Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
Intezer app icon

Intezer

Intezer connector for Splunk SOAR enables security teams to automate the analysis, detection, and response of threats by integrating Intezer's technology into their Splunk workflows

soar product badge

Latest Version 1.1.1
April 28, 2025
Compatibility
Not Available
Platform Version: 6.4, 6.3, 6.2, 6.1, 6.0, 5.5
Rating

0

(0)

Log in to rate this app
Support
Intezer support icon
Not Supported
Intezer connector for Splunk SOAR enables security teams to automate the analysis, detection, and response of threats by integrating Intezer's technology into their Splunk workflows

Supported Actions

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • detonate file: Analyze a file from Splunk vault with Intezer
  • detonate hash: Analyze a file hash (SHA1, SHA256, or MD5) with Intezer
  • get file report: Get a file analysis report based on an analysis ID or a file hash
  • detonate url: Analyze a suspicious URL with Intezer
  • get url report: Get a URL analysis report based on a URL analysis ID
  • get alert: Get an ingested alert triage and response information using alert ID
  • submit alert: Submit a new alert, including the raw alert information, to Intezer for processing
  • submit suspicious email: Submit a suspicious phishing email in a raw format (.MSG or .EML) to Intezer for processing
  • index file: Index the file's genes into the organizational database
  • unset index file: Unset file's indexing

Categories

Created By

SOAR Community

Type

connector

Downloads

248

Resources

Login to report this app listing