Intel 471 Malware Intelligence

Updated 1 month ago by TruSTAR

This document describes how to set up the Intel 471 Malware Intelligence premium intelligence source in the TruSTAR platform.

This source leverages Intel 471’s industry-leading access within the cybercriminal underground to obtain early access to malware including Trojans, RATs and Stealers, which is then analyzed and reverse-engineered malware to create actionable signatures and malware reports. Malware Intelligence was developed for seamless and automated ingestion into security tools and infrastructure.

  • Source Type: Premium Intel
  • Update Type: Feed-based
  • Update Frequency: 15 minutes
  • Parser: Yes
  • Time to Install: 10 minutes

Observables Supported

Requirements

  • A subscription to Intel 471 Malware Intelligence
  • Malware Intelligence API ID (Intel 471 portal login email)
  • Malware Intelligence API Key
    TruSTAR Admin rights are required to activate this Premium Intelligence feed.

Getting Started

  1. Log into the TruSTAR Web App.
  2. Click the Marketplace icon on the left side icon list.
  3. Choose Premium Intel.
  4. Click Subscribe on the Intel 471 Malware Intelligence box.
  5. Enter the information requested and click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

Report Mapping

The information retrieved from this intelligence source is stored in the Intel 471 Malware IntelligencemEnclave using this format.

Field 

Explanation

Example

Report Title

UID

X999a2ffcd9d8XX99

External ID

UID field of response.

X999a2ffcd9d8XX99

Report Body

Individual item of json response

Time Begun

None

Tags

Confidence field of response.

[“Confidence: high”]

Deeplink

None

Client Type

PYTHON SDK

Client Meta Tag

trustash

Known Issues

No reported issues.

Please contact support@trustar.co if you have issues with this integration.


How Did We Do?