SOCRadarIncidents
Fetches SOCRadar incidents with desired parameters so that relevant actions over the incidents can be taken by using Cortex XSOAR.
- Category
- Analytics & SIEM
- Pack
- SOCRadar
Configuration parameters
- apikey — (required)
- isFetch — Fetch incidents
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- first_fetch — First Fetch Time
- socradar_company_id — Company ID (required)
- severity — Severity Level
- max_fetch — Maximum number of incidents to fetch
- resolution_status — Resolution Status
- fp_status — FP Status
- incident_main_type — Incident Main Type
- incident_sub_type — Incident Sub Type
- include_company_id — Include Company ID
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
Commands (2)
- socradar-mark-incident-fp — Marks incident as false positive in SOCRadar platform.
- socradar-mark-incident-resolved — Marks incident as resolved in SOCRadar platform.