Infoblox BloxOne Threat Defense
Infoblox BloxOne Threat Defense is a DNS-based security solution that protects networks from cyber threats by analyzing and blocking malicious traffic.
Infoblox BloxOne Threat Defense is a comprehensive security solution that provides advanced threat intelligence and protection. This connector enables Swimlane Turbine users to automate the creation of dossier lookup jobs and retrieve active threat data, enhancing their threat detection and response capabilities. By integrating with Infoblox, users can streamline threat intelligence processes, reduce manual effort, and improve the accuracy and speed of threat investigations.
The Infoblox BloxOne Threat Defense integrates with Swimlane Turbine to lookup IPs, Hosts, and URLs and Query Threats.
Prerequisites
Before you can use the Infoblox BloxOne Threat Defense connector for Turbine, you'll need access to the Infoblox API. This requires the following:
- an API key authentication using the following parameters:
- URL: The endpoint URL for accessing Infoblox services.
- API Key: A unique key provided by Infoblox for authenticating API requests.
Capabilities
This connector provides the following capabilities:
- Create Dossier Lookup Jobs
- Lookup Host
- Lookup IP
- Lookup URL
- Lookup hash
- Lookup email
- Get Threat Intelligence Data Exchange
- Query Threats
Create Dossier Lookup Jobs
There are three available formats for the request body, only one of them should be used at a time.
The βoneβ request body searches a single indicator against multiple sources.
"one": {
"type": "host",
"target": "test.net",
"sources": [
"atp",
"rwhois"
]
}The βgroupβ request body searches multiple indicators of the same target type against multiple sources.
"group": {
"type": "host",
"target": [
"test.net",
"ohjeez.net",
"notagain.gg"
],
"sources": [
"atp",
"rwhois"
]The βlistβ request body searches multiple indicators of different target types against multiple sources.
"list": [
{
"type": "host",
"target": "nick.com",
"sources": [
"atp"
]
},
{
"type": "ip",
"target": "1.2.3.4",
"sources": [
"geo"
]
}
]Notes
- For more information on Infoblox BloxOne Threat Defense: Dossier API Documentation TIDE Data Service API Documentation
Additional Documentation
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
key | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create Dossier Lookup Jobs
Create dossier lookup jobs for one or more indicators in Infoblox BloxOne Threat Defense. Requires parameters and an optional wait parameter.
Endpoint
- URL: /tide/api/services/intel/lookup/jobs
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.wait | string | Required | Parameters for the Create Dossier Lookup Jobs action |
target | object | Optional | Parameter for Create Dossier Lookup Jobs |
target.one | object | Optional | The βoneβ request body searches a single indicator against multiple sources. |
target.one.type | string | Optional | Type of the resource |
target.one.target | string | Optional | Parameter for Create Dossier Lookup Jobs |
target.one.sources | array | Optional | Parameter for Create Dossier Lookup Jobs |
target.group | object | Optional | The βgroupβ request body searches multiple indicators of the same target type against multiple sources. |
target.group.type | string | Optional | Type of the resource |
target.group.target | array | Optional | Parameter for Create Dossier Lookup Jobs |
target.group.sources | array | Optional | Parameter for Create Dossier Lookup Jobs |
target.list | array | Optional | The βlistβ request body searches multiple indicators of different target types against multiple sources. |
target.list.type | string | Optional | Type of the resource |
target.list.target | string | Optional | Parameter for Create Dossier Lookup Jobs |
target.list.sources | array | Optional | Parameter for Create Dossier Lookup Jobs |
Input Example
{"parameters":{"wait":"true"},"json_body":{"target":{"one":{"type":"host","target":"test.net","sources":["atp","rwhois"]},"group":{"type":"host","target":["test.net","ohjeez.net","notagain.gg"],"sources":["atp","rwhois"]},"list":[{"type":"host","target":"nick.com","sources":["atp"]},{"type":"ip","target":"1.2.3.4","sources":["geo"]}]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
status | string | Status value |
job_id | string | Unique identifier |
job | object | Output field: job |
job.id | string | Unique identifier |
job.state | string | Output field: job.state |
job.status | string | Status value |
job.create_ts | number | Output field: job.create_ts |
job.create_time | string | Time value |
job.start_ts | number | Output field: job.start_ts |
job.start_time | string | Time value |
job.request_ttl | number | Output field: job.request_ttl |
job.result_ttl | number | Result of the operation |
job.pending_tasks | array | Output field: job.pending_tasks |
job.org | string | Output field: job.org |
job.user | string | Output field: job.user |
job.Authorization | string | Output field: job.Authorization |
job.tasks_tbc | number | Output field: job.tasks_tbc |
tasks | object | Output field: tasks |
tasks.4fe447a9-351b-4034-b450-6ddf7b248c17 | object | Output field: tasks.4fe447a9-351b-4034-b450-6ddf7b248c17 |
tasks.4fe447a9-351b-4034-b450-6ddf7b248c17.id | string | Unique identifier |
tasks.4fe447a9-351b-4034-b450-6ddf7b248c17.state | string | Output field: tasks.4fe447a9-351b-4034-b450-6ddf7b248c17.state |
tasks.4fe447a9-351b-4034-b450-6ddf7b248c17.status | string | Status value |
tasks.4fe447a9-351b-4034-b450-6ddf7b248c17.create_ts | number | Output field: tasks.4fe447a9-351b-4034-b450-6ddf7b248c17.create_ts |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 23 Aug 2023 20:37:23 GMT"},"reason":"OK","json_body":{"status":"pending","job_id":"4644a58d-8002-4af3-b9bd-f9c99daca819","job":{"id":"4644a58d-8002-4af3-b9bd-f9c99daca819","state":"created","status":"pending","create_ts":1622177396366,"create_time":"2021-05-28T04:49:56.366223569Z","start_ts":1622177396366,"start_time":"2021-05-28T04:49:56.366223569Z","request_ttl":0,"result_ttl":3600,"pen...
Get TIDE Query Threats
Get active threats by type and optionally indicator in Infoblox BloxOne Threat Defense. Requires specifying the threat type as a parameter.
Endpoint
- URL: /tide/api/data/threats/state
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.type | string | Required | Parameters for the Get TIDE Query Threats action |
parameters.chosenType | string | Optional | Parameters for the Get TIDE Query Threats action |
parameters.rlimit | number | Optional | Parameters for the Get TIDE Query Threats action |
parameters.distinct | string | Optional | Parameters for the Get TIDE Query Threats action |
Input Example
{"parameters":{"type":"host","chosenType":"eicar.co","rlimit":2,"distinct":"property"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
threat | array | Output field: threat |
threat.id | string | Unique identifier |
threat.type | string | Type of the resource |
threat.host | string | Output field: threat.host |
threat.domain | string | Output field: threat.domain |
threat.tld | string | Output field: threat.tld |
threat.profile | string | Output field: threat.profile |
threat.origin | string | Output field: threat.origin |
threat.property | string | Output field: threat.property |
threat.class | string | Output field: threat.class |
threat.threat_level | number | Output field: threat.threat_level |
threat.detected | string | Output field: threat.detected |
threat.received | string | Output field: threat.received |
threat.imported | string | Output field: threat.imported |
threat.dga | boolean | Output field: threat.dga |
threat.up | boolean | Output field: threat.up |
threat.bric_score | number | Score value |
threat.batch_id | string | Unique identifier |
threat.target | string | Output field: threat.target |
threat.threat_score | number | Score value |
record_count | number | Count value |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Wed, 23 Aug 2023 20:37:23 GMT"},"reason":"OK","json_body":{"threat":[{}],"record_count":10969}}
Response Headers
Header | Description | Example |
|---|---|---|
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Wed, 23 Aug 2023 20:37:23 GMT |