category: Data Enrichment & Threat Intelligence provider: Open Source commonfields: id: TAXII 2 Feed version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - additionalinfo: Indicators from this integration instance will be marked with this reputation. display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data. display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 defaultvalue: 'WHITE' required: false section: Collect - display: '' name: feedExpirationPolicy options: - never - interval - indicatorType - suddenDeath type: 17 required: false section: Collect advanced: true - display: '' name: feedExpirationInterval type: 1 required: false section: Collect advanced: true - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect advanced: true - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false section: Collect advanced: true - display: Discovery Service URL (e.g. https://example.net/taxii2) name: url required: true type: 0 section: Connect - display: Username / API Key name: credentials type: 9 required: false section: Connect - additionalinfo: The API root to use (for example default or public). If left empty, the server default API root is used. If the server has no default root, the first available API root is used instead. display: API Root to Use name: default_api_root type: 0 required: false section: Connect - additionalinfo: Indicators will be fetched from this collection. Run "taxii2-get-collections" command to get a valid value. If left empty, the instance will try to fetch from all the collections in the given discovery service. display: Collection Name To Fetch Indicators From name: collection_to_fetch type: 0 required: false section: Connect - additionalinfo: Incremental feeds pull only new or modified indicators that have been sent from the integration. As the determination if the indicator is new or modified happens on the 3rd-party vendor's side, and only indicators that are new or modified are sent to Cortex XSOAR, all indicators coming from these feeds are labeled new or modified. defaultvalue: 'false' display: Incremental Feed name: feedIncremental type: 8 required: false section: Collect advanced: true - additionalinfo: When enabled, fetch-indicators will try to fetch the entire feed for every fetch. When disabled, fetch-indicators will try to fetch just the latest entries (since the last fetch). display: Full Feed Fetch name: fetch_full_feed type: 8 required: false defaultvalue: 'true' section: Collect advanced: true - additionalinfo: The maximum number of indicators that can be fetched per fetch. If this field is left empty, there will be no limit on the number of indicators fetched. display: Max Indicators Per Fetch (disabled for Full Feed Fetch) name: limit type: 0 required: false section: Collect - display: First Fetch Time name: initial_interval defaultvalue: 1 year type: 0 required: false additionalinfo: 'The time interval for the first retroactive fetch, formatted as