category: Data Enrichment & Threat Intelligence provider: AT&T Cybersecurity commonfields: id: AlienVault OTX TAXII Feed version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: Bad display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: C - Fairly reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - defaultvalue: indicatorType name: feedExpirationPolicy display: '' options: - never - interval - indicatorType - suddenDeath type: 17 required: false - defaultvalue: '20160' name: feedExpirationInterval display: '' type: 1 required: false - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false - name: credentials type: 9 displaypassword: API Key hiddenusername: true required: false - display: API Key hidden: true name: api_key type: 4 required: false - additionalinfo: When selected, will run on all active collections regardless of the supplied collections. Inactive or empty collections will be ignored. display: Get All Active Collections name: all_collections type: 8 required: false - additionalinfo: Supports a CSV of collections to fetch from. If an inactive or empty collection is supplied, a Timeout error will be raised. If not set, it will raise an error listing all the available collections. display: Collections to Fetch From name: collections type: 0 required: false - display: First Fetch Time name: initial_interval type: 0 additionalinfo: The time interval for the first fetch (retroactive).