SOCRadarIoCEnrichment

Enrich indicators with deep threat intelligence using SOCRadar IoC Enrichment API. Get categorization, signal strength, confidence levels, and historical data.

Data Enrichment & Threat Intelligence · SOCRadar

Details

IDSOCRadarIoCEnrichment
ProviderSOCRadar
CategoryData Enrichment & Threat Intelligence
From Version6.10.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

SOCRadar IoC Enrichment Integration

Overview

The SOCRadar IoC Enrichment integration provides deep threat intelligence enrichment for indicators of compromise (IoCs). Get comprehensive data including categorization, signal strength, confidence levels, historical events, threat actor attribution, and campaign associations.

Key Features

  • Rich Threat Context: Detailed categorization (CDN, Cloud, Malware, ThreatActor, Tor, VPN, etc.)
  • Signal Strength: IoC reliability assessment (Very Strong to Noisy)
  • Confidence Levels: Cross-source validation (Very High, High, Medium, Low)
  • Historical Data: Timeline of indicator activity across threat feeds
  • Threat Attribution: Associated campaigns, threat actors, malware families
  • Target Intelligence: Industries and countries targeted
  • Performance Optimized: AI insights excluded for fast responses

Configuration

Prerequisites

  • SOCRadar API Key with IoC Enrichment access
  • Network access to platform.socradar.com

Setup

  1. Navigate to SettingsIntegrationsServers & Services
  2. Search for “SOCRadar IoC Enrichment”
  3. Click Add Instance
  4. Configure:
    • Name: Instance name
    • API Key: Your SOCRadar API key
    • Source Reliability: B - Usually reliable (recommended)
  5. Click Test to validate
  6. Click Save & Exit

Commands

ip

Enriches IP addresses with threat intelligence data.

Input

Argument Description Required
ip IP addresses to enrich (IPv4 or IPv6). Supports multiple IPs (comma-separated). Required

Context Output

Path Type Description
SOCRadarIoCEnrichment.IP.Indicator String The IP address
SOCRadarIoCEnrichment.IP.Score Number Threat score (0-100)
SOCRadarIoCEnrichment.IP.SignalStrength String IoC reliability (Very Strong, Strong, Moderate, Slightly Noisy, Noisy)
SOCRadarIoCEnrichment.IP.Confidence String Cross-source confidence (Very High, High, Medium, Low)
SOCRadarIoCEnrichment.IP.Country String Country of origin
SOCRadarIoCEnrichment.IP.ASN String Autonomous System Name
SOCRadarIoCEnrichment.IP.FirstSeen Date First observed date
SOCRadarIoCEnrichment.IP.LastSeen Date Last observed date
SOCRadarIoCEnrichment.IP.Categorization Object Service categorization flags
SOCRadarIoCEnrichment.IP.Categorization.Malware Boolean Associated with malware
SOCRadarIoCEnrichment.IP.Categorization.ThreatActor Boolean Associated with threat actors
SOCRadarIoCEnrichment.IP.Categorization.Tor Boolean Tor exit node
SOCRadarIoCEnrichment.IP.Categorization.VPN Boolean VPN service
SOCRadarIoCEnrichment.IP.Categorization.CDN Boolean Content delivery network
SOCRadarIoCEnrichment.IP.Categorization.Cloud Boolean Cloud hosting
SOCRadarIoCEnrichment.IP.Classifications Object Threat classifications
SOCRadarIoCEnrichment.IP.Classifications.Campaign String Associated campaign name
SOCRadarIoCEnrichment.IP.Classifications.Malwares Array Associated malware families
SOCRadarIoCEnrichment.IP.Classifications.ThreatActors Array Associated threat actors
SOCRadarIoCEnrichment.IP.Classifications.Industries Array Targeted industries
SOCRadarIoCEnrichment.IP.Classifications.TargetCountries Array Targeted countries
SOCRadarIoCEnrichment.IP.History Array Historical events (last 10)
DBotScore.Score Number DBot score (0=Unknown, 1=Good, 2=Suspicious, 3=Malicious)

Command Example

!ip ip="104.251.122.20"
!ip ip="1.1.1.1,8.8.8.8"

domain

Enriches domains with threat intelligence data.

Input

Argument Description Required
domain Domain names to enrich. Supports multiple domains (comma-separated). Required

Context Output

Similar to IP command, with SOCRadarIoCEnrichment.Domain.* prefix.

Command Example

!domain domain="malicious-site.com"
!domain domain="example.com,test.net"

url

Enriches URLs with threat intelligence data.

Input

Argument Description Required
url URLs to enrich. Supports multiple URLs (comma-separated). Required

Context Output

Similar to IP command, with SOCRadarIoCEnrichment.URL.* prefix.

Command Example

!url url="https://malicious-site.com/payload.exe"
!url url="http://phishing.example.com,https://c2.attacker.net"

file

Enriches file hashes with threat intelligence data.

Input

Argument Description Required
file File hashes to enrich (MD5, SHA1, SHA256). Supports multiple hashes. Required

Context Output

Similar to IP command, with SOCRadarIoCEnrichment.File.* prefix.

Command Example

!file file="44d88612fea8a8f36de82e1278abb02f"
!file file="3b7b359ea17ac76341957573e332a2d6bcac363401ac71c8df94dac93df6d792"

DBot Score Interpretation

DBot Score Meaning Criteria
3 Malicious Score > 80 OR Signal Strength = Very Strong/Strong
2 Suspicious Score 40-80 OR Signal Strength = Moderate
1 Good Score 1-40
0 Unknown Score = 0 or NULL

Use Cases

1. Incident Investigation

# Enrich suspicious IP from logs
!ip ip="192.168.1.100"

# Check associated domain
!domain domain="suspicious-domain.com"

# Investigate related hash
!file file="abc123def456..."

Output: Get complete threat context including campaigns, threat actors, target industries, and historical activity.

2. Threat Hunting

# Enrich multiple indicators
!ip ip="1.1.1.1,2.2.2.2,3.3.3.3"

Output: Batch enrichment with categorization flags to identify Tor nodes, VPNs, malware C2s, etc.

3. Playbook Enrichment

- id: "1"
  task: Enrich Incident IOCs
  command: ip
  args:
    ip: ${incident.sourceip}

- id: "2"
  task: Check Signal Strength
  condition: ${SOCRadarIoCEnrichment.IP.SignalStrength} == "Very Strong"
  nexttasks:
    "true":
      - Block IP

4. Threat Intelligence Analysis

# Get detailed classification
!ip ip="203.0.113.45"

Output:

  • Signal Strength: Very Strong
  • Confidence: Very High
  • Campaign: APT28 Infrastructure
  • Threat Actors: [“APT28”, “Fancy Bear”]
  • Target Industries: [“Government”, “Defense”]
  • Malwares: [“CHOPSTICK”, “SOURFACE”]

Signal Strength Explained

Level Description Recommended Action
Very Strong High-confidence malicious indicator, low false positive rate Block immediately
Strong Reliable malicious indicator Block with review
Moderate Potentially malicious, moderate confidence Monitor/investigate
Slightly Noisy Some legitimate use cases exist Investigate context
Noisy High false positive rate Review carefully before action

Confidence Levels

Level Description
Very High Validated across multiple high-quality sources
High Confirmed by multiple sources
Medium Moderate source validation
Low Limited source validation

Categorization Flags

Flag Meaning
Malware Associated with malware distribution/C2
ThreatActor Attributed to known threat actor
Tor Tor network node
VPN VPN service endpoint
Proxy Proxy service
CDN Content delivery network
Cloud Cloud hosting (AWS, Azure, GCP, etc.)
Hosting Web hosting service
Honeypot Honeypot/research environment
Cryptocurrency Crypto mining/wallet
Scanner Port/vulnerability scanner

Performance Notes

  • AI Insights Excluded: For optimal performance, AI-generated insights are not requested
  • Fields Requested: indicator_details, indicator_history, indicator_relations
  • Response Time: Typically < 2 seconds per indicator
  • Rate Limits: Check your API key’s rate limit with SOCRadar

Troubleshooting

Test Module Fails

Error: “Authorization Error”

  • Solution: Verify API key is correct and has IoC Enrichment access

Error: “Connection failed”

  • Solution: Check network connectivity to platform.socradar.com

No Data Returned

Issue: Empty response for valid indicator

  • Cause: Indicator not in SOCRadar database
  • Note: No data doesn’t mean indicator is safe, just unknown to SOCRadar

Rate Limit Exceeded

Error: “Rate limit has been exceeded”

  • Solution: Contact SOCRadar to increase rate limit or wait for reset

Best Practices

  1. Enrich All IOCs: Run enrichment on all indicators during investigation
  2. Trust Signal Strength: Use signal strength for automated blocking decisions
  3. Check Categorization: Validate if indicator is CDN/Cloud before blocking
  4. Review History: Examine historical events for pattern analysis
  5. Combine with Other Sources: Use alongside other TI feeds for validation
  6. Playbook Integration: Automate enrichment in incident response playbooks

Additional Resources


Version History

  • 1.0.0: Initial release with IP, Domain, URL, and File enrichment

Integration Type: Data Enrichment & Threat Intelligence
Vendor: SOCRadar
Support: Community
Categories: Threat Intelligence, IoC Enrichment, Reputation

Configuration parameters

  • apikey — (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • integrationReliability — Source Reliability
  • include_ai_insights — Include AI Insights (slower response time)

Commands (5)

  • domain

    Enriches domains with SOCRadar IoC threat intelligence data.

  • file

    Enriches file hashes with SOCRadar IoC threat intelligence data.

  • ip

    Enriches IP addresses with SOCRadar IoC threat intelligence data.

  • socradar-ioc-enrichment

    Generic enrichment command with automatic indicator type detection. Enriches any indicator type (IP, domain, URL, hash) without specifying the type.

  • url

    Enriches URLs with SOCRadar IoC threat intelligence data.

name: SOCRadarIoCEnrichment
display: SOCRadar IoC Enrichment
category: Data Enrichment & Threat Intelligence
provider: SOCRadar
commonfields:
  id: SOCRadarIoCEnrichment
  version: -1
sectionorder:
- Connect
- Collect
configuration:
- name: apikey
  displaypassword: API Key
  required: true
  type: 9
  hiddenusername: true
  additionalinfo: API Key to access the SOCRadar service.
  section: Connect
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
  section: Connect
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
  section: Connect
- additionalinfo: Reliability of the source providing the intelligence data.
  defaultvalue: B - Usually reliable
  display: Source Reliability
  name: integrationReliability
  options:
  - A+ - 3rd party enrichment
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  type: 15
  required: false
  section: Collect
- additionalinfo: Include AI-generated insights in enrichment results. Warning - This significantly increases response time (2-5x slower) due to AI processing. Recommended to keep disabled for performance.
  defaultvalue: 'false'
  display: Include AI Insights (slower response time)
  name: include_ai_insights
  type: 8
  required: false
  section: Collect
defaultclassifier: 'null'
description: Enrich indicators with deep threat intelligence using SOCRadar IoC Enrichment API. Get categorization, signal strength, confidence levels, and historical data.
script:
  commands:
  - arguments:
    - default: true
      description: IP addresses to enrich (IPv4 or IPv6).
      isArray: true
      name: ip
      required: true
    description: Enriches IP addresses with SOCRadar IoC threat intelligence data.
    name: ip
    outputs:
    - contextPath: SOCRadarIoCEnrichment.IP.Indicator
      description: The IP address.
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.Score
      description: Threat score (0-100).
      type: Number
    - contextPath: SOCRadarIoCEnrichment.IP.Name
      description: Associated name/hostname.
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.Country
      description: Country of origin.
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.ASN
      description: AS Name.
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.ASNCode
      description: AS Number.
      type: Number
    - contextPath: SOCRadarIoCEnrichment.IP.CIDR
      description: CIDR block.
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.IsWhitelisted
      description: Whether the indicator is whitelisted.
      type: Boolean
    - contextPath: SOCRadarIoCEnrichment.IP.SignalStrength
      description: IoC signal strength (Very Strong, Strong, Moderate, Slightly Noisy, Noisy).
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.Confidence
      description: Cross-source confidence level (Very High, High, Medium, Low).
      type: String
    - contextPath: SOCRadarIoCEnrichment.IP.FirstSeen
      description: First seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.IP.LastSeen
      description: Last seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.IP.Activity
      description: Activity labels for different time periods (Last1Day, Last7Days, Last30Days, Last90Days).
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.IP.Categorization
      description: Categorization flags (CDN, Cloud, Malware, ThreatActor, etc.).
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.IP.Classifications
      description: Classifications (Campaign, Malwares, ThreatActors, Industries, etc.).
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.IP.PremiumFeeds
      description: Premium threat feeds where this indicator appears.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.IP.Relations
      description: Related entities (limited to 10).
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.IP.History
      description: Historical events (limited to 10 most recent).
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.IP.AIInsight
      description: AI-generated threat intelligence insight (only if AI insights enabled).
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Reliability
      description: Reliability of the source.
      type: String
    - contextPath: IP.Address
      description: IP address.
      type: String
  - arguments:
    - default: true
      description: Domain names to enrich.
      isArray: true
      name: domain
      required: true
    description: Enriches domains with SOCRadar IoC threat intelligence data.
    name: domain
    outputs:
    - contextPath: SOCRadarIoCEnrichment.Domain.Indicator
      description: The domain name.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.Score
      description: Threat score (0-100).
      type: Number
    - contextPath: SOCRadarIoCEnrichment.Domain.Name
      description: Associated name.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.Country
      description: Country of registration/hosting.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.ASN
      description: AS Name.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.ASNCode
      description: AS Number.
      type: Number
    - contextPath: SOCRadarIoCEnrichment.Domain.CIDR
      description: CIDR block.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.IsWhitelisted
      description: Whether the indicator is whitelisted.
      type: Boolean
    - contextPath: SOCRadarIoCEnrichment.Domain.SignalStrength
      description: IoC signal strength.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.Confidence
      description: Cross-source confidence level.
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.FirstSeen
      description: First seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.Domain.LastSeen
      description: Last seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.Domain.Activity
      description: Activity labels for different time periods.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.Domain.Categorization
      description: Categorization flags.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.Domain.Classifications
      description: Classifications.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.Domain.PremiumFeeds
      description: Premium threat feeds where this indicator appears.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.Domain.Relations
      description: Related entities.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.Domain.History
      description: Historical events.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.Domain.AIInsight
      description: AI-generated threat intelligence insight (only if AI insights enabled).
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: Domain.Name
      description: Domain name.
      type: String
  - arguments:
    - default: true
      description: URLs to enrich.
      isArray: true
      name: url
      required: true
    description: Enriches URLs with SOCRadar IoC threat intelligence data.
    name: url
    outputs:
    - contextPath: SOCRadarIoCEnrichment.URL.Indicator
      description: The URL.
      type: String
    - contextPath: SOCRadarIoCEnrichment.URL.Score
      description: Threat score (0-100).
      type: Number
    - contextPath: SOCRadarIoCEnrichment.URL.IsWhitelisted
      description: Whether the indicator is whitelisted.
      type: Boolean
    - contextPath: SOCRadarIoCEnrichment.URL.SignalStrength
      description: IoC signal strength.
      type: String
    - contextPath: SOCRadarIoCEnrichment.URL.Confidence
      description: Cross-source confidence level.
      type: String
    - contextPath: SOCRadarIoCEnrichment.URL.FirstSeen
      description: First seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.URL.LastSeen
      description: Last seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.URL.Activity
      description: Activity labels for different time periods.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.URL.Categorization
      description: Categorization flags.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.URL.Classifications
      description: Classifications.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.URL.PremiumFeeds
      description: Premium threat feeds where this indicator appears.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.URL.Relations
      description: Related entities.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.URL.History
      description: Historical events.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.URL.AIInsight
      description: AI-generated threat intelligence insight (only if AI insights enabled).
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: URL.Data
      description: URL.
      type: String
  - arguments:
    - default: true
      description: File hashes to enrich (MD5, SHA1, SHA256).
      isArray: true
      name: file
      required: true
    description: Enriches file hashes with SOCRadar IoC threat intelligence data.
    name: file
    outputs:
    - contextPath: SOCRadarIoCEnrichment.File.Indicator
      description: The file hash.
      type: String
    - contextPath: SOCRadarIoCEnrichment.File.Score
      description: Threat score (0-100).
      type: Number
    - contextPath: SOCRadarIoCEnrichment.File.IsWhitelisted
      description: Whether the indicator is whitelisted.
      type: Boolean
    - contextPath: SOCRadarIoCEnrichment.File.SignalStrength
      description: IoC signal strength.
      type: String
    - contextPath: SOCRadarIoCEnrichment.File.Confidence
      description: Cross-source confidence level.
      type: String
    - contextPath: SOCRadarIoCEnrichment.File.FirstSeen
      description: First seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.File.LastSeen
      description: Last seen date.
      type: Date
    - contextPath: SOCRadarIoCEnrichment.File.Activity
      description: Activity labels for different time periods.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.File.Categorization
      description: Categorization flags.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.File.Classifications
      description: Classifications (Malwares, Campaigns, ThreatActors).
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.File.PremiumFeeds
      description: Premium threat feeds where this indicator appears.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.File.Relations
      description: Related entities.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.File.History
      description: Historical events.
      type: Unknown
    - contextPath: SOCRadarIoCEnrichment.File.AIInsight
      description: AI-generated threat intelligence insight (only if AI insights enabled).
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: File.MD5
      description: MD5 hash.
      type: String
    - contextPath: File.SHA1
      description: SHA1 hash.
      type: String
    - contextPath: File.SHA256
      description: SHA256 hash.
      type: String
  - arguments:
    - description: Indicator to enrich (IP, domain, URL, or hash). Type is automatically detected.
      name: indicator
      required: true
    description: Generic enrichment command with automatic indicator type detection. Enriches any indicator type (IP, domain, URL, hash) without specifying the type.
    name: socradar-ioc-enrichment
    outputs:
    - contextPath: SOCRadarIoCEnrichment.IP.Indicator
      description: The indicator (if IP).
      type: String
    - contextPath: SOCRadarIoCEnrichment.Domain.Indicator
      description: The indicator (if domain).
      type: String
    - contextPath: SOCRadarIoCEnrichment.URL.Indicator
      description: The indicator (if URL).
      type: String
    - contextPath: SOCRadarIoCEnrichment.File.Indicator
      description: The indicator (if hash).
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
  dockerimage: demisto/python3:3.12.13.10116658
  runonce: false
  script: '-'
  subtype: python3
  type: python
fromversion: 6.10.0
tests:
- No tests