
Oct 17, 2023
2.0.4
ThreatQ versions >= 4.52.0
CISA Reports CDF
Overview
The CISA Reports CDF consumes data provided by the CISA to notify organizations about threats that exist on the Internet.
The integration provides the following endpoint:
The integration provides the following endpoint:
- CISA Reports - ingests reports from the xml source as well as related system objects.
The integration ingests the following system object types:
- Files
- Incidents
- Indicators
- Reports
- TTPs
Note: The CISA Reports CDF replaces the US-CERT Reports CDF. The US-CERT website was removed and its threat intelligence feed was migrated to the main CISA website. This resulted in a naming update as well as an update to the endpoint utilized by the integration.