GoogleThreatIntelligenceDTMAlerts
This integration allows the creation of incidents based on DTM Alerts from Google Threat Intelligence.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- GoogleThreatIntelligence
Configuration parameters
- credentials — (required)
- isFetch — Fetch incidents
- max_fetch — Max Fetch
- first_fetch — First Fetch Time
- mirror_direction — Mirroring Direction
- alert_type — Alert Type
- alert_monitor_ids — Alert Monitor ID
- alert_status — Alert Status
- alert_severity — Alert Severity
- alert_tags — Alert Tags
- alert_match_value — Alert Match Value
- alert_mscore_gte — Alert mscore
- alert_search — Alert Search
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
Commands (3)
- gti-dtm-alert-get — Get a particular DTM Alert by ID.
- gti-dtm-alert-list — Search the DTM Alerts with provided filter arguments.
- gti-dtm-alert-status-update — Update the status of DTM alert.