XFE Deprecated
Deprecated. Use the IBM X-Force Exchange v2 integration instead.
Data Enrichment & Threat Intelligence · IBM X-Force Exchange
Details
| ID | XFE |
|---|---|
| Provider | IBM |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Supported Modules | Agentix XSIAM |
Configuration parameters
Language— Language (required)authentication— API Key (required)useproxy— Use system proxy settingsinsecure— Trust any certificate (not secure)ipThreshold— IP Threshold. Minimum risk score for the IP to be consodered malicious (ranges from 1 to 10).urlThreshold— URL Threshold. Minimum risk score for the URL to be consodered malicious (ranges from 1 to 10).
Commands (6)
-
cve-latestReturn the latest vulnerabilities found
-
cve-searchSearch for details about the given CVE
-
domainCheck domain reputation
-
fileCheck file reputation
-
ipCheck IP reputation
-
urlCheck the given URL reputation
Don’t have XFE credentials? Create IBM ID: https://www.ibm.com/account/profile/us?page=reg Login to XFE: https://exchange.xforce.ibmcloud.com/ Select the “Show User Menu” icon Choose settings / API Access / Generate Indicators threshold: Configure the default threshold for each indicator type in the instance settings. Note that it is also possible to specify the threshold when runing the command. Indicators with risk score equal or bigger than the threshold will be considered malicious. Indicators with risk score equal or bigger than half of the threshold value, and lower than the threshold, will be considered suspicious.