Expanse
Deprecated. Use the Expanse v2 integration instead. The Expanse App for Demisto leverages the Expander API to retrieve network exposures and risky flows to create incidents in Demisto. This application also allows for IP, Domain, Certificate, Behavior, and Exposure enrichment, retrieving assets and exposures information drawn from Expanse’s unparalleled view of the Internet.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Expanse
Configuration parameters
- api_key — API Key (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- behavior — Include Behavior data in incidents
- page_limit — How many events to pull from Expander per run
- first_run — How many days to pull past events on first run
- minimum_severity — Minimum severity of Expanse Exposure to create an incident for
Commands (6)
- domain — Submits a domain to check.
- expanse-get-behavior — Returns Risky Flows for the specified IP address. The maximum number of results is 20.
- expanse-get-certificate — Returns information about the domain certificate.
- expanse-get-domains-for-certificate — Returns all domains which have been seen with the specified certificate.
- expanse-get-exposures — Deprecated command by Expanse. Returns exposure information about the ip.
- ip — Submits an IP address to check.