{
  "name": "ti_cif3",
  "title": "Collective Intelligence Framework v3",
  "version": "1.20.2",
  "release": "ga",
  "description": "Ingest threat indicators from a Collective Intelligence Framework v3 instance with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_cif3/ti_cif3-1.20.2.zip",
  "path": "/package/ti_cif3/1.20.2",
  "icons": [
    {
      "src": "/img/csg_logo_big.svg",
      "path": "/package/ti_cif3/1.20.2/img/csg_logo_big.svg",
      "title": "csirtgadgets logo",
      "size": "1047x748",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    }
  },
  "owner": {
    "type": "community",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_cif3/ti_cif3-1.20.2.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_cif3/1.20.2/docs/README.md",
  "license": "basic",
  "assets": [
    "/package/ti_cif3/1.20.2/LICENSE.txt",
    "/package/ti_cif3/1.20.2/changelog.yml",
    "/package/ti_cif3/1.20.2/manifest.yml",
    "/package/ti_cif3/1.20.2/validation.yml",
    "/package/ti_cif3/1.20.2/docs/README.md",
    "/package/ti_cif3/1.20.2/img/csg_logo_big.svg",
    "/package/ti_cif3/1.20.2/kibana/tags.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/lifecycle.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/manifest.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/sample_event.json",
    "/package/ti_cif3/1.20.2/kibana/dashboard/ti_cif3-6005a190-0aba-11ed-bcc0-01c79f2670f3.json",
    "/package/ti_cif3/1.20.2/kibana/dashboard/ti_cif3-63a0e470-0a30-11ed-bcc0-01c79f2670f3.json",
    "/package/ti_cif3/1.20.2/kibana/dashboard/ti_cif3-aedada10-0ab5-11ed-bcc0-01c79f2670f3.json",
    "/package/ti_cif3/1.20.2/kibana/dashboard/ti_cif3-b4d9d9b0-0a2f-11ed-bcc0-01c79f2670f3.json",
    "/package/ti_cif3/1.20.2/kibana/dashboard/ti_cif3-bda23600-0abb-11ed-bcc0-01c79f2670f3.json",
    "/package/ti_cif3/1.20.2/kibana/dashboard/ti_cif3-fef149c0-0a2f-11ed-bcc0-01c79f2670f3.json",
    "/package/ti_cif3/1.20.2/kibana/tag/ti_cif3-ec8c3e30-0c59-11ed-9b65-435777f1d8a1.json",
    "/package/ti_cif3/1.20.2/data_stream/feed/fields/base-fields.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/fields/beats.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/fields/ecs.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/fields/fields.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/manifest.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/transform.yml",
    "/package/ti_cif3/1.20.2/data_stream/feed/agent/stream/httpjson.yml.hbs",
    "/package/ti_cif3/1.20.2/data_stream/feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_cif3/1.20.2/data_stream/feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/fields/base-fields.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/fields/beats.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/fields/ecs.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/fields/fields.yml",
    "/package/ti_cif3/1.20.2/elasticsearch/transform/latest_threat/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_cif3",
      "title": "Collective Intelligence Framework v3",
      "description": "Ingest threat indicators from a Collective Intelligence Framework v3 instance with Elastic Agent.",
      "inputs": [
        {
          "type": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "url",
              "title": "CIFv3 API base URL",
              "description": "Base URL for CIFv3 instance, e.g.: https://cif.yourdomain.tld",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "api_token",
              "type": "password",
              "title": "API Token",
              "description": "The CIFv3 API read token",
              "multi": false,
              "required": true,
              "show_user": true
            }
          ],
          "title": "Collect threat indicators via API",
          "description": "Ingest threat indicators from a Collective Intelligence Framework v3 instance with Elastic Agent."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_cif3.feed",
      "ilm_policy": "logs-ti_cif3.feed-default_policy",
      "title": "CIFv3 Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "confidence",
              "type": "text",
              "title": "Confidence",
              "description": "Minimum confidence (0-10) to return indicator in feed",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 8
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "cif_tags",
              "type": "text",
              "title": "Filter on indicator tags",
              "description": "A comma separated list of indicator tags to retrieve, e.g.: 'botnet,exploit,malware,phishing'",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "type",
              "type": "text",
              "title": "Filter on indicator type",
              "description": "An indicator type (fqdn|ipv4|url|ssdeep) to retrieve, example: 'md5'",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "limit",
              "type": "text",
              "title": "Result size limit",
              "description": "Maximum result set size, capped at 250000",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 100000
            },
            {
              "name": "initial_lookback",
              "type": "text",
              "title": "Initial lookback period",
              "description": "How far back to look for indicators the first time the agent is started.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "120h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "How frequently to pull the feed. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "60m"
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "Enforces all IOCs to expire after this duration since their report time indicated in the feed. Use [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units) in days, hours, or minutes (e.g 90d)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "730d"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL",
              "description": "Default example enables https verification. Change to 'none' to disable. https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "verification_mode: full"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "120s"
            },
            {
              "name": "proxy_url",
              "type": "url",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags to add to each event once ingested into Elastic. Ingested indicators' tags will be appended dynamically to this list.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "cif3-indicator"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "CIFv3 feed indicators",
          "description": "Collect CIFv3 feed indicators",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_cif3",
      "path": "feed"
    }
  ]
}
