category: Data Enrichment & Threat Intelligence provider: Open Source commonfields: id: JSON Feed version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: feedInstanceReputationNotSet display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: F - Reliability cannot be judged display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false section: Collect - defaultvalue: indicatorType display: '' name: feedExpirationPolicy options: - never - interval - indicatorType - suddenDeath type: 17 required: false section: Collect advanced: true - defaultvalue: '20160' display: '' name: feedExpirationInterval type: 1 required: false section: Collect advanced: true - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect advanced: true - display: URL name: url required: true type: 0 section: Connect - additionalinfo: If selected, the indicator type will be auto detected for each indicator. defaultvalue: 'true' display: Auto detect indicator type name: auto_detect_type type: 8 required: false section: Collect advanced: true - additionalinfo: Remove ports from IPv4 type indicators in the fetch command (e.g. ,192.168.1.1:8080 -> 192.168.1.1) display: Remove IPv4 Ports name: remove_ports type: 8 required: false defaultvalue: 'false' section: Collect advanced: true - display: Indicator Type name: indicator_type type: 0 required: false additionalinfo: Type of the indicator in the feed. If auto-detect is checked then the value set as Indicator Type will be ignored. section: Collect advanced: true - display: Username name: credentials required: false type: 9 section: Connect - additionalinfo: JMESPath expression for extracting the indicators. You can use http://jmespath.org/ to identify the proper expression. display: JMESPath Extractor name: extractor type: 0 required: true section: Collect - additionalinfo: "The JSON attribute that holds the indicator value. Default value is 'indicator'." display: JSON Indicator Attribute name: indicator type: 0 required: false section: Collect advanced: true - additionalinfo: "Send specified data in a POST request. When specified, by default will add the header: 'Content-Type: application/x-www-form-urlencoded'. To specify a different Content-Type (for example: application/json) use the Headers config param." display: POST Data name: data type: 0 required: false section: Collect advanced: true - additionalinfo: "Headers to add to the http request. Specify each header on a single line in the format: 'Name: Value'. For example: 'User-Agent: XSOAR Feed'" display: Headers name: headers type: 12 required: false section: Collect advanced: true - display: Include indicator type for mapping name: rawjson_include_indicator_type type: 8 required: false additionalinfo: "When using a custom classifier and mapper with this feed, use this option to include the indicator type in the raw JSON used for classification and mapping." section: Collect advanced: true - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect advanced: true - display: Use system proxy settings name: proxy type: 8 required: false section: Connect advanced: true - additionalinfo: "When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system." display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false section: Collect advanced: true - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false section: Collect advanced: true - display: Enrichment Excluded name: enrichmentExcluded type: 8 required: false defaultvalue: 'false' additionalinfo: Select this option to exclude the fetched indicators from the enrichment process. hidden: - xsoar_on_prem section: Collect description: Fetches indicators from a JSON feed. display: JSON Feed name: JSON Feed script: commands: - arguments: - defaultValue: '50' description: The maximum number of results to return. The default value is 50. name: limit - defaultValue: 'false' description: Remove ports from IPv4s. name: remove_ports description: Gets the feed indicators. name: json-get-indicators dockerimage: demisto/py3-tools:1.0.0.114656 feed: true runonce: false script: '-' subtype: python3 type: python tests: - JSON_Feed_Test fromversion: 5.5.0 sectionorder: - Connect - Collect