Unit 42 Threat Intelligence by Palo Alto Networks (v1.0.25)

Use the Unit 42 Threat Intelligence by Palo Alto Networks integrations to enrich indicators with threat intelligence data and fetch threat intelligence feeds.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Data Enrichment & Threat Intelligence

Integrations (2)

README

Unit 42 Threat Intelligence by Palo Alto Networks

This pack provides the Unit 42 Intelligence integration and the Unit 42 Feed integration, delivering high-fidelity threat intelligence curated by the Unit 42 team and derived from telemetry across the Palo Alto Networks product ecosystem.

Built by Unit 42, Palo Alto Networks’ threat research organization, this pack brings world-class research, adversary expertise, and at-scale telemetry together to enrich investigations and automate high-quality indicator ingestion.

What does this pack do?

The Unit 42 Threat Intelligence content pack includes integrations that allow you to:

Prerequisites

Integrations

Unit 42 Intelligence

An enrichment integration that provides threat intelligence lookups for indicators. This integration replaces the deprecated AutoFocus V2 integration with enhanced capabilities and improved context quality.

Supported Commands:

Key Features:

Unit 42 Feed

A read-only feed integration that continuously fetches indicators and threat objects (plus their relationships) from Unit 42 data sources. When relationship creation is enabled, relationships between ingested indicators and threat objects are created in your tenant based on the feed data.

Setup

  1. Install the Unit 42 by Palo Alto Networks content pack
  2. Configure the Unit 42 Intelligence integration
  3. Configure the Unit 42 Feed integration if you need indicator feeds
  4. Test the integrations using the test commands

Use Cases

Support

This pack is supported by Cortex XSOAR. For technical support, please contact Palo Alto Networks support.