Deep Instinct

The Deep Learning cybersecurity platform, for zero time prevention.

Network Security · DeepInstinct

Details

IDDeep Instinct
ProviderDeep Instinct
CategoryNetwork Security
From Version5.0.0
Docker Imagedemisto/python3:3.12.8.3296088
Supported ModulesAgentix XSIAM

README

Overview


Deep Instinct
This integration was integrated and tested with version 2.3.1.17 of Deep Instinct

Configure Deep Instinct on Cortex XSOAR


  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for Deep Instinct.
  3. Click Add instance to create and configure a new integration instance.
    • Name: a textual name for the integration instance.
    • Base server URL
    • API Key
    • Fetch incidents
    • Incident type
    • First event ID to fetch from
  4. Click Test to validate the URLs, token, and connection.

Fetched Incidents Data


Commands


You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

  1. deepinstinct-get-device
  2. deepinstinct-get-events
  3. deepinstinct-get-all-groups
  4. deepinstinct-get-all-policies
  5. deepinstinct-add-hash-to-blacklist
  6. deepinstinct-add-hash-to-whitelist
  7. deepinstinct-remove-hash-from-blacklist
  8. deepinstinct-remove-hash-from-whitelist
  9. deepinstinct-add-devices-to-group
  10. deepinstinct-remove-devices-from-group
  11. deepinstinct-delete-files-remotely
  12. deepinstinct-terminate-processes
  13. deepinstinct-close-events

1. deepinstinct-get-device


get specific device by ID

Base Command

deepinstinct-get-device

Input
Argument Name Description Required
device_id The device ID Required
Context Output
Path Type Description
DeepInstinct.devices.ID number Device ID
DeepInstinct.devices.os string Device OS
DeepInstinct.devices.osv string Device OS version
DeepInstinct.devices.ip_address string Device IP address
DeepInstinct.devices.mac_address string Device mac address
DeepInstinct.devices.hostname string Device hostname
DeepInstinct.devices.domain string Device domain
DeepInstinct.devices.scanned_files number Num of device scanned files
DeepInstinct.devices.tag string Device tag
DeepInstinct.devices.connectivity_status string Device connectivity status
DeepInstinct.devices.deployment_status string Device deployment status
DeepInstinct.devices.last_registration string Device last registration datetime
DeepInstinct.devices.last_contact string Device last contact datetime
DeepInstinct.devices.distinguished_name string Device distinguished name
DeepInstinct.devices.group_name string Device group name
DeepInstinct.devices.group_id number Device group ID
DeepInstinct.devices.policy_name string Device policy name
DeepInstinct.devices.policy_id number Device policy ID
DeepInstinct.devices.log_status string Device log status
DeepInstinct.devices.agent_version string Device agent version
DeepInstinct.devices.brain_version string Device brain version
DeepInstinct.devices.msp_name string Device msp name
DeepInstinct.devices.msp_id number Device msp ID
DeepInstinct.devices.tenant_name string Device tenant name
DeepInstinct.devices.tenant_id number Device tenant ID
Command Example

!deepinstinct-get-device device_id=1

Context Example
{
    "DeepInstinct.Devices": {
        "last_registration": "2020-04-09T14:49:39.722292Z", 
        "domain": "", 
        "msp_name": "MSP 1", 
        "distinguished_name": "OU=Organizations & Sites,DC=bancshares,DC=mib", 
        "tenant_name": "Tenant 1", 
        "osv": "Windows", 
        "tag": "", 
        "id": 1, 
        "last_contact": "2020-04-09T14:49:39.711487Z", 
        "hostname": "Mock_2020-04-09 17:49:39.408405_1", 
        "mac_address": "00:00:00:00:00:00", 
        "brain_version": "115wt", 
        "connectivity_status": "EXPIRED", 
        "deployment_status": "REGISTERED", 
        "msp_id": 1, 
        "group_name": "Windows Default Group", 
        "ip_address": "192.168.88.80", 
        "log_status": "NA", 
        "tenant_id": 1, 
        "agent_version": "2.3.1.12", 
        "scanned_files": 0, 
        "policy_name": "Windows Default Policy", 
        "group_id": 3, 
        "os": "WINDOWS", 
        "policy_id": 3
    }
}
Human Readable Output

Device

agent_version brain_version connectivity_status deployment_status distinguished_name domain group_id group_name hostname id ip_address last_contact last_registration log_status mac_address msp_id msp_name os osv policy_id policy_name scanned_files tag tenant_id tenant_name
2.3.1.12 115wt EXPIRED REGISTERED OU=Organizations & Sites,DC=bancshares,DC=mib   3 Windows Default Group Mock_2020-04-09 17:49:39.408405_1 1 192.168.88.80 2020-04-09T14:49:39.711487Z 2020-04-09T14:49:39.722292Z NA 00:00:00:00:00:00 1 MSP 1 WINDOWS Windows 3 Windows Default Policy 0   1 Tenant 1

2. deepinstinct-get-events


Get all events. Max events in response can be 50, use first_event_id parameter to define first event id to get

Base Command

deepinstinct-get-events

Input
Argument Name Description Required
first_event_id First event id to get as max events in response can be 50 Optional
Context Output
Path Type Description
DeepInstinct.Events.events.ID number event ID
DeepInstinct.Events.events.device_id number event device ID
DeepInstinct.Events.events.file_hash string event file hash
DeepInstinct.Events.events.file_type string event file type
DeepInstinct.Events.events.file_archive_hash string event file archive hash
DeepInstinct.Events.events.path unknown event file path
DeepInstinct.Events.events.file_size number event file size
DeepInstinct.Events.events.threat_severity string event threat severity
DeepInstinct.Events.events.deep_classification string Deep Instinct classification
DeepInstinct.Events.events.file_status string event file status
sandbox_statusDeepInstinct.Events.events. string event sandbox status
DeepInstinct.Events.events.model string event model
DeepInstinct.Events.events.type string event type
DeepInstinct.Events.events.trigger string event trigger
DeepInstinct.Events.events.action string event action
DeepInstinct.Events.events.tenant_id number event tenant id
DeepInstinct.Events.events.msp_id number event msp id
DeepInstinct.Events.events.status unknown event status
DeepInstinct.Events.events.close_trigger unknown event close trigger
DeepInstinct.Events.events.recorded_device_info unknown event device info
DeepInstinct.Events.events.reoccurrence_count number event reoccurrence_count
Command Example

##### Context Example

{
“DeepInstinct.Events”: [
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “d1838b541ff7ffe6489d120d89dfa855665fd2c708491f336c7267069387053f”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 18127052,
“close_timestamp”: “2020-04-22T10:27:45.391625Z”,
“id”: 1,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:39.408405_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:41.170331Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “CLOSED”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:41.154850Z”,
“msp_id”: 1,
“close_trigger”: “CLOSED_BY_ADMIN”,
“path”: “c:\temp\file1.exe”,
“reoccurrence_count”: 0,
“device_id”: 1,
“tenant_id”: 1,
“file_archive_hash”: “d1838b541ff7ffe6489d120d89dfa855665fd2c708491f336c7267069387053f”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “edf34902ff17838b4bc709ff15b5265dd49f652ee75a1adf69df9ae5bc52f960”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 15090736,
“close_timestamp”: null,
“id”: 2,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:41.170765_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:41.810047Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “OPEN”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:41.805228Z”,
“msp_id”: 1,
“close_trigger”: null,
“path”: “c:\temp\file2.exe”,
“reoccurrence_count”: 0,
“device_id”: 2,
“tenant_id”: 1,
“file_archive_hash”: “edf34902ff17838b4bc709ff15b5265dd49f652ee75a1adf69df9ae5bc52f960”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “5b40c30d3a3b5c532bb9d338defc0eee6161ace8baf9fabe3c0cb1e73eeb8571”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 6100823,
“close_timestamp”: null,
“id”: 3,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:41.826874_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:42.406046Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “OPEN”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:42.400310Z”,
“msp_id”: 1,
“close_trigger”: null,
“path”: “c:\temp\file2.exe”,
“reoccurrence_count”: 0,
“device_id”: 3,
“tenant_id”: 1,
“file_archive_hash”: “5b40c30d3a3b5c532bb9d338defc0eee6161ace8baf9fabe3c0cb1e73eeb8571”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “727c2de729aa5fc471628a7bcfdf80353286a8a3981b9f0ffb58826e11518e3a”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 1274571,
“close_timestamp”: null,
“id”: 4,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:42.419868_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:43.096316Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “OPEN”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:43.091237Z”,
“msp_id”: 1,
“close_trigger”: null,
“path”: “c:\temp\file3.exe”,
“reoccurrence_count”: 0,
“device_id”: 4,
“tenant_id”: 1,
“file_archive_hash”: “727c2de729aa5fc471628a7bcfdf80353286a8a3981b9f0ffb58826e11518e3a”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “59c6185cc5fb87f8be1cbfc0903d1486c892bd2f84c1fab685eecd1517d041cf”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 5797166,
“close_timestamp”: null,
“id”: 5,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:43.110126_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:43.829681Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “OPEN”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:43.821976Z”,
“msp_id”: 1,
“close_trigger”: null,
“path”: “c:\temp\file4.exe”,
“reoccurrence_count”: 0,
“device_id”: 5,
“tenant_id”: 1,
“file_archive_hash”: “59c6185cc5fb87f8be1cbfc0903d1486c892bd2f84c1fab685eecd1517d041cf”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “8e83ec9a47265ed552f5369d25ae8f82074be91162c77d55dea5895637770e42”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 20730162,
“close_timestamp”: null,
“id”: 6,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:43.843723_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:44.453057Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “OPEN”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:44.446870Z”,
“msp_id”: 1,
“close_trigger”: null,
“path”: “c:\temp\file5.exe”,
“reoccurrence_count”: 0,
“device_id”: 6,
“tenant_id”: 1,
“file_archive_hash”: “8e83ec9a47265ed552f5369d25ae8f82074be91162c77d55dea5895637770e42”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “5fd4efe63a89a08e860a4a53c1efd7773d7ffc07a279be04bab5860492ce4dd4”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 9009328,
“close_timestamp”: “2020-04-20T11:45:00.987088Z”,
“id”: 7,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:44.464658_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:45.101055Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “CLOSED”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:45.096553Z”,
“msp_id”: 1,
“close_trigger”: “CLOSED_BY_ADMIN”,
“path”: “c:\temp\file6.exe”,
“reoccurrence_count”: 0,
“device_id”: 7,
“tenant_id”: 1,
“file_archive_hash”: “5fd4efe63a89a08e860a4a53c1efd7773d7ffc07a279be04bab5860492ce4dd4”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “56bb8166c11e63dbbc42b18ad61c27d0df2346e72deb6235ba166f97169aad2d”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 6975122,
“close_timestamp”: “2020-04-12T10:12:45.428138Z”,
“id”: 8,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:45.116724_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:45.889202Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “CLOSED”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:45.884910Z”,
“msp_id”: 1,
“close_trigger”: “CLOSED_BY_ADMIN”,
“path”: “c:\temp\file7.exe”,
“reoccurrence_count”: 0,
“device_id”: 8,
“tenant_id”: 1,
“file_archive_hash”: “56bb8166c11e63dbbc42b18ad61c27d0df2346e72deb6235ba166f97169aad2d”,
“action”: “PREVENTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “fbf76ae6c929d5b094e376e93ef7486f0527a4060c09f0dd1ebaf073b21dd81d”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 11929486,
“close_timestamp”: “2020-04-12T10:12:45.428138Z”,
“id”: 9,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:45.906650_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:46.515957Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “CLOSED”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:46.510849Z”,
“msp_id”: 1,
“close_trigger”: “CLOSED_BY_ADMIN”,
“path”: “c:\temp\file8.exe”,
“reoccurrence_count”: 0,
“device_id”: 9,
“tenant_id”: 1,
“file_archive_hash”: “fbf76ae6c929d5b094e376e93ef7486f0527a4060c09f0dd1ebaf073b21dd81d”,
“action”: “DETECTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
},
{
“comment”: null,
“last_action”: null,
“file_type”: “ZIP”,
“tenant_name”: “Tenant 1”,
“deep_classification”: null,
“file_hash”: “0a733f0b309cc330641a1205b928ae80cfd1f129d8c5df2e03f5cde13215b4b2”,
“threat_severity”: “NONE”,
“file_status”: “NOT_UPLOADED”,
“file_size”: 18723521,
“close_timestamp”: “2020-04-12T09:41:19.991511Z”,
“id”: 10,
“msp_name”: “MSP 1”,
“last_reoccurrence”: null,
“sandbox_status”: “NOT_READY_TO_GENERATE”,
“trigger”: “BRAIN”,
“recorded_device_info”: {
“tenant_name”: “Tenant 1”,
“hostname”: “Mock_2020-04-09 17:49:46.533149_1”,
“policy_name”: “Windows Default Policy”,
“tag”: “”,
“mac_address”: “00:00:00:00:00:00”,
“group_name”: “Windows Default Group”,
“os”: “WINDOWS”
},
“insertion_timestamp”: “2020-04-09T14:49:47.192314Z”,
“type”: “STATIC_ANALYSIS”,
“status”: “CLOSED”,
“certificate_thumbprint”: null,
“timestamp”: “2020-04-09T14:49:47.187327Z”,
“msp_id”: 1,
“close_trigger”: “CLOSED_BY_ADMIN”,
“path”: “c:\temp\file9.exe”,
“reoccurrence_count”: 0,
“device_id”: 10,
“tenant_id”: 1,
“file_archive_hash”: “0a733f0b309cc330641a1205b928ae80cfd1f129d8c5df2e03f5cde13215b4b2”,
“action”: “DETECTED”,
“model”: “FileEvent”,
“certificate_vendor_name”: null
}
]
}


##### Human Readable Output

### Events

|action|certificate_thumbprint|certificate_vendor_name|close_timestamp|close_trigger|comment|deep_classification|device_id|file_archive_hash|file_hash|file_size|file_status|file_type|id|insertion_timestamp|last_action|last_reoccurrence|model|msp_id|msp_name|path|recorded_device_info|reoccurrence_count|sandbox_status|status|tenant_id|tenant_name|threat_severity|timestamp|trigger|type|
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PREVENTED |  |  | 2020-04-22T10:27:45.391625Z | CLOSED_BY_ADMIN |  |  | 1 | d1838b541ff7ffe6489d120d89dfa855665fd2c708491f336c7267069387053f | d1838b541ff7ffe6489d120d89dfa855665fd2c708491f336c7267069387053f | 18127052 | NOT_UPLOADED | ZIP | 1 | 2020-04-09T14:49:41.170331Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file1.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:39.408405_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | CLOSED | 1 | Tenant 1 | NONE | 2020-04-09T14:49:41.154850Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  |  |  |  |  | 2 | edf34902ff17838b4bc709ff15b5265dd49f652ee75a1adf69df9ae5bc52f960 | edf34902ff17838b4bc709ff15b5265dd49f652ee75a1adf69df9ae5bc52f960 | 15090736 | NOT_UPLOADED | ZIP | 2 | 2020-04-09T14:49:41.810047Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file1.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:41.170765_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | OPEN | 1 | Tenant 1 | NONE | 2020-04-09T14:49:41.805228Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  |  |  |  |  | 3 | 5b40c30d3a3b5c532bb9d338defc0eee6161ace8baf9fabe3c0cb1e73eeb8571 | 5b40c30d3a3b5c532bb9d338defc0eee6161ace8baf9fabe3c0cb1e73eeb8571 | 6100823 | NOT_UPLOADED | ZIP | 3 | 2020-04-09T14:49:42.406046Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file2.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:41.826874_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | OPEN | 1 | Tenant 1 | NONE | 2020-04-09T14:49:42.400310Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  |  |  |  |  | 4 | 727c2de729aa5fc471628a7bcfdf80353286a8a3981b9f0ffb58826e11518e3a | 727c2de729aa5fc471628a7bcfdf80353286a8a3981b9f0ffb58826e11518e3a | 1274571 | NOT_UPLOADED | ZIP | 4 | 2020-04-09T14:49:43.096316Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file3.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:42.419868_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | OPEN | 1 | Tenant 1 | NONE | 2020-04-09T14:49:43.091237Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  |  |  |  |  | 5 | 59c6185cc5fb87f8be1cbfc0903d1486c892bd2f84c1fab685eecd1517d041cf | 59c6185cc5fb87f8be1cbfc0903d1486c892bd2f84c1fab685eecd1517d041cf | 5797166 | NOT_UPLOADED | ZIP | 5 | 2020-04-09T14:49:43.829681Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file4.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:43.110126_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | OPEN | 1 | Tenant 1 | NONE | 2020-04-09T14:49:43.821976Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  |  |  |  |  | 6 | 8e83ec9a47265ed552f5369d25ae8f82074be91162c77d55dea5895637770e42 | 8e83ec9a47265ed552f5369d25ae8f82074be91162c77d55dea5895637770e42 | 20730162 | NOT_UPLOADED | ZIP | 6 | 2020-04-09T14:49:44.453057Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file5.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:43.843723_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | OPEN | 1 | Tenant 1 | NONE | 2020-04-09T14:49:44.446870Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  | 2020-04-20T11:45:00.987088Z | CLOSED_BY_ADMIN |  |  | 7 | 5fd4efe63a89a08e860a4a53c1efd7773d7ffc07a279be04bab5860492ce4dd4 | 5fd4efe63a89a08e860a4a53c1efd7773d7ffc07a279be04bab5860492ce4dd4 | 9009328 | NOT_UPLOADED | ZIP | 7 | 2020-04-09T14:49:45.101055Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file6.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:44.464658_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | CLOSED | 1 | Tenant 1 | NONE | 2020-04-09T14:49:45.096553Z | BRAIN | STATIC_ANALYSIS |
| PREVENTED |  |  | 2020-04-12T10:12:45.428138Z | CLOSED_BY_ADMIN |  |  | 8 | 56bb8166c11e63dbbc42b18ad61c27d0df2346e72deb6235ba166f97169aad2d | 56bb8166c11e63dbbc42b18ad61c27d0df2346e72deb6235ba166f97169aad2d | 6975122 | NOT_UPLOADED | ZIP | 8 | 2020-04-09T14:49:45.889202Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file7.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:45.116724_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | CLOSED | 1 | Tenant 1 | NONE | 2020-04-09T14:49:45.884910Z | BRAIN | STATIC_ANALYSIS |
| DETECTED |  |  | 2020-04-12T10:12:45.428138Z | CLOSED_BY_ADMIN |  |  | 9 | fbf76ae6c929d5b094e376e93ef7486f0527a4060c09f0dd1ebaf073b21dd81d | fbf76ae6c929d5b094e376e93ef7486f0527a4060c09f0dd1ebaf073b21dd81d | 11929486 | NOT_UPLOADED | ZIP | 9 | 2020-04-09T14:49:46.515957Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file8.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:45.906650_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | CLOSED | 1 | Tenant 1 | NONE | 2020-04-09T14:49:46.510849Z | BRAIN | STATIC_ANALYSIS |
| DETECTED |  |  | 2020-04-12T09:41:19.991511Z | CLOSED_BY_ADMIN |  |  | 10 | 0a733f0b309cc330641a1205b928ae80cfd1f129d8c5df2e03f5cde13215b4b2 | 0a733f0b309cc330641a1205b928ae80cfd1f129d8c5df2e03f5cde13215b4b2 | 18723521 | NOT_UPLOADED | ZIP | 10 | 2020-04-09T14:49:47.192314Z |  |  | FileEvent | 1 | MSP 1 | c:\temp\file9.exe | os: WINDOWS mac_address: 00:00:00:00:00:00 hostname: Mock_2020-04-09 17:49:46.533149_1 tag:  group_name: Windows Default Group policy_name: Windows Default Policy tenant_name: Tenant 1 | 0 | NOT_READY_TO_GENERATE | CLOSED | 1 | Tenant 1 | NONE | 2020-04-09T14:49:47.187327Z | BRAIN | STATIC_ANALYSIS |

### 3. deepinstinct-get-all-groups

---
get all groups

##### Base Command

`deepinstinct-get-all-groups`

##### Input

| __Argument Name__ | __Description__ | __Required__ |
| --- | --- | --- |

##### Context Output

| __Path__ | __Type__ | __Description__ |
| --- | --- | --- |
| DeepInstinct.Groups.ID | number | group id |
| DeepInstinct.Groups.os | string | group operation system |
| DeepInstinct.Groups.name | string | group name |
| DeepInstinct.Groups.policy_id | number | group policy ID |
| DeepInstinct.Groups.is_default_group | boolean | True if group is a default group, false otherwise |
| DeepInstinct.Groups.msp_name | string | msp name |
| DeepInstinct.Groups.msp_id | number | msp ID |

##### Command Example

```!deepinstinct-get-all-groups first_event_id=0```

##### Context Example

{
“DeepInstinct.Groups”: [
{
“name”: “Android Default Group”,
“msp_name”: “MSP 1”,
“msp_id”: 1,
“is_default_group”: true,
“os”: “ANDROID”,
“id”: 1,
“policy_id”: 1
},
{
“name”: “iOS Default Group”,
“msp_name”: “MSP 1”,
“msp_id”: 1,
“is_default_group”: true,
“os”: “IOS”,
“id”: 2,
“policy_id”: 2
},
{
“name”: “Windows Default Group”,
“msp_name”: “MSP 1”,
“msp_id”: 1,
“is_default_group”: true,
“os”: “WINDOWS”,
“id”: 3,
“policy_id”: 3
},
{
“name”: “macOS Default Group”,
“msp_name”: “MSP 1”,
“msp_id”: 1,
“is_default_group”: true,
“os”: “MAC”,
“id”: 4,
“policy_id”: 4
},
{
“name”: “Chrome OS Default Group”,
“msp_name”: “MSP 1”,
“msp_id”: 1,
“is_default_group”: true,
“os”: “CHROME”,
“id”: 5,
“policy_id”: 5
},
{
“name”: “Test”,
“msp_name”: “MSP 1”,
“msp_id”: 1,
“is_default_group”: false,
“priority”: 1,
“os”: “WINDOWS”,
“id”: 6,
“policy_id”: 3
}
]
}


##### Human Readable Output

### Groups

|id|is_default_group|msp_id|msp_name|name|os|policy_id|
|---|---|---|---|---|---|---|
| 1 | true | 1 | MSP 1 | Android Default Group | ANDROID | 1 |
| 2 | true | 1 | MSP 1 | iOS Default Group | IOS | 2 |
| 3 | true | 1 | MSP 1 | Windows Default Group | WINDOWS | 3 |
| 4 | true | 1 | MSP 1 | macOS Default Group | MAC | 4 |
| 5 | true | 1 | MSP 1 | Chrome OS Default Group | CHROME | 5 |
| 6 | false | 1 | MSP 1 | Test | WINDOWS | 3 |

### 4. deepinstinct-get-all-policies

---
get all policies

##### Base Command

`deepinstinct-get-all-policies`

##### Input

| __Argument Name__ | __Description__ | __Required__ |
| --- | --- | --- |

##### Context Output

| __Path__ | __Type__ | __Description__ |
| --- | --- | --- |
| DeepInstinct.Policies.ID | number | policy ID |
| DeepInstinct.Policies.name | string | policy name |
| DeepInstinct.Policies.os | string | policy operating system |
| DeepInstinct.Policies.is_default_policy | boolean | True if policy is a default policy, False otherwise |
| DeepInstinct.Policies.msp_id | number | msp ID |
| DeepInstinct.Policies.msp_name | string | msp name |

##### Command Example

```!deepinstinct-get-all-policies```

##### Context Example

{
“DeepInstinct.Policies”: [
{
“name”: “iOS Default Policy”,
“is_default_policy”: true,
“msp_id”: 1,
“msp_name”: “MSP 1”,
“os”: “IOS”,
“id”: 2
},
{
“name”: “Windows Default Policy”,
“is_default_policy”: true,
“msp_id”: 1,
“msp_name”: “MSP 1”,
“os”: “WINDOWS”,
“id”: 3
},
{
“name”: “macOS Default Policy”,
“is_default_policy”: true,
“msp_id”: 1,
“msp_name”: “MSP 1”,
“os”: “MAC”,
“id”: 4
},
{
“name”: “Chrome OS Default Policy”,
“is_default_policy”: true,
“msp_id”: 1,
“msp_name”: “MSP 1”,
“os”: “CHROME”,
“id”: 5
},
{
“name”: “testPolicy”,
“is_default_policy”: false,
“msp_id”: 1,
“msp_name”: “MSP 1”,
“os”: “WINDOWS”,
“id”: 6
},
{
“name”: “Android Default Policy”,
“is_default_policy”: true,
“msp_id”: 1,
“msp_name”: “MSP 1”,
“os”: “ANDROID”,
“id”: 1
}
]
}
```

Human Readable Output

Policies

id is_default_policy msp_id msp_name name os
2 true 1 MSP 1 iOS Default Policy IOS
3 true 1 MSP 1 Windows Default Policy WINDOWS
4 true 1 MSP 1 macOS Default Policy MAC
5 true 1 MSP 1 Chrome OS Default Policy CHROME
6 false 1 MSP 1 testPolicy WINDOWS
1 true 1 MSP 1 Android Default Policy ANDROID

5. deepinstinct-add-hash-to-blacklist


add file hash to block list

Base Command

deepinstinct-add-hash-to-blacklist

Input
Argument Name Description Required
policy_id policy ID Required
file_hash file hash Required
comment Optional, add comment to hash field Optional
Context Output

There is no context output for this command.

Command Example

!deepinstinct-add-hash-to-blacklist file_hash=bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb00 policy_id=6 comment=mycomment

Human Readable Output

ok

6. deepinstinct-add-hash-to-whitelist


add file hash to allow list

Base Command

deepinstinct-add-hash-to-whitelist

Input
Argument Name Description Required
policy_id policy ID Required
file_hash file hash Required
comment Optional, add comment to hash field Optional
Context Output

There is no context output for this command.

Command Example

!deepinstinct-add-hash-to-whitelist file_hash=wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww00 policy_id=6 comment=mycomment

Human Readable Output

ok

7. deepinstinct-remove-hash-from-blacklist


remove file hash from block list

Base Command

deepinstinct-remove-hash-from-blacklist

Input
Argument Name Description Required
policy_id policy ID Required
file_hash file hash Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-remove-hash-from-blacklist file_hash=bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb00 policy_id=6

Human Readable Output

ok

8. deepinstinct-remove-hash-from-whitelist


remove file hash from allow list

Base Command

deepinstinct-remove-hash-from-whitelist

Input
Argument Name Description Required
policy_id policy ID Required
file_hash file hash Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-remove-hash-from-whitelist file_hash=wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww00 policy_id=6

Human Readable Output

ok

9. deepinstinct-add-devices-to-group


add multiple devices to group

Base Command

deepinstinct-add-devices-to-group

Input
Argument Name Description Required
group_id group ID Required
device_ids comma separated devices ids Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-add-devices-to-group device_ids=1 group_id=6

Human Readable Output

ok

10. deepinstinct-remove-devices-from-group


remove list of devices from group

Base Command

deepinstinct-remove-devices-from-group

Input
Argument Name Description Required
group_id group ID to remove from Required
device_ids comma separeted list of device ids to remove Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-remove-devices-from-group device_ids=1 group_id=6

Human Readable Output

ok

11. deepinstinct-delete-files-remotely


delete multiple files remotely

Base Command

deepinstinct-delete-files-remotely

Input
Argument Name Description Required
event_ids comma separeted list of event ids Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-delete-files-remotely event_ids=1

Human Readable Output

ok

12. deepinstinct-terminate-processes


terminate list of processes

Base Command

deepinstinct-terminate-processes

Input
Argument Name Description Required
event_ids comma separeted list of event ids Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-terminate-processes event_ids=1,2

Human Readable Output

ok

13. deepinstinct-close-events


close list of events

Base Command

deepinstinct-close-events

Input
Argument Name Description Required
event_ids comma separeted list of event ids Required
Context Output

There is no context output for this command.

Command Example

!deepinstinct-close-events event_ids=1

Human Readable Output

ok

Configuration parameters

  • base_url — Base server URL (required)
  • apikey — API Key (required)
  • isFetch — Fetch incidents
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • first_fetch_id — First event ID to fetch from

Commands (13)

  • deepinstinct-add-devices-to-group

    add multiple devices to group.

  • deepinstinct-add-hash-to-blacklist

    add file hash to block list.

  • deepinstinct-add-hash-to-whitelist

    add file hash to allow list.

  • deepinstinct-close-events

    close list of events.

  • deepinstinct-delete-files-remotely

    delete multiple files remotely.

  • deepinstinct-get-all-groups

    get all groups.

  • deepinstinct-get-all-policies

    get all policies.

  • deepinstinct-get-device

    get specific device by ID.

  • deepinstinct-get-events

    Get all events. Max events in response can be 50, use first_event_id parameter to define first event id to get.

  • deepinstinct-remove-devices-from-group

    remove list of devices from group.

  • deepinstinct-remove-hash-from-blacklist

    remove file hash from block list.

  • deepinstinct-remove-hash-from-whitelist

    remove file hash from allow list.

  • deepinstinct-terminate-processes

    terminate list of processes.

commonfields:
  id: Deep Instinct
  version: -1
name: Deep Instinct
display: Deep Instinct
category: Network Security
sectionorder:
- Connect
- Collect
provider: Deep Instinct
description: The Deep Learning cybersecurity platform, for zero time prevention.
configuration:
- display: Base server URL
  name: base_url
  defaultvalue: "https://my-deep-instinct-path.deepinstinctweb.com"
  type: 0
  required: true
  section: Connect
- display: API Key
  name: apikey
  defaultvalue: ""
  type: 4
  required: true
  section: Connect
- display: Fetch incidents
  name: isFetch
  type: 8
  required: false
  section: Collect
- display: Incident type
  name: incidentType
  type: 13
  required: false
  section: Collect
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  advanced: true
  section: Collect
- display: First event ID to fetch from
  name: first_fetch_id
  defaultvalue: "0"
  type: 0
  required: false
  section: Collect
script:
  commands:
  - name: deepinstinct-get-device
    arguments:
    - name: device_id
      required: true
      description: The device ID.
    outputs:
    - contextPath: DeepInstinct.devices.ID
      description: Device ID.
      type: number
    - contextPath: DeepInstinct.devices.os
      description: Device OS.
      type: string
    - contextPath: DeepInstinct.devices.osv
      description: Device OS version.
      type: string
    - contextPath: DeepInstinct.devices.ip_address
      description: Device IP address.
      type: string
    - contextPath: DeepInstinct.devices.mac_address
      description: Device mac address.
      type: string
    - contextPath: DeepInstinct.devices.hostname
      description: Device hostname.
      type: string
    - contextPath: DeepInstinct.devices.domain
      description: Device domain.
      type: string
    - contextPath: DeepInstinct.devices.scanned_files
      description: Num of device scanned files.
      type: number
    - contextPath: DeepInstinct.devices.tag
      description: Device tag.
      type: string
    - contextPath: DeepInstinct.devices.connectivity_status
      description: Device connectivity status.
      type: string
    - contextPath: DeepInstinct.devices.deployment_status
      description: Device deployment status.
      type: string
    - contextPath: DeepInstinct.devices.last_registration
      description: Device last registration datetime.
      type: string
    - contextPath: DeepInstinct.devices.last_contact
      description: Device last contact datetime.
      type: string
    - contextPath: DeepInstinct.devices.distinguished_name
      description: Device distinguished name.
      type: string
    - contextPath: DeepInstinct.devices.group_name
      description: Device group name.
      type: string
    - contextPath: DeepInstinct.devices.group_id
      description: Device group ID.
      type: number
    - contextPath: DeepInstinct.devices.policy_name
      description: Device policy name.
      type: string
    - contextPath: DeepInstinct.devices.policy_id
      description: Device policy ID.
      type: number
    - contextPath: DeepInstinct.devices.log_status
      description: Device log status.
      type: string
    - contextPath: DeepInstinct.devices.agent_version
      description: Device agent version.
      type: string
    - contextPath: DeepInstinct.devices.brain_version
      description: Device brain version.
      type: string
    - contextPath: DeepInstinct.devices.msp_name
      description: Device msp name.
      type: string
    - contextPath: DeepInstinct.devices.msp_id
      description: Device msp ID.
      type: number
    - contextPath: DeepInstinct.devices.tenant_name
      description: Device tenant name.
      type: string
    - contextPath: DeepInstinct.devices.tenant_id
      description: Device tenant ID.
      type: number
    description: get specific device by ID.
  - name: deepinstinct-get-events
    arguments:
    - name: first_event_id
      description: First event id to get as max events in response can be 50.
      defaultValue: "0"
    outputs:
    - contextPath: DeepInstinct.Events.events.ID
      description: event ID.
      type: number
    - contextPath: DeepInstinct.Events.events.device_id
      description: event device ID.
      type: number
    - contextPath: DeepInstinct.Events.events.file_hash
      description: event file hash.
      type: string
    - contextPath: DeepInstinct.Events.events.file_type
      description: event file type.
      type: string
    - contextPath: DeepInstinct.Events.events.file_archive_hash
      description: event file archive hash.
      type: string
    - contextPath: DeepInstinct.Events.events.path
      description: event file path.
    - contextPath: DeepInstinct.Events.events.file_size
      description: event file size.
      type: number
    - contextPath: DeepInstinct.Events.events.threat_severity
      description: event threat severity.
      type: string
    - contextPath: DeepInstinct.Events.events.deep_classification
      description: Deep Instinct classification.
      type: string
    - contextPath: DeepInstinct.Events.events.file_status
      description: event file status.
      type: string
    - contextPath: sandbox_statusDeepInstinct.Events.events.
      description: event sandbox status.
      type: string
    - contextPath: DeepInstinct.Events.events.model
      description: event model.
      type: string
    - contextPath: DeepInstinct.Events.events.type
      description: event type.
      type: string
    - contextPath: DeepInstinct.Events.events.trigger
      description: event trigger.
      type: string
    - contextPath: DeepInstinct.Events.events.action
      description: event action.
      type: string
    - contextPath: DeepInstinct.Events.events.tenant_id
      description: event tenant id.
      type: number
    - contextPath: DeepInstinct.Events.events.msp_id
      description: event msp id.
      type: number
    - contextPath: DeepInstinct.Events.events.status
      description: event status.
      type: string
    - contextPath: DeepInstinct.Events.events.close_trigger
      description: event close trigger.
      type: string
    - contextPath: DeepInstinct.Events.events.reoccurrence_count
      description: event reoccurrence_count.
      type: number
    description: Get all events. Max events in response can be 50, use first_event_id parameter to define first event id to get.
  - name: deepinstinct-get-all-groups
    arguments: []
    outputs:
    - contextPath: DeepInstinct.Groups.ID
      description: group id.
      type: number
    - contextPath: DeepInstinct.Groups.os
      description: group operation system.
      type: string
    - contextPath: DeepInstinct.Groups.name
      description: group name.
      type: string
    - contextPath: DeepInstinct.Groups.policy_id
      description: group policy ID.
      type: number
    - contextPath: DeepInstinct.Groups.is_default_group
      description: True if group is a default group, false otherwise.
      type: boolean
    - contextPath: DeepInstinct.Groups.msp_name
      description: msp name.
      type: string
    - contextPath: DeepInstinct.Groups.msp_id
      description: msp ID.
      type: number
    description: get all groups.
  - name: deepinstinct-get-all-policies
    arguments: []
    outputs:
    - contextPath: DeepInstinct.Policies.ID
      description: policy ID.
      type: number
    - contextPath: DeepInstinct.Policies.name
      description: policy name.
      type: string
    - contextPath: DeepInstinct.Policies.os
      description: policy operating system.
      type: string
    - contextPath: DeepInstinct.Policies.is_default_policy
      description: True if policy is a default policy, False otherwise.
      type: boolean
    - contextPath: DeepInstinct.Policies.msp_id
      description: msp ID.
      type: number
    - contextPath: DeepInstinct.Policies.msp_name
      description: msp name.
      type: string
    description: get all policies.
  - name: deepinstinct-add-hash-to-blacklist
    arguments:
    - name: policy_id
      required: true
      description: policy ID.
    - name: file_hash
      required: true
      description: file hash.
    - name: comment
      description: Optional, add comment to hash field.
      defaultValue: ''
    description: add file hash to block list.
  - name: deepinstinct-add-hash-to-whitelist
    arguments:
    - name: policy_id
      required: true
      description: policy ID.
    - name: file_hash
      required: true
      description: file hash.
    - name: comment
      description: Optional, add comment to hash field.
      defaultValue: ''
    description: add file hash to allow list.
  - name: deepinstinct-remove-hash-from-blacklist
    arguments:
    - name: policy_id
      required: true
      description: policy ID.
    - name: file_hash
      required: true
      description: file hash.
    description: remove file hash from block list.
  - name: deepinstinct-remove-hash-from-whitelist
    arguments:
    - name: policy_id
      required: true
      description: policy ID.
    - name: file_hash
      required: true
      description: file hash.
    description: remove file hash from allow list.
  - name: deepinstinct-add-devices-to-group
    arguments:
    - name: group_id
      required: true
      description: group ID.
    - name: device_ids
      required: true
      description: comma separated devices ids.
      isArray: true
    description: add multiple devices to group.
  - name: deepinstinct-remove-devices-from-group
    arguments:
    - name: group_id
      required: true
      description: group ID to remove from.
    - name: device_ids
      required: true
      description: comma separeted list of device ids to remove.
      isArray: true
    description: remove list of devices from group.
  - name: deepinstinct-delete-files-remotely
    arguments:
    - name: event_ids
      required: true
      description: comma separeted list of event ids.
      isArray: true
    description: delete multiple files remotely.
  - name: deepinstinct-terminate-processes
    arguments:
    - name: event_ids
      required: true
      description: comma separeted list of event ids.
      isArray: true
    description: terminate list of processes.
  - name: deepinstinct-close-events
    arguments:
    - name: event_ids
      required: true
      description: comma separeted list of event ids.
      isArray: true
    description: close list of events.
  dockerimage: demisto/python3:3.12.8.3296088
  isfetch: true
  script: '-'
  type: python
  subtype: python3
fromversion: 5.0.0
tests:
- No tests (auto formatted)