
Oct 10, 2023
1.0.0
ThreatQ Versions >= 5.20.0
Cofense Triage Action Bundle
Overview
The Cofense Triage Action Bundle provides actions that can be utilized to create or update Cofense Triage indicators.
The integration provides the following actions:
- Cofense Triage - Create Indicators - uploads indicators contained in a thread collection to Cofense Triage.
- Cofense Triage - Update Indicators - updates Cofense Triage indicators contained in a threat collection.
The action is compatible with the following indicator types:
- MD5
- URL
- FQDN
- SHA256
The action returns the following enriched indicator types:
- MD5
- URL
- FQDN
- SHA256
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.