category: Data Enrichment & Threat Intelligence provider: Intel 471 sectionorder: - Connect - Collect commonfields: id: Intel471 Malware Indicator Feed version: -1 configuration: - additionalinfo: The Intel 471 backend from which to source data display: Intel 471 backend name: intel471_backend defaultvalue: TITAN options: - TITAN - Verity471 type: 15 required: true section: Connect - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - display: Username name: credentials type: 9 required: false section: Connect - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: Suspicious display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: B - Usually reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color defaultvalue: AMBER options: - RED - AMBER - GREEN - WHITE type: 15 required: false section: Collect - defaultvalue: indicatorType display: '' name: feedExpirationPolicy options: - never - interval - indicatorType - suddenDeath type: 17 required: false section: Collect - defaultvalue: '20160' display: '' name: feedExpirationInterval type: 1 required: false section: Collect - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect - additionalinfo: Type of the indicator in the feed. display: Indicator Type name: indicator_type required: true type: 15 defaultvalue: All options: - All - Domain - Email - File - ipv4 - URL section: Collect - additionalinfo: |- "Search indicators by malware family (e.g. gozi_isfb, smokeloader, trickbot). If empty, all malware families will be considered." display: Malware Family name: malware_family type: 0 required: false section: Collect - additionalinfo: Search indicators by confidence. See detailed description of the confidence levels below. options: - high - medium - low display: Search by confidence name: confidence type: 15 required: false section: Collect - display: Free text indicator search (all fields included) name: indicator type: 0 required: false section: Collect - additionalinfo: How far back in time to go when performing the first fetch. defaultvalue: 7 days display: First fetch timestamp (