decyfir

DeCYFIR API's provides External Threat Landscape Management insights.

Data Enrichment & Threat Intelligence · DeCYFIR

Details

IDdecyfir
ProviderCYFIRMA
CategoryData Enrichment & Threat Intelligence
From Version6.5.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

DeCYFIR API’s provides External Threat Landscape Management insights.
This integration was integrated and tested with version v2 of decyfir

Configure DeCYFIR in Cortex

Parameter Description Required
Incident type   False
DeCYFIR Server URL (e.g. https://decyfir.cyfirma.com)   True
DeCYFIR API Key   True
Fetch incidents   False
Trust any certificate (not secure)   False
Use system proxy settings   False
How much time before the first fetch to retrieve incidents   False
Maximum number of incidents per fetch The maximum number of incidents to fetch per sub-category. False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

decyfir-takedown-initiate


Initiate a take down request.

Base Command

decyfir-takedown-initiate

Input

Argument Name Description Required
alert_id The ID of the alert for which to initiate the take down request. Required

Context Output

There is no context output for this command.

Command example

!decyfir-takedown-initiate alert_id=123

Human Readable Output

The take down request was initiated successfully.

decyfir-takedown-list


Get take down list.

Base Command

decyfir-takedown-list

Input

Argument Name Description Required
sub_category The sub-category for which to retrieve the take down list. If not provided, the take down list for all sub-categories will be retrieved. Optional
size The number of records to retrieve. Default is 100. Optional
page The page number to retrieve. Default is 0. Optional

Context Output

There is no context output for this command.

Command example

!decyfir-takedown-list

Human Readable Output

The take down list retrieved successfully..

Configuration parameters

  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • url — DeCYFIR Server URL (e.g. https://decyfir.cyfirma.com) (required)
  • api_key — (required)
  • isFetch — Fetch incidents
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • first_fetch — How much time before the first fetch to retrieve incidents
  • max_fetch — Maximum number of incidents per fetch

Commands (2)

  • decyfir-takedown-initiate

    Initiate a take down request.

  • decyfir-takedown-list

    Get take down list.

# Partner Contributed Integration

CYFIRMA’s core platform, DeCYFIR, combines cyber threat intelligence with attack surface discovery and digital risk protection to deliver predictive, personalized, contextual, outside-in, and multi-layered cyber-intelligence. 
With DeCYFIR’s APIs, security teams obtain a complete view of their external threat landscape and receive actionable insights to ensure their cybersecurity posture is robust, resilient, and able to counter emerging cyber threats.

**Authorization:**

To obtain a commercial DeCYFIR API Key, please contact us at this email **_contact@cyfirma.com_**. \
_Your API key carries all your privileges, so keep it secure and don’t share it with anyone._


**Note:**
Support and maintenance for this integration is provided by **[Cyfirma](https://www.cyfirma.com)**. 
Please contact us for more details on this email **_contact@cyfirma.com_**.