Cofense Intelligence
Deprecated. Use Cofense Intelligence v2 instead. Use the Cofense Intelligence integration to check the reputation of URLs, IP addresses, file hashes, and email addresses.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Cofense-Intelligence
Configuration parameters
- url — Server URL (e.g., https://www.threathq.com/apiv1) (required)
- credentials — API username (required)
- integrationReliability — Source Reliability (required)
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- urlThreshold — URL Threshold (None, Minor, Moderate, or Major). Minimum severity to consider the URL malicious
- fileThreshold — File Threshold (None, Minor, Moderate, or Major). Minimum severity to consider the file malicious
- ipThreshold — IP Threshold (None, Minor, Moderate, or Major). Minimum severity to consider the IP malicious
- emailThreshold — Email Threshold (None, Minor, Moderate, or Major). Minimum severity to consider the email malicious
Commands (5)
- cofense-search — Searches for extracted strings identified within malware campaigns.
- email — Checks the reputation of an email address.
- file — Checks the reputation of a file hash.
- ip — Checks the reputation of an IP address.
- url — Checks the reputation of a URL.