SOCRadar (v2.3.5)

Streamline remediation of alerts and incidents with enhanced multi-tenant capabilities. Easily manage and automate security operations across multiple tenants, including for enrichment threat intelligence, reputation checking, and IoC feeds

Author
SOCRadar Cyber Intelligence Inc.
Support
partner
Default data source
SOCRadarIncidentsV4
Categories
Analytics & SIEM

Incident fields (13)

Integrations (7)

Layouts (1)

Playbooks (1)

README

SOCRadar Pack

SOCRadar is a cloud-based external threat intelligence and digital risk protection platform. The platform has the automated capability of monitoring and processing data collected from internet (surface, deep and dark web sources), then turning this data into security intelligence as incidents and threat intelligence feeds (domain, IP, hash) to improve the existing detection/protection appliances of the customers.

What does this pack do?

SOCRadar Incidents

This pack allows you to integrate SOCRadar incidents with XSOAR. Automated integration fetches and populates incidents into XSOAR from SOCRadar platform along with all the details of the incident and leads XSOAR analyst to take relevant actions over the incidents such as:

SOCRadar Incidents v4

This pack allows you to integrate SOCRadar incidents with XSOAR. Automated integration fetches and populates incidents into XSOAR from SOCRadar platform along with all the details of the incident and leads XSOAR analyst to take relevant actions over the incidents such as:

In short, you can perform the actions that an analyst would need to do on SOCRadar platform while responding an incident.

In addition to the incident management, this pack also provides integrations with SOCRadar’s threat intelligence capabilities:

SOCRadar ThreatFusion

Enrich indicators by obtaining enhanced information and reputation via SOCRadar. Supported indicator types for the SOCRadar reputation query are as follow:

SOCRadar Rapid Reputation

Fast reputation checking for IPs, domains, URLs, and file hashes with bulk support:

Commands:

Use Cases:

SOCRadar IoC Enrichment

Deep threat intelligence enrichment with comprehensive context:

Commands:

Use Cases:

SOCRadar Threat Feed

Collection-based IoC feed integration for automated indicator ingestion:

Commands:

Configuration:

  1. Log in to SOCRadar platform
  2. Navigate to Threat Intelligence > Feeds section
  3. Create custom collections or use existing ones
  4. Copy collection UUID(s) from collection detail page
  5. Enter UUID(s) in integration configuration
  6. Configure fetch interval and limits
  7. Set TLP color and custom tags

Use Cases:

Prerequisites & Licensing

Depending on the integrations you intend to use, different licensing and activation steps apply:

1. Standard API Licensing

The following integrations are included with standard API licensing and require a standard SOCRadar API Key (obtainable from the SOCRadar platform via Settings → API Options / Keys):

2. Advanced Intelligence API (Add-on or Standalone)

SOCRadar Rapid Reputation and SOCRadar IoC Enrichment operate using the Advanced Intelligence API, which is optimized for high-volume, deep context, and fast reputation queries.

3. Multi-Tenant Usage

To use Multi-tenant Incident API, the Multi-tenant Incidents API must be enabled. You must contact the MSSP Enablement Team to activate this specific API for your account. To activate, please contact our support team at support@socradar.io.

Support

For Cortex XSOAR support, contact xsoar@socradar.io or visit https://socradar.io

Demo Video

SOCRadar in Cortex XSOAR