category: Data Enrichment & Threat Intelligence provider: Open Source commonfields: id: Cortex Core - IOC version: -1 sectionorder: - Connect - Collect configuration: - display: Server URL (e.g. https://example.net) name: url type: 0 hidden: true required: false section: Connect - display: API Key ID name: apikey_id type: 4 hidden: true required: false section: Connect - display: API Key name: apikey type: 4 hidden: true required: false section: Connect - additionalinfo: Map the severity of each indicator that will be synced to Cortex. display: Cortex Severity name: severity options: - info - low - medium - high required: false defaultvalue: low type: 15 section: Connect - additionalinfo: The query used to collect indicators to sync from Cortex. defaultvalue: reputation:Bad and (type:File or type:Domain or type:IP) display: Sync Query name: query required: false type: 0 section: Collect description: The Cortex Core - IOCs integration uses the Cortex API for detection and response, by natively integrating network, endpoint, and cloud data to stop sophisticated attacks. display: Indicators detection name: Cortex Core - IOC script: commands: - arguments: - auto: PREDEFINED default: true defaultValue: 'false' description: |- For first sync, set to true. (do NOT run this twice!). name: firstTime predefined: - 'true' - 'false' description: Sync your IOC with Cortex and delete the previous version. name: core-iocs-sync - arguments: - description: IOCs to push. leave empty to push all recently modified IOCs.the indicators. isArray: true name: indicator description: Push modified IOCs to Cortex. name: core-iocs-push - arguments: - description: The time of the file creation (use UTC time zone). name: time required: true description: Set sync time manually (Do not use this command unless you unredstandard the consequences). name: core-iocs-set-sync-time - description: Creates the sync file for the manual process. Run this command when instructed by the Cortex support team. name: core-iocs-create-sync-file - arguments: - description: The indicator to enable. Only indicators managed by TIM (indicators that were synced/pushed to the Cortex tenant by this integration) can be enabled. Indicators created in the tenant, via the API, or by other sources are not affected. isArray: true name: indicator required: true description: Enables IOCs in the Cortex tenant. Applies only to TIM-managed indicators (indicators synced/pushed by this integration); indicators from other sources are not affected. name: core-iocs-enable - arguments: - description: The indicator to disable. Only indicators managed by TIM (indicators that were synced/pushed to the Cortex server by this integration) can be disabled. Indicators created in the UI, via the API, or by other sources are not affected. isArray: true name: indicator required: true description: Disables IOCs in the Cortex server. Applies only to TIM-managed indicators (indicators synced/pushed by this integration); indicators from other sources are not affected. name: core-iocs-disable dockerimage: demisto/google-cloud-storage:1.0.0.10120494 runonce: false script: '-' subtype: python3 type: python tests: - No tests fromversion: 5.5.0 defaultEnabled: true supportedModules: - xsiam - cloud - cloud_posture - cloud_runtime_security - edr