Darkmon (v1.0.1)

Stay ahead of cyber threats with Darkmon TIP - real-time threat intelligence from the Clear, Deep, and Dark Web tailored to your assets. The pack provides indicator enrichment, compromised-credentials monitoring, board-level VIP email protection, ransomware mention tracking, brand-targeting NRD detection, and critical CVE pipelines, plus provider-agnostic incident response playbooks ready to plug into any SOC stack.

Author
Darkmon
Support
developer
URL
https://darkmon.com
Categories
Data Enrichment & Threat Intelligence

Incident fields (24)

Indicator fields (5)

Integrations (2)

Jobs (6)

Layouts (12)

Lists (14)

Playbooks (20)

Scripts (6)

README

Darkmon Threat Intelligence Pack

Stay ahead of cyber threats with Darkmon TIP - real-time threat intelligence
from the Clear, Deep, and Dark Web, tailored to your assets and operationalized
inside Cortex XSOAR.

What’s in the box

This is an end-to-end content pack, not just an integration. It ships
everything a SOC team needs to put Darkmon intelligence into action.

Integration

Indicator enrichment (sub-playbooks)

These are wired into XSOAR’s reputation system via DBotScore + Common.<Type>
contracts so they slot into any existing playbook with no rewrites.

Continuous monitoring

Each ships with its own incident type, layout, dedup pre-process rule, and a
List of tunables (customer domains, brand names, tech stack, severity rules)
so multi-tenant deployments customize without forking.

Incident response

These response playbooks call provider-agnostic switchboard sub-playbooks so
they work whatever your stack looks like.

Provider-agnostic adapters (Tier 4)

Quick start

  1. Install this pack from the Cortex Marketplace.
  2. Open Settings → Integrations → Darkmon and click Add instance.
  3. Paste your Darkmon API key. Leave API Base URL at the default unless
    instructed otherwise.
  4. Click the Test button on the instance configuration page. Expect “Success”.

For full configuration, command examples, and playbook docs, see the
per-artifact READMEs under each subfolder.

Compliance posture

The pack defaults to GDPR-strict + secrets redaction. Passwords, card
numbers, and SSNs never appear in War Room markdown unless the integration’s
redact_secrets toggle is explicitly set to false. Raw values remain
available to playbooks via rawJSON so automation isn’t blocked.

Support

This pack is maintained by Darkmon as a developer-supported pack.
Visit darkmon.com or contact support@darkmon.com.

Versioning

Semantic versioning. See ReleaseNotes/ for change history.