category: Data Enrichment & Threat Intelligence provider: Intel 471 deprecated: true commonfields: id: Intel471 Malware Feed version: -1 configuration: - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false - display: Username name: credentials type: 9 required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: Suspicious display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: B - Usually reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - defaultvalue: indicatorType display: '' name: feedExpirationPolicy options: - never - interval - indicatorType - suddenDeath type: 17 required: false - defaultvalue: '20160' display: '' name: feedExpirationInterval type: 1 required: false - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false - additionalinfo: Type of the indicator in the feed. display: Indicator Type name: indicator_type required: true type: 16 defaultvalue: All options: - All - File - ipv4 - URL - additionalinfo: |- "Search indicators by threat type (e.g. malware, bulletproof_hosting, proxy_service). If empty, all threat types will be considered." display: Search by Threat Type name: threat_type type: 0 required: false - additionalinfo: |- "Search indicators by malware family (e.g. gozi_isfb, smokeloader, trickbot). If empty, all malware families will be considered." display: Malware Family name: malware_family type: 0 required: false - additionalinfo: Search indicators by confidence. See detailed description of the confidence levels below. options: - high - medium - low display: Search by confidence name: confidence type: 15 required: false - display: Free text indicator search (all fields included) name: indicator type: 0 required: false - additionalinfo: How far back in time to go when performing the first fetch. defaultvalue: '7 days' display: First fetch timestamp (