InfobloxBloxOneThreatDefense
Infoblox Threat Defense with DDI integration leverages DNS as the first line of defense to detect and block cyber threats, while also using threat intelligence to manage SOC Insight incident response and enrich indicators.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- InfobloxBloxOne
Configuration parameters
- credentials — (required)
- integrationReliability — Source Reliability
- create_relationships — Create relationships
- isFetch — Fetch incidents
- incidentType — Incident type
- ingestion_type — Ingestion Type
- soc_insight_status — SOC Insight Status
- soc_insight_threat_type — SOC Insight Threat Type
- soc_insight_priority_level — SOC Insight Priority Level
- dns_events_feed_name — DNS Security Event Feed Name
- dns_events_network — DNS Security Event Network
- dns_events_policy_action — DNS Security Event Policy Action
- dns_events_policy_name — DNS Security Event Policy Name
- dns_events_queried_name — DNS Security Event Queried Name
- dns_events_threat_class — DNS Security Event Threat Class
- dns_events_threat_family — DNS Security Event Threat Family
- dns_events_threat_indicator — DNS Security Event Threat Indicator
- dns_events_threat_level — DNS Security Event Threat Level
- max_fetch — Max Fetch
- first_fetch — First fetch timestamp
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (17)
- bloxone-td-dossier-lookup-get — The Dossier Lookup API returns detailed information on the specified indicator from the requested sources.
- bloxone-td-dossier-source-list — Get available Dossier sources.
- bloxone-td-lookalike-domain-list — Get lookalike domain lists.
- domain — Gets the comprehensive domain/host reputation and threat intelligence from Infoblox Threat Defense, including threat indicators, IPAM address information and standard domain reputation data.
- infobloxcloud-block-domain — The given domains will be added to the provided block list.
- infobloxcloud-block-ip — The given IP addresses will be added to the provided block list.
- infobloxcloud-customlist-indicator-remove — The given indicators will be removed from the provided custom list.
- infobloxcloud-mac-enrich — Enrich a MAC address with DHCP lease information.
- infobloxcloud-soc-insight-asset-list — List assets for a specific SOC Insight.
- infobloxcloud-soc-insight-comment-list — List comments for a specific SOC Insight.
- infobloxcloud-soc-insight-event-list — List events for a specific SOC Insight.
- infobloxcloud-soc-insight-indicator-list — List indicators for a specific SOC Insight.
- infobloxcloud-soc-insight-list — List SOC Insights from Infoblox Cloud.
- infobloxcloud-unblock-domain — The given domains will be added to the provided allow list.
- infobloxcloud-unblock-ip — The given IP addresses will be added to the provided allow list.
- ip — Gets the comprehensive IP reputation and threat intelligence from Infoblox Threat Defense, including threat indicators, IPAM address information, and standard IP reputation data.
- url — Gets the comprehensive URL reputation and threat intelligence from Infoblox Threat Defense, including threat indicators, and standard URL reputation data.