checkpointdome9
Dome9 integration allows to easily manage the security and compliance of the public cloud.
Network Security · Check Point Dome9 (CloudGuard)
Details
| ID | checkpointdome9 |
|---|---|
| Provider | CheckPoint Software Technologies |
| Category | Network Security |
| From Version | 6.2.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Dome9 integration allows to easily manage the security and compliance of the public cloud.
This integration was integrated and tested with version 2 of checkpointdome9
Configure Check Point Dome9 (CloudGuard) in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL | True | |
| API key ID | True | |
| API key secret | True | |
| Use system proxy settings | False | |
| Trust any certificate (not secure) | False | |
| Maximum incidents for one fetch. | Maximum number of incidents per fetch. Default is 50. The maximum is 100. | False |
| Fetch incidents | False | |
| Alert region (AWS) to fetch as incidents. | False | |
| Alert severity to fetch as incidents. | False | |
| First fetch time | First alert created date to fetch. e.g., “1 min ago”,”2 weeks ago”,”3 months ago” | False |
| Incident type | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
dome9-access-lease-list
Get a list of all active Access Leases.
Base Command
dome9-access-lease-list
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.AccessLease.cloudAccountId | String | The AWS Access Leases cloud account ID. |
| CheckPointDome9.AccessLease.region | String | The AWS Access Leases region. |
| CheckPointDome9.AccessLease.securityGroupId | String | The AWS Access Leases security group ID. |
| CheckPointDome9.AccessLease.created | String | The AWS Access Leases created date. |
| CheckPointDome9.AccessLease.user | String | The AWS Access Leases user. |
| CheckPointDome9.AccessLease.length | String | The AWS Access Leases length. |
| CheckPointDome9.AccessLease.protocol | String | The AWS Access Leases protocol. |
| CheckPointDome9.AccessLease.id | String | The AWS Access Leases ID. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"AccessLease": [
{
"accountId": "accountId",
"cloudAccountId": "cloudAccountId",
"created": "created",
"id": "id",
"ip": "ip",
"length": "length",
"name": "name",
"note": null,
"portFrom": 0,
"portTo": 0,
"protocol": "protocol",
"region": "region",
"securityGroupId": "securityGroupId",
"srl": "srl",
"user": "user"
}
]
}
}
Human Readable Output
Access Lease
Showing 1 rows out of 1.
Id Name Ip User Region Length Created id name ip userMail region length created
dome9-access-lease-delete
Terminate an Access Lease.
Base Command
dome9-access-lease-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| lease_id | The Access Lease ID. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-access-lease-delete lease_id=id
Context Example
{
"CheckPointDome9": {
"AccessLease": ""
}
}
Human Readable Output
Access Lease Deleted successfully
dome9-access-lease-invitation-list
Get a lease invitation.
Base Command
dome9-access-lease-invitation-list
Input
| Argument Name | Description | Required |
|---|---|---|
| invitation_id | The Access Lease invitation ID. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.AccessLease.Invitation.length | String | The Access Lease invitation length. |
| CheckPointDome9.AccessLease.Invitation.id | String | The Access Lease invitation ID. |
| CheckPointDome9.AccessLease.Invitation.created | String | The Access Lease invitation created time. |
| CheckPointDome9.AccessLease.Invitation.recipientName | String | The Access Lease invitation recipient name. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"AccessLease": {
"Invitation": {
"body": null,
"created": "created",
"expirationTime": "expirationTime",
"id": "id",
"issuerName": "userMail",
"length": "length",
"notifyEmail": null,
"pivotEntity": "pivotEntity",
"recipientName": "userMail",
"serviceName": "name",
"targetSrl": "targetSrl"
}
}
}
}
Human Readable Output
Access Lease invitation
Showing 1 rows out of 1.
Id Issuername Recipientname Length Created id userMail userMail length created
dome9-access-lease-invitation-delete
Delete an Access Lease invitation.
Base Command
dome9-access-lease-invitation-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| invitation_id | Access Lease invitation. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-access-lease-invitation-delete invitation_id=invitation_id
Context Example
{
"CheckPointDome9": {
"AccessLease": {
"Invitation": ""
}
}
}
Human Readable Output
Access Lease Invitation Deleted successfully
dome9-findings-search
Search for findings in CloudGuard.
Base Command
dome9-findings-search
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| severity | The findings severities. Possible values are: High, Medium, Low. | Optional |
| region | The findings regions. Possible values are: N. Virginia, Global, Canada Central, Frankfurt, Ireland, London, Mumbai, N. California, Ohio, Oregon, Osaka, Paris, Seoul, Singapore, Stockholm, Sydney, São Paulo, Tokyo. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.Findings.id | String | The findings ID. |
| CheckPointDome9.Findings.severity | String | The severity of the findings. |
| CheckPointDome9.Findings.region | String | The findings region. |
| CheckPointDome9.Findings.status | Number | The status of the findings. |
| CheckPointDome9.Findings.action | String | The action of the findings. |
| CheckPointDome9.Findings.alertType | Number | The alert type of the findings. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"Findings": [
{
"acknowledged": false,
"action": "action",
"additionalFields": [],
"alertType": "alertType",
"bundleId": "bundleId",
"bundleName": "bundleName",
"category": "",
"cloudAccountExternalId": "cloudAccountExternalId",
"cloudAccountId": "cloudAccountId",
"cloudAccountType": "cloudAccountType",
"comments": [],
"createdTime": "createdTime",
"description": "description",
"entityDome9Id": "entityDome9Id",
"entityExternalId": "entityExternalId",
"entityName": "entityName",
"entityNetwork": null,
"entityTags": [],
"entityType": "entityType",
"entityTypeByEnvironmentType": "entityTypeByEnvironmentType",
"findingKey": "findingKey",
"id": "id",
"isExcluded": false,
"labels": [],
"lastSeenTime": "lastSeenTime",
"magellan": null,
"occurrences": [],
"organizationalUnitId": "organizationalUnitId",
"organizationalUnitPath": "",
"origin": "origin",
"ownerUserName": null,
"region": "region",
"remediation": "remediation",
"remediationActions": [],
"ruleId": "ruleId",
"ruleLogic": "ruleLogic",
"ruleName": "ruleName",
"scanId": null,
"severity": "severity",
"status": "status",
"tag": "tag",
"updatedTime": "updatedTime",
"webhookResponses": null
}
]
}
}
Human Readable Output
Findings
Showing 1 rows out of 48.
Id Alerttype Severity Region Status Action Cloudaccountid Description id alertType severity region status action Cloudaccountid Description
dome9-ip-list-create
Add a new IP list.
Base Command
dome9-ip-list-create
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The IP list name. | Required |
| description | The IP list description. | Required |
| ip | Comma-separated list of IP addresses. | Optional |
| comment | Comma-separated list of comments for the IP addresses. One comment per IP address. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.IpList.id | String | The IP list ID. |
| CheckPointDome9.IpList.name | String | The IP list name. |
| CheckPointDome9.IpList.description | String | The IP list description. |
| CheckPointDome9.IpList.items | String | The IP list items (IP addresses). |
Command example
!dome9-ip-list-create description=description2022 name=name31072022
Context Example
{
"CheckPointDome9": {
"IpList": {
"description": "description2022",
"id": "id",
"items": [],
"name": "name31072022"
}
}
}
Human Readable Output
IP list created successfully
dome9-ip-list-update
Update an IP list. This will override the existing IP list.
Base Command
dome9-ip-list-update
Input
| Argument Name | Description | Required |
|---|---|---|
| list_id | The IP list ID. | Required |
| description | The IP list description. | Optional |
| ip | Comma-separated list of IP addresses. | Optional |
| comment | Comma-separated list of comments for the IP addresses. One comment per IP address. | Optional |
| update_mode | The command mode. Default mode is add_new_items. Possible values are: add_new_items, replace_old_items. | Optional |
Context Output
There is no context output for this command.
Command example
!dome9-ip-list-update list_id=id description=NEW
Context Example
{
"CheckPointDome9": {
"IpList": ""
}
}
Human Readable Output
IP list updated successfully
dome9-ip-list-get
Get an IP List by ID.
Base Command
dome9-ip-list-get
Input
| Argument Name | Description | Required |
|---|---|---|
| list_id | The IP list ID to fetch. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.IpList.id | String | The IP list ID. |
| CheckPointDome9.IpList.name | String | The IP list name. |
| CheckPointDome9.IpList.description | String | The IP list description. |
| CheckPointDome9.IpList.items | String | The IP list items (IP addresses). |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"IpList": [
{
"description": "description",
"id": "id",
"items": [
{
"comment": "new comment",
"ip": "ip"
}
],
"name": "NewList-2"
}
]
}
}
Human Readable Output
IP list
Id Name Items Description id NewList-2 ip description
dome9-ip-list-delete
Delete an IP List by ID.
Base Command
dome9-ip-list-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| list_id | The ID of the IP list to delete. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-ip-list-delete list_id=id
Context Example
{
"CheckPointDome9": {
"IpList": ""
}
}
Human Readable Output
IP list deleted successfully
dome9-ip-list-metadata-list
Get all IP addresses metadata.
Base Command
dome9-ip-list-metadata-list
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.IpList.Metadata.id | String | The IP address internal ID. |
| CheckPointDome9.IpList.Metadata.cidr | string | The IP address CIDR. |
| CheckPointDome9.IpList.Metadata.name | String | The IP address name. |
| CheckPointDome9.IpList.Metadata.classification | String | The IP address classification. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"IpList": {
"Metadata": [
{
"cidr": "cidr",
"classificaiton": "classification",
"classification": "classification",
"id": "id",
"name": "name"
}
]
}
}
}
Human Readable Output
IP List metadata
Showing 8 rows out of 8.
Id Name Cidr Classification id name cidr classification
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"IpList": {
"Metadata": [
{
"cidr": "cidr",
"classificaiton": "classification",
"classification": "classification",
"id": "id",
"name": "name"
}
]
}
}
}
Human Readable Output
IP List metadata
Showing 8 rows out of 8.
Id Name Cidr Classification id name cidr classification
dome9-ip-list-metadata-create
Add metadata for a new IP address. An IP address metadata must contain the CIDR, name, and classification. Classification can be External, Unsafe, Dmz, InternalVpc, InternalDc, or NoClassification.
Base Command
dome9-ip-list-metadata-create
Input
| Argument Name | Description | Required |
|---|---|---|
| cidr | The IP address CIDR. | Required |
| name | The IP address name. | Required |
| classification | The IP address classification. Possible values are: External, Unsafe, Dmz, InternalVpc, InternalDc, NoClassification.. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.IpList.Metadata.id | String | The IP address internal ID. |
| CheckPointDome9.IpList.Metadata.cidr | string | The IP address CIDR. |
| CheckPointDome9.IpList.Metadata.name | String | The IP address name. |
| CheckPointDome9.IpList.Metadata.classification | String | The IP address classification. |
Command example
!dome9-ip-list-metadata-create cidr=cidr classification=classification name=metadata
Context Example
{
"CheckPointDome9": {
"IpList": {
"Metadata": {
"cidr": "cidr",
"classificaiton": "classification",
"classification": "classification",
"id": "id",
"name": "metadata"
}
}
}
}
Human Readable Output
IP List metadata created successfully
Cidr Classificaiton Classification Id Name cidr classification classification id metadata
dome9-ip-list-metadata-update
Update an existing IP address metadata. Classification can only be External, Unsafe, Dmz, InternalVpc, InternalDc, or NoClassification.
Base Command
dome9-ip-list-metadata-update
Input
| Argument Name | Description | Required |
|---|---|---|
| list_metadata_id | The IP address internal ID. | Required |
| name | The IP address nName. | Optional |
| classification | The IP address classification. Possible values are: External, Unsafe, Dmz, InternalVpc, InternalDc, NoClassification.. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.IpList.Metadata.id | String | The IP address internal ID. |
| CheckPointDome9.IpList.Metadata.cidr | string | The IP address CIDR. |
| CheckPointDome9.IpList.Metadata.name | String | The IP address Name. |
| CheckPointDome9.IpList.Metadata.classification | String | The IP address classification. |
Command example
!dome9-ip-list-metadata-update classification=classification list_metadata_id=list_metadata_id name=NewName
Context Example
{
"CheckPointDome9": {
"IpList": {
"Metadata": {
"cidr": "cidr",
"classificaiton": "classification",
"classification": "classification",
"id": "list_metadata_id",
"name": "NewName"
}
}
}
}
Human Readable Output
IP List metadata updated successfully
Cidr Classificaiton Classification Id Name cidr classification classification list_metadata_id NewName
dome9-ip-list-metadata-delete
Delete an IP address metadata with a specific CIDR.
Base Command
dome9-ip-list-metadata-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| account_id | The account ID. | Required |
| address | The IP address to delete. | Required |
| mask | The subnet mask. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-ip-list-metadata-delete account_id=account_id address=ip mask=32
Context Example
{
"CheckPointDome9": {
"IpList": {
"Metadata": ""
}
}
}
Human Readable Output
IP List metadata deleted successfully
dome9-compliance-remediation-get
Get a list of remediations for the account.
Base Command
dome9-compliance-remediation-get
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.ComplianceRemediation.id | String | Remediation ID. |
| CheckPointDome9.ComplianceRemediation.ruleLogicHash | String | Hash for the rule logic. |
| CheckPointDome9.ComplianceRemediation.ruleName | String | Rule name. |
| CheckPointDome9.ComplianceRemediation.ruleId | String | Rule ID. |
| CheckPointDome9.ComplianceRemediation.logic | String | The GSL logic of the exclusion. |
| CheckPointDome9.ComplianceRemediation.rulesetId | Number | Ruleset ID. |
| CheckPointDome9.ComplianceRemediation.platform | String | Remediation platform. |
| CheckPointDome9.ComplianceRemediation.cloudBots | String | Cloud bots execution expressions. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"ComplianceRemediation": [
{
"cloudAccountId": null,
"cloudBots": [
"cloudBots"
],
"comment": "comment",
"id": "id",
"logic": null,
"platform": "platform",
"ruleId": null,
"ruleLogicHash": "ruleLogicHash",
"ruleName": null,
"rulesetId": -51
}
]
}
}
Human Readable Output
Compliance remediation
Id Rulelogichash Rulesetid Platform Comment Cloudbots id ruleLogicHash ruleset_id platform comment cloudbots
dome9-compliance-remediation-create
Add a new remediation.
Base Command
dome9-compliance-remediation-create
Input
| Argument Name | Description | Required |
|---|---|---|
| ruleset_id | Ruleset ID to apply remediation on. Use the dome9-compliance-ruleset-list command to get the Ruleset ID list. | Required |
| comment | Comment text. | Required |
| cloudbots | Cloud bots execution expressions. Possible values are: ami_set_to_private, acm_delete_certificate, cloudtrail_enable, cloudtrail_enable_log_file_validation, cloudtrail_send_to_cloudwatch, cloudwatch_create_metric_filter, config_enable, ec2_attach_sg, ec2_attach_instance_role, ec2_create_snapshot, ec2_release_eips, ec2_quarantine_instance, ec2_stop_instance, ec2_terminate_instance, ec2_update_instance_role, ec2_service_role_detach_inline_group, iam_detach_policy, iam_group_delete_inline_group, iam_generate_credential_report, iam_role_attach_policy, iam_user_attach_policy, iam_user_deactivate_unused_access_key, iam_user_delete_inline_policies, iam_user_disable_console_password, iam_user_force_password_change, iam_quarantine_role, iam_quarantine_user, iam_role_clone_with_non_enumerable_name, iam_turn_on_password_policy, igw_delete, kms_cmk_enable_key, kms_enable_rotation, lambda_detach_blanket_permissions, lambda_tag, lambda_enable_active_tracing, load_balancer_enable_access_logs, mark_for_stop_ec2_resource. | Required |
| rule_logic_hash | Hash for the rule logic. Use the compliance-ruleset-rule-list command to fetch logic hash. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-compliance-remediation-create cloudbots=cloudbots comment=COMMENT rule_logic_hash=rule_logic_hash/k4lIw ruleset_id=rule_id
Context Example
{
"CheckPointDome9": {
"ComplianceRemediation": {
"cloudAccountId": null,
"cloudBots": [
"cloudbots"
],
"comment": "COMMENT",
"id": "id",
"logic": null,
"platform": "platform",
"ruleId": null,
"ruleLogicHash": "ruleLogicHash",
"ruleName": null,
"rulesetId": "rulesetId"
}
}
}
Human Readable Output
Remediation created successfully
Cloudbots Id Rulelogichash Rulesetid Platform Comment cloudbots id ruleLogicHash ruleset_id platform COMMENT
dome9-compliance-remediation-update
Update a remediation.
Base Command
dome9-compliance-remediation-update
Input
| Argument Name | Description | Required |
|---|---|---|
| remediation_id | Remediation ID. | Required |
| ruleset_id | Ruleset ID. | Required |
| comment | Comment text. | Required |
| cloudbots | Cloud bots execution expressions. Possible values are: ami_set_to_private, acm_delete_certificate, cloudtrail_enable, cloudtrail_enable_log_file_validation, cloudtrail_send_to_cloudwatch, cloudwatch_create_metric_filter, config_enable, ec2_attach_sg, ec2_attach_instance_role, ec2_create_snapshot, ec2_release_eips, ec2_quarantine_instance, ec2_stop_instance, ec2_terminate_instance, ec2_update_instance_role, ec2_service_role_detach_inline_group, iam_detach_policy, iam_group_delete_inline_group, iam_generate_credential_report, iam_role_attach_policy, iam_user_attach_policy, iam_user_deactivate_unused_access_key, iam_user_delete_inline_policies, iam_user_disable_console_password, iam_user_force_password_change, iam_quarantine_role, iam_quarantine_user, iam_role_clone_with_non_enumerable_name, iam_turn_on_password_policy, igw_delete, kms_cmk_enable_key, kms_enable_rotation, lambda_detach_blanket_permissions, lambda_tag, lambda_enable_active_tracing, load_balancer_enable_access_logs, mark_for_stop_ec2_resource. | Required |
| rule_logic_hash | Hash for the rule logic. Use the compliance-ruleset-rule-list command to fetch logic hash. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-compliance-remediation-update remediation_id=r_id cloudbots=cloudbots comment=COMMENT rule_logic_hash=ruleLogicHash ruleset_id=ruleset_id
Context Example
{
"CheckPointDome9": {
"ComplianceRemediation": {
"cloudAccountId": null,
"cloudBots": [
"cloudbots"
],
"comment": "COMMENT",
"id": "r_id",
"logic": null,
"platform": "platform",
"ruleId": null,
"ruleLogicHash": "ruleLogicHash",
"ruleName": null,
"rulesetId": "ruleset_id"
}
}
}
Human Readable Output
Remediation updated successfully
Cloudbots Id Rulelogichash Rulesetid Platform Comment cloudbots r_id ruleLogicHash ruleset_id platform COMMENT
dome9-compliance-remediation-delete
Delete a remediation.
Base Command
dome9-compliance-remediation-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| remediation_id | Remediation ID. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-compliance-remediation-delete remediation_id=remediation_id
Context Example
{
"CheckPointDome9": {
"ComplianceRemediation": ""
}
}
Human Readable Output
Remediation deleted successfully
dome9-compliance-ruleset-list
Get all Rulesets for the account.
Base Command
dome9-compliance-ruleset-list
Input
| Argument Name | Description | Required |
|---|---|---|
| ruleset_id | The Ruleset ID. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.ComplianceRuleset.accountId | String | The account ID. |
| CheckPointDome9.ComplianceRuleset.id | Number | The Ruleset ID. |
| CheckPointDome9.ComplianceRuleset.name | String | The Ruleset name. |
| CheckPointDome9.ComplianceRuleset.description | String | The Ruleset description. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"ComplianceRuleset": [
{
"accountId": "account_id",
"cloudVendor": "cloudVendor",
"common": false,
"createdTime": "createdTime",
"default": false,
"description": "description",
"hideInCompliance": false,
"icon": "",
"id": "id",
"isTemplate": true,
"language": "language",
"minFeatureTier": "minFeatureTier",
"name": "name",
"rulesCount": 1,
"section": 2,
"showBundle": true,
"systemBundle": false,
"tooltipText": "tooltipText",
"updatedTime": "updatedTime",
"version": 32
}
]
}
}
Human Readable Output
Compliance Ruleset
Showing 50 rows out of 136.
Accountid Id Name Description account_id id name description
dome9-compliance-ruleset-rule-list
Get rule details. Get the rule logic hash to create a new remediation.
Base Command
dome9-compliance-ruleset-rule-list
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The Ruleset ID. | Required |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.ComplianceRuleset.Rule.name | String | The rule name. |
| CheckPointDome9.ComplianceRuleset.Rule.severity | String | The rule severity. |
| CheckPointDome9.ComplianceRuleset.Rule.logic | Number | The rule logic. |
| CheckPointDome9.ComplianceRuleset.Rule.logicHash | String | The rule logic hash. |
| CheckPointDome9.ComplianceRuleset.Rule.description | String | The rule description. |
Command example
!dome9-compliance-ruleset-rule-list rule_id=-41
Context Example
{
"CheckPointDome9": {
"ComplianceRuleset": {
"Rule": [
{
"category": "",
"cloudbots": null,
"complianceTag": "complianceTag",
"controlTitle": "",
"description": "description",
"domain": "",
"isDefault": false,
"labels": [],
"logic": "logic",
"logicHash": "logicHash",
"name": "name",
"priority": "",
"remediation": "remediation",
"ruleId": "ruleId",
"severity": "severity"
}
]
}
}
}
Human Readable Output
Compliance Ruleset Rules
Showing 10 rows out of 10.
Name Severity Description Logic Logichash name severity description logic logicHash
dome9-security-group-instance-attach
Attach the security group to an AWS EC2 instance.
Base Command
dome9-security-group-instance-attach
Input
| Argument Name | Description | Required |
|---|---|---|
| instance_id | AWS instance ID. | Required |
| sg_id | AWS security group internal ID. | Required |
| nic_name | The instance NIC name. Use the dome9-instance-list command to get this argument. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-security-group-instance-attach instance_id=i-instance_id nic_name=nic_name sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"Instance": {
"amiLaunchIndex": 0,
"architecture": "architecture",
"blockDeviceMappings": [
{
"deviceName": "deviceName",
"ebs": {
"attachTime": "attachTime",
"deleteOnTermination": true,
"status": "status",
"volumeId": "volumeId"
}
}
],
"clientToken": null,
"ebsOptimized": false,
"enaSupport": true,
"externalId": "externalId",
"hypervisor": "hypervisor",
"iamInstanceProfile": null,
"imageId": "imageId",
"imageName": null,
"instanceId": "instanceId",
"instanceLifecycle": null,
"instanceType": "instanceType",
"isMicro": true,
"isRunning": true,
"kernelId": null,
"keyName": "keyName",
"launchTime": "launchTime",
"monitoring": {
"state": "state"
},
"networkInterfaces": [
{
"association": {
"ipOwnerId": "ipOwnerId",
"publicDnsName": "publicDnsName",
"publicIp": "publicIp"
},
"attachment": {
"attachTime": "attachTime",
"attachmentId": "attachmentId",
"deleteOnTermination": true,
"deviceIndex": 0,
"status": "status"
},
"description": null,
"groups": [
{
"groupId": "groupId",
"groupName": "groupName"
}
],
"ipv6Addresses": [],
"macAddress": "macAddress",
"networkInterfaceId": "networkInterfaceId",
"ownerId": "ownerId",
"privateDnsName": "privateDnsName",
"privateIpAddress": "privateIpAddress",
"privateIpAddresses": [
{
"association": {
"ipOwnerId": "ipOwnerId",
"publicDnsName": "publicDnsName",
"publicIp": "publicIp"
},
"primary": true,
"privateDnsName": "privateDnsName",
"privateIpAddress": "privateIpAddress"
}
],
"sourceDestCheck": true,
"status": "status",
"subnetId": "subnetId",
"vpcId": "vpcId"
}
],
"niCs": [
{
}
],
"osType": "osType",
"placement": {
"affinity": null,
"availabilityZone": "availabilityZone",
"groupName": null,
"hostId": null,
"tenancy": "tenancy"
},
"platform": null,
"privateDnsName": "privateDnsName",
"privateIpAddress": "privateIpAddress",
"productCodes": [],
"profileArn": null,
"publicDnsName": "publicDnsName",
"publicIpAddress": "publicIpAddress",
"ramdiskId": null,
"rootDeviceName": "rootDeviceName",
"rootDeviceType": "rootDeviceType",
"securityGroups": [
],
"sourceDestCheck": true,
"spotInstanceRequestId": null,
"sriovNetSupport": null,
"state": {
},
"stateReason": null,
"stateTransitionReason": null,
"subnetId": "subnetId",
"tags": [
{
"key": "Name",
"value": "value"
}
],
"virtualizationType": "virtualizationType",
"vpcId": "vpcId"
}
}
}
Human Readable Output
Security group attach successfully
dome9-security-group-service-delete
Delete a service from an AWS security group.
Base Command
dome9-security-group-service-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| sg_id | Security group ID. | Required |
| service_id | Service ID. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-security-group-service-delete service_id=6-56 sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"SecurityGroup": {
"Service": ""
}
}
}
Human Readable Output
Service deleted successfully
dome9-security-group-tags-update
Update the list of tags for an AWS security group.
Base Command
dome9-security-group-tags-update
Input
| Argument Name | Description | Required |
|---|---|---|
| sg_id | Security group ID. | Required |
| key | The key name. | Required |
| value | The value name. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-security-group-tags-update key=KEYkey value=VALUEvalue sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"SecurityGroup": {
"Tag": {
"keYkey": "VALUEvalue"
}
}
}
}
Human Readable Output
Tag updated successfully
dome9-security-group-service-create
Create a new service (rule) for the security group.
Base Command
dome9-security-group-service-create
Input
| Argument Name | Description | Required |
|---|---|---|
| sg_id | Security group ID. | Required |
| policy_type | The service type. Possible values are: Inbound, Outbound. | Required |
| name | The service name. | Required |
| protocol_type | Service protocol type. Possible values are: ALL, HOPOPT, ICMP, IGMP, GGP, IPV4, ST, TCP, CBT, EGP, IGP, BBN_RCC_MON, NVP2, PUP, ARGUS, EMCON, XNET, CHAOS, UDP, MUX, DCN_MEAS, HMP, PRM, XNS_IDP, TRUNK1, TRUNK2, LEAF1, LEAF2, RDP, IRTP, ISO_TP4, NETBLT, MFE_NSP, MERIT_INP, DCCP, ThreePC, IDPR, XTP, DDP, IDPR_CMTP, TPplusplus, IL, IPV6, SDRP, IPV6_ROUTE, IPV6_FRAG, IDRP, RSVP, GRE, DSR, BNA, ESP, AH, I_NLSP, SWIPE, NARP, MOBILE, TLSP, SKIP, ICMPV6, IPV6_NONXT, IPV6_OPTS, CFTP, SAT_EXPAK, KRYPTOLAN, RVD, IPPC, SAT_MON, VISA, IPCV, CPNX, CPHB, WSN, PVP, BR_SAT_MON, SUN_ND, WB_MON, WB_EXPAK, ISO_IP, VMTP, SECURE_VMTP, VINES, TTP, NSFNET_IGP, DGP, TCF, EIGRP, OSPFIGP, SPRITE_RPC, LARP, MTP, AX25, IPIP, MICP, SCC_SP, ETHERIP, ENCAP, GMTP, IFMP, PNNI, PIM, ARIS, SCPS, QNX, AN, IPCOMP, SNP, COMPAQ_PEER, IPX_IN_IP, VRRP, PGM, L2TP, DDX, IATP, STP, SRP, UTI, SMP, SM, PTP, ISIS, FIRE, CRTP, CRUDP, SSCOPMCE, IPLT, SPS, PIPE, SCTP, FC, RSVP_E2E_IGNORE, MOBILITY_HEADER, UDPLITE, MPLS_IN_IP, MANET, HIP, SHIM6, WESP, ROHC. | Required |
| port | The service port (indicates a port range). | Required |
| open_for_all | Indicates if the service is open to all ports. Possible values are: True, False. | Optional |
| description | Service description. | Optional |
| data_id | IP list ID to attach. | Optional |
| data_name | IP list name to attach. | Optional |
| scope_type | Scope type to attach. Possible values are: CIDR, IPList. | Optional |
| is_valid | Whether the service is valid. Possible values are: True, False. | Optional |
| inbound | Whether the service is inbound. Possible values are: True, False. | Optional |
| icmptype | ICMP type (when protocol is ICMP). Possible values are: All, EchoReply, DestinationUnreachable, SourceQuench, Redirect, AlternateHostAddress, Echo, RouterAdvertisement, RouterSelection, TimeExceeded, ParameterProblem, Timestamp, TimestampReply, InformationRequest, InformationReply, AddressMaskRequest, AddressMaskReply, Traceroute, DatagramConversionError, MobileHostRedirect, IPv6WhereAreYou, IPv6IAmHere, MobileRegistrationRequest, MobileRegistrationReply, DomainNameRequest, DomainNameReply, SKIP, Photuris. | Optional |
| icmpv6type | ICMP V6 type (when protocol is ICMPV6). | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.SecurityGroup.Service.id | String | The security group service ID. |
| CheckPointDome9.SecurityGroup.Service.name | string | The security group service name. |
| CheckPointDome9.SecurityGroup.Service.protocolType | String | The service protocol type. |
| CheckPointDome9.SecurityGroup.Service.port | string | The service port. |
| CheckPointDome9.SecurityGroup.Service.scope | String | The service scope type. |
| CheckPointDome9.SecurityGroup.Service.description | string | The service description. |
Command example
!dome9-security-group-service-create name=NewService0107 policy_type=Inbound port=port protocol_type=protocol sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"SecurityGroup": {
"Service": {
"description": null,
"icmpType": null,
"icmpv6Type": null,
"id": "id",
"inbound": true,
"name": "NewService0107",
"openForAll": false,
"port": "port",
"protocolType": "protocol",
"scope": []
}
}
}
}
Human Readable Output
Security group service created successfully
Description Id Name Port Protocoltype id NewService0107 port protocol
dome9-security-group-service-update
Update a service (rule) for an AWS security group. Can update only the port and name.
Base Command
dome9-security-group-service-update
Input
| Argument Name | Description | Required |
|---|---|---|
| sg_id | Security group ID. | Required |
| policy_type | The service type. Possible values are: Inbound, Outbound. | Required |
| service_name | Service name. | Required |
| protocol_type | The service protocol type. Possible values are: ALL, HOPOPT, ICMP, IGMP, GGP, IPV4, ST, TCP, CBT, EGP, IGP, BBN_RCC_MON, NVP2, PUP, ARGUS, EMCON, XNET, CHAOS, UDP, MUX, DCN_MEAS, HMP, PRM, XNS_IDP, TRUNK1, TRUNK2, LEAF1, LEAF2, RDP, IRTP, ISO_TP4, NETBLT, MFE_NSP, MERIT_INP, DCCP, ThreePC, IDPR, XTP, DDP, IDPR_CMTP, TPplusplus, IL, IPV6, SDRP, IPV6_ROUTE, IPV6_FRAG, IDRP, RSVP, GRE, DSR, BNA, ESP, AH, I_NLSP, SWIPE, NARP, MOBILE, TLSP, SKIP, ICMPV6, IPV6_NONXT, IPV6_OPTS, CFTP, SAT_EXPAK, KRYPTOLAN, RVD, IPPC, SAT_MON, VISA, IPCV, CPNX, CPHB, WSN, PVP, BR_SAT_MON, SUN_ND, WB_MON, WB_EXPAK, ISO_IP, VMTP, SECURE_VMTP, VINES, TTP, NSFNET_IGP, DGP, TCF, EIGRP, OSPFIGP, SPRITE_RPC, LARP, MTP, AX25, IPIP, MICP, SCC_SP, ETHERIP, ENCAP, GMTP, IFMP, PNNI, PIM, ARIS, SCPS, QNX, AN, IPCOMP, SNP, COMPAQ_PEER, IPX_IN_IP, VRRP, PGM, L2TP, DDX, IATP, STP, SRP, UTI, SMP, SM, PTP, ISIS, FIRE, CRTP, CRUDP, SSCOPMCE, IPLT, SPS, PIPE, SCTP, FC, RSVP_E2E_IGNORE, MOBILITY_HEADER, UDPLITE, MPLS_IN_IP, MANET, HIP, SHIM6, WESP, ROHC. | Required |
| port | Service port (indicates a port range). | Required |
| open_for_all | Whether the service is open to all ports. Possible values are: True, False. | Optional |
| description | Service description. | Optional |
| data_id | IP list ID. | Optional |
| data_name | IP list name. | Optional |
| scope_type | Scope type. Possible values are: CIDR, IPList. | Optional |
| is_valid | Whether the service is valid. Possible values are: True, False. | Optional |
| inbound | Whether the service is inbound. Possible values are: True, False. | Optional |
| icmptype | ICMP type (when protocol is ICMP). Possible values are: All, EchoReply, DestinationUnreachable, SourceQuench, Redirect, AlternateHostAddress, Echo, RouterAdvertisement, RouterSelection, TimeExceeded, ParameterProblem, Timestamp, TimestampReply, InformationRequest, InformationReply, AddressMaskRequest, AddressMaskReply, Traceroute, DatagramConversionError, MobileHostRedirect, IPv6WhereAreYou, IPv6IAmHere, MobileRegistrationRequest, MobileRegistrationReply, DomainNameRequest, DomainNameReply, SKIP, Photuris. | Optional |
| icmpv6type | ICMP V6 type (when protocol is ICMPV6). | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.SecurityGroup.Service.id | String | The security group service ID. |
| CheckPointDome9.SecurityGroup.Service.name | string | The security group service name. |
| CheckPointDome9.SecurityGroup.Service.protocolType | String | The service protocol type. |
| CheckPointDome9.SecurityGroup.Service.port | string | The service port. |
| CheckPointDome9.SecurityGroup.Service.scopeType | String | The service scope type. |
| CheckPointDome9.SecurityGroup.Service.description | string | The service description. |
Command example
!dome9-security-group-service-update service_name=name policy_type=Inbound port=port protocol_type=protocol sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"SecurityGroup": {
"Service": {
"description": null,
"icmpType": null,
"icmpv6Type": null,
"id": "id",
"inbound": true,
"name": "name",
"openForAll": false,
"port": "port",
"protocolType": "protocol",
"scope": []
}
}
}
}
Human Readable Output
Security group service updated successfully
Description Id Name Port Protocoltype id name port protocol
dome9-security-group-instance-detach
Detach the security group from an AWS EC2 Instance.
Base Command
dome9-security-group-instance-detach
Input
| Argument Name | Description | Required |
|---|---|---|
| instance_id | AWS instance ID. | Required |
| sg_id | AWS security group internal ID. | Required |
| nic_name | The instance NIC name. Use the dome9-instance-list command to get this argument. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-security-group-instance-detach instance_id=i-instanceID nic_name=eth0 sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"Instance": {
"amiLaunchIndex": 0,
"architecture": "architecture",
"blockDeviceMappings": [
{
"deviceName": "deviceName",
"ebs": {
"attachTime": "attachTime",
"deleteOnTermination": true,
"status": "status",
"volumeId": "volumeId"
}
}
],
"clientToken": null,
"ebsOptimized": false,
"enaSupport": true,
"externalId": "externalId",
"hypervisor": "hypervisor",
"iamInstanceProfile": null,
"imageId": "imageId",
"imageName": null,
"instanceId": "instanceId",
"instanceLifecycle": null,
"instanceType": "instanceType",
"isMicro": true,
"isRunning": true,
"kernelId": null,
"keyName": "keyName",
"launchTime": "launchTime",
"monitoring": {
"state": "state"
},
"networkInterfaces": [
{
"association": {
"ipOwnerId": "ipOwnerId",
"publicDnsName": "publicDnsName",
"publicIp": "publicIp"
},
"attachment": {
"attachTime": "attachTime",
"attachmentId": "attachmentId",
"deleteOnTermination": true,
"deviceIndex": 0,
"status": "status"
},
"description": null,
"groups": [
{
"groupId": "groupId",
"groupName": "groupName"
}
],
"ipv6Addresses": [],
"macAddress": "macAddress",
"networkInterfaceId": "networkInterfaceId",
"ownerId": "ownerId",
"privateDnsName": "privateDnsName",
"privateIpAddress": "privateIpAddress",
"privateIpAddresses": [
{
"association": {
"ipOwnerId": "ipOwnerId",
"publicDnsName": "publicDnsName",
"publicIp": "publicIp"
},
"primary": true,
"privateDnsName": "privateDnsName",
"privateIpAddress": "privateIpAddress"
}
],
"sourceDestCheck": true,
"status": "status",
"subnetId": "subnetId",
"vpcId": "vpcId"
}
],
"niCs": [
{
}
],
"osType": "osType",
"placement": {
"affinity": null,
"availabilityZone": "availabilityZone",
"groupName": null,
"hostId": null,
"tenancy": "tenancy"
},
"platform": null,
"privateDnsName": "privateDnsName",
"privateIpAddress": "privateIpAddress",
"productCodes": [],
"profileArn": null,
"publicDnsName": "publicDnsName",
"publicIpAddress": "publicIpAddress",
"ramdiskId": null,
"rootDeviceName": "rootDeviceName",
"rootDeviceType": "rootDeviceType",
"securityGroups": [
],
"sourceDestCheck": true,
"spotInstanceRequestId": null,
"sriovNetSupport": null,
"state": {
},
"stateReason": null,
"stateTransitionReason": null,
"subnetId": "subnetId",
"tags": [
{
"key": "Name",
"value": "value"
}
],
"virtualizationType": "virtualizationType",
"vpcId": "vpcId"
}
}
}
Human Readable Output
Security group detach successfully
dome9-instance-list
Fetch an AWS EC2 instance.
Base Command
dome9-instance-list
Input
| Argument Name | Description | Required |
|---|---|---|
| instance_id | AWS instance ID. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.Instance.externalId | String | The instance external ID. |
| CheckPointDome9.Instance.region | string | The instance region. |
| CheckPointDome9.Instance.nics | String | The instance NIC names. |
| CheckPointDome9.Instance.name | string | The instance name. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"Instance": [
{
"accountId": "account_id",
"cloudAccountId": "cloudAccountId",
"externalId": "i-externalId",
"image": "ami-image",
"instanceType": "instanceType",
"isBillable": true,
"isRunning": true,
"kernelId": null,
"launchTime": "launchTime",
"name": "name",
"nics": [
{
"name": "name"
}
],
"platform": "platform",
"profileArn": "profileArn",
"publicDnsName": "publicDnsName",
"region": "region",
"roleArns": [
"roleArns"
],
"ssmAgentInstanceInformation": null,
"tags": {
"Name": "Name"
},
"vpc": "vpc"
}
]
}
}
Human Readable Output
AWS instances
Showing 5 rows out of 5.
Accountid Cloudaccountid Externalid Image Instancetype Isbillable Isrunning Kernelid Launchtime Name Nics Platform Profilearn Publicdnsname Region Rolearns Ssmagentinstanceinformation Tags Vpc account_id cloudAccountId i-Externalid ami Instancetype true true someDate name Nics region arn Name vpc
dome9-security-group-protection-mode-update
Change the protection mode for an AWS security group (FullManage or ReadOnly).
Base Command
dome9-security-group-protection-mode-update
Input
| Argument Name | Description | Required |
|---|---|---|
| protection_mode | The protection mode to update. Possible values are: FullManage, ReadOnly. | Required |
| sg_id | Security group ID. | Required |
Context Output
There is no context output for this command.
Command example
!dome9-security-group-protection-mode-update protection_mode=FullManage sg_id=sg_id
Context Example
{
"CheckPointDome9": {
"SecurityGroup": {
"cloud_account_id": "cloudAccountId",
"cloud_account_name": "cloud_account_name",
"description": "description",
"isProtected": true,
"region_id": "region",
"security_group_external_id": "sg_id",
"security_group_id": "sg_id",
"security_group_name": "security_group_name",
"vpc_id": "vpc"
}
}
}
Human Readable Output
protection mode updated for security group
Cloud Account Id Cloud Account Name Description Isprotected Region Id Security Group External Id Security Group Id Security Group Name Vpc Id cloudAccountId name description true region sg_id sg_id sg_name vpc
dome9-cloud-accounts-list
Get the cloud account list.
Base Command
dome9-cloud-accounts-list
Input
| Argument Name | Description | Required |
|---|---|---|
| account_id | account ID. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| cloud_account_od | The cloud account ID. | Optional |
Context Output
There is no context output for this command.
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"CloudAccount": {
"allowReadOnly": false,
"creationDate": "creationDate",
"credentials": {
"apikey": null,
"arn": "arn",
"iamUser": null,
"isReadOnly": true,
"secret": null,
"type": "type"
},
"error": null,
"externalAccountNumber": "externalAccountNumber",
"fullProtection": false,
"iamSafe": {
},
"id": "cloudAccountId",
"isFetchingSuspended": false,
"lambdaScanner": false,
"magellan": true,
"name": "name",
"netSec": {
"regions": [
]
},
"onboardingMode": "onboardingMode",
"organizationalUnitId": null,
"organizationalUnitName": "organizationalUnitName",
"organizationalUnitPath": "",
"serverless": {
},
"vendor": "vendor"
}
}
}
Human Readable Output
Cloud accounts
Showing 1 rows out of 1.
Id Vendor Externalaccountnumber Creationdate Organizationalunitname cloudAccountId vendor number date name
dome9-security-group-ip-list-details-get
Get AWS cloud accounts for a specific security group and region and check if there is an IP list to attach to a security group.
Base Command
dome9-security-group-ip-list-details-get
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| sg_id | Security group ID. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.SecurityGroup.security_group_id | String | The security group ID. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"SecurityGroup": [
{
"cloud_account_id": "cloudAccountId",
"cloud_account_name": "cloud_account_name",
"description": "description",
"isProtected": true,
"region_id": "region",
"security_group_external_id": "sg_id",
"security_group_id": "sg_id",
"security_group_name": "security_group_name",
"vpc_id": "vpc"
}
]
}
}
Human Readable Output
Security Groups
Showing 1 rows out of 24.
Cloud Account Id Cloud Account Name Description Isprotected Region Id Security Group External Id Security Group Id Security Group Name Vpc Id cloudAccountId name description true region sg_id sg_id sg_name vpc
dome9-security-group-list
Get all security group entities.
Base Command
dome9-security-group-list
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.SecurityGroup.security_group_id | String | The security group ID. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"SecurityGroup": [
{
"cloudAccountId": "cloudAccountId",
"cloudAccountName": "cloudAccountName",
"externalId": "sg",
"regionId": "region",
"securityGroupName": "securityGroupName",
"vpcId": "vpc"
}
]
}
}
Human Readable Output
Security Groups
Showing 1 rows out of 107.
Cloud Account Id Region Id Security Group Id Security Group Name Vpc Id cloudAccountId region sg name vpc
dome9-global-search-get
Get top results for each service.
Base Command
dome9-global-search-get
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.GlobalSearch.Alert.id | String | The global search alert ID. |
| CheckPointDome9.GlobalSearch.Alert.type | String | The global search alert type. |
| CheckPointDome9.GlobalSearch.Alert.severity | String | The global search alert severity. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"GlobalSearch": {
"Alert": [
{
"alertType": "alertType",
"bundleId": "bundleId",
"cloudAccountExternalId": "cloudAccountExternalId",
"cloudAccountId": "cloudAccountId",
"createdTime": "createdTime",
"description": "description",
"entityName": "entityName",
"id": "id",
"remediation": "remediation",
"ruleName": "ruleName",
"severity": "severity",
"updatedTime": "updatedTime"
},
{
"alertType": "alertType",
"bundleId": "bundleId",
"cloudAccountExternalId": "cloudAccountExternalId",
"cloudAccountId": "cloudAccountId",
"createdTime": "createdTime",
"description": "description",
"entityName": "entityName",
"id": "id",
"remediation": "remediation",
"ruleName": "ruleName",
"severity": "severity",
"updatedTime": "updatedTime"
}
]
}
}
}
Human Readable Output
Global Search
Alerttype Bundleid Cloudaccountexternalid Cloudaccountid Createdtime Description Entityname Id Remediation Rulename Severity Updatedtime Alerttype Bundleid Cloudaccountexternalid Cloudaccountid date Description Entityname id Remediation rule name Severity Updatedtime Alerttype Bundleid Cloudaccountexternalid Cloudaccountid date Description Entityname id remediation rule name Severity Updatedtime
dome9-cloud-trail-get
Get CloudTrail events for a Dome9 user.
Base Command
dome9-cloud-trail-get
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.CloudTrail.id | String | The CloudTrail ID. |
| CheckPointDome9.CloudTrail.name | String | The CloudTrail name. |
| CheckPointDome9.CloudTrail.trailArn | String | The CloudTrail ARN. |
| CheckPointDome9.CloudTrail.accountId | String | The CloudTrail account ID. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"CloudTrail": {
"accountId": "account_id",
"cloudAccountId": "cloudAccountId",
"cloudTrailStatus": {
},
"cloudWatchLogsLogGroupArn": null,
"cloudWatchLogsRoleArn": null,
"externalId": "arn",
"homeRegion": "homeRegion",
"id": "id",
"includeGlobalServiceEvents": true,
"isMultiRegionTrail": true,
"kmsKeyId": null,
"logFileValidationEnabled": true,
"name": "name",
"region": "region",
"s3BucketName": "s3BucketName",
"s3KeyPrefix": null,
"snsTopicArn": null,
"snsTopicName": null,
"trailArn": "arn"
}
}
}
Human Readable Output
Cloud Trail
Showing 1 rows out of 1.
Accountid Cloudaccountid Cloudtrailstatus Cloudwatchlogsloggrouparn Cloudwatchlogsrolearn Externalid Homeregion Id Includeglobalserviceevents Ismultiregiontrail Kmskeyid Logfilevalidationenabled Name Region S3bucketname S3keyprefix Snstopicarn Snstopicname Trailarn account_id cloudAccountId status arn us-east-1 id true true true name region name arn dome9-organizational-unit-view-get
Get organizational unit view entities.
Base Command
dome9-organizational-unit-view-get
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.OrganizationalUnitView.id | String | The organizational unit ID. |
| CheckPointDome9.OrganizationalUnitView.name | String | The organizational unit name. |
| CheckPointDome9.OrganizationalUnitView.path | String | The organizational unit path. |
| CheckPointDome9.OrganizationalUnitView.children | String | The organizational unit children. |
Command example
#### Context Example
```json
{
"CheckPointDome9": {
"OrganizationalUnitView": {
"children": [],
"id": "id",
"name": "name",
"path": "path"
}
}
}
Human Readable Output
Organizational Unit View
Children Id Name Path id name name
dome9-organizational-unit-flat-get
Get flat organizational units.
Base Command
dome9-organizational-unit-flat-get
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.OrganizationalUnitFlat.id | String | The organizational unit ID. |
| CheckPointDome9.OrganizationalUnitFlat.name | String | The organizational unit name. |
| CheckPointDome9.OrganizationalUnitFlat.path | String | The organizational unit path. |
| CheckPointDome9.OrganizationalUnitFlat.parentId | String | The organizational unit parent ID. |
Command example
#### Human Readable Output
>### Organizational Unit Flat
>
>Showing 0 rows out of 0.
>**No entries.**
>
### dome9-organizational-unit-get
***
Get an organizational unit by its ID.
#### Base Command
`dome9-organizational-unit-get`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| unit_id | The organizational unit ID. | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| CheckPointDome9.OrganizationalUnit.id | String | The organizational unit ID. |
| CheckPointDome9.OrganizationalUnit.name | String | The organizational unit name. |
| CheckPointDome9.OrganizationalUnit.path | String | The organizational unit path. |
| CheckPointDome9.OrganizationalUnit.parentId | String | The organizational unit parent ID. |
#### Command example
```!dome9-organizational-unit-get```
#### Context Example
```json
{
"CheckPointDome9": {
"OrganizationalUnit": {
"accountId": 0,
"alibabaAggregateCloudAccountsCount": 0,
"alibabaCloudAccountsCount": 0,
"awsAggregatedCloudAcountsCount": 1,
"awsCloudAcountsCount": 1,
"azureAggregateCloudAccountsCount": 0,
"azureCloudAccountsCount": 0,
"containerRegistryAccountsCount": 0,
"containerRegistryAggregateCloudAccountsCount": 0,
"created": "created",
"googleAggregateCloudAccountsCount": 0,
"googleCloudAccountsCount": 0,
"id": "id",
"isParentRoot": true,
"isRoot": true,
"k8sAggregateCloudAccountsCount": 0,
"k8sCloudAccountsCount": 0,
"name": "name",
"parentId": null,
"path": null,
"pathStr": null,
"shiftLeftAggregateCloudAccountsCount": 0,
"shiftLeftCloudAccountsCount": 0,
"subOrganizationalUnitsCount": 0,
"updated": "updated"
}
}
}
Human Readable Output
Organizational Unit
Accountid Alibabaaggregatecloudaccountscount Alibabacloudaccountscount Awsaggregatedcloudacountscount Awscloudacountscount Azureaggregatecloudaccountscount Azurecloudaccountscount Containerregistryaccountscount Containerregistryaggregatecloudaccountscount Created Googleaggregatecloudaccountscount Googlecloudaccountscount Id Isparentroot Isroot K8saggregatecloudaccountscount K8scloudaccountscount Name Parentid Path Pathstr Shiftleftaggregatecloudaccountscount Shiftleftcloudaccountscount Suborganizationalunitscount Updated 0 0 0 1 1 0 0 0 0 date 0 0 id true true 0 0 name 0 0 0 date
dome9-findings-get
Get a findings by its ID.
Base Command
dome9-findings-get
Input
| Argument Name | Description | Required |
|---|---|---|
| finding_id | The findings ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.Finding.id | String | The findings ID. |
| CheckPointDome9.Finding.bundleId | String | The findings bundle ID. |
| CheckPointDome9.Finding.severity | String | The findings severity. |
| CheckPointDome9.Finding.description | String | The findings description. |
| CheckPointDome9.Finding.remediation | String | The findings remediation. |
| CheckPointDome9.Finding.region | String | The findings region. |
| CheckPointDome9.Finding.cloudAccountId | String | The findings cloud account ID. |
Command example
!dome9-findings-get finding_id=finding_id
Context Example
{
"CheckPointDome9": {
"Finding": {
"acknowledged": false,
"action": "action",
"additionalFields": [],
"alertType": "alertType",
"bundleId": "bundleId",
"bundleName": "bundleName",
"category": "",
"cloudAccountExternalId": "id",
"cloudAccountId": "cloudAccountId",
"cloudAccountType": "cloudAccountType",
"comments": [],
"createdTime": "createdTime",
"description": "description",
"entityDome9Id": "entityDome9Id",
"entityExternalId": "entityExternalId",
"entityName": "entityName",
"entityNetwork": null,
"entityObject": {
},
"entityTags": [],
"bundleId": "bundleId",
"entityTypeByEnvironmentType": "",
"findingKey": "",
"id": "finding_id",
"isExcluded": false,
"labels": [],
"lastSeenTime": "lastSeenTime",
"magellan": null,
"occurrences": [],
"organizationalUnitId": "id",
"organizationalUnitPath": "",
"origin": "origin",
"ownerUserName": null,
"region": "Region",
"remediation": "remediation",
"remediationActions": [],
"ruleId": "ruleId",
"ruleLogic": "ruleLogic",
"ruleName": "ruleName",
"scanId": null,
"severity": "severity",
"status": "status",
"tag": "tag",
"updatedTime": "updatedTime",
"webhookResponses": null
}
}
}
Human Readable Output
Finding
dome9-findings-bundle-get
Get the findings for a specific rule in a bundle, for all of the user’s accounts.
Base Command
dome9-findings-bundle-get
Input
| Argument Name | Description | Required |
|---|---|---|
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | Number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| bundle_id | The bundle ID. Use the dome9-compliance-ruleset-list command to get the bundle ID list. | Required |
| rule_logic_hash | MD5 hash of the rule GSL string. Use the compliance-ruleset-rule-list command to fetch the logic hash. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CheckPointDome9.FindingsBundle.id | String | The CloudTrail ID. |
| CheckPointDome9.FindingsBundle.severity | String | The CloudTrail name. |
| CheckPointDome9.FindingsBundle.remediation | String | The Cloud Trail ARN. |
| CheckPointDome9.FindingsBundle.accountId | String | The CloudTrail account ID. |
| CheckPointDome9.FindingsBundle.description | String | The CloudTrail ARN. |
| CheckPointDome9.FindingsBundle.region | String | The CloudTrail account ID. |
Command example
!dome9-findings-bundle-get bundle_id=bundle_id rule_logic_hash=ruleLogicHash
Human Readable Output
Findings Bundle
No entries.
Configuration parameters
base_url— Server URL (required)api_key_id— API key IDapi_key_secret— API key secretapi_key_id_cred—api_key_secret_cred—proxy— Use system proxy settingsinsecure— Trust any certificate (not secure)max_fetch— Maximum incidents for one fetch.isFetch— Fetch incidentsalert_region— Alert region (AWS) to fetch as incidents.alert_severity— Alert severity to fetch as incidents.first_fetch— First fetch timeincidentType— Incident typeincidentFetchInterval— Incidents Fetch Interval
Commands (37)
-
dome9-access-lease-deleteTerminate an Access Lease.
-
dome9-access-lease-invitation-deleteDelete an Access Lease invitation.
-
dome9-access-lease-invitation-listGet a lease invitation.
-
dome9-access-lease-listGet a list of all active Access Leases.
-
dome9-cloud-accounts-listGet the cloud account list.
-
dome9-cloud-trail-getGet CloudTrail events for a Dome9 user.
-
dome9-compliance-remediation-createAdd a new remediation.
-
dome9-compliance-remediation-deleteDelete a remediation.
-
dome9-compliance-remediation-getGet a list of remediations for the account.
-
dome9-compliance-remediation-updateUpdate a remediation.
-
dome9-compliance-ruleset-listGet all Rulesets for the account.
-
dome9-compliance-ruleset-rule-listGet rule details. Get the rule logic hash to create a new remediation.
-
dome9-findings-bundle-getGet the findings for a specific rule in a bundle, for all of the user's accounts.
-
dome9-findings-getGet a findings by its ID.
-
dome9-findings-searchSearch for findings in CloudGuard.
-
dome9-global-search-getGet top results for each service.
-
dome9-instance-listFetch an AWS EC2 instance.
-
dome9-ip-list-createAdd a new IP list.
-
dome9-ip-list-deleteDelete an IP List by ID.
-
dome9-ip-list-getGet an IP List by ID.
-
dome9-ip-list-metadata-createAdd metadata for a new IP address. An IP address metadata must contain the CIDR, name, and classification. Classification can be External, Unsafe, Dmz, InternalVpc, InternalDc, or NoClassification.
-
dome9-ip-list-metadata-deleteDelete an IP address metadata with a specific CIDR.
-
dome9-ip-list-metadata-listGet all IP addresses metadata.
-
dome9-ip-list-metadata-updateUpdate an existing IP address metadata. Classification can only be External, Unsafe, Dmz, InternalVpc, InternalDc, or NoClassification.
-
dome9-ip-list-updateUpdate an IP list. This will override the existing IP list.
-
dome9-organizational-unit-flat-getGet flat organizational units.
-
dome9-organizational-unit-getGet an organizational unit by its ID.
-
dome9-organizational-unit-view-getGet organizational unit view entities.
-
dome9-security-group-instance-attachAttach the security group to an AWS EC2 instance.
-
dome9-security-group-instance-detachDetach the security group from an AWS EC2 Instance.
-
dome9-security-group-ip-list-details-getGet AWS cloud accounts for a specific security group and region and check if there is an IP list to attach to a security group.
-
dome9-security-group-listGet all security group entities.
-
dome9-security-group-protection-mode-updateChange the protection mode for an AWS security group (FullManage or ReadOnly).
-
dome9-security-group-service-createCreate a new service (rule) for the security group.
-
dome9-security-group-service-deleteDelete a service from an AWS security group.
-
dome9-security-group-service-updateUpdate a service (rule) for an AWS security group. Can update only the port and name.
-
dome9-security-group-tags-updateUpdate the list of tags for an AWS security group.
from typing import Any import demistomock as demisto # noqa: F401 from CommonServerPython import * # noqa: F401 TIME_FORMAT = "%Y-%m-%dT%H:%M:%S.%fZ" class Client(BaseClient): def __init__(self, base_url: str, key_id: str, key_secret: str, proxy: bool, verify: bool): self.base_url = base_url headers = {"Content-Type": "application/json"} auth = (key_id, key_secret) super().__init__(base_url=base_url, auth=auth, verify=verify, headers=headers, proxy=proxy) def access_lease_list_request(self) -> dict[str, Any]: """Get Access lease list. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("GET", "AccessLease") def access_lease_delete_request(self, lease_id: str) -> str: """Delete an access lease by ID. Args: lease_id (str): The access lease ID. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("DELETE", f"AccessLease/{lease_id}", resp_type="text") def access_lease_invitation_list_request(self, invitation_id: str = None) -> dict[str, Any]: """Get Access lease invitation list. Returns: Dict[str, Any]: API response from Dome9. """ url_prefix = create_url_prefix(invitation_id) # type: ignore[arg-type] response = self._http_request("GET", f"AccessLeaseInvitation{url_prefix}") return response def access_lease_invitation_delete_request(self, invitation_id: str) -> str: """Delete an access lease invitation by ID. Args: invitation_id (str): The access lease invitation ID. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("DELETE", f"AccessLeaseInvitation/{invitation_id}", resp_type="text") def findings_search_request( self, max_fetch: int, alert_severity: List[str] = None, alert_region: List[str] = None, alert_entity_type: List[str] = None, alert_acknowledged: bool = None, ) -> dict[str, Any]: """Search findings. Filter findings by account, region, VPC, IP, or instance name. Returns: Dict[str, Any]: API response from Dome9. """ fields = [] for severity in alert_severity or []: fields.append({"name": "severity", "value": severity}) for region in alert_region or []: fields.append({"name": "region", "value": region}) for entity_type in alert_entity_type or []: fields.append({"name": "entityTypeByEnvironmentType", "value": entity_type}) if alert_acknowledged: fields.append({"name": "acknowledged", "value": alert_acknowledged}) # type: ignore[dict-item] data = {"pageSize": max_fetch, "sorting": {"fieldName": "createdTime", "direction": 1}, "filter": {"fields": fields}} response = self._http_request("POST", "Compliance/Finding/search", json_data=data) return response def ip_list_create_request(self, name: str, description: str, items: List[dict[str, Any]] = None) -> dict[str, Any]: """Create a new IP list. Args: name (str): The new IP list name. description (str): IP list description. items (list, optional): List of IP address and IP comment. Returns: Dict[str, Any]: API response from Dome9. """ items = items or "" data = {"description": description, "items": items, "name": name} return self._http_request("POST", "IpList", json_data=data) def ip_list_update_request(self, list_id: str, description: str, items: List[dict[str, Any]] = None) -> str: """Update exist IP list. Args: list_id (str): The IP list ID. description (str): The new IP list description. items (list, optional): The new IP-list items (IP address and comment). Returns: Dict[str, Any]: API response from Dome9. """ data = {"description": description, "items": items} response = self._http_request("PUT", f"IpList/{list_id}", json_data=data, resp_type="text") return response def ip_list_get_request(self, list_id: str) -> dict[str, Any]: """Get an IP List by ID. Args: list_id (str): The IP-list ID to fetch. Returns: Dict[str, Any]: API response from Dome9. """ url_prefix = create_url_prefix(list_id) return self._http_request(method="GET", url_suffix=f"IpList{url_prefix}") def ip_list_delete_request(self, list_id: str) -> str: """Delete an IP List by id. Args: list_id (str): The IP-list ID to delete. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("DELETE", f"IpList/{list_id}", resp_type="text") def ip_list_metadata_list_request(self) -> dict[str, Any]: """Get all IP addresses metadata. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("GET", "IpAddressMetadata") def ip_list_metadata_create_request( self, cidr: str, name: str, classification: str, ) -> dict[str, Any]: """Add a new IP address metadata. An Ip Address metadata must contain CIDR, Name and Classification. Classification can be External or Unsafe or Dmz or InternalVpc or InternalDc or NoClassification. Args: cidr (str): The IP address CIDR. name (str): The IP address Name. classification (str): The IP address classification. Returns: Dict[str, Any]: API response from Dome9. """ data = {"cidr": cidr, "classification": classification, "name": name} response = self._http_request("POST", "IpAddressMetadata", json_data=data) return response def ip_list_metadata_update_request( self, list_id: str, classification: str, name: str, ) -> dict[str, Any]: """Update an existing IP address metadata. Classification can only be External or Unsafe or Dmz or InternalVpc or InternalDc or NoClassification. Args: list_id (str): The IP address internal ID. classification (str): The IP address classification. Returns: Dict[str, Any]: API response from Dome9. """ data = {"classification": classification, "id": list_id, "name": name} response = self._http_request("PUT", "IpAddressMetadata", json_data=data) return response def ip_list_metadata_delete_request( self, account_id: str, address: str, mask: int, ) -> str: """Delete an IP address metadata with a specific CIDR. Args: account_id (str): The account ID. address (str): The IP address to delete. mask (int): The subnet mask. Returns: Dict[str, Any]: API response from Dome9. """ params = {"accountId": account_id, "address": address, "mask": mask} response = self._http_request("DELETE", "IpAddressMetadata", params=params, resp_type="text") return response def compliance_remediation_get_request(self) -> dict[str, Any]: """Get a list of remediation for the account. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("GET", "ComplianceRemediation") def compliance_remediation_create_request( self, ruleset_id: str, rule_logic_hash: str, comment: str, cloudbots: list ) -> dict[str, Any]: """Add a new remediation. Args: ruleset_id (str): Ruleset ID to apply remediation on. rule_logic_hash (str): Hash for the rule logic. comment (str): Comment text. cloudbots (list): Cloud bots execution expressions. Returns: Dict[str, Any]: API response from Dome9. """ data = {"rulesetId": ruleset_id, "ruleLogicHash": rule_logic_hash, "cloudBots": cloudbots, "comment": comment} return self._http_request("POST", "ComplianceRemediation", json_data=data) def compliance_remediation_update_request( self, remediation_id: str, ruleset_id: str, rule_logic_hash: str, comment: str, cloudbots: list, ) -> dict[str, Any]: """Update a remediation. Args: remediation_id (str): Remediation ID. ruleset_id (str): Ruleset ID. rule_logic_hash (str): Hash for the rule logic. comment (str): Comment text. cloudbots (list): Cloud bots execution expressions. Returns: Dict[str, Any]: API response from Dome9. """ data = { "cloudBots": cloudbots, "comment": comment, "id": remediation_id, "rulesetId": ruleset_id, "ruleLogicHash": rule_logic_hash, } response = self._http_request("PUT", "ComplianceRemediation", json_data=data) return response def compliance_remediation_delete_request(self, remediation_id: str) -> str: """Delete a remediation by ID. Args: remediation_id (str): Remediation ID. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("DELETE", f"ComplianceRemediation/{remediation_id}", resp_type="text") def compliance_ruleset_list_request(self) -> dict[str, Any]: """Get all rulesets for the account. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("GET", "Compliance/Ruleset/view") def compliance_ruleset_rule_list_request(self, rule_id: int) -> dict[str, Any]: """Get rule details (get rule logic hash). Args: rule_id (int): The Ruleset ID. Returns: Dict[str, Any]: API response from Dome9. """ return self._http_request("GET", f"Compliance/Ruleset/{rule_id}") def security_group_attach_request( self, instance_id: str, sg_id: str, nic_name: str, ) -> dict[str, Any]: """Attach security Group to an AWS EC2 Instance. Args: instance_id (str): AWS Instance ID. sg_id (str): AWS security group ID. nic_name (str): The instance niCs name. Returns: Dict[str, Any]: API response from Dome9. """ data = {"groupid": sg_id, "nicname": nic_name} response = self._http_request("POST", f"cloudinstance/{instance_id}/sec-groups", json_data=data) return response def instance_list_request(self, instance_id: str) -> dict[str, Any]: """Get an AWS EC2 Instances list. Args: instance_id (str): AWS Instance ID. Returns: Dict[str, Any]: API response from Dome9. """ url_prefix = create_url_prefix(instance_id) response = self._http_request("GET", f"cloudinstance{url_prefix}") return response def security_group_service_delete_request(self, sg_id: str, service_id: str) -> str: """Delete security group service by ID. Args: sg_id (str): Security group ID. service_id (str): Service ID. Returns: Dict[str, Any]: API response from Dome9. """ response = self._http_request("DELETE", f"cloudsecuritygroup/{sg_id}/services/Inbound/{service_id}", resp_type="text") return response def security_group_tags_update_request(self, sg_id: str, key: str, value: str) -> dict[str, Any]: """Create and Update a security group tag. Args: sg_id (str): Security group ID. key (str): The tag key to add. value (str): The tag value to add. Returns: Dict[str, Any]: API response from Dome9. """ data = {"tags": {key: value}} response = self._http_request("POST", f"cloudsecuritygroup/{sg_id}/tags", json_data=data) return response def security_group_service_create_request( self, sg_id: str, name: str, protocol_type: str, port: int, policy_type: str = None, open_for_all: bool = None, description: str = None, data_id: str = None, data_name: str = None, scope_type: str = None, is_valid: bool = None, inbound: bool = None, icmptype: str = None, icmpv6type: str = None, ) -> dict[str, Any]: """Create new security group service. Args: sg_id (str): AWS Security group ID. name (str): Service name. protocol_type (str): The Service protocol type. port (int): The service port, indicates a port range. open_for_all (bool, optional): Indicates if the service is open to all ports. Defaults to None. description (str, optional): Service description. Defaults to None. data_id (str, optional): IP List ID to attach. Defaults to None. data_name (str, optional): IP List name to attach. Defaults to None. scope_type (str, optional): Scope type (CIDR / IPList) to attach. Defaults to None. is_valid (bool, optional): _description_. Defaults to None. inbound (bool, optional): _description_. Defaults to None. icmptype (str, optional): ICMP type (when protocol is ICMP). Defaults to None. icmpv6type (str, optional): ICMP V6 type (when protocol is ICMPV6). Defaults to None. Returns: Dict[str, Any]: API response from Dome9. """ data = remove_empty_elements( { "description": description, "icmpType": icmptype, "icmpv6Type": icmpv6type, "inbound": inbound, "name": name, "openForAll": open_for_all, "port": port, "protocolType": protocol_type, "scope": [{"data": {"id": data_id, "name": data_name}, "isValid": is_valid, "type": scope_type}], } ) response = self._http_request("POST", f"cloudsecuritygroup/{sg_id}/services/{policy_type}", json_data=data) return response def security_group_service_update_request( self, sg_id: str, service_name: str, protocol_type: str, port: int, policy_type: str, open_for_all: bool = None, description: str = None, data_id: str = None, data_name: str = None, scope_type: str = None, is_valid: bool = None, inbound: bool = None, icmptype: str = None, icmpv6type: str = None, ) -> dict[str, Any]: """Update security group service. Args: sg_id (str): AWS Security group ID. service_name (str): Service name. protocol_type (str): The Service protocol type. port (int): The service port, indicates a port range. open_for_all (bool, optional): Indicates if the service is open to all ports. Defaults to None. description (str, optional): Service description. Defaults to None. data_id (str, optional): IP List ID to attach. Defaults to None. data_name (str, optional): IP List name to attach. Defaults to None. scope_type (str, optional): Scope type (CIDR / IPList) to attach. Defaults to None. is_valid (bool, optional): _description_. Defaults to None. inbound (bool, optional): _description_. Defaults to None. icmptype (str, optional): ICMP type (when protocol is ICMP). Defaults to None. icmpv6type (str, optional): ICMP V6 type (when protocol is ICMPV6). Defaults to None. Returns: Dict[str, Any]: API response from Dome9. """ data = remove_empty_elements( { "description": description, "icmpType": icmptype, "icmpv6Type": icmpv6type, "inbound": inbound, "name": service_name, "openForAll": open_for_all, "port": port, "protocolType": protocol_type, "scope": [{"data": {"id": data_id, "name": data_name}, "isValid": is_valid, "type": scope_type}], } ) response = self._http_request("PUT", f"cloudsecuritygroup/{sg_id}/services/{policy_type}", json_data=data) return response def security_group_instance_detach_request( self, instance_id: str, sg_id: str, nic_name: str, ) -> dict[str, Any]: """Detach security Group from an AWS EC2 Instance. Args: instance_id (str): AWS Instance ID. sg_id (str): AWS security group ID. nic_name (str): The instance niCs name. Returns: Dict[str, Any]: API response from Dome9. """ data = {"groupid": sg_id, "nicname": nic_name} response = self._http_request("DELETE", f"cloudinstance/{instance_id}/sec-groups", json_data=data) return response def protection_mode_update_request(self, sg_id: str, protection_mode: str) -> dict[str, Any]: """Change the protection mode for an AWS security group (FullManage or ReadOnly). Args: sg_id (str): The security group ID. protection_mode (str): The protection mode to update. Returns: Dict[str, Any]: API response from Dome9. """ data = {"protectionMode": protection_mode} response = self._http_request("POST", f"cloudsecuritygroup/{sg_id}/protection-mode", json_data=data) return response def cloud_accounts_list_request(self, account_id: str = None) -> dict[str, Any]: """Get cloud accounts list. Returns: Dict[str, Any]: API response from Dome9. """ url_prefix = create_url_prefix(account_id) # type: ignore[arg-type] response = self._http_request("GET", f"CloudAccounts{url_prefix}") return response def check_ip_list_security_group_attach_request(self, sg_id: str = None) -> dict[str, Any]: """Get AWS cloud accounts for a specific security group and region and check if there is an IP-list that attach to a security group. Returns: Dict[str, Any]: API response from Dome9. """ url_prefix = create_url_prefix(sg_id) # type: ignore[arg-type] response = self._http_request("GET", f"CloudSecurityGroup{url_prefix}") return response def security_group_list_request(self) -> dict[str, Any]: """Get security group list. Returns: Dict[str, Any]: API response from Dome9. """ response = self._http_request("GET", "AwsSecurityGroup") return response def global_search_get_request(self) -> dict[str, Any]: """Get top results for each service. Returns: Dict[str, Any]: API response from Dome9. """ params = {"freeText": "String"} response = self._http_request("GET", "GlobalSearch", params=params) return response def cloud_trail_get_request(self) -> dict[str, Any]: """Get Cloud Trail events for a Dome9 user. Returns: Dict[str, Any]: API response from Dome9. """ response = self._http_request("GET", "CloudTrail") return response def findings_bundle_get_request(self, bundle_id: str, rule_logic_hash: str) -> dict[str, Any]: """Get the findings for a specific rule in a bundle, for all of the user's accounts. Args: bundle_id (str): The bundle ID. rule_logic_hash (str): MD5 hash of the rule GSL string. Returns: Dict[str, Any]: API response from Dome9. """ params = {"ruleLogicHash": rule_logic_hash, "pageSize": "100", "pageNumber": "1"} response = self._http_request("GET", f"Compliance/Finding/bundle/{bundle_id}", params=params) return response def finding_get_request(self, finding_id: str) -> dict[str, Any]: """Get a findings by its ID. Args: finding_id (str): The findings ID. Returns: Dict[str, Any]: API response from Dome9. """ response = self._http_request("GET", f"Compliance/Finding/{finding_id}") return response def organizational_unit_view_get_request(self) -> dict[str, Any]: """Get organizational unit view entities. Returns: Dict[str, Any]: API response from Dome9. """ response = self._http_request("GET", "organizationalunit/view") return response def organizational_unit_flat_get_request(self) -> dict[str, Any]: """Get all organizational units flat. Returns: Dict[str, Any]: API response from Dome9. """ response = self._http_request("GET", "organizationalunit/GetFlatOrganizationalUnits") return response def organizational_unit_get_request(self, unit_id: str) -> dict[str, Any]: """Get an organizational unit by its ID. Args: unit_id (str): The organizational unit ID. Returns: Dict[str, Any]: API response from Dome9. """ url_prefix = create_url_prefix(unit_id) response = self._http_request("GET", f"OrganizationalUnit{url_prefix}") return response def attach_comment_to_ip(ip_list: List[str], comment_list: List[str], description: str = None) -> List: """Insure comment_list has the same length as ip_list and description or ip is specified. Args: ip_list (_type_): The IP list. comment_list (_type_): The comment list. description (_type_): List description. Raises: ValueError: Description or ip must be provided. Returns: List: Items List. """ items = [] if ip_list: while len(ip_list) > len(comment_list): comment_list.append("") for ip, comment in zip(ip_list, comment_list): items.append({"ip": ip, "comment": comment}) else: if not description: raise ValueError("description or ip must be provided.") return items def validate_pagination_arguments(page: int = None, page_size: int = None, limit: int = None): """Validate pagination arguments according to their default. Args: page (int, optional): Page number of paginated results. page_size (int, optional): Number of ip-list per page. limit (int, optional): The maximum number of records to retrieve. Raises: ValueError: Appropriate error message. """ if page_size and (page_size < 1 or page_size > 50): raise ValueError("page size argument must be greater than 1 and smaller than 50.") if page and page < 1: raise ValueError("page argument must be greater than 0.") if limit and (limit < 1 or limit > 50): raise ValueError("limit argument must be greater than 1.") def pagination(response: dict, args: dict[str, Any]) -> tuple: """Executing Manual Pagination (using the page and page size arguments) or Automatic Pagination (display a number of total results). Args: response (dict): API response. page (int, optional): Page number of paginated results. page_size (int, optional): Number of ip-list per page. limit (int, optional): The maximum number of records to retrieve. Returns: dict: output and pagination message for Command Results. """ page = arg_to_number(args.get("page")) page_size = arg_to_number(args.get("page_size")) limit = arg_to_number(args.get("limit")) validate_pagination_arguments(page, page_size, limit) # type: ignore[arg-type] output = response if page and page_size: if page_size < len(response): first_item = page_size * (page - 1) output = response[first_item : first_item + page_size] else: output = response[:page_size] pagination_message = f"Showing page {page}. \n Current page size: {page_size}" else: output = response[:limit] pagination_message = f"Showing {len(output)} rows out of {len(response)}." return output, pagination_message def arg_to_boolean(arg: str) -> Optional[bool]: """Retrieve arg boolean value if it's not none. Args: arg (str): Boolean argument. Returns: Optional[bool]: The argument boolean value. """ return argToBoolean(arg) if arg else None def get_service_type_and_data(service: list) -> list: """Get security group service type and data. Args: service (list): Inbound or Outbound service. Returns: str: service type and data. """ service_type = service_data = service_scope = "" if service: service_scope = service[0]["scope"] if service_scope: service_type = service_scope[0]["type"] # type: ignore[index] service_data = service_scope[0]["data"] # type: ignore[index] return service_type, service_data # type: ignore[return-value] def create_url_prefix(path_variable: str) -> str: """Create url prefix for request. Args: path_variable (str): The path variable. Returns: str: URL prefix. """ url_prefix = f"/{path_variable}" if path_variable else "" return url_prefix def create_sg_list(fix_output: list) -> list: """Create Security Group list according to a general template. Args: fix_output (list): Security group list to edit. Returns: list: A new Security Group list according to function format. """ security_group_list = [] for sg in fix_output: inbound_services = sg["services"]["inbound"] inbound_services_type, inbound_services_data = get_service_type_and_data(inbound_services) outbound_services = sg["services"]["outbound"] outbound_services_type, outbound_services_data = get_service_type_and_data(outbound_services) security_group_list.append( { "cloud_account_id": sg["cloudAccountId"], "cloud_account_name": sg["cloudAccountName"], "region_id": sg["regionId"], "security_group_external_id": sg["externalId"], "security_group_id": sg["securityGroupId"], "security_group_name": sg["securityGroupName"], "isProtected": sg["isProtected"], "inbound_scope_type": inbound_services_type, "inbound_scope_data": inbound_services_data, "outbound_scope_type": outbound_services_type, "outbound_scope_data": outbound_services_data, "description": sg["description"], "vpc_id": sg["vpcId"], } ) return security_group_list def access_lease_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get a access lease list. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.access_lease_list_request() output = response["aws"] fix_output, pagination_message = pagination(output, args) readable_output = tableToMarkdown( name="Access Lease:", metadata=pagination_message, t=fix_output, headers=["id", "name", "ip", "user", "region", "length", "created"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.AccessLease", outputs_key_field="id", outputs=output, raw_response=response, ) return command_results def access_lease_delete_command(client: Client, args: dict[str, Any]) -> CommandResults: """Delete access lease by ID. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ lease_id = args.get("lease_id") response = client.access_lease_delete_request(lease_id) # type: ignore[arg-type] command_results = CommandResults( readable_output="Access Lease Deleted successfully", outputs_prefix="CheckPointDome9.AccessLease", outputs_key_field="", outputs=response, raw_response=response, ) return command_results def access_lease_invitation_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get a specific lease invitation. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ invitation_id = args.get("invitation_id") response = client.access_lease_invitation_list_request(invitation_id) # type: ignore[arg-type] fix_output, pagination_message = pagination(response, args) readable_output = tableToMarkdown( name="Access Lease invitation", metadata=pagination_message, t=fix_output, headers=["id", "issuerName", "recipientName", "length", "created"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.AccessLease.Invitation", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def access_lease_invitation_delete_command(client: Client, args: dict[str, Any]) -> CommandResults: """Delete a lease invitation. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ invitation_id = args.get("invitation_id") response = client.access_lease_invitation_delete_request(invitation_id) # type: ignore[arg-type] command_results = CommandResults( readable_output="Access Lease Invitation Deleted successfully", outputs_prefix="CheckPointDome9.AccessLease.Invitation", outputs_key_field="", outputs=response, raw_response=response, ) return command_results def findings_search_command(client: Client, args: dict[str, Any]) -> CommandResults: """Search findings for the account. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ severity = argToList(args.get("severity")) acknowledged = arg_to_boolean(args.get("acknowledged")) # type: ignore[arg-type] entity_type = argToList(args.get("entity_type")) region = argToList(args.get("region")) page_size = arg_to_number(args.get("limit")) response = client.findings_search_request( page_size, # type: ignore severity, region, entity_type, # type: ignore[arg-type] acknowledged, ) # type: ignore[arg-type] output = response["findings"] fix_output, pagination_message = pagination(output, args) readable_output = tableToMarkdown( name="Findings:", metadata=pagination_message, t=fix_output, headers=["id", "alertType", "severity", "region", "status", "action", "cloudAccountId", "description"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.Finding", outputs_key_field="id", outputs=fix_output, raw_response=output, ) return command_results def ip_list_create_command(client: Client, args: dict[str, Any]) -> CommandResults: """Create a new IP-list. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ name = args.get("name") description = args.get("description") ip_list = argToList(args.get("ip")) comment_list = argToList(args.get("comment")) # insure comment_list has the same length as ip_list items = attach_comment_to_ip(ip_list, comment_list, description) # type: ignore[arg-type] response = client.ip_list_create_request(name, description, items) # type: ignore[arg-type] command_results = CommandResults( readable_output="IP list created successfully", outputs_prefix="CheckPointDome9.IpList", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def ip_list_update_command(client: Client, args: dict[str, Any]) -> CommandResults: """Update IP list (description or items). Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ list_id = args.get("list_id") description = args.get("description") update_mode = args.get("update_mode", "add_new_items") ip_list = argToList(args.get("ip")) comment_list = argToList(args.get("comment")) # insure comment_list has the same length as ip_list items = attach_comment_to_ip(ip_list, comment_list, description) # type: ignore[arg-type] # This command replace items. To make the command update the list # we first get the old items if update_mode == "add_new_items": old_items = client.ip_list_get_request(list_id=list_id) # type: ignore[arg-type] items += old_items.get("items") # type: ignore[arg-type] response = client.ip_list_update_request(list_id, description, items) # type: ignore[arg-type] command_results = CommandResults( readable_output="IP list updated successfully", outputs_prefix="CheckPointDome9.IpList", outputs_key_field="", outputs=response, raw_response=response, ) return command_results def ip_list_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """List all IP Lists or Get individual by list ID. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ list_id = args.get("list_id") response = client.ip_list_get_request(list_id) # type: ignore[arg-type] if isinstance(response, dict): response = [response] # type: ignore ip_lists = [] for ip_list in response: items = [item["ip"] for item in ip_list["items"]] # type: ignore[index] item = { "id": ip_list["id"], # type: ignore[index] "items": items, "name": ip_list["name"], # type: ignore[index] "description": ip_list["description"], # type: ignore[index] } ip_lists.append(item) readable_output = tableToMarkdown( name="IP list", t=ip_lists, headers=["id", "name", "items", "description"], headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.IpList", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def ip_list_delete_command(client: Client, args: dict[str, Any]) -> CommandResults: """Delete list by list ID. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ list_id = args.get("list_id") response = client.ip_list_delete_request(list_id) # type: ignore[arg-type] command_results = CommandResults( readable_output="IP list deleted successfully", outputs_prefix="CheckPointDome9.IpList", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def ip_list_metadata_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get IP address metadata. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ output = client.ip_list_metadata_list_request() fix_output, pagination_message = pagination(output, args) readable_output = tableToMarkdown( name="IP List metadata", metadata=pagination_message, t=fix_output, headers=["id", "name", "cidr", "classification"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.IpList.Metadata", outputs_key_field="id", outputs=output, raw_response=output, ) return command_results def ip_list_metadata_create_command(client: Client, args: dict[str, Any]) -> CommandResults: """Add a new IP address metadata. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ cidr = args.get("cidr") name = args.get("name") classification = args.get("classification") response = client.ip_list_metadata_create_request(cidr, name, classification) # type: ignore[arg-type] readable_output = tableToMarkdown( name="IP List metadata created successfully", t=response, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.IpList.Metadata", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def ip_list_metadata_update_command(client: Client, args: dict[str, Any]) -> CommandResults: """Update IP address metadata. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ list_metadata_id = args.get("list_metadata_id") classification = args.get("classification") name = args.get("name") response = client.ip_list_metadata_update_request(list_metadata_id, classification, name) # type: ignore[arg-type] readable_output = tableToMarkdown( name="IP List metadata updated successfully", t=response, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.IpList.Metadata", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def ip_list_metadata_delete_command(client: Client, args: dict[str, Any]) -> CommandResults: """Delete IP address metadata. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ account_id = args.get("account_id") address = args.get("address") mask = args.get("mask") response = client.ip_list_metadata_delete_request(account_id, address, mask) # type: ignore[arg-type] command_results = CommandResults( readable_output="IP List metadata deleted successfully", outputs_prefix="CheckPointDome9.IpList.Metadata", outputs_key_field="", outputs=response, raw_response=response, ) return command_results def compliance_remediation_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get a list of remediations for the account. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.compliance_remediation_get_request() readable_output = tableToMarkdown( name="Compliance remediation:", t=response, headers=["id", "ruleLogicHash", "rulesetId", "platform", "comment", "cloudBots"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.ComplianceRemediation", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def compliance_remediation_create_command(client: Client, args: dict[str, Any]) -> CommandResults: """Add a new remediation. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ ruleset_id = arg_to_number(args.get("ruleset_id")) rule_logic_hash = args.get("rule_logic_hash") comment = args.get("comment") cloudbots = argToList(args.get("cloudbots")) response = client.compliance_remediation_create_request( ruleset_id, # type: ignore rule_logic_hash, # type: ignore comment, # type: ignore[arg-type] cloudbots, ) readable_output = tableToMarkdown( name="Remediation created successfully", t=response, headers=["id", "ruleLogicHash", "rulesetId", "platform", "comment", "cloudBots"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.ComplianceRemediation", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def compliance_remediation_update_command(client: Client, args: dict[str, Any]) -> CommandResults: """Update a remediation. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ remediation_id = args.get("remediation_id") ruleset_id = arg_to_number(args.get("ruleset_id")) comment = args.get("comment") cloudbots = argToList(args.get("cloudbots")) rule_logic_hash = args.get("rule_logic_hash") response = client.compliance_remediation_update_request( remediation_id, # type: ignore ruleset_id, # type: ignore[arg-type] rule_logic_hash, # type: ignore comment, # type: ignore cloudbots, # type: ignore ) # type: ignore[arg-type] readable_output = tableToMarkdown( name="Remediation updated successfully", t=response, headers=["id", "ruleLogicHash", "rulesetId", "platform", "comment", "cloudBots"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.ComplianceRemediation", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def compliance_remediation_delete_command(client: Client, args: dict[str, Any]) -> CommandResults: """Delete a remediation. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ remediation_id = args.get("remediation_id") response = client.compliance_remediation_delete_request(remediation_id) # type: ignore[arg-type] command_results = CommandResults( readable_output="Remediation deleted successfully", outputs_prefix="CheckPointDome9.ComplianceRemediation", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def compliance_ruleset_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get all rulesets for the account. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.compliance_ruleset_list_request() fix_output, pagination_message = pagination(response, args) readable_output = tableToMarkdown( name="Compliance Ruleset:", metadata=pagination_message, t=fix_output, headers=["accountId", "id", "name", "description"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.ComplianceRuleset", outputs_key_field="id", outputs=fix_output, raw_response=response, ) return command_results def compliance_ruleset_rule_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get all rulesets for the account (get rule logic hash for create remediation). Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ rule_id = args.get("rule_id") response = client.compliance_ruleset_rule_list_request(rule_id) # type: ignore[arg-type] output = response["rules"] fix_output, pagination_message = pagination(output, args) readable_output = tableToMarkdown( name="Compliance Ruleset Rules:", metadata=pagination_message, t=fix_output, headers=["name", "severity", "description", "logic", "logicHash"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.ComplianceRuleset.Rule", outputs_key_field="name", outputs=fix_output, raw_response=response, ) return command_results def security_group_instance_attach_command(client: Client, args: dict[str, Any]) -> CommandResults: """Attach security Group to an AWS EC2 Instance. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ instance_id = args.get("instance_id") sg_id = args.get("sg_id") nic_name = args.get("nic_name") try: response = client.security_group_attach_request(instance_id, sg_id, nic_name) # type: ignore[arg-type] except Exception: raise ValueError("Security group already attached") command_results = CommandResults( readable_output="Security group attach successfully", outputs_prefix="CheckPointDome9.Instance", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def security_group_service_delete_command(client: Client, args: dict[str, Any]) -> CommandResults: """Delete a service from an AWS security group. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ sg_id = args.get("sg_id") service_id = args.get("service_id") response = client.security_group_service_delete_request(sg_id, service_id) # type: ignore[arg-type] command_results = CommandResults( readable_output="Service deleted successfully", outputs_prefix="CheckPointDome9.SecurityGroup.Service", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def security_group_tags_update_command(client: Client, args: dict[str, Any]) -> CommandResults: """Update the list of tags for an AWS security group. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ sg_id = args.get("sg_id") key = args.get("key") value = args.get("value") response = client.security_group_tags_update_request(sg_id, key, value) # type: ignore[arg-type] readable_output = tableToMarkdown(name="Tag updated successfully", t=response, headerTransform=string_to_table_header) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.SecurityGroup.Tag", outputs_key_field="key", outputs=response, raw_response=response, ) return command_results def security_group_service_create_command(client: Client, args: dict[str, Any]) -> CommandResults: """Create a new Service (rule) for the security group. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ sg_id = args.get("sg_id") # mandatory name = args.get("name") # mandatory protocol_type = args.get("protocol_type") # mandatory port = arg_to_number(args.get("port")) # mandatory policy_type = args.get("policy_type") open_for_all = arg_to_boolean(args.get("open_for_all")) # type: ignore[arg-type] description = args.get("description") data_id = args.get("data_id") data_name = args.get("data_name") scope_type = args.get("type") is_valid = args.get("is_valid") inbound = arg_to_boolean(args.get("inbound")) # type: ignore[arg-type] icmptype = args.get("icmptype") icmpv6type = args.get("icmpv6type") response = client.security_group_service_create_request( sg_id, # type: ignore name, # type: ignore protocol_type, # type: ignore port, # type: ignore[arg-type] policy_type, open_for_all, description, # type: ignore[arg-type] data_id, data_name, scope_type, # type: ignore[arg-type] is_valid, inbound, icmptype, icmpv6type, ) # type: ignore[arg-type] sg_service = [ { "id": response["id"], "name": response["name"], "protocol Type": response["protocolType"], "port": response["port"], "description": response["description"], "security Group ID": sg_id, } ] readable_output = tableToMarkdown( name="Security group service created successfully", t=sg_service, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.SecurityGroup.Service", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def security_group_service_update_command(client: Client, args: dict[str, Any]) -> CommandResults: """Update a service (rule) for an AWS security group. Can update only port and name. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ sg_id = args.get("sg_id") policy_type = args.get("policy_type") service_name = args.get("service_name") protocol_type = args.get("protocol_type") port = arg_to_number(args.get("port")) open_for_all = args.get("open_for_all") description = args.get("description") data_id = args.get("data_id") data_name = args.get("data_name") scope_type = args.get("scope_type") is_valid = args.get("is_valid") inbound = args.get("inbound") icmptype = args.get("icmptype") icmpv6type = args.get("icmpv6type") response = client.security_group_service_update_request( sg_id, # type: ignore service_name, # type: ignore protocol_type, # type: ignore[arg-type] port, # type: ignore policy_type, # type: ignore open_for_all, # type: ignore[arg-type] description, data_id, data_name, # type: ignore[arg-type] scope_type, is_valid, inbound, icmptype, # type: ignore[arg-type] icmpv6type, ) # type: ignore[arg-type] sg_service = [ { "id": response["id"], "name": response["name"], "protocol Type": response["protocolType"], "port": response["port"], "description": response["description"], "security Group ID": sg_id, # 'scopeType': response['scope'][0]['type'], # 'scopeData': f"{response['scope'][0]['data']['id']} - {response['scope'][0]['data']['name']}", } ] readable_output = tableToMarkdown( name="Security group service updated successfully", t=sg_service, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.SecurityGroup.Service", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def security_group_instance_detach_command(client: Client, args: dict[str, Any]) -> CommandResults: """Detach security Group from an AWS EC2 Instance. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ instance_id = args.get("instance_id") sg_id = args.get("sg_id") nic_name = args.get("nic_name") try: response = client.security_group_instance_detach_request(instance_id, sg_id, nic_name) # type: ignore[arg-type] except Exception: raise ValueError("Security group already detached") command_results = CommandResults( readable_output="Security group detach successfully", outputs_prefix="CheckPointDome9.Instance", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def security_group_protection_mode_update_command(client: Client, args: dict[str, Any]) -> CommandResults: """Change the protection mode for an AWS security group (FullManage or ReadOnly). Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ protection_mode = args.get("protection_mode") sg_id = args.get("sg_id") response = client.protection_mode_update_request(sg_id, protection_mode) # type: ignore[arg-type] security_group_list = create_sg_list([response]) readable_output = tableToMarkdown( name="protection mode updated for security group :", t=security_group_list, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.SecurityGroup", outputs_key_field="security_group_id", outputs=security_group_list, raw_response=response, ) return command_results def cloud_accounts_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get cloud account list. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ account_id = args.get("account_id") response = client.cloud_accounts_list_request(account_id) # type: ignore[arg-type] if account_id: fix_output, pagination_message = response, "" else: fix_output, pagination_message = pagination(response, args) readable_output = tableToMarkdown( name="Cloud accounts:", metadata=pagination_message, headers=["id", "vendor", "externalAccountNumber", "creationDate", "organizationalUnitName"], t=fix_output, headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.CloudAccount", outputs_key_field="cloud_account_id", outputs=response, raw_response=response, ) return command_results def instance_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get AWS instances. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ instance_id = args.get("instance_id") response = client.instance_list_request(instance_id) # type: ignore[arg-type] fix_output, pagination_message = pagination(response, args) instance_list = [] for instance in fix_output: instance_list.append( { "account ID": instance["accountId"], "instance_id": instance["externalId"], "nics name": instance["nics"][0]["name"], "instance type": instance["instanceType"], "region": instance["region"], "image": instance["image"], "cloud account ID": instance["cloudAccountId"], } ) readable_output = tableToMarkdown( name="AWS instances", metadata=pagination_message, t=instance_list, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.Instance", outputs_key_field="instance_id", outputs=response, raw_response=response, ) return command_results def check_ip_list_security_group_attach_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get AWS cloud accounts for a specific security group and region and check if there is an IP-list that attach to a security group. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ sg_id = args.get("sg_id") response = client.check_ip_list_security_group_attach_request(sg_id) # type: ignore[arg-type] fix_output, pagination_message = pagination(response, args) security_group_list = create_sg_list(fix_output) readable_output = tableToMarkdown( name="Security Groups:", metadata=pagination_message, t=security_group_list, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.SecurityGroup", outputs_key_field="security_group_id", outputs=security_group_list, raw_response=response, ) return command_results def security_group_list_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get all security group Entities. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.security_group_list_request() fix_output, pagination_message = pagination(response, args) security_group_list = [] for sg in fix_output: security_group_list.append( { "cloud_account_id": sg["cloudAccountId"], "region_id": sg["regionId"], "security_group_id": sg["externalId"], "security_group_name": sg["securityGroupName"], "vpc_id": sg["vpcId"], } ) readable_output = tableToMarkdown( name="Security Groups:", metadata=pagination_message, t=security_group_list, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.SecurityGroup", outputs_key_field="security_group_id", outputs=response, raw_response=response, ) return command_results def global_search_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get top results for each service. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.global_search_get_request() output = response["alerts"] alerts = [] for alert in output: alerts.append( { "id": alert["id"], "createdTime": alert["createdTime"], "updatedTime": alert["updatedTime"], "cloudAccountId": alert["cloudAccountId"], "cloudAccountExternalId": alert["cloudAccountExternalId"], "bundleId": alert["bundleId"], "alertType": alert["alertType"], "severity": alert["severity"], "entityName": alert["entityName"], "ruleName": alert["ruleName"], "description": alert["description"], "remediation": alert["remediation"], } ) readable_output = tableToMarkdown(name="Global Search", t=alerts, headerTransform=string_to_table_header) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.GlobalSearch.Alert", outputs_key_field="id", outputs=alerts, raw_response=response, ) return command_results def cloud_trail_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get CloudTrail events for a Dome9 user. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.cloud_trail_get_request() cloud_trail = response[0] # type: ignore[index] cloud_trail_output = [] cloud_trail_output.append( { "name": cloud_trail["name"], "id": cloud_trail["id"], "region": cloud_trail["region"], "accountId": cloud_trail["accountId"], "s3BucketName": cloud_trail["s3BucketName"], } ) readable_output = tableToMarkdown(name="Cloud Trail", t=cloud_trail_output, headerTransform=string_to_table_header) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.CloudTrail", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def findings_bundle_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get the findings for a specific rule in a bundle, for all of the user's accounts. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ bundle_id = arg_to_number(args.get("bundle_id")) rule_logic_hash = args.get("rule_logic_hash") response = client.findings_bundle_get_request(bundle_id, rule_logic_hash) # type: ignore[arg-type] readable_output = tableToMarkdown(name="Findings Bundle", t=response, headerTransform=string_to_table_header) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.FindingBundle", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def organizational_unit_view_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get organizational unit view entities. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.organizational_unit_view_get_request() readable_output = tableToMarkdown(name="Organizational Unit View", t=response, headerTransform=string_to_table_header) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.OrganizationalUnitView", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def organizational_unit_flat_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get organizational unit view entities. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ response = client.organizational_unit_flat_get_request() fix_output, pagination_message = pagination(response, args) readable_output = tableToMarkdown( name="Organizational Unit Flat", metadata=pagination_message, t=fix_output, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.OrganizationalUnitFlat", outputs_key_field="id", outputs=fix_output, raw_response=response, ) return command_results def organizational_unit_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get an organizational unit by its ID. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ unit_id = args.get("unit_id") response = client.organizational_unit_get_request(unit_id) # type: ignore[arg-type] output = response[0]["item"] # type: ignore[index] organizational_unit_list = [] organizational_unit_list.append( { "accountId": output["accountId"], "id": output["id"], "name": output["name"], "created": output["created"], "updated": output["updated"], "isRoot": output["isRoot"], "awsCloudAcountsCount": output["awsCloudAcountsCount"], } ) readable_output = tableToMarkdown( name="Organizational Unit", t=organizational_unit_list, headerTransform=string_to_table_header ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.OrganizationalUnit", outputs_key_field="id", outputs=output, raw_response=response, ) return command_results def finding_get_command(client: Client, args: dict[str, Any]) -> CommandResults: """Get a findings by its ID. Args: client (Client): Dome9 API client. args (Dict[str, Any]): Command arguments from XSOAR. Returns: CommandResults: outputs, readable outputs and raw response for XSOAR. """ finding_id = args.get("finding_id") response = client.finding_get_request(finding_id) # type: ignore[arg-type] readable_output = tableToMarkdown( name="Findings:", t=response, headers=["id", "alertType", "severity", "region", "status", "action", "cloudAccountId", "description"], headerTransform=string_to_table_header, ) command_results = CommandResults( readable_output=readable_output, outputs_prefix="CheckPointDome9.Finding", outputs_key_field="id", outputs=response, raw_response=response, ) return command_results def parse_incident(alert: dict) -> dict: """ Parse alert to XSOAR Incident. Args: alert (dict): alert item. Returns: dict: XSOAR Incident. """ alert_date = datetime.strptime(alert.get("createdTime"), TIME_FORMAT) # type: ignore[arg-type] iso_time = FormatIso8601(alert_date) + "Z" incident = { "name": "Dome9 Alert ID: " + alert.get("id"), # type: ignore[arg-type,operator] "occurred": iso_time, "rawJSON": json.dumps(alert), } return incident def fetch_incidents(client: Client, args: dict) -> None: """This function retrieves new alerts every interval (default is 1 minute). This function has to implement the logic of making sure that incidents are fetched only onces and no incidents are missed. By default it's invoked by XSOAR every minute. It will use last_run to save the timestamp of the last alert it processed. If last_run is not provided, it should use the integration parameter first_fetch to determine when to start fetching the first time. Args: client (Client): The API client. args (dict): The args for fetch: alert types, alert severities, alert status, max fetch and first fetch. """ last_run = demisto.getLastRun() last_run_id = last_run.get("id") last_run_time = last_run.get("time") if not last_run: last_run_time = args.get("first_fetch", "3 Days") max_fetch = args.get("max_fetch") else: max_fetch = arg_to_number(args.get("max_fetch")) alert_severity = argToList(args.get("alert_severity")) alert_region = argToList(args.get("alert_region")) first_fetch = arg_to_datetime(arg=last_run_time, arg_name="First fetch time", required=True) first_fetch_timestamp = int(first_fetch.timestamp()) if first_fetch else None assert isinstance(first_fetch_timestamp, int) alert_list = client.findings_search_request(max_fetch, alert_severity, alert_region) # type: ignore[arg-type] incidents = [] # convert the last_run_time to dome9 time format last_run_datetime = dateparser.parse(last_run_time) last_run_str = last_run_datetime.strftime(TIME_FORMAT) # type: ignore[union-attr] last_run_datetime = dateparser.parse(last_run_str) for alert in alert_list["findings"]: alert_time = dateparser.parse(alert["createdTime"]) if alert.get("id") != last_run_id and last_run_datetime < alert_time: # type: ignore[return-value,operator] incidents.append(parse_incident(alert)) demisto.incidents(incidents) if incidents: last_run_time = alert["createdTime"] last_run_id = alert["id"] demisto.setLastRun({"time": last_run_time, "id": last_run_id}) def test_module(client: Client) -> None: try: client.access_lease_list_request() except DemistoException as e: if "password" in str(e): return "Authorization Error: make sure API key ID & secret are correctly set" # type: ignore[return-value] else: raise e return "ok" # type: ignore[return-value] def main() -> None: params: dict[str, Any] = demisto.params() args: dict[str, Any] = demisto.args() base_url = params.get("base_url") key_id = params.get("api_key_id") key_secret = params.get("api_key_secret") api_key_id_cred = params.get("api_key_id_cred", {}).get("password") api_key_secret_cred = params.get("api_key_secret_cred", {}).get("password") # get the api key and secret credentials key_id = api_key_id_cred or key_id key_secret = api_key_secret_cred or key_secret # validate the api key and secret credentials if not key_id: raise ValueError("Please provide a valid API key ID.") if not key_secret: raise ValueError("Please provide a valid API key secret.") verify_certificate: bool = not params.get("insecure", False) proxy = params.get("proxy", False) command = demisto.command() demisto.debug(f"Command being called is {command}") commands = { "dome9-access-lease-list": access_lease_list_command, "dome9-access-lease-delete": access_lease_delete_command, "dome9-access-lease-invitation-list": access_lease_invitation_list_command, "dome9-access-lease-invitation-delete": access_lease_invitation_delete_command, "dome9-findings-search": findings_search_command, "dome9-ip-list-create": ip_list_create_command, "dome9-ip-list-update": ip_list_update_command, "dome9-ip-list-get": ip_list_get_command, "dome9-ip-list-delete": ip_list_delete_command, "dome9-ip-list-metadata-list": ip_list_metadata_list_command, "dome9-ip-list-metadata-create": ip_list_metadata_create_command, "dome9-ip-list-metadata-update": ip_list_metadata_update_command, "dome9-ip-list-metadata-delete": ip_list_metadata_delete_command, "dome9-compliance-remediation-get": compliance_remediation_get_command, "dome9-compliance-remediation-create": compliance_remediation_create_command, "dome9-compliance-remediation-update": compliance_remediation_update_command, "dome9-compliance-remediation-delete": compliance_remediation_delete_command, "dome9-compliance-ruleset-list": compliance_ruleset_list_command, "dome9-compliance-ruleset-rule-list": compliance_ruleset_rule_list_command, "dome9-security-group-instance-attach": security_group_instance_attach_command, "dome9-security-group-service-delete": security_group_service_delete_command, "dome9-security-group-tags-update": security_group_tags_update_command, "dome9-security-group-service-create": security_group_service_create_command, "dome9-security-group-service-update": security_group_service_update_command, "dome9-security-group-instance-detach": security_group_instance_detach_command, "dome9-security-group-protection-mode-update": security_group_protection_mode_update_command, "dome9-cloud-accounts-list": cloud_accounts_list_command, "dome9-security-group-ip-list-details-get": check_ip_list_security_group_attach_command, "dome9-security-group-list": security_group_list_command, "dome9-instance-list": instance_list_command, "dome9-findings-get": finding_get_command, "dome9-organizational-unit-get": organizational_unit_get_command, "dome9-organizational-unit-flat-get": organizational_unit_flat_get_command, "dome9-organizational-unit-view-get": organizational_unit_view_get_command, "dome9-findings-bundle-get": findings_bundle_get_command, "dome9-cloud-trail-get": cloud_trail_get_command, "dome9-global-search-get": global_search_get_command, } try: client: Client = Client( base_url, # type: ignore key_id, key_secret, proxy, # type: ignore[arg-type] verify_certificate, ) # type: ignore if command == "test-module": return_results(test_module(client)) # type: ignore[func-returns-value] if command == "fetch-incidents": fetch_incidents(client, params) elif command in commands: return_results(commands[command](client, args)) else: raise NotImplementedError(f"{command} command is not implemented.") except Exception as e: return_error(f"One or more of the specified fields are invalid. Please validate them. {e}") if __name__ in ["__main__", "builtin", "builtins"]: main()