Sixgill_Darkfeed
Leverage the power of Sixgill to supercharge Cortex XSOAR with real-time Threat Intelligence indicators. Get IOCs such as domains, URLs, hashes, and IP addresses straight into the XSOAR platform.
Data Enrichment & Threat Intelligence · Sixgill Darkfeed - Annual Subscription · Feed
Details
| ID | Sixgill_Darkfeed |
|---|---|
| Provider | Bitsight |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/sixgill:1.0.0.10120494 |
| Supported Modules | Agentix XSIAM |
README
Sixgill’s premium underground intelligence collection capabilities, real-time collection and advanced warnings of IOCs help you keep your edge against unknown threats.
This integration was integrated and tested with Sixgill clients.
Configure Sixgill_Darkfeed on XSOAR
| Parameter | Description | Required |
|---|---|---|
| client_id | Sixgill API client ID. | True |
| client_secret | Sixgill API client secret. | True |
| feed | Fetch indicators. | False |
| feedReputation | The reputation to apply to the fetched indicators. | False |
| feedReliability | The reliability of the this feed. | True |
| tlp_color | The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlp | False |
| feedExpirationPolicy | False | |
| feedExpirationInterval | False | |
| feedFetchInterval | Feed Fetch Interval | False |
| feedBypassExclusionList | Bypass exclusion list | False |
| maxIndicators | The maximum number of indicators to fetch. | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
Fetch indicators
Fetching Sixgill DarkFeed indicators
Required Permissions
- A valid Sixgill API client id and client secret.
Base Command
sixgill-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. | Optional |
Context Output
There is no context output for this command.
Command Example
!sixgill-get-indicators
Human Readable Output
Indicators from Sixgill Dark Feed
| value | type | rawJSON | score |
|---|---|---|---|
| https://dropmefiles.com/TgvuH | URL | created: 2020-02-06T10:03:54.091Z description: Malware available for download from file-sharing sites external_reference: {'description': 'Mitre attack tactics and technique reference', 'mitre_attack_tactic': 'Build Capabilities', 'mitre_attack_tactic_id': 'TA0024', 'mitre_attack_tactic_url': 'https://attack.mitre.org/tactics/TA0024/', 'mitre_attack_technique': 'Obtain/re-use payloads', 'mitre_attack_technique_id': 'T1346', 'mitre_attack_technique_url': 'https://attack.mitre.org/techniques/T1346/', 'source_name': 'mitre-attack'} id: indicator--7a39257a-83d4-4f39-90d1-5b81ce1156e9 labels: malicious-activity, malware, Build Capabilities, Obtain/re-use payloads lang: en modified: 2020-02-06T10:03:54.091Z object_marking_refs: marking-definition--41eaaf7c-0bc0-4c56-abdf-d89a7f096ac4, marking-definition--f88d31f6-486f-44da-b317-01333bde0b82 pattern: [url:value = 'https://dropmefiles.com/TgvuH'] sixgill_actor: vvv555 sixgill_confidence: 80 sixgill_feedid: darkfeed_010 sixgill_feedname: malware_download_urls sixgill_postid: 2f1dcc205421d20a4038b9f51b9d2c5b0b7451d1 sixgill_posttitle: SOCKS socks4 sixgill_severity: 80 sixgill_source: forum_bhf spec_version: 2.0 type: indicator valid_from: 2020-01-06T03:00:59Z |
3 |
Output
[{
'value': 'https://dropmefiles.com/TgvuH',
'type': 'URL',
'rawJSON':
{'created': '2020-02-06T10:03:54.091Z',
'description': 'Malware available for download from file-sharing sites',
'external_reference': [{
'description': 'Mitre attack tactics and technique reference',
'mitre_attack_tactic': 'Build Capabilities',
'mitre_attack_tactic_id': 'TA0024',
'mitre_attack_tactic_url': 'https://attack.mitre.org/tactics/TA0024/',
'mitre_attack_technique': 'Obtain/re-use payloads',
'mitre_attack_technique_id': 'T1346',
'mitre_attack_technique_url': 'https://attack.mitre.org/techniques/T1346/',
'source_name': 'mitre-attack'
}],
'id': 'indicator--7a39257a-83d4-4f39-90d1-5b81ce1156e9',
'labels': ['malicious-activity', 'malware', 'Build Capabilities', 'Obtain/re-use payloads'],
'lang': 'en',
'modified': '2020-02-06T10:03:54.091Z',
'object_marking_refs': [
'marking-definition--41eaaf7c-0bc0-4c56-abdf-d89a7f096ac4',
'marking-definition--f88d31f6-486f-44da-b317-01333bde0b82'
],
'pattern': "[url:value = 'https://dropmefiles.com/TgvuH']",
'sixgill_actor': 'vvv555',
'sixgill_confidence': 80,
'sixgill_feedid': 'darkfeed_010',
'sixgill_feedname': 'malware_download_urls',
'sixgill_postid': '2f1dcc205421d20a4038b9f51b9d2c5b0b7451d1',
'sixgill_posttitle': 'SOCKS socks4',
'sixgill_severity': 80,
'sixgill_source': 'forum_bhf',
'spec_version': '2.0',
'type': 'indicator',
'valid_from': '2020-01-06T03:00:59Z'
},
'fields': {
'source': 'forum_bhf',
'name': 'malware_download_urls',
'description': "description: Malware available for download from file-sharing sites\n
feedid: darkfeed_010\n
title: SOCKS socks4\n
post_id: 2f1dcc205421d20a4038b9f51b9d2c5b0b7451d1\n
actor: vvv555\nlang: en\n
labels: ['malicious-activity', 'malware', 'Build Capabilities', 'Obtain/re-use payloads']\n
external_reference: [{'description': 'Mitre attack tactics and technique reference',
'mitre_attack_tactic': 'Build Capabilities',
'mitre_attack_tactic_id': 'TA0024',
'mitre_attack_tactic_url': 'https://attack.mitre.org/tactics/TA0024/',
'mitre_attack_technique': 'Obtain/re-use payloads',
'mitre_attack_technique_id': 'T1346',
'mitre_attack_technique_url': 'https://attack.mitre.org/techniques/T1346/',
'source_name': 'mitre-attack'}]"},
'score': 3
}]
Additional Information
Contact us: sales@cybersixgill.com
Configuration parameters
client_id— Sixgill API client ID (required)client_secret— Sixgill API client secret (required)confidence— Sixgill Confidencefeed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—feedExpirationInterval—feedFetchInterval— Feed Fetch IntervalmaxIndicators— The maximum number of indicators to fetch.feedBypassExclusionList— Bypass exclusion listproxy— Use system proxy settingsfeedIncremental— Incremental Feedinsecure— Trust any certificate (not secure)feedTags— Tags
Commands (1)
-
sixgill-get-indicatorsFetching Sixgill DarkFeed indicators.
category: Data Enrichment & Threat Intelligence provider: Bitsight sectionorder: - Connect - Collect commonfields: id: Sixgill_Darkfeed version: -1 configuration: - display: Sixgill API client ID name: client_id required: true type: 0 section: Connect - display: Sixgill API client secret name: client_secret required: true type: 4 section: Connect - defaultvalue: 'all' display: Sixgill Confidence name: confidence type: 15 options: - all - "90" - "80" - "70" - "60" additionalinfo: 'Ingest all IOCs=all, IOC exactly fits description=90, IOC almost exactly fits description=80, IOC mostly fits description=70, IOC generally fits description=60' required: false section: Collect - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: feedInstanceReputationNotSet display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 defaultvalue: B - Usually reliable section: Collect - name: tlp_color display: "Traffic Light Protocol Color" options: - RED - AMBER - GREEN - WHITE type: 15 additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed required: false section: Collect - defaultvalue: 'indicatorType' display: "" name: feedExpirationPolicy type: 17 options: - never - interval - indicatorType required: false section: Collect - defaultvalue: '20160' display: "" name: feedExpirationInterval type: 1 required: false section: Collect - defaultvalue: '2' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect - display: The maximum number of indicators to fetch. name: maxIndicators type: 0 defaultvalue: '1000' required: false section: Collect - display: Bypass exclusion list name: feedBypassExclusionList type: 8 additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. required: false section: Collect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Incremental Feed name: feedIncremental type: 8 defaultvalue: 'true' hidden: true required: false section: Collect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false section: Collect description: Leverage the power of Sixgill to supercharge Cortex XSOAR with real-time Threat Intelligence indicators. Get IOCs such as domains, URLs, hashes, and IP addresses straight into the XSOAR platform. display: Sixgill DarkFeed Threat Intelligence name: Sixgill_Darkfeed script: script: '-' commands: - arguments: - default: true defaultValue: '50' description: The maximum number of results to return. name: limit description: Fetching Sixgill DarkFeed indicators. execution: true name: sixgill-get-indicators dockerimage: demisto/sixgill:1.0.0.10120494 feed: true runonce: false subtype: python3 type: python fromversion: 5.5.0 tests: - No tests (auto formatted)