Mandiant Advantage Threat Intelligence
Enrich Indicators of Compromise, and fetch information about Actors, Malware Families, and Campaigns from Mandiant Advantage.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- MandiantAdvantageThreatIntelligence
Configuration parameters
- api_base_url — API Base URL
- api_key — API Key (required)
- secret_key — Secret Key (required)
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedMinimumConfidence — Feed Minimum Confidence Score (required)
- feedExcludeOSIntel — Feed Exclude Open Source Intelligence
- type — Mandiant indicator type
- first_fetch — First fetch time
- max_fetch — Maximum number of indicators per fetch
- feedTags — Tags
- timeout — Timeout
- feedBypassExclusionList — Bypass exclusion list
- indicatorMetadata — Retrieve indicator metadata
- indicatorRelationships — Create relationships
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (10)
- cve — Retrieve information about a Vulnerability (by CVE) from Mandiant.
- domain — Retrieve information about an FQDN from Mandiant.
- file — Retrieve information about a File Hash from Mandiant.
- ip — Retrieve information about an IP Address from Mandiant.
- mati-feed-get-indicators — Get Mandiant Indicators.
- mati-get-actor — Get information about a Threat Actor from Mandiant.
- mati-get-campaign — Retrieve information about a Campaign from Mandiant.
- mati-get-indicator — Get information about a single Indicator of Compromise (IP Address, FQDN, URL, or File Hash) from Mandiant.
- mati-get-malware — Get information about a Malware Family from Mandiant.
- url — Retrieve information about a URL from Mandiant.