ACME [Ansible_Powered_Integrations] — Automatic Certificate Management Environment of Linux hosts. Deprecated. Use Ansible ACME (in the Ansible Linux pack) instead.
ACTI Indicator Feed [AccentureCTI_Feed] — Fetches indicators from a ACTI feed. You can filter returned indicators by indicator type, indicator severity, threat type, confidence, and malware family (each of these are an integration parameter).
AMPv2 [AMP] — Cisco Advanced Malware Protection software is designed to prevent, detect, and help remove threats in an efficient manner from computer systems. Threats can take the form of software viruses and other malware such as ransomware, worms, Trojans, spyware, adware, and fileless malware.
ANY.RUN Cloud Sandbox [ANYRUN] — ANY.RUN Sandbox is an online interactive sandbox for malware analysis, a tool for detection, monitoring, and research of cyber threats in real time.
ANY.RUN TI Feed [ANYRUN] — Threat Intelligence Feeds provide data on the known indicators of compromise such as malicious IPs, URLs, Domains.
ANY.RUN TI Lookup [ANYRUN] — TI Lookup is a searchable database of IOCs, IOAs, IOBs, and events for threat hunting and a service for browsing malicious files by their content.
ANYRUN [ANYRUN] — Deprecated. Use ANY.RUN TI Feeds, ANY.RUN TI Lookup, ANY.RUN Cloud Sandbox instead.
APIMetricsValidation [DeveloperTools] — This integration runs through all scenarios as defined in the API Metrics expected results guide.
APIVoid [APIVoid] — APIVoid wraps up a number of services such as ipvoid & urlvoid.
ARIA Packet Intelligence [ARIAPacketIntelligence] — The ARIA Cybesecurity Solutions Software-Defined Security (SDS) platform integrates with Cortex XSOAR to add robustness when responding to incidents. The combination of ARIA hardware, in the form of a Secure Intelligent Adapter (SIA), and software, specifically Packet Intelligence and SDS orchestrator (SDSo), provides the elements required to react instantly when an incident is detected. When integrated with the ARIA solution, you can create playbooks that instruct one or more SIAs to add, modify, or delete rules automatically. These rule changes, which take effect immediately, can block conversations, redirect packets to a recorder or VLAN, or perform a variety of other actions.
AWS [AWS] — Cloud integrations are installed from the **Data Sources** page. To configure a cloud integration, go to Settings > Data Sources and click "Add Data Source", select AWS, then in Advanced Settings > Security Capabilities, enable "Automation".
AWS - ACM [AWS-ACM] — Amazon Web Services Certificate Manager Service (ACM).
AWS - AccessAnalyzer [AWS-AccessAnalyzer] — Amazon Web Services IAM Access Analyzer.
AWS - Security Hub v2 [AWS-SecurityHub] — Use the AWS Security Hub V2 integration to import, manage, and retrieve unified security and compliance findings across your cloud environments.
AWS - System Manager [AWS_SystemManager] — AWS Systems Manager is the operations hub for your AWS applications and resources and a secure end-to-end management solution for hybrid cloud environments that enables safe and secure operations at scale.
AWS Feed [FeedAWS] — Use the AWS feed integration to fetch indicators from the feed.
AWS Network Firewall [AWS-NetworkFirewall] — AWS Network Firewall is a stateful, managed, network firewall and intrusion detection and prevention service for Amazon Virtual Private Cloud (Amazon VPC). With Network Firewall, you can filter traffic at the perimeter of your VPC. This includes filtering traffic going to and coming from an internet gateway, NAT gateway, or over VPN or AWS Direct Connect. Network Firewall uses rules that are compatible with Suricata, a free, open source intrusion detection system (IDS) engine.
AWS Security Lake [AWS-SecurityLake] — Amazon Security Lake is a fully managed security data lake service.
AWS-EKS [AWS-EKS] — The AWS EKS integration allows for the management and operation of Amazon Elastic Kubernetes Service (EKS) clusters.
AWS-ILM [AWS-ILM] — Integrate with AWS's services to execute CRUD and Group operations for employee lifecycle processes.
AWS-SNS-Listener [AWS-SNS-Listener] — Amazon Simple Notification Service (SNS) is a managed service that provides message delivery from publishers to subscribers.
AWS-WAF [AWS_WAF] — Amazon Web Services Web Application Firewall (WAF).
Abnormal Security [AbnormalSecurity] — Abnormal Security detects the whole spectrum of email attacks, from vendor email compromise and spear-phishing to unwanted email spam and graymail. To stop these advanced attacks, Abnormal leverages the industry’s most advanced behavioral data science to baseline known good behavior and detects anomalies.
Absolute [Absolute] — Absolute is an adaptive endpoint security solution that delivers device security, data security, and asset management of endpoints.
AbuseIPDB [AbuseDB] — Central repository to report and identify IP addresses that have been associated with malicious activity online. Check the Detailed Information section for more information on how to configure the integration.
Acalvio ShadowPlex [AcalvioShadowplex] — Acalvio ShadowPlex is a comprehensive Autonomous Deception Platform that offers Advanced Threat Detection, Investigation and Response capabilities.
Accessdata [Accessdata] — Deprecated. Use Exterro FTK instead.
Active Directory Query v2 [Active_Directory_Query] — The Active Directory Query integration enables you to access and manage Active Directory objects (users, contacts, and computers).
ActiveMQ [ActiveMQ] — Integration with ActiveMQ queue.
AdminByRequest [AdminByRequest] — AdminByRequest is a Privileged Access Management (PAM) solution that enables secure, temporary elevation to local admin rights.
Aella Star Light [Aella_StarLight] — Aella Star Light Integration.
Agari Phishing Defense [AgariPhishingDefense] — Agari Phishing Defense stops phishing, BEC, and other identity deception attacks that trick employees into harming your business.
Aha [AHA] — Use the Aha! integration to list and manage Cortex XSOAR features from Aha.
Akamai WAF [Akamai_WAF] — Use the Akamai WAF integration to manage common sets of lists used by various Akamai security products and features.
This is the modified version where a new command "akamai-update-network-list-elements" was added by the SA.
Akamai WAF SIEM [Akamai_SIEM] — Use the Akamai WAF SIEM integration to retrieve security events from Akamai Web Application Firewall (WAF) service.
Alexa Rank Indicator [Alexa] — Deprecated. Vendor has declared end of life for this product. No available replacement.
Alexa Rank Indicator v2 [Alexa] — Deprecated. Vendor has declared end of life for this product. No available replacement.
AlgoSec [Algosec] — Algosec AppViz, Firewall Analyzer (AFA) and FireFlow(AFF).
AlphaSOC Wisdom [AlphaSOC_Wisdom] — DNS and IP threat intelligence via the AlphaSOC platform.
AlphaVantage [AlphaVantage] — This is an API to get stock prices etc.
Amazon DynamoDB [AWS_DynamoDB] — Amazon DynamoDB Amazon DynamoDB is a fully managed NoSQL database service that provides fast and predictable performance with seamless scalability. DynamoDB lets you offload the administrative burdens of operating and scaling a distributed database, so that you don't have to worry about hardware provisioning, setup and configuration, replication, software patching, or cluster scaling. With DynamoDB, you can create database tables that can store and retrieve any amount of data, and serve any level of request traffic. You can scale up or scale down your tables' throughput capacity without downtime or performance degradation, and use the AWS Management Console to monitor resource utilization and performance metrics. DynamoDB automatically spreads the data and traffic for your tables over a sufficient number of servers to handle your throughput and storage requirements, while maintaining consistent and fast performance. All of your data is stored on solid state disks (SSDs) and automatically replicated across multiple Availability Zones in an AWS region, providing built-in high availability and data durability.
Analyst1 [illuminate] — This integration utilizes Analyst1's system to enrich XSOAR indicators with data provided by the Analyst1 REST API, such as actor and malware information, activity and reported dates, evidence and hit counts, and more.
Anomali Enterprise [Anomali_Enterprise] — Use Anomali Match to search indicators and enrich domains.
Anomali ThreatStream [Anomali_ThreatStream] — Deprecated. Use Anomali ThreatStream v3 instead. Use Anomali ThreatStream to query and submit threats
Anomali ThreatStream Feed [AnomaliThreatStreamFeed] — Use the Anomali ThreatStream Feed Integration to fetch indicators from the Anomali ThreatStream.
Anomali ThreatStream v3 [Anomali_ThreatStream] — Use Anomali ThreatStream to query and submit threats.
AnomaliSecurityAnalyticsAlerts [AnomaliSecurityAnalyticsAlerts] — The Anomali Security Analytics pack allows users to manage security alerts by interacting directly with the Anomali Security Analytics platform. It supports creating search jobs, monitoring their status, retrieving results, and updating alert statuses or comments, streamlining integration with Palo Alto XSOAR.
AnsibleACME [AnsibleLinux] — Control Automatic Certificate Management Environment on Linux hosts.
Anthropic Claude [AnthropicClaude] — Designed to assist security professionals with security investigations, threat hunting, and anomaly detection, leveraging Anthropic Claude's natural language conversational capabilities.
AnthropicClaudeStandardConnector [AnthropicClaudeStandardConnector] — This integration is configured automatically as part of the Anthropic Claude Standard Connector. Do not configure this integration directly — set it up from the connector page instead.
AnythingLLM [AnythingLLM] — Retrieval Augmented Generation (RAG) with LLM and Vector DB that can be local for full data privacy or cloud-based for greater functionality. Prompts and responses can be scanned for security issues using Prisma Airs.
APIs are documented at: <Anything LLM URL> /api/docs
Product documentation: https://docs.useanything.com/
AppSentinels.ai [AppSentinelsAi] — Appsentinels.ai offers a platform for collecting, analyzing, and managing security events to provide comprehensive application protection.
ArcSight XML [ArcSightXML] — Deprecated. Use the ArcSight ESM v2 integration instead.
Arcanna.AI [Arcanna] — Arcanna integration for using the power of AI in SOC.
ArcusTeam [ArcusTeam] — The ArcusTeam API allows the user to inspect connected devices' attack surface. By feeding device identifiers and the software it runs: DeviceTotal will return a map of the device’s attack surface. DeviceTotal was built from the ground up in order to provide complete visibility into connected devices and mitigate 3rd party risk. DeviceTotal can continuously identify & predict such that the connected device security posture is being assessed, prioritized and mitigated effectively.
Arduino [Arduino] — Connects to and controls an Arduino pin system using the network.
ArgusManagedDefence [mnemonicMDR] — Rapidly detect, analyse and respond to security threats with mnemonic’s leading Managed Detection and Response (MDR) service.
Arkime [Arkime] — Arkime (formerly Moloch) is a large scale, open source, indexed packet capture and search tool.
Armis [Armis] — Use the Armis integration to search alerts and devices, tag and untag devices, and set alert statuses.
ArmisEventCollector [Armis] — Collects alerts, devices and activities from Armis resources.
Armorblox [Armorblox] — Armorblox is an API-based platform that stops targeted email attacks,
protects sensitive data, and automates incident response.
AsanaConnect [AsanaConnect] — This Integration uses Asana PATs to connect to projects tied to the Asana account.
Asimily Insight [Asimily_Insight] — Integrate Asimily Insight to ingest security anomalies, CVEs, and leverage detailed asset data for streamlined incident investigation.
Ataya Harmony [Ataya] — Use the Ataya Harmony integration to assign client which has not yet under assigned status by client imsi.
Atlassian Confluence Cloud [AtlassianConfluenceCloud] — Atlassian Confluence Cloud allows users to interact with confluence entities like content, space, users, and groups. Users can also manage the space permissions.
Atlassian IAM [Attlasian] — Integrate with Atlassian's services to execute CRUD operations for employee lifecycle processes.
AtlassianJiraServiceManagement [AtlassianJiraServiceManagement] — Use this integration to manage Jira objects and attach files to Jira objects from Cortex XSOAR.
AttackIQFireDrill [AttackIQFireDrill] — An attack simulation platform that provides validations for security controls, responses, and remediation exercises.
AttackSurfaceManagement [MandiantAdvantageAttackSurfaceManagement] — Integrate with Mandiant Advantage Attack Surface Management to import "issues" as Incidents.
AutoFocus Feed [AutoFocus] — Deprecated. Use Unit 42 Feed integration instead.
AutoFocus V2 [AutoFocus] — Deprecated. Use the Unit 42 Intelligence integration instead.
AutoFocusTagsFeed [AutoFocus] — Deprecated. Use Unit 42 Intel Objects Feed instead. Use the AutoFocus Tags Feed integration to fetch indicators from AutoFocus Tags.
Autofocus [AutoFocus] — Deprecated. Use the Palo Alto Networks AutoFocus v2 integration instead. Palo Alto Networks AutoFocus enables you to distinguish the most important threats from everyday commodity attacks.
Automox [Automox] — Administrate your IT organization from XSOAR with comprehensive commands for the Automox platform.
AwsSecretsManager [Aws-SecretsManager] — AWS Secrets Manager helps you to securely encrypt, store, and retrieve credentials for your databases and other services.
Axonius [Axonius] — This integration is for fetching information about assets in Axonius.
Azure [Azure] — Cloud integrations are installed from the **Data Sources** page. To configure a cloud integration, go to Settings > Data Sources and click "Add Data Source", select Azure, then in Advanced Settings > Security Capabilities, enable "Automation".
Azure AD Connect Health Feed [FeedAzureADConnectHealth] — Use the Microsoft Azure AD Connect Health Feed integration to get indicators from the feed.
Azure Firewall [AzureFirewall] — Azure Firewall is a cloud-native and intelligent network firewall security service that provides breed threat protection for cloud workloads running in Azure. It's a fully stateful, firewall as a service, with built-in high availability and unrestricted cloud scalability.
Azure Kubernetes Services [AzureKubernetesServices] — Deploy and manage containerized applications with a fully managed Kubernetes service.
Azure Log Analytics [AzureLogAnalytics] — Log Analytics is a service that helps you collect and analyze data generated by resources in your cloud and on-premises environments.
Azure Network Security Groups [AzureNetworkSecurityGroups] — Azure network security groups are used to filter network traffic to and from Azure resources in an Azure virtual network.
Azure Resource Graph [AzureResourceGraph] — Azure Resource Graph integration is designed to allow for executing Azure Resource Graph commands, like querying resource data.
Azure SQL Management [AzureSQLManagement] — Microsoft Azure SQL Management Integration manages the Auditing and Threat Policies for Azure SQL.
Azure Security Center [DeprecatedContent] — Deprecated. Unified security management and advanced threat protection across hybrid cloud workloads.
Azure Security Center v2 [AzureSecurityCenter] — Unified security management and advanced threat protection across hybrid cloud workloads.
Azure Sentinel [AzureSentinel] — Microsoft Sentinel is a scalable, cloud-native solution that provides: Security information and event management (SIEM) Security orchestration, automation, and response (SOAR).
Azure Storage [AzureStorage] — Deploy and manage storage accounts and blob services.
Azure Storage FileShare [AzureStorageFileShare] — Create and Manage Azure FileShare Files and Directories.
Azure Storage Queue [AzureStorageQueue] — Create and Manage Azure Storage Queues and Messages.
Azure Storage Table [AzureStorageTable] — Create and Manage Azure Storage Tables and Entities.
AzureComputeV3 [Ansible_Powered_Integrations] — Manage Azure Compute resources. Deprecated. Use Ansible Azure (from the Ansible Azure pack) instead.
AzureDataExplorer [AzureDataExplorer] — Use the Azure Data Explorer integration to collect and analyze data inside Azure Data Explorer clusters, and to manage search queries.
AzureDevOps [AzureDevOps] — Manage Git repositories in Azure DevOps Services. Integration capabilities include retrieving, creating, and updating pull requests. Run pipelines and retrieve Git information.
AzureKeyVault [AzureKeyVault] — Use the Azure Key Vault integration to safeguard and manage cryptographic keys and secrets used by cloud applications and services.
AzureNetworking [Ansible_Powered_Integrations] — Manage Azure Networking resources. Deprecated. Use Ansible Azure (from the Ansible Azure pack) instead.
AzureRiskyUsers [AzureRiskyUsers] — Azure Risky Users provides access to all at-risk users and risk detections in the Azure AD environment.
AzureWAF [AzureWAF] — The Azure WAF (Web Application Firewall) integration provides centralized protection of your web applications from common exploits and vulnerabilities.
It enables you to control policies that are configured in the Azure Firewall management platform, and allows you to add, delete, or update policies,
and also to get details of a specific policy or a list of policies.
BMC Discovery [BMCDiscovery] — BMC Discovery is a SaaS-based, cloud-native discovery and dependency modeling system that provides instant visibility into hardware, software, and service dependencies across multi-cloud, hybrid, and on-premises environments.
BMCHelixRemedyforce [BmcHelixRemedyForce] — BMC Helix Remedyforce integration enables customers to create/update service requests and incidents, update statuses, and resolve service requests and incidents with customer notes. This integration exposes standard ticketing capabilities that can be utilized as part of automation & orchestration.
BPA [BPA] — Deprecated. Use Palo Alto Networks AIops instead, run aiops-bpa-report-generate command.
Bambenek Consulting Feed [FeedBambenekConsulting] — Use the Bambenek Consulting feed integration to fetch indicators from the feed.
Barracuda Reputation Block List - BRBL [Barracuda] — This integration enables reputation checks against IPs from Barracuda Reputation Block List (BRBL).
BaseIntegration [StarterPack] — [Enter a comprehensive, yet concise, description of what the integration does, what use cases it is designed for, etc.].
Bastille Networks [BastilleNetworks] — RF monitoring for wireless intrusion detection and policy enforcement. Visit https://www.bastille.net for details.
BeyondTrust - Authorization Requests [BeyondTrust-AuthorizationRequests] — Use this integration to handle Beyond Trust authorization requests through XSOAR.
BeyondTrust Password Safe [BeyondTrust_Password_Safe] — Unified password and session management for seamless accountability and control over privileged accounts.
BeyondTrust Privilege Management Cloud [BeyondTrust] — BeyondTrust Privilege Management Cloud (PM Cloud) integration for retrieving audit events and activity logs.
BigFix [BigFix] — HCL BigFix Patch provides an automated, simplified patching process that is administered from a single console.
Binalyze AIR [Binalyze] — Collect your forensics data under 10 minutes.
Binalyze AIR Extended [BinalyzeAIRExtended] — Manage Binalyze AIR forensic acquisition, endpoint isolation, triage, cases, tasks, assets, repositories, and evidence artifacts from Cortex XSOAR.
BitDam [BitDam] — BitDam secure email gateway protects from advanced content-borne threats with the most accurate prevention of known and unknown threats, at their source.
BitSight Event Collector [BitSight] — Use this integration to fetch BitSight findings as events in XSIAM.
BitSight for Security Performance Management [BitSight] — Use the "Bitsight for Security Performance Management" Integration to get company guid, details, and findings. This integration also allows to fetch the findings by using the fetch incidents capability.
Bitbucket [Bitbucket] — Bitbucket Cloud is a Git-based code and CI/CD tool optimized for teams using Jira.
BitcoinAbuse [BitcoinAbuse] — Deprecated. No available replacement.
Bitwarden Password Manager [BitwardenPasswordManager] — This integration collects event logs from Bitwarden Password Manager to Cortex XSIAM.
Blockade.io [Blockade.io] — Deprecated. No available replacement.
Blocklist_de Feed [FeedBlocklist_de] — Use the Blocklist.de feed integration to fetch indicators from the feed.
BloodHoundEnterprise [BloodHoundEnterprise] — Deprecated. Use the SpecterOps BloodHound Enterprise integration instead. Use this integration to fetch audit logs from BloodHound Enterprise as events in Cortex XSIAM.
BluecatAddressManager [BluecatAddressManager] — Use the BlueCat Address Manager integration to enrich IP addresses and manage response policies.
Blueliv ThreatCompass [BluelivThreatCompass] — Blueliv ThreatCompass systematically looks for information about companies,products, people, brands, logos, assets, technology and other information, depending on your needs. Blueliv ThreatCompass allows you to monitor and track all this information to keep your data, your
organization and its employees safe.
Blueliv ThreatContext [BluelivThreatContext] — The Threat Context module provides SOC, Incident Response, and Threat Intelligence teams with continuously updated and intuitive information around threat actors, campaigns, malware indicators, attack patterns, tools, signatures and CVEs.
Blueliv_Beta [Blueliv] — Deprecated. No available replacement.
BmcITSM [BmcITSM] — BMC Helix ITSM integration enables customers to manage service request, incident, change request, task, problem investigation, known error and work order tickets.
Bonusly [Bonusly] — The Bonusly integration is used to interact with the Bonusly platform through the API. Bonusly is an employee recognition platform which enterprises use to for employee recognition.
BotDefender [PerimeterX] — Gathers PerimeterX related data.
Box [Box] — Deprecated. Use the Box v2 integration instead.
Brandefense [Brandefense] — Branddefense is looking for data for each brand and collecting information and alarming the related brand about dark web finding (credentials, similar domain names etc.) related to the firm.With Brandefense integration it is possible to automate Brand related alarms and breach notifications, actions and much more.
BrandefenseDRPS [BrandefenseDRPS] — Brandefense is a Cyber Intelligence Platform that responds directly and effectively to today's complex cyber threats.
BreachRx [BreachRx] — Automate your privacy Incident Response workflow through the BreachRx platform.
BruteForceBlocker Feed [FeedBruteForceBlocker] — BruteForceBlocker is a Perl script that works with pf – firewall developed by the OpenBSD team, and is also available on FreeBSD from version 5.2. From BruteForceBlocker version 1.2 it is also possible to report blocked IP addresses to the project site and share your information with other users.
C2sec irisk [C2sec] — Understand Your Cyber Exposure as Easy as a Google Search.
CIRCL [CIRCL] — CIRCL Passive DNS is a database storing historical DNS records from various resources.
CIRCL Passive SSL is a database storing historical X.509 certificates seen per IP address. The Passive SSL historical data is indexed per IP address.
CIRCL CVE Search [CIRCL] — Searches for CVE information using circl.lu.
CIRCLEHashlookup [CIRCLHashlookup] — CIRCL hash lookup is a public API to lookup hash values against known database of files. NSRL RDS database is included and many others are also included. The API is accessible via HTTP ReST API and the API is also described as an OpenAPI. The service is free and served as a best-effort basis.
CSCDomainManager [CSCDomainManager] — CSCDomainManager is an integration that supports querying and enriching domains through CSCDomainManager API.
CSVFeed [FeedCSV] — Fetch indicators from a CSV feed.
CTIX [CTIX] — Deprecated. Use Cyware Intel Exchange instead.
CTIX v3 [CTIX] — Integrates with Cyware Intel Exchange to enrich indicators, fetch incidents and threat intelligence indicators, manage tags and notes, view related objects, perform vulnerability lookups, and run generic API requests.
CTM360_CyberBlindspot [CTM360-CyberBlindspot] — Take action on incidents derived from CTM360 CBS threat intelligence that is directly linked to your organization.
CTM360_HackerView [CTM360-CyberBlindspot] — External Attack Surface Management platform, which combines automated asset discovery, issue identification / management, remediation guidelines, security ratings and third party risk management.
CadoResponse [CadoResponse] — Automate data collection. Process data at cloud speed. Analyze with purpose.
Camlytics [Camlytics] — You can use this integration to automate different Camlytics surveillance analysis actions.
CapeSandbox [CapeSandbox] — CAPE Sandbox is an open-source software for automating the analysis of suspicious files and URLs.
Carbon Black Defense [CarbonBlackDefense] — Deprecated. Use Carbon Black Endpoint Standard instead.
Carbon Black Endpoint Standard [CarbonBlackDefense] — Endpoint Standard is an industry-leading next-generation antivirus (NGAV) and behavioral endpoint detection and response (EDR) solution. Endpoint Standard is delivered through the Carbon Black Cloud, an endpoint protection platform that consolidates security in the cloud using a single agent, console and data set.
Carbon Black Endpoint Standard v3 [CarbonBlackDefense] — Endpoint Standard is an industry-leading next-generation antivirus (NGAV) and behavioral endpoint detection and response (EDR) solution. Endpoint Standard is delivered through the Carbon Black Cloud, an endpoint protection platform that consolidates security in the cloud using a single agent, console and data set.
Carbon Black Enterprise EDR [CarbonBlackEnterpriseEDR] — VMware Carbon Black Enterprise EDR (formerly known as Carbon Black ThreatHunter) is an advanced threat hunting and incident response solution delivering continuous visibility for top security operations centers (SOCs) and incident response (IR) teams. (formerly known as ThreatHunter).
CarbonBlackEndpointStandardEventCollector [CarbonBlackDefense] — Endpoint Standard (formerly called Carbon Black Defense), a Next-Generation Anti-Virus + EDR. Collect Anti-Virus & EDR alerts and Audit Log Events.
CarbonBlackLiveResponseCloud [CarbonBlackDefense] — VMware Carbon Black Endpoint Standard Live Response is a feature that enables security operators to collect information and take action on remote endpoints in real time. These actions include the ability to upload, download, and remove files, retrieve and remove registry entries, dump contents of physical memory, and execute and terminate processes.
CarbonBlackProtectionV2 [CarbonBlackProtect] — VMware Carbon Black App Control (formerly known as Carbon Black Enterprise Protection) is a next-generation endpoint threat prevention solution to deliver a portfolio of protection policies, real-time visibility across environments, and comprehensive compliance rule sets in a single platform. This integration only supports Carbon Black on-premise APIs.
CelonisEventCollector [Celonis] — The Celonis Platform offers you a suite of process mining and intelligence features, helping you to integrate your data and then use that data to analyze, improve, and monitor your business performance across key metrics.
Censys [Censys] — Deprecated. Use Censys v2 instead. Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the internet. Driven by internet-wide scanning, Censys lets researchers find specific hosts and create aggregate reports on how devices, websites, and certificates are configured and deployed.
CensysV2 [Censys] — Built on the industry’s most comprehensive Internet Map, the Censys Platform delivers unmatched visibility into global internet assets, adversary infrastructure, and evolving threats.
Centrify Vault [CentrifyVault] — Leverage the Centrify Vault integration to create and manage Secrets.
Check Point [CheckpointFirewall] — Deprecated. Use the Check Point Firewall v2 integration instead. Manage Check Point firewall via API
Check Point Sandblast [Sandblast] — Deprecated. Use Check Point Threat Emulation (SandBlast) instead. Query, upload and download data using Check Point Sandblast on cloud.
Check Point Sandblast Appliance [SandBlastAppliance] — Deprecated. Use Check Point Threat Emulation (SandBlast) instead. Query, upload and download data using Check Point Sandblast on local gateway.
CheckPhish [CheckPhish] — Check any URL to detect supsicious behavior.
CheckPointFirewall_v2 [CheckpointFirewall] — Use this integration to read information and send commands to the Check Point Firewall server.
CheckPointHEC [CheckPointHEC] — The Best Way to Protect Enterprise Email & Collaboration from phishing, malware, account takeover, data loss, etc.
CheckPointHarmonyEndpoint [CheckPointHarmonyEndpoint] — Checkpoint Harmony Endpoint provides a complete endpoint security solution built to protect organizations and the remote workforce from today's complex threat landscape.
CheckPointNDR [CheckPointNDR] — Collect network security events from Check Point Infinity NDR for your secured SaaS periodically.
CheckPointSandBlast [CheckPointSandBlast] — Uploads files using polling. The service supports Microsoft Office files, as well as PDF, SWF, archives, and executables. Active content will be cleaned from any documents that you upload (Microsoft Office and PDF files only). Queries on existing IOCs, file status, analysis, and reports. Downloads files from the database. Supports both appliance and cloud. Supported Threat Emulation versions are any R80x.
CheckPointXDR [CheckPointXDR] — Fetch and manage incidents from Check Point XDR.
Cherwell [Cherwell] — Cloud-based IT service management solution.
CimTrak [CimTrak-SystemIntegrityAssurance] — The CimTrak integration helps you detect unexpected system/device/config modifications and automatically respond/react to threats.
CipherTrust [ThalesCipherTrustManager] — Manage secrets and protect sensitive data through Thales CipherTrust security platform.
CircleCI [CircleCI] — Gets the details of the CircleCI workflows; including the details of the last runs and the jobs, and retrieves the artifacts of the jobs.
Cisco ASA [CiscoASA] — Use the Cisco Adaptive Security Appliance Software integration to manage interfaces, rules, and network objects.
Cisco AppDynamics [CiscoAppDynamics] — AppDynamics enables you to automate incident management, gain real-time performance metrics, and optimize applications to meet business needs.
Cisco Firepower [CiscoFirepower] — Use the Cisco Firepower integration for unified management of firewalls, application control, intrusion prevention, URL filtering, and advanced malware protection.
Cisco ISE [cisco-ise] — Next-generation secure network access.
Cisco IronPort EMail API [CiscoESAIronPortEmailAPI] — Deprecated. Use Cisco Email Security Appliance (IronPort) V2 instead.
Cisco Meraki [cisco-meraki] — Cloud controlled WiFi, routing, and security. Deprecated. Use CiscoMerakiv2 instead.
Cisco Meraki v2 [cisco-meraki] — Cisco Meraki is a cloud-managed IT company that simplifies networking, security, communications, and endpoint management. Its platform offers centralized management for devices, networks, and security through an intuitive web interface. Key functionalities include managing organizations, networks, devices, and their licenses, as well as monitoring device statuses and client activities.
Cisco Secure Malware Analytics [ThreatGrid] — Secure Malware Analytics (formerly Threat Grid) combines advanced sandboxing with threat intelligence into one unified solution to protect organizations from malware.
Cisco Spark [CiscoSpark] — Send messages, create rooms and more, via the Cisco Spark API.
Cisco Stealthwatch [CiscoStealthwatch] — Scalable visibility and security analytics.
Cisco Umbrella Cloud Security v2 [Cisco-umbrella-cloud-security] — Cisco Umbrella is a cloud security platform providing the first line of defense against internet threats. It uses DNS-layer security to block malicious requests before a connection is established, offering protection against malware, ransomware, phishing, and more. It offers real-time reporting, integrates with other Cisco solutions for layered security, and uses machine learning to uncover and predict threats.
Cisco Umbrella Investigate [Cisco-umbrella] — Cisco Umbrella Investigate enables you to research domains, IPs, and URLs observed by the Umbrella resolvers.
Cisco Umbrella Reporting [CiscoUmbrellaReporting] — The Umbrella Reporting v2 API provides visibility into your core network and security activities and Umbrella logs.
Cisco WebEx Feed [CiscoWebExFeed] — Use the Cisco Webex Feed integration to fetch indicators from Webex.
CiscoAMP [CiscoAMP] — Deprecated. Use Cisco AMP v2 instead.
CiscoAMPEventCollector [AMP] — This is the Cisco AMP event collector integration for Cortex XSIAM.
CiscoESA [IronPort] — The Cisco Email Security Appliance is an email security gateway product. It is designed to detect and block a wide variety of email-born threats, such as malware, spam and phishing attempts.
CiscoEmailSecurity [CiscoEmailSecurity] — Deprecated. Use Cisco Security Management Appliance instead.
CiscoIOS [Ansible_Powered_Integrations] — Cisco IOS Platform management over SSH. Deprecated. Use Ansible Cisco IOS (from the Ansible Cisco IOS pack) instead.
CiscoNX-OS [Ansible_Powered_Integrations] — Cisco NXOS Platform management over SSH. Deprecated. Use Ansible Cisco NXOS (from the Ansible Cisco NXOS pack) instead.
CiscoSMA [CiscoSMA] — The Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs) and Web Security Appliances (WSAs).
CiscoThousandEyes [CiscoThousandEyes] — This is the Cisco ThousandEyes event collector integration for Cortex XSIAM.
CiscoWSA [CiscoWSA] — Deprecated. Use CiscoWSAV2 instead.
CiscoWSAv2 [CiscoWSA] — Cisco Secure Web Appliance protects your organization by automatically blocking risky sites and testing unknown sites before allowing users to click on them.
CiscoWebexEventCollector [CiscoSpark] — Cisco Webex Event Collector fetches Events and Admin Audit Events and Security Audit Events.
CitrixCloud [Citrix] — Citrix cloud services simplify the delivery and management of Citrix technologies.
CitrixDaas [Citrix] — Citrix DaaS simplifies the delivery and management of Citrix technologies.
Clarizen IAM [Clarizen] — IAM integration for Clarizen. Handles user account auto-provisioning to Clarizen.
Claroty [Claroty] — Use the Claroty CTD integration to manage assets and alerts.
ClickSend [ClickSend] — This is the ClickSend integration for make a phonecall from XSOAR made by Trustnet.
Cloaken [Cloaken] — Unshorten URLs onsite using the power of a Tor proxy server to prevent leaking IP addresses to adversaries.
CloudConvert [CloudConvert] — Use the CloudConvert integration to convert your files to the desired format.
CloudShark [CloudShark] — Use the CloudShark integration to upload, share, and collaborate on network packet capture files using your on-premises CS Enterprise system.
Cloudflare Feed [FeedCloudflare] — Use the Cloudflare feed integration to fetch indicators from the feed.
Cloudflare Zero Trust [CloudflareZeroTrust] — Cloudflare provides network and security products for consumers and businesses, utilizing reverse proxies for web traffic, edge computing, and a content distribution network to provide content across its network of servers.
CloudflareWAF [CloudflareWAF] — Cloudflare WAF integration allows customers to manage firewall rules, filters, and IP-lists. It also allows to retrieve zones list for each account.
Code42 [Code42] — Use the Code42 integration to identify potential data exfiltration from insider threats while speeding investigation and response by providing fast access to file events and metadata across physical and cloud environments.
Code42 Event Collector [Code42] — Code42 Insider Risk software solutions provide the right balance of transparency, technology and training to detect and appropriately respond to data risk. Use the Code42EventCollector integration to fetch file events and audit logs.
Cofense Feed [FeedCofense] — Use the Cofense Feed Integration to fetch indicators from the feed.
Cofense Intelligence [Cofense-Intelligence] — Deprecated. Use Cofense Intelligence v2 instead. Use the Cofense Intelligence integration to check the reputation of URLs, IP addresses, file hashes, and email addresses.
Cofense Triage [CofenseTriage] — Deprecated. Use the Cofense Triage v2 integration instead.
Cofense Triage v2 [CofenseTriage] — Use the Cofense Triage integration to ingest reported phishing indicators.
Cofense Triage v3 [CofenseTriage] — The integration uses the Cofense Triage v2 API that allows users to ingest phishing reports as incident alerts and execute commands such as threat indicators, reporters, categorize reports, and more.
Cofense Vision [CofenseVision] — The Cofense Vision integration provides commands to initiate advanced search jobs to hunt suspicious emails matching IOCs. It also contains commands to quarantine emails, download messages and their attachments, and aids to manage IOCs in the local repository to keep up with upcoming emerging threats.
CofenseIntelligenceV2 [CofenseIntelligenceV2] — Use the Cofense Intelligence integration to check the reputation of domains, URLs, IP addresses, file hashes, and email addresses.
Cognni [Cognni] — Autonomous detection and investigation of information security incidents and other potential threats.
CohesityHelios [CohesityHelios] — Integrate with Cohesity Helios services to fetch alerts and take remedial action.
CommvaultSecurityIQ [CommvaultSecurityIQ] — Commvault Cloud provides pre-built integrations, automation workflows, and playbooks to streamline operations, enhance threat intelligence integration, and gain actionable insights through advanced reporting and analytics.
Computer Vision Engine [ComputerVisionEngine] — This integration is processing images or movies and detects objects on them by using Machine Learning.
It is using OpenCV with:
YOLO COCO.
ConcentricAI [ConcentricAI] — Concentric’s Semantic Intelligence™ solution discovers and protects business critical, unstructured data. We use deep learning to identify risky sharing, inappropriate third party access, assets in the wrong location, mis-classified documents, or lateral movement of data – all without rules or complex upfront configuration.
Confluera [Confluera] — This is the confluera Iq-Hub integration with cortex.
Coralogix [Coralogix] — Fetch incidents, search for supporting data and tag interesting datapoints in/from your Coralogix account.
Core Lock [DemistoLocking] — Locking mechanism that prevents concurrent execution of different tasks
Core REST API [DemistoRESTAPI] — Use Core REST APIs.
Cortex Attack Surface Management [CortexAttackSurfaceManagement] — Integration to pull assets and other ASM related information.
Cortex Core - IOC [Core] — The Cortex Core - IOCs integration uses the Cortex API for detection and response, by natively integrating network, endpoint, and cloud data to stop sophisticated attacks.
Cortex Core - IR [Core] — The Cortex Core IR integration uses the Cortex API for detection and response, by natively integrating network, endpoint, and cloud data to stop sophisticated attacks.
Cortex Core - Platform [Core] — This integration uses the Cortex API to access all the core services and capabilities of the Cortex platform.
Cortex Data Lake [CortexDataLake] — Palo Alto Networks Strata Logging Service XSOAR Connector provides cloud-based, centralized log storage and aggregation for your organization on premise, virtual (private cloud and public cloud) firewalls, for Prisma Access, and for cloud-delivered services such as Cortex XDR.
Cortex XDR - IOC [CortexXDR] — Use the Cortex XDR - IOCs feed integration to sync indicators from Cortex XSOAR to Cortex XDR and back to Cortex XSOAR. Cortex XDR is the world's first detection and response app that natively integrates network, endpoint and cloud data to stop sophisticated attacks.
Cortex XDR - IR [CortexXDR] — Cortex XDR is the world's first detection and response app that natively integrates network, endpoint, and cloud data to stop sophisticated attacks.
Cortex XDR - IR CTF [ctf01] — Cortex XDR is the world's first detection and response app that natively integrates network, endpoint, and cloud data to stop sophisticated attacks.
Cortex XDR - XQL Query Engine [CortexXDR] — Cortex XDR - XQL Query Engine enables you to run XQL queries on your data sources.
Cortex Xpanse [CortexXpanse] — Integration to pull assets and other ASM related information.
CounterCraft Deception Director [CounterCraft] — CounterCraft Deception Solution detects advanced adversaries. Automate counterintelligence campaigns to discover targeted attacks with real-time active response.
CounterTack [CounterTack] — CounterTack empowers endpoint security teams to assure endpoint protection for Identifying Cyber Threats. Integrating a predictive endpoint protection platform.
Covalence For Security Providers [CovalenceForSecurityProviders] — Triggers by any alert from endpoint, cloud, and network security monitoring, with mitigation steps where applicable. Query Covalence for more detail.
Covalence Managed Security [CovalenceManagedSecurity] — Triggers by triaged alerts from endpoint, cloud, and network security monitoring. Contains event details and easy-to-follow mitigation steps.
CreateIncidents [DeveloperTools] — CreateIncidents fetches custom incidents that are created manually.
CriblSearch [Cribl] — Cribl Search allows you to query, retrieve, and manage search jobs, datasets, and saved searches across your Cribl Cloud deployment.
CriminalIP [CriminalIP] — Criminal IP is a comprehensive cyber threat intelligence solution that provides actionable insights into IP addresses, domains, and connected assets across the internet.
It enables organizations to detect malicious indicators, assess asset reputation, and enhance threat detection by integrating enriched threat data directly into security operations via the XSOAR interface.
CrowdSec [CrowdSec] — Identify Malicious IP addresses with the CrowdSec CTI API.
CrowdStrike Falcon Intel v2 [CrowdStrikeIntel] — CrowdStrike Threat intelligence service integration helps organizations defend themselves against adversary activity by investigating incidents, and accelerating alert triage and response.
CrowdStrike Falcon Streaming v2 [CrowdStrikeFalconStreamingV2] — Use the CrowdStrike Falcon Stream v2 integration to stream detections and audit security events.
CrowdStrike Falcon X [CrowdStrikeFalconX] — Use the CrowdStrike Falcon Intelligence Sandbox integration to submit files, file hashes, URLs, and FTPs for sandbox analysis, and to retrieve reports.
CrowdStrike Indicator Feed [FeedCrowdstrikeFalconIntel] — Retrieves indicators from the CrowdStrike Falcon Intel Feed.
CrowdStrike OpenAPI [CrowdStrikeOpenAPI] — Use the CrowdStrike OpenAPI integration to interact with CrowdStrike APIs that do not have dedicated integrations in Cortex XSOAR, for example, CrowdStrike FalconX, etc.
CrowdStrikeMalquery [CrowdStrikeMalquery] — Use the MalQuery Integration to query the contents of clean and malicious binary files, which forms part of Falcon's search engine.
Crowdstrike Falcon Intel Feed [FeedCrowdstrikeFalconIntel] — The CrowdStrike intelligence team tracks the activities of threat actor groups and advanced persistent threats (APTs) to understand as much as possible about their known aliases, targets, methods, and more. This integration retrieves indicators from the CrowdStrike Falcon Intel Feed.
CrowdstrikeFalcon [CrowdStrikeFalcon] — The CrowdStrike Falcon OAuth 2 API (formerly the Falcon Firehose API), enables fetching and resolving detections, searching devices, getting behaviors by ID, containing hosts, and lifting host containment.
Cryptocurrency [Cryptocurrency] — Cryptocurrency will help classify Cryptocurrency indicators with the configured score when ingested.
Cryptosim [Cryptosim] — CRYPTOSIM gets correlations and correlation's alerts. Integration fetchs alerts to incident according to instance.
CustomIndicatorDemo [DeveloperTools] — This is a demo integration that demonstrates the usage of the CustomIndicator helper class.
CyCognito [CyCognito] — The CyCognito integration fetches issues discovered by the CyCognito platform, thereby providing users with a view of their organization's internet-exposed attack surface. These issues include identification, prioritization, and recommendations for remediation of the risks faced by the organization. The integration contains commands to query assets and issues detected by the CyCognito platform, and includes a rich dashboard and layout with issue management capability.
CybelAngel [CybelAngel] — This integration connects your alerts from CybelAngel.
CybelAngel Event Collector [CybelAngel] — CybelAngel collects reports from the CybelAngel platform, which specializes in external attack surface protection and management.
Cyber Triage [CyberTriage] — Allows you to conduct a mini-forensic investigation on an endpoint. It pushes a collection tool to the remote endpoint, collects volatile and file system data, and analyzes the data.
CyberArk Identity Event Collector [CyberArkIdentity] — This integration collects events from the Idaptive Next-Gen Access (INGA) using REST APIs.
CyberArkAIM [cyberark_AIM] — Deprecated. Use the CyberArk AIM v2 integration instead.
CyberArkAIM v2 [cyberark_AIM] — The CyberArk Application Identity Manager (AIM) provides a secure safe in which to store your account credentials. Use this integration to retrieve the account credentials in CyberArk AIM.
CyberArkEPMEventCollector [CyberArkEPM] — Collects policy audits, admin audits, and detailed (raw) events from CyberArk Endpoint Privilege Manager (EPM).
CyberArkEPMSOCResponse [CyberArkEPM] — Use the CyberArk EPM integration to activate and deactivate CyberArk EPM risk plans for specific endpoints.
CyberArkISP [CyberArkPAS] — CyberArk Identity Security Platform secures human and machine identities across hybrid/multi-cloud environments with intelligent privilege controls, AI-driven threat detection, and Zero Trust enforcement.
CyberArkPAS [CyberArkPAS] — Use the CyberArk Privileged Access Management (PAM) solution to manage users, safes, vaults, and accounts from Cortex XSOAR.
CyberChef [CyberChef] — CyberChef is a web-application developed by GCHQ that's been called the “Cyber Swiss Army Knife”.
CyberTotal [CyberTotal] — CyberTotal is a cloud-based threat intelligence service developed by CyCraft.
Cybereason [Cybereason] — Endpoint detection and response to manage and query malops, connections and processes.
Cyberhaven [Cyberhaven] — Fetches DLP incidents from the Cyberhaven data security platform and enables investigation of events and data lineage.
Cyberint Feed [Cyberint] — Use the Cyberint Feed integration to get indicators from the feed.
Cyberint Premium Feed [Cyberint] — Use the Check Point EM ThreatCloud Intelligence Feed integration to ingest high-fidelity IOC indicators from the Cyberint Infinity External Risk Management IOC APIs and to enrich a single indicator on demand.
Cyberint Takedowns [Cyberint] — Use the Cyberint Takedowns integration to manage takedowns requests.
Cyberpion [Cyberpion] — The Cyberpion integration allows you to seamlessly receive all your Cyberpion security solution Action Items and supportive information to your Cortex XSOAR.
Cybersixgill_Actionable_Alerts [Cybersixgill-ActionableAlerts] — Cybersixgill automatically collects intelligence in real-time on all items that appear in the underground sources which we monitor. By using various rules and machine learning models, Cybersixgill automatically correlates these intelligence items with pre defined organization assets, and automatically alerts users in real time of any relevant intelligence items.
Cybersixgill_DVE_Enrichment [Cybersixgill-DVE] — By enriching CVEs with the DVE Score, Cortex XSOAR customers gain deeper visibility with relevant threat intel from the deep and dark web with dynamic attributes such as where they are trending, POC exploit details, and more. Loaded with extra-context, this allows users to accurately understand the real impact of CVEs to effectively prioritize critical vulnerabilities.
Cyberwatch [Cyberwatch] — Get Assets, CVEs, and Security Issues data from Cyberwatch Vulnerability and Compliance Manager.
CybleEvents [CybleEvents] — Cyble Events for Vision Users. Must have Vision API access to use the threat intelligence.
CybleThreatIntel [CybleThreatIntel] — Cyble Threat Intelligence for Vision Users. Must have access to Cyble TAXII Feed to access the threat intelligence.
Cyjax Feed [FeedCyjax] — The feed allows customers to pull indicators of compromise from cyber incidents (IP addresses, URLs, domains, CVE and file hashes).
Cylance Protect v2 [Cylance_Protect] — Manage Endpoints using Cylance protect.
Cymon [DeprecatedContent] — Deprecated. Analyzes suspicious domains and IP addresses
Cymptom [Cymptom] — Cymptom is a Breach and Attack Simulation solution that revolutionizes the existing approach by transforming attack simulation into a data analysis question. Cymptom agentless scanning brings real-time always-on visibility into the entire security posture.
Cymulate [Cymulate] — Multi-Vector Cyber Attack, Breach and Attack Simulation.
Cypho Threat Intelligence [CyphoThreatIntelligence] — This integration enables your organization to efficiently collect, analyze, and respond to actionable cyber alerts generated within the Cypho platform enhancing visibility, automation, and overall security posture.
Cyren Inbox Security [CyrenInboxSecurity] — Cyren Inbox Security is an innovative solution that safeguards Office 365 mailboxes in your organization against evasive phishing, business email compromise (BEC), and fraud. This integration imports incidents from Cyren Inbox Security into XSOAR, and includes a playbook for incident resolution.
CyrenThreatInDepth [FeedCyrenThreatInDepth] — Threat InDepth's actionable and contextualized intelligence helps enterprises improve their threat detection and response by providing unprecedented visibility into new email-borne security threats faster than other security vendors.
DB2 [DB2] — Integration to provide connectivity to IBM DB2 using the python ibm_db2 library.
DBot Truth Bombs [DBotTruthBombs] — You thought you know DBot... guess again! Here are some super secrete facts about DBot we bet you didn't know.
DFIRe [DFIRe] — Integration with DFIRe (Digital Forensics and Incident Response) platform for case management and IOC indicator tracking.
DHS Feed [FeedDHS] — The Cybersecurity and Infrastructure Security Agency’s (CISA’s) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community.
DHS Feed v2 [FeedDHS] — The Cybersecurity and Infrastructure Security Agency’s (CISA’s) free Automated Indicator Sharing (AIS) capability enables the exchange of cyber threat indicators, at machine speed, to the Federal Government community.
DNS [Ansible_Powered_Integrations] — Manage DNS records using NSUpdate. Deprecated. Use Ansible DNS (in the Ansible Linux pack) instead.
DNSDB_v2 [DNSDB] — Farsight Security DNSDB
DNSDB is a Passive DNS (pDNS) historical database that provides a unique, fact-based, multifaceted view of the configuration of the global Internet infrastructure DNSDB leverages the richness of Farsight’s Security Information Exchange (SIE) data-sharing platform and is engineered and operated by leading DNS experts.
DNSOverHttps [DNSOverHttps] — Query dns names over https from Cloudflare or Google
DSPM [DSPM] — Remediate your data security risks. Integrate with Prisma Cloud DSPM to fetch your data security risks and remediate them with OOTB playbooks.
DShield Feed [FeedDShield] — This integration fetches a list that summarizes the top 20 attacking class C (/24) subnets over the last three days from Dshield.
DUO Admin [DuoAdminApi] — DUO for admins.
Must have access to the admin api in order to use this.
Darkmon [Darkmon] — Stay ahead of cyber threats with Darkmon TIP - real-time threat intelligence from the Clear, Deep, and Dark Web tailored to your assets.
Pack also helps with integration with Cortex XSOAR and provides pre-made playbooks/templates to ease integration use.
Darkmon Feed [Darkmon] — Darkmon TIP indicator feed for Cortex XSOAR. Pulls IPs, URLs, domains, file hashes,
emails, and accounts from the Darkmon Threat Intel firehose into the XSOAR TIM
module. Pair with the Darkmon integration for incident fetching and automation
commands.
Darktrace [Darktrace] — Deprecated. Use DarktraceMBs, DarktraceAIA, DarktraceAdmin instead.
Darktrace ASM [DarktraceASM] — This pack includes configurations to combine the world-class threat detection of Darktrace with the synchrony and automation abilities of XSOAR, allowing security teams to monitor their attack surface for risks, high-impact vulnerabilities and external threats.\nTo configure the connection to your Darktrace Attack Surface Management instance, you will provide:\n- Server URL of Darktrace ASM instance (ex: darktrace.yourcompany.com) and any necessary proxy information\n- The API Token from the Darktrace ASM instance.
Darktrace Event Collector [Darktrace] — Use this integration to fetch model breaches from Darktrace as events in XSIAM.
DarktraceAIA [Darktrace] — Rapid detection of malicious behaviour can make all the difference in the response to a security event. This pack includes configurations to combine the world-class threat detection of Darktrace with the synchrony and automation abilities of XSOAR, allowing security teams to investigate critical incidents along with accompanying summaries and timelines. AI actions can also be applied.
DarktraceAdmin [Darktrace] — This pack includes configurations to combine the world-class threat detection of Darktrace with the synchrony and automation abilities of XSOAR, allowing security teams to manage device actions including device statuses and tags. Your understanding of potential threats can also be levelled-up with Advanced Search logs from DPI.
DarktraceEmail [Darktrace] — This pack includes configurations to combine the world-class threat detection of Darktrace with the synchrony and automation abilities of XSOAR, allowing security teams to investigate critical incidents along with accompanying summaries and timelines.
DarktraceMBs [Darktrace] — Rapid detection of malicious behaviour can make all the difference in the response to a security event. This pack includes configurations to combine the world-class threat detection of Darktrace with the synchrony and automation abilities of XSOAR, allowing security teams to investigate model breaches and all model breach related actions (such as commenting, acknowledging and model logic info).
DataBee [DataBee] — DataBee, from Comcast Technology Solutions, is a cloud-native security and compliance data fabric that ingests data from multiple disparate feeds and then aggregates, compresses, standardizes, enriches, correlates, and normalizes the data before transferring a full time-series dataset to your data lake of choice.
DatadogCloudSIEM [DatadogCloudSIEM] — Deprecated. Datadog is an observability service for cloud-scale applications, providing monitoring of servers, databases, tools, and services, through a SaaS-based data analytics platform.
The SaaS platform integrates and automates infrastructure monitoring, application performance monitoring and log management to provide unified, real-time observability of our customers' entire technology stack.
DatadogCloudSIEMV2 [DatadogCloudSIEM] — Datadog Cloud SIEM integration for XSOAR provides security signal management capabilities. This integration allows you to retrieve, filter, and manage security signals from Datadog's Cloud SIEM platform, enabling security teams to investigate threats, manage signal triage states, and assign signals to team members. Supports incoming mirroring of signals to XSOAR incidents.
Dataminr Pulse [DataminrPulse] — Dataminr Pulse's AI-powered, real-time intelligence integrates into Cortex XSOAR workflows for faster detection and response.
Dataminr Pulse ReGenAI [DataminrPulse] — Dataminr Pulse's AI-powered, real-time intelligence integrates into Cortex XSOAR workflows for faster detection and response.
DeHashed [DeHashed] — This integration allows you to check if your personal information such as your email, username, or password is being compromised.
DecyfirEventCollector [DeCYFIR] — Collects event logs from DeCYFIR for ingestion into Cortex XSIAM.
Deep Instinct [DeepInstinct] — The Deep Learning cybersecurity platform, for zero time prevention.
DeepInstinct v3 [DeepInstinct] — Deep Instinct is a prevention-first approach to stopping ransomware and other malware using the world's first purpose-built, deep learning cybersecurity framework.
DeepL [DeepL] — This integration uses DeepL (https://www.deepl.com/) to translate text or files
DelineaDSV [DelineaDSV] — Manage credentials for applications, databases, CI/CD tools, and services without causing friction in the development process.
DelineaSS [DelineaSS] — Delinea Secret Server and Platform is the fully featured Privileged Account Management (PAM) solution available both on premise and in the cloud. It empowers security and IT ops teams to secure and manage all types of privileged accounts and offers the fastest time to value of any PAM solution.
Dell Secureworks [SecureWorks] — Provides access to the Secureworks CTP ticketing system.
Demisto Lock [DemistoLocking] — Locking mechanism that prevents concurrent execution of different tasks.
Devo [Devo] — Deprecated. Use the Devo v2 integration instead.
Devo_v2 [Devo] — Use the Devo v2 integration to query Devo for alerts, lookup tables, with support of pagination, and to write to lookup tables.
Digital Defense FrontlineVM [Digital_Defense_FrontlineVM] — Use the Digital Defense FrontlineVM to identify and evaluate the security and business risks of network devices and applications deployed as premise, cloud, or hybrid network-based implementations.
Digital Guardian [DigitalGuardian] — Use Digital Guardian Integration to fetch incidents and to programmatically add or remove entries from watchlists and component lists.
Digital Shadows [DigitalShadows] — Digital Shadows monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web.
Discord [Discord] — This is the Discord integration for sending Messages from XSOAR to Discord server made by Trustnet
Docker Engine API [DevSecOps] — The Engine API is an HTTP API served by Docker Engine. It is the API the Docker client uses to communicate with the Engine, so everything the Docker client can do can be done with the API.
Docusign [Docusign] — Docusign is a leading provider of electronic signature technology, allowing individuals and organizations to sign, send, and manage documents digitally.
DomainTools [DomainTools] — Deprecated. Use DomainTools Iris Pack instead.
DomainTools Iris [DomainTools_Iris] — Together, DomainTools and Cortex XSOAR automate and orchestrate the incident response process with essential domain profile, web crawl, SSL and infrastructure data. SOCs can create custom, automated workflows to trigger Indicator of Compromise (IoC) investigations, block threats based on connected infrastructure, and identify potentially malicious domains before weaponization. The DomainTools App for Cortex XSOAR is shipped with pre-built playbooks to enable automated enrichment, decision logic, ad-hoc investigations, and the ability to persist enriched intelligence.
DomainToolsIrisDetect [DomainToolsIrisDetect] — DomainTools is an essential component in the security stack of mature enterprises and performance-driven security teams.
Doppel [Doppel] — Doppel is a Modern Digital Risk Protection Solution, that detects the phishing and brand cyber attacks on the emerging channels. Doppel scans millions of channels online which includes, social media, domains, paid ads, dark web, emerging channels, etc. Doppel can identify the malicious content and cyber threats, and enables their customers to take down the digital risks proactively.
The Cortex XSOAR pack for Doppel mirrors the alerts created by Doppel as Cortex XSOAR incidents. The pack also contains the commands to perform different operations on Doppel alerts.
Dragos Worldview [DragosWorldview] — Custom integration designed to pull in reports from the Dragos Worldview API as incidents.
Drift [Drift] — Drift integration to fetch, modify, create and delete contacts within the Drift Plattform's Contact API.
Druva Ransomware Response [Druva] — Druva Ransomware Response Integration provides ransomware protection for endpoints, SaaS applications and data center workloads for Druva Ransomware Recovery customers.
DruvaEventCollector [Druva] — Druva Ransomware Response Integration provides ransomware protection for endpoints, SaaS applications and data center workloads for Druva Ransomware Recovery customers.
Duo Event Collector [DuoAdminApi] — Collects Auth and Audit events for Duo using the API.
DuoAuth [DuoAuth] — The Duo Auth API lets developers integrate with Duo Security's platform at a low level.
EDL [EDL] — Use the Generic Export Indicators Service integration to provide an endpoint with a list of indicators as a service for the system indicators.
EDL Monitor [EDLMonitor] — This integration can monitor EDLs by emailing the content of an EDL as a zipped file to a specified user at an interval (when run with a job), and/or simply monitor the EDL for availability and email the user if the EDL is not available in other playbooks
EWS Extension Online Powershell v3 [MicrosoftExchangeOnline] — Use the EWS Extension Online Powershell v3 integration to get information about mailboxes and users in your organization. This integration can also retrieve and modify Tenant Allow/Block Lists.
EWS Mail Sender [MicrosoftExchangeOnPremise] — Exchange Web Services mail sender. Note: this integration supports Office 365 basic authentication only. If you are using Office 365, we recommend using the EWS O365 Integration instead, which supports modern authentication (oauth2). Deprecated. Use EWS v2 instead
EWS v2 [MicrosoftExchangeOnPremise] — Exchange Web Services and Office 365 (mail).
EWSO365 [MicrosoftExchangeOnline] — The new EWS O365 integration uses OAuth 2.0 protocol and can be used with Exchange Online and Office 365 (mail).
EasyVista [EasyVista] — EasyVista Service Manager manages the entire process of designing, managing and delivering IT services.
EclecticIQ Intelligence Center v3 [EclecticIQ] — Threat Intelligence Platform that connects and interprets intelligence data from open sources, commercial suppliers and industry partnerships .
Elasticsearch v2 [Elasticsearch] — Search for and analyze data in real time.
Supports version 6 and later.
ElasticsearchEventCollector [Elasticsearch] — Search for and analyze data in real time.
Supports version 6 and later.
ElasticsearchFeed [FeedElasticsearch] — Fetches indicators stored in an Elasticsearch database.
Email Hippo [EmailHippo] — This is the Email Hippo integration used to verify email sources as fake emails that were used as part of phishing attacks.
EmailRepIO [EmailRepIO] — Provides email address reputation and reports.
Endace [Endace] — The EndaceProbe Analytics Platform provides 100% accurate, continuous packet capture on network links up to 100Gbps, with unparalleled depth of storage and retrieval performance. Coupled with the Endace InvestigationManager, this provides a central search and data-mining capability across a fabric of EndaceProbes deployed in a network.
This integration uses Endace APIs to search, archive and download PCAP file from either a single EndaceProbe or many via the InvestigationManager and enables integration of full historical packet capture into security automation workflows.
Endgame [Endgame] — Endpoint protection built to stop advanced attacks before damage and loss occurs.
Envoy IAM [Envoy] — Integrate with Envoy Identity Access Management services to execute CRUD operations to employee lifecycle processes.
Exabeam [Exabeam] — The Exabeam Security Management Platform provides end-to-end detection, User Event Behavioral Analytics, and SOAR.
Exabeam Data Lake [ExabeamDataLake] — Exabeam Data Lake provides a searchable log management system. Data Lake is used for log collection, storage, processing, and presentation.
ExabeamSecOpsPlatform [ExabeamSecurityOperationsPlatform] — Exabeam Security Operations Platform offers a centralized and scalable platform for log management.
ExceedLMS IAM [ExceedLMS] — Integrate with Exceed LMS Identity Access Management services to execute CRUD operations to employee lifecycle processes.
Expanse [Expanse] — Deprecated. Use the Expanse v2 integration instead. The Expanse App for Demisto leverages the Expander API to retrieve network exposures and risky flows to create incidents in Demisto. This application also allows for IP, Domain, Certificate, Behavior, and Exposure enrichment, retrieving assets and exposures information drawn from Expanse’s unparalleled view of the Internet.
ExpanseV2 [ExpanseV2] — Deprecated. Use Cortex Xpanse integration instead. > The Xpanse integration for Cortex XSOAR leverages the Expander API to create incidents from Cortex Xpanse issues. It also leverages Cortex Xpanse's unparalleled view of the Internet to enrich IPs, domains and certificates using information from assets discovered by Cortex Xpanse Expander and risky flows detected by Cortex Xpanse Behavior.
ExportIndicators [ExportIndicators] — Deprecated. Use the Generic Export Indicators Service integration instead. Use the Export Indicators Service integration to provide an endpoint with a list of indicators as a service for the system indicators.
Exterro FTK [Exterro] — Use the Exterro FTK integration to protect against and provide additional visibility into phishing and other malicious email attacks.
ExtraHop [DeprecatedContent] — Deprecated. We recommend using ExtraHop Reveal(x) instead. ExtraHop performs real-time stream analysis of the packets that carry data across a network.
ExtraHop v2 [ExtraHop] — ExtraHop Reveal(x) for Cortex XSOAR is a network detection and response solution that provides complete visibility of network communications at enterprise scale, real-time threat detections backed by machine learning, and guided investigation workflows that simplify response.
ExtrahopRevealXEventCollector [ExtraHop] — ExtraHop Reveal(x) is a network detection and response solution that provides complete visibility of network communications at enterprise scale, real-time threat detections backed by machine learning, and guided investigation workflows that simplify response.
F5Silverline [F5Silverline] — F5 Silverline Threat Intelligence is a cloud-based service incorporating external IP reputation and reducing threat-based communications. By identifying IP addresses and security categories associated with malicious activity, this managed service integrates dynamic lists of threatening IP addresses with the Silverline cloud-based platform, adding context-based security to policy decisions.
FTP [FTP] — FTP integration to download or upload files to a remote FTP server. Please note that FTP transfer is insecure. Please use it with care.
FalconHost [CrowdStrikeHost] — Deprecated. Use the CrowdStrike Falcon integration instead.
Fastly Feed [FeedFastly] — Use Fastly Feed to get assigned CIDRs and add them to your firewall's allowlist in order to enable using Fastly's services.
FeedCyCognito [FeedCyCognito] — The CyCognito Feed integration retrieves the discovered assets from the CyCognito platform based on user-specified filters. A comprehensive dashboard and layout are also included.
FeedDomainTools [FeedDomainTools] — Real-Time Threat Intelligence Feeds provide data on the different stages of the domain lifecycle: from first-observed in the wild, to newly re-activated after a period of quiet. Newly Active Domains surfaces apex-level domains seen for the first time or after ten or more days of inactivity. Newly Observed Domains surfaces domains that we observe for the first time.
FeedExpanse [ExpanseV2] — Deprecated. Use Xpanse Feed integration instead. > Use this feed to retrieve the discovered IPs/Domains/Certificates from Expanse Expander asset database.
FeedMISPThreatActors [FeedMISPThreatActors] — Fetches the MISP threat actor galaxy and builds it into Threat Actor indicators in Cortex Threat Intel Management (TIM).
FeedMandiant [FeedMandiant] — Deprecated. Use Mandiant Advantage Threat Intelligence instead.
FeedNVDv2 [FeedNVDv2] — This feed pulls CVE information from the NIST National Vulnerability Database using v2.0 of the API.
By default, CVEs with a REJECTED status are excluded. Enable 'Include Rejected CVEs' to ingest them.
This integration/feed deprecates the original National Vulnerability Database Feed integraiton as v1.0 of the API is being sunsetted in 2023.
FeedORKL [FeedORKL] — Use the ORKL Threat Intel Feed integration to get receive threat intelligence indicators from the feed.
FeedSOCRadarThreatFeed [FeedSOCRadarThreatFeed] — Retrieve indicators provided by collections via SOCRadar Threat Intelligence Feeds.
FeedSOCRadarThreatFeedV2 [SOCRadar] — Retrieve indicators provided by SOCRadar Collection Based IOC Feed using collection UUIDs. Users can create custom feed collections on the SOCRadar platform and use their UUIDs to fetch IOCs via this integration.
FeedServiceNow [FeedServiceNow] — This is a feed integration for extracting indicators from ServiceNow.
FeedURLhaus [FeedURLhaus] — Fetch url indicators for URLHaus.
FeedUstaThreatStream [USTAv4] — Fetches indicators from the USTAv4 Threat Stream feed. The indicators can be of type malicious URLs or malware hashes.
Feedly Feed [FeedFeedly] — Ingest articles with indicators, entities and relationships from Feedly into XSOAR.
Feodo Tracker Hashes Feed [FeedFeodoTracker] — Deprecated. Feodo Tracker no longer supports this feed. No available replacement.
Fidelis EDR [FidelisEndpoint] — Use the Fidelis Endpoint integration for advanced endpoint detection and response (EDR) across Windows, Mac and Linux OSes for faster threat remediation.
Fidelis Elevate Network [FidelisElevateNetwork] — Automate Detection and Response to Network Threats and data leakage in your organization with Fidelis Elevate Network Integration.
FireEye Central Management [FireEyeCM] — FireEye Central Management (CM Series) is the FireEye threat intelligence hub. It services the FireEye ecosystem, ensuring that FireEye products share the latest intelligence and correlate across attack vectors to detect and prevent cyber attacks.
FireEye Detection on Demand [FireEye-Detection-on-Demand] — FireEye Detection On Demand is a threat detection service delivered as an API for integration into the SOC workflow, SIEM analytics, data repositories, or web applications, etc. It delivers flexible file and content analysis to identify malicious behavior wherever the enterprise needs it.
FireEye ETP [FireEyeETP] — Trellix Email Security - Cloud is a cloud-based platform that protects against advanced email attacks.
FireEye ETP Event Collector [FireEyeETP] — Use this integration to fetch email security incidents from Trellix Email Security - Cloud as Cortex XSIAM events.
FireEye Email Security [FireEyeEX] — FireEye Email Security (EX) series protects against breaches caused by advanced email attacks.
FireEye HX [FireEyeHX] — Deprecated. Use FireEyeHX v2 instead.
FireEyeHX v2 [FireEyeHX] — FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. This integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. You can extract critical data and effectively operate the security operations automated playbook.
FireEyeHelix [FireEyeHelix] — FireEye Helix is a security operations platform. FireEye Helix integrates security tools and augments them with next-generation SIEM, orchestration and threat intelligence tools such as alert management, search, analysis, investigations and reporting.
FireEyeNX [FireEyeNX] — FireEye Network Security is an effective cyber threat protection solution that helps organizations minimize the risk of costly breaches by accurately detecting and immediately stopping advanced, targeted, and other evasive attacks hiding in internet traffic.
FireMonSecurityManager [FireMonSecurityManager] — FireMon Security Manager delivers comprehensive rule lifecycle management to help you manage and automate every stage of the change management process. Workflows can be customized and automated to conform to your security goals and standards, with tools at your disposal to evolve policy and protection over time.
Flashpoint [Flashpoint] — Deprecated. Use Flashpoint Ignite instead.
Flashpoint Vulnerability Feed [FeedFlashpointVulnerability] — Flashpoint Vulnerability Feed Integration allows importing vulnerability intelligence from the Flashpoint platform, empowering teams to reduce exposure windows by identifying high-risk vulnerabilities weeks before public sources. This includes independent research, zero-day disclosures, analyst recommendations, affected and non-affected versions, and over 105,000 vulnerabilities not found in the public NVD/CVE feeds database.
FlashpointFeed [FlashpointFeed] — Deprecated. Use Flashpoint Ignite Feed instead.
Forcepoint [Forcepoint] — Advanced threat protection with added local management controls.
Forcepoint DLP Event Collector [ForcepointDLP] — Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events.
Forcepoint Security Management Center [ForcepointSecurityManagementCenter] — Forcepoint SMC provides unified, centralized management of all models of Forcepoint engines whether physical, virtual or cloud—across large, geographically distributed enterprise environments.
Forescout [Forescout] — Unified device visibility and control platform for IT and OT Security.
ForescoutEyeInspect [ForescoutEyeInspect] — Delivers flexible and scalable OT/ICS asset visibility.
Fortanix DSM [Fortanix-DSM] — Manage Secrets and Protect Confidential Data using Fortanix Data Security Manager.
FortiAuthenticator [FortiAuthenticator] — This integration allows you to manage the user configuration on FortiAuthenticator.
FortiGate [FortiGate] — FortiGate provides flawless convergence that can scale to any location: remote office, branch, campus, data center, and cloud. FortiGate always delivered on the concept of hybrid mesh firewalls with FortiManager for unified management and consistent security across complex hybrid environments. The Fortinet FortiOS operating system provides deep visibility and security across a variety of form factors.
FortiManager [FortiManager] — FortiManager is a single console central management system that manages Fortinet devices.
FortiSIEM [FortiSIEM] — Search and update events of FortiSIEM and manage resource lists.
FortiSIEMV2 [FortiSIEM] — Use FortiSIEM v2 to fetch and update incidents, search events and manage watchlists of FortiSIEM.
FortiSandbox [FortiSandbox] — FortiSandbox integration is used to submit files to FortiSandbox for malware analysis and retrieving the report of the analysis. It can also provide file rating based on hashes for already scanned files. Deprecated. Use FortiSandboxv2 instead.
FortiSandboxv2 [FortiSandbox] — FortiSandbox is an advanced security tool that goes beyond standard sandboxing. It combines proactive mitigation, enhanced threat detection, and in-depth reporting, using Fortinet's dynamic antivirus technology, dual-level sandboxing, and FortiGuard cloud integration to counter advanced threats. It effectively detects viruses, Advanced Persistent Threats (APTs), and malicious URLs, integrating seamlessly with existing Fortinet devices like FortiGate and FortiMail for comprehensive network protection.
FraudWatch [FraudWatch] — Manage incidents via the Fraudwatch API. FraudWatch International provides a fully managed Enterprise Digital Brand Protection Suite, including online brand management & monitoring, as well as providing other brand protection solutions that protect organizations and their customers around the world against online brand-related abuse.
Freshdesk [FreshDesk] — The Freshdesk integration allows you to create, update, and delete tickets; reply to and create notes for tickets as well as view Groups, Agents and Contacts.
FreshworksFreshservice [FreshworksFreshservice] — Freshservice is a service management solution that allows customers to manage service requests, incidents, change requests tasks, and problem investigation.
FullHunt [FullHunt] — Cortex XSOAR integration with FullHunt.io API.
G Suite Security Alert Center [GSuiteSecurityAlertCenter] — G Suite Security Alert Center allows users to fetch different alert types such as Suspicious login, Device compromised, Leaked password, and more. Users can delete or recover a single alert or a batch of alerts and retrieve the alert's metadata. This integration allows users to provide feedback for alerts and fetch existing feedback for a particular alert.
GCP [GCP] — Manage and secure Google Cloud Platform resources. On Cortex Platform, authentication is handled automatically via the cloud connector. For Cortex XSOAR and Cortex XSIAM (version < 3.0), configure a GCP Service Account private key JSON and a default GCP Project ID.
GCP Whitelist Feed [FeedGCPWhitelist] — Deprecated. Use the Google IP Ranges Feed integration instead.
GCP-IAM [GCP-IAM] — Manage identity and access control for Google Cloud Platform resources.
GCenter [Gatewatcher-AionIQ] — This integration allows, via about twenty commands, to interact with the GCenter appliance via its API.
GCenter 103 [Gatewatcher-AionIQ] — This integration fetch events generated by the GCenter appliance.
GLIMPS_Detect [GLIMPS_Detect] — Use the GLIMPS Detect Integration to send files to GLIMPS Malware and get results from it.
GSuiteAdmin [GSuiteAdmin] — G Suite or Google Workspace Admin is an integration to perform an action on IT infrastructure, create users, update settings, and more administrative tasks.
GSuiteAuditor [GsuiteAuditor] — G Suite Auditor is an integration that receives Audit logs from G Suite's different applications - admin, drive, calender, and more.
Gamma [Gamma] — Query and update violations in Gamma.
Gem [Gem] — Use Gem alerts as a trigger for Cortex XSOAR’s custom playbooks, to automate response to specific TTPs.
Generic SQL [GenericSQL] — Use the Generic SQL integration to run SQL queries on the following databases: MySQL, PostgreSQL, Microsoft SQL Server, Oracle, Teradata and Trino.
Generic Webhook [GenericWebhook] — The Generic Webhook integration is used to create incidents on event triggers. The trigger can be any query posted to the integration.
Generic Webhook (Form Data) [GenericWebhook_FormData] — The Generic Webhook (Form Data) integration is used to create incidents on event triggers. The trigger can be any query posted to the integration.
GenericAPICall [GenericAPICall] — Integration version of the httpv2 automation used to send HTTP requests for API calls to endpoints not associated with an existing XSOAR integration.
GenericAPIEventCollector [GenericAPIEventCollector] — Collect logs from 3rd party vendors using API.
GenesysCloud [GenesysCloud] — Fetch audit events to see changes within a Genesys Cloud organization.
Genians [Genians] — Use the Genian NAC integration to block IP addresses using the assign tag.
Gigamon ThreatINSIGHT [GigamonThreatINSIGHT] — Gigamon ThreatINSIGHT is a cloud-native network detection and response solution built for the rapid detection of threat activity, investigation of suspicious behavior, proactive hunting for potential risks, and directing a fast and effective response to active threats.
Giphy [Giphy] — Display random GIF in the War Room (e.g. !giphy hello). Powered By Giphy.
GitGuardianEventCollector [GitGuardian] — This is the GitGuardian event collector integration for Cortex XSIAM.
Google Apigee [GoogleApigee] — Apigee is Google Cloud's native API management platform that can be used to build, manage, and secure APIs — for any use case, environment, or scale. Apigee offers high performance API proxies to create a consistent, reliable interface for your backend services. The proxy layer gives you granular control over security, rate limiting, quotas, analytics, and more for all of your services. Apigee supports REST, gRPC, SOAP, and GraphQL, providing the flexibility to implement any API architectural style.
Google BigQuery [GoogleBigQuery] — Integration for Google BigQuery, a data warehouse for querying and analyzing large databases. In all commands, for any argument not specified, the BigQuery default value for that argument will be applied.
Google Chat via Webhook [GoogleChatViaWebhook] — Integration for sending notifications to a Google Chat space via Incoming Webhook.
Google Chronicle Backstory [GoogleChronicleBackstory] — Use the Chronicle integration to retrieve Asset alerts or IOC Domain matches as Incidents. Use it to fetch a list of infected assets based on the indicator accessed. This integration also provides reputation and threat enrichment of indicators observed in the enterprise.
Google Chronicle Backstory Streaming API [GoogleChronicleBackstory] — Use the Google SecOps Streaming API integration to ingest detections created by both user-created rules and Google SecOps Rules as XSOAR incidents.
Google Cloud Compute [GoogleCloudCompute] — Google Compute Engine delivers virtual machines running in Google's innovative data centers and worldwide fiber network. Compute Engine's tooling and workflow support enable scaling from single instances to global, load-balanced cloud computing.
Google Cloud Functions [GoogleCloudFunctions] — Google Cloud Functions is an event-driven serverless compute platform that enables you to run your code locally or in the cloud without having to provision servers.
Google Cloud Storage [GoogleCloudStorage] — Google Cloud Storage is a RESTful online file storage web service for storing and accessing data on Google Cloud Platform infrastructure.
Google Dorking [GoogleDorking] — Automate the process of google dorking searches in order to detect leaked data.
Google IP Ranges Feed [FeedGCPWhitelist] — Use the Google IP Ranges integration to get GCP and Google global IP ranges.
Google Key Management Service [GoogleKeyManagementService] — Use the Google Key Management Service API for CryptoKey management and encrypt/decrypt functionality.
Google Safe Browsing v2 [GoogleSafeBrowsing] — Search Safe Browsing, The Safe Browsing APIs (v4) let your client applications check URLs against Google's constantly updated lists of unsafe web resources.
Google Threat Intelligence IoC Stream Feed [GoogleThreatIntelligence] — Use this feed integration to fetch Google Threat Intelligence IoC Stream notifications as indicators.
Google Threat Intelligence Threat Lists [GoogleThreatIntelligence] — Use this feed integration to fetch Google Threat Intelligence Threat Lists matches as indicators.
Google Vertex AI [GoogleVertexAI] — Fine-tuned to conduct natural conversation. Using Google Vertex Ai (PaLM API for Chat).
The current integration of Google Vertex Ai is focusing only on the Generative AI model (PaLM) using the Chat prediction.
Later, this plugin will be updated to include the following:
- Model Creation
- Model Fine Tuning
- PaLM Text.
Google Vision AI [GoogleVisionAPI] — Image processing with Google Vision API.
GoogleCalendar [GoogleCalendar] — Google Calendar is a time-management and scheduling calendar service developed by Google. This integration helps you to perform various tasks on the access control list (ACL).
GoogleCloudLogging [GoogleCloudLogging] — With Google Cloud Logging, users can centralize all their logs in a single location, making it easier to troubleshoot issues and gain insights from their data.
GoogleCloudSCC [GoogleCloudSCC] — Security Command Center is a security and risk management platform for Google Cloud. Security Command Center enables you to understand your security and data attack surface by providing asset inventory and discovery, identifying vulnerabilities and threats, and helping you mitigate and remediate risks across an organization. This integration helps you to perform tasks related to findings and assets.
GoogleCloudTranslate [GoogleCloudTranslate] — A Google API cloud based translation service.
GoogleDocs [GoogleDocs] — Use the Google Docs integration to create and modify Google Docs documents.
GoogleDrive [GoogleDrive] — Google Drive allows users to store files on their servers, synchronize files across devices, and share files. This integration helps you to create a new drive, query past activity, and view change logs performed by the users.
GoogleDriveStandardConnector [GoogleDriveStandardConnector] — This integration is configured automatically as part of the Google Drive Standard Connector. Do not configure this integration directly — set it up from the connector page instead.
GoogleGemini [GoogleGemini] — Google Gemini LLM Integration for AI-powered analysis and chat capabilities.
This integration provides access to Google Gemini's large language models for:
- AI-powered chat conversations
- Text analysis and generation
- Natural language processing tasks
Supports both Google AI Studio (API key) and Google Cloud Vertex AI (service account) authentication.
Supported models include Gemini 2.0 Flash, Gemini 1.5 Pro, and various preview models.
GoogleKubernetesEngine [GoogleKubernetesEngine] — The Google Kubernetes Engine integration is used for building and managing container based
applications in Google Cloud Platform (GCP), powered by the open source Kubernetes technology.
GoogleMaps [GoogleMaps] — Use the Google Maps API.
GooglePubSub [GooglePubSub] — Google Cloud Pub/Sub is a fully-managed real-time messaging service that enables you to send and receive messages between independent applications.
GoogleSafeBrowsing [GoogleSafeBrowsing] — Deprecated. Use Google Safe Browsing v2 instead.
GoogleSecOps [GoogleChronicleBackstory] — Use the Google SecOps integration to retrieve IOC Domain matches as Incidents. This integration also provides reputation and threat enrichment of indicators observed in the enterprise.
GoogleSecOpsCases [GoogleChronicleBackstory] — Use the Google SecOps Cases integration to retrieve Cases as Incidents. This integration also provides commands to manage the Cases lifecycle.
GoogleSheets [GoogleSheets] — Google Sheets is a spreadsheet program that is part of the free web-based Google applications to create and format spreadsheets. Use this integration to create and modify spreadsheets.
GoogleThreatIntelligence [GoogleThreatIntelligence] — Analyzes suspicious hashes, URLs, domains, and IP addresses.
GoogleThreatIntelligenceASMIssues [GoogleThreatIntelligence] — This integration allows the creation of incidents based on ASM Issues from Google Threat Intelligence.
GoogleThreatIntelligenceDTMAlerts [GoogleThreatIntelligence] — This integration allows the creation of incidents based on DTM Alerts from Google Threat Intelligence.
GoogleThreatIntelligenceRSAlerts [GoogleThreatIntelligence] — This integration allows the creation of incidents based on RS Alerts from Google Threat Intelligence.
Gophish [Gophish] — Gophish is a powerful, open-source phishing framework that makes it easy to test your organization's exposure to phishing. For Free.
GraphQL [GraphQL] — The Generic GraphQL client can interact with any GraphQL server API.
GravityZone [GravityZone] — GravityZone provides secure access to incident and endpoint data and enables remediation actions through its APIs.
Graylog [Graylog] — Integration with Graylog to search for logs and events.
GreatHorn [GreatHorn] — The only cloud-native security platform that stops targeted social engineering and phishing attacks on cloud email platforms like Office 365 and G Suite.
GreyNoise [GreyNoise] — GreyNoise is a cybersecurity platform that collects and analyzes Internet-wide scan and attack traffic. With this integration, users can contextualize existing alerts, filter false-positives, identify compromised devices, and track emerging threats.
GreyNoise Community [GreyNoise] — GreyNoise is a cybersecurity platform that collects and analyzes Internet-wide scan and attack traffic. With this integration, users can contextualize existing alerts, filter false-positives, identify compromised devices, and track emerging threats. This Integration is design specifically for GreyNoise Community users and only provides the subset of intel available via the GreyNoise Community API.
GreyNoise Indicator Feed [FeedGreyNoiseIndicator] — GreyNoise is a cybersecurity platform that collects and analyzes Internet-wide scan and attack traffic. With this integration, users can contextualize existing alerts, filter false-positives, identify compromised devices, and track emerging threats. This Integration provides a feed of IPv4 Internet Scanners from GreyNoise.
Group-IB Digital Risk Protection [GroupIB_DigitalRiskProtection] — Pack helps to integrate Group-IB Digital Risk Protection and get violations incidents directly into Cortex XSOAR.
Group-IB TDS Polygon [Polygon] — THF Polygon is a Malware Detonation & Research platform designed for deep dynamic analysis and enhanced indicators extraction. THF Polygon analyzes submitted files and urls and extracts deep IOCs that appear when malicious code is triggered and executed. Polygon could be used either for application-level tasks (like smtp-based mail filtering) and analytical purposes (files/urls analysis for verdict, report and indicators).
Group-IB Threat Intelligence & Attribution [GroupIB_ThreatIntelligenceAttribution] — Pack helps to integrate Group-IB Threat Intelligence and get incidents directly into Cortex XSOAR.
The list of included collections:
Compromised Accounts, Compromised Cards, Compromised Masked Cards, Brand Protection Phishing, Brand Protection Phishing Kit, OSI Git Leak, OSI Public Leak, Targeted Malware.
Group-IB Threat Intelligence & Attribution Feed [GroupIB_ThreatIntelligenceAttribution] — Use Group-IB Threat Intelligence Feed integration to fetch IOCs from various Group-IB collections.
GuardiCore [GuardiCore] — Deprecated. Use GuardiCore v2 instead.
GuardiCore v2 [GuardiCore] — The GuardiCore v2 integration provides access to incident and endpoint (asset) information via the GuardiCore API.
Guidance Encase Endpoint [Guidance_Encase_Endpoint] — Use the Enterprise Service Bus (ESB) to request scans of specified endpoints.
Gurucul-GRA [Gurucul] — Gurucul Risk Analytics (GRA) is a Unified Security and Risk Analytics platform.
HCloud [Ansible_Powered_Integrations] — Manage your Hetzner Cloud environment. Deprecated. Use the Ansible HCloud (from the Ansible Hetzner Cloud Pack) instead.
HPEArubaCentralEventCollector [HPEArubaCentral] — This is the Aruba Central event collector integration for Cortex XSIAM.
HPEArubaClearPass [HPEArubaClearPass] — Aruba ClearPass Policy Manager provides role and device-based network access control for employees, contractors, and guests across any multi-vendor wired, wireless, and VPN infrastructure.
HYAS Insight [HYASInsight] — Use the HYAS Insight integration to interactively lookup PassiveDNS, DynamicDNS, WHOIS, Sample Malware Records, C2 Attribution, Passive Hash, SSL Certificate, Open Source Indicators, Device Geo, Sinkhole, Malware Sample Information – either as playbook tasks or through API calls in the War Room.
HYAS Protect [HYASProtect] — Use the HYAS Protect integration to get the verdict information for FQDN, IP Address and NameServer – either as playbook tasks or through API calls in the War Room.
HackerOne [HackerOne] — HackerOne integration allows users to fetch reports by using the fetch incidents capability. It also provides commands to retrieve all the reports and programs.
Hackuity [Hackuity] — From a war-room, query your Hackuity cockpit in order to seamlessly retrieve information related to your vulnerability stock.
Halcyon [Halcyon] — Halcyon is a device management platform that helps organizations monitor, control, and secure their network of devices. It provides centralized tools for overseeing hardware and software inventory, deploying updates, enforcing security policies, and ensuring compliance across device environments.
HashiCorp Vault [HashiCorp-Vault] — Manage Secrets and Protect Sensitive Data through HashiCorp Vault.
HashicorpTerraform [HashiCorpTerraform] — Hashicorp Terraform provide infrastructure automation to provision and manage resources in any cloud or data center with Terraform.
Hatching Triage [HatchingTriage] — Submit a high volume of samples to run in a sandbox and view reports.
Have I Been Pwned? V2 [Pwned] — Uses the Have I Been Pwned? service to check whether email addresses, domains, or usernames were compromised in previous breaches.
Hello IAM World [HelloIAMWorld] — An Identity and Access Management integration template.
HelloWorld [HelloWorld] — This is the Hello World integration for getting started.
HelloWorld Feed [HelloWorld] — This is the Feed Hello World integration for getting started with your feed integration.
HelloWorldEventCollector [HelloWorld] — This is the Hello World event collector integration for Cortex XSIAM.
HelloWorldV2 [HelloWorld] — Use the Hello World v2 integration to learn how to build and configure Cortex integrations.
HostIo [HostIo] — Use the HostIo integration to enrich domains using the Host.io API.
Hoxhunt [Hoxhunt] — Deprecated. Use Hoxhunt V2 instead.
Hoxhunt v2 [Hoxhunt] — Use the Hoxhunt integration to send feedback to reporters of incidents, set incident sensitivity, and apply SOC classification to incidents.
Hudsonrock [Hudsonrock] — Enrichment from Hudsonrock OSINT tools at https://cavalier.hudsonrock.com/api/json/v2/osint-tools/ Supports: IP, Email and Username.
IBM Resilient Systems [IBMResilientSystems] — Case management that enables visibility across your tools for continual IR improvement.
IBM Storage Scale [IBMStorageScale] — Collects Command Line Interface (CLI) audit log records from IBM Storage Scale.
IBMMaaS360Security [IBMMaaS360Security] — This is the IBM MaaS360 Security event collector integration for Cortex XSIAM.
IBMSecurityGuardium [IBMGuardium] — Collect events from IBM Guardium Data Security Center.
IBMSecurityVerify [IBMSecurityVerify] — IBM Security Verify provides a secure and scalable solution for collecting and managing security events from IBM Security Verify, offering advanced threat detection and response capabilities for protecting identities, applications, and data.
IP-API [IP-API] — This integration will enrich IP addresses from IP-API with data about the geolocation, as well as a determination of the IP address being associated with a mobile device, hosting or proxy. Revers DNS is also returned.
This service is available for free (with a throttle) - or paid.
IP2LocationIO [IP2LocationIO] — IP2Location.io integration to query IP geolocation data.
IRIS DFIR [IRISDFIR] — IRIS is a collaborative platform aiming to help incident responders to share technical details during investigations. It's free and open-source.
Ignite [Flashpoint] — Use the Ignite integration to reduce business risk. Ignite allows users to ingest alerts and compromised credentials as incident alerts and executes commands such as search intelligence report, ip, url, get events, and more.
IgniteFeed [FlashpointFeed] — Flashpoint Ignite Feed Integration allows importing indicators of compromise that occur in the context of an event on the Flashpoint Ignite platform which contains finished intelligence reports data, data from illicit forums, marketplaces, chat services, blogs, paste sites, technical data, card shops, and vulnerabilities. The indicators of compromise are ingested as indicators on the Cortex XSOAR and displayed in the War Room using a command.
IgniteFeedV2 [FlashpointFeed] — Flashpoint Ignite Feed V2 Integration allows importing indicators of compromise using the V2 API that provides a more concise, context-rich response structure. It includes sightings of IOCs over time and IOC relationships, providing visibility into an IOC's evolution. The indicators of compromise are ingested into Cortex XSOAR and displayed in the War Room.
IllumioCore [Illumio] — Connects to Illumio Core APIs to perform investigative and restorative actions.
IllusiveNetworks [IllusiveNetworks] — The Illusive Attack Management API allows customers to retrieve detected incidents with a forensics timeline, attack surface insights, collect forensics on-demand, and manage a variety of operations with regard to deceptive entities, deception policies, and more.
Impartner [Impartner] — Impartner is the fastest-growing, most award-winning channel management solution provider on the market.
Imperva Skyfence [Imperva_Skyfence] — The Imperva Skyfence Cloud Gateway is a Cloud Access Security Broker (CASB) that provides visibility and control over sanctioned and unsanctioned cloud apps to enable their safe and productive use.
Imperva WAF [Imperva_WAF] — Use the Imperva WAF integration to manage IP groups and web security policies in Imperva WAF.
Incapsula [Incapsula] — Uses incapsula to manage sites and IPs.
Inception [Stairwell] — Stairwell Inception is a security intelligence engine that automates the continuous capture, storage, and of executable files and other primary security artifacts to improve detection and response against advanced attacks that evade traditional security tools.
Indeni [Indeni] — Indeni is a turn-key automated monitoring providing visibility for security infrastructure. Indeni's production-ready Knowledge is curated from vetted, community-sourced experience, to deliver automation of tedious tasks with integration with your existing processes.
Infinipoint [Infinipoint] — Use the Infinipoint integration to retrieve security and policy incompliance events, vulnerabilities or incidents. Investigate and respond to events in real-time.
InfoArmor VigilanteATI [InfoArmor_VigilanteATI] — VigilanteATI redefines Advanced Threat Intelligence. InfoArmor's VigilanteATI platform and cyber threat services act as an extension of your IT security team.
Infoblox [Infoblox] — Infoblox NIOS enables you to receive metadata about IPs in your network and manages the DNS Firewall by configuring RPZs. It defines RPZ rules to block DNS resolution for malicious or unauthorized hostnames, or redirect clients to a walled garden by substituting responses.
Infoblox BloxOne Threat Defense Event Collector [InfobloxBloxOne] — BloxOne Threat Defense is a hybrid cybersecurity solution that leverages DNS as the first line of defense to detect and block cyber threats.
InfobloxBloxOneThreatDefense [InfobloxBloxOne] — Infoblox Threat Defense with DDI integration leverages DNS as the first line of defense to detect and block cyber threats, while also using threat intelligence to manage SOC Insight incident response and enrich indicators.
InfobloxThreatIntelligenceFeed [FeedInfobloxThreatIntelligence] — The Infoblox Threat Intelligence Feed retrieves the discovered indicators from the Infoblox platform based on user-specified filters.
Infocyte [Infocyte] — Infocyte can pivot off incidents to automate triage, validate events with forensic data and enabling dynamic response actions against any or all host using both agentless or agented endpoint access.
IntSights [IntSight] — Deprecated. Use Rapid7 Threat Command instead.
Intel471 Actors Feed [FeedIntel471] — Deprecated. To be replaced by use case centric functionality. No available replacement.
Intel471 Malware Indicator Feed [FeedIntel471] — Intel471's Malware Intelligence is focused on the provisioning of a high fidelity and timely indicators feed with rich context, TTP information, and malware intelligence reports.
This feed allows customers to block and gain an understanding of the latest crimeware campaigns and is for those that value timeliness, confidence (little to no false positives), and seek rich context and insight around the attacks they are seeing.
Intel471 Watcher Alerts [FeedIntel471] — Intel 471's watcher alerts provide a mechanism by which customers can be notified in a timely manner of Intel471 content that is most relevant to them.
Intel471Credentials [FeedIntel471] — Fetches leaked credentials from the Intel471 Credentials API and produces an indicator per credential. While building each indicator the integration also creates an associated incident.
Intezer v2 [Intezer] — Malware detection and analysis based on code reuse.
Inventa [Inventa] — Use the Inventa integration to generate DSAR reports within Inventa instance and retrieve DSAR data for the XSOAR.
Ipstack [Ipstack] — One of the leading IP to geolocation
APIs and global IP database services.
IronDefense [IronDefense] — The IronDefense Integration for Cortex XSOAR allows users to interact with IronDefense alerts within Cortex XSOAR. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, to report observed bad activity, get alerts, get events, and get IronDome information.
Ironscales [Ironscales] — IRONSCALES, a self-learning email security platform integration.
Ironscales Event Collector [IronscalesEventCollector] — Use this integration to fetch email security incidents from Ironscales as XSIAM events.
IsItPhishing [IsItPhishing] — Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage.
Ivanti Heat [IvantiHeat] — Use the Ivanti Heat integration to manage issues and create Cortex XSOAR incidents from Ivanti Heat.
JARM [JARM] — Active TLS fingerprinting using JARM.
JSON Feed [FeedJSON] — Fetches indicators from a JSON feed.
JSONSampleIncidentGenerator [JSONSampleIncidentGenerator] — A utility for testing incident fetching with mock JSON data.
JWT [JWT] — JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. This Integration can be used to Generate New JWT Tokens, Encode and Decode Existing Ones.
Ja3er [Ja3er] — Query the ja3er API for MD5 hashes of JA3 fingerprints.
Jamf Protect Event Collector [JamfProtect] — Use this integration to fetch audit logs events, alerts events and computer assets from Jamf Protect to Cortex XSIAM.
Jask [Jask] — Deprecated. Use Sumo Logic Cloud SIEM instead. Freeing the analyst with autonomous decisions.
Jira V3 [Jira] — Use the Jira integration to manage issues, create Cortex XSOAR incidents from Jira projects, and mirror issues to existing issue incidents in Cortex XSOAR. The integration now supports both OnPrem, and Cloud instances.
JizoM [Jizo_M] — This integration ensures interaction with the JizoM API.
Joe Security [JoeSecurity] — Deprecated. Use Joe Security v2 instead.
JoeSecurityV2 [JoeSecurity] — Access the full set of possibilities the JoeSandbox Cloud provides via the RESTful Web API v2.
JsonWhoIs [JsonWhoIs] — Provides data enrichment for domains and IP addresses.
KOI [Koi] — KOI is an endpoint security platform that provides visibility and control over browser extensions, SaaS applications, and web-based threats.
Kafka V2 [Kafka] — Deprecated. Use the Kafka v3 integration instead. The Open source distributed streaming platform.
KafkaV3 [Kafka] — Kafka is an open source distributed streaming platform.
Kali Dog Security CertStream [CertStream] — Hunts for homograph-attacks by monitoring newly created X.509 certificates using CertStream by Kali Dog Security.
Kaspersky Security Center [KasperskySecurityCenter] — Manages endpoints and groups through the Kaspersky Security Center.
KeeperSecretsManager [KeeperSecretsManager] — Use the Keeper Secrets Manager integration to manage secrets and protect sensitive data through Keeper Vault.
KeeperSecurity [KeeperSecurity] — Use this integration to fetch audit logs from Keeper Security Admin Console as XSIAM events.
Kennav2 [Kenna] — Use the Kenna v2 integration to search and update vulnerabilities, schedule a run connector, and manage tags and attributes.
Keyfactor [Keyfactor] — Basic Keyfactor Integration that Posts CSR and Retrieves the certificates.
Kibana [CommunityElasticSearch] — This integration enables using Elastic Security for SIEM for security operations management and searching Elastic logs. This pack is to be used in combination with the Elasticsearch v2 integration.
KnowBe4 KMSAT Event Collector [KnowBe4_KMSAT] — KnowBe4_KMSAT allows you to push and pull your external data to and from the KnowBe4 console.
KnowBe4KMSAT [KnowBe4KMSAT] — Deprecated. Use KnowBe4KMSAT instead.
KnowBe4_KMSAT [KnowBe4_KMSAT] — KnowBe4 KMSAT integration allows you to pull Risk Scores, Phishing Tests, Campaigns and Enrollments.
LINENotify [LINENotify] — LINE API Integration is used for sending a message to LINE Group.
LOLBAS Feed [FeedLOLBAS] — "Living off the land binaries" is a term used to describe malware or hacking techniques that take advantage of legitimate tools and processes that are already present on a computer or network, rather than introducing new malware or malicious code. The goal is to blend in with normal activity and avoid detection. Examples of this include using built-in Windows commands to move laterally through a network, or using scripting languages that are commonly installed on a system to execute malicious code. LOLBAS project is documenting binaries, scripts, and libraries that can be used for Living Off The Land techniques.
Lacework [Lacework] — Lacework provides end-to-end cloud security automation for AWS, Azure, and GCP with a comprehensive view of risks across cloud workloads and containers.
Lansweeper [Lansweeper] — The Lansweeper integration allows users to retrieve the asset details.
LastInfoSec [Gatewatcher-LIS] — This integration allow to interact with the Gatewatcher LastInfoSec product via API.
Lastline v2 [Lastline] — Use the Lastline v2 integration to provide threat analysts and incident response teams with the advanced malware isolation and inspection environment needed to safely execute advanced malware samples, and understand their behavior.
Linkshadow [Linkshadow] — Fetch Network Anomalies data from LinkShadow and execute the remediation Actions.
Linux [Ansible_Powered_Integrations] — Agentlesss Linux host management over SSH. Deprecated. Use Ansible Linux (in the Ansible Linux pack) instead.
Lockpath KeyLight v2 [Lokpath_Keylight] — Use the LockPath KeyLight integration to manage GRC tickets in the Keylight platform.
LogPoint SIEM Integration [LogPoint_SIEM_Integration] — Use this Content Pack to search logs, fetch incident logs from LogPoint, analyze them for underlying threats, and respond to these threats in real-time.
LogRhythm [LogRhythm] — Deprecated. Use the LogRhythmRest v2 integration instead.
Looker [Looker] — Use the Looker integration to query an explore, save queries as looks, run looks, and fetch look results as incidents.
LookoutMobileEndpointSecurity [LookoutMobileEndpointSecurity] — Lookout Mobile Endpoint Security (MES) provides visibility and protection against mobile threats with AI-driven mobile security dataset.
Luminar_IOCs_and_leaked_credentials [FeedCognyteLuminar] — This connector allows integration of intelligence-based IOC data and customer-related leaked records identified by Luminar.
Luminate [Luminate] — Deprecated. No available replacement. Enrich your report and Respond to incidents with Luminate
Lumu [Lumu] — SecOps operations - Reflect and manage the Lumu Incidents either from XSOAR Cortex or viceversa using the mirroring integration flow, https://lumu.io/
MAC Vendors [MacVendors] — Query MAC Vendors for vendor names when providing a MAC address.
MAC Vendors maintains a list of vendors provided directly from the IEEE Standards Association and is updated multiple times each day. The IEEE is the registration authority and provides data on over 16,500 registered vendors.
MITRE ATT&CK v2 [FeedMitreAttackv2] — Use the MITRE ATT&CK® feed to fetch MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) content. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.
MS-ISAC [MS-ISAC] — This API queries alerts and alert data from the MS-ISAC API to enrich and query alerts from the platform.
MagnetAutomate [MagnetForensics] — Magnet Automate is an orchestration and automation platform that accelerates your digital forensics investigations by automating workflows and integrating with various forensic tools.
Mail Listener v2 [MailListener] — Listens to a mailbox and enables incident triggering via e-mail.
Mail Sender (New) [MailSenderNew] — Send emails implemented in Python with embedded image support.
MailListener - POP3 [MailListener_-_POP3] — Listen to a mailbox, enable incident triggering via e-mail.
Majestic Million [FeedMajesticMillion] — Free search and download of the top million websites.
Maltiverse [Maltiverse] — Use the Maltiverse integration to analyze suspicious hashes, URLs, domains and IP addresses.
MalwareBazaar [MalwareBazaar] — MalwareBazaar is a project from abuse.ch with the goal of sharing malware samples with the Infosec community, AV vendors, and threat intelligence providers.
MalwareBazaar Feed [FeedMalwareBazaar] — Use the MalwareBazaar Feed integration to get the list of malware samples added to MalwareBazaar within the last 60 minutes.
Malwarebytes [Malwarebytes] — Scan and Remediate threats on endpoints in the Malwarebytes cloud.
MalwationAIMA [MalwationAIMA] — Deprecated. Use ThreatZone instead.
ManageEngine [ManageEngine] — ManageEngine Endpoint Central is a Unified Endpoint Management solution that helps in managing thousands of servers, desktops, laptops and mobile devices from a single console..
ManageEngine PAM360 [ManageEngine_PAM360] — Integration to fetch passwords from the PAM360 repository, and to manage accounts, resources, and privileged credentials.
Mandiant [MandiantAdvantageThreatIntelligence] — Enrich Indicators of Compromise, and fetch information about Actors, Malware Families, and Campaigns from Mandiant Advantage.
Mandiant Advantage Threat Intelligence [MandiantAdvantageThreatIntelligence] — Enrich Indicators of Compromise, and fetch information about Actors, Malware Families, and Campaigns from Mandiant Advantage.
Mantis [Mantis] — create and update issues in MantisBT,MantisBT is a popular free web-based bug tracking system.
MattermostV2 [Mattermost] — Mattermost is an open-source, self-hostable online chat service with file sharing, search, and integrations. It is designed as an internal chat for organizations and companies.
MaxMind GeoIP2 [MaxMind_GeoIP2] — Enriches IP addresses.
McAfee ESM v2 [McAfee_ESM] — This integration runs queries and receives alarms from McAfee Enterprise Security Manager (ESM). Supports version 10 and above.
McAfee ESM-v10 [McAfee_ESM-v10] — Deprecated. Use the McAfee ESM v2 integration instead.
McAfeeNSMv2 [McAfeeNSM] — McAfee Network Security Manager gives you real-time visibility and control over all McAfee intrusion prevention systems deployed across your network.
Menlo Security [MenloSecurity] — Collects web, email, audit, SMTP, attachment, DLP, HEAT, firewall, bandwidth, auth flows, and Menlo Security Client logs from the Menlo Security Isolation Platform (MSIP).
MetaDefender Aether [OPSWAT-MetaDefender-Aether] — Next-generation unified Zero-Day detection solution, combining Threat Reputation, Dynamic Analysis, Threat Scoring, and Threat Hunting into a single adaptive detection pipeline (previously known as MetaDefender Sandbox).
MetaDefender Sandbox [OPSWAT-MetaDefender-Sandbox] — Deprecated. Use MetaDefender Aether instead.
MicroFocusSMAX [MicroFocusSMAX] — Fetch SMAX cases and automate differen SMAX case management actions.
Microsoft 365 Defender [Microsoft365Defender] — Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
Microsoft Defender Advanced Threat Protection [MicrosoftDefenderAdvancedThreatProtection] — Microsoft Defender for Endpoint (previously Microsoft Defender Advanced Threat Protection (ATP)) is a unified platform for preventative protection, post-breach detection, automated investigation, and response.
Microsoft Endpoint Configuration Manager [MicrosoftECM] — The Microsoft Endpoint Configuration Manager provides the overall Configuration Management (CM) infrastructure and environment to the product development team (formerly known as SCCM).
Microsoft Graph [MicrosoftGraphSecurity] — Unified gateway to security insights - all from a unified Microsoft Graph Security API.
Microsoft Graph API [MicrosoftGraphAPI] — Use the Microsoft Graph API integration to interact with Microsoft APIs that do not have dedicated integrations in Cortex XSOAR, for example, Mail Single-User, etc.
Microsoft Graph Calendar [MicrosoftGraphCalendar] — O365 Outlook Calendar enables you to create and manage different calendars and events according to your requirements.
Microsoft Graph Device Management [MicrosoftGraphDeviceManagement] — Microsoft Intune is a Microsoft cloud-based management solution that provides for mobile device and operating system management.
Microsoft Graph Groups [MicrosoftGraphGroups] — Entra ID Groups integration (formely Azure Active Directory Groups) enables you to create and manage different types of groups and group functionality according to your requirements.
Microsoft Graph Mail Single User [MicrosoftGraphMail] — Microsoft Graph grants Cortex XSOAR authorized access to a user's Microsoft Outlook mail data in a personal account or organization account.
Microsoft Graph Search [MicrosoftGraphSearch] — Use the Microsoft Search API in Microsoft Graph to search content stored in OneDrive or SharePoint: files, folders, lists, list items, or sites.
Microsoft Graph User [MicrosoftGraphUser] — The Entra ID Users integration (formerly Azure Active Directory Users) is a Unified gateway to security insights - all from a unified Microsoft Graph User API.
Microsoft Intune Feed [FeedMicrosoftIntune] — Use the Microsoft Intune Feed integration to get indicators from the feed.
Microsoft Management Activity API (O365 Azure Events) [MicrosoftManagementActivity] — The Microsoft Management Activity API integration enables you to subscribe or unsubscribe to different audits, receive their content, and fetch new content as incidents.
Microsoft Teams [MicrosoftTeams] — Send messages and notifications to your team members.
Microsoft Teams via Webhook [MicrosoftTeams] — Integration for sending notifications to a Microsoft Teams channel via a workflow of type `Post to a channel when a webhook request is received`.
MicrosoftCloudAppSecurity [MicrosoftCloudAppSecurity] — Microsoft Cloud App Security is a multimode Cloud Access Security Broker (CASB). It provides rich visibility, control over data travel, and sophisticated analytics to identify and combat cyber threats across all your cloud services. Use the integration to view and resolve alerts, view activities, view files, and view user accounts.
MicrosoftDefenderThreatIntelligence [MicrosoftDefenderThreatIntelligence] — Use the Microsoft Defender Threat Intelligence integration to query enriched threat intelligence data such as articles, threat actor profiles, WHOIS records, and host-related infrastructure.
MicrosoftGraphApplications [MicrosoftGraphApplications] — Use the Entra ID Applications integration (formerly Azure Active Directory Applications) to manage authorized applications.
MicrosoftGraphFilesStandardConnector [MicrosoftGraphFilesStandardConnector] — This integration is configured automatically as part of the O365 File Management (Onedrive/Sharepoint/Teams) Standard Connector. Do not configure this integration directly — set it up from the connector page instead.
MicrosoftGraphIdentityandAccess [MicrosoftGraphIdentityandAccess] — Use the Entra ID Identity And Access integration to manage roles and members (formerly Azure Active Directory Identity And Access).
MicrosoftGraphMail [MicrosoftGraphMail] — Microsoft Graph lets your app get authorized access to a user's Outlook mail data in a personal or organization account.
MicrosoftGraphTeams [MicrosoftGraphTeams] — Microsoft Graph lets your app get authorized access to a user's Teams app in a personal or organization account.
MicrosoftGraphTeamsStandardConnector [MicrosoftGraphTeamsStandardConnector] — This integration is configured automatically as part of the Microsoft 365 Standard Connector. Do not configure this integration directly — set it up from the connector page instead.
MicrosoftWindows [Ansible_Powered_Integrations] — Agentless Windows host management over WinRM. Deprecated. Use Ansible Microsoft Windows (from the Ansible Microsoft Windows pack) instead.
Microsoft_Graph_Files [MicrosoftGraphFiles] — Use the O365 File Management (Onedrive/Sharepoint/Teams) integration to enable your app to get authorized access to files in OneDrive, SharePoint, and MS Teams across your entire organization. This integration requires admin consent.
Mimecast Event Collector v2 [Mimecast] — Use the Mimecast Event Collector v2 integration to fetch Audit events and SIEM logs for various SIEM event types, using API 2.0 with OAuth2 authentication.
MimecastV2 [Mimecast] — Use the Mimecast integration to manage email security, continuity, and archiving services.
MinIO [DevSecOps] — An Integration with MinIO Object Storage.
Minerva Labs Anti-Evasion Platform [MinervaLabsAntiEvasionPlatform] — Minerva eliminates the endpoint security gap while empowering companies to embrace technology fearlessly.
MitreCaldera [MitreCaldera] — Mitre Caldera can be used to test endpoint security solutions and assess a network's security posture against the common post-compromise adversarial techniques contained in the ATT&CK model. CALDERA leverages the ATT&CK model to identify and replicate adversary behaviors as if a real intrusion is occurring.
Ncurion [Ncurion] — This is the Ncurion integration for getting started.
Neosec [Neosec] — Neosec is reinventing application security. Its pioneering SaaS platform gives security professionals visibility into behavior across their entire API estate. Built for organizations that expose APIs to partners, suppliers, and users, Neosec discovers all your APIs, analyzes their behavior, and stops threats lurking inside.
Nessus [nessus] — Vulnerability scanner for auditors and security analysts by Tenable Network Security.
NetQuestOMX [NetQuestOMX] — NetQuest’s products are high-capacity service nodes that help security teams access and analyze network traffic. Powerful packet and flow processing features assist security tools in detecting and mitigating security threats as cost effectively as possible.
Netcraft [Netcraft] — Deprecated. Use Netcraft_V2 (Display name: Netcraft) instead.
Netcraft V2 [Netcraft_V2] — Netcraft takedown, submission and screenshot management.
Netmiko [Netmiko] — Multi-vendor library to simplify SSH connections to network devices. Utilizes the Python library Netmiko for connections. Supports SSH Key authentication and username / password.
NetscoutAED [NetscoutAED] — Use the Netscout Arbor Edge Defense integration to detect and stop both inbound threats and outbound malicious communication from compromised internal devices.
NetscoutArborSightline [NetscoutArborSightline] — DDoS protection and network visibility.
Netskope [Netskope] — Cloud access security broker that enables to find, understand, and secure cloud apps. Deprecated. Use Netskope (API v1) instead.
Nexthink [Nexthink] — Nexthink helps IT teams deliver on the promise of the modern digital workplace. Nexthink is the only solution to provide enterprises with a way to visualize, act and engage across the entire IT ecosystem to lower IT cost and improve digital employee experience.
Nist NVD [NistNVD] — National Vulnerability Database.
NodeZero [NodeZero] — Integrates with the NodeZero autonomous penetration testing platform to fetch weaknesses discovered during pentest operations. Automatically ingests HIGH and CRITICAL severity weaknesses as incidents for tracking and remediation.
Nozomi Networks [NozomiNetworks] — The Nozomi Networks platform, available as a hardware, virtual appliance, or via the Vantage Cloud product, provides comprehensive monitoring for OT, IoT, and IT networks. It combines asset discovery, network visualization, vulnerability assessment, risk monitoring, and advanced threat detection in a unified solution. The integration is designed to gather alerts and asset information from Nozomi, whether deployed on-premises or in the cloud via Vantage, ensuring seamless visibility and security across environments.
NucleonCyberFeed [NucleonCyber] — This is the NucleonCyber Feed integration.
Nutanix Hypervisor [NutanixHypervisor] — Nutanix Hypervisor abstracts and isolates the VMs and their programs from the underlying server hardware, enabling a more efficient use of physical resources, simpler maintenance and operations, and reduced costs.
O365 Defender SafeLinks [Microsoft365Defender] — Provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages and other locations.
O365 Defender SafeLinks - Single User [Microsoft365Defender] — Deprecated. Use O365 Defender SafeLinks instead. Enables URL scanning, rewriting inbound email messages in the mail flow, time-of-click URL verification, and links in email messages and other locations.
O365 Message Trace [MicrosoftExchangeOnline] — Message Trace enables tenant administrators to track the lifecycle of an email, determine its delivery status (delivered, pending, failed, or quarantined), and understand the actions applied to it.
OHMYVT_CTF [ctf01] — Analyzes suspicious hashes, URLs, domains, and IP addresses.
OPNSense [OPNSense] — Manage OPNsense Firewall.
For more information see OPNsense documentation.
OPNsense is an open source, easy-to-use and easy-to-build HardenedBSD based firewall and routing platform.
OPSWAT Filescan [OPSWAT-Filescan] — Deprecated. Use MetaDefender Sandbox instead.
OPSWAT-Metadefender V2 [opswat-metadefender] — multi-scanning engine uses 30+ anti-malware engines to scan files for threats, significantly increasing malware detection.
OSV [OpenSourceVulnerabilities] — OSV (Open Source Vulnerability) is a vulnerability database for open source projects. For each vulnerability, it perform bisects to figure out the exact commit that introduces the bug, as well the exact commit that fixes it. This is cross referenced against upstream repositories to figure out the affected tags and commit ranges.
OTRS [OTRS] — Service management suite that comprises ticketing, workflow automation, and notification.
Office 365 Feed [FeedOffice365] — The Office 365 IP Address and URL web service is a read-only API provided by Microsoft to expose the URLs and IPs used by Office 365. The Office 365 Feed integration fetches indicators from the service, with which you can create a list (allow list, block list, EDL, etc.) for your SIEM or firewall service to ingest and apply to its policy rules.
Okta Event Collector [Okta] — Collects the events log for authentication and Audit provided by Okta admin API.
Okta IAM [Okta] — Integrate with Okta's Identity Access Management service to execute CRUD operations to employee lifecycle processes.
OktaASA [OktaASA] — Okta Advanced Server Access integration for Cortex XSIAM allows you to fetch logs of a wide range of configuration, enrollment, authentication, and authorization events that occur within the product and on your servers.
Ollama [Ollama] — Integrate with open source LLMs using Ollama. With an instance of Ollama running locally you can use this integration to have a conversation in an Incident, download models, and create new models.
OnboardingIntegration [OnboardingIntegration] — Creates mock email incidents using one of two randomly selected HTML templates. Textual content is randomly generated and defined to include some text (100 random words) and the following data (at least 5 of each data type): IP addresses, URLs, SHA-1 hashes, SHA-256 hashes, MD5 hashes, email addresses, domain names.
OnePassword [OnePassword] — Fetch events about actions performed by 1Password users within a specific account, access and modifications to items in shared vaults, and user sign-in attempts.
OpenAI [OpenAI] — Deprecated. Use `OpenAI GPT` instead.
OpenAi ChatGPT v3 [OpenAI] — This integration assists security professionals with security investigations, threat hunting, and anomaly detection by leveraging OpenAI GPT models' natural language conversation capabilities.
OpenCTI [OpenCTI] — Manages OpenCTI platform. Compatible with OpenCTI 4.X API and OpenCTI 5.X API versions.
OpenCTI Feed [FeedOpenCTI] — Deprecated. Use OpenCTI Feed 4.X instead.
OpenCTI Feed 4.X [FeedOpenCTI] — Ingest indicators from the OpenCTI feed. Compatible with OpenCTI 5.12.17 and above.
OpenCVE [OpenCVE] — Searches for CVE information using OpenCVE.
OpenLDAP [OpenLDAP] — Authenticate using OpenLDAP or Active Directory.
OpenPhish [OpenPhish] — Deprecated. Use the OpenPhish v2 integration instead.
OpenPhish_v2 [OpenPhish] — OpenPhish uses proprietary Artificial Intelligence algorithms to automatically identify zero-day phishing sites and provide comprehensive, actionable, real-time threat intelligence.
OpenSSL [Ansible_Powered_Integrations] — Control OpenSSL on a remote Linux hosts. Deprecated. Use Ansible OpenSSL (in the Ansible Linux pack) instead.
OpsGenie [OpsGenie] — Deprecated. Use the OpsGenie v3 integration instead
OpsGenieV3 [OpsGenie] — Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner.
Opsgeniev2 [Opsgeniev2] — Deprecated. Use the OpsGenieV3 integration instead.
Oracle Cloud Infrastructure Feed [OracleCloudInfrastructureFeed] — Oracle Cloud Infrastructure Feed (OCI Feed)
This feed provides information about public IP address ranges for services that are deployed in Oracle Cloud Infrastructure.
OrionMalware [OrionMalware] — This is the Orion Malware integration. Analyzes hash and files with static and dynamic analysis.
PAN-OS Policy Optimizer [PANOSPolicyOptimizer] — Automate your AppID Adoption by using this integration together with your Palo Alto Networks Next-Generation Firewall or Panorama.
PATHelpdeskAdvanced [PATHelpdeskAdvanced] — Improve the effectiveness of your service provision and resources, and the quality of your IT department.
PICUS [PICUS] — Deprecated. Use PicusAutomation instead.
Palo Alto Networks AIOps [PaloAltoNetworksAIOps] — Palo Alto Networks Best Practice Assessment (BPA) analyzes NGFW and Panorama configurations and compares them to the best practices.
Palo Alto Networks Cortex [DeprecatedContent] — Deprecated. We recommend using the Cortex Data Lake integration instead. This framework manages all PA's cloud managed products
Palo Alto Networks Device Security [PaloAltoNetworks_DeviceSecurity] — Use the Palo Alto Networks Device Security integration to fetch alerts and vulnerabilities, retrieve device details, and resolve security incidents (previously Zingbox).
Palo Alto Networks Enterprise DLP [Palo_Alto_Networks_Enterprise_DLP] — Palo Alto Networks Enterprise DLP discovers and protects company data across every data channel and repository. Integrated Enterprise DLP enables data protection and compliance everywhere without complexity.
Palo Alto Networks IoT [PaloAltoNetworks_IoT] — This is the Palo Alto Networks IoT integration (previously Zingbox).
Palo Alto Networks IoT 3rd Party [PaloAltoNetworks_IoT3rdParty] — Deprecated. Use the following link instead. To get the latest Palo Alto Networks IoT 3rd Party Integrations content pack, visit: https://docs.paloaltonetworks.com/iot/iot-security-integration/get-started-with-iot-security-integrations/third-party-integrations-using-a-full-featured-xsoar-server
Palo Alto Networks Threat Vault v2 [PaloAltoNetworks_Threat_Vault] — Use the Palo Alto Networks Threat Vault to research the latest threats (vulnerabilities/exploits, viruses, and spyware) that Palo Alto Networks next-generation firewalls can detect and prevent.
Query the Advanced Threat Protection (ATP) API endpoint for Analysis reports and PCAPs.
Palo Alto Networks Threat Vault v2 Feed [FeedThreatVault] — Retrieve Threat Vault predefined EDL content for Malicious IP, Known IP, TOR and Bulletproof hosting.
PaloAltoNetworks_PrismaCloudCompute [PrismaCloudCompute] — Use the Prisma Cloud Compute integration to fetch incidents from your Prisma Cloud Compute environment.
Panorama [PAN-OS] — Manage Palo Alto Networks Firewall and Panorama. Use this pack to manage Prisma Access through Panorama. For more information, see the Panorama documentation.
PanoraysFindingsAPI [Panorays] — Retrieve and monitor internal security findings for your organization from the Panorays platform to streamline self-assessment posture and automate internal incident response within Cortex XSOAR.
PassiveTotal [PassiveTotal] — Deprecated. Use the PassiveTotal v2 integration instead.
PassiveTotal v2 [PassiveTotal] — Analyze and understand threat infrastructure from a variety of sources-passive DNS, active DNS, WHOIS, SSL certificates and more-without devoting resources to time-intensive manual threat research and analysis.
Penfield [PenfieldAI] — The penfield-get-assignee command takes in necessary context data, and returns the analyst that Penfield believes the incident should be assigned to based on Penfield's models of skill and process. The test command verfies that the endpoint is reachable.
Pentera [Pcysys] — Automate remediation actions based on Pentera, the Automated Security Validation Platform, proactively exposing high-risk vulnerabilities.
PerceptionPoint [PerceptionPoint] — Loads incidents from Perception Point and releases falsely quarantined emails.
Perch [Perch] — Perch is a co-managed threat detection and response platform.
Perplexity AI [PerplexityAI] — Perplexity AI is a web search engine that uses a large language model to process queries and synthesize responses based on web search results. With a conversational approach, Perplexity AI allows users to ask follow-up questions and receive answers with citations to its sources from the internet.
Phish.AI [PhishAI] — Deprecated. Vendor has declared end of life for this integration. No available replacement.
PhishLabs IOC [PhishLabs] — Get indicators of compromise from PhishLabs.
PhishLabs IOC DRP [PhishLabs] — Retrieves Digital Risk cases Protection from PhishLabs.
PhishLabs IOC EIR [PhishLabs] — Get Email Incident Reports from PhishLabs.
PhishTank [PhishTank] — Deprecated. Use the PhishTank v2 integration instead.
PhishTank V2 [PhishTank] — PhishTank is a free community site where anyone can submit, verify, track, and share phishing data.
Phisher [knowbe4Phisher] — KnowBE4 PhishER integration allows to pull events from PhishER system and do mutations.
PiHole [PiHole] — Pi-hole is a network-level advertisement and Internet tracker blocking application which acts as a DNS sinkhole and optionally a DHCP server, intended for use on a private network.
PiHoleV6 [PiHole] — PiHole V6 integration using the new REST API. PiHole is a network-level advertisement and Internet tracker blocking application which acts as a DNS sinkhole.
Picus [PicusAutomation] — Run commands on Picus and automate security validation with playbooks.
PicusNG [PicusNGAutomation] — Picus - The Complete Security Control Validation NG Platform.
PingCastle [PingCastle] — This integration will run a server that will listen for PingCastle XML reports.
PingOne [PingIdentity] — Integrates with the PingOne Management API to unlock, create, delete and update users.
Pipl [Pipl] — Get contact, social, and professional information about people.
Plain Text Feed [FeedPlainText] — Fetches indicators from a plain text feed.
Polar Security [PolarSecurity] — Polar Security, an innovator in technology that helps companies discover, continuously monitor and secure cloud and software-as-a-service (SaaS) application data – and addresses the growing shadow data problem.
PolySwarm [PolySwarm] — Deprecated. Use PolySwarm V2 instead.
PolySwarmV2 [PolySwarm] — Real-time threat intelligence from a crowd-sourced network of security experts and antivirus companies.
Popular News [PopularCybersecurityNews] — Popular News integration fetches from three sources of news - Threatpost, The Hacker News and Krebs on Security. It outputs the title, links of the news articles and other metadata as a markdown table. The integration commands can either fetch the news from one source or all sources at a time.
Postmark Spamcheck [PostmarkSpamcheck] — Postmark's spam API, Spamcheck, is a RESTfull interface to the Spam filter tool SpamAssassin.
PowerShell Remoting [PowershellRemoting] — PowerShell Remoting is a comprehensive built-in remoting subsystem that is a part of Microsoft's native Windows management framework (WMF) and Windows remote management (WinRM).
This feature allows you to handle most remoting tasks in any configuration you might encounter by creating a remote PowerShell session to Windows hosts and executing commands in the created session.
The integration includes out-of-the-box commands which supports agentless forensics for remote hosts.
Preempt [Preempt] — Deprecated. No available replacement. Preempt Behavioral Firewall - Detection and enforcement based on user identity
Prisma Access [PrismaAccess] — Integrate with Prisma Access to monitor the status of the Service, alert and take actions.
Prisma Access Egress IP feed [PrismaAccess] — Dynamically retrieve and add to allow list IPs Prisma Access uses to egress traffic to the internet and SaaS apps.
PrismaCloud IAM [PrismaCloud] — The Prisma Cloud IAM API consists of a set of API endpoints that allow customers to perform CRUD operation on their user profiles.
PrismaCloud v2 [PrismaCloud] — Prisma Cloud secures infrastructure, workloads and applications, across the entire cloud-native technology stack.
Prometheus [Prometheus] — Query Prometheus via its HTTP API (/api/v1/query). Supports a pipe-separated metric list (e.g., "co2|solar|load") which is converted to a metric-name regex on __name__. Returns a tidy table plus machine-readable outputs under Prometheus.Metrics.
Proofpoint Cloud Threat Response [ProofpointCloudThreatResponse] — Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSOAR for case management, and exposes commands to list and retrieve incident details.
Proofpoint Server Protection [ProofpointServerProtection] — Deprecated. Use Proofpoint Protection Server V2 instead.
Proofpoint TAP v2 [ProofpointTAP] — Use the Proofpoint Targeted Attack Protection (TAP) integration to protect against and provide additional visibility into phishing and other malicious email attacks.
Proofpoint Threat Protection [ProofpointThreatProtection] — Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations.
Proofpoint Threat Response [ProofpointThreatResponse] — Use the Proofpoint Threat Response integration to orchestrate and automate incident response.
ProofpointFeed [FeedProofpoint] — Detailed feed of domains and IP addresses classified in different categories. You need a valid authorization code from Proofpoint ET to access this feed.
ProofpointIsolationEventCollector [ProofpointIsolation] — Proofpoint Isolation is an integration that supports fetching Browser and Email Isolation logs events.
ProofpointThreatResponseEventCollector [ProofpointThreatResponse] — Use the Proofpoint Threat Response integration to orchestrate and automate incident response.
ProtectWise [ProtectWise] — Cloud based Security Network DVR.
Public DNS Feed [FeedPublicDNS] — A feed of known benign IPs of public DNS servers.
Publish List [PublishList] — The Publish List integration is used to publish XSOAR lists for external consumption.
Pulsedive [Pulsedive] — Enrich and analyze any domain, URL, or IP. Pivot to search on data points and linked indicators to investigate risky properties.
QRadar [QRadar] — Deprecated. Use IBM QRadar v2 or IBM QRadar v3 instead.
QRadar v3 [QRadar] — IBM QRadar SIEM helps security teams accurately detect and prioritize threats across the enterprise, supports API versions 10.1 and above. Provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents.
QRadar_v2 [QRadar] — Deprecated. Use the IBM QRadar v3 integration instead. Fetch offenses from QRadar using Cortex XSOAR. Supports API versions until 10.0. You can fetch the offenses with their related events and assets by creating a comma-separated list of event fields.
QSS [QSS] — QSS integration helps you to fetch Cases from Q-SCMP and add new cases automatically through XSOAR.
QintelPMI [Qintel] — Qintel’s Patch Management Intelligence (PMI) product simplifies the vulnerability management process by providing vital context around reported Common Vulnerabilities and Exposures. With this integration, users can query PMI to surface CVEs that are known by Qintel to be leveraged by eCrime and Nation State adversaries.
QintelQSentry [Qintel] — QSentry queries help measure the likelihood that a user is masking their identity using publicly or privately available proxy or VPN services. The returns also flag any known fraud associations. QSentry aggregates data from Qintel’s proprietary Deep and DarkWeb research, as well as from commercially available anonymization services.
QintelQWatch [Qintel] — Qintel's QWatch system contains credentials obtained from dump sites, hacker collaboratives, and command and control infrastructures of eCrime- and APT-related malware. With this integration, users can fetch exposure alerts as incidents and discover exposed credentials associated with their organization.
Qualys [qualys] — Deprecated. Use Qualys VMDR instead.
QualysV2 [qualys] — Qualys Vulnerability Management lets you create, run, manage reports and to fetch Activity Logs, Assets and Vulnerabilities, launch and manage vulnerability and compliance scans, and manage the host assets you want to scan for vulnerabilities and compliance.
Query.AI [QueryAI] — Query.AI is a decentralized data access and analysis technology that simplifies security investigations across disparate platforms without data duplication.
QuestKace [QuestKace] — Use the Comprehensive Quest KACE solution to Provision, manage, secure, and service all network-connected devices.
RDAP [RDAP] — Use the RDAP integration to query domain and IP information.
RSA Archer [ArcherRSA] — Deprecated. Use the RSA Archer v2 integration instead.
RSA Archer v2 [ArcherRSA] — The RSA Archer GRC platform provides a common foundation for managing policies, controls, risks, assessments, and deficiencies across lines of business.
RSA NetWitness Endpoint [RSANetWitnessEndpoint] — RSA NetWitness Endpoint provides deep visibility beyond basic endpoint security solutions by monitoring and collecting activity across all of your endpoints on and off your network. The RSA Demisto integration provides access to information about endpoints, modules and indicators.
RSA NetWitness Packets and Logs [RsaNetWitnessPacketsAndLogs] — RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.
RSA NetWitness Security Analytics [RsaNetwitnessSecurityAnalytics] — RSA Security Analytics, compatible with prior to v11. A distributed and modular system that enables highly flexible deployment architectures that scale with the needs of the organization. Security Analytics allows administrators to collect two types of data from the network infrastructure, packet data and log data.
RSANetWitnessv115 [RSANetWitness_v11_1] — The RSA NetWitness integration provides system log, network, and endpoint visibility for real-time collection, detection, and automated response with the Cortex XSOAR Enterprise platform. Using full session analysis, customers can extract critical data and effectively run security operations automated playbooks.
RTIR [RTIR] — Request Tracker for Incident Response is a ticketing system which provides pre-configured queues and workflows designed for incident response teams.
RaDark [KELARaDark] — This integration enables you to fetch incidents and manage your RaDark monitor from Cortex XSOAR.
Radware Cloud DDoS Protection Services [RadwareCloudDDoSProtectionServices] — Radware Cloud Service provides customers and partners with the ability to programmatically perform service-related actions. The integration can be used to automate application and assets creation and day-to-day management to retrieve up-to-date data about Security Events and Operational Alerts.
Rapid7 InsightIDR [Rapid7_InsightIDR] — Rapid7’s InsightIDR is your security center for incident detection and response, authentication monitoring, and endpoint visibility. Together, these form Extended Detection and Response (XDR). InsightIDR identifies unauthorized access from external and internal threats and highlights suspicious activity so you don’t have to weed through thousands of data streams.
Rapid7 InsightVM Cloud [Rapid7InsightVMCloud] — InsightVM is a vulnerability management tool that can scan your network, eliminate vulnerabilities, and track and communicate its progress.
Rapid7 Nexpose [Rapid7_Nexpose] — Vulnerability management solution to help reduce threat exposure.
Rasterize [rasterize] — Converts URLs, PDF files, and emails to an image file or PDF file.
Reco [Reco] — Reco is the leader in SaaS & AI Security, providing full visibility and control across your SaaS ecosystem and AI agents.
Recorded Future [Recorded_Future] — Deprecated. Use Recorded Future v2 from RecordedFuture pack instead. Unique threat intel technology that automatically serves up relevant insights in real time.
Recorded Future Feed [FeedRecordedFuture] — Ingests indicators from Recorded Future feeds into Demisto.
Recorded Future Identity [IdentityRecordedFuture] — Fetch & triage | Search & Lookup | Access Recorded Future Identity data and Playbook Alerts.
Recorded Future v2 [RecordedFuture] — Unique threat intel technology that automatically serves up relevant insights in real time.
RecordedFutureASI [RecordedFutureASI] — Attack Surface Intelligence Risk Rules help security teams take risk and vulnerability prioritization to the next level by helping organizations identify the biggest weaknesses within their attack surface in mere seconds.
RecordedFutureAlerts [RecordedFutureV3] — Fetch and triage alerts from Recorded Future.
RecordedFutureLists [RecordedFuture] — Search and manage watchlists in Recorded Future.
RecordedFuturePlaybookAlerts [RecordedFuture] — Deprecated. Use "Recorded Future Alerts" from "Recorded Future" pack instead.
RedCanary [RedCanary] — Red Canary collects endpoint data using Carbon Black Response and CrowdStrike Falcon. The collected data is standardized into a common schema which allows teams to detect, analyze and respond to security incidents.
RedLock [PrismaCloud] — Deprecated. Use the Prisma Cloud v2 integration instead.
Redmine [Redmine] — A project management and issue tracking system that provides a web-based platform for managing projects, tracking tasks, and handling various types of project-related activities.
ReliaQuest GreyMatter DRP Event Collector [DigitalShadows] — ReliaQuest GreyMatter DRP Event Collector monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web.
ReliaQuest GreyMatter DRP Incidents [DigitalShadows] — ReliaQuest GreyMatter DR monitors and manages an organization's digital risk across the widest range of data sources within the open, deep, and dark web.
ReliaquestTakedown [DigitalShadows] — This is Reliaquest DRP Takedown integration. It enables xsoar user to create and manage takedowns.
Remedy AR [Remedy_AR] — BMC Remedy AR System is a professional development environment that leverages the recommendations of the IT Infrastructure Library (ITIL) and provides a foundation for Business Service Management (BSM) solutions. For incident management (i.e. create, fetch, update), please refer to Remedy On-Demand integration.
Remedy On-Demand [Remedy-On-Demand] — Deprecated. Use BMC Helix ITSM instead.
RemoteAccess v2 [RemoteAccess] — This integration transfers files between Cortex XSOAR and a remote machine and executes commands on the remote machine.
ResecurityMonitoring [Resecurity] — This package allows retrieving asset monitoring results from monitoring tasks that can be configured in Context and Risk platforms.
Respond_Analyst [Respond] — Use the Mandiant Automated Defense integration to fetch and update incidents from Mandiant Automated Defense. Mandiant Automated Defense fetches open incidents and updates them every minute. Changes made within XSOAR are reflected in Mandiant Automated Defense platform with bi-directional mirroring capabilities enabled.
Retarus Secure Email Gateway [RetarusSecureEmailGateway] — Integrate Retarus Secure Email Gateway to seamlessly fetch events from Secure Email Gateway by Retarus and enhance email security.
ReversingLabs A1000 [ReversingLabs_A1000] — Deprecated. Use the ReversingLabs A1000 v2 integration instead.
ReversingLabs Ransomware and Related Tools Feed [FeedReversingLabsRansomwareAndRelatedToolsApp] — Deprecated. Use TAXII 2 Feed to connect to the ReversingLabs Ransomware and Related Tools TAXII Feed.
ReversingLabs Titanium Cloud [ReversingLabs_Titanium_Cloud] — Deprecated. Use the ReversingLabs TitaniumCloud v2 integration instead.
ReversingLabs TitaniumCloud v2 [ReversingLabs_Titanium_Cloud] — ReversingLabs TitaniumCloud provides threat analysis data from various ReversingLabs cloud services.
RiskIQDigitalFootprint [RiskIQDigitalFootprint] — The RiskIQ Digital Footprint integration enables your security team to manage assets outside your firewall. Using the integration, you can view asset details, add or update assets and analyze your digital footprint from the adversary's perspective.
RiskSense [RiskSense] — RiskSense is a cloud-based platform that provides vulnerability management and prioritization to measure and control cybersecurity risk.
Roksit DNS Security [RoksitDNSSecurity] — This integration provides adding selected domains to the Roksit Secure DNS's Blacklisted Domain List through API .
RubrikPolaris [RubrikPolaris] — The Rubrik Security Cloud integration will fetch the Rubrik Anomaly Event and is rich with commands to perform the on-demand scans, backups, recoveries and many more features to manage and protect the organizational data.
RunZero [RunZero] — RunZero is a network discovery and asset inventory
platform that uncovers every network in use and identifies every device connected – without credentials.
Scan your network and build your asset inventory in minutes.
RunZero Event Collector [RunZero] — This is the RunZero event collector integration for XSIAM.
Rundeck [Rundeck] — Rundeck is a runbook automation for incident management, business continuity, and self-service operations. |- The integration enables you to install software on a list of machines or perform a task periodically. Can be used when there is a new attack and you want to perform an update of the software to block the attack.
SAP-IAM [SAP_IAM] — Integrate with SAP's services to execute CRUD operations for employee lifecycle processes.
SAPBTP [SAP_BTP] — SAP Business Technology Platform (BTP) is a cloud platform for building, integrating, and extending enterprise applications with data, analytics, AI, and automation.
SAPCloudForCustomerC4C [SAPCloudForCustomerC4C] — Integrates with SAP Cloud for Customer (C4C) and collects audit events via its OData Analytics API to boost security monitoring and compliance.
SCADAfence CNM [SCADAfence_CNM] — fetching data from CNM.
SEKOIAIntelligenceCenter [SEKOIAIntelligenceCenter] — Fetch Indicator and Observables from SEKOIA.IO Intelligence Center.
To use this integration, please create an API Key with the right permissions.
SIGNL4 [SIGNL4] — SIGNL4 offers critical alerting, incident response and service dispatching for operating critical infrastructure. It alerts you persistently via app push, SMS text, voice calls, and email including tracking, escalation, on-call duty scheduling and collaboration.
SMIME Messaging [SMIME_Messaging] — Use the S/MIME (Secure Multipurpose Internet Mail Extensions) integration to send and receive secure MIME data.
SNDBOX [SNDBOX] — Deprecated. No available replacement.
SOCFWPackManager [SocFrameworkManager] — Downloads a SOC Framework content pack from a ZIP URL and installs it on the tenant as system content. Used internally by the SOCFWPackManager script — end users invoke the script, not this integration directly.
SOCRadar Takedown [SOCRadarTakedown] — Submit and track takedown requests for phishing domains, social media impersonation, source code leaks, and rogue mobile apps through SOCRadar platform.
SOCRadarIncidents [SOCRadar] — Fetches SOCRadar incidents with desired parameters so that relevant actions over the incidents can be taken by using Cortex XSOAR.
SOCRadarIncidentsMultiTenant [SOCRadar] — SOCRadar Multi-Tenant Incidents integration with advanced incident management, status reasons, and compliance tracking. Fetches security incidents from SOCRadar platform across all tenant companies with proper deduplication and date handling. Uses Multi-Tenant API for incident fetching and company-specific APIs for alarm management.
SOCRadarIncidentsV4 [SOCRadar] — SOCRadar Incidents v4 API integration with advanced incident management, status reasons, and compliance tracking. Fetches security incidents from SOCRadar platform with proper deduplication and date handling. Supports filtering by alarm type IDs for granular control.
SOCRadarIoCEnrichment [SOCRadar] — Enrich indicators with deep threat intelligence using SOCRadar IoC Enrichment API. Get categorization, signal strength, confidence levels, and historical data.
SOCRadarRapidReputation [SOCRadar] — Enrich indicators (IP, Domain, URL, Hash) by obtaining reputation information via SOCRadar Rapid Reputation API.
SOCRadarThreatFusion [SOCRadar] — Enrich indicators by obtaining enhanced information and reputation via ThreatFusion of SOCRadar.
SaasSecurity [PrismaSaasSecurity] — SaaS Security API is a cloud-based service that you can connect directly to your sanctioned SaaS applications using the cloud app’s API to provide data classification, sharing and permission visibility, and threat detection. This Content Pack provides insights into risks posed by data exposure and policy violations and enables you to use Cortex XSOAR to effectively manage the incidents discovered by SaaS Security API.
SafeBreach v2 [SafeBreach] — Deprecated. No available replacement.
SafeNet Trusted Access [SafeNet_Trusted_Access] — This integration enables you to process alerts from SafeNet Trusted Access (STA) indicating security risks to end user accounts, and apply security remediation actions on SafeNet Trusted Access through security orchestration playbooks.
SafeNetTrustedAccessEventCollector [SafeNet_Trusted_Access] — Retrieve access, authentication, and audit logs and store them on a Security Information and Event Management (SIEM) system, local repository, or syslog file server. You can retrieve the logs only for the tenant that is associated with the API key, or for a direct or delegated child of that tenant.
Safebreach [SafeBreach] — For enterprises using SafeBreach and XSOAR, integrating this package streamlines operations by allowing you to operate SafeBreach through XSOAR, making SafeBreach an integral part of the enterprise workflows. This integration includes commands for managing tests, insight indicators, simulators and deployments, users, API keys, integration issues, and more.
SailPointIdentityIQ [SailPointIdentityIQ] — SailPoint IdentityIQ context pack enables XSOAR customers to utilize the deep, enriched contextual data in the SailPoint predictive identity platform to better drive identity-aware security practices.
SailPointIdentityNow [SailPointIdentityNow] — The SailPoint Identity Security platform can be configured either on-prem/single tenant SaaS, or multi-tenant. This package is intended to be used with the SaaS, multi-tenant solution, IdentityNow.
SailPointIdentityNowEventCollector [SailPointIdentityNow] — This is the SailPoint IdentityNow event collector integration for Cortex XSIAM.
Salesforce Fusion IAM [SalesforceFusion] — Integrate with Salesforce Fusion Identity Access Management service to execute CRUD (create, read, update, and delete) operations for employee lifecycle processes.
Salesforce IAM [Salesforce] — Integrate with Salesforce's services to perform Identity Lifecycle Management operations.
Salesforce Indicators [SalesforceIndicators] — Pull any Salesforce Object as an indicator.
SaviyntEICEventCollector [SaviyntEIC] — Collector for Saviynt Enterprise Identity Cloud (EIC) audit logs using Analytics Runtime Control V2.
Screenshot Machine [ScreenshotMachine] — Uses screenshot machine to get a screenshot.
SecBI [SecBI] — A threat, intelligence, and investigation platform, enabled by automation of detection and investigation, including remediation and prevention policy enforcements on all integrated appliances.
Secneurx Threat Feeds [SecneurXThreatFeeds] — SecneurX provides real-time threat intelligence that protects companies against the latest cyber threats, including APTs, phishing, malware, ransomware, data exfiltration, and brand infringement. Security teams rely on our dependable and rich data to expand their threat landscape visibility, resulting in improved detection rates and response times.
SecurityAdvisor [SecurityAdvisor] — Deprecated. No available replacement.
SecurityAndCompliance [MicrosoftExchangeOnline] — This integration allows you to manage and interact with Microsoft security and compliance content search.
SecurityAndComplianceV2 [MicrosoftExchangeOnline] — Deprecated. Use the Microsoft Graph Security integration instead. This integration allows you to manage and interact with Microsoft security and compliance content search.
SecurityIntelligenceServicesFeed [SecurityIntelligenceServicesFeed] — A PassiveTotal with Security Intelligence Services Feed provides you with newly observed Domain, Malware, Phishing, Content and Scam Blacklist with Hourly ingestion available.
SecurityScorecard [SecurityScorecard] — Provides scorecards for domains.
SecurityScorecardEventCollector [SecurityScorecard] — This integration collects history events from SecurityScorecard for Cortex XSIAM.
SecurityTrails [SecurityTrails] — This integration provides API access to the SecurityTrails platform.
Securonix [Securonix] — Use the Securonix integration to manage incidents, threats, lookup tables, whitelists and watchlists.
Sekoia XDR [SekoiaXDR] — Fetch alerts and events from SEKOIA.IO XDR.\nTo use this integration, please create an API Key with the appropriate permissions.
SendGrid [SendGrid] — SendGrid provides a cloud-based service that assists businesses with email delivery. It allows companies to track email opens, unsubscribes, bounces, and spam reports. Our SendGrid pack utilize these SendGrid use cases to help you send and manage your emails.
SentinelOne [SentinelOne] — Deprecated. Use the SentinelOne v2 integration instead.
SentinelOne V2 [SentinelOne] — Use the SentinelOne integration to send requests to your management server and get responses with data pulled from agents or from the management database.
SentinelOneEventCollector [SentinelOne] — This integration fetches activities, threats, and alerts from SentinelOne.
Sepio [Sepio] — Get Agent, Switches and Events from your Sepio Prime.
Server Message Block (SMB) [SMB] — Deprecated. Use the Server Message Block (SMB) v2 integration instead.
Server Message Block (SMB) v2 [SMB] — Files and Directories management with an SMB server. Supports SMB2 and SMB3 protocols.
Service Manager [HPE_Service_Manager] — Service Manager By Micro Focus (Formerly HPE Software).
ServiceDeskPlus [ServiceDeskPlus] — Use this integration to manage on-premises and cloud Service Desk Plus requests. The integration allows you to create, update, and delete requests, assign groups and technicians to requests, and link/unlink requests and modify their resolution.
ServiceNow [ServiceNow] — Deprecated. Use the ServiceNow v2 integration instead.
ServiceNow CMDB [ServiceNow] — ServiceNow CMDB is a service‑centric foundation that proactively analyzes service‑impacting changes, identifies issues, and eliminates outages.
ServiceNow Event Collector [ServiceNow] — Use this integration to fetch audits, syslog transactions, cases, and outbound HTTP logs from ServiceNow as Cortex XSIAM events.
ServiceNow IAM [ServiceNow] — Integrate with ServiceNow's services to execute CRUD operations for employee lifecycle processes.
ServiceNow v2 [ServiceNow] — Use The ServiceNow IT Service Management (ITSM) solution to modernize the way you manage and deliver services to your users.
Shodan_v2 [Shodan] — A search engine used for searching Internet-connected devices.
Signal Sciences WAF [SignalSciences] — Protect your web application using Signal Sciences.
Signum [Signum] — Signum password expiry notification.
SilentPush [SilentPush] — The Silent Push Platform uses first-party data and a proprietary scanning engine to enrich global DNS data with risk and reputation scoring, giving security teams the ability to join the dots across the entire IPv4 and IPv6 range, and identify adversary infrastructure before an attack is launched. The content pack integrates with the Silent Push system to gain insights into domain/IP information, reputations, enrichment, and infratag-related details. It also provides functionality to live-scan URLs and take screenshots of them. Additionally, it allows fetching future attack feeds from the Silent Push system.
SilentPush_v2 [SilentPush] — The Silent Push Platform uses first-party data and a proprietary scanning engine to enrich global DNS data with risk and reputation scoring, giving security teams the ability to join the dots across the entire IPv4 and IPv6 range, and identify adversary infrastructure before an attack is launched. The content pack integrates with the Silent Push system to gain insights into domain/IP information, reputations, enrichment, and infratag-related details. It also provides functionality to live-scan URLs and take screenshots of them. Additionally, it allows fetching future attack feeds from the Silent Push system.
Silverfort [Silverfort] — Use the Silverfort integration to get and update Silverfort risk severity.
Simple API Proxy [SimpleAPIProxy] — Provide a simple API proxy to restrict privileges or minimize the amount of credentials issued at the API.
Simple SFTP [SimpleSFTP] — Simple SFTP Integration to copy files from SFTP Server using paramiko.
SingleConnect [SingleConnect] — Single Connect is a PAM product that enables enterprises to remove static passwords stored in applications by instead keeping passwords in a secure password vault. Single Connect provides a token-based authentication for 3rd party applications when accessing the password vault. This authentication process verifies the application identity and gives secure access to the password associated with that identity.
Sixgill_DVE_Feed [Sixgill-Darkfeed] — Deprecated. Use Cybersixgill DVE Feed Threat Intelligence v2 from the Cybersixgill-DVE pack instead.
Sixgill_DVE_Feed v2 [Cybersixgill-DVE] — The Cybersixgill Dynamic Vulnerability Exploit (DVE) Score is based on the most comprehensive collection of vulnerability-related threat intelligence and is the only solution that provides users total context and predicts the immediate risks of a vulnerability based on threat actors’ intent. Cortex XSOAR users can track threats stemming from CVEs that most others define as irrelevant and have a higher probability of being exploited via their Cortex XSOAR dashboard.
Sixgill_Darkfeed [Sixgill-Darkfeed] — Leverage the power of Sixgill to supercharge Cortex XSOAR with real-time Threat Intelligence indicators. Get IOCs such as domains, URLs, hashes, and IP addresses straight into the XSOAR platform.
Sixgill_Darkfeed_Enrichment [Sixgill-Darkfeed] — Sixgill Darkfeed Enrichment – powered by the broadest automated collection from the deep and dark web – is the most comprehensive IOC enrichment solution on the market. By enriching Palo Alto Networks Cortex XSOAR IOCs with Darkfeed, customers gain unparalleled context and essential explanations in order to accelerate their incident prevention and response and stay ahead of the threat curve. Automatically enrich Cortex XSOAR IOCs (machine to machine) via Darkfeed. Block threats and enrich endpoint protection in real-time from the Cortex XSOAR dashboard, gain contextual and actionable insights with essential explanations of Cortex XSOAR IOCs.
Skyhigh Security [SkyhighSecurity] — Skyhigh Security is a cloud-based, multi-tenant service that enables Cloud Discovery and Risk Monitoring, Cloud Usage Analytics, Cloud Access and Control.
Slack IAM [Slack] — Integrate with Slack's services to execute CRUD operations for employee lifecycle processes.
SlackV2 [Slack] — Deprecated. Use SlackV3 instead.
SlackV3 [Slack] — Send messages and notifications to your Slack team.
SlashNext Phishing Incident Response [SlashNextPhishingIncidentResponse] — SlashNext Phishing Incident Response integration allows Cortex XSOAR users to fully automate analysis of suspicious URLs. For example, IR teams responsible for abuse inbox management can extract links or domains out of suspicious emails and automatically analyze them with the SlashNext SEER threat detection cloud to get definitive, binary verdicts (malicious or benign) along with IOCs, screen shots, and more. Automating URL analysis can save IR teams hundreds of hours versus manually triaging these emails or checking URLs and domains against less accurate phishing databases and domain reputation services.
Smokescreen IllusionBLACK [Smokescreen_IllusionBLACK] — Smokescreen IllusionBLACK is a deception-based threat defense platform designed to accurately and efficiently detect targeted threats including reconnaissance, lateral movement, malware-less attacks, social engineering, Man-in-the-Middle attacks, and ransomware in real-time.
Snort IP Blocklist Feed [SnortIPBlocklist] — This is the Snort IP Block List feed obtained from https://snort.org/
Snowflake [Snowflake] — Analytic data warehouse provided as Software-as-a-Service.
SolarWinds [SolarWinds] — The SolarWinds integration interacts with the SWIS API to allow you to fetch alerts and events. It also provides commands to retrieve lists of alerts and events.
Sophos Central [SophosCentral] — The unified console for managing Sophos products.
Spamcop [Spamcop] — SpamCop is an email spam reporting service, integration allow checking the reputation of an IP address.
SpamhausFeed [FeedSpamhaus] — Use the Spamhaus feed integration to fetch indicators from the feed.
SpecterOpsBHE [SpecterOpsBHE] — Deprecated. Use the SpecterOps BloodHound Enterprise integration instead. Use the SpecterOpsBHE integration to retrieve attack path findings from BloodHound Enterprise to streamline incident creation and investigation.
SpecterOpsBloodHoundEnterprise [SpecterOpsBloodHoundEnterprise] — Use the SpecterOpsBloodHoundEnterprise integration to retrieve attack path findings from BloodHound Enterprise to streamline incident creation and investigation.
SplunkPy [SplunkPy] — Run queries on Splunk and fetch Notable Events (Splunk ES versions up to 8.2).
SplunkPy v2 [SplunkPy] — Run queries on Splunk and fetch Splunk ES Findings and Investigations (Splunk ES 8.2+).
SplunkPyPreRelease [SplunkPyPreRelease] — Runs queries on Splunk servers.
SpurContextAPI [SpurContextAPI] — Enrich indicators using the Spur Context API.
SpyCloud [SpyCloud] — With the SpyCloud integration data from breaches can be pulled and further processed in Playbooks. Filtering parameters can be used to filter the data set.
SpyCloudEnterpriseProtectionEnrichment [SpyCloudEnterpriseProtection] — Integrate the SpyCloud Enterprise Protection API to use enrichment commands (along with sample Enrichment Playbooks) to look up your watchlists, domains, emails, IP addresses, usernames, and passwords. Data for malware-infected devices and exposed corporate applications are available for SpyCloud Compass users.
SpyCloudEnterpriseProtectionFeed [SpyCloudEnterpriseProtection] — Fetch SpyCloud watchlist data (breach, malware and access records) for daily monitoring, incident response, and mitigation.
Stamus [Stamus] — [Get Declaration of Compromises from Stamus Security Platform and build Incidents. Then get related artifacts, events and Host Insight information].
Stealthwatch Cloud [Stealthwatch_Cloud] — Protect your cloud assets and private network.
StellarCyber [StellarCyber] — Fetches and mirrors in Cases from Stellar Cyber to XSOAR. In addition, provides a command to update Case severity/status/assignee/tags, and a command to query an Alert.
SumoLogic [SumoLogic] — Cloud-based service for logs & metrics management.
SumoLogicSEC [SumoLogic_Cloud_SIEM] — Freeing the analyst with autonomous decisions.
SupernaZeroTrust [SupernaZeroTrust] — Run Superna Zero Trust ransomware containment actions (critical path snapshot, user lockout/unlock) via the Superna API.
Symantec Data Loss Prevention [SymantecDLP] — Deprecated. Use the Symantec Data Loss Prevention V2 integration instead. Symantec Data Loss Prevention enables you to discover, monitor and protect your sensitive corporate information.
Symantec Data Loss Prevention v2 [SymantecDLP] — Symantec Data Loss Prevention version 15.7 enables you to discover, monitor and protect your sensitive corporate information.
Symantec Email Security Cloud [SymantecEmailSecurity] — Symantec Email Security.cloud is a hosted service that filters email messages and helps protect organizations from malware (including targeted attacks and phishing), spam, and unwanted bulk email. The service offers encryption and data protection options to help control sensitive information sent by email and supports multiple mailbox types from various vendors.
Symantec Endpoint Protection V2 [SymantecEndpointProtection] — Query the Symantec Endpoint Protection Manager using the official REST API.
Symantec MSS [SymantecMSS] — Leverage the power of Symantec Managed Security Services for continual threat monitoring and customized guidance 24x7.
Symantec Management Center [SymantecManagementCenter] — Symantec Management Center provides a unified management environment for the Symantec Security Platform portfolio of products.
Symantec Messaging Gateway [Symantec_Messaging_Gateway] — Symantec Messaging Gateway protects against spam, malware, targeted attacks and provides advanced content filtering, data loss prevention, and email encryption.
SymantecEDR [SymantecEDR] — Symantec EDR (On Prem) endpoints help to detect threats in your network by filter endpoints data to find Indicators of Compromise (IoCs) and take actions to remediate the threat(s). EDR on-premise capabilities allow incident responders to quickly search, identify, and contain all impacted endpoints while investigating threats using a choice of on-premises.
SysAid [SysAid] — SysAid is a robust IT management system designed to meet all of the needs of an IT department.
SysdigResponseActions [Sysdig] — Uses the Sysdig agent to respond to malicious activity by triggering different actions at the host or container level, such as killing a container, quarantining a file, or performing a system capture.
Syslog Sender [Syslog] — Use the Syslog Sender integration to send messages and mirror incident War Room entries to Syslog.
Syslog v2 [Syslog] — A Syslog server enables automatically opening incidents from Syslog clients. This integration supports filtering logs to convert to incidents, or alternatively converting all logs.
TAXII 2 Feed [FeedTAXII] — Ingests indicator feeds from TAXII 2.0 and 2.1 servers.
TAXII Server [TAXIIServer] — This integration provides TAXII Services for system indicators (Outbound feed).
TAXII2 Server [TAXIIServer] — This integration provides TAXII2 Services for system indicators (Outbound feed).
TAXIIFeed [FeedTAXII] — Ingests indicator feeds from TAXII 1.x servers.
TOPdesk [TOPdesk] — TOPdesk’s Enterprise Service Management software (ESM) lets your service teams join forces and process requests from a single platform.
TaegisXDR [SecureWorks] — Deprecated. Use TaegisXDR v2 instead.
TaegisXDRv2 [SecureWorks] — For integration with the Secureworks Taegis XDR platform.
Talos Feed [FeedTalos] — Use the Talos Feed integration to get indicators from the feed.
Tanium [Tanium] — Deprecated. Use Tanium v2 instead.
Tanium Threat Response [TaniumThreatResponse] — Use the Tanium Threat Response integration to manage endpoints processes, evidence, alerts, files, snapshots, and connections. This Integration works with Tanium Threat Response version below 3.0.159. In order to use Tanium Threat Response version 3.0.159 and above, use Tanium Threat Response V2 Integration.
Tanium Threat Response v2 [TaniumThreatResponse] — Use the Tanium Threat Response integration to manage endpoint processes, evidence, alerts, files, snapshots, and connections. This integration works with Tanium Threat Response version 3.0.159 and above.
Tanium v2 [Tanium] — Tanium endpoint security and systems management, filters out [current results unavailable] when returning question results.
Tavily [Tavily] — Tavily is a web service that provides real-time web search and retrieval capabilities through an API, enabling developers to fetch and extract relevant information from the internet in structured formats like JSON.
Team Cymru Scout [TeamCymru] — Team Cymru's Scout integration with Palo Alto XSOAR helps streamline incident triage and accelerate threat response by providing domain and threat intelligence data.
TeamCymru [TeamCymru] — Team Cymru provides various service options dedicated to mapping IP numbers to BGP prefixes and ASNs. Each of the services is based on the same BGP feeds from 50+ BGP peers and is updated at 4-hour intervals.
Tenable.io [Tenable_io] — A comprehensive asset-centric solution to accurately track resources while accommodating dynamic assets such as cloud, mobile devices, containers, and web applications. Fetch capabilities are only available for certain licenses.
Tenable.sc [Tenable_sc] — With Tenable.sc (formerly SecurityCenter) you get a real-time, continuous assessment of your security posture so you can find and fix vulnerabilities faster.
Tessian [Tessian] — Tessian is an email security platform that allows organizations to protect their users from inbound phishing threats, outbound data loss (both malicious and accidental) and account takeovers.
TheHive Project [TheHiveProject] — Integration with The Hive Project Security Incident Response Platform.
Thinkst Canary [ThinkstCanary] — By presenting itself as an apparently benign and legitimate service(s), the Canary draws the attention of unwanted activity. When someone trips one of the Canary's triggers, an alert is sent to notify the responsible parties so that action can be taken before valubale systems in your network are compromised.
ThousandEyes [ThousandEyes] — This Integration is used to to fetch-incidents via "Active alerts", get alert details via "Alert details", and get the "Agent list".
Threat Crowd [Threat_Crowd] — Deprecated. Use Threat Crowd v2 instead.
ThreatConnect [ThreatConnect] — Deprecated. Use the ThreatConnect v3 integration instead.
ThreatConnect Feed [FeedThreatConnect] — This integration fetches indicators from ThreatConnect.
ThreatConnect v2 [ThreatConnect] — Deprecated. Use the ThreatConnect v3 integration instead.
ThreatConnect v3 [ThreatConnect] — ThreatConnect's integration is a intelligence-driven security operations solution with intelligence, automation, analytics, and workflows.
ThreatCrowd_v2 [Threat_Crowd] — Deprecated. No available replacement.
ThreatExchange [ThreatExchange] — Deprecated. Use the ThreatExchange v2 integration instead.
ThreatExchange v2 [ThreatExchange] — Receive threat intelligence about applications, IP addresses, URLs, and hashes. A service by Facebook.
ThreatFox Feed [FeedThreatFox] — ThreatFox is a free platform from abuse.ch with the goal of sharing indicators of compromise (IOCs) associated with malware. Use the ThreatFox Feed integration to fetch indicators from the feed.
ThreatGridv2 [ThreatGrid] — Query and upload samples to Cisco threat grid.
ThreatMiner [ThreatMiner] — Data Mining for Threat Intelligence.
ThreatMon Threat Feed [ThreatMonThreatFeed] — Fetches Indicators of Compromise (IOCs) from the ThreatMon IOC platform and ingests them into Cortex as indicators.
ThreatQ v2 [ThreatQ] — A threat intelligence platform that collects and interprets intelligence data from open sources and manages indicator scoring, types, and attributes.
ThreatQ_Beta [ThreatQ] — Deprecated. Use ThreatQ v2 instead. ThreatQ Integration
ThreatX [ThreatX] — The ThreatX integration allows automated enforcement and intel gathering actions.
Tor Exit Addresses Feed [FeedTorExitAddresses] — Tor is free software and an open network that helps you defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security.
Traceable [Traceable] — Traceable Platform Integration enables publishing Traceable Detected Security Events to be published to Cortex Xsoar for further action.
Traps [Traps] — Deprecated. Use CortexXDR instead.
Trello [Trello] — Interact with the Trello task manager.
Trend Micro [trendMicroDsm] — Deprecated. Use Trend Micro Deep Security instead.
Trend Micro Apex [TrendMicroApex] — TrendAI™ Apex One central automation to manage agents and User-Defined Suspicious Objects.
Trend Micro Deep Discovery Analyzer [TrendMicroDDA] — TrendAI™ Deep Discovery™ Analyzer is a turnkey appliance that uses virtual images of endpoint configurations to analyze and detect targeted attacks.
Trend Micro Vision One [TrendMicroVisionOne] — TrendAI Vision One™ is a purpose-built threat defense platform that provides added value and new benefits beyond XDR solutions, allowing you to see more and respond faster. Providing deep and broad extended detection and response (XDR) capabilities that collect and automatically correlate data across multiple security layers—email, endpoints, servers, cloud workloads, and networks—TrendAI Vision One™ prevents the majority of attacks with automated protection.
Trend Micro Vision One V3 [TrendMicroVisionOne] — TrendAI Vision One™ is a purpose-built threat defense platform that provides added value and new benefits beyond XDR solutions, allowing you to see more and respond faster. Providing deep and broad extended detection and response (XDR) capabilities that collect and automatically correlate data across multiple security layers—email, endpoints, servers, cloud workloads, and networks—TrendAI Vision One™ prevents the majority of attacks with automated protection.
TrendMicro Cloud App Security [TrendMicroCAS] — Use TrendAI™ Cloud App Security integration to protect against ransomware, phishing, malware, and unauthorized transmission of sensitive data for cloud applications, such as Microsoft 365, Box, Dropbox, Google G Suite and Salesforce.
TrendMicroVisionOneEventCollector [TrendMicroVisionOne] — Palo Alto Networks TrendAI Vision One™ Event Collector integration for Cortex XSIAM collects the Workbench, Observed Attack Techniques, Search Detections and Audit logs.
Tripwire [Tripwire] — Tripwire is a file integrity management (FIM), FIM monitors files and folders on systems and is triggered when they have changed.
TruSTAR [TruSTAR] — Deprecated. Not supported since TrueSTAR was acquired by Splunk, No available replacement.
TruSTAR v2 [TruSTAR] — Deprecated. Not supported since TrueSTAR was acquired by Splunk, No available replacement.
TrustwaveFusion [TrustwaveFusion] — The Trustwave Fusion platform connects your organization’s digital footprint
to a robust security cloud comprised of the Trustwave data lake, advanced
analytics, actionable threat intelligence and a wide range of Trustwave
services including Trustwave SpiderLabs , elite team of security
specialists. Your team will benefit from deep visibility and the advanced
security expertise necessary for protecting assets and eradicating threats as
they arise.
Tufin [Tufin] — Retrieve and analyze network access controls across Tufin-managed firewalls, SDN, and public cloud to identify vulnerable access paths of an attack.
Twilio SendGrid [TwilioSendGrid] — Twilio SendGrid is a cloud-based email delivery platform that provides email activity tracking and analytics.
Twinwave [Twinwave] — TwinWave’s threat analysis platform analyzes both URLs and files to detect credential phishing and malware threats. Our platform automatically navigates complex attack chains that attackers put in front of threats in order to evade analysis. In addition to detecting threats, the TwinWave platform generates actionable intelligence for threat hunting and other activities.
Twitter [Twitter] — Deprecated. Use Twitter v2 instead.
Twitter v2 [Twitter] — Twitter integration provides access to searching recent Tweets (in last 7 days) and user information using the Twitter v2 API.
TwitterIOCHunter - Full Daily Feed [TwitterIOCHunter-FullDailyFeed] — Fetch the full daily feed from www.tweettioc.com/v1/tweets/daily/full
UBIRCH [UBIRCH] — The UBIRCH solution can be seen as an external data certification provider, as a data notary service, giving data receivers the capability to verify data they have received with regard to its authenticity and integrity and correctness of sequence.
URLhaus [URLHaus] — URLhaus has the goal of sharing malicious URLs that are being used for malware distribution.
USTA [USTA] — USTA is an Cyber Intelligence Platform that responds directly and effectively to today's complex cyber threats.
USTA Account Takeover Prevention [USTAv4] — Collects compromised credentials sourced from stealer malware attacks, helping organizations identify potential account takeovers and enhance their security posture. Provided by PRODAFT.
USTA Stolen Credit Cards [USTAv4] — This integration offers organizations the ability to track stolen credit card data across the web, providing comprehensive insight into compromised card information sourced from underground markets, dark web forums, and other malicious platforms.
UltraMSG [UltraMSG] — This is the UltraMSG integration for getting started made by Trustnet.
UnifiVideo [UnifiVideoNVR] — Connect to UnifiVideo NVR and manage CCTV cameras!
This integration allows you to fetch motion recording events as incidents.
The integration commands also allow downloading snapshots, recordings and controlling the camera infra-red capabilities.
Unisys Stealth [UnisysStealth] — This integration is intended to aid companies in integrating with the Stealth EcoAPI service. Using the included commands, security teams can trigger dynamically isolation of users or endpoints from the rest of the Stealth network.
Unit 42 Feed [Unit42ThreatIntelligencebyPaloAltoNetworks] — Unit 42 Feed integration provides threat intelligence from Palo Alto Networks Unit 42 research team.
Unit 42 Intelligence [Unit42ThreatIntelligencebyPaloAltoNetworks] — Enrich indicators with Unit 42 threat intelligence context including verdicts, threat object associations, and relationships.
Unit42 Feed [FeedUnit42] — Deprecated. Use Unit42 ATOMs Feed instead.
Unit42v2 Feed [FeedUnit42v2] — Deprecated. Use the Unit42 Feed instead.
Uptycs [Uptycs] — Fetches data from the Uptycs database.
UptycsEventCollector [Uptycs] — Uptycs is a cloud-native security analytics platform that provides visibility, threat detection, and compliance across endpoints and cloud workloads.
VBR REST API [Veeam] — Veeam Backup & Replication REST API allows you to query information about Veeam Backup & Replication entities and perform operations with these entities using HTTP requests and standard HTTP methods.
VMware [VMware] — VMware vCenter server is a centralized management application that lets you manage virtual machines and ESXi hosts centrally.
VMware Carbon Black EDR v2 [Carbon_Black_Enterprise_Response] — VMware Carbon Black EDR (formerly known as Carbon Black Response).
VMware Workspace ONE UEM (AirWatch MDM) [VMwareWorkspaceONEUEM] — VMware Workspace ONE UEM integration allows users to search enrolled corporate or employee-owned devices, provides detailed information about each device such as its serial number, installed OS's, pending OS updates, network details, and much more leveraging Workspace ONE UEM's (formerly AirWatch MDM) API.
VMwareV2 [Ansible_Powered_Integrations] — Manage VMware vSphere Server, Guests, and ESXi Hosts. Deprecated. Use Ansible VMware (from the Ansible VMware pack) instead.
VaronisDataSecurityPlatform [VaronisDataSecurityPlatform] — Streamline alerts and related forensic information from Varonis DSP.
VaronisSaaS [VaronisSaaS] — Streamline alerts and related forensic information from Varonis SaaS.
Vectra [Vectra] — Deprecated. Use Vectra Detect instead.
Vectra v2 [Vectra] — Deprecated. Use Vectra Detect instead.
VectraAIEventCollector [Vectra_AI] — Collects Vectra Detections and Audits into XSIAM Events.
VectraRUXEventsDetections [VectraRUX] — This integration allows the security operations center to create and manage incidents based on Vectra Events Detections.
VectraXDR [VectraXDR] — This integration allows to create incidents based on Vectra XDR Entities.
Vectra_Detect [Vectra_AI] — This integration allows to create incidents based on Vectra Accounts/Hosts/Detections objects.
Veeam ONE REST API [Veeam] — Veeam ONE REST API allows you to query information about Veeam ONE entities and perform operations with these entities using HTTP requests and standard HTTP methods.
Vega [Vega] — Vega integration for fetching alerts and incidents from the Vega platform.
Venafi [Venafi] — Deprecated. Use Venafi TLS Protect instead.
VenafiTLSProtect [Venafi] — Retrieves information about certificates stored in Venafi.
VercaraUltraDNS [VercaraUltraDNS] — Vercara UltraDNS integration for Cortex. Leverage UltraDNS's cloud-based DNS event and configuration data for security automation and real-time threat detection in Cortex.
Verodin [Verodin] — Verodin simulations and topology.
VersaDirector [VersaDirector] — Versa Director is a virtualization and service creation platform that simplifies the design, automation, and delivery of SASE services. Versa Director provides the essential management, monitoring, and orchestration capabilities needed to deliver all of the networking and security capabilities within Versa SASE.
Viper [Viper] — Viper is a binary analysis and management framework.
VirusTotal [VirusTotal] — Deprecated. Use VirusTotalV3 integration instead.
VirusTotal (API v3) [VirusTotal] — Analyzes suspicious hashes, URLs, domains, and IP addresses.
VirusTotal - Premium (API v3) [VirusTotal] — Analyse retro hunts, read live hunt notifications and download files from VirusTotal.
VirusTotal - Private API [VirusTotal-Private_API] — Deprecated. Use "VirusTotal (API v3)" or "VirusTotal - Premium (API v3)" integrations instead.
VirusTotal Livehunt Feed [VirusTotal] — Use this feed integration to fetch VirusTotal Livehunt notifications as indicators.
VirusTotal Retrohunt Feed [VirusTotal] — Use this feed integration to fetch VirusTotal Retrohunt matches.
VulnDB [VulnDB] — Lists all of the security vulnerabilities for various products (OS,Applications) etc).
VxStream [CrowdStrikeFalconSandbox] — Deprecated. Use CrowdStrike Falcon Sandbox V2 instead.
WALLIX Bastion [WALLIXBastion] — Centralized Control and Monitoring of Privileged Access to Sensitive Assets.
Web File Repository [WebFileRepository] — Simple web server with a file uploading console to store small files.
This is helpful to make your environment ready for testing purpose for your playbooks or automations to download files from a web server.
WhatsMyBrowser [WhatIsMyBrowser] — Parse user agents and determine if they are malicious as well as enrich information about the agent.
Whois [Whois] — Provides data enrichment for domains.
WildFire-Reports [Palo_Alto_Networks_WildFire] — Generates a Palo Alto Networks WildFire PDF report. For internal use with the TIM Sample Analysis feature.
Windows Remote Management [WinRM] — Uses the Python pywinrm library and commands to execute either a process or using Powershell scripts.
WithSecureEventCollector [WithSecure] — WithSecure event collector integration for Cortex XSIAM.
Wiz [Wiz] — Agentless cloud security with bidirectional Issue mirroring, status sync, comment sync, and due-date sync between Wiz and Cortex XSOAR.
WizDefend [Wiz] — Agentless cloud security platform for detecting and addressing cloud issues, detections, and threats.
Wolken ITSM [WolkenITSM] — Use The Wolken IT Service Management (ITSM) solution to modernize the way you manage and deliver services to your users.
WootCloud [WootCloud] — Append HyperContext™ insights to your SIEM data and feed them into your orchestration workflows.
Wordpress [Wordpress] — The WordPress REST API provides an interface for applications to interact with your WordPress site by sending and receiving data as JSON (JavaScript Object Notation) objects. It is the foundation of the WordPress Block Editor, and can likewise enable your theme, plugin or custom application to present new, powerful interfaces for managing and publishing your site content.
Workday [Workday] — Workday offers enterprise-level software solutions for financial management, human resources, and planning.
Workday Event Collector [Workday] — Use Workday Event Collector integration to get activity loggings from Workday.
Workday IAM [Workday] — Use the Workday IAM Integration as part of the IAM premium pack.
Workday Sign On Event Collector [Workday] — Use the Workday Sign On Event Collector integration to get sign on logs from Workday.
XDome [ClarotyXDome] — Use the xDome integration to manage assets and alerts.
XFE [XForceExchange] — Deprecated. Use the IBM X-Force Exchange v2 integration instead.
XFE_v2 [XForceExchange] — IBM X-Force Exchange lets you receive threat intelligence about applications, IP addresses, URls and hashes.
XMCyber [XMCyber] — The XM Cyber integration creates unique incidents with valuable data collected daily, and enriches your existing incidents with attack simulation context. This enables you to prioritize your responses based on XM Cyber’s insights.
XMCyberCEM [XMCyber] — The XM Cyber integration connects XM Cyber's Continuous Exposure Management (CEM) platform with XSOAR, enhancing your Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response processes with attack graph context and prioritization, while also feeding relevant entities back to CEM to be defined as breach points in CEM scenarios.
XQL Query Engine [Core] — XQL Query Engine enables you to run XQL queries on your data sources.
XSOAR EDL Checker [XSOAR_EDL_Checker] — Checks an XSOAR hosted EDL to make sure it's returning a valid response. Supports PAN-OS (text), CSV, or JSON EDLs.
XSOAR Engineer Training [XSOAR_Engineer_Training] — The XSOAR Engineer Training (XET) integration provides sample data to fetch events into Cortex XSOAR, and commands to build playbooks around.
Use for training purposes only.
XSOAR File Management [XSOARFileManagement] — This integration uses the XSOAR API to perform basic but essentials actions on files.
XSOAR Mirroring [XSOARmirroring] — Facilitates mirroring of Cortex XSOAR incidents between different Cortex XSOAR tenants.
XSOAR Storage [XSOARStorage] — Facilitates the storage and retrieval of key/value pairs within XSOAR.
XSOAR-Web-Server [XsoarWebserver] — This is a simple web-server that as of now, supports handling configurable user responses (like Yes/No/Maybe) and data collection tasks that can be used to fetch key value pairs. What makes it different from Data collection tasks is that, the URL to perform a certain action is predictable and written to the incident context when an action is setup.This URL can be inserted to for eg: an HTML email. User clicks are are recorded in the integration context and can be polled by Scheduled Commands/ Generic Polling.
Xpanse Feed [CortexXpanse] — Use this feed to retrieve the discovered IPs/domains/certificates from the Cortex Xpanse asset database.
XsoarPowershellTesting [DeveloperTools] — Powershell Integration for testing that Powershell support is working as expected.
Xsoar_Utils [Xsoar_Utils] — This is a wrapper on top of XSOAR API. Can be used to implement commands that call the XSOAR API in the background. This is mostly to avoid constructing raw json strings while calling the demisto rest api integration.
The first implemented command can be used to create an entry on any investigation; playground by default. An example use-case could be debugging a pre-process script. (Call demisto.execute_command("xsoar-create-entry",{arguments})
The idea is to use the same code to test from a local machine.
python3 Xsoar_Utils.py xsoar-create-entry '{"data":"# testapi4","inv_id":"122c7bff-feae-4177-867e-37e2096cd7d9"}'
Read the code to understand more.
Zabbix [Zabbix] — Allow integration with Zabbix api.
Zafran API [Zafran] — The Zafran API provides a programmatic way to interact with the Zafran Exposure Management Platform for various use cases.
Zendesk [Zendesk] — Deprecated. Use the Zendesk v2 integration instead.
ZeroDayLiveTIFUSION Feed [FeedZeroDayLiveTIFusion] — Zero Day Live is Blackwired's flagship product that delivers proprietary cyber threat intelligence, enabling our clients to operate at the same speed as the adversary. Zero Day Live specializes in unknown, zero day and early warning threats. Our intelligence is delivered finished, actionable and seamlessly orchestrated, directly into the existing security infrastructure - measurably reducing the risk of breach.
ZeroFox [ZeroFox] — Cloud-based SaaS to detect risks found on social media and digital channels.
ZeroFoxKeyIncidents [ZeroFox] — Cloud-based SaaS to detect risks found on social media and digital channels.
ZeroNetworksSegmentEventCollector [ZeroNetworksSegment] — Integrates with Zero Networks Segment API to fetch and process audit and network events.
ZeroTrustAnalyticsPlatform [ZeroTrustAnalyticsPlatform] — Zero Trust Analytics Platform (ZTAP) is the underlying investigation platform and user interface for Critical Start's MDR service.
Zerohack XDR [Zerohack_XDR] — The companion integration for Zerohack XDR. Current versions allow the user to collect data from the XDR and later versions will support data exfiltration to XDR.
Zimperium [Zimperium] — Fetch and investigate mobile security alerts, generated based on anomalous or unauthorized activities detected on a user's mobile device.
Zimperium v2 [Zimperium] — Fetch and investigate mobile security alerts, generated based on anomalous or unauthorized activities detected on a user's mobile device. Compatible with Zimperium 5.X API version.
Zoom [Zoom] — Use the Zoom integration to manage your Zoom users and meetings.
Zoom Feed [FeedZoom] — Use the Zoom Feed integration to get indicators from the feed.
Zoom Mail [ZoomMail] — Enables interaction with the Zoom Mail API.
ZoomEventCollector [Zoom] — This is the Zoom event collector integration for Cortex XSIAM.
Zoom_IAM [Zoom] — An Identity and Access Management integration template.
Zscaler [Zscaler] — Zscaler is a cloud security solution built for performance and flexible scalability. This integration enables you to manage URL and IP address allow lists and block lists, manage and update categories, get Sandbox reports, create, manage, and update IP destination groups and manually log in, log out, and activate changes in a Zscaler session.
ZscalerZIdentity [Zscaler] — Zscaler Internet Access via ZIdentity OAuth 2.0. Provides URL/IP/domain classification, denylist and allowlist management, URL category management, sandbox reporting, user and group management, and IP destination group management using OAuth 2.0 client credentials authentication through ZIdentity.
abuse.ch SSL Blacklist Feed [Feedsslabusech] — The SSL IP Blacklist contains all hosts (IP addresses) that SSLBL has seen in the past 30 days and identified as being associated with a malicious SSL certificate.
appNovi [AppNovi] — Search across meshed network, security, and business data in appNovi to make efficient informed security decisions for risk management and incident response. Gain immediate intelligence on assets, visualize risk and threats across your network, and undertake interactive investigations across the network to reduce MTTR for incident response.
carbonblack-v2 [Carbon_Black_Enterprise_Response] — Deprecated. Use VMware Carbon Black EDR v2 instead.
carbonblackliveresponse [Carbon_Black_Enterprise_Live_Response] — Collect information and take action on remote endpoints in real time with VMware Carbon Black EDR (Live Response API) (formerly known as Carbon Black Enterprise Live Response).
checkpointdome9 [CheckPointDome9] — Dome9 integration allows to easily manage the security and compliance of the public cloud.
cyberint [Cyberint] — Cyberint provides intelligence-driven digital risk protection. This integration will help your enterprise effectively consume actionable cyber alerts to increase your security posture.
cybleeventsv2 [CybleEventsV2] — Cyble Events for Vision Users. Must have Vision API access to use the threat intelligence.
cymulate_v2 [Cymulate] — Multi-Vector Cyber Attack, Breach and Attack Simulation.
cymulate_v3 [Cymulate] — This integration fetches findings from completed Cymulate assessments as Cortex XSOAR incidents using the V2 Assessment API.
fortimail [Fortimail] — FortiMail is a comprehensive email security solution by Fortinet, offering advanced threat protection, data loss prevention, encryption, and email authentication to safeguard organizations against email-based cyber threats and protect sensitive information.
fortiweb_vm [FortinetFortiwebVM] — Fortiweb VM integration allows to manage WAF policies and block cookies, URLs, and host names.
google-vault [GoogleVault] — Archiving and eDiscovery for G Suite.
iDefense [iDefense] — Deprecated. Use the iDefense v2 integration instead.
iDefense Feed [iDefense] — Deprecated. Use Accenture CTI Feed instead.
iDefense_v2 [iDefense] — Deprecated. Use Accenture CTI v2 instead.
iLert [ILert] — Alert and notify users using iLert.
iManageThreatManager [iManageThreatManager] — iManage Threat Manager protects privileged information against internal and external threat actors using machine learning and user behavior analytics.
iZOOlogic [iZOOlogic] — Fetches and manages incidents from iZOOlogic, enabling automated ingestion, incident creation, and advanced filtering for brand protection and threat management.
iboss [Iboss] — Manage block lists, manage allow lists, and perform domain, IP, and/or URL reputation and categorization lookups.
icebrg [ICEBRG] — Reduces risk by accelerating threat detection, triage, and response to rapidly-evolving breaches across global networks.
illuminate [illuminate] — Deprecated. Use Analyst1 integration instead.
ipinfo [ipinfo] — Deprecated. Use IPinfo v2 instead. Use the ipinfo.io API to get data about an IP address
ipinfo_v2 [ipinfo] — Use the IPinfo.io API to get data about an IP address.
jamf [jamf] — Deprecated. Use Jamf v2 instead. Jamf device management. Please note, this integration is currently only compatible with the Jamf V1 API.
jamf v2 [jamf] — Enterprise Mobility Management (EMM) for Apple devices (Mac, iPhone, Apple TV, iPad). Can be used to control various configurations via different policies, install and uninstall applications, lock devices, smart groups searches, and more.
jira-v2 [Jira] — Deprecated. Use the Atlassian Jira v3 integration instead
malwr [Malwr] — Deprecated. The site at malwr.com is no longer available. No available replacement.
netskope_api_v2 [Netskope] — Netskope API v2 provides a powerful interface for managing and monitoring Netskope deployments. It enables users to retrieve alerts and events, manage URL lists, and control clients. With Netskope API v2, organizations can proactively respond to security threats, enforce web access policies, and efficiently administer their Netskope environment.
nmap [Nmap] — Run nmap scans with the given parameters.
okta [Okta] — Deprecated. Use the Okta v2 integration instead.
palo_alto_networks_pan_os_edl_management [PaloAltoNetworks_PAN_OS_EDL_Management] — Deprecated. Use the Generic Export Indicators Service integration instead. This integration is still supported however, for customers with over 1000 Firewalls.
qualys_fim [QualysFIM] — Log and track file changes across global IT systems.
rapid7_threat_command [IntSight] — Rapid7 Insight - Threat Command allows managing alerts, CVEs, IOCs, and assets by accounts and MSSP accounts.
rapid7appsec [Rapid7AppSec] — Rapid7 AppSec integration allows the management of applications vulnerabilities and scans.
remedy_sr_beta [remedy_SR] — The BMC Service Request Management application enables an IT department and other business departments to easily define available services, publish those services in a service catalog, and automate fulfillment of those services for the user community, enabling users to help themselves.
This integration uses SOAP API and supports SRM 9.0 version.
sophos_firewall [SophosXGFirewall] — On-premise firewall by Sophos enables you to manage your firewall, respond to threats, and monitor what’s happening on your network.
trustwave secure email gateway [TrustwaveSEG] — Trustwave SEG is a secure messaging solution that protects businesses and users from email-borne threats, including phishing, blended threats, and spam. Trustwave Secure Email Gateway also delivers improved policy enforcement and data leakage prevention.
unshortenMe [Unshorten_Me] — Unshorten.me is a free service to Un-Shorten the URLs created by URL shortening services. Unshorten.me can un-shorten URLs created by different services like goo.gl (Google), fb.me (Facebook), t.co (Twitter), bit.ly, TinyURL, ow.ly among others.
urlscan.io [UrlScan] — Use urlscan.io integration to perform scans on suspected URLs and see their reputation.