Cortex Core - IOC
The Cortex Core - IOCs integration uses the Cortex API for detection and response, by natively integrating network, endpoint, and cloud data to stop sophisticated attacks.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Core
Configuration parameters
- url — Server URL (e.g. https://example.net)
- apikey_id — API Key ID
- apikey — API Key
- severity — Cortex Severity
- query — Sync Query
Commands (6)
- core-iocs-create-sync-file — Creates the sync file for the manual process. Run this command when instructed by the Cortex support team.
- core-iocs-disable — Disables IOCs in the Cortex server. Applies only to TIM-managed indicators (indicators synced/pushed by this integration); indicators from other sources are not affected.
- core-iocs-enable — Enables IOCs in the Cortex tenant. Applies only to TIM-managed indicators (indicators synced/pushed by this integration); indicators from other sources are not affected.
- core-iocs-push — Push modified IOCs to Cortex.
- core-iocs-set-sync-time — Set sync time manually (Do not use this command unless you unredstandard the consequences).
- core-iocs-sync — Sync your IOC with Cortex and delete the previous version.