category: Data Enrichment & Threat Intelligence provider: DHS commonfields: id: DHS Feed v2 version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false - defaultvalue: https://ais2.cisa.dhs.gov/taxii2/ display: Discovery Service URL (e.g., https://ais2.cisa.dhs.gov/taxii2/) name: url required: true type: 0 - displaypassword: Key File as Text additionalinfo: For more information, visit https://us-cert.cisa.gov/ais. name: key type: 9 required: true hiddenusername: true - additionalinfo: For more information, visit https://us-cert.cisa.gov/ais. display: Certificate File as Text name: certificate required: true type: 12 - additionalinfo: The default API root to use (e.g., default, public). If left empty, the server default API root will be used. When the server has no default root, the first available API root will be used instead. The user must be authorized to reach the selected API root. defaultvalue: 'public' display: Default API Root to use name: default_api_root type: 0 required: false - additionalinfo: Indicators will be fetched from this collection. Run the "dhs-get-collections" command to get a valid value. If left empty, the instance will try to fetch from all the collections in the given discovery service. display: Collection Name To Fetch Indicators From name: collection_to_fetch type: 0 required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation. defaultvalue: Bad display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: F - Reliability cannot be judged display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - defaultvalue: indicatorType display: '' name: feedExpirationPolicy options: - never - interval - indicatorType type: 17 required: false - defaultvalue: '20160' display: '' name: feedExpirationInterval type: 1 required: false - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false - additionalinfo: 'The time interval for the first fetch (retroactive) in the following format: