name: FeedMandiantThreatIntelligence display: Mandiant Feed description: Fetch indicators from Mandiant Advantage. category: Data Enrichment & Threat Intelligence provider: Google commonfields: id: FeedMandiantThreatIntelligence version: -1 sectionorder: - Connect - Collect configuration: - defaultvalue: 'true' display: Fetch indicators additionalinfo: 'Whether the integration should check Mandiant for new indicators.' name: feed type: 8 required: false section: Collect - additionalinfo: Your API Key from Mandiant Advantage Threat Intelligence. display: API Key name: api_key required: true type: 0 section: Connect - additionalinfo: Your Secret Key from Mandiant Advantage Threat Intelligence. display: Secret Key name: secret_key required: true type: 4 section: Connect - name: page_size type: 0 display: Page Size required: true defaultvalue: 1000 additionalinfo: 'The number of indicators to request in each page.' section: Collect advanced: true - additionalinfo: API calls timeout. defaultvalue: '60' display: Timeout name: timeout type: 0 required: false section: Connect advanced: true - additionalinfo: Indicators from this integration instance will be marked with this reputation. display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: A - Completely reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - name: feedMinimumThreatScore type: 0 display: Feed Minimum Threat Score required: true defaultvalue: 80 additionalinfo: 'The minimum Threat Score value to import as part of the feed.' section: Collect - additionalinfo: The maximum value allowed is 90 days. defaultvalue: 30 display: First fetch time name: first_fetch type: 0 required: false section: Collect - name: feedExcludeOSIntel display: Feed Exclude Open Source Intelligence type: 8 defaultvalue: 'true' additionalinfo: 'Whether to exclude Open Source Intelligence as part of the feed' required: false section: Collect - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 defaultvalue: RED required: false section: Collect - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false section: Collect - name: feedExpirationPolicy display: '' additionalinfo: Defines how expiration of an indicator created by the feed will be managed. options: - never - interval - indicatorType type: 17 required: false section: Collect - name: feedExpirationInterval display: '' type: 1 required: false section: Collect - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval additionalinfo: 'How frequently the feed should check Mandiant for new indicators.' type: 19 required: true section: Collect - additionalinfo: Incremental feeds pull only new or modified indicators that have been sent from the integration. The determination if the indicator is new or modified happens on the 3rd-party vendor's side, so only indicators that are new or modified are sent to Cortex XSOAR. Therefore, all indicators coming from these feeds are labeled new or modified. defaultvalue: 'true' display: Incremental feed hidden: true name: feedIncremental required: false type: 8 section: Collect - name: feedBypassExclusionList display: Bypass exclusion list type: 8 additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. section: Collect script: commands: - name: mandiant-get-indicators arguments: - description: The maximum number of indicators to fetch. name: limit description: Fetch indicators. dockerimage: demisto/python3:3.12.13.10116658 feed: true runonce: false script: '-' subtype: python3 type: python fromversion: 6.10.0 tests: - No tests (auto formatted)