Cisco Umbrella Cloud Security v2

Cisco Umbrella is a cloud security platform providing the first line of defense against internet threats. It uses DNS-layer security to block malicious requests before a connection is established, offering protection against malware, ransomware, phishing, and more. It offers real-time reporting, integrates with other Cisco solutions for layered security, and uses machine learning to uncover and predict threats.

Network Security · Cisco Umbrella cloud security

Details

IDCisco Umbrella Cloud Security v2
ProviderCisco Systems
CategoryNetwork Security
From Version6.9.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Cisco Umbrella is a cloud security platform providing the first line of defense against internet threats. It uses DNS-layer security to block malicious requests before a connection is established, offering protection against malware, ransomware, phishing, and more. It offers real-time reporting, integrates with other Cisco solutions for layered security, and uses machine learning to uncover and predict threats.
This integration was tested with version 2 of Cisco Umbrella Cloud Security

Configure Cisco Umbrella Cloud Security v2 in Cortex

Parameter Required
API Key True
API Secret True
Use system proxy settings False
Trust any certificate (not secure) False
Base URL True

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

umbrella-destinations-list


Get destinations within a destination list. A destination is a URL, IP or fully qualified domain name.

Base Command

umbrella-destinations-list

Input

Argument Name Description Required
destination_list_id The ID of the destination list. Destination lists can be fetched with the umbrella-destination-lists-list command. Required
destination_ids Comma-separated list of destination IDs to be retrieved from a list of destinations. Optional
destinations Comma-separated list of destinations to retrieve, a destination may be a domain, URL, or IP address. Optional
page Page number of paginated results. Minimum 1; Default 1. Optional
page_size The number of items per page. Minimum 1; Maximum 100; Default 50. Optional
limit The number of items per page. Minimum 1. Default is 50. Optional

Context Output

Path Type Description
Umbrella.Destinations.id String The unique ID of the destination.
Umbrella.Destinations.destination String A destination may be a domain, URL, or IP address.
Umbrella.Destinations.type String The type of destination within the destination list.
Umbrella.Destinations.comment String A comment about the destination.
Umbrella.Destinations.createdAt Date The date and time when the destination list was created.

Command example

!umbrella-destinations-list destination_list_id=17425859 limit=3

Context Example

{
    "Umbrella": {
        "Destinations": [
            {
                "comment": "Added from XSOAR",
                "createdAt": "2023-07-19 18:21:11",
                "destination": "www.facebook.com",
                "id": "154",
                "type": "domain"
            },
            {
                "comment": "Lior",
                "createdAt": "2023-07-06 04:42:55",
                "destination": "cisco.com",
                "id": "30058",
                "type": "domain"
            },
            {
                "comment": "Sabri",
                "createdAt": "2023-07-06 04:42:55",
                "destination": "www.pokemon.com",
                "id": "138036",
                "type": "domain"
            }
        ]
    }
}

Human Readable Output

Destination(s)

Id Destination Type Comment Created At
154 www.facebook.com domain Added from XSOAR 2023-07-19 18:21:11
30058 cisco.com domain Pikachu 2023-07-06 04:42:55
138036 www.pokemon.com domain Choose 2023-07-06 04:42:55

umbrella-destination-add


Add a destination to a destination list. A destination is a URL, IPv4, CIDR or fully qualified domain name. Accepted types for destination list with the access “allow” are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access “block” are: URL and DOMAIN.

Base Command

umbrella-destination-add

Input

Argument Name Description Required
destination_list_id The ID of the destination list. Destination lists can be fetched with the umbrella-destination-lists-list command. Required
destinations Comma-separated list of destinations. A destination may be a URL, IPv4, CIDR or fully qualified domain name. Required
comment A comment about all the inserted destinations. Default is Added from XSOAR. Optional

Context Output

Path Type Description
Umbrella.DestinationLists.id Number The unique ID of the destination list.
Umbrella.DestinationLists.organizationId Number The organization ID.
Umbrella.DestinationLists.access String The type of access for the destination list. Valid values are: allow or block.
Umbrella.DestinationLists.isGlobal Boolean Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization.
Umbrella.DestinationLists.name String The name of the destination list.
Umbrella.DestinationLists.thirdpartyCategoryId Number The third-party category ID of the destination list.
Umbrella.DestinationLists.createdAt Number The date and time when the destination list was created.
Umbrella.DestinationLists.modifiedAt Number The date and time when the destination list was modified.
Umbrella.DestinationLists.isMspDefault Boolean Specifies whether MSP is the default.
Umbrella.DestinationLists.markedForDeletion Boolean Specifies whether the destination list is marked for deletion.
Umbrella.DestinationLists.bundleTypeId Number The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns ‘1’ for the DNS policy or ‘2’ for the Web policy.
Umbrella.DestinationLists.meta.destinationCount Number The total number of destinations in a destination list.

Base Command

umbrella-destination-add

Input

Argument Name Description Required
destination_list_id The ID of the destination list. Destination Lists can be fetched with umbrella-destination-lists-list. Required
destinations Comma separated list of destinations. A destination may be a URL, IPv4, CIDR or fully qualified domain name. Required
comment A comment about all the inserted destinations. Default value: “Added from XSOAR”. Default is Added from XSOAR. Optional

Context Output

Path Type Description
Umbrella.DestinationLists.id Number The unique ID of the destination list.
Umbrella.DestinationLists.organizationId Number The organization ID.
Umbrella.DestinationLists.access String The type of access for the destination list. Valid values are: allow or block.
Umbrella.DestinationLists.isGlobal Boolean Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization.
Umbrella.DestinationLists.name String The name of the destination list.
Umbrella.DestinationLists.thirdpartyCategoryId Number The third-party category ID of the destination list.
Umbrella.DestinationLists.createdAt Number The date and time when the destination list was created.
Umbrella.DestinationLists.modifiedAt Number The date and time when the destination list was modified.
Umbrella.DestinationLists.isMspDefault Boolean Specifies whether MSP is the default.
Umbrella.DestinationLists.markedForDeletion Boolean Specifies whether the destination list is marked for deletion.
Umbrella.DestinationLists.bundleTypeId Number The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns ‘1’ for the DNS policy or ‘2’ for the Web policy.
Umbrella.DestinationLists.meta.destinationCount Number The total number of destinations in a destination list.

Command example

!umbrella-destination-add destination_list_id=17463731 destinations="www.LiorSabri.com,1.1.1.1"

Human Readable Output

The destination(s) “[‘www.LiorSabri.com’, ‘1.1.1.1’]” were successfully added to the destination list “17463731”

umbrella-destination-delete


Remove a destination from a destination list. A destination is a URL, IP or fully qualified domain name.

Base Command

umbrella-destination-delete

Input

Argument Name Description Required
destination_list_id The ID of the destination list. Destination lists can be fetched with the umbrella-destination-lists-list command. Required
destination_ids Comma-separated list of destination IDs. Destinations can be fetched with the umbrella-destination-list command. Required

Context Output

Path Type Description
Umbrella.DestinationLists.id Number The unique ID of the destination list.
Umbrella.DestinationLists.organizationId Number The organization ID.
Umbrella.DestinationLists.access String The type of access for the destination list. Valid values are: allow or block.
Umbrella.DestinationLists.isGlobal Boolean Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization.
Umbrella.DestinationLists.name String The name of the destination list.
Umbrella.DestinationLists.thirdpartyCategoryId Number The third-party category ID of the destination list.
Umbrella.DestinationLists.createdAt Number The date and time when the destination list was created.
Umbrella.DestinationLists.modifiedAt Number The date and time when the destination list was modified.
Umbrella.DestinationLists.isMspDefault Boolean Specifies whether MSP is the default.
Umbrella.DestinationLists.markedForDeletion Boolean Specifies whether the destination list is marked for deletion.
Umbrella.DestinationLists.bundleTypeId Number The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns ‘1’ for the DNS policy or ‘2’ for the Web policy.
Umbrella.DestinationLists.meta.destinationCount Number The total number of destinations in a destination list.

Command example

!umbrella-destination-delete destination_list_id=17463733 destination_ids=25826

Human Readable Output

The destination(s) “[25826]” were successfully removed from the destination list “17463733”

umbrella-destination-lists-list


Get destination lists. A list of destinations (for example, domain name or URL) to which you can block or allow access.

Base Command

umbrella-destination-lists-list

Input

Argument Name Description Required
destination_list_id The ID of the destination list to retrieve. Optional
page Page number of paginated results. Minimum 1; Default 1. Optional
page_size The number of items per page. Minimum 1; Maximum 100; Default 50. Optional
limit The maximum number of records to retrieve. Minimum 1. Default is 50. Optional

Context Output

Path Type Description
Umbrella.DestinationLists.id Number The unique ID of the destination list.
Umbrella.DestinationLists.organizationId Number The organization ID.
Umbrella.DestinationLists.access String The type of access for the destination list. Valid values are: allow or block.
Umbrella.DestinationLists.isGlobal Boolean Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization.
Umbrella.DestinationLists.name String The name of the destination list.
Umbrella.DestinationLists.thirdpartyCategoryId Number The third-party category ID of the destination list.
Umbrella.DestinationLists.createdAt Number The date and time when the destination list was created.
Umbrella.DestinationLists.modifiedAt Number The date and time when the destination list was modified.
Umbrella.DestinationLists.isMspDefault Boolean Specifies whether MSP is the default.
Umbrella.DestinationLists.markedForDeletion Boolean Specifies whether the destination list is marked for deletion.
Umbrella.DestinationLists.bundleTypeId Number The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns ‘1’ for the DNS policy or ‘2’ for the Web policy.
Umbrella.DestinationLists.meta.destinationCount Number The total number of destinations in a destination list.
Umbrella.DestinationLists.meta.domainCount Number The total number of domains in a destination list. Domains are part of the total number of destinations in a destination list.
Umbrella.DestinationLists.meta.ipv4Count Number The total number of IP addresses in a destination list. IP addresses are part of the total number of destinations in a destination list.
Umbrella.DestinationLists.meta.urlCount Number The total number of URLs in a destination list. URLs are part of the total number of destinations in a destination list.
Umbrella.DestinationLists.meta.applicationCount Number The total number or applications in a destination list. Applications are part of the total number of destinations in a destination list.

Command example

!umbrella-destination-lists-list limit=3

Context Example

{
    "Umbrella": {
        "DestinationLists": [
            {
                "access": "allow",
                "bundleTypeId": 1,
                "createdAt": 1690184121,
                "id": 17463749,
                "isGlobal": false,
                "isMspDefault": false,
                "markedForDeletion": false,
                "meta": {
                    "applicationCount": 0,
                    "destinationCount": 1,
                    "domainCount": 0,
                    "ipv4Count": 1,
                    "urlCount": 0
                },
                "modifiedAt": 1690184121,
                "name": "Lior",
                "organizationId": 123456,
                "thirdpartyCategoryId": null
            },
            {
                "access": "allow",
                "bundleTypeId": 1,
                "createdAt": 1690184234,
                "id": 17463756,
                "isGlobal": false,
                "isMspDefault": false,
                "markedForDeletion": false,
                "meta": {
                    "applicationCount": 0,
                    "destinationCount": 8,
                    "domainCount": 4,
                    "ipv4Count": 4,
                    "urlCount": 0
                },
                "modifiedAt": 1690184435,
                "name": "LiorSB",
                "organizationId": 123456,
                "thirdpartyCategoryId": null
            },
            {
                "access": "allow",
                "bundleTypeId": 1,
                "createdAt": 1638798710,
                "id": 15609454,
                "isGlobal": true,
                "isMspDefault": false,
                "markedForDeletion": false,
                "meta": {
                    "applicationCount": 0,
                    "destinationCount": 14,
                    "domainCount": 10,
                    "ipv4Count": 4,
                    "urlCount": 0
                },
                "modifiedAt": 1690183660,
                "name": "Global Allow List",
                "organizationId": 123456,
                "thirdpartyCategoryId": null
            }
        ]
    }
}

Human Readable Output

Destination List

Id Name Access Is Global Destination Count
17463749 Lior allow false 1
17463756 LiorSB allow false 8
15609454 Global Allow List allow true 14

umbrella-destination-list-create


Create a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access. Accepted types for destination list with the access “allow” are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access “block” are: URL and DOMAIN.

Base Command

umbrella-destination-list-create

Input

Argument Name Description Required
bundle_type The type of the Umbrella policy associated with the destination list. If the field is not specified, the default value is ‘DNS’. Possible values are: DNS, WEB. Optional
access The type of access for the destination list. Valid values are “allow” or “block”. Accepted types for destination list with the access “allow” are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access “block” are: URL and DOMAIN. Possible values are: allow, block. Required
is_global Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization. Possible values are: True, False. Required
name The name of the destination list. Required
destinations Comma-separated list of destinations. A destination may be a URL, IPv4, CIDR or fully qualified domain name. Optional
destinations_comment A comment about all the inserted destinations. Default is Added from XSOAR. Optional

Context Output

Path Type Description
Umbrella.DestinationLists.id Number The unique ID of the destination list.
Umbrella.DestinationLists.organizationId Number The organization ID.
Umbrella.DestinationLists.access String The type of access for the destination list. Valid values are: allow or block.
Umbrella.DestinationLists.isGlobal Boolean Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization.
Umbrella.DestinationLists.name String The name of the destination list.
Umbrella.DestinationLists.thirdpartyCategoryId Number The third-party category ID of the destination list.
Umbrella.DestinationLists.createdAt Number The date and time when the destination list was created.
Umbrella.DestinationLists.modifiedAt Number The date and time when the destination list was modified.
Umbrella.DestinationLists.isMspDefault Boolean Specifies whether MSP is the default.
Umbrella.DestinationLists.markedForDeletion Boolean Specifies whether the destination list is marked for deletion.
Umbrella.DestinationLists.bundleTypeId Number The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns ‘1’ for the DNS policy or ‘2’ for the Web policy.
Umbrella.DestinationLists.meta.destinationCount Number The total number of destinations in a destination list.

Command example

!umbrella-destination-list-create access=allow is_global=False name=LiorSBList bundle_type=WEB destinations="https://pokemon.com"

Context Example

{
    "Umbrella": {
        "DestinationLists": {
            "access": "allow",
            "bundleTypeId": 1,
            "createdAt": 1690208665,
            "id": 17464621,
            "isGlobal": false,
            "isMspDefault": false,
            "markedForDeletion": false,
            "meta": {
                "destinationCount": 1
            },
            "modifiedAt": 1690208665,
            "name": "LiorSBList",
            "organizationId": 123456,
            "thirdpartyCategoryId": null
        }
    }
}

Human Readable Output

Destination List

Id Name Access Is Global Destination Count
17464621 LiorSBList allow false 1

umbrella-destination-list-update


Edit a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access.

Base Command

umbrella-destination-list-update

Input

Argument Name Description Required
destination_list_id The ID of the destination list. Destination lists can be fetched with the umbrella-destination-lists-list command. Required
name The name of the destination list. Required

Context Output

Path Type Description
Umbrella.DestinationLists.id Number The unique ID of the destination list.
Umbrella.DestinationLists.organizationId Number The organization ID.
Umbrella.DestinationLists.access String The type of access for the destination list. Valid values are: allow or block.
Umbrella.DestinationLists.isGlobal Boolean Specifies whether the destination list is a global destination list. There is only one default destination list of type ‘allow’ or ‘block’ for an organization.
Umbrella.DestinationLists.name String The name of the destination list.
Umbrella.DestinationLists.thirdpartyCategoryId Number The third-party category ID of the destination list.
Umbrella.DestinationLists.createdAt Number The date and time when the destination list was created.
Umbrella.DestinationLists.modifiedAt Number The date and time when the destination list was modified.
Umbrella.DestinationLists.isMspDefault Boolean Specifies whether MSP is the default.
Umbrella.DestinationLists.markedForDeletion Boolean Specifies whether the destination list is marked for deletion.
Umbrella.DestinationLists.bundleTypeId Number The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns ‘1’ for the DNS policy or ‘2’ for the Web policy.
Umbrella.DestinationLists.meta.destinationCount Number The total number of destinations in a destination list.

Command example

!umbrella-destination-list-update destination_list_id=17463733 name=LiorUpdated

Context Example

{
    "Umbrella": {
        "DestinationLists": {
            "access": "allow",
            "bundleTypeId": 1,
            "createdAt": 1690183414,
            "id": 17463733,
            "isGlobal": false,
            "isMspDefault": false,
            "markedForDeletion": false,
            "meta": {
                "destinationCount": 0
            },
            "modifiedAt": 1690208670,
            "name": "LiorUpdated",
            "organizationId": 123456,
            "thirdpartyCategoryId": null
        }
    }
}

Human Readable Output

Destination List

Id Name Access Is Global Destination Count
17463733 LiorUpdated allow false 0

umbrella-destination-list-delete


Delete a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access.

Base Command

umbrella-destination-list-delete

Input

Argument Name Description Required
destination_list_id The ID of the destination list. Destination lists can be fetched with the umbrella-destination-lists-list command. Required

Context Output

There is no context output for this command.

Command example

!umbrella-destination-list-delete destination_list_id=17463733

Human Readable Output

The destination list “17463733” was successfully deleted

Breaking changes from the previous version of this integration - Cisco Umbrella Cloud Security v2

The following sections list the changes in this version.

Commands

The following commands were removed in this version

  • umbrella-get-destination-lists - this command was replaced by umbrella-destination-lists-list.
  • umbrella-add-domain - this command was replaced by umbrella-destination-add.
  • umbrella-remove-domain - this command was replaced by umbrella-destination-delete.
  • umbrella-get-destination-domain - this command was replaced by umbrella-destinations-list.
  • umbrella-get-destination-domains - this command was replaced by umbrella-destinations-list.
  • umbrella-search-destination-domains - this command was replaced by umbrella-destinations-list.

Arguments

The following arguments were removed in this version

In the umbrella-get-destination-lists command:

  • orgId - this argument was removed.
    In the umbrella-add-domain command:
  • orgId - this argument was removed.
    In the umbrella-remove-domain command:
  • orgId - this argument was removed.
    In the umbrella-get-destination-domain command:
  • orgId - this argument was removed.
    In the umbrella-get-destination-domains command:
  • orgId - this argument was removed.
    In the umbrella-search-destination-domains command:
  • orgId - this argument was removed.

The behavior of the following arguments was changed

In the umbrella-add-domain command:

  • destId - this argument was replaced by destination_list_id.
  • domains - this argument was replaced by destinations.
    In the umbrella-remove-domain command:
  • destId - this argument was replaced by destination_list_id.
  • domainIds - this argument was replaced by destination_ids.
    In the umbrella-get-destination-domain command:
  • destId - this argument was replaced by destination_list_id.
    In the umbrella-get-destination-domains command:
  • destId - this argument was replaced by destination_list_id.
    In the umbrella-search-destination-domains command:
  • destId - this argument was replaced by destination_list_id.
  • domains - this argument was replaced by destinations.

Configuration parameters

  • credentials — API Key (required)
  • proxy — Use system proxy settings
  • insecure — Trust any certificate (not secure)
  • baseURL — Base URL (required)

Commands (13)

  • umbrella-add-domain Deprecated

    Deprecated. Use the `umbrella-destination-add` instead.

  • umbrella-destination-add

    Add a destination to a destination list. A destination is a URL, IPv4, CIDR or fully qualified domain name. Accepted types for destination list with the access "allow" are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access "block" are: URL and DOMAIN.

  • umbrella-destination-delete

    Remove a destination from a destination list. A destination is a URL, IP or fully qualified domain name.

  • umbrella-destination-list-create

    Create a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access. Accepted types for destination list with the access "allow" are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access "block" are: URL and DOMAIN.

  • umbrella-destination-list-delete

    Delete a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access.

  • umbrella-destination-list-update

    Edit a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access.

  • umbrella-destination-lists-list

    Get destination lists. A list of destinations (for example, domain name or URL) to which you can block or allow access.

  • umbrella-destinations-list

    Get destinations within a destination list. A destination is a URL, IP or fully qualified domain name.

  • umbrella-get-destination-domain Deprecated

    Deprecated. Use the `umbrella-destinations-list` instead.

  • umbrella-get-destination-domains Deprecated

    Deprecated. Use the `umbrella-destinations-list` instead.

  • umbrella-get-destination-lists Deprecated

    Deprecated. Use the `umbrella-destination-lists-list` instead.

  • umbrella-remove-domain Deprecated

    Deprecated. Use the `umbrella-destination-delete` instead.

  • umbrella-search-destination-domains Deprecated

    Deprecated. Use the `umbrella-destinations-list` instead.

commonfields:
  id: Cisco Umbrella Cloud Security v2
  version: -1
sectionorder:
  - Connect
name: Cisco Umbrella Cloud Security v2
display: Cisco Umbrella Cloud Security v2
category: Network Security
provider: Cisco Systems
description: Cisco Umbrella is a cloud security platform providing the first line of defense against internet threats. It uses DNS-layer security to block malicious requests before a connection is established, offering protection against malware, ransomware, phishing, and more. It offers real-time reporting, integrates with other Cisco solutions for layered security, and uses machine learning to uncover and predict threats.
configuration:
- name: credentials
  display: API Key
  displaypassword: API Secret
  type: 9
  required: true
  section: Connect
- name: proxy
  display: Use system proxy settings
  defaultvalue: 'false'
  type: 8
  required: false
  section: Connect
- name: insecure
  display: Trust any certificate (not secure)
  defaultvalue: 'false'
  type: 8
  required: false
  section: Connect
- name: baseURL
  display: Base URL
  type: 0
  required: true
  additionalinfo: Cisco Umbrella Investigate base URL.
  defaultvalue: https://api.umbrella.com
  section: Connect
script:
  commands:
  - name: umbrella-destinations-list
    description: Get destinations within a destination list. A destination is a URL, IP or fully qualified domain name.
    arguments:
    - name: destination_list_id
      description: The ID of the destination list. Destination lists can be fetched with the `umbrella-destination-lists-list` command.
      required: true
    - name: destination_ids
      description: Comma-separated list of destination IDs to be retrieved from a list of destinations.
      isArray: true
    - name: destinations
      description: Comma-separated list of destinations to retrieve, a destination may be a domain, URL, or IP address.
      isArray: true
    - name: page
      description: Page number of paginated results. Minimum 1; Default 1.
    - name: page_size
      description: The number of items per page. Minimum 1; Maximum 100; Default 50.
    - name: limit
      description: The number of items per page. Minimum 1.
      defaultValue: '50'
    outputs:
    - type: String
      contextPath: Umbrella.Destinations.id
      description: The unique ID of the destination.
    - type: String
      contextPath: Umbrella.Destinations.destination
      description: A destination may be a domain, URL, or IP address.
    - type: String
      contextPath: Umbrella.Destinations.type
      description: The type of destination within the destination list.
    - type: String
      contextPath: Umbrella.Destinations.comment
      description: A comment about the destination.
    - type: Date
      contextPath: Umbrella.Destinations.createdAt
      description: The date and time when the destination list was created.
  - name: umbrella-destination-add
    description: 'Add a destination to a destination list. A destination is a URL, IPv4, CIDR or fully qualified domain name. Accepted types for destination list with the access "allow" are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access "block" are: URL and DOMAIN.'
    compliantpolicies:
      - Domain Blockage
    arguments:
    - name: destination_list_id
      description: The ID of the destination list. Destination lists can be fetched with the `umbrella-destination-lists-list` command.
      required: true
    - name: destinations
      description: Comma-separated list of destinations. A destination may be a URL, IPv4, CIDR or fully qualified domain name.
      required: true
    - name: comment
      description: A comment about all the inserted destinations.
      defaultValue: Added from XSOAR
    outputs:
    - type: Number
      contextPath: Umbrella.DestinationLists.id
      description: The unique ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.organizationId
      description: The organization ID.
    - type: String
      contextPath: Umbrella.DestinationLists.access
      description: 'The type of access for the destination list. Valid values are: allow or block.'
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isGlobal
      description: Specifies whether the destination list is a global destination list. There is only one default destination list of type 'allow' or 'block' for an organization.
    - type: String
      contextPath: Umbrella.DestinationLists.name
      description: The name of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.thirdpartyCategoryId
      description: The third-party category ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.createdAt
      description: The date and time when the destination list was created.
    - type: Number
      contextPath: Umbrella.DestinationLists.modifiedAt
      description: The date and time when the destination list was modified.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isMspDefault
      description: Specifies whether MSP is the default.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.markedForDeletion
      description: Specifies whether the destination list is marked for deletion.
    - type: Number
      contextPath: Umbrella.DestinationLists.bundleTypeId
      description: The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns '1' for the DNS policy or '2' for the Web policy.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.destinationCount
      description: The total number of destinations in a destination list.
  - name: umbrella-destination-delete
    description: Remove a destination from a destination list. A destination is a URL, IP or fully qualified domain name.
    compliantpolicies:
      - Domain Blockage
    arguments:
    - name: destination_list_id
      description: The ID of the destination list. Destination lists can be fetched with the `umbrella-destination-lists-list` command.
      required: true
    - name: destination_ids
      description: Comma-separated list of destination IDs. Destinations can be fetched with the `umbrella-destination-list` command.
      required: true
      isArray: true
    outputs:
    - type: Number
      contextPath: Umbrella.DestinationLists.id
      description: The unique ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.organizationId
      description: The organization ID.
    - type: String
      contextPath: Umbrella.DestinationLists.access
      description: 'The type of access for the destination list. Valid values are: allow or block.'
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isGlobal
      description: Specifies whether the destination list is a global destination list. There is only one default destination list of type 'allow' or 'block' for an organization.
    - type: String
      contextPath: Umbrella.DestinationLists.name
      description: The name of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.thirdpartyCategoryId
      description: The third-party category ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.createdAt
      description: The date and time when the destination list was created.
    - type: Number
      contextPath: Umbrella.DestinationLists.modifiedAt
      description: The date and time when the destination list was modified.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isMspDefault
      description: Specifies whether MSP is the default.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.markedForDeletion
      description: Specifies whether the destination list is marked for deletion.
    - type: Number
      contextPath: Umbrella.DestinationLists.bundleTypeId
      description: The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns '1' for the DNS policy or '2' for the Web policy.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.destinationCount
      description: The total number of destinations in a destination list.
  - name: umbrella-destination-lists-list
    description: Get destination lists. A list of destinations (for example, domain name or URL) to which you can block or allow access.
    arguments:
    - name: destination_list_id
      description: The ID of the destination list to retrieve.
    - name: page
      description: Page number of paginated results. Minimum 1; Default 1.
    - name: page_size
      description: The number of items per page. Minimum 1; Maximum 100; Default 50.
    - name: limit
      description: The maximum number of records to retrieve. Minimum 1.
      defaultValue: '50'
    outputs:
    - type: Number
      contextPath: Umbrella.DestinationLists.id
      description: The unique ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.organizationId
      description: The organization ID.
    - type: String
      contextPath: Umbrella.DestinationLists.access
      description: 'The type of access for the destination list. Valid values are: allow or block.'
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isGlobal
      description: Specifies whether the destination list is a global destination list. There is only one default destination list of type 'allow' or 'block' for an organization.
    - type: String
      contextPath: Umbrella.DestinationLists.name
      description: The name of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.thirdpartyCategoryId
      description: The third-party category ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.createdAt
      description: The date and time when the destination list was created.
    - type: Number
      contextPath: Umbrella.DestinationLists.modifiedAt
      description: The date and time when the destination list was modified.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isMspDefault
      description: Specifies whether MSP is the default.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.markedForDeletion
      description: Specifies whether the destination list is marked for deletion.
    - type: Number
      contextPath: Umbrella.DestinationLists.bundleTypeId
      description: The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns '1' for the DNS policy or '2' for the Web policy.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.destinationCount
      description: The total number of destinations in a destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.domainCount
      description: The total number of domains in a destination list. Domains are part of the total number of destinations in a destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.ipv4Count
      description: The total number of IP addresses in a destination list. IP addresses are part of the total number of destinations in a destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.urlCount
      description: The total number of URLs in a destination list. URLs are part of the total number of destinations in a destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.applicationCount
      description: The total number or applications in a destination list. Applications are part of the total number of destinations in a destination list.
  - name: umbrella-destination-list-create
    description: 'Create a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access. Accepted types for destination list with the access "allow" are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access "block" are: URL and DOMAIN.'
    arguments:
    - name: bundle_type
      description: The type of the Umbrella policy associated with the destination list. If the field is not specified, the default value is 'DNS'.
      auto: PREDEFINED
      predefined:
      - 'DNS'
      - 'WEB'
    - name: access
      description: 'The type of access for the destination list. Valid values are "allow" or "block". Accepted types for destination list with the access "allow" are: DOMAIN, IPv4 and CIDR. Accepted types for destination list with the access "block" are: URL and DOMAIN.'
      required: true
      auto: PREDEFINED
      predefined:
      - 'allow'
      - 'block'
    - name: is_global
      description: Specifies whether the destination list is a global destination list. There is only one default destination list of type 'allow' or 'block' for an organization.
      required: true
      auto: PREDEFINED
      predefined:
      - 'True'
      - 'False'
    - name: name
      description: The name of the destination list.
      required: true
    - name: destinations
      description: Comma-separated list of destinations. A destination may be a URL, IPv4, CIDR or fully qualified domain name.
      isArray: true
    - name: destinations_comment
      description: A comment about all the inserted destinations.
      defaultValue: Added from XSOAR
    outputs:
    - type: Number
      contextPath: Umbrella.DestinationLists.id
      description: The unique ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.organizationId
      description: The organization ID.
    - type: String
      contextPath: Umbrella.DestinationLists.access
      description: 'The type of access for the destination list. Valid values are: allow or block.'
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isGlobal
      description: Specifies whether the destination list is a global destination list. There is only one default destination list of type 'allow' or 'block' for an organization.
    - type: String
      contextPath: Umbrella.DestinationLists.name
      description: The name of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.thirdpartyCategoryId
      description: The third-party category ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.createdAt
      description: The date and time when the destination list was created.
    - type: Number
      contextPath: Umbrella.DestinationLists.modifiedAt
      description: The date and time when the destination list was modified.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isMspDefault
      description: Specifies whether MSP is the default.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.markedForDeletion
      description: Specifies whether the destination list is marked for deletion.
    - type: Number
      contextPath: Umbrella.DestinationLists.bundleTypeId
      description: The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns '1' for the DNS policy or '2' for the Web policy.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.destinationCount
      description: The total number of destinations in a destination list.
  - name: umbrella-destination-list-update
    description: Edit a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access.
    arguments:
    - name: destination_list_id
      description: The ID of the destination list. Destination lists can be fetched with the `umbrella-destination-lists-list` command.
      required: true
    - name: name
      description: The name of the destination list.
      required: true
    outputs:
    - type: Number
      contextPath: Umbrella.DestinationLists.id
      description: The unique ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.organizationId
      description: The organization ID.
    - type: String
      contextPath: Umbrella.DestinationLists.access
      description: 'The type of access for the destination list. Valid values are: allow or block.'
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isGlobal
      description: Specifies whether the destination list is a global destination list. There is only one default destination list of type 'allow' or 'block' for an organization.
    - type: String
      contextPath: Umbrella.DestinationLists.name
      description: The name of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.thirdpartyCategoryId
      description: The third-party category ID of the destination list.
    - type: Number
      contextPath: Umbrella.DestinationLists.createdAt
      description: The date and time when the destination list was created.
    - type: Number
      contextPath: Umbrella.DestinationLists.modifiedAt
      description: The date and time when the destination list was modified.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.isMspDefault
      description: Specifies whether MSP is the default.
    - type: Boolean
      contextPath: Umbrella.DestinationLists.markedForDeletion
      description: Specifies whether the destination list is marked for deletion.
    - type: Number
      contextPath: Umbrella.DestinationLists.bundleTypeId
      description: The number that represents the type of the Umbrella policy associated with the destination list. Umbrella returns '1' for the DNS policy or '2' for the Web policy.
    - type: Number
      contextPath: Umbrella.DestinationLists.meta.destinationCount
      description: The total number of destinations in a destination list.
  - name: umbrella-destination-list-delete
    description: Delete a destination list. A list of destinations (for example, domain name or URL) to which you can block or allow access.
    arguments:
    - name: destination_list_id
      description: The ID of the destination list. Destination lists can be fetched with the `umbrella-destination-lists-list` command.
      required: true
  - arguments:
    - description: Organization ID.
      name: orgId
    deprecated: true
    description: Deprecated. Use the `umbrella-destination-lists-list` instead.
    name: umbrella-get-destination-lists
    outputs:
    - contextPath: Umbrella.DestinationLists
      description: List of destination lists in an organization.
      type: Unknown
  - arguments:
    - description: Optional organization ID. If not provided, will use the one provided in the integration configuration.
      name: orgId
    - description: Destination list ID.
      name: destId
      required: true
    - description: 'List of domains to add to the destination list. (Format: domain1.com,domain2.com).'
      isArray: true
      name: domains
      required: true
    - defaultValue: Added from XSOAR
      description: Note on what the domain is or why it is being added.
      name: comment
    deprecated: true
    description: Deprecated. Use the `umbrella-destination-add` instead.
    name: umbrella-add-domain
  - arguments:
    - description: Optional organization ID. By default, uses the one set in the instance configuration.
      name: orgId
    - description: Destination list ID to get domains from. Use the umbrella-get-destination-lists command to get the list ID.
      name: destId
      required: true
    deprecated: true
    description: Deprecated. Use the `umbrella-destinations-list` instead.
    name: umbrella-get-destination-domains
    outputs:
    - contextPath: Umbrella.Destinations.id
      description: ID of the domain within the destination list.
    - contextPath: Umbrella.Destinations.destination
      description: Domain within the destination list.
    - contextPath: Umbrella.Destinations.type
      description: Type of destination within the destination list.
    - contextPath: Umbrella.Destinations.createdAt
      description: The date and time when the domain within the destination list was created.
    - contextPath: Umbrella.Destinations.comment
      description: Comment associated with the domain within the destination list.
  - arguments:
    - description: Optional organization ID. If not provided, will use the one provided in the integration configuration.
      name: orgId
    - description: Destination list ID.
      name: destId
      required: true
    - description: 'Comma-separated list of entry IDs to remove from the destination list. (Format: 1234,1235).'
      isArray: true
      name: domainIds
      required: true
    deprecated: true
    description: Deprecated. Use the `umbrella-destination-delete` instead.
    name: umbrella-remove-domain
  - arguments:
    - description: Optional organization ID. By default, uses the one set in the instance configuration.
      name: orgId
    - description: Destination list ID to get domains from. Use the umbrella-get-destination-lists command to get the list ID.
      name: destId
      required: true
    - description: Domain to get from a destination list.
      name: domain
      required: true
    deprecated: true
    description: Deprecated. Use the `umbrella-destinations-list` instead.
    name: umbrella-get-destination-domain
    outputs:
    - contextPath: Umbrella.Destinations.id
      description: ID of the domain within the destination list.
    - contextPath: Umbrella.Destinations.destination
      description: Domain within the destination list.
    - contextPath: Umbrella.Destinations.type
      description: Type of destination within the destination list.
    - contextPath: Umbrella.Destinations.createdAt
      description: The date and time when domain within the destination list was created.
    - contextPath: Umbrella.Destinations.comment
      description: Comment associated with the domain within the destination list.
  - arguments:
    - description: Optional organization ID. By default, uses the one set in the instance configuration.
      name: orgId
    - description: Destination list ID to get domains from. Use the umbrella-get-destination-lists command to get the list ID.
      name: destId
      required: true
    - description: Comma-separated list of domains to search for in a destination list.
      isArray: true
      name: domains
      required: true
    deprecated: true
    description: Deprecated. Use the `umbrella-destinations-list` instead.
    name: umbrella-search-destination-domains
    outputs:
    - contextPath: Umbrella.Destinations.id
      description: ID of domain within the destination list.
      type: number
    - contextPath: Umbrella.Destinations.destination
      description: Domain within the destination list.
      type: string
    - contextPath: Umbrella.Destinations.type
      description: Type of destination within the destination list.
      type: string
    - contextPath: Umbrella.Destinations.createdAt
      description: Date and time when the domain within the destination list was created.
      type: date
    - contextPath: Umbrella.Destinations.comment
      description: Comment associated with the domain within the destination list.
      type: string
  script: ''
  type: python
  subtype: python3
  dockerimage: demisto/python3:3.12.13.10116658
  isfetch: false
fromversion: 6.9.0
tests:
- No tests (auto formatted)