
Jan 22, 2025
2.0.2
ThreatQ versions >= 5.0.0
Mandiant Intelligence Reports CDF
Overview
The Mandiant Intelligence Reports integration allows a user to ingest threat intelligence reports from Mandiant’s API.
The integration provides the following feeds:
- Mandiant Intelligence Reports - returns a list of finished intelligence reports created by Mandiant.
- Mandiant Report Download (Supplemental) - returns details of a Mandiant report.
- Mandiant Report Related Indicators (Supplemental) - returns indicators from a Mandiant report.
The integration ingests the following system object types:
- Adversaries
- Indicators
- Malware
- Reports
- Vulnerabilities
- TTP
- Signatures