other TI feeds for validation
- Playbook Integration: Automate enrichment in incident response playbooks
Additional Resources
- API Documentation: https://platform.socradar.com/docs/api/
- Support: operation@socradar.io
- SOCRadar Platform: https://platform.socradar.com
Version History
- 1.0.0: Initial release with IP, Domain, URL, and File enrichment
Integration Type: Data Enrichment & Threat Intelligence
Vendor: SOCRadar
Support: Community
Categories: Threat Intelligence, IoC Enrichment, Reputation
Configuration parameters
apikey— (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsintegrationReliability— Source Reliabilityinclude_ai_insights— Include AI Insights (slower response time)
Commands (5)
-
domainEnriches domains with SOCRadar IoC threat intelligence data.
-
fileEnriches file hashes with SOCRadar IoC threat intelligence data.
-
ipEnriches IP addresses with SOCRadar IoC threat intelligence data.
-
socradar-ioc-enrichmentGeneric enrichment command with automatic indicator type detection. Enriches any indicator type (IP, domain, URL, hash) without specifying the type.
-
urlEnriches URLs with SOCRadar IoC threat intelligence data.
name: SOCRadarIoCEnrichment display: SOCRadar IoC Enrichment category: Data Enrichment & Threat Intelligence provider: SOCRadar commonfields: id: SOCRadarIoCEnrichment version: -1 sectionorder: - Connect - Collect configuration: - name: apikey displaypassword: API Key required: true type: 9 hiddenusername: true additionalinfo: API Key to access the SOCRadar service. section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged type: 15 required: false section: Collect - additionalinfo: Include AI-generated insights in enrichment results. Warning - This significantly increases response time (2-5x slower) due to AI processing. Recommended to keep disabled for performance. defaultvalue: 'false' display: Include AI Insights (slower response time) name: include_ai_insights type: 8 required: false section: Collect defaultclassifier: 'null' description: Enrich indicators with deep threat intelligence using SOCRadar IoC Enrichment API. Get categorization, signal strength, confidence levels, and historical data. script: commands: - arguments: - default: true description: IP addresses to enrich (IPv4 or IPv6). isArray: true name: ip required: true description: Enriches IP addresses with SOCRadar IoC threat intelligence data. name: ip outputs: - contextPath: SOCRadarIoCEnrichment.IP.Indicator description: The IP address. type: String - contextPath: SOCRadarIoCEnrichment.IP.Score description: Threat score (0-100). type: Number - contextPath: SOCRadarIoCEnrichment.IP.Name description: Associated name/hostname. type: String - contextPath: SOCRadarIoCEnrichment.IP.Country description: Country of origin. type: String - contextPath: SOCRadarIoCEnrichment.IP.ASN description: AS Name. type: String - contextPath: SOCRadarIoCEnrichment.IP.ASNCode description: AS Number. type: Number - contextPath: SOCRadarIoCEnrichment.IP.CIDR description: CIDR block. type: String - contextPath: SOCRadarIoCEnrichment.IP.IsWhitelisted description: Whether the indicator is whitelisted. type: Boolean - contextPath: SOCRadarIoCEnrichment.IP.SignalStrength description: IoC signal strength (Very Strong, Strong, Moderate, Slightly Noisy, Noisy). type: String - contextPath: SOCRadarIoCEnrichment.IP.Confidence description: Cross-source confidence level (Very High, High, Medium, Low). type: String - contextPath: SOCRadarIoCEnrichment.IP.FirstSeen description: First seen date. type: Date - contextPath: SOCRadarIoCEnrichment.IP.LastSeen description: Last seen date. type: Date - contextPath: SOCRadarIoCEnrichment.IP.Activity description: Activity labels for different time periods (Last1Day, Last7Days, Last30Days, Last90Days). type: Unknown - contextPath: SOCRadarIoCEnrichment.IP.Categorization description: Categorization flags (CDN, Cloud, Malware, ThreatActor, etc.). type: Unknown - contextPath: SOCRadarIoCEnrichment.IP.Classifications description: Classifications (Campaign, Malwares, ThreatActors, Industries, etc.). type: Unknown - contextPath: SOCRadarIoCEnrichment.IP.PremiumFeeds description: Premium threat feeds where this indicator appears. type: Unknown - contextPath: SOCRadarIoCEnrichment.IP.Relations description: Related entities (limited to 10). type: Unknown - contextPath: SOCRadarIoCEnrichment.IP.History description: Historical events (limited to 10 most recent). type: Unknown - contextPath: SOCRadarIoCEnrichment.IP.AIInsight description: AI-generated threat intelligence insight (only if AI insights enabled). type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Reliability description: Reliability of the source. type: String - contextPath: IP.Address description: IP address. type: String - arguments: - default: true description: Domain names to enrich. isArray: true name: domain required: true description: Enriches domains with SOCRadar IoC threat intelligence data. name: domain outputs: - contextPath: SOCRadarIoCEnrichment.Domain.Indicator description: The domain name. type: String - contextPath: SOCRadarIoCEnrichment.Domain.Score description: Threat score (0-100). type: Number - contextPath: SOCRadarIoCEnrichment.Domain.Name description: Associated name. type: String - contextPath: SOCRadarIoCEnrichment.Domain.Country description: Country of registration/hosting. type: String - contextPath: SOCRadarIoCEnrichment.Domain.ASN description: AS Name. type: String - contextPath: SOCRadarIoCEnrichment.Domain.ASNCode description: AS Number. type: Number - contextPath: SOCRadarIoCEnrichment.Domain.CIDR description: CIDR block. type: String - contextPath: SOCRadarIoCEnrichment.Domain.IsWhitelisted description: Whether the indicator is whitelisted. type: Boolean - contextPath: SOCRadarIoCEnrichment.Domain.SignalStrength description: IoC signal strength. type: String - contextPath: SOCRadarIoCEnrichment.Domain.Confidence description: Cross-source confidence level. type: String - contextPath: SOCRadarIoCEnrichment.Domain.FirstSeen description: First seen date. type: Date - contextPath: SOCRadarIoCEnrichment.Domain.LastSeen description: Last seen date. type: Date - contextPath: SOCRadarIoCEnrichment.Domain.Activity description: Activity labels for different time periods. type: Unknown - contextPath: SOCRadarIoCEnrichment.Domain.Categorization description: Categorization flags. type: Unknown - contextPath: SOCRadarIoCEnrichment.Domain.Classifications description: Classifications. type: Unknown - contextPath: SOCRadarIoCEnrichment.Domain.PremiumFeeds description: Premium threat feeds where this indicator appears. type: Unknown - contextPath: SOCRadarIoCEnrichment.Domain.Relations description: Related entities. type: Unknown - contextPath: SOCRadarIoCEnrichment.Domain.History description: Historical events. type: Unknown - contextPath: SOCRadarIoCEnrichment.Domain.AIInsight description: AI-generated threat intelligence insight (only if AI insights enabled). type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: Domain.Name description: Domain name. type: String - arguments: - default: true description: URLs to enrich. isArray: true name: url required: true description: Enriches URLs with SOCRadar IoC threat intelligence data. name: url outputs: - contextPath: SOCRadarIoCEnrichment.URL.Indicator description: The URL. type: String - contextPath: SOCRadarIoCEnrichment.URL.Score description: Threat score (0-100). type: Number - contextPath: SOCRadarIoCEnrichment.URL.IsWhitelisted description: Whether the indicator is whitelisted. type: Boolean - contextPath: SOCRadarIoCEnrichment.URL.SignalStrength description: IoC signal strength. type: String - contextPath: SOCRadarIoCEnrichment.URL.Confidence description: Cross-source confidence level. type: String - contextPath: SOCRadarIoCEnrichment.URL.FirstSeen description: First seen date. type: Date - contextPath: SOCRadarIoCEnrichment.URL.LastSeen description: Last seen date. type: Date - contextPath: SOCRadarIoCEnrichment.URL.Activity description: Activity labels for different time periods. type: Unknown - contextPath: SOCRadarIoCEnrichment.URL.Categorization description: Categorization flags. type: Unknown - contextPath: SOCRadarIoCEnrichment.URL.Classifications description: Classifications. type: Unknown - contextPath: SOCRadarIoCEnrichment.URL.PremiumFeeds description: Premium threat feeds where this indicator appears. type: Unknown - contextPath: SOCRadarIoCEnrichment.URL.Relations description: Related entities. type: Unknown - contextPath: SOCRadarIoCEnrichment.URL.History description: Historical events. type: Unknown - contextPath: SOCRadarIoCEnrichment.URL.AIInsight description: AI-generated threat intelligence insight (only if AI insights enabled). type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: URL.Data description: URL. type: String - arguments: - default: true description: File hashes to enrich (MD5, SHA1, SHA256). isArray: true name: file required: true description: Enriches file hashes with SOCRadar IoC threat intelligence data. name: file outputs: - contextPath: SOCRadarIoCEnrichment.File.Indicator description: The file hash. type: String - contextPath: SOCRadarIoCEnrichment.File.Score description: Threat score (0-100). type: Number - contextPath: SOCRadarIoCEnrichment.File.IsWhitelisted description: Whether the indicator is whitelisted. type: Boolean - contextPath: SOCRadarIoCEnrichment.File.SignalStrength description: IoC signal strength. type: String - contextPath: SOCRadarIoCEnrichment.File.Confidence description: Cross-source confidence level. type: String - contextPath: SOCRadarIoCEnrichment.File.FirstSeen description: First seen date. type: Date - contextPath: SOCRadarIoCEnrichment.File.LastSeen description: Last seen date. type: Date - contextPath: SOCRadarIoCEnrichment.File.Activity description: Activity labels for different time periods. type: Unknown - contextPath: SOCRadarIoCEnrichment.File.Categorization description: Categorization flags. type: Unknown - contextPath: SOCRadarIoCEnrichment.File.Classifications description: Classifications (Malwares, Campaigns, ThreatActors). type: Unknown - contextPath: SOCRadarIoCEnrichment.File.PremiumFeeds description: Premium threat feeds where this indicator appears. type: Unknown - contextPath: SOCRadarIoCEnrichment.File.Relations description: Related entities. type: Unknown - contextPath: SOCRadarIoCEnrichment.File.History description: Historical events. type: Unknown - contextPath: SOCRadarIoCEnrichment.File.AIInsight description: AI-generated threat intelligence insight (only if AI insights enabled). type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: File.MD5 description: MD5 hash. type: String - contextPath: File.SHA1 description: SHA1 hash. type: String - contextPath: File.SHA256 description: SHA256 hash. type: String - arguments: - description: Indicator to enrich (IP, domain, URL, or hash). Type is automatically detected. name: indicator required: true description: Generic enrichment command with automatic indicator type detection. Enriches any indicator type (IP, domain, URL, hash) without specifying the type. name: socradar-ioc-enrichment outputs: - contextPath: SOCRadarIoCEnrichment.IP.Indicator description: The indicator (if IP). type: String - contextPath: SOCRadarIoCEnrichment.Domain.Indicator description: The indicator (if domain). type: String - contextPath: SOCRadarIoCEnrichment.URL.Indicator description: The indicator (if URL). type: String - contextPath: SOCRadarIoCEnrichment.File.Indicator description: The indicator (if hash). type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python fromversion: 6.10.0 tests: - No tests