Integrates a variety of ThreatQ services into Splunk SOAR
Supported Actions
- test connectivity: Validate the asset configuration for connectivity
- query indicators: Query ThreatQ for indicator context
- create indicators: Create indicators within ThreatQ
- create adversaries: Create adversaries within ThreatQ
- create custom objects: Create custom objects within ThreatQ
- add attribute: Adds an attribute to objects in ThreatQ
- add comment: Adds a comment to objects in ThreatQ
- add tag: Adds a tag to objects in ThreatQ
- set indicator status: Set a status for a given list of indicators
- create task: Create a task within ThreatQ
- create event: Create an event within ThreatQ
- start investigation: Start an investigation within ThreatQ
- upload spearphish: Upload a spearphish attempt to ThreatQ
- upload file: Upload (and parse) a file to ThreatQ
- get related objects: Query ThreatQ for an object's relationships
- create signature: Create a signature within ThreatQ