Threatmon
Integration with Threatmon for vulnerability threat intelligence.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- ThreatMon
Configuration parameters
- url — API URL (required)
- credentials — (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- lastIncidentId — Last Incident ID (for initial fetch)
- incidentType — Incident type
- isFetch — Fetch incidents
- fetchInterval — Fetch Interval (minutes)
- incidentFetchInterval — Incidents Fetch Interval
Commands (5)
- threatmon_list_cves — Retrieves a paginated list of all CVEs monitored by ThreatMon.
- threatmon_list_subscribed_cves — Retrieves a paginated list of CVEs affecting products that the authenticated company (or a specified child customer) is actively subscribed to.
- threatmon_request_data_removal — Submits a Black Market Monitoring data removal request for a specific ThreatMon finding. Requires the company to have remaining Black Market Data Removal credits. Returns 403 if the quota is exceeded or rights are insufficient.
- threatmon_request_takedown — Submits a takedown request for a specific Threatmon finding. Eligible finding types include Phishing Domain Detected, Rogue Mobile App Detected, Fake SM Account Detected, and similar alarm types.
- threatmon_update_incident_status — Update Incident Status endpoint allows you to change/update status. of specified Threatmon incidents.