Blueliv ThreatCompass
Blueliv ThreatCompass systematically looks for information about companies,products, people, brands, logos, assets, technology and other information, depending on your needs. Blueliv ThreatCompass allows you to monitor and track all this information to keep your data, your organization and its employees safe.
Data Enrichment & Threat Intelligence · Blueliv ThreatCompass
Details
| ID | Blueliv ThreatCompass |
|---|---|
| Provider | Outpost24 |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Blueliv ThreatCompass systematically looks for information about companies,products, people, brands, logos, assets, technology and other information, depending on your needs. Blueliv ThreatCompass allows you to monitor and track all this information to keep your data, your
organization and its employees safe
Configure Blueliv ThreatCompass in Cortex
| Parameter | Description | Required |
|---|---|---|
| url | Server URL (e.g. https://demisto.blueliv.com/api/v2 ) |
False |
| credentials | Username | False |
| organization | Organization ID | True |
| type | Module Type | True |
| module | Module ID | True |
| unsecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
| isFetch | Fetch incidents | False |
| incidentType | Incident type | False |
| fetch_limit | Fetch Limit (Max.- 200, Recommended less than 50) | False |
| fetch_status | Fetch resource status (POSITIVE, NEGATIVE…) | False |
| first_fetch_time | First fetch time | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
blueliv-resource-all
Recovers all resources from the module.
Base Command
blueliv-resource-all
Input
| Argument Name | Description | Required |
|---|---|---|
| startDate | Minimum date to recover resources. Formats: yyyy-mm-dd or yyyy-mm-ddThh:mm:ss | Optional |
| finalDate | Maximum date to recover resources. Formats: yyyy-mm-dd or yyyy-mm-ddThh:mm:ss | Optional |
| page | Results page to get. For each page, there are {limit} resources. | Optional |
| limit | Maximum number of resources to recover | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| BluelivThreatCompass | Unknown | List object of recovered resources |
Command Example
!blueliv-resource-all limit=10
Context Example
{
"BluelivThreatCompass": {
"DataLeakage": [
{
"analysis_calc_result": "POSITIVE",
"analysis_result": "POSITIVE",
"analysis_user_result": "POSITIVE",
"changed_at": 1589634898000,
"checked_at": 1589634898000,
"content_type": "text/html;charset=utf-8",
"countries_id": "US",
"created_at": 1589634898000,
"domain_type": "SOCIAL_NETWORK",
"fav": "USER_STARRED",
"file": "2020/5/16/10712044.html",
"followedUp": false,
"history": [],
"id": 10712044,
"issued": false,
"labels": [
{
"id": 1306,
"name": "Confidential",
"type": "MODULE_LABEL"
},
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
},
{
"id": 205,
"name": "TopScribdDocsSearch",
"type": "MODULE_LABEL"
}
],
"language_id": "en",
"read": false,
"retweet_info": [],
"searchPhrase": "falabella.com.pe",
"search_words": [
"falabella.com.pe"
],
"title": "TOTUS SEDE SJM FINAL.doc | Internet Protocols | Transmission Control Protocol",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://www.scribd.com/document/461608373",
"user_rating": 3
},
{
"analysis_calc_result": "POSITIVE",
"analysis_result": "POSITIVE",
"changed_at": 1589634865000,
"checked_at": 1589634865000,
"content_type": "text/html;charset=utf-8",
"countries_id": "US",
"created_at": 1589634865000,
"domain_type": "SOCIAL_NETWORK",
"fav": "NOT_STARRED",
"file": "2020/5/16/10712019.html",
"followedUp": false,
"history": [],
"id": 10712019,
"issued": false,
"labels": [
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
},
{
"id": 205,
"name": "TopScribdDocsSearch",
"type": "MODULE_LABEL"
}
],
"language_id": "en",
"read": false,
"retweet_info": [],
"searchPhrase": "falabella.com",
"search_words": [
"falabella.com"
],
"title": "CASO FALABELLA | America latina | Marketing",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://www.scribd.com/document/461631347",
"user_rating": 0
},
{
"analysis_calc_result": "POSITIVE",
"analysis_result": "POSITIVE",
"changed_at": 1589634865000,
"checked_at": 1589634865000,
"content_type": "text/html;charset=utf-8",
"countries_id": "US",
"created_at": 1589634865000,
"domain_type": "SOCIAL_NETWORK",
"fav": "NOT_STARRED",
"file": "2020/5/16/10712020.html",
"followedUp": false,
"history": [],
"id": 10712020,
"issued": false,
"labels": [
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
},
{
"id": 205,
"name": "TopScribdDocsSearch",
"type": "MODULE_LABEL"
}
],
"language_id": "en",
"read": false,
"retweet_info": [],
"searchPhrase": "falabella.com",
"search_words": [
"falabella.com"
],
"title": "tipos de Ventas ejemplos.docx",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://www.scribd.com/document/461606657",
"user_rating": 0
},
{
"analysis_calc_result": "INFORMATIVE",
"analysis_result": "INFORMATIVE",
"changed_at": 1589633157000,
"checked_at": 1589633157000,
"content_type": "text/html",
"countries_id": "GB",
"created_at": 1589633157000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711255,
"issued": false,
"labels": [
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
},
{
"id": 1864,
"name": "VDocumentsSite",
"type": "MODULE_LABEL"
}
],
"language_id": "pt",
"read": false,
"retweet_info": [],
"searchPhrase": "linio",
"search_words": [
"linio"
],
"title": "T\u0623\u2030RMINOS Y CONDICIONES - LINIO MARKETPLACE PREMIUM amp;Cs/20190501_T\u0622\u00a0 asociados (ejemplo: seguro,",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://vdocuments.site/trminos-y-condiciones-linio-marketplace-premium-ampcs20190501t-asociados.html",
"user_rating": 0
},
{
"analysis_calc_result": "INFORMATIVE",
"analysis_result": "INFORMATIVE",
"changed_at": 1589633149000,
"checked_at": 1589633149000,
"content_type": "text/html",
"countries_id": "IN",
"created_at": 1589633149000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711254,
"issued": false,
"labels": [
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
},
{
"id": 1863,
"name": "VDocumentsMX",
"type": "MODULE_LABEL"
}
],
"language_id": "pt",
"read": false,
"retweet_info": [],
"searchPhrase": "linio",
"search_words": [
"linio"
],
"title": "T\u0623\u2030RMINOS Y CONDICIONES - LINIO MARKETPLACE PREMIUM amp;Cs/20190501_T\u0622\u00a0 asociados (ejemplo: seguro,",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://vdocuments.mx/trminos-y-condiciones-linio-marketplace-premium-ampcs20190501t-asociados.html",
"user_rating": 0
},
{
"analysis_calc_result": "INFORMATIVE",
"analysis_result": "INFORMATIVE",
"changed_at": 1589633137000,
"checked_at": 1589633137000,
"content_type": "text/html",
"countries_id": "DE",
"created_at": 1589633137000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711253,
"issued": false,
"labels": [
{
"id": 1862,
"name": "FDocumentsWorld",
"type": "MODULE_LABEL"
},
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
}
],
"language_id": "pt",
"read": false,
"retweet_info": [],
"searchPhrase": "linio",
"search_words": [
"linio"
],
"title": "T\u0623\u2030RMINOS Y CONDICIONES - LINIO MARKETPLACE PREMIUM amp;Cs/20190501_T\u0622\u00a0 asociados (ejemplo: seguro,",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://fdocuments.net/document/trminos-y-condiciones-linio-marketplace-premium-ampcs20190501t-asociados.html",
"user_rating": 0
},
{
"analysis_calc_result": "POSITIVE",
"analysis_result": "POSITIVE",
"changed_at": 1589633026000,
"checked_at": 1589633026000,
"content_type": "text/html",
"countries_id": "DE",
"created_at": 1589633026000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711233,
"issued": false,
"labels": [
{
"id": 1861,
"name": "FDocumentsSpain",
"type": "MODULE_LABEL"
},
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
}
],
"language_id": "es",
"read": false,
"retweet_info": [],
"searchPhrase": "sodimac",
"search_words": [
"sodimac"
],
"title": "Sodimac Chile 18.151 trabajadores 617.398 horas destinadas a capacitaci\u0623\u00b3n en 2017. ... productividad",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://fdocuments.es/document/sodimac-chile-18151-trabajadores-617398-horas-destinadas-a-capacitacin-en-2017.html",
"user_rating": 0
},
{
"analysis_calc_result": "INFORMATIVE",
"analysis_result": "INFORMATIVE",
"changed_at": 1589633026000,
"checked_at": 1589633026000,
"content_type": "text/html",
"countries_id": "DE",
"created_at": 1589633026000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711234,
"issued": false,
"labels": [
{
"id": 1861,
"name": "FDocumentsSpain",
"type": "MODULE_LABEL"
},
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
}
],
"language_id": "es",
"read": false,
"retweet_info": [],
"searchPhrase": "sodimac",
"search_words": [
"sodimac"
],
"title": "Emisi\u0623\u00b3n de Bonos Ordinarios Fuente: Organizaci\u0623\u00b3n Corona y Sodimac Corporativo, 1Capital IQ Agosto",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://fdocuments.es/document/emisin-de-bonos-ordinarios-fuente-organizacin-corona-y-sodimac-corporativo.html",
"user_rating": 0
},
{
"analysis_calc_result": "POSITIVE",
"analysis_result": "POSITIVE",
"changed_at": 1589633026000,
"checked_at": 1589633026000,
"content_type": "text/html",
"countries_id": "DE",
"created_at": 1589633026000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711235,
"issued": false,
"labels": [
{
"id": 1861,
"name": "FDocumentsSpain",
"type": "MODULE_LABEL"
},
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
}
],
"language_id": "es",
"read": false,
"retweet_info": [],
"searchPhrase": "sodimac",
"search_words": [
"sodimac"
],
"title": "SODIMAC COLOMBIA S.A. - ?\u00b7 empresas emisoras de valores, lo que nos conlleva a presentar a consideraci\u00f3n\u2026",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://fdocuments.es/document/sodimac-colombia-sa-empresas-emisoras-de-valores-lo-que-nos-conlleva-a.html",
"user_rating": 0
},
{
"analysis_calc_result": "INFORMATIVE",
"analysis_result": "INFORMATIVE",
"changed_at": 1589633026000,
"checked_at": 1589633026000,
"content_type": "text/html",
"countries_id": "DE",
"created_at": 1589633026000,
"domain_type": "UNKNOWN",
"fav": "NOT_STARRED",
"followedUp": false,
"history": [],
"id": 10711236,
"issued": false,
"labels": [
{
"id": 1861,
"name": "FDocumentsSpain",
"type": "MODULE_LABEL"
},
{
"id": 1305,
"name": "Public",
"type": "MODULE_LABEL"
}
],
"language_id": "es",
"read": false,
"retweet_info": [],
"searchPhrase": "sodimac",
"search_words": [
"sodimac"
],
"title": "Programa SCM Update ?\u00b7 en Sodimac. Mauri Mu\u00f1oz log\u00edstica en Cl\u00ednica Alemana. L\u00eda Vera\u2026",
"tlpStatus": "AMBER",
"total_retweets": 0,
"url": "https://fdocuments.es/document/programa-scm-update-en-sodimac-mauricio-munoz-jefe-de-logistica-en-clinica.html",
"user_rating": 0
}
]
}
}
Human Readable Output
Blueliv DataLeakage info
analysis_calc_result analysis_result analysis_user_result changed_at checked_at content_type countries_id created_at domain_type fav file followedUp history id issued labels language_id read retweet_info searchPhrase search_words title tlpStatus total_retweets url user_rating POSITIVE POSITIVE POSITIVE 1589634898000 1589634898000 text/html;charset=utf-8 US 1589634898000 SOCIAL_NETWORK USER_STARRED 2020/5/16/10712044.html false 10712044 false {‘id’: 1306, ‘name’: ‘Confidential’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 205, ‘name’: ‘TopScribdDocsSearch’, ‘type’: ‘MODULE_LABEL’}en false falabella.com.pe falabella.com.pe TOTUS SEDE SJM FINAL.doc | Internet Protocols | Transmission Control Protocol AMBER 0 https://www.scribd.com/document/461608373 3 POSITIVE POSITIVE 1589634865000 1589634865000 text/html;charset=utf-8 US 1589634865000 SOCIAL_NETWORK NOT_STARRED 2020/5/16/10712019.html false 10712019 false {‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 205, ‘name’: ‘TopScribdDocsSearch’, ‘type’: ‘MODULE_LABEL’}en false falabella.com falabella.com CASO FALABELLA | America latina | Marketing AMBER 0 https://www.scribd.com/document/461631347 0 POSITIVE POSITIVE 1589634865000 1589634865000 text/html;charset=utf-8 US 1589634865000 SOCIAL_NETWORK NOT_STARRED 2020/5/16/10712020.html false 10712020 false {‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 205, ‘name’: ‘TopScribdDocsSearch’, ‘type’: ‘MODULE_LABEL’}en false falabella.com falabella.com tipos de Ventas ejemplos.docx AMBER 0 https://www.scribd.com/document/461606657 0 INFORMATIVE INFORMATIVE 1589633157000 1589633157000 text/html GB 1589633157000 UNKNOWN NOT_STARRED false 10711255 false {‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1864, ‘name’: ‘VDocumentsSite’, ‘type’: ‘MODULE_LABEL’}pt false linio linio Tأ‰RMINOS Y CONDICIONES - LINIO MARKETPLACE PREMIUM amp;Cs/20190501_Tآ asociados (ejemplo: seguro, AMBER 0 https://vdocuments.site/trminos-y-condiciones-linio-marketplace-premium-ampcs20190501t-asociados.html 0 INFORMATIVE INFORMATIVE 1589633149000 1589633149000 text/html IN 1589633149000 UNKNOWN NOT_STARRED false 10711254 false {‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1863, ‘name’: ‘VDocumentsMX’, ‘type’: ‘MODULE_LABEL’}pt false linio linio Tأ‰RMINOS Y CONDICIONES - LINIO MARKETPLACE PREMIUM amp;Cs/20190501_Tآ asociados (ejemplo: seguro, AMBER 0 https://vdocuments.mx/trminos-y-condiciones-linio-marketplace-premium-ampcs20190501t-asociados.html 0 INFORMATIVE INFORMATIVE 1589633137000 1589633137000 text/html DE 1589633137000 UNKNOWN NOT_STARRED false 10711253 false {‘id’: 1862, ‘name’: ‘FDocumentsWorld’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’}pt false linio linio Tأ‰RMINOS Y CONDICIONES - LINIO MARKETPLACE PREMIUM amp;Cs/20190501_Tآ asociados (ejemplo: seguro, AMBER 0 https://fdocuments.net/document/trminos-y-condiciones-linio-marketplace-premium-ampcs20190501t-asociados.html 0 POSITIVE POSITIVE 1589633026000 1589633026000 text/html DE 1589633026000 UNKNOWN NOT_STARRED false 10711233 false {‘id’: 1861, ‘name’: ‘FDocumentsSpain’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’}es false sodimac sodimac Sodimac Chile 18.151 trabajadores 617.398 horas destinadas a capacitaciأ³n en 2017. … productividad AMBER 0 https://fdocuments.es/document/sodimac-chile-18151-trabajadores-617398-horas-destinadas-a-capacitacin-en-2017.html 0 INFORMATIVE INFORMATIVE 1589633026000 1589633026000 text/html DE 1589633026000 UNKNOWN NOT_STARRED false 10711234 false {‘id’: 1861, ‘name’: ‘FDocumentsSpain’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’}es false sodimac sodimac Emisiأ³n de Bonos Ordinarios Fuente: Organizaciأ³n Corona y Sodimac Corporativo, 1Capital IQ Agosto AMBER 0 https://fdocuments.es/document/emisin-de-bonos-ordinarios-fuente-organizacin-corona-y-sodimac-corporativo.html 0 POSITIVE POSITIVE 1589633026000 1589633026000 text/html DE 1589633026000 UNKNOWN NOT_STARRED false 10711235 false {‘id’: 1861, ‘name’: ‘FDocumentsSpain’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’}es false sodimac sodimac SODIMAC COLOMBIA S.A. - ?· empresas emisoras de valores, lo que nos conlleva a presentar a consideración… AMBER 0 https://fdocuments.es/document/sodimac-colombia-sa-empresas-emisoras-de-valores-lo-que-nos-conlleva-a.html 0 INFORMATIVE INFORMATIVE 1589633026000 1589633026000 text/html DE 1589633026000 UNKNOWN NOT_STARRED false 10711236 false {‘id’: 1861, ‘name’: ‘FDocumentsSpain’, ‘type’: ‘MODULE_LABEL’},
{‘id’: 1305, ‘name’: ‘Public’, ‘type’: ‘MODULE_LABEL’}es false sodimac sodimac Programa SCM Update ?· en Sodimac. Maur Muñoz logística en Clínica Alemana. Lía Vera… AMBER 0 https://fdocuments.es/document/programa-scm-update-en-sodimac-mauricio-munoz-jefe-de-logistica-en-clinica.html 0
blueliv-resource-search
Search for a specific resource.
Base Command
blueliv-resource-search
Input
| Argument Name | Description | Required |
|---|---|---|
| search | Keywords to search in resources text | Optional |
| status | Comma-separated list of any combination of status: NOT_AVAILABLE, NOT_IMPORTANT, NOT_PROCESSABLE, POSITIVE, NEGATIVE, INFORMATIVE, IMPORTANT | Optional |
| startDate | Minimum date to recover resources. Formats: yyyy-mm-dd or yyyy-mm-ddThh:mm:ss | Optional |
| finalDate | Maximum date to recover resources. Formats: yyyy-mm-dd or yyyy-mm-ddThh:mm:ss | Optional |
| read | What results read status to get. | Optional |
| limit | Maximum number of resources to recover | Optional |
| page | Results page to get. For each page, there are {limit} resources. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| BluelivThreatCompass | Unknown | List object of recovered resources |
Command Example
#### Human Readable Output
### blueliv-resource-search-by-id
***
Recovers all the information of a given resource
#### Base Command
`blueliv-resource-search-by-id`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| id | Resource ID | Required |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| BluelivThreatCompass | Unknown | Object with the information of the recovered resource |
#### Command Example
```!blueliv-resource-search-by-id id=10712044```
#### Context Example
```
{
"BluelivThreatCompass": {
"DataLeakage": {
"analysis_calc_result": "POSITIVE",
"analysis_result": "POSITIVE",
"analysis_user_result": "POSITIVE",
"changed_at": 1589634898000,
"checked_at": 1589634898000,
"content_type": "text/html;charset=utf-8",
"countries_id": "US",
"created_at": 1589634898000,
"domain_type": "SOCIAL_NETWORK",
"fav": "USER_STARRED",
"file": "2020/5/16/10712044.html",
"followedUp": false,
"history": [],
"id": 10712044,
"issued": false,
"labels": [
{
"id": 1306,
"name": "Confidential",
"type": "GLOBAL"
},
{
"id": 1305,
"name": "Public",
"type": "GLOBAL"
},
{
"id": 205,
"name": "TopScribdDocsSearch",
"type": "GLOBAL"
}
],
"language_id": "en",
"read": false,
"retweet_info": [],
"searchPhrase": "falabella.com.pe",
"search_words": [
"falabella.com.pe"
],
"title": "TOTUS SEDE SJM FINAL.doc | Internet Protocols | Transmission Control Protocol",
"tlpStatus": "AMBER",
"total_retweets": 0,
"transform": "TopScribdDocsSearch",
"url": "https://www.scribd.com/document/461608373",
"user_rating": 3
}
}
}
```
#### Human Readable Output
>### Blueliv DataLeakageinfo
>
>|analysis_calc_result|analysis_result|analysis_user_result|changed_at|checked_at|content_type|countries_id|created_at|domain_type|fav|file|followedUp|history|id|issued|labels|language_id|read|retweet_info|searchPhrase|search_words|title|tlpStatus|total_retweets|transform|url|user_rating|
>|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
>| POSITIVE | POSITIVE | POSITIVE | 1589634898000 | 1589634898000 | text/html;charset=utf-8 | US | 1589634898000 | SOCIAL_NETWORK | USER_STARRED | 2020/5/16/10712044.html | false | | 10712044 | false | {'id': 1306, 'name': 'Confidential', 'type': 'GLOBAL'},<br/>{'id': 1305, 'name': 'Public', 'type': 'GLOBAL'},<br/>{'id': 205, 'name': 'TopScribdDocsSearch', 'type': 'GLOBAL'} | en | false | | falabella.com.pe | falabella.com.pe | TOTUS SEDE SJM FINAL.doc \| Internet Protocols \| Transmission Control Protocol | AMBER | 0 | TopScribdDocsSearch | https://www.scribd.com/document/461608373 | 3 |
### blueliv-resource-set-status
***
Changes a resource status.
#### Base Command
`blueliv-resource-set-status`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| id | Resource ID | Required |
| status | New status to assign to the resource | Required |
#### Context Output
There is no context output for this command.
#### Command Example
```!blueliv-resource-set-status id=10712044 status=positive```
#### Context Example
```
{}
```
#### Human Readable Output
>Status changed to **positive**
### blueliv-resource-set-label
***
Adds a label to the given resource
#### Base Command
`blueliv-resource-set-label`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| id | Resource ID | Required |
| labelId | Label ID | Required |
#### Context Output
There is no context output for this command.
#### Command Example
Human Readable Output
blueliv-resource-set-read-status
Mark the result as read or not.
Base Command
blueliv-resource-set-read-status
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Resource ID | Required |
| read | The read status to set. | Optional |
Context Output
There is no context output for this command.
Command Example
!blueliv-resource-set-read-status id=10712044 read=false
Context Example
{}
Human Readable Output
Read status changed to false.
blueliv-resource-assign-rating
Assign tating to a given result.
Base Command
blueliv-resource-assign-rating
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Resource ID | Required |
| rating | Rating to assign to the result. | Optional |
Context Output
There is no context output for this command.
Command Example
!blueliv-resource-assign-rating id=10712044 rating=3
Context Example
{}
Human Readable Output
Rating changed to 3.
blueliv-resource-fav
Changes the favourite status of a resource.
Base Command
blueliv-resource-fav
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Resource ID | Required |
| fav | The new fav status of the resource. Can be applied to the user, group or general. | Optional |
Context Output
There is no context output for this command.
Command Example
!blueliv-resource-fav id=10712044 fav=User
Context Example
{}
Human Readable Output
Resource fav masked as User correctly.
blueliv-resource-set-tlp
Sets a new TLP status to a given resource.
Base Command
blueliv-resource-set-tlp
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Resource ID | Required |
| tlp | The new TLP to assign. | Optional |
Context Output
There is no context output for this command.
Command Example
``````
Human Readable Output
blueliv-resource-favourite
Changes the favorite status of a resource.
Base Command
blueliv-resource-favourite
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Resource ID. | Required |
| favourite | The new favorite status of the resource. Can be “Not”, “User”, “Group”, or “All”. Possible values are: Not, User, Group, All. Default is group. | Optional |
Context Output
There is no context output for this command.
blueliv-module-get-labels
Gets the label list of the module.
Base Command
blueliv-module-get-labels
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| BluelivThreatCompass.Label.BackgroundColor | String | Hexadecimal color of the label background in the GUI. |
| BluelivThreatCompass.Label.Id | String | Label ID. |
| BluelivThreatCompass.Label.Name | String | Label name. |
| BluelivThreatCompass.Label.Protected | Boolean | Whether the label is protected. |
| BluelivThreatCompass.Label.TypeId | Number | Label type ID. |
| BluelivThreatCompass.Label.TypeName | String | Label type name |
| BluelivThreatCompass.Label.Prioritized | Boolean | Whether the label is prioritized. |
| BluelivThreatCompass.Label.TextColor | String | Hexadecimal color of the label text in the GUI. |
Configuration parameters
url— Server URL (e.g. https://demisto.blueliv.com/api/v2)credentials— Usernameorganization— Organization ID (required)type— Module Type (required)module— Module ID (required)unsecure— Trust any certificate (not secure)proxy— Use system proxy settingsisFetch— Fetch incidentsincidentType— Incident typeincidentFetchInterval— Incidents Fetch Intervalfetch_limit— Fetch Limit (Max.- 200, Recommended less than 50)fetch_status— Fetch resource status (POSITIVE, NEGATIVE...)first_fetch_time— First fetch time
Commands (10)
-
blueliv-module-get-labelsGets the label list of the module.
-
blueliv-resource-allRecovers all resources from the module.
-
blueliv-resource-assign-ratingAssigns a rating to the given result.
-
blueliv-resource-favouriteChanges the favorite status of a resource.
-
blueliv-resource-searchSearch for a specific resource.
-
blueliv-resource-search-by-idRecovers all the information of a given resource.
-
blueliv-resource-set-labelAdds a label to the given resource.
-
blueliv-resource-set-read-statusMarks the result as read or not read.
-
blueliv-resource-set-statusChanges the status of a resource.
-
blueliv-resource-set-tlpSets a new TLP (Traffic Light Protocol) status to a given resource.
import demistomock as demisto # noqa: F401 from CommonServerPython import * # noqa: F401 """ IMPORTS """ import json from datetime import datetime, timedelta import urllib3 from dateutil.parser import parse from CommonServerUserPython import * """ PARAM DEFINITION """ MAX_RESOURCES = 100 STATUS_VALUES = ["NOT_AVAILABLE", "NOT_IMPORTANT", "NOT_PROCESSABLE", "POSITIVE", "NEGATIVE", "INFORMATIVE", "IMPORTANT"] MODULES = { "Hacktivism": "hacktivism", "MobileApps": "mobile_apps", "Credentials": "credentials", "DarkWeb": "dark_web", "MediaTracker": "media_tracker", "Malware": "malware", "DomainProtection": "domain_protection", "DataLeakage": "data_leakage", "CreditCards": "credit_card", } """FETCH PARAMETERS""" BLUELIV_TIME_FORMAT = "%Y-%m-%dT%H:%M:%S" class Client(BaseClient): def __init__( self, base_url, verify=True, proxy=False, ok_codes=(), headers=None, auth=None, organization=0, module=0, module_type="" ): BaseClient.__init__(self, base_url, verify=verify, proxy=proxy, ok_codes=ok_codes, headers=headers, auth=auth) self.module_type = module_type self._organization = organization self._module = module self._module_url = f"/organization/{organization}/module/{module}/{MODULES[module_type]}" def authenticate(self, username: str, password: str): body = {"username": username, "password": password} res = self._http_request(method="POST", url_suffix="/auth", json_data=body) self._headers = {"Content-Type": "application/json", "x-cookie": str(res.get("token"))} return str(res.get("token")) def resource_select(self, args): params = create_search_query(args) path = "/resource" res = self._http_request(method="GET", url_suffix=self._module_url + path, params=params) return res def resource_get(self, args): resource_id = args.get("id", "") path = f"/resource/{resource_id}" res = self._http_request(method="GET", url_suffix=self._module_url + path) return res def module_get_labels(self): path = "/resource/label" res = self._http_request(method="GET", url_suffix=self._module_url + path) return res def resource_label(self, args): path = "/resource/label" body = {"label": args.get("labelId", 0), "resources": [str(args.get("id", 0))]} res = self._http_request(method="PUT", url_suffix=self._module_url + path, json_data=body) return res def resource_user_result(self, args): resource_id = args.get("id", "") user_result = args.get("status", "") path = f"/resource/{resource_id}/userResult/{user_result}" res = self._http_request(method="PUT", url_suffix=self._module_url + path) return res def resource_set_tlp(self, args): resource_id = args.get("id", "") tlp = args.get("tlp", "") path = f"/resource/{resource_id}/tlpStatus/{tlp.upper()}" res = self._http_request(method="PUT", url_suffix=self._module_url + path) return res def resource_read_result(self, args): resource_id = args.get("id", 0) read_result = args.get("read", "true") read_result = read_result == "true" data = {"resources": [resource_id], "read": read_result} path = "/resource/markAs" res = self._http_request(method="PUT", url_suffix=self._module_url + path, json_data=data) return res def resource_fav(self, args): resource_id = args.get("id", 0) fav = args.get("favourite", "group") fav = fav + "_STARRED" data = {"resource": resource_id, "status": fav.upper()} path = "/resource/fav" res = self._http_request(method="PUT", url_suffix=self._module_url + path, json_data=data) return res def resource_rating(self, args): resource_id = args.get("id", 0) read_result = args.get("rating", "1") data = {"resource": resource_id, "rate": read_result} path = "/resource/rating" res = self._http_request(method="PUT", url_suffix=self._module_url + path, json_data=data) return res def test_module_connection(self): path = "/resource/total" res = self._http_request(method="GET", url_suffix=self._module_url + path) return res def create_search_query(args): params = {} # Pagination limit = int(args.get("limit", MAX_RESOURCES)) limit = min(limit, MAX_RESOURCES) page = int(args.get("page", 1)) if int(args.get("page", 0)) != 0 else 1 params["page"] = str(page) params["maxRows"] = str(limit) # Time filter ini_date = args.get("iniDate", "") fin_date = args.get("finDate", "") params["o"] = args.get("order", "id,ASC") params["granularity"] = "DAY" if fin_date: params["to"] = blueliv_date_to_timestamp(fin_date) if ini_date: params["since"] = blueliv_date_to_timestamp(ini_date) # Search parameters if "read" in args and args["read"].lower() in ["both", "read", "unread"]: number = {"both": "0", "read": "1", "unread": "2"} params["read"] = number[args["read"].lower()] if "search" in args: params["q"] = args["search"] if "since" in args: params["since"] = args["since"] if "to" in args: params["to"] = args["to"] if "rows" in args: params["maxRows"] = args["rows"] if "page" in args: params["page"] = args["page"] if "status" in args and all(status in STATUS_VALUES for status in args["status"].split(",")): params["analysisCalcResult"] = args["status"] return params # This function return false when there are no results to display def not_found(): return_results( { "ContentsFormat": formats["json"], "Type": entryTypes["note"], "Contents": "No results found.", "EntryContext": {"BluelivThreatCompass": {}}, } ) # Possible inputs dateTime: yyyy-mm-dd / yyyy-mm-ddThh:mm:ss / yyyy-mm-dd hh:mm:ss def blueliv_date_to_timestamp(now): if "/" in now: now = now.replace("/", "-") try: if "T" in now: str_date = datetime.strptime(now, "%Y-%m-%dT%H:%M:%S") elif len(now) == 10: now = now + "T00:00:00" str_date = datetime.strptime(now, "%Y-%m-%dT%H:%M:%S") elif " " in now and len(now) == 19: now = now.replace(" ", "T") str_date = datetime.strptime(now, "%Y-%m-%dT%H:%M:%S") else: now = datetime.now() now = str(now).replace(" ", "T") str_date = datetime.strptime(now, "%Y-%m-%dT%H:%M:%S") except ValueError: now = datetime.now() now = str(now).replace(" ", "T") str_date = datetime.strptime(now, "%Y-%m-%dT%H:%M:%S") timestamp = str(datetime.timestamp(str_date)) if "." in timestamp: timestamp = timestamp.split(".")[0] if len(timestamp) == 10: timestamp = timestamp + "000" return int(timestamp) def parse_resource(result): # Labels labels = [] for lbl in result.get("labels", []): label = {"id": lbl.get("id"), "name": lbl.get("name"), "type": lbl.get("type")} labels.append(label) result["labels"] = labels if "module_id" in result: del result["module_id"] if "module_name" in result: del result["module_name"] if "module_short_name" in result: del result["module_short_name"] if "module_type" in result: del result["module_type"] return result def parse_label(result): labels = [] for label in result: labels.append( { "BackgroundColor": label["bgColorHex"], "Id": label["id"], "Name": label["label"], "Protected": label["labelProtected"], "TypeId": label["labelTypeId"], "TypeName": label["labelTypeName"], "Prioritized": label["prioritized"], "TextColor": label["textColorHex"], } ) return labels def get_all_resources(client: Client, args): result = client.resource_select(args) total_resources = result["total_resources"] if total_resources > 0: resources_array = [] for r in result["list"]: resource = parse_resource(r) resources_array.append(resource) return_results( { "ContentsFormat": formats["json"], "Type": entryTypes["note"], "Contents": resources_array, "ReadableContentsFormat": formats["markdown"], "HumanReadable": tableToMarkdown("Blueliv " + client.module_type + " info", resources_array), "EntryContext": {"BluelivThreatCompass." + client.module_type + "(val.id && val.id == obj.id)": resources_array}, } ) else: not_found() def set_resource_read_status(client: Client, args): client.resource_read_result(args) return_results( { "ContentsFormat": formats["text"], "Type": entryTypes["note"], "Contents": "Read status changed to {}.".format(args.get("read", 0)), "ReadableContentsFormat": formats["markdown"], "HumanReadable": "Read status changed to **{}**.".format(args.get("read", 0)), } ) def set_resource_rating(client: Client, args): client.resource_rating(args) return_results( { "ContentsFormat": formats["text"], "Type": entryTypes["note"], "Contents": "Rating changed to {}.".format(args.get("rating", 0)), "ReadableContentsFormat": formats["markdown"], "HumanReadable": "Rating changed to **{}**.".format(args.get("rating", 0)), } ) def get_resources_fetch(client: Client, ini_date, limit, status): args = {"limit": limit, "since": ini_date, "status": status} result = client.resource_select(args) total_resources = result["total_resources"] if total_resources > 0: return result["list"] else: return [] def fetch_incidents(client: Client, last_run, first_fetch_time, fetch_limit, fetch_status): last_fetch = last_run.get("last_fetch", None) if last_fetch is None: if first_fetch_time: last_fetch = blueliv_date_to_timestamp(first_fetch_time) else: last_fetch = int(datetime.now().timestamp()) * 1000 # convert the events to demisto incident events = get_resources_fetch(client, last_fetch, fetch_limit, fetch_status) incidents = [] for e in events: incident = { "name": e.get("title", ""), # name is required field, must be set "occurred": timestamp_to_datestring(e.get("created_at", int(time.time()) * 1000)), # needs ISO8601 "rawJSON": json.dumps(e), # the original event } incidents.append(incident) if incidents: last_fetch = parse(incidents[-1]["occurred"]) + timedelta(seconds=1) # add 1 second for the next fetch demisto.setLastRun( { "last_fetch": int(last_fetch.timestamp()) * 1000 # Save in milliseconds } ) return incidents def search_resource(client: Client, args): result = client.resource_select(args) total_resources = result["total_resources"] if total_resources > 0: resource = parse_resource(result) return_results( { "ContentsFormat": formats["json"], "Type": entryTypes["note"], "Contents": resource["list"], "ReadableContentsFormat": formats["markdown"], "HumanReadable": tableToMarkdown("Blueliv " + client.module_type + " info", resource), "EntryContext": {"BluelivThreatCompass." + client.module_type + "(val.id && val.id == obj.id)": resource["list"]}, } ) else: not_found() def search_resource_by_id(client: Client, args): result = client.resource_get(args) resource = parse_resource(result) if demisto.get(resource, "id"): return_results( { "ContentsFormat": formats["json"], "Type": entryTypes["note"], "Contents": resource, "ReadableContentsFormat": formats["markdown"], "HumanReadable": tableToMarkdown("Blueliv " + client.module_type + " info", resource), "EntryContext": {"BluelivThreatCompass." + client.module_type + "(val.id && val.id == obj.id)": resource}, } ) else: not_found() def resource_set_tlp(client: Client, args): client.resource_set_tlp(args) return_results( { "ContentsFormat": formats["text"], "Type": entryTypes["note"], "Contents": "TLP changed to {}.".format(args.get("tlp")), "ReadableContentsFormat": formats["markdown"], "HumanReadable": "TLP changed to **{}**".format(args.get("tlp")), } ) def set_resource_status(client: Client, args): client.resource_user_result(args) return_results( { "ContentsFormat": formats["text"], "Type": entryTypes["note"], "Contents": "Status changed to {}.".format(args.get("status")), "ReadableContentsFormat": formats["markdown"], "HumanReadable": "Status changed to **{}**".format(args.get("status")), } ) def resource_add_label(client: Client, args): client.resource_label(args) return_results( { "ContentsFormat": formats["text"], "Type": entryTypes["note"], "Contents": "Label {} correctly added.".format(args.get("labelId", 0)), "ReadableContentsFormat": formats["markdown"], "HumanReadable": "Label **{}** correctly added.".format(args.get("labelId", 0)), } ) def resource_fav(client: Client, args): client.resource_fav(args) return_results( { "ContentsFormat": formats["text"], "Type": entryTypes["note"], "Contents": "Resource favourite masked as {} correctly.".format(args.get("favourite", "group")), "ReadableContentsFormat": formats["markdown"], "HumanReadable": "Resource favourite masked as **{}** correctly.".format(args.get("favourite", "group")), } ) def module_get_labels(client: Client): res = client.module_get_labels() label_array = parse_label(res) return_results( { "ContentsFormat": formats["json"], "Type": entryTypes["note"], "Contents": res, "ReadableContentsFormat": formats["markdown"], "HumanReadable": tableToMarkdown("Blueliv " + client.module_type + " labels", label_array), "EntryContext": {"BluelivThreatCompass.Label(val.Id && val.Id == obj.Id)": label_array}, } ) def test_module(client: Client): try: res = client.test_module_connection() if "total_resources" not in res: return_error(message="Error connecting to module.") except DemistoException as exception: return_error( message="Error connecting to module.\nPlease check that organization ID, " + "module ID and module type matches.", error=exception, ) # DEMISTO command evaluation def main(): urllib3.disable_warnings() params = demisto.params() server_url = params.get("url").rstrip("/") verify_ssl = not params.get("unsecure", False) proxy = params.get("proxy") username = params["credentials"]["identifier"] password = params["credentials"]["password"] organization = params.get("organization", 0) module = params.get("module", 0) module_type = params.get("type", 0) client = Client( server_url, verify_ssl, proxy, headers={"Accept": "application/json"}, organization=organization, module=module, module_type=module_type, ) client.authenticate(username, password) args = demisto.args() if demisto.command() == "test-module": # Checks if the user is correctly authenticated and organization, module & module_type are correct test_module(client) return_results("ok") elif demisto.command() == "fetch-incidents": last_run = demisto.getLastRun() first_fetch_time = demisto.params().get("first_fetch_time", None) fetch_limit = max(min(200, int(demisto.params().get("fetch_limit"))), 1) fetch_status = demisto.params().get("fetch_status") fetch_status = ",".join(fetch_status) incidents = fetch_incidents(client, last_run, first_fetch_time, fetch_limit, fetch_status) demisto.incidents(incidents) elif demisto.command() == "blueliv-resource-search": search_resource(client, args) elif demisto.command() == "blueliv-resource-search-by-id": search_resource_by_id(client, args) elif demisto.command() == "blueliv-resource-set-status": set_resource_status(client, args) elif demisto.command() == "blueliv-resource-set-label": resource_add_label(client, args) elif demisto.command() == "blueliv-resource-all": get_all_resources(client, args) elif demisto.command() == "blueliv-resource-set-read-status": set_resource_read_status(client, args) elif demisto.command() == "blueliv-resource-assign-rating": set_resource_rating(client, args) elif demisto.command() == "blueliv-resource-favourite": resource_fav(client, args) elif demisto.command() == "blueliv-resource-set-tlp": resource_set_tlp(client, args) elif demisto.command() == "blueliv-module-get-labels": module_get_labels(client) if __name__ in ("__main__", "__builtin__", "builtins"): main()