ThreatConnect Feed
This integration fetches indicators from ThreatConnect.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedThreatConnect
Configuration parameters
- tc_api_path — Base URL (required)
- api_credentials — Access ID (required)
- api_access_id — Access ID
- api_secret_key — Secret key
- fetch_limit — Indicators to get per fetch
- tags — Tags to filter results by
- owners — Owners
- feedIncremental — Incremental feed
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- indicator_type — Indicator types
- group_type — Group types
- indicator_active — Active Indicators Only
- createRelationships — Create Relationships
- indicator_query — Indicator Query
- use_indicator_query_for_group — Use Indicator Query For Group
- group_query — Group Query
- confidence — Confidence Threshold
- threat_assess_score — Threat Assess Score Threshold
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- insecure — Trust any certificate (not secure)
- feedBypassExclusionList — Bypass exclusion list
- feedTags — Tags
Commands (2)
- tc-get-indicators — Gets indicators from ThreatConnect.
- tc-get-owners — Gets available indicators owners.