ACTI Indicator Feed
Fetches indicators from a ACTI feed. You can filter returned indicators by indicator type, indicator severity, threat type, confidence, and malware family (each of these are an integration parameter).
- Category
- Data Enrichment & Threat Intelligence
- Pack
- AccentureCTI_Feed
Configuration parameters
- feed — Fetch indicators
- api_token — (required)
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedIncremental — Incremental Feed
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- indicator_type — Indicator Type (required)
- severity — Indicator Severity
- threat_type — Threat Type
- confidence_from — Confidence
- malware_family — Malware Family
- feedBypassExclusionList — Bypass exclusion list
- feedTags — Tags
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (1)
- acti-get-indicators — Gets the feed indicators.