Details
| ID | Cylance Protect v2 |
|---|---|
| Provider | Arctic Wolf |
| Category | Endpoint |
| From Version | 5.0.0 |
| Docker Image | demisto/auth-utils:1.0.0.11671917 |
| Supported Modules | Agentix XSIAM EDR Cortex Cloud Cloud Runtime Security |
README
Overview
Use the Cylance Protect v2 integration to manage endpoints, streamline remediation, and response from Cortex XSOAR.
This integration was integrated and tested with version 2.0.5 rev6 of Cylance Protect and Optics.
Prerequisites
Before you integrate Cylance Protect on Cortex XSOAR, you need to obtain a Cylance token.
- In Cylance, navigate to Settings > Integrations.
- Click Add Application.
- Enter an Application Name, and select the necessary privileges.
- Click Save.
- Record the Application ID and Application Secret for later use. You will not be able to access these later.
- Locate the Tenant ID at the top right side of the Integrations page and record it for later use.
Configure the Cylance Protect v2 Integration on Cortex XSOAR
- Navigate to Settings > Integrations > Servers & Services.
- Search for Cylance Protect v2.
- Click Add instance to create and configure a new integration instance.
- Name: A textual name for the integration instance.
- Server URL: URL of Cylance server.
- Application ID
- Application Secret
- Tenant API Key
- Use system proxy settings
- File Threshold: Default is -59
- Fetch Incidents
- Trust any certificate (not secure)
- Click Test to validate the URLs and connection.
Understanding the Cylance Score
The Cylance score ranges from -100 to 100, and is translated as follows.
Score translation
| Score Range | Color | Severity Level |
| -100 to -60 | Red | Malicious |
| -59 to 0 | Red | Supsicious |
| 1-100 | Green | Good |
Use Cases
- Retrieve and update threats and devices.
- Produce threat data report of indicators.
- Retrieve and create policies and zones.
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
- List console device resources for a tenant: cylance-protect-get-devices
- Get a console device resource for a tenant: cylance-protect-get-device
- Update a device: cylance-protect-update-device
- Get information for device threats: cylance-protect-get-device-threats
- Get information for console policy resources: cylance-protect-get-policies
- Create a zone: cylance-protect-create-zone
- Get information for multiple zones: cylance-protect-get-zones
- Get information for a single zone: cylance-protect-get-zone
- Update a zone: cylance-protect-update-zone
- Get information for a threat: cylance-protect-get-threat
- Get information for a threat device: cylance-protect-get-threat-devices
- Generate a report for indicators: cylance-protect-get-indicators-report
- Get information for threats: cylance-protect-get-threats
- Update device threats: cylance-protect-update-device-threats
- Get a list for hashes: cylance-protect-get-list
- Download a threat: cylance-protect-download-threat
- Add a hash to a list: cylance-protect-add-hash-to-list
- Delete a hash from a list: cylance-protect-delete-hash-from-lists
- Get details of a policy: cylance-protect-get-policy-details
- Delete devices: cylance-protect-delete-devices
- Create a new Instaquery: cylance-optics-create-instaquery
- Get Instaquery result: cylance-optics-get-instaquery-result
- List current Instaquery: cylance-optics-list-instaquery
1. List console device resources for a tenant
Returns a list of console device resources that belong to a tenant. The list is sorted by registration created date, with the most recent at the top of the list.
Base Command
cylance-protect-get-devices
Input
| Input Parameter | Description |
| pageNumber | Page number, default is 1 |
| pageSize | Specifies if the command polls for the result of the analysis, default is 100, maximum is 200 |
Context Output
| Path | Description |
| CylanceProtect.Device.AgentVersion | CylancePROTECT Agent version installed on the device |
| CylanceProtect.Device.DateFirstRegistered | Date and time (in UTC) when the device record was created |
| CylanceProtect.Device.ID | Device’s unique identifier |
| Endpoint.IPAddress | List of IP addresses for the device |
| Endpoint.MACAddress | List of MAC addresses for the device |
| Endpoint.Hostname | Device name |
| CylanceProtect.Device.Policy.ID | Device policy ID |
| CylanceProtect.Device.State | Machine state |
| CylanceProtect.Device.Policy.Name | Device policy name |
| CylanceProtect.Device.Hostname | Device name |
| CylanceProtect.Device.MACAddress | List of MAC addresses for the device |
| CylanceProtect.Device.IPAddress | List of IP addresses for the device |
Command Example
!cylance-protect-get-devices pageNumber=2 pageSize=75
Raw Output
{
"agent_version":"2.0.1440",
"date_first_registered":"2018-01-21T15:45:42",
"id":"652bbfa9-cf74-4e24-90f7-d01b16429701",
"ip_addresses":[
"172.31.31.110"
],
"mac_addresses":[
"06-F8-13-8B-16-C9"
],
"name":"WIN-0VJ9RO3P33Q",
"policy":{
"id":null,
"name":"Default"
},
"state":"Online"
}
2. Get a console device resource for a tenant
Returns a single device resource that belongs to a tenant.
Base Command
cylance-protect-get-device
Input
| Input Parameter | Description |
| id | Device ID |
Context Output
| Path | Description |
| CylanceProtect.Device.AgentVersion | CylancePROTECT Agent version installed on the device |
| CylanceProtect.Device.DateFirstRegistered | Date and time (in UTC) when the device record was created |
| CylanceProtect.Device.BackgroundDetection | If true, the agent is running |
| CylanceProtect.Device.DateLastModified | Date and time (in UTC) when the device record was last modified |
| CylanceProtect.Device.DateOffline | Date and time (in UTC) when the device last communicated with the console |
| CylanceProtect.Device.Hostname | Hostname for the device |
| CylanceProtect.Device.ID | Unique identifier for the device |
| CylanceProtect.Device.IPAddress | List of IP addresses for the device |
| CylanceProtect.Device.MACAddress | List of MAC addresses for the device |
| CylanceProtect.Device.IsSafe | If true, there are no outstanding threats |
| CylanceProtect.Device.UpdateAvailable | If true, there is available update for the device |
| CylanceProtect.Device.State | Machine state |
| Endpoint.Hostname | Device hostname |
| Endpoint.MACAddress | List of MAC addresses for the device |
| Endpoint.IPAddress | List of IP addresses for the device |
| Endpoint.OSVersion | Device OS version |
| CylanceProtect.Device.OSVersion | Device OS version |
| CylanceProtect.Device.Name | Device name |
Command Example
!cylance-protect-get-devices pageNumber=2 pageSize=75
Raw Output
{
"agent_version":"2.0.1440",
"date_first_registered":"2018-01-21T15:45:42",
"id":"652bbfa9-cf74-4e24-90f7-d01b16429701",
"ip_addresses":[
"172.31.31.110"
],
"mac_addresses":[
"06-F8-13-8B-16-C9"
],
"name":"WIN-0VJ9RO3P33Q",
"policy":{
"id":null,
"name":"Default"
},
"state":"Online"
}
3. Update a device
Updates a specified device.
Base Command
cylance-protect-update-device
Input
| Input Parameter | Description |
| id | Device ID |
| name | Device name |
| policyId | Policy ID |
| addZones | Zones IDs to add |
| removeZones | Zones IDs to remove |
Context Output
There is no context output for this command.
Command Example
!cylance-protect-update-device id=652bbfa9-cf74-4e24-90f7-d01b16429701
Raw Output
{
"Name":"TestName",
"PolicyID":"7bcb0817-e9c9-444d-96e2-be9b59f429cb",
"id":"6033f7a1-e66c-4aef-9c7d-ed454457d071"
}
4. Get information for device threats
Returns information about threats to devices, including classification, threat score, and more.
Base Command
cylance-protect-get-device-threats
Input
| Input Parameter | Description |
| id | Device ID |
| pageNumber | Page number, default is 1 |
| pageSize | Specifies if the command polls for the result of the analysis, default is 100, maximum is 200 |
Context Output
| Path | Description |
| File.Classification | Cylance threat classification assigned to the threat |
| File.CylanceScore | Cylance score assigned to the threat |
| File.DateFound | Date and time (in UTC) when the threat was found on the device |
| File.FilePath | File path where the threat was found on the device |
| File.FileStatus | Current status of the file on the device.
|
| File.Name | Threat name |
| File.Sha256 | SHA-256 has for the threat |
| File.SubClassification | Cylance threat sub-classification assigned to the threat |
| DBotScore.Indicator | Tested indicator |
| DBotScore.Type | Indicator type |
| DBotScore.Vendor | Vendor used to calculate the score |
| DbotScore.Score | Actual score |
Command Example
!cylance-protect-get-device-threats id=6033f7a1-e66c-4aef-9c7d-ed454457d071 pageNumber=2 pageSize=75
Raw Output
{
"classification":"Malware",
"cylance_score":-1,
"date_found":"2017-11-21T17:34:51",
"file_path":"C:\\$Recycle.Bin\\S-1-5-21-3378384064-522475393-1698893855-1001\\$RPJNCM8\\artifacts\\2017-08-12-Trickbot-binary-from-usdata.estoreseller.com.exe",
"file_status":"Default",
"name":"2017-08-12-Trickbot-binary-from-usdata.estoreseller.com.exe",
"sha256":"5DA547E87D6EF12349FB4DBBA9CF3146A358E284F72361DD07BBABFC95B0BAC3",
"sub_classification":"Trojan"
}
5. Get information for console policy resources
Returns information for console policy resources.
Base Command
cylance-protect-get-policies
Input
| Input Parameter | Description |
| pageNumber | Page number, default is 1 |
| pageItems | Number of items on a page, default is 100 |
Context Output
| Path | Description |
| CylanceProtect.Policies.DateAdded | Date and time (in UTC) when the Console policy resource was first created |
| CylanceProtect.Policies.DateModified | Date and time (in UTC) when the Console policy resource was last modified |
| CylanceProtect.Policies.DeviceCount | Number of devices assigned to this policy |
| CylanceProtect.Policies.Id | Unique ID for the policy resource |
| CylanceProtect.Policies.Name | Policy name |
| CylanceProtect.Policies.ZoneCount | Number of zones assigned to this policy |
Command Example
!cylance-protect-get-policies id=6033f7a1-e66c-4aef-9c7d-ed454457d071 pageNumber=2 pageSize=75
Raw Output
{
"date_added":"2018-03-05T12:29:02",
"date_modified":"2018-03-05T12:29:02",
"device_count":0,
"id":"7bcb0817-e9c9-444d-96e2-be9b59f429cb",
"name":"Test_Policy",
"zone_count":4
}
6. Create a zone
Creates a zone with a policy ID and criticality level.
Base Command
cylance-protect-create-zone
Input
| Input Parameter | Description |
| name | Zone name |
| policy_id | Unique ID for the policy assigned to the zone |
| criticality | Criticality value of the zone |
Context Output
There is no context output for this command.
Command Example
!cylance-protect-create-zone name=TestingZone3 criticality=High
Raw Output
{
"criticality":"High",
"date_created":"2018-03-13T11:38:52.2065082Z",
"id":"f15b2f79-c100-4146-b056-a8005c13b2de",
"name":"TestingZone3",
"policy_id":"7bcb0817-e9c9-444d-96e2-be9b59f429cb"
}
7. Get information for multiple zones
Returns information for multiple zones.
Base Command
cylance-protect-get-zones
Input
| Input Parameter | Description |
| pageNumber | Page number to request |
| pageItems | Number of zone records to retrieve for each page |
Context Output
| Path | Description |
| CylanceProtect.Zones.Criticality |
Zone value.
|
| CylanceProtect.Zones.DateCreated | Date and time (in UTC) when the zone was created |
| CylanceProtect.Zones.DateModified | Date and time (in UTC) when the zone was last modified |
| CylanceProtect.Zones.Id | Zone unique ID |
| CylanceProtect.Zones.Name | Zone name |
| CylanceProtect.Zones.PolicyId | Unique ID of the policy assigned to the zone |
| CylanceProtect.Zones.UpdateType | Update type for the zone |
| CylanceProtect.Zones.ZoneRuleId | Unique ID for the zone rule created for the zone |
Command Example
!cylance-protect-get-zones pageNumber=2 pageItems=10
Raw Output
{
"criticality":"High",
"date_created":"2018-03-13T11:38:52",
"date_modified":"2018-03-13T11:38:52",
"id":"f15b2f79-c100-4146-b056-a8005c13b2de",
"name":"TestingZone3",
"policy_id":"7bcb0817-e9c9-444d-96e2-be9b59f429cb",
"update_type":"Production",
"zone_rule_id":null
}
8. Get information for a single zone
Returns information for a single zone.
Base Command
cylance-protect-get-zone
Input
| Input Parameter | Description |
| id | Zone ID |
Context Output
| Path | Description |
| CylanceProtect.Zones.Criticality |
Zone value.
|
| CylanceProtect.Zones.DateCreated | Date and time (in UTC) when the zone was created |
| CylanceProtect.Zones.DateModified | Date and time (in UTC) when the zone was last modified |
| CylanceProtect.Zones.Id | Zone unique ID |
| CylanceProtect.Zones.Name | Zone name |
| CylanceProtect.Zones.PolicyId | Unique ID of the policy assigned to the zone |
| CylanceProtect.Zones.UpdateType | Update type for the zone |
| CylanceProtect.Zones.ZoneRuleId | Unique ID for the zone rule created for the zone |
Command Example
!cylance-protect-get-zone id=f15b2f79-c100-4146-b056-a8005c13b2de
Raw Output
{
"criticality":"High",
"date_created":"2018-03-13T11:38:52",
"date_modified":"2018-03-13T11:38:52",
"id":"f15b2f79-c100-4146-b056-a8005c13b2de",
"name":"TestingZone3",
"policy_id":"7bcb0817-e9c9-444d-96e2-be9b59f429cb",
"update_type":"Production",
"zone_rule_id":null
}
9. Update a zone
Updates a specified zone.
Base Command
cylance-protect-update-zone
Input
| Input Parameter | Description |
| id | Zone ID |
| name | Zone name |
| policyId | Unique ID for the policy assigned to the Zone |
| criticality | Criticality value of the zone |
Context Output
There is no context output for this command.
Command Example
!cylance-protect-update-zone id=f15b2f79-c100-4146-b056-a8005c13b2de
Raw Output
true
10. Get information for a threat
Returns information for a threat.
Base Command
cylance-protect-get-threat
Input
| Input Parameter | Description |
| sha256 | SHA-256 hash of the threat |
| theshold | Threat threshold |
Context Output
| Path | Description |
| File.AutoRun | Indicates if the file is set to automatically run on system startup |
| File.AvIndustry | The score provided by the Anti-Virus industry |
| File.CertIssuer | ID for the certificate issuer |
| File.CertPublisher | ID for the certificate publisher |
| File.CertTimestamp | Date and time (in UTC) when the file was signed using the certificate |
| File.Classification | Threat classification for the threat |
| File.CylanceScore | Cylance Score assigned to the threat |
| File.DetectedBy | Name of the Cylance module that detected the threat |
| File.FileSize | Size of the file |
| File.GlobalQuarantine | Identifies if the threat is on the Global Quarantine list |
| File.Md5 | MD5 hash for the threat |
| File.Name | Threat name |
| File.Running | Identifies if the threat is executing, or another executable loaded or called it |
| File.Safelisted | Identifies if the threat is on the Safe List |
| File.Sha256 | SHA-256 hash for the threat |
| File.Signed | Identifies the file as signed or not signed |
| File.SubClassification | The threat sub-classification for the threat |
| File.UniqueToCylance | The threat was identified by Cylance but not by other anti-virus sources |
| DBotScore.Indicator | The tested indicator |
| DBotScore.Type | Indicator type |
| DBotScore.Vendor | Vendor used to calculate the score |
| DBotScore.Score | The actual score |
Command Example
!cylance-protect-get-threat sha256=ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA
Raw Output
{
"auto_run":false,
"av_industry":null,
"cert_issuer":"",
"cert_publisher":"",
"cert_timestamp":"0001-01-01T00:00:00",
"classification":"Malware",
"cylance_score":-1,
"detected_by":"File Watcher",
"file_size":3514368,
"global_quarantined":true,
"md5":"84C82835A5D21BBCF75A61706D8AB549",
"name":"wanncry.exe",
"running":false,
"safelisted":false,
"sha256":"ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA",
"signed":false,
"sub_classification":"Ransom",
"unique_to_cylance":false
}
11. Get information for a threat device
Returns information for a threat device.
Base Command
cylance-protect-get-threat-devices
Input
| Input Parameter | Description |
| sha256 | SHA-256 hash of the threat |
Context Output
| Path | Description |
| CylanceProtect.Threat.Devices.ID | Device ID |
| CylanceProtect.Threat.Devices.DateFound | Date and time (in UTC) when the threat was found on the device |
| CylanceProtect.Threat.Devices.AgentVersion | Agent version installed on the device |
| CylanceProtect.Threat.Devices.FileStatus |
Current quarantine status of the file on the device.
|
| Endpoint.IPAddress | List of IP addresses for the device |
| Endpoint.MACAddress | List of MAC addresses for the device |
| Endpoint.Hostname | Device name for the device |
| CylanceProtect.Threat.Devices.PolicyID | Unique identifier of the policy assigned to the device, or null if no policy is assigned |
| CylanceProtect.Threat.Devices.State |
Device state.
|
| File.SHA256 | SHA-256 hash of the threat |
| File.Path | Path where the file was found on the device |
| CylanceProtect.Threat.Devices.Hostname | Device name for the device |
| CylanceProtect.Threat.Devices.IPAddress | List of IP addresses for the device |
| CylanceProtect.Threat.Devices.MACAddress | List of MAC addresses for the device |
Command Example
!cylance-protect-get-threat-devices sha256=ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA
Raw Output
{
"agent_version":"2.0.1440",
"date_found":"2018-01-21T15:45:46",
"file_status":"Whitelisted",
"id":"652bbfa9-cf74-4e24-90f7-d01b16429701",
"ip_addresses":"172.31.31.110",
"mac_addresses":"06-F8-13-8B-16-C9",
"name":"WIN-0VJ9RO3P33Q",
"policy_id":null,
"state":"Online"
}
12. Generate a report for indicators
Generates a report for indicators.
Base Command
cylance-protect-get-indicators-report
Input
| Input Parameter | Description |
| token | Threat data report token |
Context Output
There is not context output for this command.
Command Example
cylance-protect-get-indicators-report token=As3424$%
Raw Output
There is no raw output for this command.
13. Get information for threats
Returns information for threats.
Base Command
cylance-protect-get-threats
Input
| Input Parameter | Description |
| page_size | Number of device records to retrieve for each page |
| page | Page number to request |
| threshold | Threat threshold |
Context Output
| Path | Description |
| File.Classification | Threat classification for the threat |
| File.SubClassification | Threat sub-classification for the threat |
| File.Sha256 | SHA-256 hash for the threat |
| File.Safelisted | Identifies if the threat is on the Safe List |
| File.Name | Threat name |
| File.LastFound | Date and time (in UTC) when the file was last found |
| File.CylanceScore | The Cylance Score assigned to the threat |
| File.GlobalQuarantine | Identifies if the threat is on the Global Quarantine list |
| File.UniqueToCylance | The threat was identified by Cylance but not by other anti-virus sources |
| File.FileSize | File size |
| File.Md5 | MD5 hash for the threat |
| DBotScore.Indicator | The tested indicator |
| DBotScore.Type | Indicator type |
| DBotScore.Vendor | Vendor used to calculate the score |
| DBotScore.Score | The actual score |
Command Example
!cylance-protect-get-threats page_size=4
Raw Output
{
"av_industry":null,
"classification":"Malware",
"cylance_score":-1,
"file_size":3514368,
"global_quarantined":true,
"last_found":"2018-01-21T15:45:46",
"md5":"84C82835A5D21BBCF75A61706D8AB549",
"name":"wanncry.exe",
"safelisted":false,
"sha256":"ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA",
"sub_classification":"Ransom",
"unique_to_cylance":false
}
14. Update device threats
Updates multiple device threats.
Base Command
cylance-protect-update-device-threats
Input
| Input Parameter | Description |
| threat_id | SHA-256 of the convicted threat |
| event | Requested status update for the convicted threat |
| device_id | ID of the device to update |
Context Output
There is no context output for this command.
Command Example
!cylance-protect-update-device-threats threat_id=ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA
Raw Output
true
15. Get a list for hashes
Returns a list for hashes.
Base Command
cylance-protect-get-list
Input
| Input Parameter | Description |
| listTypeId |
Type of list to retrieve hashes for.
|
| page_size | Number of device records to retrieve for each page |
| page | Page number to request |
| threshold | Threat threshold |
Context Output
| Path | Description |
| File.Added | Timestamp when the file was added to the list |
| File.AddedBy | Tenant user ID who added the file to the list |
| File.AvIndustry | The score provided by the Anti-Virus industry |
| File.Category | The category for the list specified (for the Global Safe list only) |
| File.Classification | Threat classification assigned by Cylance |
| File.CylanceScore | The Cylance score assigned to the threat |
| File.ListType | list type that the threat belongs to |
| File.Md5 | MD5 of the threat |
| File.Sha256 | SHA-256 of the threat |
| File.Name | Threat name |
| DBotScore.Indicator | The tested indicator |
| DBotScore.Type | Indicator type |
| DBotScore.Vendor | Vendor used to calculate the score |
| DBotScore.Score | The actual score |
Command Example
!cylance-protect-get-list listTypeId=0 page_size=4
Raw Output
{
"added":"2017-11-07T04:30:04",
"added_by":"3ff9b11e-b64e-4350-97ba-aeb0a099b8ee",
"av_industry":null,
"category":"",
"classification":"Malware",
"cylance_score":-1,
"list_type":"GlobalQuarantine",
"md5":"84C82835A5D21BBCF75A61706D8AB549",
"name":"wanncry.exe",
"reason":"Malicious File Found",
"sha256":"ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA",
"sub_classification":"Ransom"
}
16. Download a threat
Downloads a threat attached to a specific SHA-256 hash.
Base Command
cylance-protect-download-threat
Input
| Argument Name | Description | Required |
|---|---|---|
| sha256 | The SHA-256 hash for the file you want to download | Required |
| threshold | File threshold to determine reputation | Optional |
| unzip | Check to return the file unzipped to the War Room | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| File.SHA256 | string | SHA-256 of the file |
| File.Name | string | File name |
| File.Size | number | File size |
| File.Safelisted | boolean | Safelisted |
| File.Timestamp | string | Timestamp |
| File.Md5 | string | MD5 |
| DBotScore.Indicator | string | The Indicator |
| DBotScore.Score | number | The DBot score |
| DBotScore.Type | string | The Indicator type |
| DBotScore.Vendor | string | The DBot score vendor |
| File.Malicious.Vendor | string | For malicious files, the vendor that made the decision |
| File.Malicious.Description | string | For malicious files, the reason that the vendor made the decision |
Command Example
!cylance-protect-download-threat sha256="0f427b33b824110427b2ba7be20740b45ea4da41bc1416dd55771edfb0c18f09" unzip="yes"
Context Example
DBotScore
{
"Indicator": "AutoitLocker.exe",
"Score": 3,
"Type": "file",
"Vendor": "Cylance Protect"
}
File
{
"DownloadURL": "https://cylanceephemeralfilestore.s3.amazonaws.com/0F/42/7B/33/0F427B33B824110427B2BA7BE20740B45EA4DA41BC1416DD55771EDFB0C18F09.zip? Signature=98kI7a19I2q%2BeE7Ef1un4BjSolQ%3D&Expires=1541875473&AWSAccessKeyId=AKIAIAD6JC2YTYVBFRFA",
"MD5": "2FC103D0D52466B63D44444CE12A5901",
"Malicious": {
"Description": "Score determined by get threat command",
"Vendor": "Cylance Protect"
},
"Name": "AutoitLocker.exe",
"SHA256": "0F427B33B824110427B2BA7BE20740B45EA4DA41BC1416DD55771EDFB0C18F09",
"Safelisted": false,
"Size": 405345,
"Timestamp": "0001-01-01T00:00:00"
}
Human Readable Output
17. Add a hash to a list
Adds an identified threat to either the Global Quarantine list or the Global Safe list for a particular Tenant.
Base Command
cylance-protect-add-hash-to-list
Input
| Argument Name | Description | Required |
|---|---|---|
| sha256 | SHA-256 hash to add to the Global Safe list | Required |
| listType | The list type the threat belongs to (GlobalQuarantine or GlobalSafe) | Required |
| reason | The reason why the file was added to the list | Optional |
| category | This field is required only if the list_type value is Global Safe. The value can be one ofthe following:• Admin Tool• Commercial Software• Drivers• Internal Application• Operating System• Security Software• None | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| File.SHA256 | string | The SHA-256 hash for the threat |
| File.Cylance.ListType | string | The list type the threat belongs to (GlobalQuarantine or GlobalSafe) |
| File.Cylance.Category | string | This field is required only if the list_type value is Global Safe. The value can be one of the following: • Admin Tool • Commercial Software • Drivers • Internal Application • Operating System • Security Software • None |
Command Example
!cylance-protect-add-hash-to-list sha256="9ACD45F5F3F2C7629E51FE3123D31296EF763F6ABC1F895CDD1BF1AFB9A7453B" listType="GlobalQuarantine"
Human Readable Output
18. Remove a threat from a list
Removes an identified threat from either the Global Quarantine list or the Global Safe list for a particular Tenant.
Base Command
cylance-protect-delete-hash-from-lists
Input
| Argument Name | Description | Required |
|---|---|---|
| sha256 | The SHA-256 hash for the threat | True |
| listType | The list type the threat belongs to (GlobalQuarantine or GlobalSafe) | True |
Context Output
| Path | Type | Description |
|---|---|---|
| File.SHA256 | string | SHA-256 of the file |
| File.Cylance.ListType | string | The list type the threat belongs to (GlobalQuarantine or GlobalSafe) |
Command Example
!cylance-protect-delete-hash-from-lists sha256="9ACD45F5F3F2C7629E51FE3123D31296EF763F6ABC1F895CDD1BF1AFB9A7453B" listType="GlobalQuarantine"
Human Readable Output
19. Get details for a policy
Gets details for a single policy.
Base Command
cylance-protect-get-policy-details
Input
| Argument Name | Description | Required |
|---|---|---|
| policyID | The Tenant policy ID to the service endpoint. | True |
Context Output
| Path | Type | Description |
|---|---|---|
| Cylance.Policy.ID | string | Policy ID |
| Cylance.Policy.Name | string | Policy name |
| Cylance.Policy.Timestamp | string | The date and time the policy was created, in UTC. |
20. Delete devices
Deletes one or more devices from an organization.
Base Command
cylance-protect-delete-devices
Input
| Argument Name | Description | Required |
|---|---|---|
| deviceIds | The unique identifiers for the devices to delete. The maximum number of Device IDs per request is 20. | Required |
| batch_size | The number of devices to delete per request (batch) | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Cylance.Device.Id | string | The unique identifier of the deletion request |
| Cylance.Device.Name | string | Device name |
| Cylance.Device.Deleted | string | Checks if the device was deleted (boolean) |
Command Example
!cylance-protect-get-policy-details policyID="7bcb0817-e9c9-444d-96e2-be9b59f429cb"
Context Example
Cylance
{
"Policy": {
"ID": "7bcb0817-e9c9-444d-96e2-be9b59f429cb",
"Name": "Test_Policy",
"Timestamp": "2018-03-05T12:29:03.000000+00:00"
}
}
Human Readable Output
cylance-protect-get-device-by-hostname
Allows a caller to request a specific device resource belonging to a Tenant by hostname
Base Command
cylance-protect-get-device-by-hostname
Input
| Argument Name | Description | Required |
|---|---|---|
| hostname | The hostname (DNS name). | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| CylanceProtect.Device.AgentVersion | String | The CylancePROTECT Agent version installed on the device. |
| CylanceProtect.Device.IPAddress | Unknown | The list of IP addresses for the device. |
| CylanceProtect.Device.MACAddress | Unknown | The list of MAC addresses for the device. |
| CylanceProtect.Device.Hostname | string | The hostname for the device. |
| CylanceProtect.Device.OSVersion | string | Device OS version. |
| CylanceProtect.Device.UpdateAvailable | boolean | If true, there is available update for the device. |
| CylanceProtect.Device.BackgroundDetection | boolean | If true, the Agent is currently running. |
| CylanceProtect.Device.DateFirstRegistered | date | The date and time (in UTC) when the device record was created. |
| CylanceProtect.Device.DateLastModified | date | The date and time (in UTC) when the device record was last modified. |
| CylanceProtect.Device.DateOffline | date | The date and time (in UTC) when the device last communicated with the Console. |
| CylanceProtect.Device.IsSafe | boolean | If true, there are no outstanding threats. |
| CylanceProtect.Device.LastLoggedInUser | string | Last logged in user. |
| CylanceProtect.Device.State | string | Machine state. |
| CylanceProtect.Device.ID | string | The unique identifier for the device. |
| CylanceProtect.Device.Name | string | Device name. |
| CylanceProtect.Device.UpdateType | string | Device update type. |
| CylanceProtect.Device.Policy.ID | string | Device policy ID. |
| CylanceProtect.Device.Policy.Name | string | Device policy name. |
| Endpoint.Hostname | string | Device hostname. |
| Endpoint.MACAddress | Unknown | The list of MAC addresses for the device. |
| Endpoint.IPAddress | Unknown | The list of IP addresses for the device. |
| Endpoint.OSVersion | string | Device OS version. |
Command Example
!cylance-protect-get-device-by-hostname hostname=WIN-5HMOGIEG6M5
Context Example
{
"CylanceProtect": {
"Device": {
"AgentVersion": "1.2.1418",
"BackgroundDetection": false,
"DateFirstRegistered": "2017-12-29T04:07:56",
"DateLastModified": null,
"DateOffline": "2020-02-07T02:25:34.151",
"Hostname": "WIN-5HMOGIEG6M5",
"ID": "b4eceeb0-8699-4d42-b853-155513042d6e",
"IPAddress": [
"127.0.0.1"
],
"IsSafe": true,
"LastLoggedInUser": "",
"MACAdress": [
"02-76-91-6B-0A-BB"
],
"Name": "WIN-5HMOGIEG6M5",
"OSVersion": "Microsoft Windows Server 2012 R2 Standard",
"Policy": {
"ID": "32e4aacd-7698-4ef0-93e8-3e6f1f5c6857",
"Name": "Default"
},
"State": "Offline",
"UpdateAvailable": false
}
},
"Endpoint": {
"Hostname": "WIN-5HMOGIEG6M5",
"IPAddress": [
"127.0.0.1"
],
"MACAdress": [
"02-76-91-6B-0A-BB"
],
"OSVersion": "Microsoft Windows Server 2012 R2 Standard"
}
}
Human Readable Output
Cylance Protect Device WIN-5HMOGIEG6M5
AgentVersion BackgroundDetection DateFirstRegistered DateOffline DlcmStatus HostName Id IpAddresses IsSafe MacAddresses Name OsKernelVersion OsVersion Policy Products State UpdateAvailable 1.2.1418 false 2017-12-29T04:07:56 2020-02-07T02:25:34.151 Unknown WIN-5HMOGIEG6M5 b4eceeb0-8699-4d42-b853-155513042d6e 127.0.0.1 true 02-76-91-6B-0A-BB WIN-5HMOGIEG6M5 6.3.0 Microsoft Windows Server 2012 R2 Standard Default {u’status’: u’Offline’, u’version’: u’1.2.1418’, u’name’: u’protect’} Offline false
21. Create a new Instaquery
cylance-optics-create-instaquery
Create a cylance InstaQuery
Base Command
cylance-optics-create-instaquery
Input
| Argument Name | Description | Required |
|---|---|---|
| name | InstaQuery name. | Required |
| description | InstaQuery description. | Required |
| artifact | InstaQuery artifact, select from the list. Possible values are: File, Process, NetworkConnection, RegistryKey. | Required |
| match_value_type | InstaQuery value type to match, select from the list. Possible values are: File.Path, File.Md5, File.Sha2, File.Owner, File.CreationDateTime, Process.Name, Process.Commandline, Process.PrimaryImagePath, Process.PrimaryImageMd5, Process.StartDateTime, NetworkConnection.DestAddr, NetworkConnection.DestPort, RegistryKey.ProcessName, RegistryKey.ProcessPrimaryImagePath, RegistryKey.ValueName, RegistryKey.FilePath, RegistryKey.FileMd5, RegistryKey.IsPersistencePoint. | Required |
| match_values | Value to search in InstaQuery. | Required |
| zone | Zone of the object. | Required |
| match_type | Match type fuzzy or exact. Possible values are: Fuzzy, Exact. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| InstaQuery.New.id | string | The unique identifier of the created InstaQuery. |
| InstaQuery.New.created_at | date | The Date and Time that the InstaQuery was created. |
| InstaQuery.New.progress | string | The progress of the InstaQuery. |
Command Example
!cylance-optics-create-instaquery name="Test Insta continue" description="Test only" artifact="File" match_value_type="File.Path" match_values="exe" zone="6608ca0e-88c6-4647-b276-271cc5ea4295" match_type="Fuzzy"
Human Readable Output
| Result | |
|---|---|
| case_sensitive | false |
| artifact | File |
| created_at | 2022-05-05T05:52:36Z |
| description | Test only |
| id | 9E2CCDA5A93918C588E6865ED6FEEA70 |
| match_type | Fuzzy |
| match_value_type | Path |
| match_values | exe |
| name | Test Insta continue |
| progress | |
| results_available | false |
| zones | 6608CA0E88C64647B276271CC5EA4295 |
22. Get Instaquery result
cylance-optics-get-instaquery-result
Get a cylance InstaQuery search result
Base Command
cylance-optics-get-instaquery-result
Input
| Argument Name | Description | Required |
|---|---|---|
| query_id | InstaQuery ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| InstaQuery.Results.result | string | The InstaQuery results. |
Command Example
!cylance-optics-get-instaquery-result query_id=9E2CCDA5A93918C588E6865ED6FEEA70
Human Readable Output
| Result | |
|---|---|
| id | 9E2CCDA5A93918C588E6865ED6FEEA70 |
| result | false |
| status | {u’@timestamp’: 1651729959.177779, u’HostName’: u’windows-server-‘, u’DeviceId’: u’ 65DB26864E364409B50DDC23291A3511 ‘, u’@version’: u’1’, u’CorrelationId’: u’ 9E2CCDA5A93918C588E6865ED6FEEA70 ‘, u’Result’: u’{“FirstObservedTime”: “1970-01-01T00:00:00.000Z”, “LastObservedTime”: “1970-01-01T00:00:00.000Z”, “Uid”: “dHrtLYQzbt9oJPxO8HaeyA==”, “Type”: “File”, “Properties”: {“Path”: “c:\program files\cylance\optics\ cyoptics.exe “, “CreationDateTime”: “2021-03-29T22:34:14.000Z”, “Md5”: “ A081D3268531485BF95DC1A15A5BC6B0 “, “Sha256”: “ 256809AABD3AB57949003B9AFCB556A9973222CDE81929982DAE7D306648E462 “, “Owner”: “NT AUTHORITY\SYSTEM”, “SuspectedFileType”: “Executable/PE”, “FileSignature”: “”, “Size”: “594104”, “OwnerUid”: “P3p6fdq3FlMsld6Rz95EOA==”}}’} |
23. List current Instaqueries
cylance-optics-list-instaquery
Get a list of InstaQuery
Base Command
cylance-optics-list-instaquery
Input
| Argument Name | Description | Required |
|---|---|---|
| page | number of page to collect. | Optional |
| page_size | number of items per page to collect. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| InstaQuery.List | string | The list of InstaQuery |
Command Example
!cylance-optics-list-instaquery page_size="10"
Human Readable Output
| Result | |
|---|---|
| page_items | {u’match_type’: u’Fuzzy’, u’name’: u’Test Insta continue’, u’created_at’: u’2022-05-05T05:52:36Z’, u’artifact’: u’File’, u’case_sensitive’: False, u’zones’: [u’6608CA0E88C64647B276271CC5EA4295’], u’progress’: {u’queried’: 0, u’responded’: 0}, u’match_value_type’: u’Path’, u’results_available’: True, u’match_values’: [u’exe’], u’id’: u’9E2CCDA5A93918C588E6865ED6FEEA70’, u’description’: u’Test only’} |
| page_number | 1 |
| page_size | 10 |
| total_number_of_items | 8 |
| total_pages | 1 |
Configuration parameters
server— Server URL (required)app_id— Application IDapp_secret— Application Secrettid— Tenant API Keyapp_creds— Application IDapi_key—proxy— Use system proxy settingsunsecure— Trust any certificate (not secure)isFetch— Fetch incidentsincidentType— Incident typefile_threshold— File ThresholdincidentFetchInterval— Incidents Fetch Interval
Commands (24)
-
cylance-optics-create-instaqueryCreate a cylance InstaQuery to search for artifacts in one or multiple zones.
-
cylance-optics-get-instaquery-resultGet a cylance InstaQuery search result.
-
cylance-optics-list-instaqueryGet a list of all current InstaQueries.
-
cylance-protect-add-hash-to-listAdds a convicted threat for a particular tenant to either the Global Quarantine list or the Global Safe list.
-
cylance-protect-create-zoneCreates (adds) a zone to your Console.
-
cylance-protect-delete-devicesDelete one or more devices from an organization.
-
cylance-protect-delete-hash-from-listsRemoves a convicted threat for a particular tenant from either the Global Quarantine list or the Global Safe list.
-
cylance-protect-download-threatDownloads the threat (file) attached to a specific SHA256 hash.
-
cylance-protect-get-deviceAllows a caller to request a specific device resource belonging to a Tenant.
-
cylance-protect-get-device-by-hostnameAllows a caller to request a specific device resource belonging to a Tenant by hostname.
-
cylance-protect-get-device-threatsAllows a caller to request a page with a list of threats found on a specific device.
-
cylance-protect-get-devicesAllows a caller to request a page with a list of Console device resources that belongings to a tenant, sorted by registration (created) date in descending order (most recent device registered listed first).
-
cylance-protect-get-indicators-reportProduces a CSV threat data report of the indicators.
-
cylance-protect-get-listReturns a list of global list resources for a tenant.
-
cylance-protect-get-policiesAllows the caller to get a list of tenant policies.
-
cylance-protect-get-policy-detailsReturns details for a single policy.
-
cylance-protect-get-threatRequests threat details for a specific threat.
-
cylance-protect-get-threat-devicesAllows a caller to request a list of devices on a specific threat.
-
cylance-protect-get-threatsReturns information about Cylance Protect threats.
-
cylance-protect-get-zoneRequest zone information for a specific zone in your organization.
-
cylance-protect-get-zonesRequest zone information for your organization. This will return the top 100 records.
-
cylance-protect-update-deviceAllows a caller to update a specific Console device resource belonging to a Tenant.
-
cylance-protect-update-device-threatsUpdates the status of a convicted threat. Can be "Quarantine" or "Waive".
-
cylance-protect-update-zoneUpdates a zone in your organization.
category: Endpoint provider: Arctic Wolf sectionorder: - Connect - Collect commonfields: id: Cylance Protect v2 version: -1 configuration: - defaultvalue: https://protectapi.cylance.com display: Server URL name: server required: true type: 0 section: Connect - display: Application ID name: app_id type: 0 section: Connect hidden: true required: false - display: Application Secret name: app_secret type: 4 section: Connect hidden: true required: false - display: Tenant API Key name: tid type: 4 section: Connect hidden: true required: false - display: Application ID name: app_creds type: 9 section: Connect displaypassword: Application Secret required: false - name: api_key type: 9 section: Connect hiddenusername: true displaypassword: Tenant API Key required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - display: Trust any certificate (not secure) name: unsecure type: 8 section: Connect advanced: true required: false - display: Fetch incidents name: isFetch type: 8 section: Collect required: false supportedModules: - agentix - xsiam - display: Incident type name: incidentType type: 13 section: Connect required: false supportedModules: - agentix - xsiam - defaultvalue: "-59" display: File Threshold name: file_threshold type: 0 section: Connect advanced: true required: false - defaultvalue: "1" display: Incidents Fetch Interval name: incidentFetchInterval type: 19 section: Collect advanced: true required: false supportedModules: - agentix - xsiam description: Manage Endpoints using Cylance protect. display: Cylance Protect v2 name: Cylance Protect v2 script: commands: - arguments: - description: The page number parameter is optional. When the value is not specified, the default is 1. name: pageNumber - description: The page size parameter is optional. When the value is not specified, the default is 10. Max is 200. name: pageSize description: Allows a caller to request a page with a list of Console device resources that belongings to a tenant, sorted by registration (created) date in descending order (most recent device registered listed first). name: cylance-protect-get-devices outputs: - contextPath: CylanceProtect.Device.AgentVersion description: The CylancePROTECT Agent version installed on the device. type: string - contextPath: CylanceProtect.Device.DateFirstRegistered description: The date and time (in UTC) when the device record was created. type: date - contextPath: CylanceProtect.Device.ID description: The device’s unique identifier. type: string - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.Hostname description: The device name. type: string - contextPath: CylanceProtect.Device.Policy.ID description: Device policy ID. type: string - contextPath: CylanceProtect.Device.State description: Machine state. type: string - contextPath: CylanceProtect.Device.Policy.Name description: Device policy name. type: string - contextPath: CylanceProtect.Device.Hostname description: The device name. type: string - contextPath: CylanceProtect.Device.MACAddress description: The list of MAC addresses for the device. type: unknown - contextPath: CylanceProtect.Device.IPAddress description: The list of IP addresses for the device. type: Unknown - arguments: - default: true description: The device ID. name: id required: true description: Allows a caller to request a specific device resource belonging to a Tenant. name: cylance-protect-get-device outputs: - contextPath: CylanceProtect.Device.AgentVersion description: The CylancePROTECT Agent version installed on the device. type: date - contextPath: CylanceProtect.Device.DateFirstRegistered description: The date and time (in UTC) when the device record was created. type: date - contextPath: CylanceProtect.Device.BackgroundDetection description: If true, the Agent is currently running. type: boolean - contextPath: CylanceProtect.Device.DateLastModified description: The date and time (in UTC) when the device record was last modified. type: date - contextPath: CylanceProtect.Device.DateOffline description: The date and time (in UTC) when the device last communicated with the Console. type: date - contextPath: CylanceProtect.Device.Hostname description: The hostname for the device. type: string - contextPath: CylanceProtect.Device.ID description: The unique identifier for the device. type: string - contextPath: CylanceProtect.Device.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.IsSafe description: If true, there are no outstanding threats. type: boolean - contextPath: CylanceProtect.Device.UpdateAvailable description: If true, there is available update for the device. type: boolean - contextPath: CylanceProtect.Device.State description: Machine state. type: string - contextPath: Endpoint.Hostname description: Device hostname. type: string - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.OSVersion description: Device OS version. type: string - contextPath: CylanceProtect.Device.OSVersion description: Device OS version. type: string - contextPath: CylanceProtect.Device.Name description: Device name. type: string - arguments: - default: true description: The hostname (DNS name). name: hostname required: true description: Allows a caller to request a specific device resource belonging to a Tenant by hostname. name: cylance-protect-get-device-by-hostname outputs: - contextPath: CylanceProtect.Device.AgentVersion description: The CylancePROTECT Agent version installed on the device. type: String - contextPath: CylanceProtect.Device.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.Hostname description: The hostname for the device. type: string - contextPath: CylanceProtect.Device.OSVersion description: Device OS version. type: string - contextPath: CylanceProtect.Device.UpdateAvailable description: If true, there is available update for the device. type: boolean - contextPath: CylanceProtect.Device.BackgroundDetection description: If true, the Agent is currently running. type: boolean - contextPath: CylanceProtect.Device.DateFirstRegistered description: The date and time (in UTC) when the device record was created. type: date - contextPath: CylanceProtect.Device.DateLastModified description: The date and time (in UTC) when the device record was last modified. type: date - contextPath: CylanceProtect.Device.DateOffline description: The date and time (in UTC) when the device last communicated with the Console. type: date - contextPath: CylanceProtect.Device.IsSafe description: If true, there are no outstanding threats. type: boolean - contextPath: CylanceProtect.Device.LastLoggedInUser description: Last logged in user. type: string - contextPath: CylanceProtect.Device.State description: Machine state. type: string - contextPath: CylanceProtect.Device.ID description: The unique identifier for the device. type: string - contextPath: CylanceProtect.Device.Name description: Device name. type: string - contextPath: CylanceProtect.Device.UpdateType description: Device update type. type: string - contextPath: CylanceProtect.Device.Policy.ID description: Device policy ID. type: string - contextPath: CylanceProtect.Device.Policy.Name description: Device policy name. type: string - contextPath: Endpoint.Hostname description: Device hostname. type: string - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.OSVersion description: Device OS version. type: string - arguments: - default: true description: The device ID. name: id required: true - description: The device name. name: name - description: The policy ID. name: policyId - description: Zones IDs to add. isArray: true name: addZones - description: Zones IDs to remove. isArray: true name: removeZones description: Allows a caller to update a specific Console device resource belonging to a Tenant. name: cylance-protect-update-device - arguments: - default: true description: The device ID. name: id required: true - description: If the threat score is less than or equal to the threshold, then file will be considered malicious. If the threshold is not specified, the default file threshold that was configured in the instance settings will be used. name: threshold - description: The page number. If not specified, the default is 1. name: pageNumber - description: The page size. If not specified, the default is 10. name: pageSize description: Allows a caller to request a page with a list of threats found on a specific device. name: cylance-protect-get-device-threats outputs: - contextPath: File.Classification description: The Cylance threat classification. type: string - contextPath: File.CylanceScore description: The Cylance score assigned to the threat. type: number - contextPath: File.DateFound description: The date and time (in UTC) when the threat was found on the device. type: string - contextPath: File.FilePath description: The file path where the threat was found on the device. type: string - contextPath: File.FileStatus description: The current status of the file on the device. This can be one of the following:Default (0), Quarantined (1), Whitelisted (2), Suspicious (3), FileRemoved (4), Corrupt (5). type: number - contextPath: File.Name description: The name of the threat. type: string - contextPath: File.SHA256 description: The SHA256 hash of the threat. type: string - contextPath: File.Sha256 description: The SHA256 hash of the threat. type: string - contextPath: File.MD5 description: The SHA256 hash of the threat. type: string - contextPath: File.SubClassification description: The Cylance threat sub-classification. type: string - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - description: The page number. If not specified, the default is 1. name: pageNumber - description: The page size. If not specified, the default is 10. Maximum is 200. name: pageSize description: Allows the caller to get a list of tenant policies. name: cylance-protect-get-policies outputs: - contextPath: CylanceProtect.Policies.DateAdded description: The date and time (in UTC) when the Console policy resource was first created. type: string - contextPath: CylanceProtect.Policies.DateModified description: The date and time (in UTC) when the Console policy resource was last modified. type: string - contextPath: CylanceProtect.Policies.DeviceCount description: The number of devices assigned to this policy. type: number - contextPath: CylanceProtect.Policies.Id description: The unique ID for the policy resource. type: string - contextPath: CylanceProtect.Policies.Name description: The name of the policy. type: string - contextPath: CylanceProtect.Policies.ZoneCount description: The number of zones assigned to this policy. type: number - arguments: - description: The name of the zone. name: name required: true - description: The unique ID for the policy assigned to the Zone. name: policy_id required: true - auto: PREDEFINED description: The criticality value of the Zone. name: criticality predefined: - Low - Medium - High required: true description: Creates (adds) a zone to your Console. name: cylance-protect-create-zone - arguments: - description: The page number parameter is optional. When the value is not specified, the default is 1. name: pageNumber - description: The page size parameter is optional. When the value is not specified, the default is 10. Max is 200. name: pageSize description: Request zone information for your organization. This will return the top 100 records. name: cylance-protect-get-zones outputs: - contextPath: CylanceProtect.Zones.Criticality description: The value of the zone (Low, Medium, or High). type: string - contextPath: CylanceProtect.Zones.DateCreated description: The date and time (in UTC) when the zone was created. type: string - contextPath: CylanceProtect.Zones.DateModified description: The date and time (in UTC) when the zone was last modified. type: string - contextPath: CylanceProtect.Zones.Id description: The unique ID of the zone. type: string - contextPath: CylanceProtect.Zones.Name description: The name of the zone. type: string - contextPath: CylanceProtect.Zones.PolicyId description: The unique ID of the policy assigned to the zone. type: string - contextPath: CylanceProtect.Zones.UpdateType description: The update type for the zone. type: string - contextPath: CylanceProtect.Zones.ZoneRuleId description: The unique ID for the zone rule created for the zone. type: string - arguments: - default: true description: The zone ID. name: id required: true description: Request zone information for a specific zone in your organization. name: cylance-protect-get-zone outputs: - contextPath: CylanceProtect.Zones.Criticality description: The value of the zone (Low, Medium, or High). type: string - contextPath: CylanceProtect.Zones.DateCreated description: The date and time (in UTC) when the zone was created. type: string - contextPath: CylanceProtect.Zones.DateModified description: The date and time (in UTC) when the zone was last modified. type: string - contextPath: CylanceProtect.Zones.Id description: The unique ID of the zone. type: string - contextPath: CylanceProtect.Zones.Name description: The name of the zone. type: string - contextPath: CylanceProtect.Zones.PolicyId description: The unique ID of the policy assigned to the zone. type: string - contextPath: CylanceProtect.Zones.UpdateType description: The update type for the zone. type: string - contextPath: CylanceProtect.Zones.ZoneRuleId description: The unique ID for the zone rule created for the zone. type: string - arguments: - default: true description: The zone ID. name: id required: true - description: The name of the zone. name: name - description: The unique ID for the policy assigned to the Zone. name: policyId - auto: PREDEFINED description: The criticality value of the zone. Can be "Low", "Medium", or "High". name: criticality predefined: - Low - Medium - High description: Updates a zone in your organization. name: cylance-protect-update-zone - arguments: - default: true description: The SHA256 hash of the threat. name: sha256 required: true description: Requests threat details for a specific threat. name: cylance-protect-get-threat outputs: - contextPath: File.AutoRun description: Indicates if the file is set to automatically run on system startup. type: boolean - contextPath: File.AvIndustry description: The score provided by the Anti-Virus industry. type: number - contextPath: File.CertIssuer description: The ID for the certificate issuer. type: string - contextPath: File.CertPublisher description: The ID for the certificate publisher. type: string - contextPath: File.CertTimestamp description: The date and time (in UTC) when the file was signed using the certificate. type: string - contextPath: File.Classification description: The threat classification for the threat. type: string - contextPath: File.CylanceScore description: The Cylance Score assigned to the threat. type: number - contextPath: File.DetectedBy description: The name of the Cylance module that detected the threat. type: string - contextPath: File.FileSize description: The size of the file. type: number - contextPath: File.GlobalQuarantine description: Identifies if the threat is on the Global Quarantine list. type: boolean - contextPath: File.MD5 description: The MD5 hash for the threat. type: string - contextPath: File.Name description: The name of the threat. type: string - contextPath: File.Running description: Identifies if the threat is executing, or another executable loaded or called it. type: boolean - contextPath: File.Safelisted description: Identifies if the threat is on the Safe List. type: boolean - contextPath: File.SHA256 description: The SHA256 hash for the threat. type: string - contextPath: File.Signed description: Identifies the file as signed or not signed. type: boolean - contextPath: File.SubClassification description: The threat sub-classification for the threat. type: string - contextPath: File.UniqueToCylance description: Whether the threat was identified by Cylance, and not by other anti-virus sources. type: boolean - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - default: true description: The SHA256 hash of the threat. name: sha256 required: true - description: The page number parameter is optional. When the value is not specified, the default is 1. name: pageNumber - description: The page size parameter is optional. When the value is not specified, the default is 10. Max is 200. name: pageSize description: Allows a caller to request a list of devices on a specific threat. name: cylance-protect-get-threat-devices outputs: - contextPath: CylanceProtect.Threat.Devices.ID description: The device ID. type: string - contextPath: CylanceProtect.Threat.Devices.DateFound description: The date and time (in UTC) when the threat was found on the device. type: date - contextPath: CylanceProtect.Threat.Devices.AgentVersion description: The agent version installed on the device. type: string - contextPath: CylanceProtect.Threat.Devices.FileStatus description: Current quarantine status of the file on the device. Default (0), Quarantined (1), Whitelisted (2), Suspicious (3), FileRemoved (4), Corrupt (5). type: number - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.Hostname description: The device name for the device. type: string - contextPath: CylanceProtect.Threat.Devices.PolicyID description: The unique identifier of the policy assigned to the device. If no policy is assigned, will be null. type: string - contextPath: CylanceProtect.Threat.Devices.State description: The state of the device. Can be "Offline" or "Online". type: string - contextPath: File.SHA256 description: The SHA256 hash of the threat. type: string - contextPath: File.Path description: The path where the file was found on the device. type: string - contextPath: CylanceProtect.Threat.Devices.Hostname description: The device name for the device. type: string - contextPath: CylanceProtect.Threat.Devices.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: CylanceProtect.Threat.Devices.MACAddress description: The list of MAC addresses for the device. type: Unknown - arguments: - description: Threat data report token. name: token required: true description: Produces a CSV threat data report of the indicators. name: cylance-protect-get-indicators-report - arguments: - description: The page size. If not specified, the default is 10. Maximum is 200. name: pageSize - description: The page number. If not specified, the default is 1. name: pageNumber description: Returns information about Cylance Protect threats. name: cylance-protect-get-threats outputs: - contextPath: File.Classification description: The threat classification for the threat. type: string - contextPath: File.SubClassification description: The threat sub-classification for the threat. type: string - contextPath: File.SHA256 description: The SHA256 hash for the threat. type: string - contextPath: File.Sha256 description: The SHA256 hash for the threat. type: string - contextPath: File.Safelisted description: Identifies if the threat is on the Safe List. type: boolean - contextPath: File.Name description: The name of the threat. type: string - contextPath: File.LastFound description: The date and time (in UTC) when the file was last found. type: string - contextPath: File.CylanceScore description: The Cylance Score assigned to the threat. type: number - contextPath: File.GlobalQuarantine description: Identifies if the threat is on the Global Quarantine list. type: string - contextPath: File.UniqueToCylance description: The threat was identified by Cylance but not by other anti-virus sources. type: string - contextPath: File.FileSize description: The size of the file. type: number - contextPath: File.MD5 description: The MD5 hash of the threat. type: string - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - description: The SHA256 hash of the convicted threat. name: threat_id required: true - auto: PREDEFINED description: The requested status update for the convicted threat. Can be "Quarantine" or "Waive". name: event predefined: - Quarantine - Waive required: true - description: ID of device to be updated. name: device_id required: true description: Updates the status of a convicted threat. Can be "Quarantine" or "Waive". execution: true name: cylance-protect-update-device-threats - arguments: - auto: PREDEFINED description: The type of the list for which to retrieve the ashes. Can be "GlobalQuarantine" or "GlobalSafe". name: listTypeId predefined: - GlobalQuarantine - GlobalSafe required: true - description: The page number. If not specified, the default is 1. name: pageNumber - description: The page size. If not specified, the default is 10. Maximum is 200. name: pageSize description: Returns a list of global list resources for a tenant. name: cylance-protect-get-list outputs: - contextPath: File.Added description: The timestamp when the file was added to the list. type: string - contextPath: File.AddedBy description: The tenant user ID who added the file to the list. type: string - contextPath: File.AvIndustry description: The score provided by the anti-virus industry. type: number - contextPath: File.Category description: The category for the list specified (Global Safe list only). type: string - contextPath: File.Classification description: The Cylance threat classification. type: string - contextPath: File.CylanceScore description: The Cylance score assigned to the threat. type: number - contextPath: File.ListType description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". type: string - contextPath: File.MD5 description: The MD5 hash of the threat. type: string - contextPath: File.SHA256 description: The SHA256 hash of the threat. type: string - contextPath: File.Sha256 description: The SHA256 hash of the threat. type: string - contextPath: File.Name description: The name of the threat. type: string - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - description: The SHA256 hash for the file to download. name: sha256 required: true - description: File threshold to determine the file reputation. name: threshold - auto: PREDEFINED defaultValue: "no" description: If "yes" the file is unzipped and returned to the War Room. name: unzip predefined: - "yes" - "no" description: Downloads the threat (file) attached to a specific SHA256 hash. name: cylance-protect-download-threat outputs: - contextPath: File.SHA256 description: SHA256 hash of the file. type: string - contextPath: File.Sha256 description: SHA256 hash of the file. type: string - contextPath: File.Name description: File name. type: string - contextPath: File.Size description: File size. type: number - contextPath: File.Safelisted description: Whether the file is on the Safe List. type: boolean - contextPath: File.Timestamp description: Timestamp. type: string - contextPath: File.MD5 description: MD5 hash of the file. type: string - contextPath: DBotScore.Indicator description: The Indicator. type: string - contextPath: DBotScore.Score description: The DBot score. type: number - contextPath: DBotScore.Type description: The Indicator type. type: string - contextPath: DBotScore.Vendor description: The DBot score vendor. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the reason for the vendor to make the decision. type: string - arguments: - description: SHA256 hash to add to the GlobalSafe list or GlobalQuarantine list. name: sha256 required: true - auto: PREDEFINED description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". name: listType predefined: - GlobalQuarantine - GlobalSafe required: true - defaultValue: Added by Demisto description: The reason why the file was added to the list. name: reason - auto: PREDEFINED defaultValue: None description: This field is required only if the list_type value is Global Safe. Can be "Admin Tool", "Commercial Software", "Drivers", "Internal Application", "Operating System", "Security Software", or "None". Default is "None". name: category predefined: - Admin Tool - Commercial Software - Drivers - Internal Application - Operating System - Security Software - None description: Adds a convicted threat for a particular tenant to either the Global Quarantine list or the Global Safe list. name: cylance-protect-add-hash-to-list outputs: - contextPath: File.SHA256 description: The SHA256 hash for the threat. type: string - contextPath: File.Cylance.ListType description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". type: string - contextPath: File.Cylance.Category description: This field is required only if the list_type value is Global Safe. Can be "Admin Tool", "Commercial Software", "Drivers", "Internal Application", "Operating System", "Security Software", or "None". type: string - arguments: - description: The SHA256 hash of the threat. name: sha256 required: true - auto: PREDEFINED description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". name: listType predefined: - GlobalSafe - GlobalQuarantine required: true description: Removes a convicted threat for a particular tenant from either the Global Quarantine list or the Global Safe list. execution: true name: cylance-protect-delete-hash-from-lists outputs: - contextPath: File.SHA256 description: SHA256 hash of the file. type: string - contextPath: File.Cylance.ListType description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". type: string - arguments: - description: The Tenant policy ID to the service endpoint. name: policyID required: true description: Returns details for a single policy. name: cylance-protect-get-policy-details outputs: - contextPath: Cylance.Policy.ID description: The ID of the policy. type: string - contextPath: Cylance.Policy.Name description: The name of the policy. type: string - contextPath: Cylance.Policy.Timestamp description: The date and time (in UTC) that the policy was created. type: string - arguments: - description: The unique identifiers for the devices to be deleted. The maximum number of Device IDs per request is 20. isArray: true name: deviceIds required: true - defaultValue: "20" description: The number of devices to delete per batch. The default is 20, which is also the maximum number of devices that can be deleted per request. name: batch_size description: Delete one or more devices from an organization. execution: true name: cylance-protect-delete-devices outputs: - contextPath: Cylance.Device.Id description: The unique identifier of the deletion request. type: string - contextPath: Cylance.Device.Name description: Device name. type: string - contextPath: Cylance.Device.Deleted description: A boolean to check if the device was deleted. type: boolean - name: cylance-optics-create-instaquery arguments: - name: name description: |- InstaQuery name ok test. required: true - name: description description: InstaQuery description. required: true - name: artifact description: InstaQuery artifact, select from the list. required: true auto: PREDEFINED predefined: - File - Process - NetworkConnection - RegistryKey - name: match_value_type description: InstaQuery value type to match, select from the list. required: true auto: PREDEFINED predefined: - File.Path - File.Md5 - File.Sha2 - File.Owner - File.CreationDateTime - Process.Name - Process.Commandline - Process.PrimaryImagePath - Process.PrimaryImageMd5 - Process.StartDateTime - NetworkConnection.DestAddr - NetworkConnection.DestPort - RegistryKey.ProcessName - RegistryKey.ProcessPrimaryImagePath - RegistryKey.ValueName - RegistryKey.FilePath - RegistryKey.FileMd5 - RegistryKey.IsPersistencePoint - name: match_values description: Value to search in InstaQuery. required: true - name: zone description: Zone of the object. required: true - name: match_type description: Match type fuzzy or exact. required: true auto: PREDEFINED predefined: - Fuzzy - Exact description: Create a cylance InstaQuery to search for artifacts in one or multiple zones. outputs: - contextPath: InstaQuery.New.id description: The unique identifier of the created InstaQuery. type: string - contextPath: InstaQuery.New.created_at description: The Date and Time that the InstaQuery was created. type: date - contextPath: InstaQuery.New.progress description: The progress of the InstaQuery. type: string - name: cylance-optics-get-instaquery-result arguments: - name: query_id description: InstaQuery ID. required: true description: Get a cylance InstaQuery search result. outputs: - contextPath: InstaQuery.Results.result description: The InstaQuery results. type: string - name: cylance-optics-list-instaquery arguments: - name: page_number description: The page number to collect. If not specified, the default is 1. defaultValue: "1" - name: page_size description: The page size. If not specified, the default is 20. defaultValue: "20" description: Get a list of all current InstaQueries. outputs: - contextPath: InstaQuery.List description: The list of InstaQuery. type: string dockerimage: demisto/auth-utils:1.0.0.11671917 isfetch: true script: '' subtype: python3 type: python tests: - Cylance Protect v2 Test fromversion: 5.0.0



