
Dec 17, 2024
1.1.2
ThreatQ Version: >= 4.34.0
VMRay Feed
Overview
VMRay feed: VMRay TI Extraction Connector Capabilities
Connects Out of Analyzer: Yes – The VMRay TI Extraction ingests threat intelligence data that has been submitted to VMRay Platform via the “VMRay Operation”. VMRay Platform returns Indicators of type URL, MD5, SHA-1, SHA-256, Fuzzy Hash, IPv4 Address, Registry Key, Filename, FQDN and Malware Objects, Attack Patterns and uses basic HTTP authentication based on API key
Use Cases: Enhanced Threat Intelligence, IOC Mining, Detonation, Threat Hunting