Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Data source

Description

API endpoint

Collector service name

Devo table

Available from release

Incidents

SOCRadar incidents

/company/{company_id}/incidents/v2

incidents

threatintel.socradar.xti.incidents.1.json

v1.0

Audit logs

SOCRadar audit events

/company/{company_id}/auditlogs

audit_logs

threatintel.socradar.xti.audit_logs.1.json

v1.0

Threat feeds

SOCRadar threat feed entries

/threat/intelligence/socradar_collections

threat_feed

Lookups:

socradar_threat_intelligence_urls

socradar_threat_intelligence_hashes

socradar_threat_intelligence_domains

socradar_threat_intelligence_ips

 

v1.0

For more information on how the events are parsed, visit our page

Flattening preprocessing

Data source

Collector service

Optional

Incidents

incidents

No

Audit logs

audit_logs

No

Threat feeds

threat_feed

No

...