CTIX v3
Integrates with Cyware Intel Exchange to enrich indicators, fetch incidents and threat intelligence indicators, manage tags and notes, view related objects, perform vulnerability lookups, and run generic API requests.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- CTIX
Configuration parameters
- base_url — Endpoint URL (required)
- access_id — Access Key (required)
- secret_key — Secret Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- timeout — Timeout
- isFetch — Fetch incidents
- incidentFetchInterval — Incidents Fetch Interval
- incidentType — Incident type
- classifier — Classifier
- mapper — Mapper (incoming)
- integrationReliability — Source Reliability
- first_fetch — First fetch time
- max_fetch — Maximum number of incidents per fetch
- incident_fetch_query — Incident Fetch CQL Query
- feed — Fetch indicators
- saved_result_set_label — Saved Result Set Label
- saved_result_set_version — Saved Result Set Version
- retrieve_enriched_data — Retrieve Enriched Data
- feedFetchInterval — Feed Fetch Interval
- feedReliability — Source Reliability (required)
- feedReputation — Indicator Reputation
- feedExpirationPolicy —
- feedExpirationInterval —
- tlp_color — Traffic Light Protocol Color
- feedBypassExclusionList — Bypass exclusion list
- feedTags — Tags
Commands (39)
- ctix-add-analyst-score — Add Analyst Score for a Threat data.
- ctix-add-analyst-tlp — Add Analyst TLP.
- ctix-add-indicator-as-false-positive — Add indicators as false positive in CTIX.
- ctix-add-tag-indicator — Adding Tag to Indicator.
- ctix-allowed-iocs — Adds list of same type of iocs to allowed.
- ctix-bulk-ioc-lookup-advanced — Performs a bulk lookup for threat data objects in the CTIX platform and retrieves details such as basic info, enriched data, and relations.
- ctix-create-note — Creates a new Note from the parameter 'text'.
- ctix-create-tag — Create new tag in the ctix platform.
- ctix-delete-note — Deletes an existing Note, as specified by its ID.
- ctix-deprecate-ioc — Deprecate ioc bulk api.
- ctix-disable-or-enable-tags — Disables or enables one or more tags based on their IDs.
- ctix-get-actions — Enrichment tools listing API.
- ctix-get-all-notes — Get paginated list of Notes.
- ctix-get-allowed-iocs — get paginated list of allowed iocs.
- ctix-get-conversion-feed-source — Get Conversion feed source.
- ctix-get-create-threat-data — Gets or creates threat data.
- ctix-get-indicator-details — Get Indicator Details.
- ctix-get-indicator-observations — Get Indicator Observations.
- ctix-get-indicator-tags — Get Indicator Tags.
- ctix-get-lookup-threat-data — Lookup to get threat data.
- ctix-get-note-details — Get details of a Note as specified by its ID.
- ctix-get-object-relations — Get Object Relations.
- ctix-get-saved-searches — Saved Search listing api with pagination.
- ctix-get-server-collections — Source Collection listing api with pagination.
- ctix-get-tags — Get paginated list of tags.
- ctix-get-threat-data — Command for querying and listing threat data.
- ctix-get-vulnerability-data — Lookup vulnerability info.
- ctix-ioc-manual-review — Adds ioc to manual review bulk api.
- ctix-make-request — allows you to make any HTTP request using CTIX endpoints.
- ctix-remove-allowed-ioc — Removes a allowed ioc with given id.
- ctix-remove-tag-from-indicator — Remove Tag From Indicator.
- ctix-saved-result-set — Saved Result Set.
- ctix-search-for-tag — Search for tag.
- ctix-update-note — Updates the Note text from an existing Note, as specified by its ID.
- cve — Lookup vulnerability info.
- domain — Lookup domain threat data.
- file — Lookup file threat data.
- ip — Lookup ip threat data.
- url — Lookup url threat data.