category: Data Enrichment & Threat Intelligence provider: Anomali sectionorder: - Connect - Collect commonfields: id: Anomali ThreatStream v3 version: -1 configuration: - defaultvalue: https://api.threatstream.com display: Server URL (e.g., https://www.test.com) name: url required: true type: 0 section: Connect - display: Username name: credentials required: true type: 9 displaypassword: API Key section: Connect - display: URL threshold name: url_threshold type: 0 section: Collect advanced: true required: false - display: IP threshold name: ip_threshold type: 0 section: Collect advanced: true required: false - display: Domain threshold name: domain_threshold type: 0 section: Collect advanced: true required: false - display: File threshold name: file_threshold type: 0 section: Collect advanced: true required: false - display: Email threshold additionalinfo: Email indicators with confidence value above this threshold are considered malicious. name: email_threshold type: 0 section: Collect advanced: true required: false - defaultvalue: 'false' additionalinfo: Whether to include inactive indicators in reputation commands. display: Include inactive results name: include_inactive type: 8 section: Collect advanced: true required: false - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: false type: 15 section: Collect - defaultvalue: Benign display: Default DBOT score for indicators with low confidence name: indicator_default_score options: - Benign - Unknown required: false type: 15 section: Collect - defaultvalue: 'false' display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - defaultvalue: 'true' additionalinfo: Create relationships between indicators as part of enrichment. display: Create relationships name: create_relationships type: 8 section: Collect advanced: true required: false - additionalinfo: Gather additional information about the threat model from remote APIs. defaultvalue: 'false' display: Remote API name: remote_api required: false type: 8 section: Collect defaultclassifier: 'null' description: Use Anomali ThreatStream to query and submit threats. display: Anomali ThreatStream v3 name: Anomali ThreatStream v3 script: commands: - arguments: - default: true description: The IP to check. isArray: true name: ip required: true - description: If confidence is greater than the threshold the IP address is considered malicious, otherwise it is considered good. This argument overrides the default IP threshold defined as a parameter. name: threshold - auto: PREDEFINED description: Whether to include results with an inactive status. name: include_inactive predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: 'Enhance generic reputation commands to include additional information such as Threat Bulletins, Attach patterns, Actors, Campaigns, TTPs, vulnerabilities, etc. Note: If set to true, additional 6 API calls will be performed.' name: threat_model_association predefined: - 'True' - 'False' description: Checks the reputation of the given IP address. name: ip outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: IP.ASN description: The Autonomous System (AS) number associated with the indicator. type: String - contextPath: IP.Address description: The IP address of the indicator. type: String - contextPath: IP.Geo.Country description: The country associated with the indicator. type: String - contextPath: IP.Geo.Location description: The longitude and latitude of the IP address. type: String - contextPath: ThreatStream.IP.ASN description: The Autonomous System (AS) number associated with the indicator. type: String - contextPath: ThreatStream.IP.Address description: The IP address of the indicator. type: String - contextPath: ThreatStream.IP.Country description: The country associated with the indicator. type: String - contextPath: ThreatStream.IP.Type description: The indicator type. type: String - contextPath: ThreatStream.IP.Modified description: 'The time the indicator was last updated. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time.' type: String - contextPath: ThreatStream.IP.Severity description: The indicator severity ("very-high", "high", "medium", or "low"). type: String - contextPath: ThreatStream.IP.Confidence description: The observable certainty level of a reported indicator type. Confidence score can range from 0-100, in increasing order of confidence. type: String - contextPath: ThreatStream.IP.Status description: The status assigned to the indicator. type: String - contextPath: ThreatStream.IP.Organization description: The name of the business that owns the IP address associated with the indicator. type: String - contextPath: ThreatStream.IP.Source description: The indicator source. type: String - contextPath: IP.Malicious.Vendor description: The vendor that reported the indicator as malicious. type: String - contextPath: ThreatStream.IP.Tags description: Tags assigned to the IP. type: Unknown - contextPath: ThreatStream.IP.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: IP.Tags description: List of IP tags. type: Unknown - contextPath: IP.ThreatTypes description: Threat types associated with the IP. type: Unknown - contextPath: ThreatStream.IP.Actor.assignee_user description: The assignee user of the threat actor. type: Unknown - contextPath: ThreatStream.IP.Actor.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.IP.Actor.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.IP.Actor.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.IP.Actor.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.IP.Actor.created_ts description: The date the threat actor was created. type: Date - contextPath: ThreatStream.IP.Actor.feed_id description: The feed ID of the threat actor. type: Number - contextPath: ThreatStream.IP.Actor.id description: The ID of the threat actor. type: Number - contextPath: ThreatStream.IP.Actor.is_anonymous description: Whether the threat actor is anonymous. type: Boolean - contextPath: ThreatStream.IP.Actor.is_cloneable description: Whether the threat actor is cloneable. type: String - contextPath: ThreatStream.IP.Actor.is_public description: Whether the threat actor is public. type: Boolean - contextPath: ThreatStream.IP.Actor.is_team description: Whether the threat actor is a team. type: Boolean - contextPath: ThreatStream.IP.Actor.modified_ts description: The date the threat actor was modified. type: Date - contextPath: ThreatStream.IP.Actor.name description: The name of the threat actor. type: String - contextPath: ThreatStream.IP.Actor.organization_id description: The organization ID of the threat actor. type: Number - contextPath: ThreatStream.IP.Actor.owner_user_id description: The owner user ID of the threat actor. type: Number - contextPath: ThreatStream.IP.Actor.primary_motivation description: The primary motivation of the threat actor. type: Unknown - contextPath: ThreatStream.IP.Actor.publication_status description: The publication status of the threat actor. type: String - contextPath: ThreatStream.IP.Actor.published_ts description: The date the threat actor was published. type: Date - contextPath: ThreatStream.IP.Actor.resource_level description: The resource level of the threat actor. type: Unknown - contextPath: ThreatStream.IP.Actor.resource_uri description: The resource URI of the threat actor. type: String - contextPath: ThreatStream.IP.Actor.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.IP.Actor.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.IP.Actor.start_date description: The start date. type: Unknown - contextPath: ThreatStream.IP.Actor.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.IP.Actor.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.IP.Actor.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.IP.Actor.tlp description: The TLP of the threat actor. type: String - contextPath: ThreatStream.IP.Actor.uuid description: The UUID of the threat actor. type: String - contextPath: ThreatStream.IP.Signature.assignee_user description: The assignee user of the signature. type: Unknown - contextPath: ThreatStream.IP.Signature.association_info.comment description: The comment in the association info of the signature. type: Unknown - contextPath: ThreatStream.IP.Signature.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.IP.Signature.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.IP.Signature.can_add_public_tags description: Whether you can add public tags to the signature. type: Boolean - contextPath: ThreatStream.IP.Signature.created_ts description: The date the signature was created. type: Date - contextPath: ThreatStream.IP.Signature.feed_id description: The feed ID of the signature. type: Number - contextPath: ThreatStream.IP.Signature.id description: The ID of the signature. type: Number - contextPath: ThreatStream.IP.Signature.is_anonymous description: Whether the signature was anonymous. type: Boolean - contextPath: ThreatStream.IP.Signature.is_cloneable description: Whether the signature is cloneable. type: String - contextPath: ThreatStream.IP.Signature.is_public description: Whether the signature is public. type: Boolean - contextPath: ThreatStream.IP.Signature.is_team description: Whether the signature is a team signature. type: Boolean - contextPath: ThreatStream.IP.Signature.modified_ts description: The date the signature was modified. type: Date - contextPath: ThreatStream.IP.Signature.name description: The name of the signature. type: String - contextPath: ThreatStream.IP.Signature.organization_id description: The organization ID of the signature. type: Number - contextPath: ThreatStream.IP.Signature.owner_user_id description: The owner user ID of the signature. type: Number - contextPath: ThreatStream.IP.Signature.primary_motivation description: The primary motivation of the signature. type: Unknown - contextPath: ThreatStream.IP.Signature.publication_status description: The publication status of the signature. type: String - contextPath: ThreatStream.IP.Signature.published_ts description: The date the signature was published. type: Date - contextPath: ThreatStream.IP.Signature.resource_level description: The resource level of the signature. type: Unknown - contextPath: ThreatStream.IP.Signature.resource_uri description: The resource URI of the signature. type: String - contextPath: ThreatStream.IP.Signature.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.IP.Signature.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.IP.Signature.start_date description: The start date. type: Unknown - contextPath: ThreatStream.IP.Signature.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.IP.Signature.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.IP.Signature.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.IP.Signature.tlp description: The TLP of the signature. type: String - contextPath: ThreatStream.IP.Signature.uuid description: The UUID of the signature. type: String - contextPath: ThreatStream.IP.ThreatBulletin.all_circles_visible description: Whether all of the circles are visible. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.assignee_org description: The assignee organization. type: String - contextPath: ThreatStream.IP.ThreatBulletin.assignee_org_id description: The assignee organization ID. type: String - contextPath: ThreatStream.IP.ThreatBulletin.assignee_org_name description: The assignee organization name. type: String - contextPath: ThreatStream.IP.ThreatBulletin.assignee_user description: The assignee user. type: String - contextPath: ThreatStream.IP.ThreatBulletin.assignee_user_id description: The assignee user ID. type: String - contextPath: ThreatStream.IP.ThreatBulletin.assignee_user_name description: The assignee user name. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.IP.ThreatBulletin.association_info.from_id description: The ID from which the association info is related. type: String - contextPath: ThreatStream.IP.ThreatBulletin.body_content_type description: The body content type. type: String - contextPath: ThreatStream.IP.ThreatBulletin.campaign description: The campaign of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.can_add_public_tags description: Whether you can add public tags. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.created_ts description: The date the threat bulletin was created. type: Date - contextPath: ThreatStream.IP.ThreatBulletin.feed_id description: The feed ID of the threat bulletin. type: Number - contextPath: ThreatStream.IP.ThreatBulletin.id description: The ID of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.is_anonymous description: Whether the threat bulletin is anonymous. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.is_cloneable description: Whether the threat bulletin is cloneable. type: String - contextPath: ThreatStream.IP.ThreatBulletin.is_editable description: Whether the threat bulletin is editable. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.is_email description: Whether the threat bulletin is an email. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.is_public description: Whether the threat bulletin is public. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.modified_ts description: The date the threat bulletin was modified. type: Date - contextPath: ThreatStream.IP.ThreatBulletin.name description: The name of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.original_source description: The original source of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.original_source_id description: The original source ID of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_org.resource_uri description: The owner organization URI. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_org_id description: The ID of the owner user. type: Number - contextPath: ThreatStream.IP.ThreatBulletin.owner_org_name description: The name of the owner organization. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.avatar_s3_url description: The URL of the owner user. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.can_share_intelligence description: Whether you can share intelligence. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.email description: The email of the owner user. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.id description: The ID of the owner user. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.is_active description: Whether the owner user is active. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.is_readonly description: Whether the owner user has read-only permission. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.must_change_password description: Whether the owner user must change the password. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.name description: The owner user name. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.nickname description: The owner user nickname. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.organization.id description: The ID of the owner user organization. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.organization.name description: The name of the owner user organization. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.organization.resource_uri description: The resource URI of the owner user organization. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user.resource_uri description: The resource URI of the owner user. type: String - contextPath: ThreatStream.IP.ThreatBulletin.owner_user_id description: The owner user ID of the threat bulletin. type: Number - contextPath: ThreatStream.IP.ThreatBulletin.owner_user_name description: The owner user name of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.parent description: The parent of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.published_ts description: The date the threat bulletin was published. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.resource_uri description: The resource URI of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.source description: The source of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.starred_by_me description: Whether the threat bulletin was started by me. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.starred_total_count description: The total number of times the threat bulletin was starred. type: Number - contextPath: ThreatStream.IP.ThreatBulletin.status description: The status of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.threat_actor description: The threat actor of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.tlp description: The TLP of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.ttp description: The TTP of the threat bulletin. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.uuid description: The UUID of the threat bulletin. type: String - contextPath: ThreatStream.IP.ThreatBulletin.votes.me description: The number of votes by me. type: Unknown - contextPath: ThreatStream.IP.ThreatBulletin.votes.total description: The number of total votes. type: Number - contextPath: ThreatStream.IP.ThreatBulletin.watched_by_me description: Whether the threat bulletin was watched by me. type: Boolean - contextPath: ThreatStream.IP.ThreatBulletin.watched_total_count description: The total number of watchers. type: Number - contextPath: ThreatStream.IP.TTP.assignee_user description: The assignee user of the TTP. type: Unknown - contextPath: ThreatStream.IP.TTP.association_info.comment description: The comment in the association info of the TTP. type: Unknown - contextPath: ThreatStream.IP.TTP.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.IP.TTP.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.IP.TTP.can_add_public_tags description: Whether you can add public tags to the TTP. type: Boolean - contextPath: ThreatStream.IP.TTP.created_ts description: The date the TTP was created. type: Date - contextPath: ThreatStream.IP.TTP.feed_id description: The feed ID of the TTP. type: Number - contextPath: ThreatStream.IP.TTP.id description: The ID of the TTP. type: Number - contextPath: ThreatStream.IP.TTP.is_anonymous description: Whether the TTP was anonymous. type: Boolean - contextPath: ThreatStream.IP.TTP.is_cloneable description: Whether the TTP was cloneable. type: String - contextPath: ThreatStream.IP.TTP.is_public description: Whether the TTP is public. type: Boolean - contextPath: ThreatStream.IP.TTP.is_team description: Whether the TTP is a team. type: Boolean - contextPath: ThreatStream.IP.TTP.modified_ts description: The date the TTP was modified. type: Date - contextPath: ThreatStream.IP.TTP.name description: The name of the TTP. type: String - contextPath: ThreatStream.IP.TTP.organization_id description: The organization ID of the TTP. type: Number - contextPath: ThreatStream.IP.TTP.owner_user_id description: The owner user ID of the TTP. type: Number - contextPath: ThreatStream.IP.TTP.primary_motivation description: The primary motivation of the TTP. type: Unknown - contextPath: ThreatStream.IP.TTP.publication_status description: The publication status of the TTP. type: String - contextPath: ThreatStream.IP.TTP.published_ts description: The date the TTP was published. type: Date - contextPath: ThreatStream.IP.TTP.resource_level description: The resource level of the TTP. type: Unknown - contextPath: ThreatStream.IP.TTP.resource_uri description: The resource URI of the TTP. type: String - contextPath: ThreatStream.IP.TTP.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.IP.TTP.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.IP.TTP.start_date description: The start date. type: Unknown - contextPath: ThreatStream.IP.TTP.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.IP.TTP.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.IP.TTP.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.IP.TTP.tlp description: The TLP of the TTP. type: String - contextPath: ThreatStream.IP.TTP.uuid description: The UUID of the TTP. type: String - contextPath: ThreatStream.IP.Vulnerability.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.IP.Vulnerability.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.IP.Vulnerability.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.IP.Vulnerability.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.IP.Vulnerability.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.IP.Vulnerability.circles.id description: The ID of the circle. type: String - contextPath: ThreatStream.IP.Vulnerability.circles.name description: The name of the circle. type: String - contextPath: ThreatStream.IP.Vulnerability.circles.resource_uri description: The resource URI of the circle. type: String - contextPath: ThreatStream.IP.Vulnerability.created_ts description: The date the vulnerability was created. type: Date - contextPath: ThreatStream.IP.Vulnerability.feed_id description: The feed ID of the vulnerability. type: Number - contextPath: ThreatStream.IP.Vulnerability.id description: The ID of the vulnerability. type: Number - contextPath: ThreatStream.IP.Vulnerability.is_anonymous description: Whether the vulnerability is anonymous. type: Boolean - contextPath: ThreatStream.IP.Vulnerability.is_cloneable description: Whether the vulnerability is cloneable. type: String - contextPath: ThreatStream.IP.Vulnerability.is_public description: Whether the vulnerability is public. type: Boolean - contextPath: ThreatStream.IP.Vulnerability.is_system description: Whether the vulnerability is in the system. type: Boolean - contextPath: ThreatStream.IP.Vulnerability.modified_ts description: The date the vulnerability was modified. type: Date - contextPath: ThreatStream.IP.Vulnerability.name description: The name of the vulnerability. type: String - contextPath: ThreatStream.IP.Vulnerability.organization_id description: The organization ID of the vulnerability. type: Number - contextPath: ThreatStream.IP.Vulnerability.owner_user_id description: The owner user ID of the vulnerability. type: Unknown - contextPath: ThreatStream.IP.Vulnerability.publication_status description: The publication status of the vulnerability. type: String - contextPath: ThreatStream.IP.Vulnerability.published_ts description: The date the vulnerability was published. type: Date - contextPath: ThreatStream.IP.Vulnerability.resource_uri description: The resource URI of the vulnerability. type: String - contextPath: ThreatStream.IP.Vulnerability.source description: The source of the vulnerability. type: String - contextPath: ThreatStream.IP.Vulnerability.source_created description: The feed ID of the vulnerability. type: Unknown - contextPath: ThreatStream.IP.Vulnerability.source_modified description: Whether the source was modified. type: Unknown - contextPath: ThreatStream.IP.Vulnerability.tags description: The tags of the vulnerability. type: String - contextPath: ThreatStream.IP.Vulnerability.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.IP.Vulnerability.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.IP.Vulnerability.tlp description: The TLP of the vulnerability. type: String - contextPath: ThreatStream.IP.Vulnerability.update_id description: The update ID of the vulnerability. type: Number - contextPath: ThreatStream.IP.Vulnerability.uuid description: The UUID of the vulnerability. type: String - contextPath: ThreatStream.IP.Campaign.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.IP.Campaign.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.IP.Campaign.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.IP.Campaign.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.IP.Campaign.can_add_public_tags description: Whether you can add public tags to the campaign. type: Boolean - contextPath: ThreatStream.IP.Campaign.created_ts description: The date the campaign was created. type: Date - contextPath: ThreatStream.IP.Campaign.end_date description: The end date of the campaign. type: Unknown - contextPath: ThreatStream.IP.Campaign.feed_id description: The feed ID of the campaign. type: Number - contextPath: ThreatStream.IP.Campaign.id description: The ID of the campaign. type: Number - contextPath: ThreatStream.IP.Campaign.is_anonymous description: Whether the campaign is anonymous. type: Boolean - contextPath: ThreatStream.IP.Campaign.is_cloneable description: Whether the campaign is cloneable. type: String - contextPath: ThreatStream.IP.Campaign.is_public description: Whether the campaign is public. type: Boolean - contextPath: ThreatStream.IP.Campaign.modified_ts description: The date the campaign was modified. type: Date - contextPath: ThreatStream.IP.Campaign.name description: The name of the campaign. type: String - contextPath: ThreatStream.IP.Campaign.objective description: The objective of the campaign. type: Unknown - contextPath: ThreatStream.IP.Campaign.organization_id description: The organization ID of the campaign. type: Number - contextPath: ThreatStream.IP.Campaign.owner_user_id description: The owner user ID of the campaign. type: Number - contextPath: ThreatStream.IP.Campaign.publication_status description: The publication status of the campaign. type: String - contextPath: ThreatStream.IP.Campaign.published_ts description: The date the campaign was published. type: Unknown - contextPath: ThreatStream.IP.Campaign.resource_uri description: The resource URI of the campaign. type: String - contextPath: ThreatStream.IP.Campaign.source_created description: The date the campaign was created. type: Date - contextPath: ThreatStream.IP.Campaign.source_modified description: Whether the source was modified. type: Date - contextPath: ThreatStream.IP.Campaign.start_date description: The start date of the campaign. type: Unknown - contextPath: ThreatStream.IP.Campaign.status.display_name description: The display name of the status. type: String - contextPath: ThreatStream.IP.Campaign.status.id description: The ID of the status of the campaign. type: Number - contextPath: ThreatStream.IP.Campaign.status.resource_uri description: The resource URI of the status of the campaign. type: String - contextPath: ThreatStream.IP.Campaign.tlp description: The TLP of the campaign. type: String - contextPath: ThreatStream.IP.Campaign.uuid description: The UUID of the campaign. type: String - arguments: - default: true description: The domain name to check. isArray: true name: domain required: true - description: If confidence is greater than the threshold the domain is considered malicious, otherwise it is considered good. This argument overrides the default domain threshold defined as a parameter. name: threshold - auto: PREDEFINED description: Whether to include results with an inactive status. name: include_inactive predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: 'Enhance generic reputation commands to include additional information such as Threat Bulletins, Attach patterns, Actors, Campaigns, TTPs, vulnerabilities, etc. Note: If set to true, additional 6 API calls will be performed.' name: threat_model_association predefined: - 'True' - 'False' description: Checks the reputation of the given domain name. name: domain outputs: - contextPath: Domain.Name description: The domain name. type: String - contextPath: Domain.DNS description: The IP addresses resolved by the DNS. type: String - contextPath: Domain.WHOIS.CreationDate description: |- The date the domain was created. The date format is: YYYYMMDDThhmmss, where T denotes the start of the value for time in UTC time. type: Date - contextPath: Domain.WHOIS.UpdatedDate description: |- The date the domain was last updated. The date format is: YYYYMMDDThhmmss, where T denotes the start of the value for time in UTC time. type: Date - contextPath: Domain.WHOIS.Registrant.Name description: The registrant name. type: String - contextPath: Domain.WHOIS.Registrant.Email description: The registrant email address. type: String - contextPath: Domain.WHOIS.Registrant.Phone description: The registrant phone number. type: String - contextPath: ThreatStream.Domain.ASN description: The Autonomous System (AS) number associated with the indicator. type: String - contextPath: ThreatStream.Domain.Address description: The indicator domain name. type: String - contextPath: ThreatStream.Domain.Country description: The country associated with the indicator. type: String - contextPath: ThreatStream.Domain.Type description: The indicator type. type: String - contextPath: ThreatStream.Domain.Modified description: |- The date and time the indicator was last updated. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time. type: String - contextPath: ThreatStream.Domain.Severity description: The indicator severity ("very-high", "high", "medium", "low"). type: String - contextPath: ThreatStream.Domain.Confidence description: The observable certainty level of a reported indicator type. Confidence score ranges from 0-100, in increasing order of confidence. type: String - contextPath: ThreatStream.Domain.Status description: The status assigned to the indicator. type: String - contextPath: ThreatStream.Domain.Organization description: The name of the business that owns the IP address associated with the indicator. type: String - contextPath: ThreatStream.Domain.Source description: The indicator source. type: String - contextPath: Domain.Malicious.Vendor description: The vendor that reported the indicator as malicious. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: ThreatStream.Domain.Tags description: Tags assigned to the domain. type: Unknown - contextPath: ThreatStream.Domain.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: Domain.Tags description: List of domain tags. type: Unknown - contextPath: Domain.ThreatTypes description: Threat types associated with the domain. type: Unknown - contextPath: ThreatStream.Domain.Actor.assignee_user description: The assignee user of the threat actor. type: Unknown - contextPath: ThreatStream.Domain.Actor.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.Domain.Actor.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.Domain.Actor.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.Domain.Actor.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.Domain.Actor.created_ts description: The date the threat actor was created. type: Date - contextPath: ThreatStream.Domain.Actor.feed_id description: The feed ID of the threat actor. type: Number - contextPath: ThreatStream.Domain.Actor.id description: The ID of the threat actor. type: Number - contextPath: ThreatStream.Domain.Actor.is_anonymous description: Whether the threat actor is anonymous. type: Boolean - contextPath: ThreatStream.Domain.Actor.is_cloneable description: Whether the threat actor is cloneable. type: String - contextPath: ThreatStream.Domain.Actor.is_public description: Whether the threat actor is public. type: Boolean - contextPath: ThreatStream.Domain.Actor.is_team description: Whether the threat actor is a team. type: Boolean - contextPath: ThreatStream.Domain.Actor.modified_ts description: The date the threat actor was modified. type: Date - contextPath: ThreatStream.Domain.Actor.name description: The name of the threat actor. type: String - contextPath: ThreatStream.Domain.Actor.organization_id description: The organization ID of the threat actor. type: Number - contextPath: ThreatStream.Domain.Actor.owner_user_id description: The owner user ID of the threat actor. type: Number - contextPath: ThreatStream.Domain.Actor.primary_motivation description: The primary motivation of the threat actor. type: Unknown - contextPath: ThreatStream.Domain.Actor.publication_status description: The publication status of the threat actor. type: String - contextPath: ThreatStream.Domain.Actor.published_ts description: The date the threat actor was published. type: Date - contextPath: ThreatStream.Domain.Actor.resource_level description: The resource level of the threat actor. type: Unknown - contextPath: ThreatStream.Domain.Actor.resource_uri description: The resource URI of the threat actor. type: String - contextPath: ThreatStream.Domain.Actor.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.Domain.Actor.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.Domain.Actor.start_date description: The start date. type: Unknown - contextPath: ThreatStream.Domain.Actor.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.Domain.Actor.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.Domain.Actor.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.Domain.Actor.tlp description: The TLP of the threat actor. type: String - contextPath: ThreatStream.Domain.Actor.uuid description: The UUID of the threat actor. type: String - contextPath: ThreatStream.Domain.Signature.assignee_user description: The assignee user of the signature. type: Unknown - contextPath: ThreatStream.Domain.Signature.association_info.comment description: The comment in the association info of the signature. type: Unknown - contextPath: ThreatStream.Domain.Signature.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.Domain.Signature.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.Domain.Signature.can_add_public_tags description: Whether you can add public tags to the signature. type: Boolean - contextPath: ThreatStream.Domain.Signature.created_ts description: The date the signature was created. type: Date - contextPath: ThreatStream.Domain.Signature.feed_id description: The feed ID of the signature. type: Number - contextPath: ThreatStream.Domain.Signature.id description: The ID of the signature. type: Number - contextPath: ThreatStream.Domain.Signature.is_anonymous description: Whether the signature is anonymous. type: Boolean - contextPath: ThreatStream.Domain.Signature.is_cloneable description: Whether the signature is cloneable. type: String - contextPath: ThreatStream.Domain.Signature.is_public description: Whether the signature is public. type: Boolean - contextPath: ThreatStream.Domain.Signature.is_team description: Whether the signature is a team signature. type: Boolean - contextPath: ThreatStream.Domain.Signature.modified_ts description: The date the signature was modified. type: Date - contextPath: ThreatStream.Domain.Signature.name description: The name of the signature. type: String - contextPath: ThreatStream.Domain.Signature.organization_id description: The organization ID of the signature. type: Number - contextPath: ThreatStream.Domain.Signature.owner_user_id description: The owner user ID of the signature. type: Number - contextPath: ThreatStream.Domain.Signature.primary_motivation description: The primary motivation of the signature. type: Unknown - contextPath: ThreatStream.Domain.Signature.publication_status description: The publication status of the signature. type: String - contextPath: ThreatStream.Domain.Signature.published_ts description: The date the signature was published. type: Date - contextPath: ThreatStream.Domain.Signature.resource_level description: The resource level of the signature. type: Unknown - contextPath: ThreatStream.Domain.Signature.resource_uri description: The resource URI of the signature. type: String - contextPath: ThreatStream.Domain.Signature.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.Domain.Signature.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.Domain.Signature.start_date description: The start date. type: Unknown - contextPath: ThreatStream.Domain.Signature.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.Domain.Signature.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.Domain.Signature.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.Domain.Signature.tlp description: The TLP of the signature. type: String - contextPath: ThreatStream.Domain.Signature.uuid description: The UUID of the signature. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.all_circles_visible description: Whether all of the circles are visible. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.assignee_org description: The assignee organization. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.assignee_org_id description: The assignee organization ID. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.assignee_org_name description: The assignee organization name. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.assignee_user description: The assignee user. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.assignee_user_id description: The assignee user ID. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.assignee_user_name description: The assignee user name. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.Domain.ThreatBulletin.association_info.from_id description: The ID from which the association info is related. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.body_content_type description: The body content type. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.campaign description: The campaign of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.can_add_public_tags description: Whether you can add public tags. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.created_ts description: The date the threat bulletin was created. type: Date - contextPath: ThreatStream.Domain.ThreatBulletin.feed_id description: The feed ID of the threat bulletin. type: Number - contextPath: ThreatStream.Domain.ThreatBulletin.id description: The ID of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.is_anonymous description: Whether the threat bulletin is anonymous. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.is_cloneable description: Whether the threat bulletin is cloneable. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.is_editable description: Whether the threat bulletin is editable. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.is_email description: Whether the threat bulletin is an email. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.is_public description: Whether the threat bulletin is public. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.modified_ts description: The date the threat bulletin was modified. type: Date - contextPath: ThreatStream.Domain.ThreatBulletin.name description: The name of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.original_source description: The original source of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.original_source_id description: The original source ID of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_org.resource_uri description: The owner organization URI. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_org_id description: The ID of the owner user. type: Number - contextPath: ThreatStream.Domain.ThreatBulletin.owner_org_name description: The name of the owner organization. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.avatar_s3_url description: The URL of the owner user. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.can_share_intelligence description: Whether you can share intelligence. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.email description: The email of the owner user. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.id description: The ID of the owner user. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.is_active description: Whether the owner user is active. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.is_readonly description: Whether the owner user has read-only permission. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.must_change_password description: Whether the owner user must change the password. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.name description: The owner user name. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.nickname description: The owner user nickname. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.organization.id description: The ID of the owner user organization. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.organization.name description: The name of the owner user organization. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.organization.resource_uri description: The resource URI of the owner user organization. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user.resource_uri description: The resource URI of the owner user. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user_id description: The owner user ID of the threat bulletin. type: Number - contextPath: ThreatStream.Domain.ThreatBulletin.owner_user_name description: The owner user name of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.parent description: The parent of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.published_ts description: The date the threat bulletin was published. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.resource_uri description: The resource URI of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.source description: The source of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.starred_by_me description: Whether the threat bulletin was started by me. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.starred_total_count description: The total number of times the threat bulletin was starred. type: Number - contextPath: ThreatStream.Domain.ThreatBulletin.status description: The status of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.threat_actor description: The threat actor of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.tlp description: The TLP of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.ttp description: The TTP of the threat bulletin. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.uuid description: The UUID of the threat bulletin. type: String - contextPath: ThreatStream.Domain.ThreatBulletin.votes.me description: The number of votes by me. type: Unknown - contextPath: ThreatStream.Domain.ThreatBulletin.votes.total description: The number of total votes. type: Number - contextPath: ThreatStream.Domain.ThreatBulletin.watched_by_me description: Whether the threat bulletin was watched by me. type: Boolean - contextPath: ThreatStream.Domain.ThreatBulletin.watched_total_count description: The total number of watchers. type: Number - contextPath: ThreatStream.Domain.TTP.assignee_user description: The assignee user of the TTP. type: Unknown - contextPath: ThreatStream.Domain.TTP.association_info.comment description: The comment in the association info of the TTP. type: Unknown - contextPath: ThreatStream.Domain.TTP.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.Domain.TTP.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.Domain.TTP.can_add_public_tags description: Whether you can add public tags to the TTP. type: Boolean - contextPath: ThreatStream.Domain.TTP.created_ts description: The date the TTP was created. type: Date - contextPath: ThreatStream.Domain.TTP.feed_id description: The feed ID of the TTP. type: Number - contextPath: ThreatStream.Domain.TTP.id description: The ID of the TTP. type: Number - contextPath: ThreatStream.Domain.TTP.is_anonymous description: Whether the TTP was anonymous. type: Boolean - contextPath: ThreatStream.Domain.TTP.is_cloneable description: Whether the TTP was cloneable. type: String - contextPath: ThreatStream.Domain.TTP.is_public description: Whether the TTP is public. type: Boolean - contextPath: ThreatStream.Domain.TTP.is_team description: Whether the TTP is a team. type: Boolean - contextPath: ThreatStream.Domain.TTP.modified_ts description: The date the TTP was modified. type: Date - contextPath: ThreatStream.Domain.TTP.name description: The name of the TTP. type: String - contextPath: ThreatStream.Domain.TTP.organization_id description: The organization ID of the TTP. type: Number - contextPath: ThreatStream.Domain.TTP.owner_user_id description: The owner user ID of the TTP. type: Number - contextPath: ThreatStream.Domain.TTP.primary_motivation description: The primary motivation of the TTP. type: Unknown - contextPath: ThreatStream.Domain.TTP.publication_status description: The publication status of the TTP. type: String - contextPath: ThreatStream.Domain.TTP.published_ts description: The date the TTP was published. type: Date - contextPath: ThreatStream.Domain.TTP.resource_level description: The resource level of the TTP. type: Unknown - contextPath: ThreatStream.Domain.TTP.resource_uri description: The resource URI of the TTP. type: String - contextPath: ThreatStream.Domain.TTP.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.Domain.TTP.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.Domain.TTP.start_date description: The start date. type: Unknown - contextPath: ThreatStream.Domain.TTP.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.Domain.TTP.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.Domain.TTP.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.Domain.TTP.tlp description: The TLP of the TTP. type: String - contextPath: ThreatStream.Domain.TTP.uuid description: The UUID of the TTP. type: String - contextPath: ThreatStream.Domain.Vulnerability.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.Domain.Vulnerability.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.Domain.Vulnerability.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.Domain.Vulnerability.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.Domain.Vulnerability.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.Domain.Vulnerability.circles.id description: The ID of the circle. type: String - contextPath: ThreatStream.Domain.Vulnerability.circles.name description: The name of the circle. type: String - contextPath: ThreatStream.Domain.Vulnerability.circles.resource_uri description: The resource URI of the circle. type: String - contextPath: ThreatStream.Domain.Vulnerability.created_ts description: The date the vulnerability was created. type: Date - contextPath: ThreatStream.Domain.Vulnerability.feed_id description: The feed ID of the vulnerability. type: Number - contextPath: ThreatStream.Domain.Vulnerability.id description: The ID of the vulnerability. type: Number - contextPath: ThreatStream.Domain.Vulnerability.is_anonymous description: Whether the vulnerability is anonymous. type: Boolean - contextPath: ThreatStream.Domain.Vulnerability.is_cloneable description: Whether the vulnerability is cloneable. type: String - contextPath: ThreatStream.Domain.Vulnerability.is_public description: Whether the vulnerability is public. type: Boolean - contextPath: ThreatStream.Domain.Vulnerability.is_system description: Whether the vulnerability is in the system. type: Boolean - contextPath: ThreatStream.Domain.Vulnerability.modified_ts description: The date the vulnerability was modified. type: Date - contextPath: ThreatStream.Domain.Vulnerability.name description: The name of the vulnerability. type: String - contextPath: ThreatStream.Domain.Vulnerability.organization_id description: The organization ID of the vulnerability. type: Number - contextPath: ThreatStream.Domain.Vulnerability.owner_user_id description: The owner user ID of the vulnerability. type: Unknown - contextPath: ThreatStream.Domain.Vulnerability.publication_status description: The publication status of the vulnerability. type: String - contextPath: ThreatStream.Domain.Vulnerability.published_ts description: The date the vulnerability was published. type: Date - contextPath: ThreatStream.Domain.Vulnerability.resource_uri description: The resource URI of the vulnerability. type: String - contextPath: ThreatStream.Domain.Vulnerability.source description: The source of the vulnerability. type: String - contextPath: ThreatStream.Domain.Vulnerability.source_created description: The feed ID of the vulnerability. type: Unknown - contextPath: ThreatStream.Domain.Vulnerability.source_modified description: Whether the source was modified. type: Unknown - contextPath: ThreatStream.Domain.Vulnerability.tags description: The tags of the vulnerability. type: String - contextPath: ThreatStream.Domain.Vulnerability.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.Domain.Vulnerability.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.Domain.Vulnerability.tlp description: The TLP of the vulnerability. type: String - contextPath: ThreatStream.Domain.Vulnerability.update_id description: The update ID of the vulnerability. type: Number - contextPath: ThreatStream.Domain.Vulnerability.uuid description: The UUID of the vulnerability. type: String - contextPath: ThreatStream.Domain.Campaign.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.Domain.Campaign.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.Domain.Campaign.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.Domain.Campaign.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.Domain.Campaign.can_add_public_tags description: Whether you can add public tags to the campaign. type: Boolean - contextPath: ThreatStream.Domain.Campaign.created_ts description: The date the campaign was created. type: Date - contextPath: ThreatStream.Domain.Campaign.end_date description: The end date of the campaign. type: Unknown - contextPath: ThreatStream.Domain.Campaign.feed_id description: The feed ID of the campaign. type: Number - contextPath: ThreatStream.Domain.Campaign.id description: The ID of the campaign. type: Number - contextPath: ThreatStream.Domain.Campaign.is_anonymous description: Whether the campaign is anonymous. type: Boolean - contextPath: ThreatStream.Domain.Campaign.is_cloneable description: Whether the campaign is cloneable. type: String - contextPath: ThreatStream.Domain.Campaign.is_public description: Whether the campaign is public. type: Boolean - contextPath: ThreatStream.Domain.Campaign.modified_ts description: The date the campaign was modified. type: Date - contextPath: ThreatStream.Domain.Campaign.name description: The name of the campaign. type: String - contextPath: ThreatStream.Domain.Campaign.objective description: The objective of the campaign. type: Unknown - contextPath: ThreatStream.Domain.Campaign.organization_id description: The organization ID of the campaign. type: Number - contextPath: ThreatStream.Domain.Campaign.owner_user_id description: The owner user ID of the campaign. type: Number - contextPath: ThreatStream.Domain.Campaign.publication_status description: The publication status of the campaign. type: String - contextPath: ThreatStream.Domain.Campaign.published_ts description: The date the campaign was published. type: Unknown - contextPath: ThreatStream.Domain.Campaign.resource_uri description: The resource URI of the campaign. type: String - contextPath: ThreatStream.Domain.Campaign.source_created description: The date the campaign was created. type: Date - contextPath: ThreatStream.Domain.Campaign.source_modified description: Whether the source was modified. type: Date - contextPath: ThreatStream.Domain.Campaign.start_date description: The start date of the campaign. type: Unknown - contextPath: ThreatStream.Domain.Campaign.status.display_name description: The display name of the status. type: String - contextPath: ThreatStream.Domain.Campaign.status.id description: The ID of the status of the campaign. type: Number - contextPath: ThreatStream.Domain.Campaign.status.resource_uri description: The resource URI of the status of the campaign. type: String - contextPath: ThreatStream.Domain.Campaign.tlp description: The TLP of the campaign. type: String - contextPath: ThreatStream.Domain.Campaign.uuid description: The UUID of the campaign. type: String - arguments: - default: true description: The hash of file to check. isArray: true name: file required: true - description: If the confidence is greater than the threshold the hash of the file is considered malicious, otherwise it is considered good. This argument overrides the default file threshold defined as a parameter. name: threshold - auto: PREDEFINED description: Whether to include results with an inactive status. name: include_inactive predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: 'Enhance generic reputation commands to include additional information such as Threat Bulletins, Attach patterns, Actors, Campaigns, TTPs, vulnerabilities, etc. Note: If set to true, additional 6 API calls will be performed.' name: threat_model_association predefined: - 'True' - 'False' description: Checks the reputation of the given hash of the file. name: file outputs: - contextPath: File.MD5 description: The MD5 hash of the file. type: String - contextPath: File.SHA1 description: The SHA1 hash of the file. type: String - contextPath: File.SHA256 description: The SHA256 hash of the file. type: String - contextPath: File.SHA512 description: The SHA512 hash of the file. type: String - contextPath: File.Malicious.Vendor description: The vendor that reported the indicator as malicious. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: ThreatStream.File.Severity description: The indicator severity ("very-high", "high", "medium", "low"). type: String - contextPath: ThreatStream.File.Confidence description: The observable certainty level of a reported indicator type. Confidence score ranges from 0-100, in increasing order of confidence. type: String - contextPath: ThreatStream.File.Status description: The status assigned to the indicator. type: String - contextPath: ThreatStream.File.Type description: The indicator type. type: String - contextPath: ThreatStream.File.MD5 description: The MD5 hash of the indicator. type: String - contextPath: ThreatStream.File.SHA1 description: The SHA1 hash of the indicator. type: String - contextPath: ThreatStream.File.SHA256 description: The SHA256 hash of the indicator. type: String - contextPath: ThreatStream.File.SHA512 description: The SHA512 hash of the indicator. type: String - contextPath: ThreatStream.File.Modified description: |- The date and time the indicator was last updated. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time. type: String - contextPath: ThreatStream.File.Source description: The indicator source. type: String - contextPath: ThreatStream.File.Tags description: Tags assigned to the file. type: Unknown - contextPath: ThreatStream.File.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: File.Tags description: List of file tags. type: Unknown - contextPath: File.ThreatTypes description: Threat types associated with the file. type: Unknown - contextPath: ThreatStream.File.Actor.assignee_user description: The assignee user of the threat actor. type: Unknown - contextPath: ThreatStream.File.Actor.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.File.Actor.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.File.Actor.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.File.Actor.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.File.Actor.created_ts description: The date the threat actor was created. type: Date - contextPath: ThreatStream.File.Actor.feed_id description: The feed ID of the threat actor. type: Number - contextPath: ThreatStream.File.Actor.id description: The ID of the threat actor. type: Number - contextPath: ThreatStream.File.Actor.is_anonymous description: Whether the threat actor is anonymous. type: Boolean - contextPath: ThreatStream.File.Actor.is_cloneable description: Whether the threat actor is cloneable. type: String - contextPath: ThreatStream.File.Actor.is_public description: Whether the threat actor is public. type: Boolean - contextPath: ThreatStream.File.Actor.is_team description: Whether the threat actor is a team. type: Boolean - contextPath: ThreatStream.File.Actor.modified_ts description: The date the threat actor was modified. type: Date - contextPath: ThreatStream.File.Actor.name description: The name of the threat actor. type: String - contextPath: ThreatStream.File.Actor.organization_id description: The organization ID of the threat actor. type: Number - contextPath: ThreatStream.File.Actor.owner_user_id description: The owner user ID of the threat actor. type: Number - contextPath: ThreatStream.File.Actor.primary_motivation description: The primary motivation of the threat actor. type: Unknown - contextPath: ThreatStream.File.Actor.publication_status description: The publication status of the threat actor. type: String - contextPath: ThreatStream.File.Actor.published_ts description: The date the threat actor was published. type: Date - contextPath: ThreatStream.File.Actor.resource_level description: The resource level of the threat actor. type: Unknown - contextPath: ThreatStream.File.Actor.resource_uri description: The resource URI of the threat actor. type: String - contextPath: ThreatStream.File.Actor.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.File.Actor.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.File.Actor.start_date description: The start date. type: Unknown - contextPath: ThreatStream.File.Actor.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.File.Actor.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.File.Actor.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.File.Actor.tlp description: The TLP of the threat actor. type: String - contextPath: ThreatStream.File.Actor.uuid description: The UUID of the threat actor. type: String - contextPath: ThreatStream.File.Signature.assignee_user description: The assignee user of the signature. type: Unknown - contextPath: ThreatStream.File.Signature.association_info.comment description: The comment in the association info of the signature. type: Unknown - contextPath: ThreatStream.File.Signature.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.File.Signature.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.File.Signature.can_add_public_tags description: Whether you can add public tags to the signature. type: Boolean - contextPath: ThreatStream.File.Signature.created_ts description: The date the signature was created. type: Date - contextPath: ThreatStream.File.Signature.feed_id description: The feed ID of the signature. type: Number - contextPath: ThreatStream.File.Signature.id description: The ID of the signature. type: Number - contextPath: ThreatStream.File.Signature.is_anonymous description: Whether the signature is anonymous. type: Boolean - contextPath: ThreatStream.File.Signature.is_cloneable description: Whether the signature is cloneable. type: String - contextPath: ThreatStream.File.Signature.is_public description: Whether the signature is public. type: Boolean - contextPath: ThreatStream.File.Signature.is_team description: Whether the signature is a team signature. type: Boolean - contextPath: ThreatStream.File.Signature.modified_ts description: The date the signature was modified. type: Date - contextPath: ThreatStream.File.Signature.name description: The name of the signature. type: String - contextPath: ThreatStream.File.Signature.organization_id description: The organization ID of the signature. type: Number - contextPath: ThreatStream.File.Signature.owner_user_id description: The owner user ID of the signature. type: Number - contextPath: ThreatStream.File.Signature.primary_motivation description: The primary motivation of the signature. type: Unknown - contextPath: ThreatStream.File.Signature.publication_status description: The publication status of the signature. type: String - contextPath: ThreatStream.File.Signature.published_ts description: The date the signature was published. type: Date - contextPath: ThreatStream.File.Signature.resource_level description: The resource level of the signature. type: Unknown - contextPath: ThreatStream.File.Signature.resource_uri description: The resource URI of the signature. type: String - contextPath: ThreatStream.File.Signature.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.File.Signature.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.File.Signature.start_date description: The start date. type: Unknown - contextPath: ThreatStream.File.Signature.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.File.Signature.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.File.Signature.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.File.Signature.tlp description: The TLP of the signature. type: String - contextPath: ThreatStream.File.Signature.uuid description: The UUID of the signature. type: String - contextPath: ThreatStream.File.ThreatBulletin.all_circles_visible description: Whether all of the circles are visible. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.assignee_org description: The assignee organization. type: String - contextPath: ThreatStream.File.ThreatBulletin.assignee_org_id description: The assignee organization ID. type: String - contextPath: ThreatStream.File.ThreatBulletin.assignee_org_name description: The assignee organization name. type: String - contextPath: ThreatStream.File.ThreatBulletin.assignee_user description: The assignee user. type: String - contextPath: ThreatStream.File.ThreatBulletin.assignee_user_id description: The assignee user ID. type: String - contextPath: ThreatStream.File.ThreatBulletin.assignee_user_name description: The assignee user name. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.File.ThreatBulletin.association_info.from_id description: The ID from which the association info is related. type: String - contextPath: ThreatStream.File.ThreatBulletin.body_content_type description: The body content type. type: String - contextPath: ThreatStream.File.ThreatBulletin.campaign description: The campaign of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.can_add_public_tags description: Whether you can add public tags. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.created_ts description: The date the threat bulletin was created. type: Date - contextPath: ThreatStream.File.ThreatBulletin.feed_id description: The feed ID of the threat bulletin. type: Number - contextPath: ThreatStream.File.ThreatBulletin.id description: The ID of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.is_anonymous description: Whether the threat bulletin is anonymous. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.is_cloneable description: Whether the threat bulletin is cloneable. type: String - contextPath: ThreatStream.File.ThreatBulletin.is_editable description: Whether the threat bulletin is editable. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.is_email description: Whether the threat bulletin is an email. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.is_public description: Whether the threat bulletin is public. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.modified_ts description: The date the threat bulletin was modified. type: Date - contextPath: ThreatStream.File.ThreatBulletin.name description: The name of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.original_source description: The original source of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.original_source_id description: The original source ID of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_org.resource_uri description: The owner organization URI. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_org_id description: The ID of the owner user. type: Number - contextPath: ThreatStream.File.ThreatBulletin.owner_org_name description: The name of the owner organization. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.avatar_s3_url description: The URL of the owner user. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.owner_user.can_share_intelligence description: Whether you can share intelligence. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.owner_user.email description: The email of the owner user. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.id description: The ID of the owner user. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.is_active description: Whether the owner user is active. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.owner_user.is_readonly description: Whether the owner user has read-only permission. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.owner_user.must_change_password description: Whether the owner user must change the password. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.owner_user.name description: The owner user name. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.nickname description: The owner user nickname. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.organization.id description: The ID of the owner user organization. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.organization.name description: The name of the owner user organization. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.organization.resource_uri description: The resource URI of the owner user organization. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user.resource_uri description: The resource URI of the owner user. type: String - contextPath: ThreatStream.File.ThreatBulletin.owner_user_id description: The owner user ID of the threat bulletin. type: Number - contextPath: ThreatStream.File.ThreatBulletin.owner_user_name description: The owner user name of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.parent description: The parent of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.published_ts description: The date the threat bulletin was published. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.resource_uri description: The resource URI of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.source description: The source of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.starred_by_me description: Whether the threat bulletin was started by me. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.starred_total_count description: The total number of times the threat bulletin was starred. type: Number - contextPath: ThreatStream.File.ThreatBulletin.status description: The status of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.threat_actor description: The threat actor of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.tlp description: The TLP of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.ttp description: The TTP of the threat bulletin. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.uuid description: The UUID of the threat bulletin. type: String - contextPath: ThreatStream.File.ThreatBulletin.votes.me description: The number of votes by me. type: Unknown - contextPath: ThreatStream.File.ThreatBulletin.votes.total description: The number of total votes. type: Number - contextPath: ThreatStream.File.ThreatBulletin.watched_by_me description: Whether the threat bulletin was watched by me. type: Boolean - contextPath: ThreatStream.File.ThreatBulletin.watched_total_count description: The total number of watchers. type: Number - contextPath: ThreatStream.File.TTP.assignee_user description: The assignee user of the TTP. type: Unknown - contextPath: ThreatStream.File.TTP.association_info.comment description: The comment in the association info of the TTP. type: Unknown - contextPath: ThreatStream.File.TTP.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.File.TTP.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.File.TTP.can_add_public_tags description: Whether you can add public tags to the TTP. type: Boolean - contextPath: ThreatStream.File.TTP.created_ts description: The date the TTP was created. type: Date - contextPath: ThreatStream.File.TTP.feed_id description: The feed ID of the TTP. type: Number - contextPath: ThreatStream.File.TTP.id description: The ID of the TTP. type: Number - contextPath: ThreatStream.File.TTP.is_anonymous description: Whether the TTP was anonymous. type: Boolean - contextPath: ThreatStream.File.TTP.is_cloneable description: Whether the TTP was cloneable. type: String - contextPath: ThreatStream.File.TTP.is_public description: Whether the TTP is public. type: Boolean - contextPath: ThreatStream.File.TTP.is_team description: Whether the TTP is a team. type: Boolean - contextPath: ThreatStream.File.TTP.modified_ts description: The date the TTP was modified. type: Date - contextPath: ThreatStream.File.TTP.name description: The name of the TTP. type: String - contextPath: ThreatStream.File.TTP.organization_id description: The organization ID of the TTP. type: Number - contextPath: ThreatStream.File.TTP.owner_user_id description: The owner user ID of the TTP. type: Number - contextPath: ThreatStream.File.TTP.primary_motivation description: The primary motivation of the TTP. type: Unknown - contextPath: ThreatStream.File.TTP.publication_status description: The publication status of the TTP. type: String - contextPath: ThreatStream.File.TTP.published_ts description: The date the TTP was published. type: Date - contextPath: ThreatStream.File.TTP.resource_level description: The resource level of the TTP. type: Unknown - contextPath: ThreatStream.File.TTP.resource_uri description: The resource URI of the TTP. type: String - contextPath: ThreatStream.File.TTP.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.File.TTP.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.File.TTP.start_date description: The start date. type: Unknown - contextPath: ThreatStream.File.TTP.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.File.TTP.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.File.TTP.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.File.TTP.tlp description: The TLP of the TTP. type: String - contextPath: ThreatStream.File.TTP.uuid description: The UUID of the TTP. type: String - contextPath: ThreatStream.File.Vulnerability.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.File.Vulnerability.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.File.Vulnerability.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.File.Vulnerability.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.File.Vulnerability.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.File.Vulnerability.circles.id description: The ID of the circle. type: String - contextPath: ThreatStream.File.Vulnerability.circles.name description: The name of the circle. type: String - contextPath: ThreatStream.File.Vulnerability.circles.resource_uri description: The resource URI of the circle. type: String - contextPath: ThreatStream.File.Vulnerability.created_ts description: The date the vulnerability was created. type: Date - contextPath: ThreatStream.File.Vulnerability.feed_id description: The feed ID of the vulnerability. type: Number - contextPath: ThreatStream.File.Vulnerability.id description: The ID of the vulnerability. type: Number - contextPath: ThreatStream.File.Vulnerability.is_anonymous description: Whether the vulnerability is anonymous. type: Boolean - contextPath: ThreatStream.File.Vulnerability.is_cloneable description: Whether the vulnerability is cloneable. type: String - contextPath: ThreatStream.File.Vulnerability.is_public description: Whether the vulnerability is public. type: Boolean - contextPath: ThreatStream.File.Vulnerability.is_system description: Whether the vulnerability is in the system. type: Boolean - contextPath: ThreatStream.File.Vulnerability.modified_ts description: The date the vulnerability was modified. type: Date - contextPath: ThreatStream.File.Vulnerability.name description: The name of the vulnerability. type: String - contextPath: ThreatStream.File.Vulnerability.organization_id description: The organization ID of the vulnerability. type: Number - contextPath: ThreatStream.File.Vulnerability.owner_user_id description: The owner user ID of the vulnerability. type: Unknown - contextPath: ThreatStream.File.Vulnerability.publication_status description: The publication status of the vulnerability. type: String - contextPath: ThreatStream.File.Vulnerability.published_ts description: The date the vulnerability was published. type: Date - contextPath: ThreatStream.File.Vulnerability.resource_uri description: The resource URI of the vulnerability. type: String - contextPath: ThreatStream.File.Vulnerability.source description: The source of the vulnerability. type: String - contextPath: ThreatStream.File.Vulnerability.source_created description: The feed ID of the vulnerability. type: Unknown - contextPath: ThreatStream.File.Vulnerability.source_modified description: Whether the source was modified. type: Unknown - contextPath: ThreatStream.File.Vulnerability.tags description: The tags of the vulnerability. type: String - contextPath: ThreatStream.File.Vulnerability.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.File.Vulnerability.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.File.Vulnerability.tlp description: The TLP of the vulnerability. type: String - contextPath: ThreatStream.File.Vulnerability.update_id description: The update ID of the vulnerability. type: Number - contextPath: ThreatStream.File.Vulnerability.uuid description: The UUID of the vulnerability. type: String - contextPath: ThreatStream.File.Campaign.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.File.Campaign.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.File.Campaign.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.File.Campaign.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.File.Campaign.can_add_public_tags description: Whether you can add public tags to the campaign. type: Boolean - contextPath: ThreatStream.File.Campaign.created_ts description: The date the campaign was created. type: Date - contextPath: ThreatStream.File.Campaign.end_date description: The end date of the campaign. type: Unknown - contextPath: ThreatStream.File.Campaign.feed_id description: The feed ID of the campaign. type: Number - contextPath: ThreatStream.File.Campaign.id description: The ID of the campaign. type: Number - contextPath: ThreatStream.File.Campaign.is_anonymous description: Whether the campaign is anonymous. type: Boolean - contextPath: ThreatStream.File.Campaign.is_cloneable description: Whether the campaign is cloneable. type: String - contextPath: ThreatStream.File.Campaign.is_public description: Whether the campaign is public. type: Boolean - contextPath: ThreatStream.File.Campaign.modified_ts description: The date the campaign was modified. type: Date - contextPath: ThreatStream.File.Campaign.name description: The name of the campaign. type: String - contextPath: ThreatStream.File.Campaign.objective description: The objective of the campaign. type: Unknown - contextPath: ThreatStream.File.Campaign.organization_id description: The organization ID of the campaign. type: Number - contextPath: ThreatStream.File.Campaign.owner_user_id description: The owner user ID of the campaign. type: Number - contextPath: ThreatStream.File.Campaign.publication_status description: The publication status of the campaign. type: String - contextPath: ThreatStream.File.Campaign.published_ts description: The date the campaign was published. type: Unknown - contextPath: ThreatStream.File.Campaign.resource_uri description: The resource URI of the campaign. type: String - contextPath: ThreatStream.File.Campaign.source_created description: The date the campaign was created. type: Date - contextPath: ThreatStream.File.Campaign.source_modified description: Whether the source was modified. type: Date - contextPath: ThreatStream.File.Campaign.start_date description: The start date of the campaign. type: Unknown - contextPath: ThreatStream.File.Campaign.status.display_name description: The display name of the status. type: String - contextPath: ThreatStream.File.Campaign.status.id description: The ID of the status of the campaign. type: Number - contextPath: ThreatStream.File.Campaign.status.resource_uri description: The resource URI of the status of the campaign. type: String - contextPath: ThreatStream.File.Campaign.tlp description: The TLP of the campaign. type: String - contextPath: ThreatStream.File.Campaign.uuid description: The UUID of the campaign. type: String - arguments: - description: The email address to check. name: email required: true - description: If the confidence is greater than the threshold the email address is considered malicious, otherwise it is considered good. This argument overrides the default email threshold defined as a parameter. name: threshold - auto: PREDEFINED description: Whether to include results with an inactive status. name: include_inactive predefined: - 'True' - 'False' description: Checks the reputation of the given email address. name: threatstream-email-reputation outputs: - contextPath: DBotScore.Indicator description: The tested indicator. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: ThreatStream.EmailReputation.Severity description: The indicator severity ("very-high", "high", "medium", "low"). type: String - contextPath: ThreatStream.EmailReputation.Confidence description: The observable certainty level of a reported indicator type. Confidence score ranges from 0-100, in increasing order of confidence. type: String - contextPath: ThreatStream.EmailReputation.Status description: The status assigned to the indicator. type: String - contextPath: ThreatStream.EmailReputation.Type description: The indicator type. type: String - contextPath: ThreatStream.EmailReputation.Email description: The indicator email address. type: String - contextPath: ThreatStream.EmailReputation.Source description: The indicator source. type: String - contextPath: ThreatStream.EmailReputation.Modified description: |- The date and time the indicator was last updated. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time. type: String - contextPath: ThreatStream.EmailReputation.Tags description: Tags assigned to the email. type: Unknown - arguments: - auto: PREDEFINED defaultValue: ip description: The type of passive DNS search ("ip", "domain"). name: type predefined: - ip - domain required: true - description: The values that can be sent to the API should correspond to the type that is chosen. For example,if IP is chosen in the type argument, then a valid IP address should be sent in the value argument. name: value required: true - defaultValue: '50' description: The maximum number of results to return. name: limit - auto: PREDEFINED defaultValue: 'false' description: 'Whether to retrieve all results. The "limit" argument will be ignored.' name: all_results predefined: - 'false' - 'true' description: Returns enrichment data for Domain or IP for available observables. name: threatstream-get-passive-dns outputs: - contextPath: ThreatStream.PassiveDNS.Domain description: The domain value. type: String - contextPath: ThreatStream.PassiveDNS.Ip description: The IP value. type: String - contextPath: ThreatStream.PassiveDNS.Rrtype description: The RRTYPE value. type: String - contextPath: ThreatStream.PassiveDNS.Source description: The source value. type: String - contextPath: ThreatStream.PassiveDNS.FirstSeen description: |- The first seen date. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time, in UTC time. type: String - contextPath: ThreatStream.PassiveDNS.LastSeen description: |- The last seen date. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time. type: String - arguments: - defaultValue: '50' description: The observable certainty level of a reported indicator type. name: confidence - description: Ratio (0-100) between the source confidence and the ThreatStream confidence. To use your specified confidence entirely and not re-assess the value using machine learning algorithms, set this argument to 100. name: source_confidence_weight - auto: PREDEFINED defaultValue: private description: Whether the indicator data is public or private to the organization. name: classification predefined: - private - public - auto: PREDEFINED defaultValue: exploit description: Type of threat associated with the imported observables. name: threat_type predefined: - adware - anomalous - anonymization - apt - bot - brute - c2 - compromised - crypto - data_leakage - ddos - dyn_dns - exfil - exploit - hack_tool - i2p - informational - malware - p2p - parked - phish - scan - sinkhole - spam - suppress - suspicious - tor - vps - auto: PREDEFINED defaultValue: low description: The potential impact of the indicator type with which the observable is believed to be associated. name: severity predefined: - low - medium - high - very-high - auto: PREDEFINED description: The import type of the indicator. name: import_type predefined: - datatext - file-id - url required: true - description: 'The imported data source. Can be one of the following: url or file-id datatext of the file uploaded to the War Room. Supported file types for file-id are: CSV, HTML, IOC, JSON, PDF, TXT.' name: import_value required: true - description: Indicator type to assign if a specific type is not associated with an observable. This is a global setting that applies to any imported IP-type observable when an explicit itype is not specified for it. name: ip_mapping - description: Indicator type to assign if a specific type is not associated with an observable. This is a global setting that applies to any imported domain-type observable when an explicit itype is not specified for it. name: domain_mapping - description: Indicator type to assign if a specific type is not associated with an observable. This is a global setting that applies to any imported URL-type observable when an explicit itype is not specified for it. name: url_mapping - description: Indicator type to assign if a specific type is not associated with an observable. This is a global setting that applies to any imported email-type observable when an explicit itype is not specified for it. name: email_mapping - description: Indicator type to assign if a specific type is not associated with an observable. This is a global setting that applies to any imported MD5-type observable when an explicit itype is not specified for it. name: md5_mapping - description: A comma-separated list of tags applied to the imported observables. For example, tag1,tag2. name: tags - auto: PREDEFINED description: You can add tags that are private to your organization by setting the tlp attribute for the tag to red. If you do not specify a tlp setting, the tag is visible to any ThreatStream user with access to the observable. name: tags_tlp predefined: - Red - Amber - Green - White - description: The timestamp when intelligence will expire on ThreatStream, in ISO format. For example, 2020-12-24T00:00:00. By default, the expiration_ts is set to 90 days from the current date. name: expiration_ts - auto: PREDEFINED defaultValue: 'inactive' description: Whether the import job must be approved from the ThreatStream user interface before observables become active. When default_state is set to active, observables become active upon submission, without requiring approval. In these cases, an import job is created on ThreatStream which is automatically approved. name: default_state predefined: - active - inactive description: 'Imports indicators (observables) into ThreatStream. The imported data must be approved using the ThreatStream UI. The data can be imported using one of three methods: plain-text, file, or URL. You must have the Approve Import privilege in order to import observables through the API with default_state set to active.' name: threatstream-import-indicator-with-approval outputs: - contextPath: ThreatStream.Import.JobID description: The identifier for the job on ThreatStream. type: Number - contextPath: ThreatStream.Import.ImportID description: The ID for the import job. type: Number - arguments: - defaultValue: '50' description: The observable certainty level of a reported indicator type. name: confidence - description: Ratio (0-100) between the source confidence and the ThreatStream confidence. To use your specified confidence entirely and not re-assess the value using machine learning algorithms, set this argument to 100. name: source_confidence_weight - description: The timestamp when intelligence will expire on ThreatStream, in ISO format. For example, 2020-12-24T00:00:00. By default, the expiration_ts is set to 90 days from the current date. name: expiration_ts - description: The severity to assign to the observable when it is imported. name: severity predefined: - low - medium - high - very-high auto: PREDEFINED - description: 'A comma-separated list of tags applied to the imported observables. For example, tag1,tag2. Note: In cases where tags are specified at both the global and per observable level, tags specified per observable overwrite global tags.' name: tags - description: A comma-separated list of trusted circle IDs with which threat data should be shared. name: trustedcircles - auto: PREDEFINED description: Denotes whether the indicator data is public or private to the organization. name: classification predefined: - private - public required: true - auto: PREDEFINED description: Whether unresolved domain observables included in the file will be accepted as valid in ThreatStream and imported. name: allow_unresolved predefined: - 'yes' - 'no' - description: The entry ID of a file (containing a JSON with an "objects" array and "meta" maps) that is uploaded to the War Room. It is recommended to use the "ThreatstreamBuildIocImportJson" script to build a valid JSON file if possible. name: file_id - description: The “meta” section will be added to this json, and we will send this json to the api endpoint. It is recommended to use the "ThreatstreamBuildIocImportJson" script to build a valid JSON file if possible. name: indicators_json - auto: PREDEFINED description: You can add tags that are private to your organization by setting the tlp attribute for the tag to red. If you do not specify a tlp setting, the tag is visible to any ThreatStream user with access to the observable. name: tags_tlp predefined: - Red - Amber - Green - White description: Imports indicators (observables) into ThreatStream. Approval is not required for the imported data. You must have the Approve Intel user permission to import without approval using the API. name: threatstream-import-indicator-without-approval - arguments: - auto: PREDEFINED description: The threat model of the returned list. name: model predefined: - actor - campaign - incident - signature - ttp - vulnerability - tipreport - malware - attack pattern required: true - description: Limits the model size list. Specifying limit=0 returns up to a maximum of 1000 models. For limit=0, the output is not set in the context. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Returns a list of threat models. name: threatstream-get-model-list outputs: - contextPath: ThreatStream.List.Type description: The threat model type. type: String - contextPath: ThreatStream.List.Name description: The threat model name. type: String - contextPath: ThreatStream.List.ID description: The threat model ID. type: String - contextPath: ThreatStream.List.CreatedTime description: 'The date and time of threat model creation. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time.' type: String - arguments: - auto: PREDEFINED description: The threat model. name: model predefined: - actor - campaign - incident - signature - ttp - vulnerability - tipreport required: true - description: The threat model ID. name: id required: true description: Returns an HTML file with a description of the threat model. name: threatstream-get-model-description outputs: - contextPath: File.Name description: The file name of the model description. type: String - contextPath: File.EntryID description: The entry ID of the model description. type: String - arguments: - auto: PREDEFINED description: The threat model. name: model predefined: - actor - campaign - incident - signature - ttp - vulnerability - tipreport - malware - attack pattern required: true - description: The model ID. name: id required: true - description: The maximum number of results to return. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Returns a list of indicators associated with the specified model and ID of the model. name: threatstream-get-indicators-by-model outputs: - contextPath: ThreatStream.Model.ModelType description: The threat model type. type: String - contextPath: ThreatStream.Model.ModelID description: The threat model ID. type: String - contextPath: ThreatStream.Model.Indicators.Value description: The value of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.ID description: The ID of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Severity description: The indicator severity associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Confidence description: The confidence of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Country description: The country of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Organization description: The organization of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.ASN description: The ASN of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Status description: The status of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Tags description: The tags of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Modified description: The date and time the indicator was last modified. type: String - contextPath: ThreatStream.Model.Indicators.Source description: The indicator source. type: String - contextPath: ThreatStream.Model.Indicators.Type description: The indicator type. type: String - arguments: - auto: PREDEFINED defaultValue: private description: Classification of the sandbox submission. name: submission_classification predefined: - private - public - auto: PREDEFINED defaultValue: WINDOWS7 description: The platform on which the submitted URL or file is run. To obtain a list of supported platforms, run the threatstream-supported-platforms command. name: report_platform predefined: - WINDOWS7 - WINDOWSXP - auto: PREDEFINED defaultValue: file description: The detonation type. name: submission_type predefined: - file - url required: true - description: The submission value. Possible values are a valid URL or a file ID that was uploaded to the War Room to detonate. name: submission_value required: true - auto: PREDEFINED defaultValue: 'true' description: Deprecated, must be set to 'true'. name: premium_sandbox predefined: - 'false' - 'true' deprecated: true - description: A comma-separated list of additional details for the indicator. This information is displayed in the Tag column of the ThreatStream UI. name: detail - default: true auto: PREDEFINED description: If you want to initiate an import job for observables discovered during detonation, set this value to true. Default value is true. name: import_indicators predefined: - 'false' - 'true' description: Submits a file or URL to the ThreatStream-hosted sandbox for detonation. name: threatstream-submit-to-sandbox outputs: - contextPath: ThreatStream.Analysis.ReportID description: The report ID submitted to the sandbox. type: String - contextPath: ThreatStream.Analysis.Status description: The analysis status. type: String - contextPath: ThreatStream.Analysis.Platform description: The platform of the submission submitted to the sandbox. type: String - arguments: - description: The report ID to check the status. name: report_id required: true description: Returns the current status of the report submitted to the sandbox. The report ID is returned from the threatstream-submit-to-sandbox command. name: threatstream-get-analysis-status outputs: - contextPath: ThreatStream.Analysis.ReportID description: The report ID of the file or URL that was detonated in the sandbox. type: String - contextPath: ThreatStream.Analysis.Status description: The report status of the file or URL that was detonated in the sandbox. type: String - contextPath: ThreatStream.Analysis.Platform description: The platform used for detonation. type: String - contextPath: ThreatStream.Analysis.Verdict description: The report verdict of the file or URL detonated in the sandbox. The verdict remains "benign" until detonation is complete. type: String - arguments: - description: The report ID to return. name: report_id required: true description: Returns the report of a file or URL submitted to the sandbox. name: threatstream-analysis-report outputs: - contextPath: ThreatStream.Analysis.ReportID description: The ID of the report submitted to the sandbox. type: String - contextPath: ThreatStream.Analysis.Category description: The report category. type: String - contextPath: ThreatStream.Analysis.Started description: The detonation start time. type: String - contextPath: ThreatStream.Analysis.Completed description: The detonation completion time. type: String - contextPath: ThreatStream.Analysis.Duration description: The duration of the detonation (in seconds). type: Number - contextPath: ThreatStream.Analysis.VmName description: The VM name. type: String - contextPath: ThreatStream.Analysis.VmID description: The VM ID. type: String - contextPath: ThreatStream.Analysis.Network.UdpSource description: The UDP source. type: String - contextPath: ThreatStream.Analysis.Network.UdpDestination description: The UDP destination. type: String - contextPath: ThreatStream.Analysis.Network.UdpPort description: The UDP port. type: String - contextPath: ThreatStream.Analysis.Network.IcmpSource description: The ICMP source. type: String - contextPath: ThreatStream.Analysis.Network.IcmpDestination description: The ICMP destination. type: String - contextPath: ThreatStream.Analysis.Network.IcmpPort description: The ICMP port. type: String - contextPath: ThreatStream.Analysis.Network.TcpSource description: The TCP source. type: String - contextPath: ThreatStream.Analysis.Network.TcpDestination description: The TCP destination. type: String - contextPath: ThreatStream.Analysis.Network.TcpPort description: The TCP port. type: String - contextPath: ThreatStream.Analysis.Network.HttpSource description: The source of the HTTP address. type: String - contextPath: ThreatStream.Analysis.Network.HttpDestinaton description: The destination of the HTTP address. type: String - contextPath: ThreatStream.Analysis.Network.HttpPort description: The port of the HTTP address. type: String - contextPath: ThreatStream.Analysis.Network.HttpsSource description: The source of the HTTPS address. type: String - contextPath: ThreatStream.Analysis.Network.HttpsDestinaton description: The destination of the HTTPS address. type: String - contextPath: ThreatStream.Analysis.Network.HttpsPort description: The port of the HTTPS address. type: String - contextPath: ThreatStream.Analysis.Network.Hosts description: The network analysis hosts. type: String - contextPath: ThreatStream.Analysis.Verdict description: The verdict of the sandbox detonation. type: String - arguments: - description: The Anomali Observable Search Filter Language query to filter indicator results. If a query is passed as an argument, it overrides all other arguments. name: query - description: The Autonomous System (AS) number associated with the indicator. name: asn - description: |- The observable certainty level of a reported indicator type. Confidence scores range from 0-100 in increasing order of confidence, and are assigned by ThreatStream based on several factors. name: confidence - description: The country associated with the indicator. name: country - description: |- The date the indicator was first seen on the ThreatStream cloud platform. The date must be specified in this format: YYYYMMDDThhmmss, where "T" denotes the start of the value for time, in UTC time. For example, 2014-10-02T20:44:35. name: created_ts - description: The unique ID for the indicator. name: id - auto: PREDEFINED description: Whether the classification of the indicator is public. Default is "false". name: is_public predefined: - 'false' - 'true' - description: The severity assigned to the indicator by ThreatStream. name: indicator_severity - description: The registered owner (organization) of the IP address associated with the indicator. name: org - auto: PREDEFINED description: The status assigned to the indicator. name: status predefined: - active - inactive - falsepos - description: The tag assigned to the indicator. name: tags_name - auto: PREDEFINED description: The type of indicator. name: type predefined: - domain - email - ip - md5 - string - url - description: 'The value of the indicator. .' name: indicator_value - description: The maximum number of results to return from ThreatStream. Default value is 20. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Return filtered indicators from ThreatStream. If a query is defined, it overrides all other arguments that were passed to the command. name: threatstream-get-indicators outputs: - contextPath: ThreatStream.Indicators.IType description: The indicator type. type: String - contextPath: ThreatStream.Indicators.Modified description: |- The date and time the indicator was last updated in ThreatStream. The date format is: YYYYMMDDThhmmss, where T denotes the start of the value for time in UTC time. type: String - contextPath: ThreatStream.Indicators.Confidence description: The observable certainty level of a reported indicator type. type: String - contextPath: ThreatStream.Indicators.Value description: The indicator value. type: String - contextPath: ThreatStream.Indicators.Status description: The indicator status. type: String - contextPath: ThreatStream.Indicators.Organization description: The registered owner (organization) of the IP address associated with the indicator. type: String - contextPath: ThreatStream.Indicators.Country description: The country associated with the indicator. type: String - contextPath: ThreatStream.Indicators.Tags description: The tag assigned to the indicator. type: String - contextPath: ThreatStream.Indicators.Source description: The indicator source. type: String - contextPath: ThreatStream.Indicators.ID description: The indicator ID. type: String - contextPath: ThreatStream.Indicators.ASN description: The Autonomous System (AS) number associated with the indicator. type: String - contextPath: ThreatStream.Indicators.Severity description: The severity assigned to the indicator. type: String - arguments: - auto: PREDEFINED defaultValue: intelligence description: The type of threat model entity to which to add the tag. name: model predefined: - actor - campaign - incident - intelligence - signature - tipreport - ttp - vulnerability - description: 'A comma-separated list of tags applied to the specified threat model entities or observables. .' isArray: true name: tags required: true - description: The ID of the model to which to add the tag. name: model_id required: true description: Adds tags to intelligence to filter for related entities. name: threatstream-add-tag-to-model - arguments: - auto: PREDEFINED description: The type of threat model to create. name: model predefined: - actor - campaign - incident - ttp - vulnerability - tipreport required: true - description: The name of the threat model to create. name: name required: true - auto: PREDEFINED defaultValue: 'false' description: Whether the scope of threat model is visible. name: is_public predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: red description: The Traffic Light Protocol designation for the threat model. name: tlp predefined: - red - amber - green - white - description: A comma-separated list of tags. name: tags - description: A comma-separated list of indicators IDs associated with the threat model on the ThreatStream platform. name: intelligence - description: The description of the threat model. name: description description: Creates a threat model with the specified parameters. name: threatstream-create-model outputs: - contextPath: ThreatStream.Model.ModelType description: The threat model type. type: String - contextPath: ThreatStream.Model.ModelID description: The threat model ID. type: String - contextPath: ThreatStream.Model.Indicators.Value description: The value of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.ID description: The ID of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Severity description: The severity of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Confidence description: The confidence of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Country description: The country of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Organization description: The organization of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.ASN description: The ASN of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Status description: The status of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Tags description: The tags of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Modified description: The date and time the indicator was last modified. type: String - contextPath: ThreatStream.Model.Indicators.Source description: The indicator source. type: String - contextPath: ThreatStream.Model.Indicators.Type description: The indicator type. type: String - arguments: - auto: PREDEFINED description: The type of threat model to update. name: model predefined: - actor - campaign - incident - ttp - vulnerability - tipreport required: true - description: The ID of the threat model to update. name: model_id required: true - description: The name of the threat model to update. name: name - auto: PREDEFINED defaultValue: 'false' description: Whether the scope of threat model is visible. name: is_public predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: red description: The Traffic Light Protocol designation for the threat model. name: tlp predefined: - red - amber - green - white - description: A comma-separated list of tags. name: tags - description: A comma-separated list of indicator IDs associated with the threat model on the ThreatStream platform. name: intelligence - description: The description of the threat model. name: description description: Updates a threat model with specific parameters. If one or more optional parameters are defined, the command overrides previous data stored in ThreatStream. name: threatstream-update-model outputs: - contextPath: ThreatStream.Model.ModelType description: The threat model type. type: String - contextPath: ThreatStream.Model.ModelID description: The threat model ID. type: String - contextPath: ThreatStream.Model.Indicators.Value description: The value of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.ID description: The ID of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Severity description: The severity of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Confidence description: The confidence of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Country description: The country of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Organization description: The organization of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.ASN description: The ASN of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Status description: The status of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Tags description: The tags of the indicator associated with the specified model. type: String - contextPath: ThreatStream.Model.Indicators.Modified description: The date and time the indicator was last modified. type: String - contextPath: ThreatStream.Model.Indicators.Source description: The indicator source. type: String - contextPath: ThreatStream.Model.Indicators.Type description: The indicator type. type: String - arguments: - auto: PREDEFINED defaultValue: default description: The type of sandbox. name: sandbox_type predefined: - default - premium - defaultValue: '50' description: The maximum number of results to return from ThreatStream. name: limit - auto: PREDEFINED defaultValue: 'false' description: 'Whether to retrieve all results. The "limit" argument will be ignored.' name: all_results predefined: - 'false' - 'true' description: Returns a list of supported platforms for default or premium sandbox. name: threatstream-supported-platforms outputs: - contextPath: ThreatStream.PremiumPlatforms.Name description: The name of the supported platform for the premium sandbox. type: String - contextPath: ThreatStream.PremiumPlatforms.Types description: The type of supported submissions for the premium sandbox. type: String - contextPath: ThreatStream.PremiumPlatforms.Label description: The display name of the supported platform of the premium sandbox. type: String - contextPath: ThreatStream.DefaultPlatforms.Name description: The name of the supported platform for the standard sandbox. type: String - contextPath: ThreatStream.DefaultPlatforms.Types description: The type of the supported submissions for the standard sandbox. type: String - contextPath: ThreatStream.DefaultPlatforms.Label description: The display name of the supported platform of the standard sandbox. type: String - arguments: - default: true description: The URL to check. isArray: true name: url required: true - description: If confidence is greater than the threshold the URL is considered malicious, otherwise it is considered good. This argument overrides the default URL threshold defined as a parameter. name: threshold - auto: PREDEFINED description: Whether to include results with an inactive status. name: include_inactive predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: 'Enhance generic reputation commands to include additional information such as Threat Bulletins, Attach patterns, Actors, Campaigns, TTPs, vulnerabilities, etc. Note: If set to true, additional 6 API calls will be performed.' name: threat_model_association predefined: - 'True' - 'False' description: Checks the reputation of the given URL. name: url outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: URL.Data description: The URL of the indicator. type: String - contextPath: URL.Malicious.Vendor description: The vendor that reported the indicator as malicious. type: String - contextPath: ThreatStream.URL.Modified description: |- The date and time the indicator was last updated. The date format is: YYYYMMDDThhmmss, where "T" denotes the start of the value for time in UTC time. type: String - contextPath: ThreatStream.URL.Confidence description: The observable certainty level of a reported indicator type. Confidence score ranges from 0-100, in increasing order of confidence. type: String - contextPath: ThreatStream.URL.Status description: The indicator status. type: String - contextPath: ThreatStream.URL.Organization description: The name of the business that owns the IP address associated with the indicator. type: String - contextPath: ThreatStream.URL.Address description: The indicator URL. type: String - contextPath: ThreatStream.URL.Country description: The country associated with the indicator. type: String - contextPath: ThreatStream.URL.Type description: The indicator type. type: String - contextPath: ThreatStream.URL.Source description: The indicator source. type: String - contextPath: ThreatStream.URL.Severity description: The indicator severity ("very-high", "high", "medium", or "low"). type: String - contextPath: ThreatStream.URL.Tags description: Tags assigned to the URL. type: Unknown - contextPath: ThreatStream.URL.IType description: The itype of the indicator associated with the specified model. type: String - contextPath: URL.Tags description: List of URL tags. type: Unknown - contextPath: URL.ThreatTypes description: Threat types associated with the url. type: Unknown - contextPath: ThreatStream.URL.Actor.assignee_user description: The assignee user of the threat actor. type: Unknown - contextPath: ThreatStream.URL.Actor.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.URL.Actor.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.URL.Actor.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.URL.Actor.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.URL.Actor.created_ts description: The date the threat actor was created. type: Date - contextPath: ThreatStream.URL.Actor.feed_id description: The feed ID of the threat actor. type: Number - contextPath: ThreatStream.URL.Actor.id description: The ID of the threat actor. type: Number - contextPath: ThreatStream.URL.Actor.is_anonymous description: Whether the threat actor is anonymous. type: Boolean - contextPath: ThreatStream.URL.Actor.is_cloneable description: Whether the threat actor is cloneable. type: String - contextPath: ThreatStream.URL.Actor.is_public description: Whether the threat actor is public. type: Boolean - contextPath: ThreatStream.URL.Actor.is_team description: Whether the threat actor is a team. type: Boolean - contextPath: ThreatStream.URL.Actor.modified_ts description: The date the threat actor was modified. type: Date - contextPath: ThreatStream.URL.Actor.name description: The name of the threat actor. type: String - contextPath: ThreatStream.URL.Actor.organization_id description: The organization ID of the threat actor. type: Number - contextPath: ThreatStream.URL.Actor.owner_user_id description: The owner user ID of the threat actor. type: Number - contextPath: ThreatStream.URL.Actor.primary_motivation description: The primary motivation of the threat actor. type: Unknown - contextPath: ThreatStream.URL.Actor.publication_status description: The publication status of the threat actor. type: String - contextPath: ThreatStream.URL.Actor.published_ts description: The date the threat actor was published. type: Date - contextPath: ThreatStream.URL.Actor.resource_level description: The resource level of the threat actor. type: Unknown - contextPath: ThreatStream.URL.Actor.resource_uri description: The resource URI of the threat actor. type: String - contextPath: ThreatStream.URL.Actor.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.URL.Actor.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.URL.Actor.start_date description: The start date. type: Unknown - contextPath: ThreatStream.URL.Actor.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.URL.Actor.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.URL.Actor.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.URL.Actor.tlp description: The TLP of the threat actor. type: String - contextPath: ThreatStream.URL.Actor.uuid description: The UUID of the threat actor. type: String - contextPath: ThreatStream.URL.Signature.assignee_user description: The assignee user of the signature. type: Unknown - contextPath: ThreatStream.URL.Signature.association_info.comment description: The comment in the association info of the signature. type: Unknown - contextPath: ThreatStream.URL.Signature.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.URL.Signature.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.URL.Signature.can_add_public_tags description: Whether you can add public tags to the signature. type: Boolean - contextPath: ThreatStream.URL.Signature.created_ts description: The date the signature was created. type: Date - contextPath: ThreatStream.URL.Signature.feed_id description: The feed ID of the signature. type: Number - contextPath: ThreatStream.URL.Signature.id description: The ID of the signature. type: Number - contextPath: ThreatStream.URL.Signature.is_anonymous description: Whether the signature is anonymous. type: Boolean - contextPath: ThreatStream.URL.Signature.is_cloneable description: Whether the signature is cloneable. type: String - contextPath: ThreatStream.URL.Signature.is_public description: Whether the signature is public. type: Boolean - contextPath: ThreatStream.URL.Signature.is_team description: Whether the signature is a team signature. type: Boolean - contextPath: ThreatStream.URL.Signature.modified_ts description: The date the signature was modified. type: Date - contextPath: ThreatStream.URL.Signature.name description: The name of the signature. type: String - contextPath: ThreatStream.URL.Signature.organization_id description: The organization ID of the signature. type: Number - contextPath: ThreatStream.URL.Signature.owner_user_id description: The owner user ID of the signature. type: Number - contextPath: ThreatStream.URL.Signature.primary_motivation description: The primary motivation of the signature. type: Unknown - contextPath: ThreatStream.URL.Signature.publication_status description: The publication status of the signature. type: String - contextPath: ThreatStream.URL.Signature.published_ts description: The date the signature was published. type: Date - contextPath: ThreatStream.URL.Signature.resource_level description: The resource level of the signature. type: Unknown - contextPath: ThreatStream.URL.Signature.resource_uri description: The resource URI of the signature. type: String - contextPath: ThreatStream.URL.Signature.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.URL.Signature.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.URL.Signature.start_date description: The start date. type: Unknown - contextPath: ThreatStream.URL.Signature.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.URL.Signature.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.URL.Signature.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.URL.Signature.tlp description: The TLP of the signature. type: String - contextPath: ThreatStream.URL.Signature.uuid description: The UUID of the signature. type: String - contextPath: ThreatStream.URL.ThreatBulletin.all_circles_visible description: Whether all of the circles are visible. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.assignee_org description: The assignee organization. type: String - contextPath: ThreatStream.URL.ThreatBulletin.assignee_org_id description: The assignee organization ID. type: String - contextPath: ThreatStream.URL.ThreatBulletin.assignee_org_name description: The assignee organization name. type: String - contextPath: ThreatStream.URL.ThreatBulletin.assignee_user description: The assignee user. type: String - contextPath: ThreatStream.URL.ThreatBulletin.assignee_user_id description: The assignee user ID. type: String - contextPath: ThreatStream.URL.ThreatBulletin.assignee_user_name description: The assignee user name. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.association_info.comment description: The comment in the association info of the threat actor. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.URL.ThreatBulletin.association_info.from_id description: The ID from which the association info is related. type: String - contextPath: ThreatStream.URL.ThreatBulletin.body_content_type description: The body content type. type: String - contextPath: ThreatStream.URL.ThreatBulletin.campaign description: The campaign of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.can_add_public_tags description: Whether you can add public tags. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.created_ts description: The date the threat bulletin was created. type: Date - contextPath: ThreatStream.URL.ThreatBulletin.feed_id description: The feed ID of the threat bulletin. type: Number - contextPath: ThreatStream.URL.ThreatBulletin.id description: The ID of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.is_anonymous description: Whether the threat bulletin is anonymous. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.is_cloneable description: Whether the threat bulletin is cloneable. type: String - contextPath: ThreatStream.URL.ThreatBulletin.is_editable description: Whether the threat bulletin is editable. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.is_email description: Whether the threat bulletin is an email. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.is_public description: Whether the threat bulletin is public. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.modified_ts description: The date the threat bulletin was modified. type: Date - contextPath: ThreatStream.URL.ThreatBulletin.name description: The name of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.original_source description: The original source of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.original_source_id description: The original source ID of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_org.resource_uri description: The owner organization URI. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_org_id description: The ID of the owner user. type: Number - contextPath: ThreatStream.URL.ThreatBulletin.owner_org_name description: The name of the owner organization. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.avatar_s3_url description: The URL of the owner user. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.can_share_intelligence description: Whether you can share intelligence. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.email description: The email of the owner user. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.id description: The ID of the owner user. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.is_active description: Whether the owner user is active. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.is_readonly description: Whether the owner user has read-only permission. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.must_change_password description: Whether the owner user must change the password. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.name description: The owner user name. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.nickname description: The owner user nickname. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.organization.id description: The ID of the owner user organization. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.organization.name description: The name of the owner user organization. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.organization.resource_uri description: The resource URI of the owner user organization. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user.resource_uri description: The resource URI of the owner user. type: String - contextPath: ThreatStream.URL.ThreatBulletin.owner_user_id description: The owner user ID of the threat bulletin. type: Number - contextPath: ThreatStream.URL.ThreatBulletin.owner_user_name description: The owner user name of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.parent description: The parent of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.published_ts description: The date the threat bulletin was published. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.resource_uri description: The resource URI of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.source description: The source of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.starred_by_me description: Whether the threat bulletin was started by me. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.starred_total_count description: The total number of times the threat bulletin was starred. type: Number - contextPath: ThreatStream.URL.ThreatBulletin.status description: The status of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.threat_actor description: The threat actor of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.tlp description: The TLP of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.ttp description: The TTP of the threat bulletin. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.uuid description: The UUID of the threat bulletin. type: String - contextPath: ThreatStream.URL.ThreatBulletin.votes.me description: The number of votes by me. type: Unknown - contextPath: ThreatStream.URL.ThreatBulletin.votes.total description: The number of total votes. type: Number - contextPath: ThreatStream.URL.ThreatBulletin.watched_by_me description: Whether the threat bulletin was watched by me. type: Boolean - contextPath: ThreatStream.URL.ThreatBulletin.watched_total_count description: The total number of watchers. type: Number - contextPath: ThreatStream.URL.TTP.assignee_user description: The assignee user of the TTP. type: Unknown - contextPath: ThreatStream.URL.TTP.association_info.comment description: The comment in the association info of the TTP. type: Unknown - contextPath: ThreatStream.URL.TTP.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.URL.TTP.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.URL.TTP.can_add_public_tags description: Whether you can add public tags to the TTP. type: Boolean - contextPath: ThreatStream.URL.TTP.created_ts description: The date the TTP was created. type: Date - contextPath: ThreatStream.URL.TTP.feed_id description: The feed ID of the TTP. type: Number - contextPath: ThreatStream.URL.TTP.id description: The ID of the TTP. type: Number - contextPath: ThreatStream.URL.TTP.is_anonymous description: Whether the TTP was anonymous. type: Boolean - contextPath: ThreatStream.URL.TTP.is_cloneable description: Whether the TTP was cloneable. type: String - contextPath: ThreatStream.URL.TTP.is_public description: Whether the TTP is public. type: Boolean - contextPath: ThreatStream.URL.TTP.is_team description: Whether the TTP is a team. type: Boolean - contextPath: ThreatStream.URL.TTP.modified_ts description: The date the TTP was modified. type: Date - contextPath: ThreatStream.URL.TTP.name description: The name of the TTP. type: String - contextPath: ThreatStream.URL.TTP.organization_id description: The organization ID of the TTP. type: Number - contextPath: ThreatStream.URL.TTP.owner_user_id description: The owner user ID of the TTP. type: Number - contextPath: ThreatStream.URL.TTP.primary_motivation description: The primary motivation of the TTP. type: Unknown - contextPath: ThreatStream.URL.TTP.publication_status description: The publication status of the TTP. type: String - contextPath: ThreatStream.URL.TTP.published_ts description: The date the TTP was published. type: Date - contextPath: ThreatStream.URL.TTP.resource_level description: The resource level of the TTP. type: Unknown - contextPath: ThreatStream.URL.TTP.resource_uri description: The resource URI of the TTP. type: String - contextPath: ThreatStream.URL.TTP.source_created description: The date the source was created. type: Unknown - contextPath: ThreatStream.URL.TTP.source_modified description: The date the source was modified. type: Unknown - contextPath: ThreatStream.URL.TTP.start_date description: The start date. type: Unknown - contextPath: ThreatStream.URL.TTP.tags description: The tags of the threat indicator. type: String - contextPath: ThreatStream.URL.TTP.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.URL.TTP.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.URL.TTP.tlp description: The TLP of the TTP. type: String - contextPath: ThreatStream.URL.TTP.uuid description: The UUID of the TTP. type: String - contextPath: ThreatStream.URL.Vulnerability.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.URL.Vulnerability.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.URL.Vulnerability.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.URL.Vulnerability.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.URL.Vulnerability.can_add_public_tags description: Whether you can add public tags to the threat actor. type: Boolean - contextPath: ThreatStream.URL.Vulnerability.circles.id description: The ID of the circle. type: String - contextPath: ThreatStream.URL.Vulnerability.circles.name description: The name of the circle. type: String - contextPath: ThreatStream.URL.Vulnerability.circles.resource_uri description: The resource URI of the circle. type: String - contextPath: ThreatStream.URL.Vulnerability.created_ts description: The date the vulnerability was created. type: Date - contextPath: ThreatStream.URL.Vulnerability.feed_id description: The feed ID of the vulnerability. type: Number - contextPath: ThreatStream.URL.Vulnerability.id description: The ID of the vulnerability. type: Number - contextPath: ThreatStream.URL.Vulnerability.is_anonymous description: Whether the vulnerability is anonymous. type: Boolean - contextPath: ThreatStream.URL.Vulnerability.is_cloneable description: Whether the vulnerability is cloneable. type: String - contextPath: ThreatStream.URL.Vulnerability.is_public description: Whether the vulnerability is public. type: Boolean - contextPath: ThreatStream.URL.Vulnerability.is_system description: Whether the vulnerability is in the system. type: Boolean - contextPath: ThreatStream.URL.Vulnerability.modified_ts description: The date the vulnerability was modified. type: Date - contextPath: ThreatStream.URL.Vulnerability.name description: The name of the vulnerability. type: String - contextPath: ThreatStream.URL.Vulnerability.organization_id description: The organization ID of the vulnerability. type: Number - contextPath: ThreatStream.URL.Vulnerability.owner_user_id description: The owner user ID of the vulnerability. type: Unknown - contextPath: ThreatStream.URL.Vulnerability.publication_status description: The publication status of the vulnerability. type: String - contextPath: ThreatStream.URL.Vulnerability.published_ts description: The date the vulnerability was published. type: Date - contextPath: ThreatStream.URL.Vulnerability.resource_uri description: The resource URI of the vulnerability. type: String - contextPath: ThreatStream.URL.Vulnerability.source description: The source of the vulnerability. type: String - contextPath: ThreatStream.URL.Vulnerability.source_created description: The feed ID of the vulnerability. type: Unknown - contextPath: ThreatStream.URL.Vulnerability.source_modified description: Whether the source was modified. type: Unknown - contextPath: ThreatStream.URL.Vulnerability.tags description: The tags of the vulnerability. type: String - contextPath: ThreatStream.URL.Vulnerability.tags_v2.id description: The ID of the tag. type: String - contextPath: ThreatStream.URL.Vulnerability.tags_v2.name description: The name of the tag. type: String - contextPath: ThreatStream.URL.Vulnerability.tlp description: The TLP of the vulnerability. type: String - contextPath: ThreatStream.URL.Vulnerability.update_id description: The update ID of the vulnerability. type: Number - contextPath: ThreatStream.URL.Vulnerability.uuid description: The UUID of the vulnerability. type: String - contextPath: ThreatStream.URL.Campaign.assignee_user description: The assignee user of the vulnerability. type: Unknown - contextPath: ThreatStream.URL.Campaign.association_info.comment description: The comment in the association info of the vulnerability. type: Unknown - contextPath: ThreatStream.URL.Campaign.association_info.created description: The date the association info was created. type: Date - contextPath: ThreatStream.URL.Campaign.association_info.from_id description: The ID from which the association info is related. type: Number - contextPath: ThreatStream.URL.Campaign.can_add_public_tags description: Whether you can add public tags to the campaign. type: Boolean - contextPath: ThreatStream.URL.Campaign.created_ts description: The date the campaign was created. type: Date - contextPath: ThreatStream.URL.Campaign.end_date description: The end date of the campaign. type: Unknown - contextPath: ThreatStream.URL.Campaign.feed_id description: The feed ID of the campaign. type: Number - contextPath: ThreatStream.URL.Campaign.id description: The ID of the campaign. type: Number - contextPath: ThreatStream.URL.Campaign.is_anonymous description: Whether the campaign is anonymous. type: Boolean - contextPath: ThreatStream.URL.Campaign.is_cloneable description: Whether the campaign is cloneable. type: String - contextPath: ThreatStream.URL.Campaign.is_public description: Whether the campaign is public. type: Boolean - contextPath: ThreatStream.URL.Campaign.modified_ts description: The date the campaign was modified. type: Date - contextPath: ThreatStream.URL.Campaign.name description: The name of the campaign. type: String - contextPath: ThreatStream.URL.Campaign.objective description: The objective of the campaign. type: Unknown - contextPath: ThreatStream.URL.Campaign.organization_id description: The organization ID of the campaign. type: Number - contextPath: ThreatStream.URL.Campaign.owner_user_id description: The owner user ID of the campaign. type: Number - contextPath: ThreatStream.URL.Campaign.publication_status description: The publication status of the campaign. type: String - contextPath: ThreatStream.URL.Campaign.published_ts description: The date the campaign was published. type: Unknown - contextPath: ThreatStream.URL.Campaign.resource_uri description: The resource URI of the campaign. type: String - contextPath: ThreatStream.URL.Campaign.source_created description: The date the campaign was created. type: Date - contextPath: ThreatStream.URL.Campaign.source_modified description: Whether the source was modified. type: Date - contextPath: ThreatStream.URL.Campaign.start_date description: The start date of the campaign. type: Unknown - contextPath: ThreatStream.URL.Campaign.status.display_name description: The display name of the status. type: String - contextPath: ThreatStream.URL.Campaign.status.id description: The ID of the status of the campaign. type: Number - contextPath: ThreatStream.URL.Campaign.status.resource_uri description: The resource URI of the status of the campaign. type: String - contextPath: ThreatStream.URL.Campaign.tlp description: The TLP of the campaign. type: String - contextPath: ThreatStream.URL.Campaign.uuid description: The UUID of the campaign. type: String - arguments: - description: The value of an intelligence. name: value - description: The UUID of an intelligence. When several UUIDs stated, an “OR” operator is used. isArray: true name: uuid - auto: PREDEFINED description: The type of an intelligence. name: type predefined: - domain - email - ip - md5 - string - url - description: The itType of an intelligence. (e.g., apt_ip, apt_email). name: itype - auto: PREDEFINED description: The status of an intelligence. name: status predefined: - active - inactive - falsepos - description: The tags of an intelligence. Comma-separated list. When several tags are stated, an “OR” operator is used. isArray: true name: tags - description: The ASN of an intelligence. name: asn - description: The confidence of an intelligence. Input will be operator then value, i.e., “gt 65” or “lt 85”. If only a value is stated, then it must match exactly. name: confidence - description: The threat type of an intelligence. name: threat_type - description: Whether the intelligence is public. name: is_public - description: Query that overrides all other arguments. The filter operators used for the filter language query are the symbolic form (=, <, >, and so on) and not the descriptive form (exact, lt, gt, and so on). E.g., (confidence>=90+AND+(itype="apt_ip"+OR+itype="bot_ip"+OR+itype="c2_ip")). name: query - description: An incrementing numeric identifier associated with each update to intelligence on ThreatStream. If specified, then it is recommended to use order_by=update_id. name: update_id_gt - description: How to order the results. name: order_by - defaultValue: '50' description: The maximum number of results to return from ThreatStream. The maximum number of returned results is 1000. For more results, use the page and page_size arguments. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Returns filtered intelligence from ThreatStream. If a query is defined, it overrides all other arguments that were passed to the command. name: threatstream-search-intelligence outputs: - contextPath: ThreatStream.Intelligence.source_created description: The source from which the intelligence was created. type: String - contextPath: ThreatStream.Intelligence.status description: The status of the intelligence. type: String - contextPath: ThreatStream.Intelligence.itype description: The itype of the intelligence. type: String - contextPath: ThreatStream.Intelligence.expiration_ts description: The expiration timestamp of the intelligence. type: Date - contextPath: ThreatStream.Intelligence.ip description: The IP address of the intelligence. type: String - contextPath: ThreatStream.Intelligence.is_editable description: Whether the intelligence is editable. type: Boolean - contextPath: ThreatStream.Intelligence.feed_id description: The feed ID of the intelligence. type: String - contextPath: ThreatStream.Intelligence.update_id description: The update ID of the intelligence. type: String - contextPath: ThreatStream.Intelligence.value description: The value of the intelligence. type: String - contextPath: ThreatStream.Intelligence.is_public description: Whether the intelligence is public. type: Boolean - contextPath: ThreatStream.Intelligence.threattype description: The threat type of the intelligence. type: String - contextPath: ThreatStream.Intelligence.workgroups description: The work groups of the intelligence. type: String - contextPath: ThreatStream.Intelligence.confidence description: The confidence of the intelligence. type: String - contextPath: ThreatStream.Intelligence.uuid description: The UUID of the intelligence. type: String - contextPath: ThreatStream.Intelligence.retina_confidence description: The retina confidence of the intelligence. type: String - contextPath: ThreatStream.Intelligence.trusted_circle_ids description: The trusted circleIDs of the intelligence. type: String - contextPath: ThreatStream.Intelligence.id description: The ID of the intelligence. type: String - contextPath: ThreatStream.Intelligence.source description: The source of the iIntelligence. type: String - contextPath: ThreatStream.Intelligence.owner_organization_id description: The owner organization ID of the intelligence. type: String - contextPath: ThreatStream.Intelligence.import_session_id description: The import session ID of the intelligence. type: String - contextPath: ThreatStream.Intelligence.source_modified description: Whether the the source was modified. type: Boolean - contextPath: ThreatStream.Intelligence.type description: The type of the intelligence. type: String - contextPath: ThreatStream.Intelligence.description description: The description of the intelligence. type: String - contextPath: ThreatStream.Intelligence.tags description: The tags of the intelligence. type: String - contextPath: ThreatStream.Intelligence.threatscore description: The threat score of the intelligence. type: String - contextPath: ThreatStream.Intelligence.latitude description: The latitude of the intelligence. type: String - contextPath: ThreatStream.Intelligence.longitude description: The longitude of the intelligence. type: String - contextPath: ThreatStream.Intelligence.modified_ts description: The date the intelligence was modified. type: Date - contextPath: ThreatStream.Intelligence.org description: The organization of the intelligence. type: String - contextPath: ThreatStream.Intelligence.asn description: The ASN of the intelligence. type: Number - contextPath: ThreatStream.Intelligence.created_ts description: The date the intelligence was created. type: Date - contextPath: ThreatStream.Intelligence.tlp description: The TLP of the intelligence. type: String - contextPath: ThreatStream.Intelligence.is_anonymous description: Whether the intelligence is anonymous. type: Boolean - contextPath: ThreatStream.Intelligence.country description: The country of the intelligence. type: String - contextPath: ThreatStream.Intelligence.source_reported_confidence description: The confidence of the reported source. type: String - contextPath: ThreatStream.Intelligence.subtype description: The subtype of the intelligence. type: String - contextPath: ThreatStream.Intelligence.resource_uri description: The resource URI of the intelligence. type: String - contextPath: ThreatStream.Intelligence.severity description: The severity of the intelligence. type: String - arguments: - description: Unique ID assigned to the rule. name: rule_id - description: The maximum number of results to return. Default is 50. name: limit - description: The page number of the results to retrieve. name: page - description: The maximum number of objects to retrieve per page. name: page_size description: Gets a list of rules from ThreatStream. name: threatstream-list-rule outputs: - contextPath: ThreatStream.Rule.adv_keyword description: Advanced keyword or regular expression that the rule is designed to match. type: Unknown - contextPath: ThreatStream.Rule.backfill description: Objects that define additional filters or conditions for the rule. type: Unknown - contextPath: ThreatStream.Rule.create_investigation description: Whether an investigation should be created when the rule is triggered. type: Boolean - contextPath: ThreatStream.Rule.created_ts description: Rule creation time. type: Date - contextPath: ThreatStream.Rule.description description: The rule description. type: Unknown - contextPath: ThreatStream.Rule.exclude_notify_org_whitelisted description: Whether to exclude the rule from matching observables that are included in the organization whitelist. type: Boolean - contextPath: ThreatStream.Rule.exclude_notify_owner_org description: Whether to exclude the rule from keyword matches on observables imported by the organization from keyword match or hourly digest email notifications. type: Boolean - contextPath: ThreatStream.Rule.has_associations description: Whether the rule has associations. type: Boolean - contextPath: ThreatStream.Rule.id description: Unique ID assigned to the rule. type: Number - contextPath: ThreatStream.Rule.intelligence_initiatives description: Intelligence initiatives associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.is_editable description: Indicates whether the imported rule can be updated by an intelligence source. type: Boolean - contextPath: ThreatStream.Rule.is_enabled description: Whether the rule is currently enabled. type: Boolean - contextPath: ThreatStream.Rule.keyword description: Keyword associated with the rule. type: String - contextPath: ThreatStream.Rule.keywords description: A list of keywords associated with the rule. type: String - contextPath: ThreatStream.Rule.match_actors description: Whether the rule matches keywords in newly created actors. type: Boolean - contextPath: ThreatStream.Rule.match_all_tm description: Whether the rule should match against all threat models. type: Boolean - contextPath: ThreatStream.Rule.match_attackpatterns description: Whether the rule matches keywords in newly created attack patterns. type: Boolean - contextPath: ThreatStream.Rule.match_campaigns description: Whether the rule matches keywords in newly created campaigns. type: Boolean - contextPath: ThreatStream.Rule.match_courseofactions description: Whether the rule matches keywords in newly created course of actions. type: Boolean - contextPath: ThreatStream.Rule.match_customtms description: Whether the rule should match custom threat models. type: Boolean - contextPath: ThreatStream.Rule.match_identities description: Whether the rule matches keywords in newly created identities. type: Boolean - contextPath: ThreatStream.Rule.match_incidents description: Whether the rule matches keywords in newly created incidents. type: Boolean - contextPath: ThreatStream.Rule.match_infrastructures description: Whether the rule matches keywords in newly created infrastructures. type: Boolean - contextPath: ThreatStream.Rule.match_intrusionsets description: Whether the rule matches keywords in newly created intrusion sets. type: Boolean - contextPath: ThreatStream.Rule.match_malware description: Whether the rule matches keywords in newly created malware. type: Boolean - contextPath: ThreatStream.Rule.match_observables description: Whether the rule matches keywords in newly created observables. type: Boolean - contextPath: ThreatStream.Rule.match_reportedfiles description: Whether the rule should match keywords in newly created sandbox reports. type: Boolean - contextPath: ThreatStream.Rule.match_signatures description: Whether the rule should match keywords in newly created signatures. type: Boolean - contextPath: ThreatStream.Rule.match_tips description: Whether the rule matches keywords in newly created threat bulletins. type: Boolean - contextPath: ThreatStream.Rule.match_tools description: Whether the rule should match keywords in newly created tools. type: Boolean - contextPath: ThreatStream.Rule.match_ttps description: Whether the rule should match keywords in newly created TTPs. type: Boolean - contextPath: ThreatStream.Rule.match_vulnerabilities description: Whether the rule matches keywords in newly created vulnerabilities. type: Boolean - contextPath: ThreatStream.Rule.matches description: Total number of keyword matches for the rule. type: Number - contextPath: ThreatStream.Rule.messages description: Messages or notifications generated by the rule. type: Unknown - contextPath: ThreatStream.Rule.modified_ts description: Timestamp of when the rule was last modified, in UTC format. type: Date - contextPath: ThreatStream.Rule.name description: The rule name. type: String - contextPath: ThreatStream.Rule.notify_list_groups description: List of groups that should be notified when the rule triggers an alert. type: Unknown - contextPath: ThreatStream.Rule.notify_me description: Whether the user who created the rule should be notified when the rule triggers an alert. type: Boolean - contextPath: ThreatStream.Rule.org_id description: ID associated with the organization that created the rule. type: Number - contextPath: ThreatStream.Rule.org_shared description: Whether a rule is shared across an organization. type: Boolean - contextPath: ThreatStream.Rule.organization.id description: ID associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.organization.name description: Name associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.organization.resource_uri description: Resource URI associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.resource_uri description: Resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.user.avatar_s3_url description: URL for the avatar image associated with the user who created the rule. type: Unknown - contextPath: ThreatStream.Rule.user.can_share_intelligence description: Whether the user who created the rule can share intelligence. type: Boolean - contextPath: ThreatStream.Rule.user.email description: Email of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.id description: ID of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.is_active description: Whether the user who created the rule is active. type: Boolean - contextPath: ThreatStream.Rule.user.is_readonly description: Whether the user who created the rule should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Rule.user.must_change_password description: Whether the user who created the rule will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Rule.user.name description: Name of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.nickname description: Nickname of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.organization.id description: The ID associated to the organization. type: String - contextPath: ThreatStream.Rule.user.organization.name description: The user's organization name. type: String - contextPath: ThreatStream.Rule.user.organization.resource_uri description: The user's organization resource URI. type: String - contextPath: ThreatStream.Rule.user.resource_uri description: The user's resource URI. type: String - contextPath: ThreatStream.Rule.user_id description: User ID of the user who created the rule. type: Number - contextPath: ThreatStream.Rule.workgroups description: Assigned workgroups. type: Unknown - contextPath: ThreatStream.Rule.actors.id description: Actor's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.actors.name description: Actor's name associated with the rule. type: String - contextPath: ThreatStream.Rule.actors.resource_uri description: Actor's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.attackpatterns description: Attack patterns associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.campaigns.id description: Campaign's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.campaigns.name description: Campaign's name associated with the rule. type: String - contextPath: ThreatStream.Rule.campaigns.resource_uri description: Campaign's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.courseofaction description: Course of action entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.customtms description: Custom threat model entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.exclude_impacts description: Indicator types that are excluded from rule matches. type: String - contextPath: ThreatStream.Rule.identities description: List of identities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.incidents.id description: Incident's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.incidents.name description: Incident's name associated with the rule. type: String - contextPath: ThreatStream.Rule.incidents.resource_uri description: Incident's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.infrastructure description: Infrastructure entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.intrusionsets description: Intrusion sets associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Rule.investigation.assignee.avatar_s3_url description: URL for the avatar image associated with the assignee user. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.email description: The email of the assignee user. type: String - contextPath: ThreatStream.Rule.investigation.assignee.id description: The ID of the assignee user. type: String - contextPath: ThreatStream.Rule.investigation.assignee.is_active description: Whether the assignee user is active. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.is_readonly description: Whether the assignee user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.must_change_password description: Whether the investigation assignee user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.name description: The investigation assignee user name. type: String - contextPath: ThreatStream.Rule.investigation.assignee.nickname description: The investigation assignee user nickname. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.resource_uri description: Resource URI associated with investigation assignee user. type: String - contextPath: ThreatStream.Rule.investigation.id description: The ID of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.name description: The name of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.resource_uri description: The resource URI of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.users description: List of users associated with the investigation created by the rule. type: Unknown - contextPath: ThreatStream.Rule.investigation.workgroups description: Assigned workgroups. type: Unknown - contextPath: ThreatStream.Rule.malware.id description: ID of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.malware.name description: Name of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.malware.resource_uri description: Resource URI of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.match_impacts description: Indicator types in which you want to look for rule matches at the exclusion of all others. type: String - contextPath: ThreatStream.Rule.signatures.id description: ID of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.signatures.name description: Name of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.signatures.resource_uri description: Resource URI of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.tags.name description: Name of the tag applied to matched entities. type: String - contextPath: ThreatStream.Rule.tips.id description: ID of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tips.name description: Name of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tips.resource_uri description: Resource URI of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tools description: List of tools associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.ttps.id description: ID of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.ttps.name description: Name of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.ttps.resource_uri description: Resource URI of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.vulnerabilities.id description: ID of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.vulnerabilities.name description: Name of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.vulnerabilities.resource_uri description: Resource URI of the vulnerability with which to associate matched entities. type: String - arguments: - description: The name of the rule. name: rule_name required: true - description: 'A comma-separated list of keywords for which you want the rule to match. Keywords added to rules must adhere to the following requirements: IP addresses must be expressed as regular expressions. IP subnets should be expressed using CIDR notation and not as regular expressions. Do not start or end keywords with *. Keywords must contain at least three characters.' isArray: true name: keywords required: true - description: 'A comma-separated list of fields you want the rule to match to their keywords. Possible values: observables, sandbox reports, threat bulletins, signatures, vulnerabilities.' isArray: true name: match_include required: true - description: A comma-separated list of IDs of the actors with which you want to associate matched entities. Use the threatstream-get-model-list command to get the actor IDs. isArray: true name: actor_ids - description: A comma-separated list of IDs of the campaigns with which you want to associate matched entities. Use the threatstream-get-model-list command to get the campaign IDs. isArray: true name: campaign_ids - auto: PREDEFINED description: The action you want to perform related to the investigation. Default is 'No Action'. name: investigation_action predefined: - Create New - Add To Existing - No Action - description: The investigation name. Required when 'Create New' is selected in the investigation_action argument. name: new_investigation_name - description: Existing investigation ID. Required when 'Add To Existing' is selected in the investigation_action argument. Use the threatstream-list-investigation command to get the investigation ID. name: existing_investigation_id - description: 'A comma-separated list of indicator types you want to exclude from rule matches. Example: actor_ipv6.' isArray: true name: exclude_indicator - description: 'A comma-separated list of indicator types you want to include from rule matches. Example: actor_ipv6.' isArray: true name: include_indicator - auto: PREDEFINED description: Whether you want to exclude the rule from matching observables that are included in your organization whitelist. name: exclude_notify_org_whitelisted predefined: - 'True' - 'False' - auto: PREDEFINED description: Whether you want to exclude keyword matches on observables imported by your organization from a keyword match or hourly digest email notifications. name: exclude_notify_owner_org predefined: - 'True' - 'False' - description: A comma-separated list of IDs of the incidents with which you want to associate matched entities. Use the threatstream-get-model-list command to get the incident IDs. isArray: true name: incident_ids - description: A comma-separated list of IDs of the malwares with which you want to associate matched entities. Use the threatstream-get-model-list command to get the malware IDs. isArray: true name: malware_ids - description: A comma-separated list of IDs of the signatures with which you want to associate matched entities. Use the threatstream-get-model-list command to get the signature IDs. isArray: true name: signature_ids - description: A comma-separated list of IDs of the threat bulletin with which you want to associate matched entities. Use the threatstream-get-model-list command to get the threat bulletin IDs. isArray: true name: threat_bulletin_ids - description: A comma-separated list of IDs of the TTPs with which you want to associate matched entities. Use the threatstream-get-model-list command to get the TTPs IDs. isArray: true name: ttp_ids - description: A comma-separated list of IDs of the vulnerabilities with which you want to associate matched entities. Use the threatstream-get-model-list command to get the vulnerabilities IDs. isArray: true name: vulnerability_ids - description: A comma-separated list of IDs of the tags with which you want to associate matched entities. isArray: true name: tags description: Create a rule in the ThreatStream platform. name: threatstream-create-rule outputs: - contextPath: ThreatStream.Rule.actors.id description: Actor's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.actors.name description: Actor's name associated with the rule. type: String - contextPath: ThreatStream.Rule.actors.resource_uri description: Actor's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.adv_keyword description: Advanced keyword or regular expression that the rule is designed to match. type: Unknown - contextPath: ThreatStream.Rule.attackpatterns description: Attack patterns associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.backfill description: Objects that define additional filters or conditions for the rule. type: Unknown - contextPath: ThreatStream.Rule.campaigns.id description: Campaign's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.campaigns.name description: Campaign's name associated with the rule. type: String - contextPath: ThreatStream.Rule.campaigns.resource_uri description: Campaign's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.courseofaction description: Course of action entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.create_investigation description: Whether an investigation should be created when the rule is triggered. type: Boolean - contextPath: ThreatStream.Rule.created_ts description: Rule creation time. type: Date - contextPath: ThreatStream.Rule.customtms description: Custom threat model entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.description description: The rule description. type: Unknown - contextPath: ThreatStream.Rule.exclude_impacts description: Indicator types that are excluded from rule matches. type: String - contextPath: ThreatStream.Rule.exclude_notify_org_whitelisted description: Whether observables whitelisted by your organization are excluded from rule matches. type: Boolean - contextPath: ThreatStream.Rule.exclude_notify_owner_org description: Whether to exclude keyword matches on observables imported by your organization from keyword match or hourly digest email notifications. type: Boolean - contextPath: ThreatStream.Rule.id description: Unique ID assigned to the rule. type: Number - contextPath: ThreatStream.Rule.identities description: List of identities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.incidents.id description: Incident's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.incidents.name description: Incident's name associated with the rule. type: String - contextPath: ThreatStream.Rule.incidents.resource_uri description: Incident's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.infrastructure description: Infrastructure entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.intelligence_initiatives description: Intelligence initiatives associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.intrusionsets description: Intrusion sets associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Rule.investigation.assignee.avatar_s3_url description: URL for the avatar image associated with the assignee user. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.email description: The email of the assignee user. type: String - contextPath: ThreatStream.Rule.investigation.assignee.id description: The ID of the assignee user. type: String - contextPath: ThreatStream.Rule.investigation.assignee.is_active description: Whether the assignee user is active. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.is_readonly description: Whether the assignee user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.must_change_password description: Whether the assignee user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.name description: The investigation assignee user name. type: String - contextPath: ThreatStream.Rule.investigation.assignee.nickname description: The investigation assignee user nickname. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.resource_uri description: Resource URI associated with investigation assignee user. type: String - contextPath: ThreatStream.Rule.investigation.investigation_config.name description: The name of the investigation configuration associated with the rule. type: String - contextPath: ThreatStream.Rule.investigation.id description: The ID of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.name description: The name of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.resource_uri description: The resource URI of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.users description: List of users associated with the investigation created by the rule. type: Unknown - contextPath: ThreatStream.Rule.investigation.workgroups description: Assigned workgroups. type: Unknown - contextPath: ThreatStream.Rule.is_editable description: Indicates whether the imported rule can be updated by an intelligence source. type: Boolean - contextPath: ThreatStream.Rule.is_enabled description: Whether the rule is currently enabled. type: Boolean - contextPath: ThreatStream.Rule.keyword description: Keyword associated with the rule. type: String - contextPath: ThreatStream.Rule.keywords description: A list of keywords associated with the rule. type: String - contextPath: ThreatStream.Rule.malware.id description: ID of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.malware.name description: Name of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.malware.resource_uri description: Resource URI of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.match_actors description: Whether the rule matches keywords in newly created actors. type: Boolean - contextPath: ThreatStream.Rule.match_all_tm description: Whether the rule should match against all threat models. type: Boolean - contextPath: ThreatStream.Rule.match_attackpatterns description: Whether the rule matches keywords in newly created attack patterns. type: Boolean - contextPath: ThreatStream.Rule.match_campaigns description: Whether the rule matches keywords in newly created campaigns. type: Boolean - contextPath: ThreatStream.Rule.match_courseofactions description: Whether the rule matches keywords in newly created course of actions. type: Boolean - contextPath: ThreatStream.Rule.match_customtms description: Whether the rule should match custom threat models. type: Boolean - contextPath: ThreatStream.Rule.match_identities description: Whether the rule matches keywords in newly created identities. type: Boolean - contextPath: ThreatStream.Rule.match_impacts description: Indicator types in which you want to look for rule matches at the exclusion of all others. type: String - contextPath: ThreatStream.Rule.match_incidents description: Whether the rule matches keywords in newly created incidents. type: Boolean - contextPath: ThreatStream.Rule.match_infrastructures description: Whether the rule matches keywords in newly created infrastructures. type: Boolean - contextPath: ThreatStream.Rule.match_intrusionsets description: Whether the rule matches keywords in newly created intrusion sets. type: Boolean - contextPath: ThreatStream.Rule.match_malware description: Whether the rule matches keywords in newly created malware. type: Boolean - contextPath: ThreatStream.Rule.match_observables description: Whether the rule matches keywords in newly created observables. type: Boolean - contextPath: ThreatStream.Rule.match_reportedfiles description: Whether the rule should match keywords in newly created sandbox reports. type: Boolean - contextPath: ThreatStream.Rule.match_signatures description: Whether the rule should match keywords in newly created signatures. type: Boolean - contextPath: ThreatStream.Rule.match_tips description: Whether the rule should match keywords in newly created threat bulletins. type: Boolean - contextPath: ThreatStream.Rule.match_tools description: Whether the rule should match keywords in newly created tools. type: Boolean - contextPath: ThreatStream.Rule.match_ttps description: Whether the rule should match keywords in newly created TTPs. type: Boolean - contextPath: ThreatStream.Rule.match_vulnerabilities description: Whether the rule should match keywords in newly created vulnerabilities. type: Boolean - contextPath: ThreatStream.Rule.matches description: Total number of keyword matches for the rule. type: Number - contextPath: ThreatStream.Rule.messages description: Messages or notifications generated by the rule. type: Unknown - contextPath: ThreatStream.Rule.modified_ts description: Timestamp of when the rule was last modified, in UTC format. type: Date - contextPath: ThreatStream.Rule.name description: The rule name. type: String - contextPath: ThreatStream.Rule.notify_list_groups description: List of groups that should be notified when the rule triggers an alert. type: Unknown - contextPath: ThreatStream.Rule.notify_me description: Whether the user who created the rule should be notified when the rule triggers an alert. type: Boolean - contextPath: ThreatStream.Rule.org_id description: ID associated with the organization that created the rule. type: Number - contextPath: ThreatStream.Rule.org_shared description: Whether a rule is shared across an organization. type: Boolean - contextPath: ThreatStream.Rule.organization.id description: ID associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.organization.name description: Name associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.organization.resource_uri description: Resource URI associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.resource_uri description: Resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.signatures.id description: ID of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.signatures.name description: Name of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.signatures.resource_uri description: Resource URI of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.tags.name description: Name of the tag applied to matched entities. type: String - contextPath: ThreatStream.Rule.tips.id description: ID of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tips.name description: Name of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tips.resource_uri description: Resource URI of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tools description: List of tools associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.ttps.id description: ID of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.ttps.name description: Name of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.ttps.resource_uri description: Resource URI of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.user.avatar_s3_url description: URL for the avatar image associated with the user who created the rule. type: Unknown - contextPath: ThreatStream.Rule.user.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Rule.user.email description: Email of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.id description: ID of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.is_active description: Whether the user who created the rule is active. type: Boolean - contextPath: ThreatStream.Rule.user.is_readonly description: Whether the user who created the rule should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Rule.user.must_change_password description: Whether the user who created the rule will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Rule.user.name description: Name of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.nickname description: Nickname of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.organization.id description: The ID associated with the organization. type: String - contextPath: ThreatStream.Rule.user.organization.name description: The user's organization name. type: String - contextPath: ThreatStream.Rule.user.organization.resource_uri description: The user's organization resource URI. type: String - contextPath: ThreatStream.Rule.user.resource_uri description: The user's resource URI. type: String - contextPath: ThreatStream.Rule.user_id description: User ID of the user who created the rule. type: Number - contextPath: ThreatStream.Rule.vulnerabilities.id description: ID of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.vulnerabilities.name description: Name of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.vulnerabilities.resource_uri description: ID of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.workgroups description: Assigned workgroups. type: Unknown - arguments: - description: The rule ID. name: rule_id required: true - description: The rule name. name: rule_name - description: 'A comma-separated list of keywords for which you want the rule to match. Keywords added to rules must adhere to the following requirements: IP addresses must be expressed as regular expressions. IP subnets should be expressed using CIDR notation and not as regular expressions. Do not start or end keywords with *. Keywords must contain at least three characters.' isArray: true name: keywords - description: 'A comma-separated list of fields you want the rule to match to their keywords. Possible values: observables, sandbox reports, threat bulletins, signatures, vulnerabilities.' isArray: true name: match_include - description: A comma-separated list of IDs of the actors with which you want to associate matched entities. Use the threatstream-get-model-list command to get the actor IDs. isArray: true name: actor_ids - description: A comma-separated list of IDs of the campaigns with which you want to associate matched entities. Use the threatstream-get-model-list command to get the campaign IDs. isArray: true name: campaign_ids - auto: PREDEFINED description: The action you want to perform related to the investigation. Default is 'No Action'. name: investigation_action predefined: - Create New - Add To Existing - No Action - description: The investigation name. Required when 'Create New' is selected in the investigation_action argument. name: new_investigation_name - description: Existing investigation ID. Required when 'Add To Existing' is selected in the investigation_action argument. Use the threatstream-list-investigation command to get the investigation ID. name: existing_investigation_id - description: A comma-separated list of indicator types you want to exclude from rule matches. isArray: true name: exclude_indicator - description: A comma-separated list of indicator types you want to include from rule matches. isArray: true name: include_indicator - auto: PREDEFINED description: Whether observables whitelisted by your organization are excluded from rule matches. name: exclude_notify_org_whitelisted predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: Whether you want to exclude keyword matches on observables imported by your organization from a keyword match or hourly digest email notifications. name: exclude_notify_owner_org predefined: - 'True' - 'False' - description: A comma-separated list of IDs of the incidents with which you want to associate matched entities. Use the threatstream-get-model-list command to get the incident IDs. isArray: true name: incident_ids - description: A comma-separated list of IDs of the malwares with which you want to associate matched entities. Use the threatstream-get-model-list command to get the malware IDs. isArray: true name: malware_ids - description: A comma-separated list of IDs of the signatures with which you want to associate matched entities. Use the threatstream-get-model-list command to get the signature IDs. isArray: true name: signature_ids - description: A comma-separated list of IDs of the threat bulletin with which you want to associate matched entities. Use the threatstream-get-model-list command to get the threat bulletin IDs. isArray: true name: threat_bulletin_ids - description: A comma-separated list of IDs of the TTPs with which you want to associate matched entities. Use the threatstream-get-model-list command to get the TTPs IDs. isArray: true name: ttp_ids - description: A comma-separated list of IDs of the vulnerabilities with which you want to associate matched entities. Use the threatstream-get-model-list command to get the vulnerabilities IDs. isArray: true name: vulnerability_ids - description: A comma-separated list of tags. For example, tag1,tag2. isArray: true name: tags description: Updates existing rule from ThreatStream. name: threatstream-update-rule outputs: - contextPath: ThreatStream.Rule.actors.id description: Actor's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.actors.name description: Actor's name associated with the rule. type: String - contextPath: ThreatStream.Rule.actors.resource_uri description: Actor's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.adv_keyword description: Advanced keyword or regular expression that the rule is designed to match. type: Unknown - contextPath: ThreatStream.Rule.attackpatterns description: Attack patterns associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.backfill description: Objects that define additional filters or conditions for the rule. type: Unknown - contextPath: ThreatStream.Rule.campaigns.id description: Campaign's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.campaigns.name description: Campaign's name associated with the rule. type: String - contextPath: ThreatStream.Rule.campaigns.resource_uri description: Campaign's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.courseofaction description: Course of action entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.create_investigation description: Whether an investigation should be created when the rule is triggered. type: Boolean - contextPath: ThreatStream.Rule.created_ts description: Rule creation time. type: Date - contextPath: ThreatStream.Rule.customtms description: Custom threat model entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.description description: The rule description. type: String - contextPath: ThreatStream.Rule.exclude_impacts description: Indicator types that are excluded from rule matches. type: String - contextPath: ThreatStream.Rule.exclude_notify_org_whitelisted description: Whether observables whitelisted by your organization are excluded from rule matches. type: Boolean - contextPath: ThreatStream.Rule.exclude_notify_owner_org description: Whether to exclude keyword matches on observables imported by your organization from keyword match or hourly digest email notifications. type: Boolean - contextPath: ThreatStream.Rule.id description: Unique ID assigned to the rule. type: Number - contextPath: ThreatStream.Rule.identities description: List of identities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.incidents.id description: Incident's ID associated with the rule. type: String - contextPath: ThreatStream.Rule.incidents.name description: Incident's name associated with the rule. type: String - contextPath: ThreatStream.Rule.incidents.resource_uri description: Incident's resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.infrastructure description: Infrastructure entities associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.intelligence_initiatives description: Intelligence initiatives associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.intrusionsets description: Intrusion sets associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Rule.investigation.assignee.avatar_s3_url description: URL for the avatar image associated with the assignee user. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.email description: The email of the assignee user. type: String - contextPath: ThreatStream.Rule.investigation.assignee.id description: The ID of the assignee user. type: String - contextPath: ThreatStream.Rule.investigation.assignee.is_active description: Whether the assignee user is active. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.is_readonly description: Whether the assignee user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.must_change_password description: Whether the assignee user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Rule.investigation.assignee.name description: The investigation assignee user name. type: String - contextPath: ThreatStream.Rule.investigation.assignee.nickname description: The investigation assignee user nickname. type: Unknown - contextPath: ThreatStream.Rule.investigation.assignee.resource_uri description: Resource URI associated with investigation assignee user. type: String - contextPath: ThreatStream.Rule.investigation.investigation_config.name description: The name of the investigation configuration associated with the rule. type: String - contextPath: ThreatStream.Rule.investigation.id description: The ID of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.name description: The name of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.resource_uri description: The resource URI of the investigation. type: String - contextPath: ThreatStream.Rule.investigation.users description: List of users associated with the investigation created by the rule. type: Unknown - contextPath: ThreatStream.Rule.investigation.workgroups description: Assigned workgroups. type: Unknown - contextPath: ThreatStream.Rule.is_editable description: Indicates whether the imported entity can be updated by an intelligence source. type: Boolean - contextPath: ThreatStream.Rule.is_enabled description: Whether the rule is currently enabled. type: Boolean - contextPath: ThreatStream.Rule.keyword description: Keyword associated with the rule. type: String - contextPath: ThreatStream.Rule.keywords description: A list of keywords associated with the rule. type: String - contextPath: ThreatStream.Rule.malware.id description: ID of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.malware.name description: Name of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.malware.resource_uri description: Resource URI of the malware that associates to the rule. type: String - contextPath: ThreatStream.Rule.match_actors description: Whether the rule matches keywords in newly created actors. type: Boolean - contextPath: ThreatStream.Rule.match_all_tm description: Whether the rule should match against all threat models. type: Boolean - contextPath: ThreatStream.Rule.match_attackpatterns description: Whether the rule matches keywords in newly created attack patterns. type: Boolean - contextPath: ThreatStream.Rule.match_campaigns description: Whether the rule matches keywords in newly created campaigns. type: Boolean - contextPath: ThreatStream.Rule.match_courseofactions description: Whether the rule matches keywords in newly created course of action. type: Boolean - contextPath: ThreatStream.Rule.match_customtms description: Whether the rule should match custom threat models. type: Boolean - contextPath: ThreatStream.Rule.match_identities description: Whether the rule matches keywords in newly created identities. type: Boolean - contextPath: ThreatStream.Rule.match_impacts description: Indicator types in which you want to look for rule matches at the exclusion of all others. type: String - contextPath: ThreatStream.Rule.match_incidents description: Whether the rule matches keywords in newly created incidents. type: Boolean - contextPath: ThreatStream.Rule.match_infrastructures description: Whether the rule matches keywords in newly created infrastructures. type: Boolean - contextPath: ThreatStream.Rule.match_intrusionsets description: Whether the rule matches keywords in newly created intrusion sets. type: Boolean - contextPath: ThreatStream.Rule.match_malware description: Whether the rule matches keywords in newly created malware. type: Boolean - contextPath: ThreatStream.Rule.match_observables description: Whether the rule matches keywords in newly created observables. type: Boolean - contextPath: ThreatStream.Rule.match_reportedfiles description: Whether the rule should match keywords in newly created sandbox reports. type: Boolean - contextPath: ThreatStream.Rule.match_signatures description: Whether the rule should match keywords in newly created signatures. type: Boolean - contextPath: ThreatStream.Rule.match_tips description: Whether the rule should match keywords in newly created threat bulletins. type: Boolean - contextPath: ThreatStream.Rule.match_tools description: Whether the rule should match keywords in newly created tools. type: Boolean - contextPath: ThreatStream.Rule.match_ttps description: Whether the rule should match keywords in newly created TTPs. type: Boolean - contextPath: ThreatStream.Rule.match_vulnerabilities description: Whether the rule should match keywords in newly created vulnerabilities. type: Boolean - contextPath: ThreatStream.Rule.matches description: Total number of keyword matches for the rule. type: Number - contextPath: ThreatStream.Rule.messages description: Messages or notifications generated by the rule. type: Unknown - contextPath: ThreatStream.Rule.modified_ts description: Timestamp of when the rule was last modified, in UTC format. type: Date - contextPath: ThreatStream.Rule.name description: The rule name. type: String - contextPath: ThreatStream.Rule.notify_list_groups description: List of groups that should be notified when the rule triggers an alert. type: Unknown - contextPath: ThreatStream.Rule.notify_me description: Whether the user who created the rule should be notified when the rule triggers an alert. type: Boolean - contextPath: ThreatStream.Rule.org_id description: ID associated with the organization that created the rule. type: Number - contextPath: ThreatStream.Rule.org_shared description: Whether a rule is shared across an organization. type: Boolean - contextPath: ThreatStream.Rule.organization.id description: ID associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.organization.name description: Name associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.organization.resource_uri description: Resource URI associated with the organization that created the rule. type: String - contextPath: ThreatStream.Rule.resource_uri description: Resource URI associated with the rule. type: String - contextPath: ThreatStream.Rule.signatures.id description: ID of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.signatures.name description: Name of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.signatures.resource_uri description: Resource URI of the signature that associates to the rule. type: String - contextPath: ThreatStream.Rule.tags.name description: Name of the tag applied to matched entities. type: String - contextPath: ThreatStream.Rule.tips.id description: ID of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tips.name description: Name of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tips.resource_uri description: Resource URI of the threat bulletin that associates to matched entities. type: String - contextPath: ThreatStream.Rule.tools description: List of tools associated with the rule. type: Unknown - contextPath: ThreatStream.Rule.ttps.id description: ID of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.ttps.name description: Name of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.ttps.resource_uri description: Resource URI of the TTPs that associates to the rule. type: String - contextPath: ThreatStream.Rule.user.avatar_s3_url description: URL for the avatar image associated with the user who created the rule. type: Unknown - contextPath: ThreatStream.Rule.user.can_share_intelligence description: Whether the user who created the rule can share intelligence. type: Boolean - contextPath: ThreatStream.Rule.user.email description: Email of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.id description: ID of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.is_active description: Whether the user who created the rule is active. type: Boolean - contextPath: ThreatStream.Rule.user.is_readonly description: Whether the user who created the rule should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Rule.user.must_change_password description: Whether the user who created the rule will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Rule.user.name description: Name of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.nickname description: Nickname of the user who created the rule. type: String - contextPath: ThreatStream.Rule.user.organization.id description: The ID associated with the organization. type: String - contextPath: ThreatStream.Rule.user.organization.name description: The user's organization name. type: String - contextPath: ThreatStream.Rule.user.organization.resource_uri description: The user's organization resource URI. type: String - contextPath: ThreatStream.Rule.user.resource_uri description: The user's resource URI. type: String - contextPath: ThreatStream.Rule.user_id description: User ID of the user who created the rule. type: Number - contextPath: ThreatStream.Rule.vulnerabilities.id description: ID of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.vulnerabilities.name description: Name of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.vulnerabilities.resource_uri description: Resource URI of the vulnerability with which to associate matched entities. type: String - contextPath: ThreatStream.Rule.workgroups description: Assigned workgroups. type: Unknown - arguments: - description: The rule ID. name: rule_id required: true description: Delete a rule from ThreatStream. name: threatstream-delete-rule - arguments: - description: ID of the user. If specified, returns the specific user. name: user_id - description: The maximum number of results to return. Default is 50. name: limit - description: The page number of the results to retrieve. name: page - description: The maximum number of objects to retrieve per page. name: page_size description: Gets list of users from ThreatStream. Only users with org admin permission can run this command. name: threatstream-list-user outputs: - contextPath: ThreatStream.User.avatar_s3_url description: URL for the avatar image associated with the user. type: String - contextPath: ThreatStream.User.can_approve_intel description: Whether the user can approve intel. type: Boolean - contextPath: ThreatStream.User.can_import_to_taxii_inbox description: Whether the user can import to TAXII inbox. type: Boolean - contextPath: ThreatStream.User.can_see_api_key description: Whether the user can see the API key. type: Boolean - contextPath: ThreatStream.User.can_share_intelligence description: Whether the user can share intelligence. type: Boolean - contextPath: ThreatStream.User.can_submit_sandbox description: Whether the user can submit a sandbox. type: Boolean - contextPath: ThreatStream.User.can_use_chat description: Whether the user can use chat. type: Boolean - contextPath: ThreatStream.User.can_use_match description: Whether the user can use match. type: Boolean - contextPath: ThreatStream.User.date_joined description: Timestamp when the user was added to ThreatStream. type: Date - contextPath: ThreatStream.User.date_password_changed description: Timestamp when the user last changed their password. type: Unknown - contextPath: ThreatStream.User.email description: The user email. type: String - contextPath: ThreatStream.User.is_active description: Whether the user is active. type: Boolean - contextPath: ThreatStream.User.is_locked description: Whether the user is currently locked. type: Boolean - contextPath: ThreatStream.User.is_org_admin description: Whether the user is an Org Admin. type: Boolean - contextPath: ThreatStream.User.is_readonly description: Whether the user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.User.is_tfa_exempt description: Whether the user is excluded from having to use multi-factor authentication. type: Boolean - contextPath: ThreatStream.User.last_access_ts description: Timestamp when the user last accessed ThreatStream. type: Date - contextPath: ThreatStream.User.last_login description: Timestamp when the user was last authenticated to ThreatStream. type: Unknown - contextPath: ThreatStream.User.must_change_password description: Whether the user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.User.name description: Name entered by the user on the My Profile tab within ThreatStream settings. type: String - contextPath: ThreatStream.User.next_password_change_ts description: Future timestamp when the user will be forced to change their password. type: Unknown - contextPath: ThreatStream.User.nickname description: The user nickname. type: String - contextPath: ThreatStream.User.resource_uri description: Resource URI of the user. type: String - contextPath: ThreatStream.User.user_id description: ID of the user. type: String - arguments: - description: ID of the investigation. If specified, returns the specific investigation. name: investigation_id - description: The maximum number of results to return. Default is 50. name: limit - description: The page number of the results to retrieve. name: page - description: The maximum number of objects to retrieve per page. name: page_size description: Gets a list of investigations from ThreatStream. name: threatstream-list-investigation outputs: - contextPath: ThreatStream.Investigation.assignee.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Investigation.assignee.avatar_s3_url description: URL for the avatar image associated with the assignee user. type: Unknown - contextPath: ThreatStream.Investigation.assignee.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Investigation.assignee.email description: The email of the assignee user. type: String - contextPath: ThreatStream.Investigation.assignee.id description: The ID of the assignee user. type: String - contextPath: ThreatStream.Investigation.assignee.is_active description: Whether the assignee user is active. type: Boolean - contextPath: ThreatStream.Investigation.assignee.is_readonly description: Whether the assignee user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Investigation.assignee.must_change_password description: Whether the assignee user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Investigation.assignee.name description: The investigation assignee user name. type: String - contextPath: ThreatStream.Investigation.assignee.nickname description: The investigation assignee user nickname. type: Unknown - contextPath: ThreatStream.Investigation.assignee.resource_uri description: Resource URI associated with the investigation assignee user. type: String - contextPath: ThreatStream.Investigation.attachments description: The investigation attachments. type: Unknown - contextPath: ThreatStream.Investigation.candidate_session description: Investigation candidate session details. type: Unknown - contextPath: ThreatStream.Investigation.circles description: IDs of the trusted circles with which the investigation is shared. type: Unknown - contextPath: ThreatStream.Investigation.created_ts description: Timestamp when the investigation was created. type: Date - contextPath: ThreatStream.Investigation.description description: The investigation description. type: String - contextPath: ThreatStream.Investigation.elements description: The number of elements associated with the investigation. type: Number - contextPath: ThreatStream.Investigation.graph_content description: The investigation graph content details. type: Boolean - contextPath: ThreatStream.Investigation.id description: The ID of the investigation. type: Number - contextPath: ThreatStream.Investigation.intelligence_initiatives description: Intelligence initiatives associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.investigation_attachments description: List of attachments that are associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.is_public description: Whether the entity is public or private. type: Boolean - contextPath: ThreatStream.Investigation.modified_ts description: The date the investigation was modified. type: Date - contextPath: ThreatStream.Investigation.name description: The investigation name. type: String - contextPath: ThreatStream.Investigation.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.Investigation.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.Investigation.owner_org.resource_uri description: The owner organization resource URI. type: String - contextPath: ThreatStream.Investigation.owner_org_id description: The owner organization ID. type: Unknown - contextPath: ThreatStream.Investigation.pending_import_sessions description: Number of sessions that are currently waiting to be imported into the investigation. type: Unknown - contextPath: ThreatStream.Investigation.priority description: The priority of the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.email description: Email address of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.id description: ID of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.name description: Name of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.resource_uri description: Resource URI of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter_id description: ID of the user who created the investigation. type: Number - contextPath: ThreatStream.Investigation.resource_uri description: The investigation resource URI. type: String - contextPath: ThreatStream.Investigation.source_type description: The type of source used to create the investigation. type: String - contextPath: ThreatStream.Investigation.status description: The investigation status. type: String - contextPath: ThreatStream.Investigation.tags description: The tags associated with the investigation. type: String - contextPath: ThreatStream.Investigation.tasks description: Tasks associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.tlp description: Traffic Light Protocol designation for the investigation—red, amber, green, white. type: String - contextPath: ThreatStream.Investigation.users description: List of users associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.workgroups description: Assigned workgroups. type: Unknown - arguments: - description: The name of the investigation. name: name required: true - description: The description of the investigation. name: description - auto: PREDEFINED description: The priority of the investigation. name: priority predefined: - 'Very Low' - 'Low' - 'Medium' - 'High' - 'Very High' - auto: PREDEFINED description: The status of the investigation. name: status predefined: - 'Completed' - 'In-Progress' - 'Pending' - 'Unassigned' - description: A comma-separated list of tags. For example, tag1,tag2. isArray: true name: tags - auto: PREDEFINED description: tlp. name: tlp predefined: - 'White' - 'Green' - 'Amber' - 'Red' - description: Assignee ID. Use the threatstream-list-user command to get the user ID value. name: assignee_id - auto: PREDEFINED description: When enabled, observables related to the entity you are associating with the investigation are also added. name: connect_related_indicators predefined: - 'True' - 'False' - description: A comma-separated list of IDs of the actors with which you want to associate matched entities. Use the threatstream-get-model-list command to get the actor IDs. isArray: true name: associated_actor_ids - description: A comma-separated list of IDs of the campaigns with which you want to associate matched entities. Use the threatstream-get-model-list command to get the campaign IDs. isArray: true name: associated_campaign_ids - description: A comma-separated list of IDs of the incidents with which you want to associate matched entities. Use the threatstream-get-model-list command to get the incident IDs. isArray: true name: associated_incident_ids - description: A comma-separated list of IDs of the observables with which you want to associate matched entities. Use the threatstream-get-indicators command to get the observable IDs. isArray: true name: associated_observable_ids - description: A comma-separated list of IDs of the signatures with which you want to associate matched entities. Use the threatstream-get-model-list command to get the signature IDs. isArray: true name: associated_signature_ids - description: A comma-separated list of IDs of the threat bulletin with which you want to associate matched entities. Use the threatstream-get-model-list command to get the threat bulletin IDs. isArray: true name: associated_threat_bulletin_ids - description: A comma-separated list of IDs of the TTPs with which you want to associate matched entities. Use the threatstream-get-model-list command to get the TTPs IDs. isArray: true name: associated_ttp_ids - description: A comma-separated list of IDs of the vulnerabilities with which you want to associate matched entities. Use the threatstream-get-model-list command to get the vulnerabilities IDs. isArray: true name: associated_vulnerability_ids description: Create an investigation at ThreatStream. name: threatstream-create-investigation outputs: - contextPath: ThreatStream.Investigation.add_related_indicators description: Whether to add related indicators to the investigation. type: Number - contextPath: ThreatStream.Investigation.added_elements_count description: Number of elements added to the investigation. type: Number - contextPath: ThreatStream.Investigation.all_added description: Whether all the elements were added. type: Boolean - contextPath: ThreatStream.Investigation.already_exists_elements_count description: Number of elements that already exists. type: Number - contextPath: ThreatStream.Investigation.assignee.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Investigation.assignee.avatar_s3_url description: URL for the avatar image associated with the assignee user. type: Unknown - contextPath: ThreatStream.Investigation.assignee.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Investigation.assignee.email description: The email of the assignee user. type: String - contextPath: ThreatStream.Investigation.assignee.id description: The ID of the assignee user. type: String - contextPath: ThreatStream.Investigation.assignee.is_active description: Whether the assignee user is active. type: Boolean - contextPath: ThreatStream.Investigation.assignee.is_readonly description: Whether the assignee user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Investigation.assignee.must_change_password description: Whether the assignee user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Investigation.assignee.name description: The investigation assignee user name. type: String - contextPath: ThreatStream.Investigation.assignee.nickname description: The investigation assignee user nickname. type: Unknown - contextPath: ThreatStream.Investigation.assignee.resource_uri description: Resource URI associated with the investigation assignee user. type: String - contextPath: ThreatStream.Investigation.assignee_id description: ID of the user or workgroup to which the investigation is assigned. type: Number - contextPath: ThreatStream.Investigation.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Investigation.circles description: The trusted circles with which the investigation is shared. type: Unknown - contextPath: ThreatStream.Investigation.created_ts description: Timestamp when the investigation was created. type: Date - contextPath: ThreatStream.Investigation.description description: The investigation description. type: String - contextPath: ThreatStream.Investigation.elements.add_related_indicators description: Whether to add related indicators to the investigation. type: Number - contextPath: ThreatStream.Investigation.elements.entity.assignee_user description: The assignee user. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.created_ts description: Timestamp when the entity was created. type: Date - contextPath: ThreatStream.Investigation.elements.entity.feed_id description: The feed ID of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.id description: Unique ID assigned for the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.intelligence_initiatives description: Intelligence initiatives associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.is_anonymous description: Whether the entity is anonymous. type: Boolean - contextPath: ThreatStream.Investigation.elements.entity.is_cloneable description: Whether the entity is cloneable. type: String - contextPath: ThreatStream.Investigation.elements.entity.is_mitre description: Whether the entity is mitre. type: Boolean - contextPath: ThreatStream.Investigation.elements.entity.is_public description: Whether the entity is public or private. type: Boolean - contextPath: ThreatStream.Investigation.elements.entity.is_team description: Whether the entity is a team. type: Boolean - contextPath: ThreatStream.Investigation.elements.entity.modified_ts description: Timestamp of when the entity was last updated on ThreatStream, in UTC format. type: Date - contextPath: ThreatStream.Investigation.elements.entity.name description: The entity name. type: String - contextPath: ThreatStream.Investigation.elements.entity.organization_id description: ID of the (ThreatStream) organization that brought in the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.owner_user_id description: ID of the ThreatStream user who created the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.primary_motivation description: The primary motivation. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.publication_status description: The publication status of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.published_ts description: Timestamp of when the entity was published on ThreatStream, in UTC format. type: Date - contextPath: ThreatStream.Investigation.elements.entity.resource_level description: The resource level. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.resource_uri description: Resource URI of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.source_created description: Timestamp of when the entity was created by its original source. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.source_modified description: Timestamp of when the entity was last updated by its original source. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.start_date description: The start date. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.tlp description: Traffic Light Protocol designation for the entity—red, amber, green, white. type: String - contextPath: ThreatStream.Investigation.elements.entity.uuid description: UUID assigned to the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.workgroups description: Assigned workgroups. type: Unknown - contextPath: ThreatStream.Investigation.elements.id description: Unique ID assigned to the entity. type: Number - contextPath: ThreatStream.Investigation.elements.r_id description: Unique ID assigned to the element entity. type: Number - contextPath: ThreatStream.Investigation.elements.r_type description: Type of entity associated with the investigation. type: String - contextPath: ThreatStream.Investigation.elements.entity.s_type description: Signature type of entity associated with the investigation. type: String - contextPath: ThreatStream.Investigation.elements.entity.children.id description: A string representing the ID of the child entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.children.name description: A string representing the name of the child entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.children.resource_uri description: A string representing the resource URI of the child entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.is_category description: Whether the entity is a category. type: Boolean - contextPath: ThreatStream.Investigation.elements.entity.children description: The children of the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.aliases description: The aliases of the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.is_system description: Whether the entity is a system entity. type: Boolean - contextPath: ThreatStream.Investigation.elements.entity.source description: A string representing the source of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.update_id description: The update ID of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.assignee_user.email description: The assignee user email. type: String - contextPath: ThreatStream.Investigation.elements.entity.assignee_user.id description: The assignee user ID. type: String - contextPath: ThreatStream.Investigation.elements.entity.assignee_user.name description: The assignee user name. type: String - contextPath: ThreatStream.Investigation.elements.entity.assignee_user.resource_uri description: The assignee user resource URI. type: String - contextPath: ThreatStream.Investigation.elements.entity.end_date description: The end date of the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.objective description: The objective of the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.status.display_name description: The display name of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.status.id description: The status ID of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.status.resource_uri description: The resource URI of the status of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.asn description: The ASN of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.comments description: Comments related to the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.confidence description: The confidence of the associated entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.country description: The country associated with the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.created_by description: A string representing the creator of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.expiration_ts description: The timestamp when the entity will expire on ThreatStream. type: Date - contextPath: ThreatStream.Investigation.elements.entity.import_session_id description: A number representing the import session ID of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.import_source description: A string representing the import source of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.ip description: The IP of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.itype description: The itype of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.latitude description: The latitude of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.longitude description: The longitude of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.meta.detail2 description: Additional details associated with state of an entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.meta.severity description: Severity assigned to the entity through machine-learning algorithms ThreatStream deploys. type: String - contextPath: ThreatStream.Investigation.elements.entity.org description: Registered owner (organization) associated with the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.owner_organization_id description: The owner organization ID of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.rdns description: Domain name (obtained through reverse domain name lookup) associated with the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.retina_confidence description: The retina confidence of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.source_reported_confidence description: The source reported confidence of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.status description: The status of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.subtype description: The subtype of the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.tags description: List of tags associated with the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.threat_type description: Type of threat associated with the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.threatscore description: The threat score of the entity. type: Number - contextPath: ThreatStream.Investigation.elements.entity.trusted_circle_ids description: The trusted circleIDs of the entity. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.trusted_circles_ids description: ID of the trusted circle to which the entity data should be associated. type: Unknown - contextPath: ThreatStream.Investigation.elements.entity.type description: The type of the entity. type: String - contextPath: ThreatStream.Investigation.elements.entity.value description: Value of the entity. type: String - contextPath: ThreatStream.Investigation.errors description: Errors related to the investigation. type: Unknown - contextPath: ThreatStream.Investigation.graph_content description: The investigation graph content details. type: Unknown - contextPath: ThreatStream.Investigation.id description: The ID of the investigation. type: Number - contextPath: ThreatStream.Investigation.intelligence_initiatives description: Intelligence initiatives associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.is_public description: Whether the entity is public or private. type: Boolean - contextPath: ThreatStream.Investigation.modified_ts description: The date the investigation was modified. type: Date - contextPath: ThreatStream.Investigation.name description: The investigation name. type: String - contextPath: ThreatStream.Investigation.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.Investigation.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.Investigation.owner_org.resource_uri description: The owner organization resource URI. type: String - contextPath: ThreatStream.Investigation.owner_org_id description: Organization ID of the owner. type: Unknown - contextPath: ThreatStream.Investigation.priority description: The priority of the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.email description: Email address of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.id description: ID of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.name description: Name of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.resource_uri description: Resource URI of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter_id description: ID of the user who created the investigation. type: Number - contextPath: ThreatStream.Investigation.resource_uri description: The investigation resource URI. type: String - contextPath: ThreatStream.Investigation.source_type description: The type of source used to create the investigation. type: String - contextPath: ThreatStream.Investigation.status description: The investigation status. type: String - contextPath: ThreatStream.Investigation.tags description: The tags associated with the investigation. type: String - contextPath: ThreatStream.Investigation.tlp description: Traffic Light Protocol designation for the investigation—red, amber, green, white. type: String - contextPath: ThreatStream.Investigation.users description: List of users associated with the investigation. type: Unknown - contextPath: ThreatStream.Investigation.workgroups description: Assigned workgroups. type: Unknown - arguments: - description: The ID of the investigation. Use the threatstream-list-investigation command to get the investigation ID. name: investigation_id required: true - auto: PREDEFINED description: The priority of the investigation. name: priority predefined: - 'Very Low' - 'Low' - 'Medium' - 'High' - 'Very High' - auto: PREDEFINED description: The status of the investigation. name: status predefined: - 'Completed' - 'In-Progress' - 'Pending' - 'Unassigned' - description: A comma-separated list of tags. For example, tag1,tag2. isArray: true name: tags - auto: PREDEFINED description: The tlp (Traffic Light Protocol designation) of the investigation. name: tlp predefined: - 'White' - 'Green' - 'Amber' - 'Red' - description: Assignee ID. Use the threatstream-list-user command to get the user ID. name: assignee_id name: threatstream-update-investigation description: Updates an existing investigation at ThreatStream. outputs: - contextPath: ThreatStream.Investigation.add_related_indicators description: Errors related to the investigation. type: Number - contextPath: ThreatStream.Investigation.assignee.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Investigation.assignee.avatar_s3_url description: URL for the avatar image associated with the assignee user. type: Unknown - contextPath: ThreatStream.Investigation.assignee.can_share_intelligence description: Whether the assignee user can share intelligence. type: Boolean - contextPath: ThreatStream.Investigation.assignee.email description: The email of the assignee user. type: String - contextPath: ThreatStream.Investigation.assignee.id description: The ID of the assignee user. type: String - contextPath: ThreatStream.Investigation.assignee.is_active description: Whether the assignee user is active. type: Boolean - contextPath: ThreatStream.Investigation.assignee.is_readonly description: Whether the assignee user should be restricted to Read Only status. type: Boolean - contextPath: ThreatStream.Investigation.assignee.must_change_password description: Whether the assignee user will be forced to change their password the next time they log in. type: Boolean - contextPath: ThreatStream.Investigation.assignee.name description: The investigation assignee user name. type: String - contextPath: ThreatStream.Investigation.assignee.nickname description: The investigation assignee user nickname. type: Unknown - contextPath: ThreatStream.Investigation.assignee.resource_uri description: Resource URI associated with the investigation assignee user. type: String - contextPath: ThreatStream.Investigation.assignee_id description: ID of the user or workgroup to which the investigation is assigned. type: Number - contextPath: ThreatStream.Investigation.assignee_type description: 'Type of assignee: "user" or "tsworkgroup".' type: String - contextPath: ThreatStream.Investigation.created_ts description: Timestamp when the investigation was created. type: Date - contextPath: ThreatStream.Investigation.description description: The investigation description. type: String - contextPath: ThreatStream.Investigation.elements.add_related_indicators description: When enabled, observables related to the entity you are associating with the investigation are also added. type: Number - contextPath: ThreatStream.Investigation.elements.r_id description: Unique ID assigned to the entity. type: Number - contextPath: ThreatStream.Investigation.elements.r_type description: Type of entity associated with the investigation. type: String - contextPath: ThreatStream.Investigation.graph_content description: The investigation graph content details. type: Unknown - contextPath: ThreatStream.Investigation.id description: The ID of the investigation. type: Number - contextPath: ThreatStream.Investigation.is_public description: Whether the entity is public or private. type: Boolean - contextPath: ThreatStream.Investigation.modified_ts description: The date the investigation was modified. type: Date - contextPath: ThreatStream.Investigation.name description: The investigation name. type: String - contextPath: ThreatStream.Investigation.owner_org.id description: The owner organization ID. type: String - contextPath: ThreatStream.Investigation.owner_org.name description: The owner organization name. type: String - contextPath: ThreatStream.Investigation.owner_org.resource_uri description: The owner organization resource URI. type: String - contextPath: ThreatStream.Investigation.owner_org_id description: Organization ID of the owner. type: Unknown - contextPath: ThreatStream.Investigation.priority description: The priority of the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.email description: Email address of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.id description: ID of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.name description: Name of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter.resource_uri description: Resource URI of the user who created the investigation. type: String - contextPath: ThreatStream.Investigation.reporter_id description: ID of the user who created the investigation. type: Number - contextPath: ThreatStream.Investigation.resource_uri description: The investigation resource URI. type: String - contextPath: ThreatStream.Investigation.source_type description: The type of source used to create the investigation. type: String - contextPath: ThreatStream.Investigation.status description: The investigation status. type: String - contextPath: ThreatStream.Investigation.tags description: The tags associated with the investigation. type: String - contextPath: ThreatStream.Investigation.tlp description: Traffic Light Protocol designation for the investigation—red, amber, green, white. type: String - arguments: - description: The ID of the investigation. name: investigation_id required: true name: threatstream-delete-investigation description: Deletes an existing investigation at ThreatStream. - arguments: - description: The ID of the investigation. Use the threatstream-get-model-list command to get the investigation ID. name: investigation_id required: true - auto: PREDEFINED description: When enabled, observables related to the entity you are associating with the investigation are also added. name: connect_related_indicators predefined: - 'True' - 'False' - description: A comma-separated list of IDs of the actors with which you want to associate matched entities. Use the threatstream-get-model-list command to get the actor IDs. isArray: true name: associated_actor_ids - description: A comma-separated list of IDs of the campaigns with which you want to associate matched entities. Use the threatstream-get-model-list command to get the campaign IDs. isArray: true name: associated_campaign_ids - description: A comma-separated list of IDs of the incidents with which you want to associate matched entities. Use the threatstream-get-model-list command to get the incident IDs. isArray: true name: associated_incident_ids - description: A comma-separated list of IDs of the observables with which you want to associate matched entities. Use the threatstream-get-indicators command to get the observable IDs. isArray: true name: associated_observable_ids - description: A comma-separated list of IDs of the signatures with which you want to associate matched entities. Use the threatstream-get-model-list command to get the signature IDs. isArray: true name: associated_signature_ids - description: A comma-separated list of IDs of the threat bulletin with which you want to associate matched entities. Use the threatstream-get-model-list command to get the threat bulletin IDs. isArray: true name: associated_threat_bulletin_ids - description: A comma-separated list of IDs of the TTPs with which you want to associate matched entities. Use the threatstream-get-model-list command to get the TTPs IDs. isArray: true name: associated_ttp_ids - description: A comma-separated list of IDs of the vulnerabilities with which you want to associate matched entities. Use the threatstream-get-model-list command to get the vulnerabilities IDs. isArray: true name: associated_vulnerability_ids name: threatstream-add-investigation-element description: Add an element to the existing investigation at ThreatStream. - arguments: - auto: PREDEFINED default: true defaultValue: 'JSON' description: Defines the format of the response. name: format predefined: - 'CSV' - 'JSON' - defaultValue: '50' description: The maximum number of results to return. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Get a list of whitelist entries. name: threatstream-list-whitelist-entry outputs: - contextPath: InfoFile.Name description: Name of the file. type: string - contextPath: InfoFile.EntryID description: The entry ID of the report. type: string - contextPath: InfoFile.Size description: Size of the file. type: number - contextPath: InfoFile.Type description: File type, e.g., "PE". type: string - contextPath: InfoFile.Info description: Basic information of the file. type: string - contextPath: ThreatStream.WhitelistEntry.created_ts description: Timestamp of when the entry was created. type: Date - contextPath: ThreatStream.WhitelistEntry.id description: Unique ID associated with the whitelist entry. type: Number - contextPath: ThreatStream.WhitelistEntry.modified_ts description: Timestamp of when the entry was most recently modified. type: Date - contextPath: ThreatStream.WhitelistEntry.notes description: Contextual note associated with the entry. type: String - contextPath: ThreatStream.WhitelistEntry.resource_uri description: Resource URI of the entry. type: String - contextPath: ThreatStream.WhitelistEntry.value description: Value of the entry. type: String - contextPath: ThreatStream.WhitelistEntry.value_type description: Value type of the entry. type: String - arguments: - description: The entry ID of the file you want to upload. name: entry_id - description: A comma-separated list of CIDRs associated with the entry. isArray: true name: cidr - description: A comma-separated list of domains associated with the entry. isArray: true name: domains - description: A comma-separated list of emails associated with the entry. isArray: true name: emails - description: A comma-separated list of IPs associated with the entry. isArray: true name: ips - description: A comma-separated list of MD5 hashes associated with the entry. isArray: true name: md5 - description: A comma-separated list of URLs associated with the entry. isArray: true name: urls - description: A comma-separated list of user agents associated with the entry. isArray: true name: user_agents - description: A note that will be associated with all the indicator types that are provided in the command arguments. name: note description: Creates a new whitelist entry. name: threatstream-create-whitelist-entry - arguments: - description: The ID of the entry you want to update. name: entry_id required: true - description: A note that will be associated with all the indicator types that are provided in the command arguments. name: note required: true description: "Modify contextual notes associated with existing whitelist entries." name: threatstream-update-whitelist-entry-note - arguments: - description: The ID of the entry you want to update. Use the threatstream-list-whitelist-entry command to get the entry ID. name: entry_id required: true description: Delete a whitelist entry. name: threatstream-delete-whitelist-entry - arguments: - description: When specified, the results returned in the list are limited to specific import ID. name: import_id - auto: PREDEFINED description: When specified, the results returned in the list are limited to the selected status. name: status_in predefined: - 'Processing' - 'Errors' - 'Ready To Review' - 'Rejected' - 'Approved' - description: The maximum number of results to return. Default is 50. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Gets an import list. name: threatstream-list-import-job outputs: - contextPath: ThreatStream.Import.approved_by_id description: The ID of the user who approved the import. type: Unknown - contextPath: ThreatStream.Import.confidence description: Confidence scores assigned to the import. type: Number - contextPath: ThreatStream.Import.date description: A date representing the import date. type: Date - contextPath: ThreatStream.Import.date_modified description: A date representing the last modified date of the import. type: Date - contextPath: ThreatStream.Import.default_comment description: Default comment. type: Unknown - contextPath: ThreatStream.Import.email description: A string representing the email associated with the import. type: String - contextPath: ThreatStream.Import.exclude_source_domain description: Whether the source domain is excluded. type: Boolean - contextPath: ThreatStream.Import.expiration_ts description: The timestamp when the import will expire on ThreatStream. type: Date - contextPath: ThreatStream.Import.fileName description: A string representing the name of file associated with the import. type: String - contextPath: ThreatStream.Import.fileType description: A string representing the type of file associated with the import. type: String - contextPath: ThreatStream.Import.file_name_label description: The file name label. type: Unknown - contextPath: ThreatStream.Import.id description: A number representing the import ID. type: Number - contextPath: ThreatStream.Import.intelligence_source description: A string representing the intelligence source of the import. type: String - contextPath: ThreatStream.Import.is_anonymous description: Whether the entity is anonymous. type: Boolean - contextPath: ThreatStream.Import.is_public description: Whether the entity is public or private. type: Boolean - contextPath: ThreatStream.Import.jobID description: The job ID. type: Unknown - contextPath: ThreatStream.Import.messages description: A string representing the messages associated with the import. type: String - contextPath: ThreatStream.Import.name description: The import name. type: String - contextPath: ThreatStream.Import.notes description: A string representing the notes associated with the import. type: String - contextPath: ThreatStream.Import.numIndicators description: The number of observables that were accepted for importing. type: Number - contextPath: ThreatStream.Import.numRejected description: The number of observables that were rejected for importing. type: Number - contextPath: ThreatStream.Import.num_private description: A number representing the number of private entities associated with the import. type: Number - contextPath: ThreatStream.Import.num_public description: A number representing the number of public entities associated with the import. type: Number - contextPath: ThreatStream.Import.organization.id description: ID associated with the organization that created the import. type: String - contextPath: ThreatStream.Import.organization.name description: Name associated with the organization that created the import. type: String - contextPath: ThreatStream.Import.organization.resource_uri description: Resource URI associated with the organization that created the import. type: String - contextPath: ThreatStream.Import.processed_ts description: A date representing the timestamp when the import was processed. type: Date - contextPath: ThreatStream.Import.resource_uri description: Resource URI associated with the entity. type: String - contextPath: ThreatStream.Import.sandbox_submit description: The sandbox submit. type: Unknown - contextPath: ThreatStream.Import.source_confidence_weight description: The source confidence weight of the entity. type: Number - contextPath: ThreatStream.Import.status description: The import status. type: String - contextPath: ThreatStream.Import.threat_type description: The threat type. type: String - contextPath: ThreatStream.Import.tlp description: Traffic Light Protocol designation. type: Unknown - contextPath: ThreatStream.Import.user_id description: A string representing the ID associated with the user who created the import. type: Number - contextPath: ThreatStream.Import.visibleForReview description: Whether the entity is visible for review. type: Boolean - arguments: - description: The ID of the import job. name: import_id required: true description: Approve all observables in an import job. name: threatstream-approve-import-job - arguments: - description: 'A comma-separated list of model types. Supported values are: actor, attackpattern , campaign, courseofaction, incident,identity, infrastructure, intrusionset, malware,signature, tipreport, ttp, tool, vulnerability.' isArray: true name: model_type - description: The name of the threat model. name: name - description: 'Free text to search string in the fields: Aliases, Description, Name, Tags.' name: keyword_search - description: Other names by which the entity are known. name: alias - description: Numeric ID of the threat feed that provided the Threat Model entity. name: feed_id - auto: PREDEFINED description: Whether the entity was created as a result of an email import. name: is_email predefined: - 'True' - 'False' - auto: PREDEFINED description: 'Whether the entity is public or private. True—if the entity is public, False—if the entity is private or belongs to a Trusted Circle.' name: is_public predefined: - 'True' - 'False' - description: 'A comma-separated list of publication statuses. Supported values are: new, pending_review, review_requested, reviewed.' isArray: true name: publication_status - description: 'A comma-separated list of signature types. Supported values are: Bro, Carbon Black Query, ClamAV, Custom, CybOX, OpenIOC, RSA NetWitness, Snort, Splunk Query, Suricata, YARA.' isArray: true name: signature_type - description: 'A comma-separated list of additional comments and context associated with the entity when it was imported from its original threat feed.' isArray: true name: tags - description: Used for querying entities associated with specified trusted circles. name: trusted_circle_id - defaultValue: '50' description: The maximum number of results to return. name: limit - description: Page number to get result from. Needs to be used with the page_size argument. name: page - description: The page size of the returned results. Needs to be used with the page argument. name: page_size description: Retrieve threat model entities from ThreatStream. name: threatstream-search-threat-model outputs: - contextPath: ThreatStream.ThreatModel.source_created description: Timestamp of when the entity was created by its original source. type: Unknown - contextPath: ThreatStream.ThreatModel.circles description: Trusted circles with which data from streams is shared. type: Unknown - contextPath: ThreatStream.ThreatModel.feed_id description: Numeric ID of the threat feed that provided the threat model entity. type: Number - contextPath: ThreatStream.ThreatModel.workgroups description: Workgroups to which the threat model is visible. type: Unknown - contextPath: ThreatStream.ThreatModel.aliases description: Other names by which the threat model are known. type: Unknown - contextPath: ThreatStream.ThreatModel.is_email description: Whether the threat model was created as a result of an email import. type: Unknown - contextPath: ThreatStream.ThreatModel.published_ts description: Timestamp of when the entity was published on ThreatStream, in UTC format. type: String - contextPath: ThreatStream.ThreatModel.id description: Unique ID assigned to the entity. type: Number - contextPath: ThreatStream.ThreatModel.source_modified description: Timestamp of when the entity was last updated by its original source. type: Date - contextPath: ThreatStream.ThreatModel.type description: The threat model type. type: String - contextPath: ThreatStream.ThreatModel.start_date description: Time when a threat model was known to have started. type: Unknown - contextPath: ThreatStream.ThreatModel.publication_status description: The publication status. A threat model can be in new, pending_review, review_requested, reviewed, published statuses. type: String - contextPath: ThreatStream.ThreatModel.end_date description: Time when a threat model was known to have ended. type: Unknown - contextPath: ThreatStream.ThreatModel.tags.id description: The ID of the tag assigned to the threat model. type: String - contextPath: ThreatStream.ThreatModel.tags.name description: The name of the tag assigned to the threat model. type: String - contextPath: ThreatStream.ThreatModel.modified_ts description: Timestamp of when the tag was last updated on ThreatStream, in UTC format. type: String - contextPath: ThreatStream.ThreatModel.is_public description: Whether the entity is public or private. type: Boolean - contextPath: ThreatStream.ThreatModel.uuid description: UUID (universally unique identifier) assigned to the threat model for STIX compliance. type: String - contextPath: ThreatStream.ThreatModel.created_ts description: Timestamp when the threat model was created. type: String - contextPath: ThreatStream.ThreatModel.tlp description: TLP setting associated with the entity. type: String - contextPath: ThreatStream.ThreatModel.name description: Name of the entity. type: String - contextPath: ThreatStream.ThreatModel.status description: Status of the entity. type: Unknown - contextPath: ThreatStream.ThreatModel.model_type description: Type of threat model entity. type: String - contextPath: ThreatStream.ThreatModel.resource_uri description: Resource URI associated with the entity. type: String - arguments: - auto: PREDEFINED description: The type of threat model entity to which you are adding the association. name: entity_type predefined: - 'Actor' - 'Attack Pattern' - 'Campaign' - 'Course Of Action' - 'Identity' - 'Infrastructure' - 'Intrusion Set' - 'Incident' - 'Malware' - 'Signature' - 'Threat Bulletin' - 'Tool' - 'Ttp' - 'Vulnerability' required: true - description: The ID of the threat model entity to which you are adding the association. name: entity_id required: true - description: 'The entities IDs to associate with the primary entity. Note: The model type of all the IDs must be equal to the type in the “associated_entity_type” argument.' isArray: true name: associated_entity_ids required: true - auto: PREDEFINED description: The type of threat model entity to which you are adding the association. name: associated_entity_type predefined: - 'Actor' - 'Attack Pattern' - 'Campaign' - 'Course Of Action' - 'Identity' - 'Infrastructure' - 'Intrusion Set' - 'Incident' - 'Malware' - 'Signature' - 'Threat Bulletin' - 'Tool' - 'Ttp' - 'Vulnerability' required: true description: Creates associations between threat model entities on the ThreatStream platform. name: threatstream-add-threat-model-association - arguments: - description: A comma-separated list of unique IDs of the indicator to which you are adding tags (execute the command threatstream-get-indicators to get the list of indicators). name: indicator_ids required: true isArray: true - description: A comma-separated list of values of the tags you want to add. name: tags required: true isArray: true description: Add tags to the indicators. name: threatstream-add-indicator-tag - arguments: - description: A comma-separated list of unique IDs of the indicator to which you are removing tags (execute the command threatstream-get-indicators to get the list of indicators). name: indicator_ids required: true isArray: true - description: A comma-separated list of values of the tags you want to remove. name: tags required: true isArray: true description: Remove tags from the indicators. name: threatstream-remove-indicator-tag - arguments: - name: indicator_id required: true description: ID of the indicator to clone. name: threatstream-clone-imported-indicator description: Clones already imported indicators (observables), used with the edit classification to move to a trusted circle. outputs: - contextPath: ThreatStream.Clone.ID description: Indicator ID. type: string - contextPath: ThreatStream.Clone.Import_Session_ID description: Import Session ID for the clone request. type: string - contextPath: ThreatStream.Clone.Job_ID description: Job ID for the clone request. type: string - arguments: - name: import_id required: true description: Import Session ID of the import session from the clone-imported-indicator command. - name: data required: true description: JSON data of edits to be made {"is_public":false,"circles":[12866]}. name: threatstream-edit-classification description: Edit the values for observable that have been cloned. dockerimage: demisto/py3-tools:1.0.0.10120494 runonce: false script: '-' subtype: python3 type: python tests: - ThreatStream-Test fromversion: 6.0.0