ZeroFOX

Modified on: Thu, 22 Apr, 2021 at 12:34 PM

Overview

ZeroFOX’s patented SaaS technology processes and protects millions of posts, messages and accounts daily across the social and digital landscape, spanning LinkedIn, Facebook, Slack, Twitter, HipChat, Instagram, Pastebin, YouTube, mobile app stores, the deep & dark web, domains and more.


ZeroFOX Transforms for Maltego enable analysts to visualize and pivot between ZeroFOX’s protected social media Entities, alerts, rules, and identified perpetrators.


Benefits

  • With 40+ Transforms, search and enrich context for cyber-attacks stemming from social media and digital channels
  • Visualize ZeroFOX social media threat intelligence and custom alerts


To read more about ZeroFox click here.


[ZF] Get Rules

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Rules
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase


Variants

Transform NameInput EntitiesShort Description
zfRuleGroup2Rulezf.ruleGroupRetrieves all of the rules that fall under the selected threat rule group.
zfAssetRuleszf.AssetRetrieves the configured threat rules for the selected entity/ies(asset/s).

[ZF] Get Alert Actions

Description

Retrieves all of the Takedown-as-a-Service™ actions statuses, including the date-time, that correspond to the selected alert/s.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Alert Actions
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfAlertActions
Input Entitieszf.Alert
Output EntitiesPhrase
Short DescriptionRetrieves all of the Takedown-as-a-Service™ actions statuses, including the date-time, that correspond to the selected alert/s.

[ZF] Get All Entities

Description

Retrieves all of the configured entities(assets).


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get All Entities
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfAllAssets
Input Entitieszf.ZeroFox
Output EntitiesPhrase
Short DescriptionRetrieves all of the configured entities(assets).

[ZF] Get Entity Alerts

Description

Retrieves identified threat alerts, related to the selected network entity/ies(asset/s).


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse

Transform Meta Info

InformationValue
Display Name[ZF] Get Entity Alerts
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfAssetAlerts
Input Entitieszf.Asset
Output EntitiesPhrase
Short DescriptionRetrieves identified threat alerts, related to the selected network entity/ies(asset/s).

[ZF] Get Perpetrators

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Perpetrators
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase

Variants

Transform NameInput EntitiesShort Description
zfAlertPerpszf.AlertRetrieves social media intelligence of all the perpetrators related to the selected threat alert/s.
zfAssetPerpzf.AssetRetrieves social media intelligence of all the perpetrators related to the selected entity/ies(asset/s).
zfRuleGroup2Perpzf.ruleGroupRetrieves social media intelligence of all the perpetrators related to the selected threat rule group/s.

[ZF] Get All Rules

Description

Retrieves all of the configured threat rules.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get All Rules
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfAllRules
Input Entitieszf.ZeroFox
Output EntitiesPhrase
Short DescriptionRetrieves all of the configured threat rules.

[ZF] Get All Rule Groups

Description

Retrieves all of the configured threat rule groups.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get All Rule Groups
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfAllRuleGroups
Input Entitieszf.ZeroFox
Output EntitiesPhrase
Short DescriptionRetrieves all of the configured threat rule groups.

[ZF] Get Rule Groups

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Rule Groups
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase


Variants

Transform NameInput EntitiesShort Description
zfStatusGroupszf.StatusRetrieves the configured threat rule groups that have alerts containing the selected status/es.
zfPerpGroupmaltego.AliasRetrieves the configured threat rule groups relevant to the identified threat alerts triggered by the selected perpetrator/s violations.
zfPageGroupmaltego.URLRetrieves the configured threat rule groups for the selected page/s.
zfNetworkGroupzf.SocialNetworkRetrieves the configured threat rule groups for the selected social network/s.
zfAssetGroupzf.AssetRetrieves the configured threat rule groups for the selected entity/ies(asset/s.

[ZF] Get Alert Status

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Alert Status
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase


Variants

Transform NameInput EntitiesShort Description
zfNetworkStatuszf.SocialNetworkRetrieves the status/es of identified threat alerts, relevant to the selected social network/s.
zfRuleStatuszf.RuleRetrieves the status(es) of identified threat alerts that fall under the selected threat rule/s configured.
zfPerpStatusmaltego.AliasRetrieves the status(es) of identified threat alerts triggered by the selected perpetrator/s violations.
zfPageStatusmaltego.URLRetrieves the status(es) of identified threat alerts, relevant to the selected page/s.
zfStatuszf.ZeroFoxRetrieves all possible statuses of an identified threat alert.
zfAssetStatzf.AssetRetrieves the status(es) of identified threat alerts, relevant to the selected entitie/s(asset/s).
zfRuleGroup2Statzf.ruleGroupRetrieves the status(es) of identified threat alerts that fall under the selected threat rule/s group/s configured.

[ZF] Get Social Networks

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Social Networks
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase


Variants

Transform NameInput EntitiesShort Description
zfRuleNetzf.RuleRetrieves the social networks that are related with a selected threat rule group.
zfStatusNetzf.StatusRetrieves the social networks that have alerts containing the selected status/es.
zfAssetNetworkszf.AssetRetrieves the social networks of the selected entity/ies(asset/s).
zfRuleGroup2Netzf.ruleGroupRetrieves the social networks that are related with a selected threat rule group.

[ZF] Get Entities

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Entities
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase


Variants

Transform NameInput EntitiesShort Description
zfNetworkAssetzf.SocialNetworkRetrieves the configured entities(assets) of the selected social network(s).
zfRuleAssetzf.RuleRetrieves the entities(assets) affected by violations that fall under the selected rule.
zfStatusAssetzf.StatusRetrieves the entities(assets) that have identified threat alerts containing the selected status/es.
zfPerpAssetmaltego.AliasRetrieves the entities(assets) which are affected by the selected perpetrator/s violations.
zfRuleGroup2Assetzf.ruleGroupRetrieves the entities(assets) affected by violations that fall under the selected rule.
zfPageAssetmaltego.URLRetrieves the configured entities(assets) of the selected page/s.

[ZF] Get Rule Alerts

Description

Retrieves identified threat alerts based on the selected rule/s configured.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Rule Alerts
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfRuleAlerts
Input Entitieszf.Rule
Output EntitiesPhrase
Short DescriptionRetrieves identified threat alerts based on the selected rule/s configured.

[ZF] List Social Networks

Description

Retrieves all social networks.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] List Social Networks
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfNets
Input Entitieszf.ZeroFox
Output EntitiesPhrase
Short DescriptionRetrieves all social networks.

[ZF] Get Alerts

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Alerts
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Output EntitiesPhrase


Variants

Transform NameInput EntitiesShort Description
zfNetworkAlertszf.SocialNetworkRetrieves identified threat alerts, that are relevant to the selected social network/s.
zfStatusAlertzf.StatusRetrieves all identified threat alerts containing the selected status/es.
zfRuleGroup2Alertzf.ruleGroupRetrieves identified threat alerts based on the selected rule group/s configured.

[ZF] Get Perpetrator Alerts

Description

Retrieves identified threat alerts, relevant to the violations commited by the selected perpetrator.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Perpetrator Alerts
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfPerpAlert
Input Entitiesmaltego.Alias
Output EntitiesPhrase
Short DescriptionRetrieves identified threat alerts, relevant to the violations commited by the selected perpetrator.

[ZF] Get Page Alerts

Description

Retrieves the identified threat alerts, relevant to the selected page/s.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Page Alerts
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfPageAlert
Input Entitiesmaltego.URL
Output EntitiesPhrase
Short DescriptionRetrieves the identified threat alerts, relevant to the selected page/s.

[ZF] Get Rules by Status

Description

Retrieves the configured threat rules that have alerts containing the selected status/es.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Rules by Status
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfStatusRule
Input Entitieszf.Status
Output EntitiesPhrase
Short DescriptionRetrieves the configured threat rules that have alerts containing the selected status/es.

[ZF] Get Perpetrator Rules

Description

Retrieves the configured threat rules relevant to the identified threat alerts triggered by the selected perpetrator/s violations.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Perpetrator Rules
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfPerpRule
Input Entitiesmaltego.Alias
Output EntitiesPhrase
Short DescriptionRetrieves the configured threat rules relevant to the identified threat alerts triggered by the selected perpetrator/s violations.

[ZF] Get Page Rules

Description

Retrieves the configured threat rules for the selected page/s.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Page Rules
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfPageRule
Input Entitiesmaltego.URL
Output EntitiesPhrase
Short DescriptionRetrieves the configured threat rules for the selected page/s.

[ZF] Get Network Rules

Description

Retrieves the configured threat rule groups for the selected social network/s.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Network Rules
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfNetworkRules
Input Entitieszf.SocialNetwork
Output EntitiesPhrase
Short DescriptionRetrieves the configured threat rule groups for the selected social network/s.

[ZF] Get Network Perpetrators

Description

Retrieves social media intelligence of all the perpetrators related to the selected social network/s.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Network Perpetrators
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfNetworkPerpetrator
Input Entitieszf.SocialNetwork
Output EntitiesPhrase
Short DescriptionRetrieves social media intelligence of all the perpetrators related to the selected social network/s.

[ZF] Get Rule Perpetrators

Description

Retrieves social media intelligence of all the perpetrators related to the selected threat rule/s.


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
ZeroFOX API KeystringDefaultValueTrueTrueFalse


Transform Meta Info

InformationValue
Display Name[ZF] Get Rule Perpetrators
OwnerMaltego Transforms
Authormaltegotransforms@maltego.com
Data SourceZF
Transform NamezfRulePerp
Input Entitieszf.Rule
Output EntitiesPhrase
Short DescriptionRetrieves social media intelligence of all the perpetrators related to the selected threat rule/s.

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.