CustomIndicatorDemo

This is a demo integration that demonstrates the usage of the CustomIndicator helper class.

Vulnerability Management · Developer Tools

Details

IDCustomIndicatorDemo
ProviderOpen Source
CategoryVulnerability Management
From Version5.5.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Custom Indicator Demo is a demo integration that demonstrates the usage of the CustomIndicator helper class.

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

test-custom-indicator


This command demonstrates the usage of CustomIndicator.

Base Command

test-custom-indicator

Input

There are no input arguments for this command.

Context Output

Path Type Description
Demo.Result.Output String Dummy output.

Context Example

DBotScore
[
 {
  "Indicator": "custom_value",
  "Score": 1,
  "Type": "MyCustomIndicator",
  "Vendor": "CustomIndicatorDemo"
 }
]
Demo.Result
{
 "dummy": "test"
}
custom
[
 {
  "Value": "custom_value",
  "param1": "value1",
  "param2": "value2"
 }
]

Command Example

!test-custom-indicator

Human Readable Output

custom_value

Commands (1)

  • test-custom-indicator

    This command demonstrates the usage of the CustomIndicator helper class.

import demistomock as demisto
import urllib3
from CommonServerPython import *  # noqa # pylint: disable=unused-wildcard-import

from CommonServerUserPython import *  # noqa

# Disable insecure warnings
urllib3.disable_warnings()  # pylint: disable=no-member


""" CLIENT CLASS """


class Client(BaseClient):
    """Client class to interact with the service API

    This Client implements API calls, and does not contain any XSOAR logic.
    Should only do requests and return data.
    It inherits from BaseClient defined in CommonServerPython.
    Most calls use _http_request() that handles proxy, SSL verification, etc.
    For this implementation, no special attributes are defined.
    """

    def baseintegration_dummy(self, dummy: str) -> dict[str, str]:
        """Returns a simple python dict with the information provided
        in the input (dummy).

        :type dummy: ``str``
        :param dummy: string to add in the dummy dict that is returned

        :return: dict as {"dummy": dummy}
        :rtype: ``str``
        """

        return {"dummy": dummy}


def test_module() -> str:
    """Tests API connectivity and authentication'

    Returning 'ok' indicates that the integration works like it is supposed to.
    Connection to the service is successful.
    Raises exceptions if something goes wrong.

    :return: 'ok' if test passed, anything else will fail the test.
    :rtype: ``str``
    """
    try:
        message = "ok"
    except DemistoException as e:
        if "Forbidden" in str(e) or "Authorization" in str(e):
            message = "Authorization Error: make sure API Key is correctly set."
        else:
            raise
    return message


def custom_indicator_creation(client: Client) -> CommandResults:
    # Command using a custom indicator example

    result = client.baseintegration_dummy("test")
    score = Common.DBotScore.GOOD
    indicator_value = "custom_value"

    # Create a DBotScore object
    # Give it an indicator_type of DBotScoreType.CUSTOM
    dbot_score = Common.DBotScore(
        indicator=indicator_value,
        indicator_type=DBotScoreType.CUSTOM,
        integration_name="DummyIntegration",
        score=score,
    )
    # Create a data dictionary, which is the data of the indicator
    data = {
        "param1": "value1",
        "param2": "value2",
    }
    # Create the CustomIndicator
    custom_indicator = Common.CustomIndicator(
        indicator_type="MyCustomIndicator",
        dbot_score=dbot_score,
        value=indicator_value,
        data=data,
        context_prefix="custom",
    )
    # Return a CommandResults object containing the CustomIndicator object created
    return CommandResults(
        readable_output="custom_value",
        outputs=result,
        outputs_prefix="Demo.Result",
        outputs_key_field="test_key_field",
        indicator=custom_indicator,
    )


""" MAIN FUNCTION """


def main() -> None:
    """main function, parses params and runs command functions

    :return:
    :rtype:
    """

    demisto.debug(f"Command being called is {demisto.command()}")
    try:
        headers: dict = {}

        client = Client(base_url="", verify=False, headers=headers, proxy=False)

        if demisto.command() == "test-module":
            result = test_module()
            return_results(result)
        elif demisto.command() == "test-custom-indicator":
            return_results(custom_indicator_creation(client))

    except Exception as e:
        return_error(f"Failed to execute {demisto.command()} command.\nError:\n{e!s}")


if __name__ in ("__main__", "__builtin__", "builtins"):
    main()