BrandefenseDRPS
Brandefense is a Cyber Intelligence Platform that responds directly and effectively to today's complex cyber threats.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- BrandefenseDRPS
Configuration parameters
- url — Server URL (e.g. https://api.brandefense.io) (required)
- apikey — (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentFetchInterval — Incidents Fetch Interval
- first_fetch — First time fetching
- incidentType — Incident type
- MaxResults — Max Results
- max_fetch — Maximum incidents per fetch
- integrationReliability — Source Reliability
- IncidentCategory — Incident Category
- IncidentModule — Incident Module
- IncidentStatus — Incident Status
- IntelligenceCategory — Intelligence Category
- IntelligenceSearch — Intelligence Search
- FetchingIssueTypes — Fetching Issue Types (required)
- IncidentRules — Incident Rules
Commands (23)
- brandefense_change_incident_status — Change the status of a Brandefense incident.
- brandefense_create_confirmed_phishing — Create a confirmed phishing address incident in Brandefense.
- brandefense_get_assets — Get list of monitored assets from Brandefense.
- brandefense_get_audit_logs — Get audit log entries from Brandefense.
- brandefense_get_compromised_devices — Get compromised devices detected by Brandefense.
- brandefense_get_domain_risk_assessment — Get third-party domain risk assessments from Brandefense.
- brandefense_get_incident_detail — Get detailed information for a specific Brandefense incident.
- brandefense_get_incident_relatives — Get related incidents for a specific Brandefense incident.
- brandefense_get_incidents — Get Brandefense incidents with optional filtering by status, module, category, and time period.
- brandefense_get_indicators — Get indicators from Brandefense. Retrieves Consolidated Data and Incident indicators by type and organization with optional date range and status filters.
- brandefense_get_intelligence_detail — Get detailed information for a specific intelligence report.
- brandefense_get_intelligence_rules — Get rules associated with a Brandefense intelligence report.
- brandefense_get_intelligences — Get Brandefense intelligence reports with optional filtering.
- brandefense_get_ioc_list — Fetch and consolidate all IoCs from the last N days (default 30). Pulls all IoC types and merges into a single list.
- brandefense_get_iocs — Get Indicators of Compromise from Brandefense threat intelligence feeds.
- brandefense_incident_indicators — Get indicators associated with a Brandefense incident.
- brandefense_intelligence_indicators — Get indicators associated with a Brandefense intelligence report.
- brandefense_takedown_request — Request takedown for a confirmed phishing address.
- domain — Investigate a domain against Brandefense threat intelligence.
- file — Investigate a file hash against Brandefense threat intelligence.
- ip — Investigate an IP address against Brandefense threat intelligence.
- threat_search — Perform a CTI threat search and poll for results using ScheduledCommand.
- url — Investigate a URL against Brandefense threat intelligence.