This app implements investigative actions to perform lookups for quick reputation information, contextual threat intelligence and external threat alerts
Supported Actions
- test connectivity: Validate the asset configuration for connectivity
- alert data lookup: Get details on alerts configured and generated by Recorded Future by alert rule ID and/or time range
- alert rule lookup: Search for alert rule IDs by name
- url intelligence: Get threat intelligence for a URL
- url reputation: Get a quick indicator of the risk associated with a URL
- vulnerability intelligence: Get threat intelligence for a vulnerability
- vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
- file intelligence: Get threat intelligence for a file identified by its hash
- file reputation: Get a quick indicator of the risk associated with a file identified by its hash
- domain intelligence: Get threat intelligence for a domain
- domain reputation: Get a quick indicator of the risk associated with a domain
- ip intelligence: Get threat intelligence for an IP address
- ip reputation: Get a quick indicator of the risk associated with an IP address
- threat assessment: Get an indicator of the risk based on context
- list contexts: Get a list of possible contexts to use in threat triage