IOC Result Aggregator
The IOC Result Aggregator consolidates and unifies results from multiple IOC lookup sources to provide a single, comprehensive view of indicator findings.
The IOC Result Aggregator connector enables security teams to unify and analyze results from multiple indicator of compromise (IOC) lookup sources. By consolidating disparate IOC verdicts and reputations, this connector provides a single, comprehensive view of threat intelligence findings. Integration with Swimlane Turbine empowers users to automate the aggregation, normalization, and scoring of IOC data within playbooks—eliminating manual correlation and reducing response times. This streamlined approach enhances decision-making, ensures consistent threat classification, and accelerates incident response across diverse security tools.
Capabilities
This connector provides the following capabilities:
- Parse IOCs
Asset Setup
No asset setup needed
Actions
Aggregate IOC Results
Combine and consolidate results from multiple IOC lookup sources to provide a unified view of indicator findings.
Endpoint
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.highest_verdict_minimum_confidence_threshold | number | Optional | Parameters for the Aggregate IOC Results action |
parameters.raw_scores | string | Optional | Parameters for the Aggregate IOC Results action |
parameters.raw_reputations | string | Optional | Parameters for the Aggregate IOC Results action |
parameters.malicious_keywords | string | Optional | Parameters for the Aggregate IOC Results action |
parameters.suspicious_keywords | string | Optional | Parameters for the Aggregate IOC Results action |
parameters.benign_keywords | string | Optional | Parameters for the Aggregate IOC Results action |
parameters.suspicious_threshold | number | Optional | Parameters for the Aggregate IOC Results action |
parameters.malicious_threshold | number | Optional | Parameters for the Aggregate IOC Results action |
Input Example
{"parameters":{"highest_verdict_minimum_confidence_threshold":25,"raw_scores":"30","raw_reputations":"benign,malicious","malicious_keywords":"MALICIOUS","suspicious_keywords":"SUSPICIOUS","benign_keywords":"ALLOW","suspicious_threshold":10,"malicious_threshold":50}}
Output
Parameter | Type | Description |
|---|---|---|
last_aggregated | string | Output field: last_aggregated |
highest_verdict | string | Output field: highest_verdict |
highest_verdict_confidence | number | Unique identifier |
highest_score | number | Score value |
normalized_scores | array | Output field: normalized_scores |
all_verdicts | array | Output field: all_verdicts |
most_common_verdict | string | Output field: most_common_verdict |
most_common_verdict_confidence | number | Unique identifier |
average_score | number | Score value |
highest_verdict_context | string | Output field: highest_verdict_context |
values_by_verdict | string | Value for the parameter |
combined_verdict | string | Output field: combined_verdict |
combined_verdict_confidence | number | Unique identifier |
parsed_value_data | string | Response data |
Output Example
{"last_aggregated":"2022-11-25T15:19:10.470582+00:00","highest_verdict":"Benign","highest_verdict_confidence":100,"highest_score":3,"normalized_scores":[3,0],"all_verdicts":["Benign","Benign"],"most_common_verdict":"Benign","most_common_verdict_confidence":100,"average_score":1.5,"highest_verdict_context":"Highest Threat Score Found: 3.0%","values_by_verdict":"{\"Malicious\": [], \"Suspicious\": [], \"Benign\": [\"3.0%\", \"0.0%\"]}","combined_verdict":"Benign","combined_verdict_confidence":100,...
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |