ZeroFox
Cloud-based SaaS to detect risks found on social media and digital channels.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- ZeroFox
Configuration parameters
- url — URL (e.g., https://api.zerofox.com/) (required)
- credentials — Username (required)
- only_escalated — Fetch only escalated alerts
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- fetch_limit — Fetch Limit
- incidentFetchInterval — Incidents Fetch Interval
- isFetch — Fetch incidents
- incidentType — Incident type
Commands (22)
- zerofox-alert-cancel-takedown — Cancels a takedown of a specified alert.
- zerofox-alert-request-takedown — Requests a takedown of a specified alert.
- zerofox-alert-user-assignment — Assigns an alert to a user.
- zerofox-close-alert — Closes an alert.
- zerofox-create-entity — Creates a new entity associated with the company of the authorized user.
- zerofox-get-alert — Fetches an alert by ID.
- zerofox-get-alert-attachments — Retrieves the attachments of a specified alert.
- zerofox-get-compromised-credentials — Gets compromised credentials data for a given ZeroFox alert and uploads it to the current investigation War Room.
- zerofox-get-entity-types — Shows a table of all entity type names and IDs in the War Room.
- zerofox-get-policy-types — Shows a table of all policy type names and IDs in the War Room.
- zerofox-list-alerts — Returns alerts that match user-defined or default filters and parameters. By default, no filters are applied and the results are sorted by timestamp.
- zerofox-list-entities — Lists all entities associated with the company of the authorized user.
- zerofox-modify-alert-notes — Modify the notes of a specified alert.
- zerofox-modify-alert-tags — Adds tags to and or removes tags from a specified alert.
- zerofox-open-alert — Opens an alert.
- zerofox-search-compromised-domain — Looks for a given domain in Zerofox's CTI feeds.
- zerofox-search-compromised-email — Looks for a given email in ZeroFox's CTI feeds.
- zerofox-search-exploits — Looks for registered exploits in ZeroFox's CTI feeds.
- zerofox-search-malicious-hash — Looks for registered hashes in ZeroFox's CTI feeds.
- zerofox-search-malicious-ip — Looks for malicious ips in ZeroFox's CTI feeds.
- zerofox-send-alert-attachment — Sends an attachment to a specified alert.
- zerofox-submit-threat — Submits potential threats into the ZF alert registry for disruption.