Palo Alto Networks Threat Vault v2 Feed
Retrieve Threat Vault predefined EDL content for Malicious IP, Known IP, TOR and Bulletproof hosting.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedThreatVault
Configuration parameters
- feed — Fetch indicators
- url — URL (required)
- credentials — API Key (required)
- name — Which EDL to pull indicators from (required)
- list_format — Response Format (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feedTags — Tags
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- limit — Page Size Limit
- feedBypassExclusionList — Bypass exclusion list
- tlp_color — Traffic Light Protocol Color
Commands (1)
- threatvault-get-indicators — Retrieves indicators from Threat Vault.