ThreatMon Threat Feed
Fetches Indicators of Compromise (IOCs) from the ThreatMon IOC platform and ingests them into Cortex as indicators.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- ThreatMonThreatFeed
Configuration parameters
- url — Server URL (required)
- credentials — (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feed — Fetch indicators
- data_type — Data Type to Fetch
- limit — Maximum number of indicators per fetch
- collection_ids — Collection IDs
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedIncremental — Incremental Feed
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedBypassExclusionList — Bypass exclusion list
- feedTags — Tags
Commands (1)
- threatmon-get-indicators — Gets a sample of indicators from the ThreatMon feed. This command is used mainly for testing and debugging, and does not create indicators in the system.