Recorded Future Feed
Ingests indicators from Recorded Future feeds into Demisto.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedRecordedFuture
Configuration parameters
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedBypassExclusionList — Bypass exclusion list
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- indicator_type — Indicator Type (required)
- api_token — API token
- credentials_api_token —
- services — Services (required)
- risk_rule — Risk Rule
- fusion_file_path — Fusion File Path
- feedTags — Tags
- polling_timeout — Request Timeout (required)
- threshold — Malicious Threshold
- suspicious_threshold — Suspicious Threshold
- risk_score_threshold — IOC Risk Score Threshold
- performance — Remove rawJSON from indicators
Commands (2)
- rf-feed-get-indicators — Gets indicators from the feed.
- rf-feed-get-risk-rules — Get a list of the risk rules available for an indicator, To limit the 'connectApi' service indicators list.