XFE Deprecated

Deprecated. Use the IBM X-Force Exchange v2 integration instead.

Data Enrichment & Threat Intelligence · IBM X-Force Exchange

Details

IDXFE
ProviderIBM
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Supported ModulesAgentix XSIAM

Configuration parameters

  • Language — Language (required)
  • authentication — API Key (required)
  • useproxy — Use system proxy settings
  • insecure — Trust any certificate (not secure)
  • ipThreshold — IP Threshold. Minimum risk score for the IP to be consodered malicious (ranges from 1 to 10).
  • urlThreshold — URL Threshold. Minimum risk score for the URL to be consodered malicious (ranges from 1 to 10).

Commands (6)

  • cve-latest

    Return the latest vulnerabilities found

  • cve-search

    Search for details about the given CVE

  • domain

    Check domain reputation

  • file

    Check file reputation

  • ip

    Check IP reputation

  • url

    Check the given URL reputation

Don’t have XFE credentials?
Create IBM ID: https://www.ibm.com/account/profile/us?page=reg
Login to XFE: https://exchange.xforce.ibmcloud.com/
Select the “Show User Menu” icon
Choose settings / API Access / Generate

Indicators threshold:
Configure the default threshold for each indicator type in the instance settings.
Note that it is also possible to specify the threshold when runing the command.
Indicators with risk score equal or bigger than the threshold will be considered malicious.
Indicators with risk score equal or bigger than half of the threshold value, and lower than the threshold, will be considered suspicious.