CimTrak
The CimTrak integration helps you detect unexpected system/device/config modifications and automatically respond/react to threats.
Forensics & Malware Analysis · CimTrak - System Integrity Assurance
Details
| ID | CimTrak |
|---|---|
| Provider | Cimcor Inc |
| Category | Forensics & Malware Analysis |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
CimTrak XSOAR integration.
Configure CimTrak on Cortex XSOAR
- Fill in the URL to your App Server
- Create an API Key in the CimTrak Management Console and populate in XSOAR
- Fill in the Repository IP relative to the App Server (IE: If App Server is running on the same machine as the Repository you can use 127.0.0.1)
- Fill in Repository Port
- Once configured all unreconciled items from CimTrak will be brought into XSOAR.
Commands
get-events
Input
| Argument Name | Description | Required |
|---|---|---|
| Start | number | Starting number of record to get |
| End | number | Ending number of record to get |
| Filter | json | Filter array to limit results IE: [{name: id, operator:>, value:5}] |
| Sorts | json | Sort array to sort data IE: [{field: id, descending: False}] |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Event.id | number | Event ID |
| CimTrak.Event.leventid | number | Event ID |
| CimTrak.Event.lagentid | number | Agent ID |
| CimTrak.Event.lobjectid | number | Object ID |
| CimTrak.Event.lobjectdetailid | number | Object Detail ID |
| CimTrak.Event.lobjectdetailidint | number | Object Detail Intrusion ID |
| CimTrak.Event.lmessagelevel | number | Message Level |
| CimTrak.Event.szuser | string | User |
| CimTrak.Event.szfileuser | string | File User |
| CimTrak.Event.szmessageid | string | Message ID |
| CimTrak.Event.szmessage | string | Message |
| CimTrak.Event.szfile | string | File |
| CimTrak.Event.szcorrectionid | string | Correction ID |
| CimTrak.Event.szcorrection | string | Correction |
| CimTrak.Event.lcategory | number | Category |
| CimTrak.Event.lemailsent | number | Email Sent |
| CimTrak.Event.lstoragestatus | number | Storage Status |
| CimTrak.Event.dtmdatetime1 | string | Date Time 1 |
| CimTrak.Event.dtmdatetime2 | string | Date Time 2 |
| CimTrak.Event.szchecksum | string | Checksum |
| CimTrak.Event.status | string | Status |
| CimTrak.Event.lprocessid | number | Process ID |
| CimTrak.Event.lthreadid | number | Thread ID |
| CimTrak.Event.szprocess | string | Process |
| CimTrak.Event.szforensicdata | string | Forensic Data |
| CimTrak.Event.dtmdeleted | string | Deteled Date Time |
| CimTrak.Event.ltickcount | number | Tick Count |
| CimTrak.Event.lsubtype | number | SubType |
| CimTrak.Event.ticketNumber | string | Ticket Number |
| CimTrak.Event.ldeleteobjectdetailid | number | Deleted Object Detail ID |
| CimTrak.Event.bfoundinblacklist | number | Found In Blacklist |
| CimTrak.Event.filecontenthash | string | File Content Hash |
| CimTrak.Event.lobjectsettingid | number | Object Setting ID |
| CimTrak.Event.reconciled | number | Reconciled |
| CimTrak.Event.isauthcopy | number | Is Auth Copy |
| CimTrak.Event.externalticketnumber | string | External Ticket Number |
| CimTrak.Event.lparentid | number | Parent ID |
| CimTrak.Event.szobjectpath | string | Object Path |
| CimTrak.Event.dfilesize | number | File Size |
file-analysis-by-hash
Input
| Argument Name | Description | Required |
|---|---|---|
| Hash | string | Hash of file to check |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.FileAnalysis.analysisEngine | string | Analysis Engine used |
| CimTrak.FileAnalysis.analysisSuccess | boolean | Analysis Success Flag |
| CimTrak.FileAnalysis.analysisResults | string | Agent ID |
file-analysis-by-objectdetail-id
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectDetailId | number | Object Detail Id of file to check |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.FileAnalysis.analysisEngine | string | Analysis Engine used |
| CimTrak.FileAnalysis.analysisSuccess | boolean | Analysis Success Flag |
| CimTrak.FileAnalysis.analysisResults | string | Agent ID |
check-file-against-trusted-file-registry-by-hash
Input
| Argument Name | Description | Required |
|---|---|---|
| Hashes | list | Array of hashes of file to check IE:B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769,D2B3289F12102506717E2A1FB883F62E7DCE09FBDA48BE192905669684E68FD0 |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.TrustedFileRegistry.hash | string | Hash found in registry |
promote-authoritative-baseline-files
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectDetaildIds | list | Array of object detail IDs of file to check IE:42,43 |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.AuthoritizeBaseline.objectDetailId | number | objectDetailId of file |
| CimTrak.AuthoritizeBaseline.status | string | Status |
| CimTrak.AuthoritizeBaseline.errorCode | string | Error Code |
| CimTrak.AuthoritizeBaseline.errorDescription | string | Status |
demote-authoritative-baseline-files
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectDetaildIds | list | Array of object detail IDs of file to check IE:42,43 |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.AuthoritizeBaseline.objectDetailId | number | objectDetailId of file |
| CimTrak.AuthoritizeBaseline.status | string | Status |
update-task-disposition
Input
| Argument Name | Description | Required |
|---|---|---|
| taskId | number | Task ID |
| Disposition | string | Disposition of task |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.TaskDisposition.taskId | number | Task Id |
| CimTrak.TaskDisposition.status | string | Status |
get-tickets
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Ticket.id | number | Ticket Id |
| CimTrak.Ticket.ticketNumber | string | Ticket number |
| CimTrak.Ticket.sentiment | string | Ticket sentiment |
| CimTrak.Ticket.sentimenttypeid | string | Ticket sentiment id |
| CimTrak.Ticket.title | string | Ticket title |
| CimTrak.Ticket.description | string | Ticket description |
| CimTrak.Ticket.priority | number | Ticket priority |
| CimTrak.Ticket.disposition | string | Ticket disposition |
| CimTrak.Ticket.creationDate | string | Ticket creation date |
| CimTrak.Ticket.createdByUser | string | Ticket created by user |
| CimTrak.Ticket.modificationDate | string | Ticket modification date |
| CimTrak.Ticket.modifiedByUser | string | Ticket modified by user |
| CimTrak.Ticket.requiresAcknowledgement | boolean | Ticket requires acknowledgement |
| CimTrak.Ticket.requiresConfirmation | boolean | Ticket requires confirmation |
| CimTrak.Ticket.requiresAssessment | boolean | Ticket requires assessment |
| CimTrak.Ticket.startDate | string | Ticket start date |
| CimTrak.Ticket.endDate | string | Ticket end date |
| CimTrak.Ticket.autoPromote | boolean | Ticket auto promote |
| CimTrak.Ticket.assignedToUserId | number | Ticket assigned yo UserId |
| CimTrak.Ticket.assignedToUser | string | Ticket assigned to user |
| CimTrak.Ticket.assignedToGroupId | number | Ticket assigned to GroupId |
| CimTrak.Ticket.assignedToGroup | string | Ticket assigned to group |
| CimTrak.Ticket.externalTicketNumber | string | Ticket external ticket number |
| CimTrak.Ticket.externalTicketType | string | Ticket external ticket type |
| CimTrak.Ticket.tasks | string | Ticket tasks |
| CimTrak.Ticket.comments | string | Ticket comments |
| CimTrak.Ticket.events | string | Ticket events |
get-ticket-tasks
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.TicketTask.id | number | Ticket Task Id |
| CimTrak.TicketTask.ticketId | number | Ticket Id |
| CimTrak.TicketTask.agentObjectId | number | Agent Object id |
| CimTrak.TicketTask.startDate | string | Ticket start date |
| CimTrak.TicketTask.endDate | string | Ticket end date |
| CimTrak.TicketTask.disposition | string | Ticket disposition |
| CimTrak.TicketTask.creationDate | string | Ticket creation date |
| CimTrak.TicketTask.createdByUserId | number | Ticket created by user Id |
| CimTrak.TicketTask.modificationDate | string | Ticket modification date |
| CimTrak.TicketTask.modifiedByUserId | number | Ticket modified by user Id |
| CimTrak.TicketTask.assignedToUserId | number | Ticket assigned yo UserId |
| CimTrak.TicketTask.assignedToGroupId | number | Ticket assigned to GroupId |
| CimTrak.TicketTask.assigneeDisposition | string | Assignee Disposition |
| CimTrak.TicketTask.ticketTitle | string | Ticket title |
| CimTrak.TicketTask.description | string | Ticket description |
| CimTrak.TicketTask.priority | number | Ticket priority |
| CimTrak.TicketTask.ticketDisposition | string | Ticket disposition |
| CimTrak.TicketTask.ticketCreationDate | string | Ticket creation date |
| CimTrak.TicketTask.ticketCreatedByUserId | string | Ticket vreated by user Id |
| CimTrak.TicketTask.ticketModificationDate | string | Ticket modification date |
| CimTrak.TicketTask.requiresAcknowledgement | string | Ticket requires acknowlegment |
| CimTrak.TicketTask.requiresConfirmation | string | Ticket requires confirmation |
| CimTrak.TicketTask.requiresAssessment | string | Ticket requires assessment |
| CimTrak.TicketTask.ticketNumber | string | Ticket number |
| CimTrak.TicketTask.agentName | string | Agent name |
| CimTrak.TicketTask.createdByUsername | string | Created By Username |
| CimTrak.TicketTask.modifiedByUsername | string | Modified by username |
| CimTrak.TicketTask.assigneeName | string | Assignee Name |
add-ticket
Input
| Argument Name | Description | Required |
|---|---|---|
| title | string | Title of ticket |
| priority | number | Ticket priority |
| description | string | Ticket description |
| startDate | string | Ticket start date |
| endDate | string | Ticket end date |
| externalTicketNumber | string | External ticket number |
| externalTicketType | string | External ticket type |
| autoPromote | boolean | Auto promote |
| disposition | string | Ticket disposition |
| requiresAcknowledgement | boolean | Requires acknowledgement |
| requiresAssessment | boolean | Requires assessment |
| requiresConfirmation | boolean | Requires confirmation |
| assignedToUserId | number | Assigned to user Id |
| assignedToUser | string | Assigned to user |
| assignedToGroupId | number | Assigned to group Id |
| assignedToGroup | string | Assigned to group |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Ticket.id | number | Ticket Id |
| CimTrak.Ticket.ticketNumber | string | Ticket number |
| CimTrak.Ticket.sentiment | string | Ticket sentiment |
| CimTrak.Ticket.sentimenttypeid | string | Ticket sentiment id |
| CimTrak.Ticket.title | string | Ticket title |
| CimTrak.Ticket.description | string | Ticket description |
| CimTrak.Ticket.priority | number | Ticket priority |
| CimTrak.Ticket.disposition | string | Ticket disposition |
| CimTrak.Ticket.creationDate | string | Ticket creation date |
| CimTrak.Ticket.createdByUser | string | Ticket created by user |
| CimTrak.Ticket.modificationDate | string | Ticket modification date |
| CimTrak.Ticket.modifiedByUser | string | Ticket modified by user |
| CimTrak.Ticket.requiresAcknowledgement | boolean | Ticket requires acknowledgement |
| CimTrak.Ticket.requiresConfirmation | boolean | Ticket requires confirmation |
| CimTrak.Ticket.requiresAssessment | boolean | Ticket requires assessment |
| CimTrak.Ticket.startDate | string | Ticket start date |
| CimTrak.Ticket.endDate | string | Ticket end date |
| CimTrak.Ticket.autoPromote | boolean | Ticket auto promote |
| CimTrak.Ticket.assignedToUserId | number | Ticket assigned yo UserId |
| CimTrak.Ticket.assignedToUser | string | Ticket assigned to user |
| CimTrak.Ticket.assignedToGroupId | number | Ticket assigned to GroupId |
| CimTrak.Ticket.assignedToGroup | string | Ticket assigned to group |
| CimTrak.Ticket.externalTicketNumber | string | Ticket external ticket number |
| CimTrak.Ticket.externalTicketType | string | Ticket external ticket type |
| CimTrak.Ticket.tasks | string | Ticket tasks |
| CimTrak.Ticket.comments | string | Ticket comments |
| CimTrak.Ticket.events | string | Ticket events |
update-ticket
Input
| Argument Name | Description | Required |
|---|---|---|
| ticketId | number | Ticket Id |
| title | string | Title of ticket |
| priority | number | Ticket priority |
| description | string | Ticket description |
| startDate | string | Ticket start date |
| endDate | string | Ticket end date |
| externalTicketNumber | string | External ticket number |
| externalTicketType | string | External ticket type |
| autoPromote | boolean | Auto promote |
| disposition | string | Ticket disposition |
| requiresAcknowledgement | boolean | Requires acknowledgement |
| requiresAssessment | boolean | Requires assessment |
| requiresConfirmation | boolean | Requires confirmation |
| assignedToUserId | number | Assigned to user Id |
| assignedToUser | string | Assigned to user |
| assignedToGroupId | number | Assigned to group Id |
| assignedToGroup | string | Assigned to group |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Ticket.id | number | Ticket Id |
| CimTrak.Ticket.ticketNumber | string | Ticket number |
| CimTrak.Ticket.sentiment | string | Ticket sentiment |
| CimTrak.Ticket.sentimenttypeid | string | Ticket sentiment id |
| CimTrak.Ticket.title | string | Ticket title |
| CimTrak.Ticket.description | string | Ticket description |
| CimTrak.Ticket.priority | number | Ticket priority |
| CimTrak.Ticket.disposition | string | Ticket disposition |
| CimTrak.Ticket.creationDate | string | Ticket creation date |
| CimTrak.Ticket.createdByUser | string | Ticket created by user |
| CimTrak.Ticket.modificationDate | string | Ticket modification date |
| CimTrak.Ticket.modifiedByUser | string | Ticket modified by user |
| CimTrak.Ticket.requiresAcknowledgement | boolean | Ticket requires acknowledgement |
| CimTrak.Ticket.requiresConfirmation | boolean | Ticket requires confirmation |
| CimTrak.Ticket.requiresAssessment | boolean | Ticket requires assessment |
| CimTrak.Ticket.startDate | string | Ticket start date |
| CimTrak.Ticket.endDate | string | Ticket end date |
| CimTrak.Ticket.autoPromote | boolean | Ticket auto promote |
| CimTrak.Ticket.assignedToUserId | number | Ticket assigned yo UserId |
| CimTrak.Ticket.assignedToUser | string | Ticket assigned to user |
| CimTrak.Ticket.assignedToGroupId | number | Ticket assigned to GroupId |
| CimTrak.Ticket.assignedToGroup | string | Ticket assigned to group |
| CimTrak.Ticket.externalTicketNumber | string | Ticket external ticket number |
| CimTrak.Ticket.externalTicketType | string | Ticket external ticket type |
| CimTrak.Ticket.tasks | string | Ticket tasks |
| CimTrak.Ticket.comments | string | Ticket comments |
| CimTrak.Ticket.events | string | Ticket events |
add-ticket-comment
Input
| Argument Name | Description | Required |
|---|---|---|
| ticketId | number | Ticket Id |
| comment | string | Comment for ticket |
Context Output
| Path | Type | Description |
| — | — | — |
add-hash-allow-list
Input
| Argument Name | Description | Required |
|---|---|---|
| hash | string | Hash |
| filename | string | Filename for hash |
| source | string | Source for hash |
| sourceReference | string | SourceReference for hash |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.AllowList.status | string | Status of adding hash |
| CimTrak.AllowList.errorCode | string | Error Code of adding hash |
| CimTrak.AllowList.errorDescription | string | Error Description of adding hash |
| CimTrak.AllowList.hash | string | Hash added |
| CimTrak.AllowList.tagId | number | TagId of adding hash |
add-hash-deny-list
Input
| Argument Name | Description | Required |
|---|---|---|
| hash | string | Hash |
| filename | string | Filename for hash |
| source | string | Source for hash |
| sourceReference | string | SourceReference for hash |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.DenyList.status | string | Status of adding hash |
| CimTrak.DenyList.errorCode | string | Error Code of adding hash |
| CimTrak.DenyList.errorDescription | string | Error Description of adding hash |
| CimTrak.DenyList.hash | string | Hash added |
| CimTrak.DenyList.tagId | number | TagId of adding hash |
delete-hash-allow-list
Input
| Argument Name | Description | Required |
|---|---|---|
| hash | string | Hash |
| reason | string | Reason for deleting hash |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.AllowList.status | string | Status of deleting hash |
| CimTrak.AllowList.hash | string | Hash deleted |
| CimTrak.AllowList.tagId | number | TagId of deleting hash |
delete-hash-deny-list
Input
| Argument Name | Description | Required |
|---|---|---|
| hash | string | Hash |
| reason | string | Reason for deleting hash |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.DenyList.status | string | Status of deleting hash |
| CimTrak.DenyList.hash | string | Hash deleted |
| CimTrak.DenyList.tagId | number | TagId of deleting hash |
get-sub-generations
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.SubGenerations.caseSensitive | number | Case Sensitive |
| CimTrak.SubGenerations.agentObjectId | number | Agent Object Id |
| CimTrak.SubGenerations.subGenerationId | number | SubgenerationId |
| CimTrak.SubGenerations.objectId | number | Object Id |
| CimTrak.SubGenerations.generationId | number | Generation Id |
| CimTrak.SubGenerations.subRevision | number | SubRevision |
| CimTrak.SubGenerations.notes | string | Notes |
| CimTrak.SubGenerations.creationDate | string | Creation Date |
| CimTrak.SubGenerations.files | number | Files |
| CimTrak.SubGenerations.directories | number | Directories |
| CimTrak.SubGenerations.totalSize | number | Total Size |
| CimTrak.SubGenerations.revision | number | Revision |
| CimTrak.SubGenerations.userName | string | User Name |
deploy
Input
| Argument Name | Description | Required |
|---|---|---|
| agentObjectId | number | Agent Object Id |
| subGenerationId | number | Sub Generation Id |
| notes | string | Notes |
Context Output
| Path | Type | Description |
| — | — | — |
get-object-group
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.ObjectGroup.agentIsFilesystem | boolean | Agent Is Filesystem |
| CimTrak.ObjectGroup.cancel | boolean | Cancel |
| CimTrak.ObjectGroup.connected | boolean | Connected |
| CimTrak.ObjectGroup.logsByDays | boolean | Logs By Days |
| CimTrak.ObjectGroup.requireNotes | boolean | Require Notes |
| CimTrak.ObjectGroup.inService | string | In Service |
| CimTrak.ObjectGroup.children | number | Children |
| CimTrak.ObjectGroup.events | number | Events |
| CimTrak.ObjectGroup.intrusions | number | Intrusions |
| CimTrak.ObjectGroup.intrusionSize | number | Intrusion Size |
| CimTrak.ObjectGroup.objectId | number | Object Id |
| CimTrak.ObjectGroup.objectStatus | number | Object Status |
| CimTrak.ObjectGroup.objectSubType | number | Object SubType |
| CimTrak.ObjectGroup.objectType | number | Object Type |
| CimTrak.ObjectGroup.parentId | number | Parent Id |
| CimTrak.ObjectGroup.revisions | number | Revisions |
| CimTrak.ObjectGroup.templateId | number | Template Id |
| CimTrak.ObjectGroup.securityAdd | boolean | Security Add |
| CimTrak.ObjectGroup.securityEdit | boolean | Security Edit |
| CimTrak.ObjectGroup.securityLock | boolean | Security Lock |
| CimTrak.ObjectGroup.securityReport | boolean | Security Report |
| CimTrak.ObjectGroup.securityUnlock | boolean | Security Unlock |
| CimTrak.ObjectGroup.securityView | boolean | Security View |
| CimTrak.ObjectGroup.warnMinutes | number | Warn Minutes |
| CimTrak.ObjectGroup.contact | string | Contact |
| CimTrak.ObjectGroup.createDate | string | Create Date |
| CimTrak.ObjectGroup.description | string | Description |
| CimTrak.ObjectGroup.location | string | Location |
| CimTrak.ObjectGroup.name | string | Name |
| CimTrak.ObjectGroup.objectPath | string | Object Path |
| CimTrak.ObjectGroup.url | string | URL |
| CimTrak.ObjectGroup.agentObjectId | number | Agent Object Id |
| CimTrak.ObjectGroup.objectsCustom | string | Objects Custom |
| CimTrak.ObjectGroup.watchArray | string | Watch Array |
| CimTrak.ObjectGroup.comparisonMethod | number | Comparison Method |
unlock
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
| — | — | — |
lock
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
| — | — | — |
get-object
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Object.agentIsFilesystem | boolean | Agent Is Filesystem |
| CimTrak.Object.cancel | boolean | Cancel |
| CimTrak.Object.connected | boolean | Connected |
| CimTrak.Object.logsByDays | boolean | Logs By Days |
| CimTrak.Object.requireNotes | boolean | Require Notes |
| CimTrak.Object.inService | string | In Service |
| CimTrak.Object.children | number | Children |
| CimTrak.Object.events | number | Events |
| CimTrak.Object.intrusions | number | Intrusions |
| CimTrak.Object.intrusionSize | number | Intrusion Size |
| CimTrak.Object.objectId | number | Object Id |
| CimTrak.Object.objectStatus | number | Object Status |
| CimTrak.Object.objectSubType | number | Object SubType |
| CimTrak.Object.objectType | number | Object Type |
| CimTrak.Object.parentId | number | Parent Id |
| CimTrak.Object.revisions | number | Revisions |
| CimTrak.Object.templateId | number | Template Id |
| CimTrak.Object.securityAdd | boolean | Security Add |
| CimTrak.Object.securityEdit | boolean | Security Edit |
| CimTrak.Object.securityLock | boolean | Security Lock |
| CimTrak.Object.securityReport | boolean | Security Report |
| CimTrak.Object.securityUnlock | boolean | Security Unlock |
| CimTrak.Object.securityView | boolean | Security View |
| CimTrak.Object.warnMinutes | number | Warn Minutes |
| CimTrak.Object.contact | string | Contact |
| CimTrak.Object.createDate | string | Create Date |
| CimTrak.Object.description | string | Description |
| CimTrak.Object.location | string | Location |
| CimTrak.Object.name | string | Name |
| CimTrak.Object.objectPath | string | Object Path |
| CimTrak.Object.url | string | URL |
| CimTrak.Object.agentObjectId | number | Agent Object Id |
force-sync
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
| — | — | — |
view-file
Input
| Argument Name | Description | Required |
|---|---|---|
| objectDetailId | number | Object Detail Id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Sync.contents | string | Contents |
run-report-by-name
Input
| Argument Name | Description | Required |
|---|---|---|
| name | string | Name |
| objectId | number | Object Id |
| ReportParameters | json | Parameters for report |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Sync.html | string | HTML Report |
deploy-by-date
Input
| Argument Name | Description | Required |
|---|---|---|
| date | string | Date |
| objectId | number | Object Id |
Context Output
| Path | Type | Description |
| — | — | — |
get-current-compliance-items
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectId | number | Object ID to retrieve compliance items |
| ComplianceScanId | number | Compliance Scan ID to retrieve compliance items |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.ComplianceItems.objectid | number | Object ID |
| CimTrak.ComplianceItems.type | number | Type of item |
| CimTrak.ComplianceItems.name | string | Name |
| CimTrak.ComplianceItems.description | string | Description |
| CimTrak.ComplianceItems.scanstarttime | string | Scan Start Time |
| CimTrak.ComplianceItems.scanendtime | string | Scan End Time |
| CimTrak.ComplianceItems.scanid | number | Scanid |
| CimTrak.ComplianceItems.compliancemappingid | number | Compliance Mapping id |
| CimTrak.ComplianceItems.id | number | id |
get-objects
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectType | number | Object Type to retrieve |
| ObjectSubType | number | Object Sub Type to retrieve |
| ParentId | number | Parent ID to retrieve |
| ObjectId | number | Object ID to retrieve |
| ObjectPathAndName | string | Object path and name to retrieve |
| Recursive | boolean | Recursive |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Objects.repositoryDisplayName | string | Repository display name |
| CimTrak.Objects.connected | boolean | Connected |
| CimTrak.Objects.agentObjectId | number | Agent object Id |
| CimTrak.Objects.description | string | Description |
| CimTrak.Objects.name | string | Name |
| CimTrak.Objects.objectPath | string | Object Path |
| CimTrak.Objects.agentIsFilesystem | boolean | Agent is filesystem |
| CimTrak.Objects.cancel | boolean | Cancel |
| CimTrak.Objects.logsByDays | boolean | Logs by days |
| CimTrak.Objects.requireNotes | boolean | Require notes |
| CimTrak.Objects.inService | string | In service |
| CimTrak.Objects.events | number | Events |
| CimTrak.Objects.intrusions | number | Intrusions |
| CimTrak.Objects.intrusionSize | number | Intrusion size |
| CimTrak.Objects.objectId | number | Object ID |
| CimTrak.Objects.objectStatus | number | Object Status |
| CimTrak.Objects.objectSubType | number | object subtype |
| CimTrak.Objects.objectType | number | object type |
| CimTrak.Objects.parentId | number | Parent ID |
| CimTrak.Objects.revisions | number | Revisions |
| CimTrak.Objects.templateId | number | Template Id |
| CimTrak.Objects.securityAdd | boolean | Security add |
| CimTrak.Objects.securityEdit | boolean | Security edit |
| CimTrak.Objects.securityLock | boolean | Security lock |
| CimTrak.Objects.securityReport | boolean | Security report |
| CimTrak.Objects.securityUnlock | boolean | Security unlock |
| CimTrak.Objects.securityView | boolean | Security view |
| CimTrak.Objects.warnMinutes | number | Warn minutes |
| CimTrak.Objects.contact | string | Contact |
| CimTrak.Objects.createDate | string | Create date |
| CimTrak.Objects.location | string | Location |
| CimTrak.Objects.url | string | Url |
| CimTrak.Objects.parentName | string | Parent name |
| CimTrak.Objects.children | number | Children |
| CimTrak.Objects.agentVersion | string | Agent version |
| CimTrak.Objects.agentBuild | number | Agent build |
| CimTrak.Objects.agentOsVersion | string | Agent Os version |
| CimTrak.Objects.agentIp | string | agent Ip |
| CimTrak.Objects.agentName | string | Agent name |
| CimTrak.Objects.agentInstalled | boolean | Agent installed |
get-agent-info
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectId | number | Object ID to retrieve compliance items |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.AgentInfo.objectData | string | Object data |
| CimTrak.AgentInfo.objectsCustom | string | Object custom |
| CimTrak.AgentInfo.agentData | string | Agent data |
| CimTrak.AgentInfo.state | string | State |
get-compliance-archive-details
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectId | number | Object ID to retrieve compliance items |
| ComplianceScanId | number | Compliance Scan ID to retrieve compliance items |
| Filter | json | Filter array to limit results IE: [{name: id, operator:>, value:5}] |
| Start | number | Starting number of record to get |
| End | number | Ending number of record to get |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Compliance.testdate | string | Test Date |
| CimTrak.Compliance.datatype | string | Data Type |
| CimTrak.Compliance.scanid | number | Scan id |
| CimTrak.Compliance.ipaddress | string | IP address |
| CimTrak.Compliance.lobjectid | number | Object Id |
| CimTrak.Compliance.alternatesystemid | string | Alternate System ID |
| CimTrak.Compliance.agentuuid | string | Agent uuid |
| CimTrak.Compliance.agentname | string | Agent name |
| CimTrak.Compliance.objectpath | string | Object path |
| CimTrak.Compliance.benchmark | string | Benchmark |
| CimTrak.Compliance.profile | string | Profile |
| CimTrak.Compliance.test | string | Test |
| CimTrak.Compliance.pass | boolean | Pass |
| CimTrak.Compliance.iswaived | boolean | Is waived |
| CimTrak.Compliance.adjustedscore | number | Adjusted score |
| CimTrak.Compliance.possiblescore | number | Possible score |
| CimTrak.Compliance.rawscore | number | Raws core |
| CimTrak.Compliance.weight | number | Weight |
| CimTrak.Compliance.testran | boolean | Test ran |
| CimTrak.Compliance.remediation | string | Remediation |
| CimTrak.Compliance.severity | string | Severity |
| CimTrak.Compliance.version | string | Version |
| CimTrak.Compliance.rationale | string | Rationale |
| CimTrak.Compliance.description | string | Description |
| CimTrak.Compliance.assessment | string | Assessment |
| CimTrak.Compliance.disposition | string | Disposition |
| CimTrak.Compliance.conjunction | string | Conjunction |
| CimTrak.Compliance.negatatevalue | boolean | Negatate value |
| CimTrak.Compliance.comment | string | Comment |
| CimTrak.Compliance.controlversion | string | Controlversion |
| CimTrak.Compliance.controlnumber | string | Control number |
| CimTrak.Compliance.osversion | string | OS version |
| CimTrak.Compliance.personality | string | Personality |
| CimTrak.Compliance.objectid | number | Object id |
| CimTrak.Compliance.userId | number | User id |
| CimTrak.Compliance.block | boolean | Lock |
| CimTrak.Compliance.bunlock | boolean | Unlock |
| CimTrak.Compliance.bview | boolean | View |
| CimTrak.Compliance.bedit | boolean | Edit |
| CimTrak.Compliance.badd | boolean | Add |
| CimTrak.Compliance.breports | boolean | Reports |
| CimTrak.Compliance.blogon | boolean | Logon |
| CimTrak.Compliance.isadmin | boolean | Is admin |
get-compliance-archive-summary
Input
| Argument Name | Description | Required |
|---|---|---|
| ObjectId | number | Object ID to retrieve compliance items |
| ComplianceScanId | number | Compliance Scan ID to retrieve compliance items |
| Filter | json | Filter array to limit results IE: [{name: id, operator:>, value:5}] |
| Start | number | Starting number of record to get |
| End | number | Ending number of record to get |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Compliance.testdate | string | Test Date |
| CimTrak.Compliance.scanid | number | Scan id |
| CimTrak.Compliance.ipaddress | string | IP address |
| CimTrak.Compliance.datatype | string | Data Type |
| CimTrak.Compliance.alternatesystemid | string | Alternate System ID |
| CimTrak.Compliance.agentuuid | string | Agent uuid |
| CimTrak.Compliance.agentname | string | Agent name |
| CimTrak.Compliance.objectpath | string | Object path |
| CimTrak.Compliance.lobjectid | number | Object Id |
| CimTrak.Compliance.benchmark | string | Benchmark |
| CimTrak.Compliance.profile | string | Profile |
| CimTrak.Compliance.totalfailcount | number | Total fail count |
| CimTrak.Compliance.totalpasscount | number | Total pass count |
| CimTrak.Compliance.totaltestsskipped | number | Total tests skipped |
| CimTrak.Compliance.totalwaivecount | number | Total waive count |
| CimTrak.Compliance.pass | boolean | Pass |
| CimTrak.Compliance.totaltestsran | number | Total tests ran |
| CimTrak.Compliance.osversion | string | OS version |
| CimTrak.Compliance.personality | string | Personality |
| CimTrak.Compliance.userId | number | User id |
| CimTrak.Compliance.objectid | number | Object id |
| CimTrak.Compliance.block | boolean | Lock |
| CimTrak.Compliance.bunlock | boolean | Unlock |
| CimTrak.Compliance.bview | boolean | View |
| CimTrak.Compliance.bedit | boolean | Edit |
| CimTrak.Compliance.badd | boolean | Add |
| CimTrak.Compliance.breports | boolean | Reports |
| CimTrak.Compliance.blogon | boolean | Logon |
compliance-scan-children
Input
| Argument Name | Description | Required |
|---|---|---|
| objectParentId | number | Parent Object Id |
Context Output
| Path | Type | Description |
| — | — | — |
compliance-scan-with-summary
Input
| Argument Name | Description | Required |
|---|---|---|
| objectId | number | Object Id |
| retryCount | number | Number of times to retry to check if scan has completed |
| retrySeconds | number | Number of seconds to wait before retry to check if scan completed |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Compliance.testdate | string | Test Date |
| CimTrak.Compliance.scanid | number | Scan id |
| CimTrak.Compliance.ipaddress | string | IP address |
| CimTrak.Compliance.datatype | string | Data Type |
| CimTrak.Compliance.alternatesystemid | string | Alternate System ID |
| CimTrak.Compliance.agentuuid | string | Agent uuid |
| CimTrak.Compliance.agentname | string | Agent name |
| CimTrak.Compliance.objectpath | string | Object path |
| CimTrak.Compliance.lobjectid | number | Object Id |
| CimTrak.Compliance.benchmark | string | Benchmark |
| CimTrak.Compliance.profile | string | Profile |
| CimTrak.Compliance.totalfailcount | number | Total fail count |
| CimTrak.Compliance.totalpasscount | number | Total pass count |
| CimTrak.Compliance.totaltestsskipped | number | Total tests skipped |
| CimTrak.Compliance.totalwaivecount | number | Total waive count |
| CimTrak.Compliance.pass | boolean | Pass |
| CimTrak.Compliance.totaltestsran | number | Total tests ran |
| CimTrak.Compliance.osversion | string | OS version |
| CimTrak.Compliance.personality | string | Personality |
| CimTrak.Compliance.userId | number | User id |
| CimTrak.Compliance.objectid | number | Object id |
| CimTrak.Compliance.block | boolean | Lock |
| CimTrak.Compliance.bunlock | boolean | Unlock |
| CimTrak.Compliance.bview | boolean | View |
| CimTrak.Compliance.bedit | boolean | Edit |
| CimTrak.Compliance.badd | boolean | Add |
| CimTrak.Compliance.breports | boolean | Reports |
| CimTrak.Compliance.blogon | boolean | Logon |
get-agent-object-id-by-alternate-system-id
Input
| Argument Name | Description | Required |
|---|---|---|
| alternateSystemId | string | Alternate system Id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Object.agentObjectId | number | Object Id of agent |
get-agent-object-by-name
Input
| Argument Name | Description | Required |
|---|---|---|
| agentName | string | Agent name |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Object.agentIsFilesystem | boolean | Agent Is Filesystem |
| CimTrak.Object.cancel | boolean | Cancel |
| CimTrak.Object.connected | boolean | Connected |
| CimTrak.Object.logsByDays | boolean | Logs By Days |
| CimTrak.Object.requireNotes | boolean | Require Notes |
| CimTrak.Object.inService | string | In Service |
| CimTrak.Object.children | number | Children |
| CimTrak.Object.events | number | Events |
| CimTrak.Object.intrusions | number | Intrusions |
| CimTrak.Object.intrusionSize | number | Intrusion Size |
| CimTrak.Object.objectId | number | Object Id |
| CimTrak.Object.objectStatus | number | Object Status |
| CimTrak.Object.objectSubType | number | Object SubType |
| CimTrak.Object.objectType | number | Object Type |
| CimTrak.Object.parentId | number | Parent Id |
| CimTrak.Object.revisions | number | Revisions |
| CimTrak.Object.templateId | number | Template Id |
| CimTrak.Object.securityAdd | boolean | Security Add |
| CimTrak.Object.securityEdit | boolean | Security Edit |
| CimTrak.Object.securityLock | boolean | Security Lock |
| CimTrak.Object.securityReport | boolean | Security Report |
| CimTrak.Object.securityUnlock | boolean | Security Unlock |
| CimTrak.Object.securityView | boolean | Security View |
| CimTrak.Object.warnMinutes | number | Warn Minutes |
| CimTrak.Object.contact | string | Contact |
| CimTrak.Object.createDate | string | Create Date |
| CimTrak.Object.description | string | Description |
| CimTrak.Object.location | string | Location |
| CimTrak.Object.name | string | Name |
| CimTrak.Object.objectPath | string | Object Path |
| CimTrak.Object.url | string | URL |
| CimTrak.Object.agentObjectId | number | Agent Object Id |
get-agent-object-by-alternate-id
Input
| Argument Name | Description | Required |
|---|---|---|
| alternateSystemId | string | Agent alternate id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Object.agentIsFilesystem | boolean | Agent Is Filesystem |
| CimTrak.Object.cancel | boolean | Cancel |
| CimTrak.Object.connected | boolean | Connected |
| CimTrak.Object.logsByDays | boolean | Logs By Days |
| CimTrak.Object.requireNotes | boolean | Require Notes |
| CimTrak.Object.inService | string | In Service |
| CimTrak.Object.children | number | Children |
| CimTrak.Object.events | number | Events |
| CimTrak.Object.intrusions | number | Intrusions |
| CimTrak.Object.intrusionSize | number | Intrusion Size |
| CimTrak.Object.objectId | number | Object Id |
| CimTrak.Object.objectStatus | number | Object Status |
| CimTrak.Object.objectSubType | number | Object SubType |
| CimTrak.Object.objectType | number | Object Type |
| CimTrak.Object.parentId | number | Parent Id |
| CimTrak.Object.revisions | number | Revisions |
| CimTrak.Object.templateId | number | Template Id |
| CimTrak.Object.securityAdd | boolean | Security Add |
| CimTrak.Object.securityEdit | boolean | Security Edit |
| CimTrak.Object.securityLock | boolean | Security Lock |
| CimTrak.Object.securityReport | boolean | Security Report |
| CimTrak.Object.securityUnlock | boolean | Security Unlock |
| CimTrak.Object.securityView | boolean | Security View |
| CimTrak.Object.warnMinutes | number | Warn Minutes |
| CimTrak.Object.contact | string | Contact |
| CimTrak.Object.createDate | string | Create Date |
| CimTrak.Object.description | string | Description |
| CimTrak.Object.location | string | Location |
| CimTrak.Object.name | string | Name |
| CimTrak.Object.objectPath | string | Object Path |
| CimTrak.Object.url | string | URL |
| CimTrak.Object.agentObjectId | number | Agent Object Id |
get-agent-object-by-ip
Input
| Argument Name | Description | Required |
|---|---|---|
| ip | string | Agent alternate id |
Context Output
| Path | Type | Description |
|---|---|---|
| CimTrak.Object.agentIsFilesystem | boolean | Agent Is Filesystem |
| CimTrak.Object.cancel | boolean | Cancel |
| CimTrak.Object.connected | boolean | Connected |
| CimTrak.Object.logsByDays | boolean | Logs By Days |
| CimTrak.Object.requireNotes | boolean | Require Notes |
| CimTrak.Object.inService | string | In Service |
| CimTrak.Object.children | number | Children |
| CimTrak.Object.events | number | Events |
| CimTrak.Object.intrusions | number | Intrusions |
| CimTrak.Object.intrusionSize | number | Intrusion Size |
| CimTrak.Object.objectId | number | Object Id |
| CimTrak.Object.objectStatus | number | Object Status |
| CimTrak.Object.objectSubType | number | Object SubType |
| CimTrak.Object.objectType | number | Object Type |
| CimTrak.Object.parentId | number | Parent Id |
| CimTrak.Object.revisions | number | Revisions |
| CimTrak.Object.templateId | number | Template Id |
| CimTrak.Object.securityAdd | boolean | Security Add |
| CimTrak.Object.securityEdit | boolean | Security Edit |
| CimTrak.Object.securityLock | boolean | Security Lock |
| CimTrak.Object.securityReport | boolean | Security Report |
| CimTrak.Object.securityUnlock | boolean | Security Unlock |
| CimTrak.Object.securityView | boolean | Security View |
| CimTrak.Object.warnMinutes | number | Warn Minutes |
| CimTrak.Object.contact | string | Contact |
| CimTrak.Object.createDate | string | Create Date |
| CimTrak.Object.description | string | Description |
| CimTrak.Object.location | string | Location |
| CimTrak.Object.name | string | Name |
| CimTrak.Object.objectPath | string | Object Path |
| CimTrak.Object.url | string | URL |
| CimTrak.Object.agentObjectId | number | Agent Object Id |
Configuration parameters
url— App Server URL (required)isFetch— Fetch incidentsincidentType— Incident typeapikey— API Key (required)insecure— Trust any certificate (not secure)Repository URL— Repository URL (required)Repository Port— Repository Port (required)incidentFetchInterval— Incidents Fetch Intervalproxy— Use system proxy settingsfirst_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)max_fetch— Maximum number of incidents to fetch every time
Commands (37)
-
add-hash-allow-listAdd Hash to allow list.
-
add-hash-deny-listAdd Hash to deny list.
-
add-ticketCreates a ticket.
-
add-ticket-commentAdds a comment to a ticket or task.
-
check-file-against-trusted-file-registry-by-hashDescription Issues a request to check a list of files (specified by hashes) against the trusted file registry.
-
compliance-scan-childrenLaunch compliance scan for all children of object.
-
compliance-scan-with-summaryLaunch compliance scan for object and return results.
-
delete-hash-allow-listAdd Hash to allow list.
-
delete-hash-deny-listAdd Hash to deny list.
-
demote-authoritative-baseline-filesThis function removes a file (or list of files) from being the authoritative baseline.
-
deployDeploys a specific version of an object group. All existing files will be overwritten with the specified set.
-
deploy-by-dateDeploy By Date.
-
file-analysis-by-hashSubmits a file's hash for analysis and returns the results.
-
file-analysis-by-objectdetail-idSubmits a file's objectDetailId for analysis and returns the results.
-
force-syncSends a request to the server to synchronize an object group.
-
get-agent-infoReturns an array of agent information given an object ID.
-
get-agent-object-by-alternate-idGet agent object from alternate id.
-
get-agent-object-by-ipGet agent object from ip address.
-
get-agent-object-by-nameGet agent object from agent name.
-
get-agent-object-id-by-alternate-system-idGet agent object id from alternate system id.
-
get-compliance-archive-detailsReturns compliance scans details.
-
get-compliance-archive-summaryReturns compliance scans summary.
-
get-current-compliance-itemsThis function returns the benchmarks and/or compliance mappings for the compliance policy specified by the object ID.
-
get-eventsReturns Events from the event log.
-
get-objectRetrieves information for an object.
-
get-object-groupThis function returns an entire data structure describing an object group.
-
get-objectsRetrieves a list of objects.
-
get-sub-generationsReturns the subGenerations for an object group (specified by object ID.
-
get-ticket-tasksThis function gets ticket task information from a CimTrak Master Repository. This function returns an array of ticket task objects.
-
get-ticketsThis function gets ticket information from a CimTrak Master Repository. This function returns an array of ticket objects.
-
lockLocks an object group.
-
promote-authoritative-baseline-filesThis function sets a file (or list of files) as the authoritative baseline.
-
run-report-by-nameThis function runs the report specified by the report name. The report name can be obtained from the getReportHeaders API. The report's parameters can be obtained from the getReportArguments API.
-
unlockUnlocks an object group.
-
update-task-dispositionUpdates the tasks specified in taskIdArray to the disposition specified in the disposition parameter.
-
update-ticketUpdate Ticket.
-
view-fileThis function returns the contents of the requested file encoded in base64.
"""CimTrak Integration for Cortex XSOAR - Unit Tests file This file contains the Unit Tests for the CimTrak Integration based on pytest. Cortex XSOAR contribution requirements mandate that every integration should have a proper set of unit tests to automatically verify that the integration is behaving as expected during CI/CD pipeline. More Details ------------ More information about Unit Tests in Cortex XSOAR: https://xsoar.pan.dev/docs/integrations/unit-testing """ import json from typing import Any import CimTrak import pytest from CimTrak import Client def util_load_json(path) -> dict[str, Any]: with open(path, encoding="utf-8") as f: return json.loads(f.read()) @pytest.fixture() def client(): return Client(base_url="https://test.com/", verify=False, headers={"Authentication": "Bearer some_api_key"}) def test_add_hash_allow_list(client: Client, requests_mock): test_json_data = util_load_json("test_data/add_hash_allow_list.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.add_hash_allow_list_command( client, {"hash": "SHA256:B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769"} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_add_hash_deny_list(client: Client, requests_mock): test_json_data = util_load_json("test_data/add_hash_deny_list.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.add_hash_deny_list_command( client, {"hash": "SHA256:B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769"} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_add_ticket(client: Client, requests_mock): test_json_data = util_load_json("test_data/add_ticket.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.add_ticket_command( client, { "title": "test", "priority": 1, "autoPromote": "False", "requiresAcknowledgement": "False", "requiresAssessment": "False", "requiresConfirmation": "False", "assignedToUserId": "0", "assignedToGroupId": "0", }, ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_add_ticket_comment(client: Client, requests_mock): test_json_data = util_load_json("test_data/add_ticket_comment.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.add_ticket_comment_command(client, {"ticketId": "6", "comment": "test"}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_check_file_against_trusted_file_registry_by_hash(client: Client, requests_mock): test_json_data = util_load_json("test_data/check_file_against_trusted_file_registry_by_hash.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.check_file_against_trusted_file_registry_by_hash_command( client, {"Hashes": "B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769"} ) response = response_raw[0].outputs assert response == test_json_data["response"] def test_compliance_scan_children(client: Client, requests_mock): test_json_data = util_load_json("test_data/compliance_scan_children.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.compliance_scan_children_command(client, {"objectParentId": 1}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_compliance_scan_with_summary(client: Client, requests_mock): test_json_data = util_load_json("test_data/compliance_scan_with_summary.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.compliance_scan_with_summary_command(client, {"objectId": 1, "retryCount": 20, "retrySeconds": 10}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_delete_hash_allow_list(client: Client, requests_mock): test_json_data = util_load_json("test_data/delete_hash_allow_list.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.delete_hash_allow_list_command( client, {"hash": "SHA256:B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769"} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_delete_hash_deny_list(client: Client, requests_mock): test_json_data = util_load_json("test_data/delete_hash_deny_list.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.delete_hash_deny_list_command( client, {"hash": "SHA256:B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769"} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_demote_authoritative_baseline_files(client: Client, requests_mock): test_json_data = util_load_json("test_data/demote_authoritative_baseline_files.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.demote_authoritative_baseline_files_command(client, {"ObjectDetaildIds": "42"}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_deploy(client: Client, requests_mock): test_json_data = util_load_json("test_data/deploy.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.deploy_command(client, {"agentObjectId": 2, "subGenerationId": 1}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_deploy_by_date(client: Client, requests_mock): test_json_data = util_load_json("test_data/deploy_by_date.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.deploy_by_date_command(client, {"date": "2021-12-20 15:08:29", "objectId": "2"}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_test_fetch_incidents(client: Client, requests_mock): test_json_data = util_load_json("test_data/fetch_incidents.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) last_run = {"last_fetch": 1} _, response_raw = CimTrak.fetch_incidents( client=client, max_results=2, last_run=last_run, alert_status="ACTIVE", min_severity="Low", alert_type=None, first_fetch_time=None, ) response_raw[0]["rawJSON"] = json.loads(response_raw[0]["rawJSON"]) response = response_raw[0] assert response == test_json_data["response"] def test_file_analysis_by_hash(client: Client, requests_mock): test_json_data = util_load_json("test_data/file_analysis_by_hash.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.file_analysis_by_hash_command( client, {"Hash": "SHA256:B47DD22BFE1E5554448262D0C8E6555496B1AA6685AF50F49A12AD82D1109769"} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_file_analysis_by_object_detail_id(client: Client, requests_mock): test_json_data = util_load_json("test_data/file_analysis_by_object_detail_id.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.file_analysis_by_object_detail_id_command(client, {"ObjectDetailId": 42}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_force_sync(client: Client, requests_mock): test_json_data = util_load_json("test_data/force_sync.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.force_sync_command(client, {"objectId": 2}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_get_agent_info(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_agent_info.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_agent_info_command(client, {"ObjectId": "2"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_agent_object_by_alternate_id(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_agent_object_by_alternate_id.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_agent_object_by_alternate_id_command(client, {"alternateSystemId": "test"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_agent_object_by_ip(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_agent_object_by_ip.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_agent_object_by_ip_command(client, {"ip": "127.0.0.1"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_agent_object_by_name(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_agent_object_by_name.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_agent_object_by_name_command(client, {"agentName": "local"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_agent_object_id_by_alternate_system_id(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_agent_object_id_by_alternate_system_id.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_agent_object_id_by_alternate_system_id_command(client, {"alternateSystemId": "test"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_compliance_archive_details(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_compliance_archive_details.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_compliance_archive_details_command( client, {"Start": 1, "End": 1, "ObjectId": 1, "ComplianceScanId": -1} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_compliance_archive_summary(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_compliance_archive_summary.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_compliance_archive_summary_command( client, {"Start": 1, "End": 1, "ObjectId": 1, "ComplianceScanId": -1} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_current_compliance_items(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_current_compliance_items.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_current_compliance_items_command(client, {"ObjectId": "2", "ComplianceScanId": "-1"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_events(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_events.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_events_command(client, {"Start": 1, "End": 1}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_object(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_object.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_object_command(client, {"objectId": 2}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_object_group(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_object_group.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_object_group_command(client, {"objectId": 2}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_objects(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_objects.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_objects_command( client, {"ObjectId": "2", "ObjectType": "-1", "ObjectSubType": "-1", "ParentId": "-1", "Recursive": "false"} ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_sub_generations(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_sub_generations.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_sub_generations_command(client, {"objectId": 2}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_ticket_tasks(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_ticket_tasks.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_ticket_tasks_command(client, {}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_get_tickets(client: Client, requests_mock): test_json_data = util_load_json("test_data/get_tickets.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.get_tickets_command(client, {}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_lock(client: Client, requests_mock): test_json_data = util_load_json("test_data/lock.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.lock_command(client, {"objectId": 2}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_promote_authoritative_baseline_files(client: Client, requests_mock): test_json_data = util_load_json("test_data/promote_authoritative_baseline_files.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.promote_authoritative_baseline_files_command(client, {"ObjectDetaildIds": "42"}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_run_report_by_name(client: Client, requests_mock): test_json_data = util_load_json("test_data/run_report_by_name.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.run_report_by_name_command(client, {"Name": "Active Directory Users", "objectId": "0"}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_unlock(client: Client, requests_mock): test_json_data = util_load_json("test_data/unlock.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.unlock_command(client, {"objectId": 2}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_update_task_disposition(client: Client, requests_mock): test_json_data = util_load_json("test_data/update_task_disposition.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.update_task_disposition_command(client, {"taskId": 2, "Disposition": "REJECTED"}) response = response_raw[0].outputs assert response == test_json_data["response"] def test_update_ticket(client: Client, requests_mock): test_json_data = util_load_json("test_data/update_ticket.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.update_ticket_command( client, { "ticketId": "6", "title": "test", "priority": 1, "autoPromote": "False", "requiresAcknowledgement": "False", "requiresAssessment": "False", "requiresConfirmation": "False", "assignedToUserId": "0", "assignedToGroupId": "0", }, ) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"] def test_view_file(client: Client, requests_mock): test_json_data = util_load_json("test_data/view_file.json") for post in test_json_data["posts"]: requests_mock.post(post["url"], json=post["reply"]) response_raw = CimTrak.view_file_command(client, {"objectDetailId": 2}) response = response_raw[0].outputs ret_results: list[dict[str, Any]] = response_raw[1].outputs response["results"] = [] response["results"].append(ret_results) assert response == test_json_data["response"]