Hello Vitor,
Thank you for your submission. Currently, we only support querying X-Force casefiles/collections by a query string or collection ID. We do not support the IP reputation feature within X-Force at this time. You can mimic your query by searching for the target IP within collections
here and should see that no results are returned. Try adding a string artifact to your incident with something like "facebook" and re-trigger the rule to see results come back.
If you have ideas for how we can make the X-Force integration better, please let us know through an RFE. Let us know if you have any other questions.
Apologies for the above empty replies. The community forum was acting up a bit yesterday.
Edit: RFE's should be submitted through
Aha.Thank you,
Brian
------------------------------
Brian Reid
------------------------------
Original Message:
Sent: Wed July 08, 2020 09:07 PM
From: Vítor Fagundes Alves Nogueira
Subject: Plugin "X-Force Collections for Resilient" brings no results
After install the "X-Force Collections for Resilient" plugin, I performed some tests using IPs with bad reputation on X-Force and the queries didn't bring any results.
The researched IP was 198.54.117.198.
Follow the images bellow:
------------------------------
Vítor Fagundes Alves Nogueira
------------------------------