Skip to main content

ZeroFox V2

ZeroFox icon

Version: 1.1.0
Updated: October 1, 2026

Query data and utilize actions in the ZeroFox platform, including CTI enrichment lookups, alert management, and automated threat intelligence feeds.

Actions​

  • Indicator Lookup (Enrichment) - Searches the ZeroFox CTI indicators feed for threat intelligence on IPs, domains, URLs, and file hashes, returning confidence levels, threat types, TTPs, and ASN data.
  • Malware Lookup (Enrichment) - Searches the ZeroFox CTI malware and ransomware datasets by hash, family name, or C2 infrastructure, returning sample details and extracted C2 endpoints.
  • Vulnerability Lookup (Enrichment) - Searches ZeroFox CTI for vulnerability intelligence by CVE, product, or vendor, returning CVSS scores, remediation guidance, and optionally associated exploit code.
  • Phishing Domain Lookup (Enrichment) - Searches the ZeroFox CTI phishing dataset by domain pattern, hosting IP, or TLS certificate fingerprint, returning phishing site details with hosting and certificate context.
  • Threat Actor Profile Lookup (Enrichment) - Searches ZeroFox CTI for MITRE ATT&CK-anchored threat actor profiles by name, technique, tactic, target industry, or country.
  • Get Alert Details (Enrichment) - Retrieves a specific alert with enriched context, including AI/ML insights, metadata, WHOIS enrichment, breach data, offending content, scan results, and session cookie data.
  • List Alerts (Enrichment) - Returns alerts matching given filters and parameters.
  • List Users (Enrichment) - Lists all users.
  • Request Takedown (Containment) - Requests takedown of an existing alert.
  • Alerts Daemon (Daemon) - Polls for new ZeroFox platform alerts and ingests them for automated triage.
  • Indicator Feed Daemon (Daemon) - Polls the ZeroFox CTI indicators feed for new and updated indicators of compromise.
  • Vulnerability Daemon (Daemon) - Polls the ZeroFox CTI vulnerabilities feed for new and updated CVE records.

Configure ZeroFox in Automation Service and Cloud SOAR​

Before you can use this automation integration, you must configure its authentication settings so that the product you're integrating with can communicate with Sumo Logic. For general guidance, see Configure Authentication for Automation Integrations.

How to open the integration's configuration dialog
  1. Access App Central and install the integration. (You can configure at installation, or after installation with the following steps.)
  2. Go to the Integrations page.
    Classic UI. In the main Sumo Logic menu, select Automation and then select Integrations in the left nav bar.
    New UI. In the main Sumo Logic menu, select Automation > Integrations. You can also click the Go To... menu at the top of the screen and select Integrations.
  3. Select the installed integration.
  4. Hover over the resource name and click the Edit button that appears.
    Edit a resource

In the configuration dialog, enter information from the product you're integrating with. When done, click TEST to test the configuration, and click SAVE to save the configuration:

  • Label. Enter the name you want to use for the resource.

  • API URL. Enter your ZeroFox API URL, for example, https://api.zerofox.com.

  • Username. Enter your ZeroFox account username.

  • Password. Enter your ZeroFox account password.

  • Connection Timeout (s). Optionally set a connection timeout in seconds. Default is 180.

  • Verify SSL Certificate. Select to verify the SSL certificate for secure connections.

  • Verify Server Certificate. Select to validate the server’s SSL certificate.

  • Connection Timeout (s). Set the maximum amount of time the integration will wait for a server's response before terminating the connection. Enter the connection timeout time in seconds (for example, 180).

  • Automation Engine. Select Cloud execution for this certified integration. Select a bridge option only for a custom integration. See Cloud or Bridge execution.

  • Proxy Options. Select whether to use a proxy. (Applies only if the automation engine uses a bridge instead of cloud execution.)

    • Use no proxy. Communication runs on the bridge and does not use a proxy.
    • Use default proxy. Use the default proxy for the bridge set up as described in Using a proxy.
    • Use different proxy. Use your own proxy service. Provide the proxy URL and port number.
ZeroFox V2 configuration

For information about ZeroFox, see ZeroFox documentation.

Change Log​

VersionDateDescription
1.1.0October 1, 2026Added new CTI enrichment actions: Indicator Lookup, Malware Lookup, Vulnerability Lookup, Phishing Domain Lookup, and Threat Actor Profile Lookup. Added new daemon actions: Alerts Daemon, Indicator Feed Daemon, and Vulnerability Daemon. Enhanced Get Alert Details with sub-resource enrichment options. Updated authentication to use Bearer JWT token flow.
1.0.0April 24, 2026Initial release of the ZeroFox V2 integration.
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.