category: Data Enrichment & Threat Intelligence provider: AT&T Cybersecurity commonfields: id: AlienVault Reputation Feed version: -1 configuration: - display: Fetch indicators name: feed defaultvalue: 'true' type: 8 required: false - display: Indicator Reputation name: feedReputation defaultvalue: Bad type: 18 options: - None - Good - Suspicious - Bad additionalinfo: Indicators from this integration instance will be marked with this reputation required: false - display: Source Reliability name: feedReliability defaultvalue: C - Fairly reliable type: 15 required: true options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged additionalinfo: Reliability of the source providing the intelligence data - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - display: "" name: feedExpirationPolicy defaultvalue: indicatorType type: 17 options: - never - interval - indicatorType - suddenDeath required: false - display: "" name: feedExpirationInterval defaultvalue: "20160" type: 1 required: false - display: Feed Fetch Interval name: feedFetchInterval defaultvalue: "60" type: 19 required: false - display: Bypass exclusion list name: feedBypassExclusionList type: 8 additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. required: false - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false description: Use the AlienVault Reputation feed integration to fetch indicators from the feed. display: AlienVault Reputation Feed name: AlienVault Reputation Feed script: commands: - arguments: - defaultValue: '50' description: The maximum number of results to return. The default value is 50. name: limit - description: The indicator type. name: indicator_type description: Gets the feed indicators. name: alienvault-get-indicators dockerimage: demisto/python3:3.12.13.10116658 feed: true runonce: false script: '-' subtype: python3 type: python tests: - AlienVaultReputationFeed_Test fromversion: 5.5.0