Group-IB Digital Risk Protection
Pack helps to integrate Group-IB Digital Risk Protection and get violations incidents directly into Cortex XSOAR.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- GroupIB_DigitalRiskProtection
Configuration parameters
- url — GIB DRP URL (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentFetchInterval — Incidents Fetch Interval
- credentials — Username (required)
- violationSection — Filter by Violation Type
- brands — Filter by Brand
- first_fetch — Incidents first fetch
- download_images — Download images
- only_typosquatting — Get Typosquatting Only
- max_fetch — Number of requests per collection (required)
Commands (4)
- gibdrp-change-violation-status — Changing the status of a single violation.
- gibdrp-get-brands — Receive all configured brands.
- gibdrp-get-subscriptions — Receive all configured subscriptions.
- gibdrp-get-violation-by-id — Getting a single violation by its ID.