ZeroFox Alerts
Automatic deploy
Verified
Brand, Digital Risk & Underground Exposure
Overview
Ingests ZeroFox operational alerts as STIX Incidents into OpenCTI, with associated victims, threat actors, and observables.
Imports ZeroFox operational alerts (impersonation, phishing, malware, domain squatting) into OpenCTI as STIX Incidents. Each alert is mapped to an Incident with associated Identity (victim), Threat Actor (perpetrator), and Observables (URLs, Domain-Names). This connector is complementary to the existing ZeroFox CTI connector which consumes curated CTI feeds.
Basic information
Connectors
External import
7.260722.0
0