{
  "name": "ti_threatq",
  "title": "ThreatQuotient",
  "version": "1.39.3",
  "release": "ga",
  "description": "Ingest threat intelligence indicators from ThreatQuotient with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_threatq/ti_threatq-1.39.3.zip",
  "path": "/package/ti_threatq/1.39.3",
  "icons": [
    {
      "src": "/img/threatq.svg",
      "path": "/package/ti_threatq/1.39.3/img/threatq.svg",
      "title": "ThreatQuotient",
      "size": "600x600",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.4 || ~9.0.7 || ^9.1.4"
    }
  },
  "owner": {
    "type": "partner",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_threatq/ti_threatq-1.39.3.zip.sig",
  "format_version": "3.3.1",
  "readme": "/package/ti_threatq/1.39.3/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/threatq-overview.png",
      "path": "/package/ti_threatq/1.39.3/img/threatq-overview.png",
      "title": "ThreatQ Overview Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/threatq-file.png",
      "path": "/package/ti_threatq/1.39.3/img/threatq-file.png",
      "title": "ThreatQ File Screenshot",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/threatq-url.png",
      "path": "/package/ti_threatq/1.39.3/img/threatq-url.png",
      "title": "ThreatQ URL Screenshot",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_threatq/1.39.3/LICENSE.txt",
    "/package/ti_threatq/1.39.3/changelog.yml",
    "/package/ti_threatq/1.39.3/manifest.yml",
    "/package/ti_threatq/1.39.3/validation.yml",
    "/package/ti_threatq/1.39.3/docs/README.md",
    "/package/ti_threatq/1.39.3/img/threatq-file.png",
    "/package/ti_threatq/1.39.3/img/threatq-overview.png",
    "/package/ti_threatq/1.39.3/img/threatq-url.png",
    "/package/ti_threatq/1.39.3/img/threatq.svg",
    "/package/ti_threatq/1.39.3/kibana/tags.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/lifecycle.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/manifest.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/sample_event.json",
    "/package/ti_threatq/1.39.3/kibana/dashboard/ti_threatq-a05fd810-78f1-11ec-a97c-7db1518ab848.json",
    "/package/ti_threatq/1.39.3/kibana/dashboard/ti_threatq-ab289de0-78f1-11ec-a97c-7db1518ab848.json",
    "/package/ti_threatq/1.39.3/kibana/dashboard/ti_threatq-b45b0c40-78f1-11ec-a97c-7db1518ab848.json",
    "/package/ti_threatq/1.39.3/kibana/tag/ti_threatq-c0cca010-78f1-11ec-a97c-7db1518ab848.json",
    "/package/ti_threatq/1.39.3/data_stream/threat/fields/agent.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/fields/base-fields.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/fields/beats.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/fields/ecs.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/fields/fields.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/fields/is-ioc-transform-source-true.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_threatq/1.39.3/data_stream/threat/agent/stream/httpjson.yml.hbs",
    "/package/ti_threatq/1.39.3/data_stream/threat/elasticsearch/ilm/default_policy.json",
    "/package/ti_threatq/1.39.3/data_stream/threat/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/fields/agent.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/fields/base-fields.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/fields/beats.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/fields/ecs.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/fields/fields.yml",
    "/package/ti_threatq/1.39.3/elasticsearch/transform/latest_ioc/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "ti_threatq",
      "title": "ThreatQuotient",
      "description": "Ingest threat intelligence indicators from ThreatQuotient with Elastic Agent.",
      "inputs": [
        {
          "type": "httpjson",
          "title": "Ingest threat intelligence indicators from ThreatQuotient with Elastic Agent.",
          "description": "Ingest threat intelligence indicators from ThreatQuotient with Elastic Agent."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_threatq.threat",
      "title": "ThreatQ",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "host",
              "type": "text",
              "title": "ThreatQ hostname",
              "description": "The hostname of the ThreatQ instance.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://threatqexample.com"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "client_id",
              "type": "text",
              "title": "ThreatQ Oauth2 Client ID",
              "description": "The Client ID used to access the ThreatQ instance.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "client_secret",
              "type": "password",
              "title": "ThreatQ Oauth2 Client Secret",
              "description": "The Client ID used to access the ThreatQ instance.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "token_url",
              "type": "text",
              "title": "ThreatQ Oauth2 Token URL",
              "description": "The Token URL used for Oauth2 Authentication.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://threatqexample.com/api/token"
            },
            {
              "name": "data_collection_id",
              "type": "text",
              "title": "ThreatQ Collection ID",
              "description": "The ID of the collection to retrieve data from.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the logs will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "ioc_expiration_duration",
              "type": "text",
              "title": "IOC Expiration Duration",
              "description": "Enforces all IOCs to expire after this duration. This setting is required to avoid \"orphaned\" IOCs that never expire. Use [Elasticsearch time units](https://www.elastic.co/guide/en/elasticsearch/reference/current/api-conventions.html#time-units) in days, hours, or minutes (e.g 10d)",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "90d"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page size",
              "description": "Maximum number of records to pull in one request. The maximum supported page size value is 1000.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "threat_library_fields",
              "type": "text",
              "title": "Threat Library Fields",
              "description": "Comma-separated list of fields to retrieve from the Threat Library. An asterisk (*) can be used to retrieve all default fields. In ThreatQ v6.12 and later, sources and attributes are no longer part of the default fields and must be explicitly requested.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "sources,attributes,attributes.name,attributes.value,*"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#verification_mode: none\n"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "threatq-threat"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve Custom fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "ThreatQuotient",
          "description": "Collect indicators from the ThreatQuotient API",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_threatq",
      "path": "threat"
    }
  ]
}
