ThreatQ_Beta Deprecated

Deprecated. Use ThreatQ v2 instead. ThreatQ Integration

Data Enrichment & Threat Intelligence · ThreatQ

Details

IDThreatQ_Beta
ProviderSecuronix
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Docker Imagedemisto/python:2.7.18.24398
Supported ModulesAgentix XSIAM

Configuration parameters

  • apiUrl — TQ API URL E.g. https://192.168.1.136/api (required)
  • client_id — TQ Client ID (required)
  • credentials — Email (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (4)

  • file

    Run file check against ThreatQ

  • ip

    Run ip check against ThreatQ

  • tq-search-by-name

    Search ThreatQ repository by keywords

  • url

    Run url check against ThreatQ

You must have a ThreatQ user account to retrieve an api token. The api token is required for all api requests. 
ThreatQ provides indicator scoring weighting for indicators and their contextual information, such as sources, attributes, and indicator types, as they are added to ThreatQ.
For detailed information on ThreatQ scoring please refer to https://helpcenter.threatq.com/

Note: This is a beta Integration, which lets you implement and test pre-release software. Since the integration is beta, it might contain bugs. Updates to the integration during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the integration to help us identify issues, fix them, and continually improve.