CrowdStrike Indicator Feed
Retrieves indicators from the CrowdStrike Falcon Intel Feed.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedCrowdstrikeFalconIntel
Configuration parameters
- feed — Fetch indicators
- base_url — CrowdStrike Base URL (required)
- credentials — CrowdStrike API Client ID (required)
- timeout — The amount of time (in seconds) that a request will wait for a client to establish a connection to a remote machine before a timeout occurs.
- type — Type
- first_fetch — First fetch time (required)
- max_indicator_to_fetch — Max. indicators per fetch
- malicious_confidence — Malicious confidence
- include_deleted — Include deleted indicators
- filter — Filter
- generic_phrase — Generic phrase match
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedTags — Tags
- create_relationships — Create relationships
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feedBypassExclusionList — Bypass exclusion list
- feedIncremental — Incremental Feed
Commands (2)
- crowdstrike-indicators-list — Gets indicators from the CrowdStrike Falcon Intel Feed.
- crowdstrike-reset-fetch-indicators — Resets the retrieving start time according to the `First Fetch Time` parameter, WARNING: This command will reset your fetch history.