Sixgill_Darkfeed

Leverage the power of Sixgill to supercharge Cortex XSOAR with real-time Threat Intelligence indicators. Get IOCs such as domains, URLs, hashes, and IP addresses straight into the XSOAR platform.

Data Enrichment & Threat Intelligence · Sixgill Darkfeed - Annual Subscription · Feed

Details

IDSixgill_Darkfeed
ProviderBitsight
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/sixgill:1.0.0.10120494
Supported ModulesAgentix XSIAM

README

Sixgill’s premium underground intelligence collection capabilities, real-time collection and advanced warnings of IOCs help you keep your edge against unknown threats.
This integration was integrated and tested with Sixgill clients.

Configure Sixgill_Darkfeed on XSOAR

Parameter Description Required
client_id Sixgill API client ID. True
client_secret Sixgill API client secret. True
feed Fetch indicators. False
feedReputation The reputation to apply to the fetched indicators. False
feedReliability The reliability of the this feed. True
tlp_color The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. More information about the protocol can be found at https://us-cert.cisa.gov/tlp False
feedExpirationPolicy   False
feedExpirationInterval   False
feedFetchInterval Feed Fetch Interval False
feedBypassExclusionList Bypass exclusion list False
maxIndicators The maximum number of indicators to fetch. False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

Fetch indicators


Fetching Sixgill DarkFeed indicators

Required Permissions
  • A valid Sixgill API client id and client secret.
Base Command

sixgill-get-indicators

Input
Argument Name Description Required
limit The maximum number of results to return. Optional
Context Output

There is no context output for this command.

Command Example

!sixgill-get-indicators

Human Readable Output

Indicators from Sixgill Dark Feed

value type rawJSON score
https://dropmefiles.com/TgvuH URL created: 2020-02-06T10:03:54.091Z description: Malware available for download from file-sharing sites external_reference: {'description': 'Mitre attack tactics and technique reference', 'mitre_attack_tactic': 'Build Capabilities', 'mitre_attack_tactic_id': 'TA0024', 'mitre_attack_tactic_url': 'https://attack.mitre.org/tactics/TA0024/', 'mitre_attack_technique': 'Obtain/re-use payloads', 'mitre_attack_technique_id': 'T1346', 'mitre_attack_technique_url': 'https://attack.mitre.org/techniques/T1346/', 'source_name': 'mitre-attack'} id: indicator--7a39257a-83d4-4f39-90d1-5b81ce1156e9 labels: malicious-activity, malware, Build Capabilities, Obtain/re-use payloads lang: en modified: 2020-02-06T10:03:54.091Z object_marking_refs: marking-definition--41eaaf7c-0bc0-4c56-abdf-d89a7f096ac4, marking-definition--f88d31f6-486f-44da-b317-01333bde0b82 pattern: [url:value = 'https://dropmefiles.com/TgvuH'] sixgill_actor: vvv555 sixgill_confidence: 80 sixgill_feedid: darkfeed_010 sixgill_feedname: malware_download_urls sixgill_postid: 2f1dcc205421d20a4038b9f51b9d2c5b0b7451d1 sixgill_posttitle: SOCKS socks4 sixgill_severity: 80 sixgill_source: forum_bhf spec_version: 2.0 type: indicator valid_from: 2020-01-06T03:00:59Z 3

Output

[{ 'value': 'https://dropmefiles.com/TgvuH', 'type': 'URL', 'rawJSON': {'created': '2020-02-06T10:03:54.091Z', 'description': 'Malware available for download from file-sharing sites', 'external_reference': [{ 'description': 'Mitre attack tactics and technique reference', 'mitre_attack_tactic': 'Build Capabilities', 'mitre_attack_tactic_id': 'TA0024', 'mitre_attack_tactic_url': 'https://attack.mitre.org/tactics/TA0024/', 'mitre_attack_technique': 'Obtain/re-use payloads', 'mitre_attack_technique_id': 'T1346', 'mitre_attack_technique_url': 'https://attack.mitre.org/techniques/T1346/', 'source_name': 'mitre-attack' }], 'id': 'indicator--7a39257a-83d4-4f39-90d1-5b81ce1156e9', 'labels': ['malicious-activity', 'malware', 'Build Capabilities', 'Obtain/re-use payloads'], 'lang': 'en', 'modified': '2020-02-06T10:03:54.091Z', 'object_marking_refs': [ 'marking-definition--41eaaf7c-0bc0-4c56-abdf-d89a7f096ac4', 'marking-definition--f88d31f6-486f-44da-b317-01333bde0b82' ], 'pattern': "[url:value = 'https://dropmefiles.com/TgvuH']", 'sixgill_actor': 'vvv555', 'sixgill_confidence': 80, 'sixgill_feedid': 'darkfeed_010', 'sixgill_feedname': 'malware_download_urls', 'sixgill_postid': '2f1dcc205421d20a4038b9f51b9d2c5b0b7451d1', 'sixgill_posttitle': 'SOCKS socks4', 'sixgill_severity': 80, 'sixgill_source': 'forum_bhf', 'spec_version': '2.0', 'type': 'indicator', 'valid_from': '2020-01-06T03:00:59Z' }, 'fields': { 'source': 'forum_bhf', 'name': 'malware_download_urls', 'description': "description: Malware available for download from file-sharing sites\n feedid: darkfeed_010\n title: SOCKS socks4\n post_id: 2f1dcc205421d20a4038b9f51b9d2c5b0b7451d1\n actor: vvv555\nlang: en\n labels: ['malicious-activity', 'malware', 'Build Capabilities', 'Obtain/re-use payloads']\n external_reference: [{'description': 'Mitre attack tactics and technique reference', 'mitre_attack_tactic': 'Build Capabilities', 'mitre_attack_tactic_id': 'TA0024', 'mitre_attack_tactic_url': 'https://attack.mitre.org/tactics/TA0024/', 'mitre_attack_technique': 'Obtain/re-use payloads', 'mitre_attack_technique_id': 'T1346', 'mitre_attack_technique_url': 'https://attack.mitre.org/techniques/T1346/', 'source_name': 'mitre-attack'}]"}, 'score': 3 }]

Additional Information

Contact us: sales@cybersixgill.com

Configuration parameters

  • client_id — Sixgill API client ID (required)
  • client_secret — Sixgill API client secret (required)
  • confidence — Sixgill Confidence
  • feed — Fetch indicators
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • tlp_color — Traffic Light Protocol Color
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • maxIndicators — The maximum number of indicators to fetch.
  • feedBypassExclusionList — Bypass exclusion list
  • proxy — Use system proxy settings
  • feedIncremental — Incremental Feed
  • insecure — Trust any certificate (not secure)
  • feedTags — Tags

Commands (1)

  • sixgill-get-indicators

    Fetching Sixgill DarkFeed indicators.

category: Data Enrichment & Threat Intelligence
provider: Bitsight
sectionorder:
- Connect
- Collect
commonfields:
  id: Sixgill_Darkfeed
  version: -1
configuration:
- display: Sixgill API client ID
  name: client_id
  required: true
  type: 0
  section: Connect
- display: Sixgill API client secret
  name: client_secret
  required: true
  type: 4
  section: Connect
- defaultvalue: 'all'
  display: Sixgill Confidence
  name: confidence
  type: 15
  options:
  - all
  - "90"
  - "80"
  - "70"
  - "60"
  additionalinfo: 'Ingest all IOCs=all, IOC exactly fits description=90, IOC almost exactly fits description=80, IOC mostly fits description=70, IOC generally fits description=60'
  required: false
  section: Collect
- defaultvalue: 'true'
  display: Fetch indicators
  name: feed
  type: 8
  required: false
  section: Collect
- additionalinfo: Indicators from this integration instance will be marked with this reputation
  defaultvalue: feedInstanceReputationNotSet
  display: Indicator Reputation
  name: feedReputation
  options:
  - None
  - Good
  - Suspicious
  - Bad
  type: 18
  required: false
  section: Collect
- additionalinfo: Reliability of the source providing the intelligence data
  display: Source Reliability
  name: feedReliability
  options:
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  required: true
  type: 15
  defaultvalue: B - Usually reliable
  section: Collect
- name: tlp_color
  display: "Traffic Light Protocol Color"
  options:
  - RED
  - AMBER
  - GREEN
  - WHITE
  type: 15
  additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed
  required: false
  section: Collect
- defaultvalue: 'indicatorType'
  display: ""
  name: feedExpirationPolicy
  type: 17
  options:
  - never
  - interval
  - indicatorType
  required: false
  section: Collect
- defaultvalue: '20160'
  display: ""
  name: feedExpirationInterval
  type: 1
  required: false
  section: Collect
- defaultvalue: '2'
  display: Feed Fetch Interval
  name: feedFetchInterval
  type: 19
  required: false
  section: Collect
- display: The maximum number of indicators to fetch.
  name: maxIndicators
  type: 0
  defaultvalue: '1000'
  required: false
  section: Collect
- display: Bypass exclusion list
  name: feedBypassExclusionList
  type: 8
  additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.
  required: false
  section: Collect
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
  section: Connect
- display: Incremental Feed
  name: feedIncremental
  type: 8
  defaultvalue: 'true'
  hidden: true
  required: false
  section: Collect
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
  section: Connect
- additionalinfo: Supports CSV values.
  display: Tags
  name: feedTags
  type: 0
  required: false
  section: Collect
description: Leverage the power of Sixgill to supercharge Cortex XSOAR with real-time Threat Intelligence indicators. Get IOCs such as domains, URLs, hashes, and IP addresses straight into the XSOAR platform.
display: Sixgill DarkFeed Threat Intelligence
name: Sixgill_Darkfeed
script:
  script: '-'
  commands:
  - arguments:
    - default: true
      defaultValue: '50'
      description: The maximum number of results to return.
      name: limit
    description: Fetching Sixgill DarkFeed indicators.
    execution: true
    name: sixgill-get-indicators
  dockerimage: demisto/sixgill:1.0.0.10120494
  feed: true
  runonce: false
  subtype: python3
  type: python
fromversion: 5.5.0
tests:
- No tests (auto formatted)