category: Data Enrichment & Threat Intelligence provider: Check Point Software Technologies sectionorder: - Connect - Collect commonfields: id: cyberint version: -1 configuration: - display: Company Name additionalinfo: Company (client) name associated with Cyberint instance. name: client_name required: true type: 0 section: Connect - display: Cyberint Access Token name: access_token type: 4 required: true additionalinfo: Cyberint API access token. section: Connect - display: Cyberint API URL additionalinfo: Cyberint API URL on which the services run (i.e https://your-company.cyberint.io) name: environment required: true type: 0 section: Connect - display: Data residency name: region type: 15 required: false hidden: true additionalinfo: Deprecated. Data residency field has been removed in favor of automatic routing. options: - US - EU defaultvalue: US section: Connect - display: Create an incident per CSV record additionalinfo: An incident will be created with the originated Alert details per CSV file record. name: duplicate_alert required: false type: 8 section: Collect - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - display: Fetch Severity name: fetch_severity type: 16 required: false additionalinfo: Severities to fetch. If none is chosen, all severity levels will be returned. options: - low - medium - high - very_high section: Collect - display: Fetch Status additionalinfo: Statuses to fetch. If none is chosen, all statuses will be returned. name: fetch_status options: - open - acknowledged - closed type: 16 required: false section: Collect - display: Fetch Environment additionalinfo: Environments to fetch (comma separated). If empty, all available environments will be returned. name: fetch_environment type: 0 required: false section: Collect - display: Incident Mirroring Direction additionalinfo: 'Choose the direction to mirror the incident: Incoming (from Cyberint to Cortex XSOAR), Outgoing (from Cortex XSOAR to Cyberint), or Incoming and Outgoing (from/to Cortex XSOAR and Cyberint). Cortex XSOAR only parameter.' name: mirror_direction type: 15 required: false defaultvalue: None options: - None - Incoming - Outgoing - Incoming And Outgoing section: Collect hidden: - marketplacev2 - platform - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - display: Close Mirrored XSOAR Incident defaultvalue: 'false' name: close_incident type: 8 additionalinfo: When selected, closing the Cyberint alert is mirrored in Cortex XSOAR. Cortex XSOAR only parameter. required: false section: Collect hidden: - marketplacev2 - platform - display: Close Mirrored Cyberint Alert name: close_alert type: 8 defaultvalue: 'false' required: false additionalinfo: When selected, closing the Cortex XSOAR incident is mirrored in Cyberint. section: Collect - display: Fetch Types name: fetch_type type: 16 required: false additionalinfo: Types to fetch. If none is chosen, all types will be returned. options: - refund_fraud - carding - coupon_fraud - money_laundering - victim_report - malicious_insider - extortion - phishing_email - phishing_kit - phishing_website - lookalike_domain - phishing_target_list - malicious_file - reconnaissance - automated_attack_tools - business_logic_bypass - target_list - official_social_media_profile - impersonation - intellectual_property_infringement - unauthorized_trading - negative_sentiment - fake_job_posting - defacement - compromised_pii - internal_information_disclosure - compromised_payment_cards - compromised_employee_credentials - compromised_customer_credentials - compromised_access_token - ransomware - exposed_web_interfaces - hijackable_subdomains - website_vulnerabilities - vulnerabilities - exposed_cloud_storage - exploitable_ports - mail_servers_in_blacklist - server_connected_to_botnet - email_security_issues - certificate_authority_issues - user_defined_saved_query - other - ssl_tls - web_app_security section: Collect - display: Fetch Limit name: max_fetch type: 0 required: false additionalinfo: Max number of alerts per fetch. Defaults to the minimum 10, max is 100. defaultvalue: '10' section: Collect - display: First fetch timestamp (