IntSights
Deprecated. Use Rapid7 Threat Command instead.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- IntSight
Configuration parameters
- server — Server URL (e.g. https://192.168.0.1) (required)
- credentials — Credentials (required)
- type — Alert type to fetch as incidents, allowed: "AttackIndication", "DataLeakage", "Phishing", "BrandSecurity", "ExploitableData", "VIP"
- severity_level — Minimum Alert severity level to fetch incidents incidents from, allowed values are: 'All', 'Low', 'Medium','High'(Setting to All will fetch all incidents)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- max_fetch — Max fetch
- incidentType — Incident type
- mssp_sub_account_id — Sub Account ID (MSSP accounts only)
Commands (21)
- intsights-add-comment-to-alert — Adds a comment to a specified alert.
- intsights-add-tag-to-alert — Adds a tag to the alert.
- intsights-alert-takedown-request — Requests an alert takedown.
- intsights-ask-the-analyst — Sends a question to the IntSights analyst about the requested alert.
- intsights-assign-alert — Assigns an alert.
- intsights-close-alert — Closes an alert
- intsights-get-alert-activities — Returns alert activities.
- intsights-get-alert-by-id — Returns the alert object by alert ID.
- intsights-get-alert-image — Returns an image of an alert by ID.
- intsights-get-alert-takedown-status — Returns the alert takedown status.
- intsights-get-alerts — Returns alerts.
- intsights-get-ioc-blocklist-status — Returns the status of the IOC block list.
- intsights-get-ioc-by-value — Searches for an exact IOC value.
- intsights-get-iocs — Returns count totals of the available IOCs.
- intsights-mssp-get-sub-accounts — Returns all Managed Security Service Provider's (MSSP) sub accounts.
- intsights-remove-tag-from-alert — Removes a tag from the specified alert.
- intsights-request-ioc-enrichment — Request and receive enrichment of an IOC.
- intsights-send-mail — Sends an email containing a question and details of the alert.
- intsights-unassign-alert — Unassigns an alert from a user.
- intsights-update-alert-severity — Changes the severity of a specified alert.
- intsights-update-ioc-blocklist-status — Updates the IOC block list status.