Skip to content

PaloAltoWildfire#

README

PaloAlto Wildfire responder#

This responder sends observable to PaloAlto Wildfire service.

Requirements#

One need valid API-key to PaloAlto's Wildfire service.
* Cloud Wildfire * Local Wildfire instance

Configuration#

  • api_key : Wildfire API-key
  • wildfire_url: Wildfire URL (default: Cloud version)

Official documenation#

Official API documentation: PaloAlto site.

PaloAltoWildfire_URL_submission#

Author: Keijo Korte - @korteke
License: AGPL-V3
Version: 1.0
Supported data types:
- url
- domain
- fqdn
Registration required: True
Subscription required: True
Free subscription: False
Third party service: https://www.paloaltonetworks.com/network-security/wildfire

Description#

Submit URL to PaloAlto Wildfire service.

Configuration#

api_key PaloAlto Wildfire API key
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required True
wildfire_url PaloAlto Wildfire Takedown URL
Default value if not configured https://wildfire.paloaltonetworks.com/publicapi/submit/link
Type of the configuration item string
The configuration item can contain multiple values False
Is required True