category: Data Enrichment & Threat Intelligence provider: Dataminr commonfields: id: ThreatConnect version: -1 deprecated: true configuration: - display: Access ID name: accessId required: true type: 0 - display: Secret Key name: secretKey required: true type: 4 - defaultvalue: https://api.threatconnect.com display: baseUrl name: baseUrl required: true type: 0 - display: Default Organization name: defaultOrg type: 0 required: false - display: ProxyIP (or http://${ip} ) name: proxyIp type: 0 required: false - display: ProxyPort name: proxyPort type: 0 required: false - defaultvalue: '3' display: Rating threshold for Malicious Indicators name: rating type: 0 required: false - defaultvalue: '50' display: Confidence threshold for Malicious Indicators name: confidence type: 0 required: false - defaultvalue: '7' display: Indicator Reputation Freshness (in days) name: freshness type: 0 required: false description: Deprecated. Use the ThreatConnect v3 integration instead. display: ThreatConnect (Deprecated) name: ThreatConnect script: commands: - arguments: - default: true description: The IPv4 or IPv6 address. name: ip required: true - description: A CSV list of a client's organizations, sources, or communities to which a user has permissions. For example, users with admin permissions can search for indicators belonging to all owners. name: owners - description: A list of results filtered by indicators whose threat rating is greater than the specified value. Can be "0" - "Unknown", "1" - "Suspicious", "2" - "Low", "3" - Moderate, "4" - High, or "5" - "Critical". name: ratingThreshold - description: A list of results filtered by indicators whose confidence rating is greater than the specified value. Can be "0%" - "Unknown," "1% " - "Discredited", "2-29%" - "Improbable," "30-49%" - "Doubtful," "50-69%" - "Possible", "70-89%" - "Probable," or "90-100%" - "Confirmed". name: confidenceThreshold deprecated: true description: Searches for an indicator of type IP address. name: ip outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The date on which the indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: IP.Address description: The IP address of the indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - arguments: - default: true description: The URL for which to search. For example, "www.demisto.com". name: url required: true - description: A CSV list of a client's organizations, sources, or communities to which a client’s API user has been granted permission. For example, "owner1", "owner2", or "owner3". name: owners - description: A list of results filtered by indicators whose threat rating is greater than the specified value. Can be "0" - "Unknown", "1" - "Suspicious", "2" - "Low", "3" - Moderate, "4" - High, or "5" - "Critical". name: ratingThreshold - description: A list of results filtered by indicators whose confidence rating is greater than the specified value. Can be "0%" - "Unknown," "1% " - "Discredited", "2-29%" - "Improbable," "30-49%" - "Doubtful," "50-69%" - "Possible", "70-89%" - "Probable," or "90-100%" - "Confirmed". name: confidenceThreshold deprecated: true description: Searches for an indicator of type URL. name: url outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The date on which the indicator was last modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: URL.Data description: The data of the URL indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - arguments: - default: true description: The hash of the file. Can be "MD5", "SHA-1", or "SHA-256". name: file required: true - description: A CSV list of a client's organizations, sources, or communities to which a user has permissions. For example, users with admin permissions can search for indicators belonging to all owners. name: owners - description: A list of results filtered by indicators whose threat rating is greater than the specified value. Can be "0" - "Unknown", "1" - "Suspicious", "2" - "Low", "3" - Moderate, "4" - High, or "5" - "Critical". name: ratingThreshold - description: A list of results filtered by indicators whose confidence rating is greater than the specified value. Can be "0%" - "Unknown," "1% " - "Discredited", "2-29%" - "Improbable," "30-49%" - "Doubtful," "50-69%" - "Possible", "70-89%" - "Probable," or "90-100%" - "Confirmed". name: confidenceThreshold deprecated: true description: Searches for an indicator of type file. name: file outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator. type: string - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: File.MD5 description: The MD5 hash of the indicator. type: string - contextPath: File.SHA1 description: The SHA1 hash of the indicator. type: string - contextPath: File.SHA256 description: The SHA256 hash of the indicator. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - deprecated: true description: Retrieves all owners for the current account. name: tc-owners outputs: - contextPath: TC.Owner.Name description: The name of the owner. type: string - contextPath: TC.Owner.ID description: The ID of the owner. type: string - contextPath: TC.Owner.Type description: The type of the owner. type: string - arguments: - description: A list of results filtered by the owner of the indicator. name: owner - description: The maximum number of results that can be returned. The default is 500. name: limit deprecated: true description: Retrieves a list of all indicators. name: tc-indicators outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: IP.Address description: The IP address of the indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The name of the domain. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - deprecated: true description: Returns a list of all ThreatConnect tags. name: tc-get-tags outputs: - contextPath: TC.Tags description: A list of tags. type: Unknown - arguments: - description: The name of the tag. name: tag required: true - description: The indicator to tag. For example, for an IP indicator, "8.8.8.8". name: indicator required: true - description: A list of indicators filtered by the owner. name: owner deprecated: true description: Adds a tag to an existing indicator. name: tc-tag-indicator - arguments: - default: true description: The name of the indicator by which to search. The command retrieves information from all owners. Can be an IP address, a URL, or a file hash. name: indicator required: true - description: A list of results filtered by indicators whose threat rating is greater than the specified value. Can be "0" - "Unknown", "1" - "Suspicious", "2" - "Low", "3" - Moderate, "4" - High, or "5" - "Critical". name: ratingThreshold - description: A list of results filtered by indicators whose confidence rating is greater than the specified value. Can be "0%" - "Unknown," "1% " - "Discredited", "2-29%" - "Improbable," "30-49%" - "Doubtful," "50-69%" - "Possible", "70-89%" - "Probable," or "90-100%" - "Confirmed". name: confidenceThreshold deprecated: true description: Retrieves information about an indicator. name: tc-get-indicator outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: IP.Address description: The IP address of the indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the indicator of the URL. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The domain name of the indicator. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - default: true description: The name of the tag by which to filter. name: tag required: true - description: A list of indicators filtered by the owner. name: owner deprecated: true description: Fetches all indicators that have a tag. name: tc-get-indicators-by-tag outputs: - contextPath: TC.Indicator.Name description: The name of the tagged indicator. type: string - contextPath: TC.Indicator.Type description: The type of the tagged indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the tagged indicator. type: string - contextPath: TC.Indicator.Description description: The description of the tagged indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the tagged indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the tagged indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the tagged indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the tagged indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the tagged indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: DBotScore.Indicator description: The value assigned by DBot for the tagged indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the tagged indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the tagged indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: IP.Address description: The IP address of the tagged indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the tagged indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The domain name of the tagged indicator. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - description: The indicator to add. name: indicator required: true - description: The threat rating of the indicator. Can be "0" - "Unknown", "1" - "Suspicious", "2" - "Low", "3" - Moderate, "4" - High, or "5" - "Critical". name: rating - description: The confidence rating of the indicator. Can be "0%" - "Unknown," "1% " - "Discredited", "2-29%" - "Improbable," "30-49%" - "Doubtful," "50-69%" - "Possible", "70-89%" - "Probable," or "90-100%" - "Confirmed". name: confidence - description: The owner of the new indicator. The default is the "defaultOrg" parameter. name: owner deprecated: true description: Adds a new indicator to ThreatConnect. name: tc-add-indicator outputs: - contextPath: TC.Indicator.Name description: The name the indicator. type: string - contextPath: TC.Indicator.Type description: The type of indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the added indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the added indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: IP.Address description: The IP address of the indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The name of the added indicator of the domain. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - description: The owner of the new incident. The default is the "defaultOrg" parameter. name: owner - default: true description: The name of the incident group. name: incidentName required: true - description: The creation time of an incident in the "2017-03-21T00:00:00Z" format. name: eventDate - description: The tag applied to the incident. name: tag - auto: PREDEFINED description: The security label applied to the incident. Can be "TLP:RED", "TLP:GREEN", "TLP:AMBER", or "TLP:WHITE". name: securityLabel predefined: - TLP:RED - TLP:GREEN - TLP:AMBER - TLP:WHITE - description: The description of the incident. name: description deprecated: true description: Creates a new incident group. name: tc-create-incident outputs: - contextPath: TC.Incident.Name description: The name of the new incident group. type: string - contextPath: TC.Incident.Owner description: The owner of the new incident. type: string - contextPath: TC.Incident.EventDate description: The date on which the event that indicates an incident occurred. type: date - contextPath: TC.Incident.Tag description: The name of the tag of the new incident. type: string - contextPath: TC.Incident.SecurityLabel description: The security label of the new incident. type: string - contextPath: TC.Incident.ID description: The ID of the new incident. type: Unknown - arguments: - default: true description: The fetched incidents filtered by ID. name: incidentId - description: The fetched incidents filtered by owner. name: owner - description: The fetched incidents filtered by incident name. name: incidentName deprecated: true description: Fetches incidents from ThreatConnect. name: tc-fetch-incidents outputs: - contextPath: TC.Incident description: The name of the group of fetched incidents. type: string - contextPath: TC.Incident.ID description: The ID of the fetched incidents. type: string - contextPath: TC.Incident.Owner description: The owner of the fetched incidents. type: string - arguments: - auto: PREDEFINED description: The type of the indicator. Can be "ADDRESSES", "EMAIL_ADDRESSES", "URLS", "HOSTS", "FILES", or "CUSTOM_INDICATORS". name: indicatorType predefined: - ADDRESSES - EMAIL_ADDRESSES - URLS - HOSTS - FILES - CUSTOM_INDICATORS required: true - description: The ID of the incident to which the indicator is associated. name: incidentId required: true - default: true description: The name of the indicator. name: indicator required: true - description: A list of indicators filtered by the owner. name: owner deprecated: true description: Associates an indicator with an existing incident. The indicator must exist before running this command. To add an indicator, run the tc-add-indicator command. name: tc-incident-associate-indicator outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator associated was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator associated was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: IP.Address description: IP address of the associated indicator of the file. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the associated indicator of the file. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The name of the indicator of the domain. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - default: true description: The name of the domain. name: domain required: true - description: A CSV list of a client's organizations, sources, or communities to which a user has permissions. For example, users with admin permissions can search for indicators belonging to all owners. name: owners - description: A list of results filtered by indicators whose threat rating is greater than the specified value. Can be "0" - "Unknown", "1" - "Suspicious", "2" - "Low", "3" - Moderate, "4" - High, or "5" - "Critical". name: ratingThreshold - description: A list of results filtered by indicators whose confidence rating is greater than the specified value. Can be "0%" - "Unknown," "1% " - "Discredited", "2-29%" - "Improbable," "30-49%" - "Doubtful," "50-69%" - "Possible", "70-89%" - "Probable," or "90-100%" - "Confirmed". name: confidenceThreshold deprecated: true description: Searches for an indicator of type domain. name: domain outputs: - contextPath: TC.Indicator.Name description: The name of the of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the domain. type: string - contextPath: TC.Indicator.ID description: The ID of the domain. type: string - contextPath: TC.Indicator.Description description: The description of the domain. type: string - contextPath: TC.Indicator.Owner description: The owner of the domain. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator of the domain was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator of the domain was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the domain. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the domain. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: Domain.Name description: The name of the domain. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - arguments: - default: true description: The ID of the incident. name: incidentId required: true - description: A list of indicators filtered by the owner. name: owner deprecated: true description: Returns indicators that are related to a specific incident. name: tc-get-incident-associate-indicators outputs: - contextPath: TC.Indicator.Name description: The name of the returned indicator. type: string - contextPath: TC.Indicator.Type description: The type of the returned indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the returned indicator. type: string - contextPath: TC.Indicator.Description description: The description of the returned indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the returned indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the returned indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the returned indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the returned indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the returned indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: DBotScore.Indicator description: The value assigned by DBot for the indicator. type: string - contextPath: DBotScore.Type description: The type assigned by DBot for the indicator. type: string - contextPath: DBotScore.Score description: The score assigned by DBot for the indicator. type: number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: string - contextPath: IP.Address description: The IP address of the returned indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the returned indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The name of the domain. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - description: The name of the updated indicator. name: indicator required: true - description: The threat rating of the updated indicator. name: rating - description: The confidence rating of the updated indicator. name: confidence - description: The size of the file of the updated indicator. name: size - description: The active DNS indicator (only for hosts). name: dnsActive - description: The active indicator (only for hosts). name: whoisActive - description: A CSV list of field:value pairs to update. For example, "rating=3", "confidence=42", and "description=helloWorld". name: updatedValues - auto: PREDEFINED description: The updated indicator set as a false positive. Can be "True" or "False". name: falsePositive predefined: - 'True' - 'False' - description: The number observations on the updated indicator. name: observations - auto: PREDEFINED description: The security label applied to the incident. Can be "TLP:RED", "TLP:GREEN", "TLP:AMBER", or "TLP:WHITE". name: securityLabel predefined: - TLP:RED - TLP:GREEN - TLP:AMBER - TLP:WHITE - description: Assesses the confidence rating of the indicator. name: threatAssessConfidence - description: Assesses the threat rating of the indicator. name: threatAssessRating deprecated: true description: Updates the indicator in ThreatConnect. name: tc-update-indicator outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: IP.Address description: The IP address of the indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The domain name of the indicator. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - description: The name of the indicator from which to remove a tag. name: indicator required: true - description: The name of the tag to remove from the indicator. name: tag required: true deprecated: true description: Removes a tag from a specified indicator. name: tc-delete-indicator-tag outputs: - contextPath: TC.Indicator.Name description: The name of the indicator. type: string - contextPath: TC.Indicator.Type description: The type of the indicator. type: string - contextPath: TC.Indicator.ID description: The ID of the indicator. type: string - contextPath: TC.Indicator.Description description: The description of the indicator. type: string - contextPath: TC.Indicator.Owner description: The owner of the indicator. type: string - contextPath: TC.Indicator.CreateDate description: The date on which the indicator was created. type: date - contextPath: TC.Indicator.LastModified description: The last date on which the indicator was modified. type: date - contextPath: TC.Indicator.Rating description: The threat rating of the indicator. type: number - contextPath: TC.Indicator.Confidence description: The confidence rating of the indicator. type: number - contextPath: TC.Indicator.WhoisActive description: The active indicator (for domains only). type: string - contextPath: TC.Indicator.File.MD5 description: The MD5 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA1 description: The SHA1 hash of the indicator of the file. type: string - contextPath: TC.Indicator.File.SHA256 description: The SHA256 hash of the indicator of the file. type: string - contextPath: IP.Address description: The IP address of the indicator. type: string - contextPath: IP.Malicious.Vendor description: For malicious IP addresses, the vendor that made the decision. type: string - contextPath: IP.Malicious.Description description: For malicious IP addresses, the full description. type: string - contextPath: URL.Data description: The data of the URL of the indicator. type: string - contextPath: URL.Malicious.Vendor description: For malicious URLs, the vendor that made the decision. type: string - contextPath: URL.Malicious.Description description: For malicious URLs, the full description. type: string - contextPath: Domain.Name description: The domain name of the indicator. type: string - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: string - contextPath: Domain.Malicious.Description description: For malicious domains, the full description. type: string - contextPath: File.MD5 description: The MD5 hash of the file. type: string - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the full description. type: string - arguments: - description: The name of the indicator to delete. name: indicator required: true deprecated: true description: Deletes an indicator from ThreatConnect. name: tc-delete-indicator - arguments: - description: The name of the campaign group. name: name required: true - description: The earliest date on which the campaign was seen. name: firstSeen - description: The owner of the new incident. The default is the "defaultOrg" parameter. name: owner - description: The description of the campaign. name: description - description: The name of the tag to apply to the campaign. name: tag - description: The security label of the campaign. For example, "TLP:Green". name: securityLabel deprecated: true description: Creates a group based on the "Campaign" type. name: tc-create-campaign outputs: - contextPath: TC.Campaign.Name description: The name of the campaign. type: string - contextPath: TC.Campaign.Owner description: The owner of the campaign. type: string - contextPath: TC.Campaign.FirstSeen description: The earliest date on which the campaign was seen. type: date - contextPath: TC.Campaign.Tag description: The tag of the campaign. type: string - contextPath: TC.Campaign.SecurityLevel description: The security label of the campaign. type: string - contextPath: TC.Campaign.ID description: The ID of the campaign. type: string - arguments: - description: The name of the event group. name: name required: true - description: The date on which the event occurred. If the date is not specified, the current date is used. name: eventDate - auto: PREDEFINED description: The status of the event. Can be "Needs Review", "False Positive", "No Further Action", or "Escalated". name: status predefined: - Needs Review - False Positive - No Further Action - Escalated - description: The owner of the event. name: owner - description: The description of the event. name: description - description: The tag of the event. name: tag deprecated: true description: Creates a group based on the "Event" type. name: tc-create-event outputs: - contextPath: TC.Event.Name description: The name of the event. type: string - contextPath: TC.Event.Date description: The date of the event. type: date - contextPath: TC.Event.Status description: The status of the event. type: string - contextPath: TC.Event.Owner description: The owner of the event. type: string - contextPath: TC.Event.Tag description: The tag of the event. type: string - contextPath: TC.Event.ID description: The ID of the event. type: string - arguments: - description: The name of the threat group. name: name required: true deprecated: true description: Creates a group based on the "Threats" type. name: tc-create-threat outputs: - contextPath: TC.Threat.Name description: The name of the threat. type: string - contextPath: TC.Threat.ID description: The ID of the threat. type: string - arguments: - description: The ID of the group to delete. name: groupID required: true - auto: PREDEFINED description: The type of the group to delete. Can be "Incidents", "Events", "Campaigns", or "Threats". name: type predefined: - Incidents - Events - Campaigns - Threats required: true deprecated: true description: Deletes a group. name: tc-delete-group - arguments: - description: The ID of the group to which to add attributes. To get the ID of the group, run the tc-get-groups command. name: group_id required: true - description: The type of attribute to add to the group. The type is located in the UI in a specific group or under Org Config. name: attribute_type required: true - description: The value of the attribute. name: attribute_value required: true - auto: PREDEFINED description: The type of the group. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true deprecated: true description: Adds an attribute to a specified group. name: tc-add-group-attribute outputs: - contextPath: TC.Group.DateAdded description: The date on which the attribute was added. type: Date - contextPath: TC.Group.LastModified description: The date on which the added attribute was last modified. type: Date - contextPath: TC.Group.Type description: The type of the group to which the attribute was added. type: String - contextPath: TC.Group.Value description: The value of the attribute added to the group. type: String - contextPath: TC.Group.ID description: The group ID to which the attribute was added. type: Number - deprecated: true description: Returns a list of events. name: tc-get-events outputs: - contextPath: TC.Event.DateAdded description: The date on which the event was added. type: Date - contextPath: TC.Event.EventDate description: The date on which the event occurred. type: Date - contextPath: TC.Event.ID description: The ID of the event. type: Number - contextPath: TC.Event.OwnerName description: The name of the owner of the event. type: String - contextPath: TC.Event.Status description: The status of the event. type: String - arguments: - auto: PREDEFINED description: The type of the group. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true deprecated: true description: Returns all groups, filtered by the group type. name: tc-get-groups outputs: - contextPath: TC.Group.DateAdded description: The date on which the group was added. type: Date - contextPath: TC.Group.EventDate description: The date on which the event occurred. type: Date - contextPath: TC.Group.Name description: The name of the group. type: String - contextPath: TC.Group.OwnerName description: The name of the owner of the group. type: String - contextPath: TC.Group.Status description: The status of the group. type: String - contextPath: TC.Group.ID description: The ID of the group. type: Number - arguments: - description: The ID of the group to which to add the security label. To get the ID, run the tc-get-groups command. name: group_id required: true - auto: PREDEFINED description: The type of the group to which to add the security label. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The name of the security label to add to the group. For example, "TLP:GREEN". name: security_label_name required: true deprecated: true description: Adds a security label to a group. name: tc-add-group-security-label - arguments: - description: The ID of the group to which to add the tag. To get the ID, run the tc-get-groups command. name: group_id required: true - auto: PREDEFINED description: The type of the group to which to add the tag. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The name of the tag to add to the group. name: tag_name required: true deprecated: true description: Adds tags to a specified group. name: tc-add-group-tag - deprecated: true description: Returns all indicator types available. name: tc-get-indicator-types outputs: - contextPath: TC.IndicatorType.ApiBranch description: The branch of the API. type: String - contextPath: TC.IndicatorType.ApiEntity description: The entity of the API. type: String - contextPath: TC.IndicatorType.CasePreference description: The case preference of the indicator. For example, "sensitive", "upper", or "lower". type: String - contextPath: TC.IndicatorType.Custom description: Whether the indicator is a custom indicator. type: Boolean - contextPath: TC.IndicatorType.Parsable description: Whether the indicator can be parsed. type: Boolean - contextPath: TC.IndicatorType.Value1Type description: The name of the indicator. type: String - contextPath: TC.IndicatorType.Value1Label description: The value label of the indicator. type: String - arguments: - description: The type of the indicator. To get the available types, run the tc-get-indicator-types command. The indicator must be spelled as displayed in the ApiBranch column of the UI. name: indicator_type required: true - description: The name of the indicator. For example, "indicator_type=emailAddresses" where "indicator=a@a.co.il". name: indicator required: true - auto: PREDEFINED description: The type of the group. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group. To get the ID of the group, run the tc-get-groups command. name: group_id required: true deprecated: true description: Associates an indicator with a group. name: tc-group-associate-indicator outputs: - contextPath: TC.Group.GroupID description: The ID of the group. type: Number - contextPath: TC.Group.GroupType description: The type of the group. type: String - contextPath: TC.Group.Indicator description: The name of the indicator. type: String - contextPath: TC.Group.IndicatorType description: The type of the indicator. type: String - arguments: - description: The name of the file to display in the UI. name: file_name required: true - description: The name of the file. name: name required: true - auto: PREDEFINED description: Whether the file is malware. If "true", ThreatConnect creates a password-protected ZIP file on your local machine that contains the sample and uploads the ZIP file. name: malware predefined: - 'true' - 'false' - description: The password of the ZIP file. name: password - description: The security label of the group. name: security_label - description: A description of the group. name: description - description: The file of the ID of the entry, as displayed in the War Room. name: entry_id required: true deprecated: true description: Creates a document group. name: tc-create-document-group outputs: - contextPath: TC.Group.Name description: The name of the group. type: String - contextPath: TC.Group.Owner description: The owner of the group. type: String - contextPath: TC.Group.EventDate description: The date on which the group was created. type: Date - contextPath: TC.Group.Description description: The description of the group. type: String - contextPath: TC.Group.SecurityLabel description: The security label of the group. type: String - contextPath: TC.Group.ID description: The ID of the group to which the attribute was added. type: Number - arguments: - auto: PREDEFINED description: The type of group for which to return the ID. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group to retrieve. To get the ID, run the tc-get-groups command. name: group_id required: true deprecated: true description: Retrieves a single group. name: tc-get-group outputs: - contextPath: TC.Group.DateAdded description: The date on which the group was added. type: Date - contextPath: TC.Group.EventDate description: The date on which the event occurred. type: Date - contextPath: TC.Group.Name description: The name of the group. type: String - contextPath: TC.Group.Owner.ID description: The ID of the group owner. type: Number - contextPath: TC.Group.Owner.Name description: The name of the group owner. type: String - contextPath: TC.Group.Owner.Type description: The type of the owner. type: String - contextPath: TC.Group.Status description: The status of the group. type: String - arguments: - auto: PREDEFINED description: The type of group for which to return the attribute. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group for which to return the attribute. To get the ID, run the tc-get-groups command. name: group_id required: true deprecated: true description: Retrieves the attribute of a group. name: tc-get-group-attributes outputs: - contextPath: TC.Group.Attribute.DateAdded description: The date on which the group was added. type: Date - contextPath: TC.Group.Attribute.Displayed description: Whether the attribute is displayed on the UI. type: Boolean - contextPath: TC.Group.Attribute.AttributeID description: The ID of the attribute. type: Number - contextPath: TC.Group.Attribute.LastModified description: The date on which the attribute was last modified. type: Date - contextPath: TC.Group.Attribute.Type description: The type of the attribute. type: String - contextPath: TC.Group.Attribute.Value description: The value of the attribute. type: String - arguments: - auto: PREDEFINED description: The type of group for which to return the security labels. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group for which to return the security labels. To get the ID, run the tc-get-groups command. name: group_id required: true deprecated: true description: Retrieves the security labels of a group. name: tc-get-group-security-labels outputs: - contextPath: TC.Group.SecurityLabel.Name description: The name of the security label. type: String - contextPath: TC.Group.SecurityLabel.Description description: The description of the security label. type: String - contextPath: TC.Group.SecurityLabel.DateAdded description: The date on which the security label was added. type: Date - arguments: - auto: PREDEFINED description: The type of group for which to return the tags. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group for which to return the tags. To get the ID, run the tc-get-groups command. name: group_id required: true deprecated: true description: Retrieves the tags of a group. name: tc-get-group-tags outputs: - contextPath: TC.Group.Tag.Name description: The name of the tag. type: String - arguments: - description: The ID of the document. name: document_id required: true deprecated: true description: Downloads the contents of a document. name: tc-download-document outputs: - contextPath: File.Size description: The size of the file. type: Number - contextPath: File.SHA1 description: The SHA1 hash of the file. type: String - contextPath: File.SHA256 description: The SHA256 hash of the file. type: String - contextPath: File.Name description: The name of the file. type: String - contextPath: File.SSDeep description: The ssdeep hash of the file (same as displayed in file entries). type: String - contextPath: File.EntryID description: The entry ID of the file. type: String - contextPath: File.Info description: The information of the file. type: String - contextPath: File.Type description: The type of the file. type: String - contextPath: File.MD5 description: The MD5 hash of the file. type: String - contextPath: File.Extension description: The extension of the file. type: String - arguments: - auto: PREDEFINED description: The type of the group for which to return the indicators. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group for which to return the indicators. To get the ID, run the tc-get-groups command. name: group_id required: true deprecated: true description: Returns indicators associated with a group. name: tc-get-group-indicators outputs: - contextPath: TC.Group.Indicator.Summary description: The summary of the indicator. type: String - contextPath: TC.Group.Indicator.ThreatAssessConfidence description: The confidence rating of the indicator. type: String - contextPath: TC.Group.Indicator.IndicatorID description: The ID of the indicator. type: Number - contextPath: TC.Group.Indicator.DateAdded description: The date on which the indicator was added. type: Date - contextPath: TC.Group.Indicator.Type description: The type of the indicator. type: String - contextPath: TC.Group.Indicator.Rating description: The threat rating of the indicator. type: Number - contextPath: TC.Group.Indicator.ThreatAssertRating description: The rating of the threat assert. type: Number - contextPath: TC.Group.Indicator.OwnerName description: The name of the owner of the indicator. type: String - contextPath: TC.Group.Indicator.LastModified description: The date that the indicator was last modified. type: Date - arguments: - auto: PREDEFINED description: The type of group. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group. To get the ID, run the tc-get-groups command. name: group_id required: true deprecated: true description: Returns indicators associated with a specified group. name: tc-get-associated-groups outputs: - contextPath: TC.Group.AssociatedGroup.DateAdded description: The date on which group was added. type: Date - contextPath: TC.Group.AssociatedGroup.GroupID description: The ID of the group. type: Number - contextPath: TC.Group.AssociatedGroup.Name description: The name of the group. type: String - contextPath: TC.Group.AssociatedGroup.OwnerName description: The name of the owner of the group. type: String - contextPath: TC.Group.AssociatedGroup.Type description: The type of the group. type: String - arguments: - auto: PREDEFINED description: The type of the group. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group. To get the ID of the group, run the tc-get-groups command. name: group_id required: true - auto: PREDEFINED description: The type of group to associate. Can be "adversaries", "campaigns", "documents", "emails", "events", "incidents", "intrusionSets", "reports", "signatures", or "threats". name: associated_group_type predefined: - adversaries - campaigns - documents - emails - events - incidents - intrusionSets - reports - signatures - threats required: true - description: The ID of the group to associate. name: associated_group_id required: true deprecated: true description: Associates one group with another group. name: tc-associate-group-to-group outputs: - contextPath: TC.Group.AssociatedGroup.AssociatedGroupID description: The ID of the associated group. type: Number - contextPath: TC.Group.AssociatedGroup.AssociatedGroupType description: The type of the associated group. type: String - contextPath: TC.Group.AssociatedGroup.GroupID description: The ID of the group to associate to. type: Number - contextPath: TC.Group.AssociatedGroup.GroupType description: The type of the group to associate to. type: String dockerimage: demisto/threatconnect-sdk:1.0.0.7659 runonce: false script: '-' type: python subtype: python2 tests: - No tests - deprecated fromversion: 5.0.0