Office 365 Feed
The Office 365 IP Address and URL web service is a read-only API provided by Microsoft to expose the URLs and IPs used by Office 365. The Office 365 Feed integration fetches indicators from the service, with which you can create a list (allow list, block list, EDL, etc.) for your SIEM or firewall service to ingest and apply to its policy rules.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedOffice365
Configuration parameters
- feed — Fetch indicators
- category — Category
- regions — Regions (required)
- services — Services (required)
- allow_germany — Allow Germany
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedTags — Tags
- feedBypassExclusionList — Bypass exclusion list
- enrichmentExcluded — Enrichment Excluded
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (1)
- office365-get-indicators — Gets indicators from the feed.