Intel471 Malware Indicator Feed
Intel471's Malware Intelligence is focused on the provisioning of a high fidelity and timely indicators feed with rich context, TTP information, and malware intelligence reports. This feed allows customers to block and gain an understanding of the latest crimeware campaigns and is for those that value timeliness, confidence (little to no false positives), and seek rich context and insight around the attacks they are seeing.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedIntel471
Configuration parameters
- intel471_backend — Intel 471 backend (required)
- feed — Fetch indicators
- credentials — Username
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- indicator_type — Indicator Type (required)
- malware_family — Malware Family
- confidence — Search by confidence
- indicator — Free text indicator search (all fields included)
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- feedTags — Tags
- feedBypassExclusionList — Bypass exclusion list
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- create_relationships — Create relationships
Commands (1)
- intel471-indicators-get-indicators — Gets the feed indicators.