Intel471Credentials
Fetches leaked credentials from the Intel471 Credentials API and produces an indicator per credential. While building each indicator the integration also creates an associated incident.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedIntel471
Configuration parameters
- credentials — Username (required)
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- feed — Fetch indicators
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- max_fetch — Maximum items per fetch
- feedFetchInterval — Feed Fetch Interval
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedTags — Tags
- feedBypassExclusionList — Bypass exclusion list
- credential_set_name — Credential set name
- credential_set_id — Credential set id
- domain — Domain
- affiliation_group — Affiliation group
- password_strength — Password strength
- detected_malware — Detected malware
- girs — GIRs
Commands (1)
- intel471-credentials-get-indicators — Gets a preview of indicators that the feed would pull on the next run (no state is persisted).