Cisco Secure Malware Analytics (v2.0.32)
Query and upload samples to Cisco threat grid.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Categories
- Forensics & Malware Analysis
Integrations (3)
- Cisco Secure Malware Analytics Feed
- Cisco Threat Grid (Deprecated)
- Cisco Secure Malware Analytics (Threat Grid) v2
Playbooks (4)
- Detonate File - ThreatGrid
- Detonate File - ThreatGrid v2
- Detonate URL - ThreatGrid
- Detonate URL - ThreatGrid v2
README
Use this pack to fetch, manage, and query threat feeds and samples.
What does this pack do?
- The Feed integration fetches indicators from Cisco Secure Malware Analytics (Threat Grid). When setting up this integration, select from which feeds to fetch indicators (for example: modified-hosts-dns, public-ip-check-dns, ransomware-dns, etc.).
- The Cisco Threat Grid integration enables you to query and upload samples to Cisco’s threat grid.
- The playbooks enable detonating one or more files or URLs. The playbooks return relevant reports to the War Room and file/URL reputations to the context data.