Anthropic Claude

Designed to assist security professionals with security investigations, threat hunting, and anomaly detection, leveraging Anthropic Claude's natural language conversational capabilities.

Messaging and Conferencing · Anthropic Claude

Details

IDAnthropic Claude
ProviderAnthropic
CategoryMessaging and Conferencing
From Version6.0.0
Docker Imagedemisto/parse-emails:0.1.48.10569905
Supported ModulesAgentix XSIAM

README

Designed to assist security professionals with security investigations, threat hunting, and anomaly detection, leveraging Anthropic Claude’s natural language conversational capabilities.

Configure Anthropic Claude on Cortex XSOAR

  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for Anthropic Claude.
  3. Click Add instance to create and configure a new integration instance.
Parameter Description Required
Server URL   True
API Key Anthropic API Key used for the LLM commands (claude-send-message, claude-check-email-*, claude-create-soc-email-template). Generate one at https://console.anthropic.com/keys. False
Model The model that will process the inputs and generate the response. False
Model (Optional - overrides selected choice) The model that will process the inputs and generate the response. False
Max tokens The maximum number of tokens that can be generated for the response. Required by Anthropic’s API (defaults to 1024). True
Temperature Sets the randomness in responses. Lower values (closer to 0) produce more deterministic and consistent outputs, while higher values (up to 1) increase randomness and variety. False
Top P Enables nucleus sampling where only the top ‘p’ percent (0 to 1) of probable tokens are considered. Lower values result in more focused outputs, while higher values increase diversity. False
Compliance Access Key Anthropic Compliance Access Key (sk-ant-api01-…) used for event collection and the read-only compliance commands. Required to fetch events and to run the claude-list-* / claude-get-* commands. False
Organization UUID The default Organization UUID to use for compliance commands that accept an org_uuid argument. The command argument overrides this value when provided. False
Fetch events   False
Activity types A comma-separated list of Activity Feed types to narrow the feed (e.g., user.login,chat.created). Leave empty to fetch all activity types. See the available activity types here: https://platform.claude.com/docs/en/api/compliance/activities/list. False
Maximum number of events per fetch The maximum number of events to fetch per cycle. Defaults to 50000 (5000 x 10 calls). False
Trust any certificate (not secure)   False
Use system proxy settings   False
  1. Click Test to validate the URLs, token, and connection.

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

claude-send-message


Send a plain message to the selected Claude model and receive the generated response.

Base Command

claude-send-message

Input

Argument Name Description Required
message The message that the Claude model will respond to. Required
reset_conversation_history Whether to keep previously sent messages in a conversation context or start a new conversation. Possible values are: yes, no. Optional
max_tokens The maximum number of tokens that can be generated for the response. Optional
temperature Sets the randomness in responses. Lower values (closer to 0) produce more deterministic and consistent outputs, while higher values (up to 1) increase randomness and variety. Optional
top_p (0-1) Enables nucleus sampling where only the top ‘p’ percent of probable tokens are considered. Lower values result in more focused outputs, while higher values increase diversity. Optional

Context Output

Path Type Description
AnthropicClaude.Conversation Dictionary Entire conversation (if not reset) between the user and the Claude model.

claude-check-email-header


Checking email header for possible security issues. It is possible to keep asking questions on the provided info using ‘claude-send-message’. Resets conversation context by default.

Base Command

claude-check-email-header

Input

Argument Name Description Required
entry_id Entry ID of an uploaded ‘.eml’ file. Required
additional_instructions Additional instructions or security issue to focus on. Optional
max_tokens The maximum number of tokens that can be generated for the response. Optional
temperature Sets the randomness in responses. Lower values (closer to 0) produce more deterministic and consistent outputs, while higher values (up to 1) increase randomness and variety. Optional
top_p Enables nucleus sampling where only the top ‘p’ percent of probable tokens are considered. Lower values result in more focused outputs, while higher values increase diversity. Optional

Context Output

Path Type Description
AnthropicClaude.Conversation Dictionary Entire conversation (if not reset) between the user and the Claude model.

claude-check-email-body


Check email body for possible security issues. It is possible to keep asking questions on the provided info using ‘claude-send-message’. Resets conversation context by default.

Base Command

claude-check-email-body

Input

Argument Name Description Required
entry_id Entry ID of an uploaded ‘.eml’ file. Required
additional_instructions Additional instructions or security issue to focus on. Optional
max_tokens The maximum number of tokens that can be generated for the response. Optional
temperature Sets the randomness in responses. Lower values (closer to 0) produce more deterministic and consistent outputs, while higher values (up to 1) increase randomness and variety. Optional
top_p Enables nucleus sampling where only the top ‘p’ percent of probable tokens are considered. Lower values result in more focused outputs, while higher values increase diversity. Optional

Context Output

Path Type Description
AnthropicClaude.Conversation Dictionary Entire conversation (if not reset) between the user and the Claude model.

claude-create-soc-email-template


Create an email template out of the conversation context to be sent from the SOC.

Base Command

claude-create-soc-email-template

Input

Argument Name Description Required
additional_instructions Additional instructions or security issue to focus on. Optional
max_tokens The maximum number of tokens that can be generated for the response. Optional
temperature Sets the randomness in responses. Lower values (closer to 0) produce more deterministic and consistent outputs, while higher values (up to 1) increase randomness and variety. Optional
top_p Enables nucleus sampling where only the top ‘p’ percent of probable tokens are considered. Lower values result in more focused outputs, while higher values increase diversity. Optional

Context Output

Path Type Description
AnthropicClaude.Conversation Dictionary Entire conversation (if not reset) between the user and the Claude model.

claude-list-chats


List chats metadata (Compliance API).

Base Command

claude-list-chats

Input

Argument Name Description Required
user_ids Up to 10 user IDs. Run claude-list-organization-users first to obtain them. Required
organization_ids Filter by organization UUID(s). Optional
project_ids Filter by project ID(s). Optional
created_at_gte RFC 3339 lower bound on creation time (example: 2025-06-07T08:09:10Z). Optional
created_at_lte RFC 3339 upper bound on creation time. Optional
updated_at_gte RFC 3339 lower bound on update time. Optional
updated_at_lte RFC 3339 upper bound on update time. Optional
limit Page size. Optional
after_id Cursor - walk toward newer chats. Optional
before_id Cursor - walk toward older chats. Optional

Context Output

Path Type Description
AnthropicClaude.Chat.id String The chat ID.
AnthropicClaude.Chat.name String The chat name.
AnthropicClaude.Chat.created_at Date The chat creation time.
AnthropicClaude.Chat.updated_at Date The chat update time.
AnthropicClaude.Chat.model String The model used in the chat.
AnthropicClaude.Chat.organization_uuid String The organization UUID.
AnthropicClaude.Chat.project_id String The project ID.

claude-list-groups


List groups, or retrieve a single group when group_id is provided (Compliance API).

Base Command

claude-list-groups

Input

Argument Name Description Required
group_id When provided, returns that single group instead of the list. Optional
limit Page size (list mode only). Optional
next_token Page token (list mode only). Optional

Context Output

Path Type Description
AnthropicClaude.Group.id String The group ID.
AnthropicClaude.Group.name String The group name.
AnthropicClaude.Group.description String The group description.
AnthropicClaude.Group.source_type String The group source type (direct or scim).
AnthropicClaude.Group.roles Unknown Array of role IDs assigned to the group.
AnthropicClaude.Group.created_at Date The group creation time.
AnthropicClaude.Group.updated_at Date The group update time.

claude-get-events


Manually retrieve Activity Feed events from the Anthropic Compliance API for testing and troubleshooting.

Base Command

claude-get-events

Input

Argument Name Description Required
limit Maximum number of events to retrieve. Default is 50. Optional
should_push_events If true, the events are pushed to Cortex XSIAM. Possible values are: true, false. Default is false. Optional
activity_types A comma-separated list of Activity Feed types to narrow the feed. Optional

Context Output

There is no context output for this command.

claude-list-roles


List roles of an organization, or retrieve a single role when role_id is provided (Compliance API).

Base Command

claude-list-roles

Input

Argument Name Description Required
org_uuid Organization UUID. Overrides the instance Organization UUID parameter when provided. Optional
role_id When provided, returns that single role instead of the list. Optional
limit Maximum number of roles to return. Maximum: 1000. Default is 50. Optional
next_token Page token (list mode only). Optional

Context Output

Path Type Description
AnthropicClaude.Organization.Role.id String The role ID.
AnthropicClaude.Organization.Role.name String The role name.
AnthropicClaude.Organization.Role.description String The role description.
AnthropicClaude.Organization.Role.created_at Date The role creation time.
AnthropicClaude.Organization.Role.updated_at Date The role update time.

claude-list-projects


List projects, or retrieve a single project when project_id is provided (Compliance API).

Base Command

claude-list-projects

Input

Argument Name Description Required
project_id When provided, returns that single project instead of the list. Optional
limit Maximum number of projects to return. Maximum: 100. Default is 50. Optional
next_token Page token (list mode only). Optional

Context Output

Path Type Description
AnthropicClaude.Project.id String The project ID.
AnthropicClaude.Project.name String The project name.
AnthropicClaude.Project.is_private Boolean Whether the project is private.
AnthropicClaude.Project.organization_uuid String The organization UUID.
AnthropicClaude.Project.created_at Date The project creation time.
AnthropicClaude.Project.updated_at Date The project update time.

claude-list-project-attachments


List the attachments of a project (Compliance API).

Base Command

claude-list-project-attachments

Input

Argument Name Description Required
project_id Project ID. Required
next_token Page token. Optional

Context Output

Path Type Description
AnthropicClaude.Project.Attachment.id String The attachment ID.
AnthropicClaude.Project.Attachment.filename String The attachment filename.
AnthropicClaude.Project.Attachment.mime_type String The attachment MIME type.
AnthropicClaude.Project.Attachment.type String The attachment type (project_file or project_doc).
AnthropicClaude.Project.Attachment.created_at Date The attachment creation time.

claude-list-organization-users


List the users of an organization (Compliance API).

Base Command

claude-list-organization-users

Input

Argument Name Description Required
org_uuid Organization UUID. Overrides the instance Organization UUID parameter when provided. Optional
limit Maximum number of users to return. Maximum: 1000. Default is 50. Optional
next_token Page token from a previous response’s next_page. Optional

Context Output

Path Type Description
AnthropicClaude.Organization.User.id String The user ID.
AnthropicClaude.Organization.User.full_name String The user full name.
AnthropicClaude.Organization.User.email String The user email.
AnthropicClaude.Organization.User.organization_role String The user’s role in the organization.
AnthropicClaude.Organization.User.created_at Date The user creation time.

claude-list-role-permissions


List the permissions of a role (Compliance API).

Base Command

claude-list-role-permissions

Input

Argument Name Description Required
org_uuid Organization UUID. Overrides the instance Organization UUID parameter when provided. Optional
role_id Role ID. Required
limit Maximum number of permissions to return. Maximum: 1000. Default is 50. Optional
next_token Page token. Optional

Context Output

Path Type Description
AnthropicClaude.Organization.Role.Permission.resource_type String The permission resource type.
AnthropicClaude.Organization.Role.Permission.resource_id String The permission resource ID.
AnthropicClaude.Organization.Role.Permission.action String The permission action.

claude-list-group-members


List the members of a group (Compliance API).

Base Command

claude-list-group-members

Input

Argument Name Description Required
group_id Group ID. Required
limit Maximum number of members to return. Maximum: 1000. Default is 50. Optional
next_token Page token. Optional

Context Output

Path Type Description
AnthropicClaude.Group.Member.user_id String The member user ID.
AnthropicClaude.Group.Member.email String The member email.
AnthropicClaude.Group.Member.created_at Date The membership creation time.
AnthropicClaude.Group.Member.updated_at Date The membership update time.

claude-get-project-document


Retrieve a project document including its text content (Compliance API).

Base Command

claude-get-project-document

Input

Argument Name Description Required
project_id Project ID. Required
document_id Project document ID. Required

Context Output

Path Type Description
AnthropicClaude.ProjectDocument.id String The document ID.
AnthropicClaude.ProjectDocument.filename String The document filename.
AnthropicClaude.ProjectDocument.mime_type String The document MIME type.
AnthropicClaude.ProjectDocument.created_at Date The document creation time.
AnthropicClaude.ProjectDocument.content String The document text content.

claude-list-organizations


List the organizations under the parent organization (Compliance API).

Base Command

claude-list-organizations

Input

Argument Name Description Required
limit Client-side cap on the number of organizations returned. Maximum: 1000. Default is 50. Optional

Context Output

Path Type Description
AnthropicClaude.Organization.uuid String The organization UUID.
AnthropicClaude.Organization.name String The organization name.
AnthropicClaude.Organization.created_at Date The organization creation time.

claude-list-chat-messages


List the messages of a chat (Compliance API).

Base Command

claude-list-chat-messages

Input

Argument Name Description Required
chat_id Chat ID. Required
limit Maximum number of messages to return. Maximum: 1000. Default is 50. Optional
after_id Cursor. Optional
before_id Cursor. Optional
order Sort direction. Possible values are: asc, desc. Optional
created_at_gte RFC 3339 lower bound on creation time. Optional
created_at_lte RFC 3339 upper bound on creation time. Optional
updated_at_gte RFC 3339 lower bound on update time. Optional
updated_at_lte RFC 3339 upper bound on update time. Optional

Context Output

Path Type Description
AnthropicClaude.Chat.Message.id String The message ID.
AnthropicClaude.Chat.Message.role String The message role (user or assistant).
AnthropicClaude.Chat.Message.created_at Date The message creation time.

claude-chat-file-delete


Permanently delete a Claude file (a conversation file or a project binary file) via the Compliance API. This is an irreversible hard delete, and it requires a Compliance Access Key with the delete:compliance_user_data scope. Deleting an already-deleted or unknown file ID succeeds (idempotent).

Base Command

claude-chat-file-delete

Input

Argument Name Description Required
file_id The Claude file ID to permanently delete (e.g., claude_file_…). Deletes a file uploaded in a conversation or a project binary file (project_file). This is an irreversible hard delete. Required

Context Output

Path Type Description
AnthropicClaude.DeletedFile.id String The ID of the file that was deleted.
AnthropicClaude.DeletedFile.type String The deletion confirmation type (claude_file_deleted).
AnthropicClaude.DeletedFile.Deleted Boolean The deletion result for the file (true when deleted).

Command example

!claude-chat-file-delete file_id=claude_file_011CbqYrHZoNLmjzW2AC53fK

Context Example

{
    "AnthropicClaude": {
        "DeletedFile": {
            "Deleted": true,
            "id": "claude_file_011CbqYrHZoNLmjzW2AC53fK",
            "type": "claude_file_deleted"
        }
    }
}

Human Readable Output

File deleted

id type Deleted
claude_file_011CbqYrHZoNLmjzW2AC53fK claude_file_deleted true

claude-project-document-delete


Permanently delete a Claude project document (a plain-text project_doc) via the Compliance API. This is an irreversible hard delete, and it requires a Compliance Access Key with the delete:compliance_user_data scope. Deleting an already-deleted or unknown document ID succeeds (idempotent).

Base Command

claude-project-document-delete

Input

Argument Name Description Required
document_id The Claude project document ID to permanently delete (e.g., claude_proj_doc_…). Applies to project plain-text documents (project_doc). This is an irreversible hard delete. Required

Context Output

Path Type Description
AnthropicClaude.DeletedProjectDocument.id String The ID of the project document that was deleted.
AnthropicClaude.DeletedProjectDocument.type String The deletion confirmation type (claude_project_document_deleted).
AnthropicClaude.DeletedProjectDocument.Deleted Boolean The deletion result for the project document (true when deleted).

Command example

!claude-project-document-delete document_id=claude_proj_doc_011CbqYrHZoNLmjzW2AC53fK

Context Example

{
    "AnthropicClaude": {
        "DeletedProjectDocument": {
            "Deleted": true,
            "id": "claude_proj_doc_011CbqYrHZoNLmjzW2AC53fK",
            "type": "claude_project_document_deleted"
        }
    }
}

Human Readable Output

Project document deleted

id type Deleted
claude_proj_doc_011CbqYrHZoNLmjzW2AC53fK claude_project_document_deleted true

<~PLATFORM>

License Requirements

The following configuration parameters require the Cortex XSIAM license:

  • Fetch events

</~PLATFORM>

Configuration parameters

  • url — Server URL (required)
  • apikey
  • model-select — Model
  • model-freetext — Model (Optional - overrides selected choice)
  • max_tokens — Max tokens (required)
  • temperature — Temperature
  • top_p — Top P
  • compliance_apikey — Compliance Access Key
  • organization_uuid — Organization UUID
  • isFetchEvents — Fetch events
  • activity_types — Activity types
  • max_events_per_fetch — Maximum number of events per fetch
  • eventFetchInterval — Events Fetch Interval
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (18)

  • claude-chat-file-delete

    Permanently delete a Claude file (a conversation file or a project binary file) via the Compliance API. This is an irreversible hard delete, and it requires a Compliance Access Key with the delete:compliance_user_data scope. Deleting an already-deleted or unknown file ID succeeds (idempotent).

  • claude-check-email-body

    Check email body for possible security issues. It is possible to keep asking questions on the provided info using 'claude-send-message'. Resets conversation context by default.

  • claude-check-email-header

    Checking email header for possible security issues. It is possible to keep asking questions on the provided info using 'claude-send-message'. Resets conversation context by default.

  • claude-create-soc-email-template

    Create an email template out of the conversation context to be sent from the SOC.

  • claude-get-events

    Manually retrieve Activity Feed events from the Anthropic Compliance API for testing and troubleshooting. Use this command for development and debugging only, as it may produce duplicate events, exceed API rate limits, or disrupt the fetch mechanism.

  • claude-get-project-document

    Retrieve a project document including its text content (Compliance API).

  • claude-list-chat-messages

    List the messages of a chat (Compliance API).

  • claude-list-chats

    List chats metadata (Compliance API).

  • claude-list-group-members

    List the members of a group (Compliance API).

  • claude-list-groups

    List groups, or retrieve a single group when group_id is provided (Compliance API).

  • claude-list-organization-users

    List the users of an organization (Compliance API).

  • claude-list-organizations

    List the organizations under the parent organization (Compliance API).

  • claude-list-project-attachments

    List the attachments of a project (Compliance API).

  • claude-list-projects

    List projects, or retrieve a single project when project_id is provided (Compliance API).

  • claude-list-role-permissions

    List the permissions of a role (Compliance API).

  • claude-list-roles

    List roles of an organization, or retrieve a single role when role_id is provided (Compliance API).

  • claude-project-document-delete

    Permanently delete a Claude project document (a plain-text project_doc) via the Compliance API. This is an irreversible hard delete, and it requires a Compliance Access Key with the delete:compliance_user_data scope. Deleting an already-deleted or unknown document ID succeeds (idempotent).

  • claude-send-message

    Send a plain message to the selected Claude model and receive the generated response.

## Anthropic Claude


### Generate an API Key
1. Sign-up or login to [https://console.anthropic.com](https://console.anthropic.com).
2. Generate a new API Key at [https://console.anthropic.com/keys](https://console.anthropic.com/keys).

### Models & Rate Limits
The integration utilizes the **'Messages'** endpoint. Therefore, it will only be possible to configure models that support the following endpoint: _https://api.anthropic.com/v1/messages_.

_Claude models offer different capabilities, with more advanced models providing better reasoning and comprehension capabilities._

For tasks requiring deep understanding and extensive inputs, opt for more advanced models (e.g. claude-3-opus). These models offer a larger context window, allowing them to process bigger documents, and provide more refined and comprehensive responses.
The more basic models (e.g. claude-3-haiku) often provide simpler answers but are faster and less costly.
- [Models overview](https://docs.anthropic.com/claude/docs/models-overview)

- Each model has its own rate limits: Refer to [rate-limits](https://docs.anthropic.com/claude/reference/rate-limits).


### How to use this integration with XSIAM
This integration allows you to:
- Send messages to Claude models and receive AI-generated responses
- Analyze email headers and bodies for security threats
- Generate SOC email templates
- Collect Anthropic Compliance API Activity Feed events into Cortex XSIAM
- Enumerate the directory (organizations, users, roles, groups) and retrieve content metadata (chats, files, projects)

### Credentials
This integration supports two independent credentials; configure either or both:
- **API Key** — required for the LLM commands (`claude-send-message`, `claude-check-email-*`, `claude-create-soc-email-template`). Generate one at [https://console.anthropic.com/keys](https://console.anthropic.com/keys).
- **Compliance Access Key** (`sk-ant-api01-...`) — required for event collection and the read-only `claude-list-*` / `claude-get-*` commands.

### Compliance API
Event collection and the read-only compliance commands use the **Compliance Access Key**.

#### Prerequisites
The Compliance API is enabled on request (Claude Enterprise plan for the full API). An org owner creates a Compliance Access Key in claude.ai with scopes `read:compliance_activities`, `read:compliance_org_data`, and `read:compliance_user_data`.

See [how to create a Compliance API Key](https://platform.claude.com/docs/en/manage-claude/compliance-api-access).

To enable event collection, set the Compliance Access Key and select **Fetch events**. The first fetch collects the last minute of activity; subsequent fetches continue from the last collected event.

You can optionally set a default **Organization UUID** that the compliance commands fall back to when their `org_uuid` argument is not provided. Use the **Activity types** parameter (a comma-separated list) to narrow the Activity Feed; see the available types in the [Compliance API documentation](https://platform.claude.com/docs/en/api/compliance/activities/list).

---