category: Data Enrichment & Threat Intelligence provider: Open Source commonfields: id: SecurityIntelligenceServicesFeed version: -1 configuration: - display: S3 Access Key name: accessKey required: true type: 4 - display: S3 Secret Key name: secretKey required: true type: 4 - defaultvalue: Domain display: Feed Type name: feedType options: - Domain - Scam - Phishing - Malware - Content required: true type: 16 - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: feedInstanceReputationNotSet display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: F - Reliability cannot be judged display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false - display: '' name: feedExpirationPolicy type: 17 options: - never - interval - indicatorType - suddenDeath required: false - name: feedExpirationInterval type: 1 display: '' required: false - defaultvalue: '5' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false - additionalinfo: The historical indicators available in the time-range provided will be fetched. defaultvalue: 1 day display: First Fetch Time Range (