Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tim Feed Threatfox #35748

Merged
merged 73 commits into from
Aug 19, 2024
Merged
Changes from 1 commit
Commits
Show all changes
73 commits
Select commit Hold shift + click to select a range
2d854f7
run init
YaelShamai Jul 10, 2024
694c0fd
start API call function
YaelShamai Jul 10, 2024
8cb37c4
Merge remote-tracking branch 'origin' into yshamai-tim-feed-threatfox
YaelShamai Jul 10, 2024
ae657d5
api request
YaelShamai Jul 14, 2024
411d0c0
continue
YaelShamai Jul 15, 2024
8eeabaf
finish API func with unit tests
YaelShamai Jul 15, 2024
7072291
description
YaelShamai Jul 17, 2024
a3a9562
continue
YaelShamai Jul 21, 2024
fd9d1db
more
YaelShamai Jul 22, 2024
f2a4d3c
finish get-indicators command
YaelShamai Jul 22, 2024
6522ba2
add test_module function
YaelShamai Jul 22, 2024
7f107ea
start fetch command
YaelShamai Jul 22, 2024
b7a962e
start fetch-indicators
YaelShamai Jul 25, 2024
e8f14a1
Merge remote-tracking branch 'origin' into yshamai-tim-feed-threatfox
YaelShamai Jul 25, 2024
36b3801
almost finished
YaelShamai Jul 29, 2024
35c8ab5
almost finished
YaelShamai Jul 29, 2024
82e1e2f
Merge remote-tracking branch 'origin' into yshamai-tim-feed-threatfox
YaelShamai Jul 31, 2024
bdd34b7
validate arg
YaelShamai Jul 31, 2024
d22050a
nicer code and fixes
YaelShamai Aug 1, 2024
eff0827
remove duplicate tags
YaelShamai Aug 1, 2024
a22cedd
typing
YaelShamai Aug 1, 2024
3269c69
typing and descriptions
YaelShamai Aug 4, 2024
7e1e5b0
fetch last run and little fixes
YaelShamai Aug 4, 2024
04d0361
tests
YaelShamai Aug 4, 2024
2193a90
more unit tests
YaelShamai Aug 4, 2024
8ff48d6
more unit tests and fix fetch
YaelShamai Aug 5, 2024
8fee335
Merge remote-tracking branch 'origin' into yshamai-tim-feed-threatfox
YaelShamai Aug 6, 2024
34d65c7
more
YaelShamai Aug 6, 2024
ec4ab6a
more tests and testaybook
YaelShamai Aug 7, 2024
047612f
pre commit
YaelShamai Aug 7, 2024
7446d76
remove the dev
YaelShamai Aug 7, 2024
d06719b
pack readme
YaelShamai Aug 8, 2024
6a2ae91
Update Packs/FeedThreatFox/README.md
YaelShamai Aug 8, 2024
2c22a43
Update Packs/FeedThreatFox/README.md
YaelShamai Aug 8, 2024
38414fe
code review fixes
YaelShamai Aug 12, 2024
7ba211e
exception
YaelShamai Aug 12, 2024
f8e7e0f
ThreatFox version
YaelShamai Aug 12, 2024
496a072
add indicator example
YaelShamai Aug 12, 2024
95dbc2c
CR
YaelShamai Aug 14, 2024
a6b3710
dateparser
YaelShamai Aug 15, 2024
3de6f94
two fixes
YaelShamai Aug 15, 2024
525af73
change malware error
YaelShamai Aug 15, 2024
6b62da3
tag and malware description
YaelShamai Aug 18, 2024
fc83dd2
pre commit
YaelShamai Aug 18, 2024
e10c8d9
import get_value
YaelShamai Aug 18, 2024
9795824
parsed_date
YaelShamai Aug 18, 2024
a2c06f3
pre commit
YaelShamai Aug 18, 2024
0da4ae7
long lines
YaelShamai Aug 18, 2024
1591122
/
YaelShamai Aug 18, 2024
f2116ce
more outopep
YaelShamai Aug 18, 2024
20c2b85
Merge remote-tracking branch 'origin/HEAD' into yshamai-tim-feed-thre…
YaelShamai Aug 18, 2024
de4e3a4
ruff
YaelShamai Aug 18, 2024
6f67340
malicious
YaelShamai Aug 18, 2024
70e19ad
malicious to bad
YaelShamai Aug 18, 2024
2de307b
validate
YaelShamai Aug 18, 2024
9467369
updated docker image
YaelShamai Aug 18, 2024
38be344
add test playbook to yml
YaelShamai Aug 18, 2024
179ca87
docker image
YaelShamai Aug 18, 2024
cf68484
required: true
YaelShamai Aug 18, 2024
06d3657
conf json
YaelShamai Aug 18, 2024
28437da
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox_t…
YaelShamai Aug 18, 2024
df38f78
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox_t…
YaelShamai Aug 18, 2024
7a8ae2e
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox_t…
YaelShamai Aug 18, 2024
504aa92
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox_t…
YaelShamai Aug 18, 2024
11640d7
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox_t…
YaelShamai Aug 18, 2024
d6d8c49
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox.yml
YaelShamai Aug 18, 2024
7e1d612
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/README.md
YaelShamai Aug 18, 2024
f76e32d
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox.py
YaelShamai Aug 18, 2024
65aa38b
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox.py
YaelShamai Aug 18, 2024
bfb2a6c
Update Packs/FeedThreatFox/Integrations/FeedThreatFox/FeedThreatFox.yml
YaelShamai Aug 18, 2024
540a9d4
pre commit
YaelShamai Aug 19, 2024
2f127c6
delete test playbook
YaelShamai Aug 19, 2024
a72ce5f
delete test playbook
YaelShamai Aug 19, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
almost finished
  • Loading branch information
YaelShamai committed Jul 29, 2024
commit 36b3801e043c8f111e1a91884418dbe502028e04
57 changes: 54 additions & 3 deletions Packs/FeedThreatFox/Integrations/FeedThreatFox/README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,56 @@
This README contains the full documentation for your integration.
Use the ThreatFox Feed integration to fetch indicators from the feed.
This integration was integrated and tested with version xx of ThreatFox Feed.
YaelShamai marked this conversation as resolved.
Show resolved Hide resolved

You auto-generate this README file from your integration YML file using the `demisto-sdk generate-docs` command.
## Configure ThreatFox Feed on Cortex XSOAR

For more information see the [integration documentation](https://xsoar.pan.dev/docs/integrations/integration-docs).
1. Navigate to **Settings** > **Integrations** > **Servers & Services**.
2. Search for ThreatFox Feed.
3. Click **Add instance** to create and configure a new integration instance.

| **Parameter** | **Description** | **Required** |
| --- | --- | --- |
| Server URL | | True |
| Use system proxy settings | | False |
| Trust any certificate (not secure) | | False |
| Fetch indicators | | False |
| Source Reliability | Reliability of the source providing the intelligence data | False |
| Indicator Reputation | Indicators from this integration instance will be marked with this reputation. | False |
| Traffic Light Protocol Color | The Traffic Light Protocol \(TLP\) designation to apply to indicators fetched from the feed | False |
YaelShamai marked this conversation as resolved.
Show resolved Hide resolved
| | | False |
| | | False |
| Bypass exclusion list | When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. | False |
| Feed Fetch Interval | | False |
| Return IOCs with Ports | | False |
| Confidence Threshold | | False |
| Create relationship | | False |

4. Click **Test** to validate the URLs, token, and connection.

## Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

### threatfox-get-indicators

***
Retrieves indicators from the ThreatFox API.

#### Base Command

`threatfox-get-indicators`

#### Input

| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| search_term | Indicator value to search for. | Optional |
| id | Indicator id to search for. | Optional |
| hash | Hash to search for. | Optional |
| tag | need to check this. | Optional |
| malware | Malware to search for. | Optional |
| limit | Maximum indicators to search for. Available only when searching by 'malware' or 'tag'. Default is 50. | Optional |
YaelShamai marked this conversation as resolved.
Show resolved Hide resolved

#### Context Output

There is no context output for this command.