PhishLabs IOC
Get indicators of compromise from PhishLabs.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- PhishLabs
Configuration parameters
- url — Server URL (e.g., https://ioc.phishlabs.com) (required)
- credentials — Username (required)
- integrationReliability — Source Reliability (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- fetch_time — Fetch for this time period, e.g., "1d", "1h", "10m". The default is 1h.
- fetch_limit — Number of incidents to fetch each time
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
Commands (2)
- phishlabs-get-incident-indicators — Retrieves indicators from a speicifed PhishLabs incident. To fetch incidents to Demisto, enable fetching incidents.
- phishlabs-global-feed — Retrieves the global IOC feed from PhishLabs.