category: Data Enrichment & Threat Intelligence provider: Accenture commonfields: id: ACTI Indicator Query version: -1 sectionorder: - Connect - Collect configuration: - display: URL name: url defaultvalue: https://api.intelgraph.idefense.com/ type: 0 required: true section: Connect - displaypassword: API Token additionalinfo: The API Token to use for connection name: api_token type: 9 required: true hiddenusername: true section: Connect - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: use_proxy type: 8 required: false section: Connect description: ACTI provides intelligence regarding security threats and vulnerabilities. display: ACTI Indicator Query name: ACTI Indicator Query script: commands: - name: ip arguments: - name: ip default: true description: IP address to check. isArray: true outputs: - contextPath: IP.Address description: The IP address that was checked. type: String - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: String - contextPath: IP.Malicious.Description description: For malicious IP addresses, the reason the vendor made that decision. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: String description: Checks the reputation of the given IP address. - name: domain arguments: - name: domain default: true description: The domain to check. isArray: true outputs: - contextPath: Domain.Name description: The name of the domain that was checked. type: String - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: String - contextPath: Domain.Malicious.Description description: For malicious domains, the reason the vendor made that decision. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number description: Checks the reputation of the given domain. - name: url arguments: - name: url default: true description: The URL to check (must start with "http://"). isArray: true outputs: - contextPath: URL.Data description: The URL that was checked. type: String - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: String - contextPath: URL.Malicious.Description description: For malicious URLs, the reason the vendor made that decision. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number description: Checks the reputation of the given URL. - name: acti-get-ioc-by-uuid description: Checks reputation of a specific indicator(URL/IP/Domain) uuid. arguments: - name: uuid required: true description: Unique User ID. outputs: - contextPath: IP.Address description: The IP address. type: String - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: String - contextPath: IP.Malicious.Description description: For malicious IP addresses, the reason the vendor made that decision. type: String - contextPath: Domain.Name description: The domain name. type: String - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: String - contextPath: Domain.Malicious.Description description: For malicious domains, the reason the vendor made that decision. type: String - contextPath: URL.Data description: The URL. type: String - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: String - contextPath: URL.Malicious.Description description: For malicious URLs, the reason the vendor made that decision. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - name: acti-get-fundamentals-by-uuid description: Checks reputation of a specific Malware Family/ Threat Campaign/ Threat Group/ Threat Actor. arguments: - name: uuid required: true default: true description: Unique ID of the specific Malware Family/ Threat Campaign/ Threat Group/ Threat Actor. outputs: - contextPath: ACTI_MalwareFamily.display_text description: The display text of the Malware Family, for example, 'Artemis'. type: String - contextPath: ACTI_MalwareFamily.threat_types description: The threat type of the Malware Family. type: String - contextPath: ACTI_MalwareFamily.type description: The type of fundamental i.e. an Malware Family , for example, 'malware_family'. type: String - contextPath: ACTI_MalwareFamily.last_published description: The last published date of the Malware Family, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_MalwareFamily.last_modified description: The last modified date of the Malware Family, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_MalwareFamily.index_timestamp description: The index timestamp of the Malware Family, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_MalwareFamily.created_on description: The creation timestamp of the Malware Family, for example, '2020-03-12T22:22:25.000Z'. type: String - contextPath: ACTI_MalwareFamily.description description: The description of the Malware Family. type: String - contextPath: ACTI_MalwareFamily.analysis description: The analysis of the Malware Family. type: String - contextPath: ACTI_ThreatGroup.display_text description: The display text of the Threat Group, for example, 'Black Shadow'. type: String - contextPath: ACTI_ThreatGroup.threat_types description: The threat type of the Threat Group. type: String - contextPath: ACTI_ThreatGroup.type description: The type of fundamental i.e. an Threat Group, for example, 'threat_group'. type: String - contextPath: ACTI_ThreatGroup.last_published description: The last published date of the Threat Group, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatGroup.last_modified description: The last modified date of the Threat Group, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatGroup.index_timestamp description: The index timestamp of the Threat Group, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatGroup.created_on description: The creation timestamp of the Threat Group, for example, '2020-03-12T22:22:25.000Z'. type: String - contextPath: ACTI_ThreatGroup.description description: The description of the Threat Group. type: String - contextPath: ACTI_ThreatGroup.analysis description: The analysis of the Threat Group. type: String - contextPath: ACTI_ThreatActor.display_text description: The display text of the Threat Actor, for example, 'RastaFarEye'. type: String - contextPath: ACTI_ThreatActor.threat_types description: The threat type of the Threat Actor. type: String - contextPath: ACTI_ThreatActor.type description: The type of fundamental i.e. an Threat Actor, for example, 'threat_actor'. type: String - contextPath: ACTI_ThreatActor.last_published description: The last published date of the Threat Actor, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatActor.last_modified description: The last modified date of the Threat Actor, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatActor.index_timestamp description: The index timestamp of the Threat Actor, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatActor.created_on description: The creation timestamp of the Threat Actor, for example, '2020-03-12T22:22:25.000Z'. type: String - contextPath: ACTI_ThreatActor.description description: The description of the Threat Actor. type: String - contextPath: ACTI_ThreatActor.analysis description: The analysis of the Threat Actor. type: String - contextPath: ACTI_ThreatCampaign.display_text description: The display text of the Threat Campaign, for example, 'FBI Flash CU-000141-MW'. type: String - contextPath: ACTI_ThreatCampaign.threat_types description: The threat type of the Threat Campaign. type: String - contextPath: ACTI_ThreatCampaign.type description: The type of fundamental i.e. an Threat Campaign , for example, 'threat_campaign'. type: String - contextPath: ACTI_ThreatCampaign.last_published description: The last published date of the Threat Campaign, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatCampaign.last_modified description: The last modified date of the Threat Campaign, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatCampaign.index_timestamp description: The index timestamp of the Threat Campaign, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: ACTI_ThreatCampaign.created_on description: The creation timestamp of the Threat Campaign, for example, '2020-03-12T22:22:25.000Z'. type: String - contextPath: ACTI_ThreatCampaign.description description: The description of the Threat Campaign. type: String - contextPath: ACTI_ThreatCampaign.analysis description: The analysis of the Threat Campaign. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - name: acti-getThreatIntelReport description: Fetches Intelligence Alerts & Intelligence Reports. arguments: - name: uuid default: true description: uuid of Intelligence Alert/Report (IA/IR) in the ACTI IntelGraph platform. required: true outputs: - contextPath: IAIR.abstract description: This field is specific to Intelligence Alert and provides a summarised context, for example, 'The worldwide COVID-19 outbreak...'. type: String - contextPath: IAIR.last_published description: The last published timestamp of the IA/IR, for example, '2020-06-26T01:14:56.000Z'. type: String - contextPath: IAIR.index_timestamp description: The index timestamp of the IA/IR, for example, '2022-02-11T17:24:03.604Z'. type: String - contextPath: IAIR.display_text description: The display text of the IA/IR, for example, 'SITREP Cybersecurity Risks Related to COVID-19'. type: String - contextPath: IAIR.value description: The value of the IA/IR, for example, '8b8b48f1-92a0-411a-a073-3241f6819f8b'. type: String - contextPath: IAIR.last_modified description: The last modified timestamp of the IA/IR, for example, '2022-02-11T17:21:48.000Z'. type: String - contextPath: IAIR.threat_types description: The threat type of the IA/IR, for example, '- Hacktivism- Cyber Espionage- Cyber Crime- Vulnerability'. It's formatted in such a way that it gets displayed better. type: String - contextPath: IAIR.created_on description: The creation timestamp of the IA/IR, for example, '2020-03-12T22:22:25.000Z'. type: String - contextPath: IAIR.title description: The title of the IA/IR, for example, 'SITREP Cybersecurity Risks Related to COVID-19'. type: String - contextPath: IAIR.type description: The type of report i.e. an IA/IR , for example, 'intelligence_alert'. type: String - contextPath: IAIR.uuid description: The uuid of the IA/IR, for example, '8b8b48f1-92a0-411a-a073-3241f6819f8b'. type: String - contextPath: IAIR.analysis description: The analysis of the IA/IR, for example, 'COVID-19 Introduces Cyberthreat Opportunities...'. type: String - contextPath: IAIR.attachment_links description: Provides with the document links related to the Intelligence Alert. This field is specific to Intelligence Alert, for example, 'https://intelgraph.idefense.com/rest/files/download/...'. type: String - contextPath: IAIR.severity description: Provides severity rating. This field is specific to Intelligence Alert, for example, '4'. type: String - contextPath: IAIR.mitigation description: Provides info on how to mitigate. This field is specific to Intelligence Alert, for example, '## Expert, Experienced Advice Will be CriticalTo minimize targeting opportunities...'. type: String - contextPath: IAIR.conclusion description: Provides conclusion of the report. This field is specific to Intelligence Report. type: String - contextPath: IAIR.summary description: Provides with a summary of the report. This field is specific to Intelligence Report. type: String - contextPath: IAIR.dynamic_properties description: Provides with the dynamic properties related to the intelligence alert/report. type: String - contextPath: IAIR.links description: Provides details of the linked fields related to the intelligence alert/report. type: String - contextPath: IAIR.sources_external description: Provides with external sources related to the intelligence alert/report. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor that was used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: String dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python fromversion: 5.5.0 tests: - ACTI Indicator Query Test