category: Data Enrichment & Threat Intelligence provider: Cofense commonfields: id: Cofense Feed version: -1 configuration: - display: Username name: credentials type: 9 required: false - display: Fetch indicators name: feed defaultvalue: 'true' type: 8 required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: feedInstanceReputationNotSet display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false - display: Source Reliability name: feedReliability defaultvalue: A - Completely reliable type: 15 required: true options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged additionalinfo: Reliability of the source providing the intelligence data - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - display: "" name: feedExpirationPolicy defaultvalue: indicatorType type: 17 options: - never - interval - indicatorType - suddenDeath required: false - display: "" name: feedExpirationInterval defaultvalue: "20160" type: 1 required: false - defaultvalue: '60' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false - additionalinfo: To fetch malware and phishing indicators select "all". defaultvalue: all display: The threat type for which to fetch indicators name: threat_type options: - all - malware type: 15 required: false - additionalinfo: This value also will be used as an expiration time - all indicators before the given time will not be fetched. defaultvalue: 3 days display: First fetch time range (