IronDefense Classifier
IronNet
- Details
- Content
- Dependencies
- Version History
The IronDefense Integration allows users to interact with IronDefense alerts within Demisto. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, and to report observed bad activity.
| Name | Description |
|---|---|
IronDefense - Classifier | |
IronDefense - Incoming Mapper | IronDefense Mapper |
| Name | Description |
|---|---|
IronDefense Severity Malicious Details | |
IronDefense Event ID | |
IronDefense Analyst Expectation | |
IronDefense Src Network ID | |
IronDefense Src IP | |
IronDefense Bytes In | |
IronDefense Mismatch Details | |
IronDefense IronDome ID | |
IronDefense Is Blacklisted | |
IronDefense Event Count | |
IronDefense Alert IDs | |
IronDefense Dst Entity Attribute Type | |
IronDefense Severity | |
IronDefense High Cognitive System Details | |
IronDefense Src Entity Attribute Type | |
IronDefense Start Time | |
IronDefense Severity Suspicious Details | |
IronDefense Confidence | |
IronDefense Created | |
IronDefense VUE URL | |
IronDefense SubCategory | |
IronDefense Is Whitelisted | |
IronDefense Dst Network ID | |
IronDefense Comment Details | |
IronDefense Alert ID | |
IronDefense Raw Data Format | |
IronDefense First Event Created | |
IronDefense End Time | |
IronDefense Dst Port | |
IronDefense Analyst Severity | |
IronDefense IronDome Category | |
IronDefense Dome Shared Time | |
IronDefense Dome Tags | |
IronDefense Secondary App Protocol | |
IronDefense Total Bytes | |
IronDefense Category | |
IronDefense Dst Entity Attribute | |
IronDefense Aggregation Criteria | |
IronDefense Updated | |
IronDefense Status | |
IronDefense Src Entity Attribute | |
IronDefense Primary App Protocol | |
IronDefense Severity Details | |
IronDefense Last event Created | |
IronDefense Bytes Out | |
IronDefense Dst IP | |
IronDefense App Domains |
| Name | Description |
|---|---|
IronDefense Alert Notification | |
IronDefense Event Notification | |
IronDefense IronDome Notification |
| Name | Description |
|---|---|
| IronDefense (Partner Contribution) | The IronDefense Integration for Cortex XSOAR allows users to interact with IronDefense alerts within Cortex XSOAR. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, to report observed bad activity, get alerts, get events, and get IronDome information. |
| Name | Description |
|---|---|
IronDefense Alert Notification | IronDefense Alert Notification Layout |
IronDefense Event Notification | IronDefense Event Notification Layout |
IronDefense IronDome Notification | IronDefense IronDome Notification Layout |
| Name | Description |
|---|---|
IronDefense - Classifier | IronDefense Classifier |
IronDefense - Incoming Mapper | IronDefense Mapper |
| Name | Description |
|---|---|
IronDefense Src Entity Attribute Type | |
IronDefense Alert ID | |
IronDefense App Domains | |
IronDefense Severity Details | |
IronDefense Is Whitelisted | |
IronDefense Severity Malicious Details | |
IronDefense SubCategory | |
IronDefense Alert IDs | |
IronDefense IronDome ID | |
IronDefense Bytes In | |
IronDefense High Cognitive System Details | |
IronDefense Severity | |
IronDefense Dome Shared Time | |
IronDefense Analyst Severity | |
IronDefense Start Time | |
IronDefense Aggregation Criteria | |
IronDefense Raw Data Format | |
IronDefense Comment Details | |
IronDefense Severity Suspicious Details | |
IronDefense End Time | |
IronDefense Total Bytes | |
IronDefense Mismatch Details | |
IronDefense Dst Entity Attribute | |
IronDefense Status | |
IronDefense Confidence | |
IronDefense Is Blacklisted | |
IronDefense Src Entity Attribute | |
IronDefense VUE URL | |
IronDefense Dst Entity Attribute Type | |
IronDefense Analyst Expectation | |
IronDefense Created | |
IronDefense Updated | |
IronDefense Secondary App Protocol | |
IronDefense Last event Created | |
IronDefense Event Count | |
IronDefense Bytes Out | |
IronDefense Dome Tags | |
IronDefense Event ID |
| Name | Description |
|---|---|
IronDefense Event Notification | |
IronDefense IronDome Notification | |
IronDefense Alert Notification |
| Name | Description |
|---|---|
| IronDefense (Partner Contribution) | The IronDefense Integration for Cortex allows users to interact with IronDefense alerts within Cortex. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, to report observed bad activity, get alerts, get events, and get IronDome information. |
| Name | Description |
|---|---|
IronDefense Alert Notification Layout Rule | |
IronDome Notification Layout Rule | |
IronDefense Event Notification Layout Rule |
| Name | Description |
|---|---|
IronDefense Event Notification | IronDefense Event Notification Layout |
IronDefense Alert Notification | IronDefense Alert Notification Layout |
IronDefense IronDome Notification | IronDefense IronDome Notification Layout |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Common Types | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
Incident Fields
- IronDefense Category
- IronDefense IronDome Category
Incident Fields
- IronDefense Category
- IronDefense Dst Network ID
- IronDefense IronDome Category
- IronDefense Primary App Protocol
Incident Fields
- IronDefense First Event Created
- IronDefense Src Network ID
Incident Fields
Maintenance and stability enhancements for the following fields:
- IronDefense Src IP
- IronDefense Dst Port
- IronDefense Dst IP
Integrations
IronDefense
- Updated the Docker image to: demisto/python3:3.9.8.24399.
Incident Fields
- IronDefense IronDome Category
- Maintenance and stability enhancements.
Integrations
IronDefense
- Updated the Docker image to: demisto/python3:3.9.7.24076.
Integrations
IronDefense
- Upgraded the Docker image to: demisto/python3:3.9.5.21272.
Integrations
IronDefense
- Upgraded the Docker image to: demisto/python3:3.9.5.20958.
Layouts
- layout-details-IronDefense_Event_Notification.json
Maintenance and stability enhancements.
Integrations
IronDefense
- Upgraded the Docker image to demisto/python3:3.8.6.13358.
Integrations
IronDefense
- Updated the pack support information.
Integrations
IronDefense
- Updated the pack support information.
Integrations
IronDefense
- Added ability to retrieve IronDefense alerts and events.
- Improving descriptions.
Layouts
layout-details-IronDefense_IronDome_Notification.json
- Create layout for notificationtype
layout-details-IronDefense_Event_Notification.json
- Create layout for notificationtype
layout-details-IronDefense_Alert_Notification.json
- Create layout for notificationtype
Incident Fields
IronDefense VUE URL
- Add field
IronDefense Updated
- Add field
IronDefense Total Bytes
- Add field
IronDefense SubCategory
- Add field
IronDefense Status
- Add field
IronDefense Start Time
- Add field
IronDefense Src Network ID
- Add field
IronDefense Src IP
- Add field
IronDefense Src Entity Attribute Type
- Add field
IronDefense Src Entity Attribute
- Add field
IronDefense Severity Suspicious Details
- Add field
IronDefense Severity Malicious Details
- Add field
IronDefense Severity Details
- Add field
IronDefense Severity
- Add field
IronDefense Secondary App Protocol
- Add field
IronDefense Raw Data Format
- Add field
IronDefense Primary App Protocol
- Add field
IronDefense Mismatch Details
- Add field
IronDefense Last event Created
- Add field
IronDefense Is Whitelisted
- Add field
IronDefense Is Blacklisted
- Add field
Incident Types
IronDefense IronDome Notification
- add incident type
IronDefense IronDome ID
- Add field
IronDefense IronDome Category
- Add field
IronDefense High Cognitive System Details
- Add field
IronDefense First Event Created
- Add field
IronDefense Event Notification
- %add incident type
IronDefense Event ID
- Add field
IronDefense Event Count
- Add field
IronDefense End Time
- Add field
IronDefense Dst Port
- Add field
IronDefense Dst Network ID
- Add field
IronDefense Dst IP
- Add field
IronDefense Dst Entity Attribute Type
- Add field
IronDefense Dst Entity Attribute
- Add field
IronDefense Dome Tags
- Add field
IronDefense Dome Shared Time
- Add field
IronDefense Created
- Add field
IronDefense Confidence
- Add field
IronDefense Comment Details
- Add field
IronDefense Category
- Add field
IronDefense Bytes Out
- Add field
IronDefense Bytes In
- Add field
IronDefense App Domains
- Add field
IronDefense Analyst Severity
- Add field
IronDefense Analyst Expectation
- Add field
IronDefense Alert Notification
- add incident type
IronDefense Alert IDs
- Add field
IronDefense Alert ID
- Add field
IronDefense Aggregation Criteria
- Add field
Classifiers
IronDefense
Added new Classifier
IronDefense - Incoming Mapper
Added new incoming mapper
IronDefense - Classifier
Added new Classifier
The IronDefense Integration allows users to interact with IronDefense alerts within Demisto. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, and to report observed bad activity.
Layout Rules
New: IronDome Notification Layout Rule
- Added support for layouts and layout rules in XSIAM.
New: IronDefense Alert Notification Layout Rule
- Added support for layouts and layout rules in XSIAM.
New: IronDefense Event Notification Layout Rule
- Added support for layouts and layout rules in XSIAM.
- 23481
Download
Incident Fields
- IronDefense Category
- IronDefense IronDome Category
Incident Fields
IronDefense First Event Created
IronDefense Src Network ID
IronDefense Category
IronDefense Dst Network ID
IronDefense IronDome Category
IronDefense Primary App Protocol
Incident Fields
Maintenance and stability enhancements for the following fields:
- IronDefense Src IP
- IronDefense Dst Port
- IronDefense Dst IP
Integrations
IronDefense
- Updated the Docker image to: demisto/python3:3.9.8.24399.
Incident Fields
- IronDefense IronDome Category
- Maintenance and stability enhancements.
Integrations
IronDefense
- Updated the Docker image to: demisto/python3:3.9.7.24076.
Integrations
IronDefense
- Upgraded the Docker image to: demisto/python3:3.9.5.21272.
Integrations
IronDefense
- Upgraded the Docker image to: demisto/python3:3.9.5.20958.
Layouts
- layout-details-IronDefense_Event_Notification.json
Maintenance and stability enhancements.
Integrations
IronDefense
- Upgraded the Docker image to demisto/python3:3.8.6.13358.
Integrations
IronDefense
- Updated the pack support information.
Integrations
IronDefense
- Updated the pack support information.
Integrations
IronDefense
- Added ability to retrieve IronDefense alerts and events.
- Improving descriptions.
Layouts
layout-details-IronDefense_IronDome_Notification.json
- Create layout for notificationtype
layout-details-IronDefense_Event_Notification.json
- Create layout for notificationtype
layout-details-IronDefense_Alert_Notification.json
- Create layout for notificationtype
Incident Fields
IronDefense VUE URL
- Add field
IronDefense Updated
- Add field
IronDefense Total Bytes
- Add field
IronDefense SubCategory
- Add field
IronDefense Status
- Add field
IronDefense Start Time
- Add field
IronDefense Src Network ID
- Add field
IronDefense Src IP
- Add field
IronDefense Src Entity Attribute Type
- Add field
IronDefense Src Entity Attribute
- Add field
IronDefense Severity Suspicious Details
- Add field
IronDefense Severity Malicious Details
- Add field
IronDefense Severity Details
- Add field
IronDefense Severity
- Add field
IronDefense Secondary App Protocol
- Add field
IronDefense Raw Data Format
- Add field
IronDefense Primary App Protocol
- Add field
IronDefense Mismatch Details
- Add field
IronDefense Last event Created
- Add field
IronDefense Is Whitelisted
- Add field
IronDefense Is Blacklisted
- Add field
Incident Types
IronDefense IronDome Notification
- add incident type
IronDefense IronDome ID
- Add field
IronDefense IronDome Category
- Add field
IronDefense High Cognitive System Details
- Add field
IronDefense First Event Created
- Add field
IronDefense Event Notification
- %add incident type
IronDefense Event ID
- Add field
IronDefense Event Count
- Add field
IronDefense End Time
- Add field
IronDefense Dst Port
- Add field
IronDefense Dst Network ID
- Add field
IronDefense Dst IP
- Add field
IronDefense Dst Entity Attribute Type
- Add field
IronDefense Dst Entity Attribute
- Add field
IronDefense Dome Tags
- Add field
IronDefense Dome Shared Time
- Add field
IronDefense Created
- Add field
IronDefense Confidence
- Add field
IronDefense Comment Details
- Add field
IronDefense Category
- Add field
IronDefense Bytes Out
- Add field
IronDefense Bytes In
- Add field
IronDefense App Domains
- Add field
IronDefense Analyst Severity
- Add field
IronDefense Analyst Expectation
- Add field
IronDefense Alert Notification
- add incident type
IronDefense Alert IDs
- Add field
IronDefense Alert ID
- Add field
IronDefense Aggregation Criteria
- Add field
Classifiers
IronDefense
Added new Classifier
IronDefense - Incoming Mapper
Added new incoming mapper
IronDefense - Classifier
Added new Classifier
The IronDefense Integration allows users to interact with IronDefense alerts within Demisto. The Integration provides the ability to rate alerts, update alert statuses, add comments to alerts, and to report observed bad activity.
PUBLISHER
PLATFORMS
INFO
| Certification | Certified | Read more |
| Supported By | Partner | |
| Created | June 30, 2020 | |
| Last Release | October 29, 2025 |
WORKS WITH THE FOLLOWING INTEGRATIONS:

