AutoFocus V2
Deprecated. Use the Unit 42 Intelligence integration instead.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- AutoFocus
Configuration parameters
- credentials —
- api_key — API Key
- integrationReliability — Source Reliability
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- handle_error — Suppress errors for non found indicators
- mark_as_malicious — Additional malicious verdicts
- create_relationships — Create relationships
Commands (14)
- autofocus-get-export-list-indicators — Gets export list indicators from AutoFocus.
- autofocus-get-session-details — Get session details by session ID.
- autofocus-sample-analysis — Returns properties, behaviors, and activities observed for a sample. Run the command a single time to get the fields and operating systems under HTTP, Coverage, Behavior, Registry, Files, Processes, Connections, and DNS.
- autofocus-samples-search-results — Returns results of a previous samples search. `Autofocus Query Samples, Sessions and Tags` Playbook is recommended for querying and polling.
- autofocus-search-samples — Searches for samples in AutoFocus. To view results, run the autofocus-samples-search-results command with the returned AF Cookie. The AF Cookie expires 120 seconds after the search completes. `Autofocus Query Samples, Sessions and Tags` Playbook is recommended for querying and polling.
- autofocus-search-sessions — Searches for sessions in AutoFocus. To view results, run the autofocus-sessions-search-results command with the returned AF Cookie. The AF Cookie expires 120 seconds after the search completes. The `polling` argument was added in XSOAR 6.2.0. It enables handling the search in a single command, rather than using the `Autofocus Query Samples, Sessions and Tags` Playbook.
- autofocus-sessions-search-results — Returns results of a previous sessions search. `Autofocus Query Samples, Sessions and Tags` Playbook is recommended for querying and polling.
- autofocus-tag-details — Returns details about the given tag.
- autofocus-top-tags-results — Returns the results of a previous top tags search. `Autofocus Query Samples, Sessions and Tags` Playbook is recommended for querying and polling.
- autofocus-top-tags-search — Performs a search to identify the most popular tags. `Autofocus Query Samples, Sessions and Tags` Playbook is recommended for querying and polling.
- domain — Checks the reputation of a domain in AutoFocus.
- file — Checks the reputation of a file in AutoFocus.
- ip — Checks the reputation of an IP address in AutoFocus.
- url — Checks the reputation of a URL in AutoFocus.