Details

This atomic belongs to the Darktrace /NETWORK atomic group.

Adds one or more supported observables to the intelfeed in Darktrace. Supported observables include: external domains, IP addresses, and hostnames. Note that hostnames will be added as domains unless the "Hostnames" input is set to True. If using a user-based API token, the user must have the "Edit Domains" permission.

Target: Darktrace /NETWORK integration target or HTTP Endpoint for "your-tenant.cloud.darktrace.com" with no path

Account Key: None if using an integration-provided target, public and private tokens if using an HTTP Endpoint target

Steps:
[] Build the request payload and authorization headers
[] Send the request to Darktrace
[] Check if the request was successful:
[]> If it was, set the output variables
[]> If it wasn't, output an error

More information about this API: https://portal.darktrace.com/product-guides/main/api-intelfeed-request

About
Authorship
Cisco Managed