Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
Cofense Triage app icon

Cofense Triage

This app supports investigative actions that enable the security teams to analyze and respond to phishing faster

soar product badge

Compatibility
Not Available
Platform Version: 6.4, 6.3, 6.2, 6.1, 6.0, 5.5, 5.4, 5.3, 5.2, 5.1, 5.0, 4.10, 4.9
Rating

0

(0)

Log in to rate this app
This app supports investigative actions that enable the security teams to analyze and respond to phishing faster

Supported Actions

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • on poll: Callback action for the on_poll ingest functionality
  • get threat indicators: Retrieve the subjects, senders, domains, URLs, or MD5 or SHA256 hashes that operators identified in Cofense Triage as threat indicators within a specified timeframe
  • get reports: Retrieve all reports in the Inbox, Recon, and Processed folders that match specified parameters
  • get report: Retrieve a single report that matches the specified report ID. Optionally ingest to a provided label
  • get email: Downloads the raw email attachment for the report that matches the specified report ID
  • get file: Downloads and vault the attachment that matches the specified attachment ID
  • get reporters: Retrieves information about reporters, such as their email address and credit score, whether they are VIP reporters, how many reports they reported, and the date and time of their last report
  • get reporter: Retrieve reporter that matches the specified reporter ID
  • run query: Retrieve integration results based on the specified hash (MD5 or SHA256) or URL. Specify only one parameter (sha256, md5, or URL) with this method

Categories

Created By

SOAR Community

Type

connector

Downloads

559

Resources

Login to report this app listing