The association to bind to the tpeName field from Threatconnect.
ThreatConnect
- Details
- Content
- Dependencies
- Version History
Threat intelligence platform.
| Name | Description |
|---|---|
Threatconnect classifier | |
Threatconnect Mapper (incoming) |
| Name | Description |
|---|---|
ThreatConnect Group Type | |
ThreatConnect Id | The association to bind to the id field from Threatconnect. |
ThreatConnect Security Labels | |
ThreatConnect Victim Assets | |
ThreatConnect Attributes | |
ThreatConnect AssociatedGroups | |
ThreatConnect Event Date | The association to bind to the event date field from Threatconnect. |
ThreatConnect Associated Indicators | |
ThreatConnect Created By |
| Name | Description |
|---|---|
ThreatConnect |
| Name | Description |
|---|---|
| ThreatConnect v3 | ThreatConnect's integration is a intelligence-driven security operations solution with intelligence, automation, analytics, and workflows. |
| ThreatConnect v2 (Deprecated) | Deprecated. Use the ThreatConnect v3 integration instead. |
| ThreatConnect (Deprecated) | Deprecated. Use the ThreatConnect v3 integration instead. |
| Name | Description |
|---|---|
ThreatConnect Layout |
| Name | Description |
|---|---|
Threatconnect classifier | |
Threatconnect Mapper (incoming) |
| Name | Description |
|---|---|
ThreatConnect Associated Indicators | |
ThreatConnect Created By | |
ThreatConnect Victim Assets | |
ThreatConnect Id | The association to bind to the id field from Threatconnect. |
ThreatConnect AssociatedGroups | |
ThreatConnect Event Date | The association to bind to the event date field from Threatconnect. |
ThreatConnect Attributes | |
ThreatConnect Group Type | The association to bind to the tpeName field from Threatconnect. |
ThreatConnect Security Labels |
| Name | Description |
|---|---|
ThreatConnect |
| Name | Description |
|---|---|
| ThreatConnect v3 | ThreatConnect's integration is a intelligence-driven security operations solution with intelligence, automation, analytics, and workflows. |
| ThreatConnect v2 (Deprecated) | Deprecated. Use the ThreatConnect v3 integration instead. |
| ThreatConnect (Deprecated) | Deprecated. Use the ThreatConnect v3 integration instead. |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
| Filters And Transformers | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Common Types | By: Cortex XSOAR |
| Phishing | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Filters And Transformers | By: Cortex XSOAR |
| Base | By: Cortex XSOAR |
Integrations
ThreatConnect v3
- Fixed an issue where large ThreatConnect object IDs could lose numerical precision when processed by Cortex XSOAR, resulting in incorrect IDs being used by downstream commands. Large integer values are now returned as strings to preserve their accuracy.
- 45638
Download
Integrations
ThreatConnect v3
- Fixed an issue where the ip, url, domain, and file reputation commands returned no results when the Default Organization parameter was configured.
- Fixed an issue where the ip, domain, and file reputation commands displayed an incorrect ThreatConnect URL Reputation header.
- 44035
Download
Integrations
ThreatConnect v3
- Added a new filter argument to the tc-indicators command, allowing free-text TQL queries to filter indicator results.
- Added a new operator argument to the tc-get-indicators-by-tag command, allowing the comparison operator to be changed (e.g., EQ, NE, CONTAINS, STARTSWITH, ENDSWITH, IN). Defaults to LIKE for backward compatibility.
- Added a new TQL Filter instance configuration parameter (under the advanced section) that applies a free-text TQL filter to the fetch, combined as AND with other filters.
- 43561
Download
Integrations
ThreatConnect v3
- Added new commands to support victims:
- tc-create-victim
- tc-update-victim
- tc-delete-victim
- tc-list-victims
- tc-create-victim-asset
- tc-update-victim-asset
- tc-delete-victim-asset
- tc-list-victim-assets
- tc-create-victim-attribute
- tc-update-victim-attribute
- tc-delete-victim-attribute
- tc-list-victim-attributes
- Removed the description argument from the tc-add-indicator command as it was not supported by the API.
- Added the associated_victim_asset_id argument to the tc-update-group command.
- Updated the Docker image to: demisto/python3:3.10.13.84405.
- 31908
Download
Integrations
ThreatConnect v3
- Fixed an issue where large ThreatConnect object IDs could lose numerical precision when processed by Cortex XSOAR, resulting in incorrect IDs being used by downstream commands. Large integer values are now returned as strings to preserve their accuracy.
- 45638
Download
Integrations
ThreatConnect v3
- Fixed an issue where the ip, url, domain, and file reputation commands returned no results when the Default Organization parameter was configured.
- Fixed an issue where the ip, domain, and file reputation commands displayed an incorrect ThreatConnect URL Reputation header.
- 44035
Download
Integrations
ThreatConnect v3
- Added a new filter argument to the tc-indicators command, allowing free-text TQL queries to filter indicator results.
- Added a new operator argument to the tc-get-indicators-by-tag command, allowing the comparison operator to be changed (e.g., EQ, NE, CONTAINS, STARTSWITH, ENDSWITH, IN). Defaults to LIKE for backward compatibility.
- Added a new TQL Filter instance configuration parameter (under the advanced section) that applies a free-text TQL filter to the fetch, combined as AND with other filters.
- 43561
Download
Integrations
ThreatConnect v3
- Added new commands to support victims:
- tc-create-victim
- tc-update-victim
- tc-delete-victim
- tc-list-victims
- tc-create-victim-asset
- tc-update-victim-asset
- tc-delete-victim-asset
- tc-list-victim-assets
- tc-create-victim-attribute
- tc-update-victim-attribute
- tc-delete-victim-attribute
- tc-list-victim-attributes
- Removed the description argument from the tc-add-indicator command as it was not supported by the API.
- Added the associated_victim_asset_id argument to the tc-update-group command.
- Updated the Docker image to: demisto/python3:3.10.13.84405.
- 31908
Download
PUBLISHER
PLATFORMS
INFO
| Certification | Certified | Read more |
| Supported By | Cortex | |
| Created | July 23, 2020 | |
| Last Release | August 25, 2026 |
WORKS WITH THE FOLLOWING INTEGRATIONS:



