FalconIntel
Deprecated. Use CrowdStrike Falcon Intel v2 integration instead.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- CrowdStrikeIntel
Configuration parameters
- url — Server URL (e.g. https://192.168.0.1) (required)
- id — API ID (required)
- key — API Key (required)
- threshold — Indicator Threshold. Minimum malicious confidence from Falcon Intel to consider the indicator malicious.(low, medium, high)
- useproxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- version — Support indicator API V2
Commands (8)
- cs-actors — Search known actors based on the given parameters. Dates are formatted as YYYY-MM-DD. Max date is taken automatically looking at end-of-day time. Origins, targetCountries, targetIndustries and motivations can all receive multiple values separated by ",". Offset is 0 based. Sort is field_name.order, field_name.order where order is either asc or desc.
- cs-indicators — Search known indicators based on the given parameters
- cs-report-pdf — Retrieve the Falcon Intel Report PDF
- cs-reports — The Falcon Intel Reports API allows to query CrowdStrike intelligence publications.
- domain — Check the given URL reputation
- file — Check file reputation
- ip — Check IP reputation
- url — Check the given URL reputation