diff --git a/Packs/Alexa/Integrations/Alexa/README.md b/Packs/Alexa/Integrations/Alexa/README.md index c4a009718f97..e98a392fd47c 100644 --- a/Packs/Alexa/Integrations/Alexa/README.md +++ b/Packs/Alexa/Integrations/Alexa/README.md @@ -78,5 +78,5 @@ Provides an Alexa ranking of the Domain in question. ``` #### Human Readable Output -![image](https://user-images.githubusercontent.com/42912128/51466171-3b4ead80-1d72-11e9-9cff-14e997e9346a.png) +![image](../../doc_files/51466171-3b4ead80-1d72-11e9-9cff-14e997e9346a.png) diff --git a/Packs/Anomali_ThreatStream/.pack-ignore b/Packs/Anomali_ThreatStream/.pack-ignore index 91c381f4cb4d..af8e1d0be78f 100644 --- a/Packs/Anomali_ThreatStream/.pack-ignore +++ b/Packs/Anomali_ThreatStream/.pack-ignore @@ -1,5 +1,5 @@ [file:README.md] -ignore=RM104 +ignore=RM104,RM112 [file:Anomali_ThreatStream_v2.yml] ignore=BA108,BA109 diff --git a/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md b/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md index 528b72795ad7..6182cace1b62 100644 --- a/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md +++ b/Packs/Anomali_ThreatStream/Integrations/AnomaliThreatStream/README.md @@ -221,7 +221,7 @@ \u0026limit=1\u0026offset=1",
"offset":0,
"previous":null,
"took":39,
"total_count":49906
},
"objects":[
{
"asn":"12849",
"confidence":100,
"country":"IL",
"created_ts":"2018-01-03T16:59:29.054Z",
"description":null,
"expiration_ts":"2018-04-12T13:37:28.417Z",
"feed_id":122,
"id":50460807643,
"import_session_id":null,
"ip":"5.29.211.60",
"is_public":false,
"itype":"tor_ip",
"latitude":"32.332900",
"longitude":"34.859900",
"meta":{
"detail2":"bifocals_deactivated_on_2018-04-10_20:32:42.816201",
"severity":"low"
},
"modified_ts":"2018-04-11T13:37:28.423Z",
"org":"HOTnet",
"owner_organization_id":2,
"rdns":null,
"resource_uri":"/api/v2/intelligence/50460807643/",
"retina_confidence":-1,
"source":"TOR Exit Nodes",
"source_reported_confidence":100,
"status":"active",
"tags":null,
"threat_type":"tor",
"threatscore":25,
"trusted_circle_ids":[
146
],
"type":"ip",
"update_id":1763222542,
"uuid":"56260f15-377a-48e7-ad40-121f8580a4c5",
"value":"5.29.211.60",
"workgroups":[

War Room Output

Command: !threatstream-intelligence limit="1" country="IL"

-

image

+

image

Check IP/domain reputation: domain

Inputs

@@ -247,7 +247,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":4,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"",
         "confidence":17,
         "country":"RO",
         "created_ts":"2017-06-02T18:09:41.986Z",
         "description":null,
         "expiration_ts":"2017-08-31T11:58:38.253Z",
         "feed_id":0,
         "id":859843899,
         "import_session_id":213529,
         "ip":"185.72.179.152",
         "is_public":true,
         "itype":"adware_domain",
         "latitude":"46.000000",
         "longitude":"25.000000",
         "meta":{  
            "detail":"",
            "detail2":"bifocals_deactivated_on_2017-08-31_12:47:29.013755",
            "severity":"low"
         },
         "modified_ts":"2017-08-31T12:47:28.926Z",
         "org":"Nix Web Solutions Pvt Ltd",
         "owner_organization_id":738,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/859843899/",
         "retina_confidence":17,
         "source":"Analyst",
         "source_reported_confidence":90,
         "status":"inactive",
         "tags":[  
            {  
               "id":"rd4",
               "name":"pony"
            }
         ],
         "threat_type":"adware",
         "threatscore":4,
         "trusted_circle_ids":null,
         "type":"domain",
         "update_id":1023048164,
         "value":"kpanels.in",
         "workgroups":null
      }
   ]
}

War Room Output

Command: !domain domain="kpanels.in" threshold="3"

-

image

+

image

Check file's checksum reputation: file

Inputs

@@ -273,7 +273,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":45,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"",
         "confidence":92,
         "country":null,
         "created_ts":"2017-06-07T13:01:10.143Z",
         "description":null,
         "expiration_ts":"2017-09-04T13:31:00.194Z",
         "feed_id":0,
         "id":872721081,
         "import_session_id":214717,
         "ip":null,
         "is_public":true,
         "itype":"apt_md5",
         "latitude":null,
         "longitude":null,
         "meta":{  
            "detail":"",
            "detail2":"imported by user 3096",
            "severity":"very-high"
         },
         "modified_ts":"2017-06-07T13:03:03.200Z",
         "org":"",
         "owner_organization_id":738,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/872721081/",
         "retina_confidence":-1,
         "source":"Analyst",
         "source_reported_confidence":92,
         "status":"active",
         "tags":[  
            {  
               "id":"03e",
               "name":"trickbot"
            }
         ],
         "threat_type":"apt",
         "threatscore":79,
         "trusted_circle_ids":null,
         "type":"md5",
         "update_id":854928373,
         "value":"3e5d63b93a68d715f7559f42285223f4",
         "workgroups":null
      }
   ]
}

War Room Output

Command: !file file="3e5d63b93a68d715f7559f42285223f4" threshold="3"

-

image

+

image

Check Email Address Reputation: threatstream-email-reputation

Inputs

@@ -299,7 +299,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":4,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"",
         "confidence":17,
         "country":"RO",
         "created_ts":"2017-06-02T18:09:41.986Z",
         "description":null,
         "expiration_ts":"2017-08-31T11:58:38.253Z",
         "feed_id":0,
         "id":859843899,
         "import_session_id":213529,
         "ip":"185.72.179.152",
         "is_public":true,
         "itype":"adware_domain",
         "latitude":"46.000000",
         "longitude":"25.000000",
         "meta":{  
            "detail":"",
            "detail2":"bifocals_deactivated_on_2017-08-31_12:47:29.013755",
            "severity":"low"
         },
         "modified_ts":"2017-08-31T12:47:28.926Z",
         "org":"Nix Web Solutions Pvt Ltd",
         "owner_organization_id":738,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/859843899/",
         "retina_confidence":17,
         "source":"Analyst",
         "source_reported_confidence":90,
         "status":"inactive",
         "tags":[  
            {  
               "id":"rd4",
               "name":"pony"
            }
         ],
         "threat_type":"adware",
         "threatscore":4,
         "trusted_circle_ids":null,
         "type":"domain",
         "update_id":1023048164,
         "value":"kpanels.in",
         "workgroups":null
      }
   ]
}

War Room Output

Command: !threatstream-email-reputation email="mailonline_16@filposcv.com" threshold="3"

-

image

+

image

Check IP Reputation: ip

Inputs

@@ -325,7 +325,7 @@
{  
   "meta":{  
      "limit":1000,
      "next":null,
      "offset":0,
      "previous":null,
      "took":4,
      "total_count":1
   },
   "objects":[  
      {  
         "asn":"12400",
         "confidence":69,
         "country":"IL",
         "created_ts":"2018-03-13T10:45:16.182Z",
         "description":null,
         "expiration_ts":"2018-03-20T10:45:16.178Z",
         "feed_id":112,
         "id":50591222843,
         "import_session_id":null,
         "ip":"176.228.66.70",
         "is_public":false,
         "itype":"scan_ip",
         "latitude":"31.964200",
         "longitude":"34.804400",
         "meta":{  
            "detail2":"bifocals_deactivated_on_2018-03-20_13:56:34.918843",
            "severity":"medium"
         },
         "modified_ts":"2018-03-20T13:56:34.461Z",
         "org":"Orange Israel",
         "owner_organization_id":2,
         "rdns":null,
         "resource_uri":"/api/v2/intelligence/50591222843/",
         "retina_confidence":69,
         "source":"Anomali Labs MHN",
         "source_reported_confidence":70,
         "status":"inactive",
         "tags":null,
         "threat_type":"scan",
         "threatscore":25,
         "trusted_circle_ids":[  
            145
         ],
         "type":"ip",
         "update_id":1695845308,
         "uuid":"09688972-7581-4fb9-8e50-7c99a02cd442",
         "value":"176.228.66.70",
         "workgroups":[  

         ]
      }
   ]
}

War Room Output

Command: !ip ip="176.228.66.70" threshold="3"

-

image

+

image

Troubleshooting

The integration was tested with the v2 API on version 2.5.4.

-

This may indicate that a large amount of data returned from Arcsight Logger. To resolve this error, try to limit the search time range or the events list length.  See additional ways to set the search time range in ‘Additional info’ above.
DBot error snap-shot
 

+

This may indicate that a large amount of data returned from Arcsight Logger. To resolve this error, try to limit the search time range or the events list length.  See additional ways to set the search time range in ‘Additional info’ above.
DBot error snap-shot