SymantecICDM
Query the Symantec Endpoint Security Cloud Portal (ICDM).
- Category
- Data Enrichment & Threat Intelligence
- Pack
- SymantecICDM
Configuration parameters
- integrationReliability — Source Reliability (required)
- url — Server URL (e.g. https://api.sep.securitycloud.symantec.com) (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- max_fetch — Maximum number of incidents per fetch
- credentials — (required)
- first_fetch — First fetch time
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentFetchInterval — Incidents Fetch Interval
- ignored_domains — Ignore Domains (e.g. domain.local)
- ignore_private_ip — Ignore Private IPs (e.g. 192.168.0.1)
Commands (7)
- domain — Get reputation for given domain.
- file — Get file reputation for given SHA256.
- ip — Get ip reputation.
- symantec-protection-cve — Get returns information whether a given CVE has been blocked by any Symantec technologies.
- symantec-protection-file — Get information whether a given file has been blocked by any Symantec technologies.
- symantec-protection-network — Get information whether given domain or ip has been blocked by any Symantec technologies.
- url — Get reputation for given url.