Details

This atomic belongs to the Cisco Threat Response atomic group.

Creates a new Threat Response judgement in your private intelligence store.

Target: SecureX Private Intelligence API or HTTP Endpoint for "private.intel.amp.cisco.com"

Account Key: None (uses a token)

Steps:
[] Generate the JSON for the new judgement
[] Generate the authorization header
[] POST the judgement JSON to Threat Response
[] Check if the judgement was created:
[]> If it was, extract the judgement ID and set the output variable
[]> If it wasn't, return an error

More information about this API: https://private.intel.amp.cisco.com/index.html#/Judgement/post_ctia_judgement

About
Authorship
Cisco Managed