Details
| ID | KnowBe4KMSAT |
|---|---|
| Provider | Vista Equity Partners |
| Category | Network Security |
| From Version | 6.5.0 |
| Docker Image | demisto/python3:3.10.10.48392 |
| Supported Modules | Agentix |
README
KnowBe4’s KMSAT Console is a security awareness training and simulated phishing console that you can use to improve your organization’s overall security. This integration pack allows you to push and pull your external data to and from your KMSAT console.
| What Does This Pack Do? |
|---|
| 1. Pull Risk Score history for your account |
| 2. Pull Risk Score history for your groups |
| 3. Pull Risk Score history for your users |
| 4. Pull all Phishing Security Test (PST) results for your account |
| 5. Pull Phishing Security Test (PST) results for a specific campaign |
| 6. Pull statuses of your training campaigns |
| 7. Pull a list of your users’ training campaign enrollments |
| 8. Pull your users’ event data |
| 9. Add events to User Timelines in KMSAT |
| 10. Delete events from User Timelines in KMSAT |
Configuration
| Parameter | Description | Requirement |
|---|---|---|
| Instance Name | Enter a name for your KMSAT instance. | Required |
| Your Reporting Server URL | Enter the Reporting Server URL for your KMSAT instance, which you can find in KnowBe4’s Reporting API documentation. | Required |
| Reporting API Key | Enter the Reporting API key to use for the connection. To generate this key, see KnowBe4’s Account Settings: API documentation. | Required |
| Your User Events Server URL | Enter the User Event URL for your KMSAT instance, which you can find in KnowBe4’s User Event API documentation. | Required |
| User Events API Key | Enter the User Event API key to use for the connection. To generate this key, see KnowBe4’s User Event API documentation. | Required |
Commands
| Commands | Description |
|---|---|
| kmsat-account-info-list | Displays account information |
| kmsat-account-risk-score-history-list | Displays your organization’s Risk Score history |
| kmsat-groups-list | Displays all groups |
| kmsat-groups-risk-score-history-list | Displays Risk Score history for groups |
| kmsat-groups-members-list | Displays members of groups |
| kmsat-users-risk-score-history-list | Displays Risk Score history for users |
| kmsat-phishing-security-tests-list | Displays all PSTs |
| kmsat-phishing-security-tests-recipients-list | Displays PSTs and user data for enrolled users |
| kmsat-phishing-security-tests-failed-recipients-list | Displays failed PSTs and user data for enrolled users |
| kmsat-phishing-campaign-security-tests-list | Displays PSTs for a phishing campaign |
| kmsat-training-campaigns-list | Displays all training campaigns |
| kmsat-training-enrollments-list | Displays all training enrollments |
| kmsat-user-event-list | Displays a user event by id |
| kmsat-user-events-list | Displays all user events |
| kmsat-user-event-types-list | Displays types of user events |
| kmsat-user-event-create | Creates an event on the User Timeline |
| kmsat-user-event-delete | Deletes an event from the User Timeline |
| kmsat-user-event-status-list | Lists the status of user event request by request id |
| kmsat-user-event-statuses-list | Lists the statuses of user event requests |
kmsat-account-info-list
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.AccountInfo.name | String | Account name |
| KMSAT.AccountInfo.type | String | Account type |
| KMSAT.AccountInfo.domains | String | Account domains |
| KMSAT.AccountInfo.admins.id | Number | Account admin ID |
| KMSAT.AccountInfo.admins.first_name | String | Account admin first name |
| KMSAT.AccountInfo.admins.last_name | String | Account admin last name |
| KMSAT.AccountInfo.admins.email | String | Account admin email address |
| KMSAT.AccountInfo.subscription_email | String | Account subscription level |
| KMSAT.AccountInfo.subscription_end_date | Date | Account subscription end date |
| KMSAT.AccountInfo.number_of_seats | Number | Number of account seats |
| KMSAT.AccountInfo.current_risk_score | Number | Account Risk Score |
Command Example
#### Context Example
```json
{
"name": "KB4-Demo",
"type": "paid",
"domains": [
"kb4-demo.com"
],
"admins": [
{
"id": 974278,
"first_name": "Grace",
"last_name": "O'Malley",
"email": "example5@kb4-demo.com"
}
],
"subscription_level": "Diamond",
"subscription_end_date": "2021-03-06",
"number_of_seats": 25,
"current_risk_score": 45.742
}
kmsat-account-risk-score-history
| Argument Name | Description | Required |
|---|---|---|
| page | Page Number | No |
| per_page | Per Page Amount | No |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.AccountRiskScoreHistory.risk_score | String | Account Risk Score and associated date |
| KMSAT.AccountRiskScoreHistory.date | Date | Account Risk Score history date |
Command Example
!kmsat-account-risk-score-history-list page=1 per_page=25
Context Example
{
"risk_score": 37.3,
"date": "2021-02-07"
}
kmsat-groups-list
kmsat-account-risk-score-history
| Argument Name | Description | Requirement |
|---|---|---|
| page | Page Number | Optional |
| per_page | Per Page Amount | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.Groups.id | Number | Group ID |
| KMSAT.Groups.name | String | Group name |
| KMSAT.Groups.group_type | String | Group type |
| KMSAT.Groups.provisioning_guid | String | Group provisioning GUID |
| KMSAT.Groups.member_count | Number | Group member count |
| KMSAT.Groups.current_risk_score | Number | Group’s current Risk Score |
| KMSAT.Groups.status | String | Groups status |
Command Example
!kmsat-groups-list page=1 per_page=25
Context Example
{
"id": 3142,
"name": "Customer Service",
"group_type": "console_group",
"provisioning_guid": "abc12345-6789-abc-1234-456789abc123",
"member_count": 42,
"current_risk_score": 45.742,
"status": "active"
}
kmsat-groups-risk-score-history
| Argument Name | Description | Requirement |
|---|---|---|
| group_id | Group ID | Optional |
| page | Page number | Optional |
| per_page | Amount per page | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.GroupRiskScoreHistory.risk_score | String | Group Risk Score And associated date |
| KMSAT.GroupRiskHistory.date | Date | Group Risk Score history date |
Command Example
!kmsat-groups-risk-score-history-list page=1 per_page=25
Context Example
{
"risk_score": 37.3,
"date": "2021-02-07"
}
kmsat-groups-members
| Argument Name | Description | Requirement |
|---|---|---|
| group_id | Group ID | Required |
| page | Page Number | Optional |
| per_page | Per Page Amount | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.GroupsMembers.id | Number | User’s ID |
| KMSAT.GroupsMembers.employee_number | String | User’s employee number |
| KMSAT.GroupsMembers.first_name | String | User’s first name |
| KMSAT.GroupsMembers.last_name | String | User’s last name |
| KMSAT.GroupsMembers.job_title | String | User’s job title |
| KMSAT.GroupsMembers.email | String | User’s email address |
| KMSAT.GroupsMembers.phish_prone_percentage | Number | User’s Phish-prone Percentage |
| KMSAT.GroupsMembers.phone_number | String | User’s phone number |
| KMSAT.GroupsMembers.extension | String | User’s extension |
| KMSAT.GroupsMembers.mobile_phone_number | String | User’s phone number |
| KMSAT.GroupsMembers.location | String | User’s location |
| KMSAT.GroupsMembers.division | String | User’s division |
| KMSAT.GroupsMembers.manager_name | String | Name of user’s manager |
| KMSAT.GroupsMembers.provisioning_managed | Boolean | Email address of user’s manager |
| KMSAT.GroupsMembers.provisioning_guid | Unknown | User’s provisioning GUID |
| KMSAT.GroupsMembers.groups | Number | User’s groups |
| KMSAT.GroupsMembers.current_risk_score | Number | User’s current Risk Score |
| KMSAT.GroupsMembers.aliases | String | User’s aliases |
| KMSAT.GroupsMembers.joined_on | Date | User created at |
| KMSAT.GroupsMembers.last_sign_in | Date | User’s last login |
| KMSAT.GroupsMembers.status | String | User’s status |
| KMSAT.GroupsMembers.organization | String | User’s organization |
| KMSAT.GroupsMembers.department | String | User’s department |
| KMSAT.GroupsMembers.language | String | User’s language |
| KMSAT.GroupsMembers.comment | String | User comment |
| KMSAT.GroupsMembers.employee_start_date | Date | User’s employee start date |
| KMSAT.GroupsMembers.archived_at | Date | User archived at |
| KMSAT.GroupsMembers.custom_field_1 | String | User custom field 1 |
| KMSAT.GroupsMembers.custom_field_2 | String | User custom field 2 |
| KMSAT.GroupsMembers.custom_field_3 | String | User custom field 3 |
| KMSAT.GroupsMembers.custom_date_1 | Date | User custom date 1 |
| KMSAT.GroupsMembers.custom_date_2 | Date | User custom date 2 |
Command Example
!kmsat-groups-members-list group_id=1 page=1 per_page=25
Context Example
{
"id": 667542,
"employee_number": "19425",
"first_name": "William",
"last_name": "Marcoux",
"job_title": "VP of Sales",
"email": "example2@kb4-demo.com",
"phish_prone_percentage": 14.235,
"phone_number": "555-554-2222",
"extension": "42",
"mobile_phone_number": "555-553-4422",
"location": "Office A",
"division": "Sales",
"manager_name": "Michael Scott",
"manager_email": "example3@kb4-demo.com",
"provisioning_managed": false,
"provisioning_guid": null,
"groups": [
3264
],
"current_risk_score": 45.742,
"aliases": [
"alias_email@kb4-demo.com"
],
"joined_on": "2019-04-02T15:02:38.000Z",
"last_sign_in": "2019-04-02T15:02:38.000Z",
"status": "active",
"organization": "KB4-Demo",
"department": "Sales",
"language": "English - United States",
"comment": "Low PPP",
"employee_start_date": "2019-04-02T15:02:38.000Z",
"archived_at": null,
"custom_field_1": "Building C, 4th Floor",
"custom_field_2": null,
"custom_field_3": null,
"custom_field_4": null,
"custom_date_1": "1986-11-26",
"custom_date_2": null
}
kmsat-users-risk-score-history
| Argument Name | Description | Requirement |
|---|---|---|
| user_id | User ID | Required |
| page | Page number | Optional |
| per_page | Amount per page | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UsersRiskHistory.risk_score | Number | User’s Risk Score and associated date |
| KMSAT.UsersRiskHistory.date | Date | User’s Risk Score history date |
Command Example
!kmsat-users-risk-score-history-list user_id=1 page=1 per_page=25
Context Example
{
"risk_score": 37.3,
"date": "2021-02-07"
}
kmsat-phishing-security-tests
| Argument Name | Description | Requirement |
|---|---|---|
| page | Page number | Optional |
| per_page | Amount per page | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.PhishingSecurity.campaign_id | Number | Phishing campaign ID |
| KMSAT.PhishingSecurity.pst_id | Number | PST ID |
| KMSAT.PhishingSecurity.status | String | PST status |
| KMSAT.PhishingSecurity.name | String | PST name |
| KMSAT.PhishingSecurity.groups.group_id | Number | PST group ID |
| KMSAT.PhishingSecurity.groups.name | String | PST group name |
| KMSAT.PhishingSecurity.phish_prone_percentage | Number | PST Phish-prone Percentage |
| KMSAT.PhishingSecurity.started_at | Date | PST started date |
| KMSAT.PhishingSecurity.duration | Number | PST duration |
| KMSAT.PhishingSecurity.categories.category_id | Number | PST category ID |
| KMSAT.PhishingSecurity.categories.name | String | PST category name |
| KMSAT.PhishingSecurity.template.id | Number | PST template ID |
| KMSAT.PhishingSecurity.template.name | String | PST template Name |
| KMSAT.PhishingSecurity.lading_page.id | Number | PST landing page ID |
| KMSAT.PhishingSecurity.landing_page.name | String | PST landing page name |
| KMSAT.PhishingSecurity.scheduled_count | Number | PST scheduled count |
| KMSAT.PhishingSecurity.delivered_count | Number | PST delivered count |
| KMSAT.PhishingSecurity.opened_count | Number | PST opened count |
| KMSAT.PhishingSecurity.clicked_count | Number | PST clicked count |
| KMSAT.PhishingSecurity.replied_count | Number | PST replied count |
| KMSAT.PhishingSecurity.attachment_open_count | Number | PST attachment opened count |
| KMSAT.PhishingSecurity.macro_enabled_count | Number | PST macro enabled count |
| KMSAT.PhishingSecurity.data_entered_count | Number | PST data entered count |
| KMSAT.PhishingSecurity.qr_code_scanned_count | Number | PST QR Code scanned count |
| KMSAT.PhishingSecurity.reported_count | Number | PST reported count |
| KMSAT.PhishingSecurity.bounced_count | Number | PST bounced count |
Command Example
!kmsat-phishing-security-tests-list page=1 per_page=25
Context Example
[
{
"campaign_id": 3423,
"pst_id": 16142,
"status": "Closed",
"name": "Corporate Test",
"groups": [
{
"group_id": 16342,
"name": "Corporate Employees"
}
],
"phish_prone_percentage": 0.5,
"started_at": "2019-04-02T15:02:38.000Z",
"duration": 1,
"categories": [
{
"category_id": 4237,
"name": "Current Events"
}
],
"template": {
"id": 11428,
"name": "CNN Breaking News"
},
"landing_page": {
"id": 1842,
"name": "SEI Landing Page"
},
"scheduled_count": 42,
"delivered_count": 4,
"opened_count": 24,
"clicked_count": 20,
"replied_count": 0,
"attachment_open_count": 3,
"macro_enabled_count": 0,
"data_entered_count": 0,
"qr_code_scanned_count": 0,
"reported_count": 0,
"bounced_count": 0
}
]
kmsat-phishing-security-tests-recipients
| Argument Name | Description | Requirement |
|---|---|---|
| pst_id | PST ID | Required |
| page | Page number | Optional |
| per_page | Amount per page | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.PhishingSecurityPST.recipient_id | Number | PST recipient ID |
| KMSAT.PhishingSecurityPST.pst_id | Number | PST ID |
| KMSAT.PhishingSecurityPST.user | String | PST user |
| KMSAT.PhishingSecurityPST.template | String | PST template |
| KMSAT.PhishingSecurityPST.scheduled_at | Date | PST scheduled at |
| KMSAT.PhishingSecurityPST.delivered_at | Date | PST delivered at |
| KMSAT.PhishingSecurityPST.opened_at | Date | PST opened at |
| KMSAT.PhishingSecurityPST.clicked_at | Date | PST clicked at |
| KMSAT.PhishingSecurityPST.replied_at | Date | PST replied at |
| KMSAT.PhishingSecurityPST.attachment_opened_at | Date | PST attachment opened at |
| KMSAT.PhishingSecurityPST.macro_enabled_at | Date | PST macro enabled at |
| KMSAT.PhishingSecurityPST.data_entered_at | Date | PST data entered at |
| KMSAT.PhishingSecurityPST.qr_code_scanned | Date | PST QR code scanned at |
| KMSAT.PhishingSecurityPST.reported_at | Date | PST reported at |
| KMSAT.PhishingSecurityPST.bounced_at | Date | PST bounced at |
| KMSAT.PhishingSecurityPST.ip | String | PST IP address |
| KMSAT.PhishingSecurityPST.up_location | String | PST IP address location |
| KMSAT.PhishingSecurityPST.browser | String | PST browser |
| KMSAT.PhishingSecurityPST.browser_version | String | PST browser version |
| KMSAT.PhishingSecurityPST.os | String | PST operating system |
Command Example
!kmsat-phishing-security-tests-recipients-list pst_id=1 page=1 per_page=25
Context Example
[
{
"recipient_id": 3077742,
"pst_id": 14240,
"user": {
"id": 264215,
"provisioning_guid": null,
"first_name": "Bob",
"last_name": "Ross",
"email": "example4@kb4-demo.com"
},
"template": {
"id": 2,
"name": "Your Amazon Order"
},
"scheduled_at": "2019-04-02T15:02:38.000Z",
"delivered_at": "2019-04-02T15:02:38.000Z",
"opened_at": "2019-04-02T15:02:38.000Z",
"clicked_at": "2019-04-02T15:02:38.000Z",
"replied_at": null,
"attachment_opened_at": null,
"macro_enabled_at": null,
"data_entered_at": "2019-04-02T15:02:38.000Z",
"qr_code_scanned": "2022-05-12T15:29:54.000Z",
"reported_at": null,
"bounced_at": null,
"ip": "XX.XX.XXX.XXX",
"ip_location": "St.Petersburg, FL",
"browser": "Chrome",
"browser_version": "48.0",
"os": "MacOSX"
}
]
kmsat-phishing-security-tests-failed-recipients
| Argument Name | Description | Requirement |
|---|---|---|
| pst_id | PST ID | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.PhishingSecurityPST.recipient_id | Number | PST recipient ID |
| KMSAT.PhishingSecurityPST.pst_id | Number | PST ID |
| KMSAT.PhishingSecurityPST.user | String | PST user |
| KMSAT.PhishingSecurityPST.template | String | PST template |
| KMSAT.PhishingSecurityPST.scheduled_at | Date | PST scheduled at |
| KMSAT.PhishingSecurityPST.delivered_at | Date | PST delivered at |
| KMSAT.PhishingSecurityPST.opened_at | Date | PST opened at |
| KMSAT.PhishingSecurityPST.clicked_at | Date | PST clicked at |
| KMSAT.PhishingSecurityPST.replied_at | Date | PST replied at |
| KMSAT.PhishingSecurityPST.attachment_opened_at | Date | PST attachment opened at |
| KMSAT.PhishingSecurityPST.macro_enabled_at | Date | PST macro enabled at |
| KMSAT.PhishingSecurityPST.data_entered_at | Date | PST data entered at |
| KMSAT.PhishingSecurityPST.qr_code_scanned | Date | PST QR code scanned at |
| KMSAT.PhishingSecurityPST.reported_at | Date | PST reported at |
| KMSAT.PhishingSecurityPST.bounced_at | Date | PST bounced at |
| KMSAT.PhishingSecurityPST.ip | String | PST IP address |
| KMSAT.PhishingSecurityPST.up_location | String | PST IP address location |
| KMSAT.PhishingSecurityPST.browser | String | PST browser |
| KMSAT.PhishingSecurityPST.browser_version | String | PST browser version |
| KMSAT.PhishingSecurityPST.os | String | PST operating system |
Command Example
!kmsat-phishing-security-tests-failed-recipients-list pst_id=1
Context Example
[
{
"recipient_id": 3077742,
"pst_id": 14240,
"user": {
"id": 264215,
"provisioning_guid": null,
"first_name": "Bob",
"last_name": "Ross",
"email": "example4@kb4-demo.com"
},
"template": {
"id": 2,
"name": "Your Amazon Order"
},
"scheduled_at": "2019-04-02T15:02:38.000Z",
"delivered_at": "2019-04-02T15:02:38.000Z",
"opened_at": "2019-04-02T15:02:38.000Z",
"clicked_at": "2019-04-02T15:02:38.000Z",
"replied_at": null,
"attachment_opened_at": null,
"macro_enabled_at": null,
"data_entered_at": "2019-04-02T15:02:38.000Z",
"qr_code_scanned": "2022-05-12T15:29:54.000Z",
"reported_at": null,
"bounced_at": null,
"ip": "XX.XX.XXX.XXX",
"ip_location": "St.Petersburg, FL",
"browser": "Chrome",
"browser_version": "48.0",
"os": "MacOSX"
}
]
kmsat-phishing-campaign-security-tests
| Argument Name | Description | Requirement |
|---|---|---|
| campaign_id | Campaign ID | Required |
| page | Page number | Optional |
| per_page | Amount per page | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.CampaignPST.campaign_id | Number | Phishing campaign ID |
| KMSAT.CampaignPST.pst_id | Number | PST ID |
| KMSAT.CampaignPST.status | String | PST status |
| KMSAT.CampaignPST.name | String | PST name |
| KMSAT.CampaignPST.groups.group_id | Number | PST group ID |
| KMSAT.CampaignPST.groups.name | String | PST group name |
| KMSAT.CampaignPST.phish_prone_percentage | Number | PST Phish-prone Percentage |
| KMSAT.CampaignPST.started_at | Date | PST started at |
| KMSAT.CampaignPST.duration | Number | PST duration |
| KMSAT.CampaignPST.categories.category_id | Number | PST category ID |
| KMSAT.CampaignPST.categories.name | String | PST category name |
| KMSAT.CampaignPST.template.id | Number | PST template ID |
| KMSAT.CampaignPST.template.name | String | PST template name |
| KMSAT.CampaignPST.landing_page.id | Number | PST landing page ID |
| KMSAT.CampaignPST.landing_page.name | String | PST landing page name |
| KMSAT.CampaignPST.scheduled_count | Number | PST scheduled count |
| KMSAT.CampaignPST.delivered_count | Number | PST delivered count |
| KMSAT.CampaignPST.opened_count | Number | PST opened count |
| KMSAT.CampaignPST.clicked_count | Number | PST clicked count |
| KMSAT.CampaignPST.replied_count | Number | PST replied count |
| KMSAT.CampaignPST.attachment_open_count | Number | PST attachment opened count |
| KMSAT.CampaignPST.macro_enabled_count | Number | PST macro enabled count |
| KMSAT.CampaignPST.data_entered_count | Number | PST data entered count |
| KMSAT.CampaignPST.qr_code_scanned_count | Number | PST QR code scanned count |
| KMSAT.CampaignPST.reported_count | Number | PST reported count |
| KMSAT.CampaignPST.bounced_count | Number | PST bounced count |
Command Example
!kmsat-phishing-campaign-security-tests-list campaign_id=1 page=1 per_page=25
Context Example
[
{
"campaign_id": 3423,
"pst_id": 16142,
"status": "Closed",
"name": "Corporate Test",
"groups": [
{
"group_id": 16342,
"name": "Corporate Employees"
}
],
"phish_prone_percentage": 0.5,
"started_at": "2019-04-02T15:02:38.000Z",
"duration": 1,
"categories": [
{
"category_id": 4237,
"name": "Current Events"
}
],
"template": {
"id": 11428,
"name": "CNN Breaking News"
},
"landing_page": {
"id": 1842,
"name": "SEI Landing Page"
},
"scheduled_count": 42,
"delivered_count": 4,
"opened_count": 24,
"clicked_count": 20,
"replied_count": 0,
"attachment_open_count": 3,
"macro_enabled_count": 0,
"data_entered_count": 0,
"qr_code_scanned_count": 0,
"reported_count": 0,
"bounced_count": 0
}
]
kmsat-training-campaigns
| Argument Name | Description | Requireent |
|---|---|---|
| page | Page Number | Optional |
| per_page | Per Page Amount | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.TrainingCampaigns.campaign_id | Number | Training campaign ID |
| KMSAT.TrainingCampaigns.name | String | Training campaign name |
| KMSAT.TrainingCampaigns.groups.group_id | Number | Training campaign group ID |
| KMSAT.TrainingCampaigns.groups.name | String | Training campaign group name |
| KMSAT.TrainingCampaigns.status | String | Training campaign Status |
| KMSAT.TrainingCampaigns.content.store_purchase_id | Number | Training campaign content store purchase ID |
| KMSAT.TrainingCampaigns.content.content_type | String | Training campaign content type |
| KMSAT.TrainingCampaigns.content.name | String | Training campaign content name |
| KMSAT.TrainingCampaigns.content.description | String | Training campaign content description |
| KMSAT.TrainingCampaigns.content.type | String | Training campaign content type |
| KMSAT.TrainingCampaigns.content.duration | Number | Training campaign content duration |
| KMSAT.TrainingCampaigns.content.retired | Boolean | Training campaign content retired |
| KMSAT.TrainingCampaigns.content.retirement_date | Date | Training campaign content retirement date |
| KMSAT.TrainingCampaigns.content.publish_date | Date | Training campaign content publish date |
| KMSAT.TrainingCampaigns.content.publisher | String | Training campaign content publisher |
| KMSAT.TrainingCampaigns.content.purchase_date | Date | Training campaign content purchase date |
| KMSAT.TrainingCampaigns.content.policy_url | String | Training campaign content policy URL |
| KMSAT.TrainingCampaigns.content.policy_id | Number | Training campaign content policy ID |
| KMSAT.TrainingCampaigns.content.minimum_time | Number | Training campaign content minimum time |
| KMSAT.TrainingCampaigns.content.default_language | String | Training campaign content default language |
| KMSAT.TrainingCampaigns.content.published | Boolean | Training campaign content published |
| KMSAT.TrainingCampaigns.duration_type | String | Training campaign duration type |
| KMSAT.TrainingCampaigns.start_date | Date | Training campaign start date |
| KMSAT.TrainingCampaigns.end_date | Date | Training campaign end date |
| KMSAT.TrainingCampaigns.relative_duration | String | Training campaign relative duration |
| KMSAT.TrainingCampaigns.auto_enroll | Boolean | Training campaign auto enrolls |
| KMSAT.TrainingCampaigns.allow_multiple_enrollments | Boolean | Training campaign allows multiple enrollments |
| KMSAT.TrainingCampaigns.completion_percentage | Number | Training campaign completion percentage |
Command Example
!kmsat-training-campaigns-list campaign_id=1 page=1 per_page=25
Context Example
{
"campaign_id": 4261,
"name": "Annual Training",
"groups": [
{
"group_id": 0,
"name": "All Users"
}
],
"status": "Completed",
"content": [
[
{
"store_purchase_id": 7,
"content_type": "Store Purchase",
"name": "2019 Security Awareness Training",
"description": "A comprehensive overview of best practices...",
"type": "Training Module",
"duration": 42,
"retired": false,
"retirement_date": null,
"publish_date": "2019-04-02T15:02:38.000Z",
"publisher": "KnowBe4",
"purchase_date": "2019-04-02T15:02:38.000Z",
"policy_url": "https://www.yourcompany.com/employees/acceptableusepolicy.html"
},
{
"policy_id": 142,
"content_type": "Uploaded Policy",
"name": "Security Awareness Policy",
"minimum_time": 3,
"default_language": "en-us",
"published": true
}
]
],
"duration_type": "Specific End Date",
"start_date": "2019-04-02T15:02:38.000Z",
"end_date": "2019-04-02T15:02:38.000Z",
"relative_duration": "string",
"auto_enroll": true,
"allow_multiple_enrollments": false,
"completion_percentage": 0
}
kmsat-training-enrollments
| Argument Name | Description | Requirement |
|---|---|---|
| status | Status | Optional |
| page | Page number | Optional |
| per_page | Amount per page | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.TrainingEnrollments.enrollment_id | Number | Training enrollment ID |
| KMSAT.TrainingEnrollments.content_type | String | Training enrollment content type |
| KMSAT.TrainingEnrollments.module_name | String | Training enrollment module name |
| KMSAT.TrainingEnrollments.user.id | Number | Training enrollment user ID |
| KMSAT.TrainingEnrollments.user.first_name | String | Training enrollment user’s first name |
| KMSAT.TrainingEnrollments.user.last_name | String | Training enrollment user’s last name |
| KMSAT.TrainingEnrollments.user.email | String | Training enrollment user’s email address |
| KMSAT.TrainingEnrollments.campaign_name | String | Training enrollment campaign name |
| KMSAT.TrainingEnrollments.enrollment_date | Date | Training enrollment date |
| KMSAT.TrainingEnrollments.start_date | Date | Training enrollment start date |
| KMSAT.TrainingEnrollments.completion_date | Date | Training enrollment completion date |
| KMSAT.TrainingEnrollments.status | String | Training enrollment status |
| KMSAT.TrainingEnrollments.time_spent | Number | Training enrollment time spent |
| KMSAT.TrainingEnrollments.policy_acknowledged | Boolean | Training enrollment policy acknowledged |
Command Example
!kmsat-training-enrollments-list status="Completed" page=1 per_page=25
Context Example
{
"enrollment_id": 1425526,
"content_type": "Uploaded Policy",
"module_name": "Acceptable Use Policy",
"user": {
"id": 796742,
"first_name": "Sarah",
"last_name": "Thomas",
"email": "example1@kb4-demo.com"
},
"campaign_name": "New Employee Policies",
"enrollment_date": "2019-04-02T15:02:38.000Z",
"start_date": "2019-04-02T15:02:38.000Z",
"completion_date": "2019-04-02T15:02:38.000Z",
"status": "Passed",
"time_spent": 2340,
"policy_acknowledged": false
}
kmsat-user-event-list
| Argument Name | Type | Requirement |
|---|---|---|
| event_type | String | Optional |
| target_user | String | Optional |
| external_id | String | Optional |
| source | string | Optional |
| occurred_date | String | Optional |
| risk_level | Number | Optional |
| risk_decay_mode | Number | Optional |
| risk_expired_date | String | Optional |
| page | Number | Optional |
| per_page | Number | Optional |
| order_by | String | Optional |
| order_direction | String | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UserEvents.id | Number | Event ID |
| KMSAT.UserEvents.user.email | String | User email address |
| KMSAT.UserEvents.user.id | Number | User ID |
| KMSAT.UserEvents.user.archived | Boolean | User archived |
| KMSAT.UserEvents.external_id | String | External ID of the event |
| KMSAT.UserEvents.source | String | Source of the event |
| KMSAT.UserEvents.description | String | Description of the event |
| KMSAT.UserEvents.occurred_date | Date | Date the event occurred |
| KMSAT.UserEvents.risk.level | Number | Risk level of the event |
| KMSAT.UserEvents.risk.factor | Number | Risk factor of the event |
| KMSAT.UserEvents.risk.decay_mode | String | Decay Mode of the risk level |
| KMSAT.UserEvents.risk.expire_date | String | Risk expiration date |
| KMSAT.UserEvents.event_type.id | Number | ID of event type |
| KMSAT.UserEvents.event_type.name | String | Name of event type |
Command Example
!kmsat-user-event-list id=xyz
kmsat-user-events-list
| Argument Name | Type | Requirement |
|---|---|---|
| event_type | String | Optional |
| target_user | String | Optional |
| external_id | String | Optional |
| source | string | Optional |
| occurred_date | String | Optional |
| risk_level | Number | Optional |
| risk_decay_mode | Number | Optional |
| risk_expired_date | String | Optional |
| page | Number | Optional |
| per_page | Number | Optional |
| order_by | String | Optional |
| order_direction | String | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UserEvents.id | Number | Event ID |
| KMSAT.UserEvents.user.email | String | User email address |
| KMSAT.UserEvents.user.id | Number | User ID |
| KMSAT.UserEvents.user.archived | Boolean | User archived |
| KMSAT.UserEvents.external_id | String | External ID of the event |
| KMSAT.UserEvents.source | String | Source of the event |
| KMSAT.UserEvents.description | String | Description of the event |
| KMSAT.UserEvents.occurred_date | Date | Date the event occurred |
| KMSAT.UserEvents.risk.level | Number | Risk level of the event |
| KMSAT.UserEvents.risk.factor | Number | Risk factor of the event |
| KMSAT.UserEvents.risk.decay_mode | String | Decay Mode of the risk level |
| KMSAT.UserEvents.risk.expire_date | String | Risk expiration date |
| KMSAT.UserEvents.event_type.id | Number | ID of event type |
| KMSAT.UserEvents.event_type.name | String | Name of event type |
Command Example
!kmsat-user-events-list target_user=1 risk_level=1 page=1 per_page=25
Context Example
{
"data": [
{
"id": 0,
"user": {
"email": "string",
"id": 0,
"archived": true
},
"external_id": "string",
"source": "string",
"description": "string",
"occurred_date": "2019-08-24",
"risk": {
"level": 0,
"factor": 0,
"decay_mode": "string",
"expire_date": "string"
},
"event_type": {
"id": 0,
"name": "string"
}
}
]
}
kmsat-user-event-types-list
| Argument Name | Description | Requirement |
|---|---|---|
| name | Filter by name of the event type | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UserEventTypes.id | Number | ID of the event type |
| KMSAT.UserEventTypes.account_id | Number | Account ID |
| KMSAT.UserEventTypes.name | String | Name of the event type |
| KMSAT.UserEventTypes.description | String | Description of event type |
Command Example
!kmsat-user-event-types-list name="John"
Context Example
{
"data": [
{
"id": 0,
"name": "string",
"description": "string"
}
]
}
kmsat-user-event-create
| Argument Name | Description | Requirement |
|---|---|---|
| target_user | String | Required |
| event_type | String | Required |
| external_id | String | Optional |
| source | string | Optional |
| description | String | Optional |
| occurred_date | String | Optional |
| risk_level | Number | Optional |
| risk_decay_mode | Number | Optional |
| risk_expired_date | String | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UserEventCreate.id | Number | Unique ID of the event |
Command Example
!kmsat-user-event-create target_user="John" event_type="New Event"
Context Example
{
"data": {
"id": "string"
}
}
kmsat-user-event-delete
| Argument Name | Description | Requirement |
|---|---|---|
| id | Event ID | Required |
Command Example
!kmsat-user-event-delete id=1
kmsat-user-event-status-list
| Argument Name | Description | Requirement |
|---|---|---|
| id | request id from kmsat- | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UserEventStatus.id | Number | ID of the Event Type |
| KMSAT.UserEventTypes.details | Object | Details of event request including event id and any failures |
| KMSAT.UserEventTypes.details.events | Array | list of event ids |
| KMSAT.UserEventTypes.details.failures | Array | reasons for failure |
| KMSAT.UserEventTypes.processed | Date | Date and time event was processed |
| KMSAT.UserEventTypes.api_key | String | Name of api key used |
Command Example
!kmsat-user-event-status-list id=xyz
Context Example
{
"data": {
"id": "abcdefgh-843c-4fc8-bb2f-decf89876f7b",
"details": {
"events": [
"123456-a083-42b9-b50a-fb69b8e2b185"
],
"failures": []
},
"processed": "2023-04-1T14:39:40.132Z",
"api_key": "Test integration"
}
}
kmsat-user-event-statuses-list
| Argument Name | Description | Requirement |
|---|---|---|
| processed | date item was processed | No |
| page | Page Number | No |
| per_page | Per Page Amount | No |
Context Output
| Path | Type | Description |
|---|---|---|
| KMSAT.UserEventStatus.id | Number | ID of the Event Type |
| KMSAT.UserEventTypes.details | Object | Details of event request including event id and any failures |
| KMSAT.UserEventTypes.details.events | Array | list of event ids |
| KMSAT.UserEventTypes.details.failures | Array | reasons for failure |
| KMSAT.UserEventTypes.processed | Date | Date and time event was processed |
| KMSAT.UserEventTypes.api_key | String | Name of api key used |
Command Example
!kmsat-user-event-status-list id=xyz
Context Example
{
"data": [
{
"id": "abcdefgh-843c-4fc8-bb2f-decf89876f7b",
"details": {
"events": [
"123456-a083-42b9-b50a-fb69b8e2b185"
],
"failures": []
},
"processed": "2023-04-1T14:39:40.132Z",
"api_key": "Test integration"
},
{
"id": "qrstevei-843c-4fc8-bb2f-decf89876f7b",
"details": {
"events": [
"9876543-a083-42b9-b50a-fb69b8e2b185"
],
"failures": []
},
"processed": "2023-04-1T00:39:40.132Z",
"api_key": "Test integration"
}
]
}
Configuration parameters
url— Your Reporting Server URL (required)apikey— (required)userEventsUrl— Your User Events Server URL (required)userEventsApiKey— (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (19)
-
kmsat-account-info-listReturns KMSAT account information
-
kmsat-account-risk-score-history-listReturns KMSAT Account Risk Score History.
-
kmsat-groups-listReturns KMSAT Group Specific Risk Score History.
-
kmsat-groups-members-listReturns KMSAT Groups Members.
-
kmsat-groups-risk-score-history-listReturns KMSAT Group Specific Risk Score History.
-
kmsat-phishing-campaigns-security-tests-listReturns All Campaign Phishing Security Tests (PSTs).
-
kmsat-phishing-security-tests-failed-recipients-listReturns a Specific Failed Recipient's Results.
-
kmsat-phishing-security-tests-listReturns All Phishing Security Tests (PSTs)
-
kmsat-phishing-security-tests-recipients-listReturns a Specific Recipient's Results.
-
kmsat-training-campaigns-listReturns All Training Campaigns.
-
kmsat-training-enrollments-listReturns all Training Enrollments
-
kmsat-user-event-createAdds a User Event
-
kmsat-user-event-deleteDeletes User Event by Event ID
-
kmsat-user-event-listReturns a KMSAT User Event.
-
kmsat-user-event-status-listreturns the status of the User Event request
-
kmsat-user-event-statuses-listreturns the status of the User Event request
-
kmsat-user-event-types-listReturns all KMSAT User Event Types
-
kmsat-user-events-listReturns all KMSAT User Events.
-
kmsat-users-risk-score-history-listReturns KMSAT User Specific Risk Score History
"""Base Integration for Cortex XSOAR - Unit Tests file Pytest Unit Tests: all funcion names must start with "test_" More details: https://xsoar.pan.dev/docs/integrations/unit-testing MAKE SURE YOU REVIEW/REPLACE ALL THE COMMENTS MARKED AS "TODO" You must add at least a Unit Test function for every XSOAR command you are implementing with your integration """ import json import io from typing import Dict from KnowBe4KMSAT import Client, UserEventClient KMSAT_BASE_URL = "https://us.api.knowbe4.com" USER_EVENT_BASE_URL = "https://api.events.knowbe4.com" REPORTING_BASE_URL = "https://us.api.knowbe4.com/v1" def util_load_json(path): with io.open(path, mode="r", encoding="utf-8") as f: return json.loads(f.read()) def test_account_info(requests_mock): """ Given no params When Calling https://us.api.knowbe4.com/v1/account Then Make sure the data contains account information """ mock_response_data = util_load_json("test_data/account_response.json") from KnowBe4KMSAT import kmsat_account_info_list_command requests_mock.get( f"{REPORTING_BASE_URL}/account", json=mock_response_data, status_code=200 ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_account_info_list_command(client, args) assert requests_mock.last_request.headers['X-KB4-Integration'] == "Cortex XSOAR KMSAT" assert result.outputs_prefix == "KMSAT.AccountInfo" assert result.outputs_key_field == "name" assert result.outputs == mock_response_data def test_account_risk_score_history(requests_mock): """ Given no params When Calling https://us.api.knowbe4.com/v1/account/risk_score_history Then Make sure the data contains account risk history information """ mock_response_data = util_load_json( "test_data/account_risk_score_history_response.json" ) from KnowBe4KMSAT import kmsat_account_risk_score_history_list_command requests_mock.get( f"{REPORTING_BASE_URL}/account/risk_score_history", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_account_risk_score_history_list_command(client, args) assert result.outputs_prefix == "KMSAT.AccountRiskScoreHistory" assert result.outputs_key_field == "" assert result.outputs == mock_response_data def test_account_groups_risk_score_history(requests_mock): """ Given A group ID argument When Calling https://us.api.knowbe4.com/v1/groups/1/risk_score_history Then Make sure the data contains id with expected values """ mock_response_data = util_load_json( "test_data/groups_risk_score_history_response.json" ) from KnowBe4KMSAT import kmsat_groups_risk_score_history_list_command requests_mock.get( f"{REPORTING_BASE_URL}/groups/1/risk_score_history", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"group_id": 1} result = kmsat_groups_risk_score_history_list_command(client, args) assert result.outputs_prefix == "KMSAT.GroupsRiskScoreHistory" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data def test_groups_members_list(requests_mock): """ Given A group ID argument When Calling https://us.api.knowbe4.com/v1/groups/1/members Then Make sure the data contains id with expected values """ mock_response_data = util_load_json( "test_data/groups_risk_score_history_response.json" ) from KnowBe4KMSAT import kmsat_groups_members_list_command requests_mock.get( f"{REPORTING_BASE_URL}/groups/1/members", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"group_id": 1} result = kmsat_groups_members_list_command(client, args) assert result.outputs_prefix == "KMSAT.GroupsMembers" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data def test_users_risk_score_history_list(requests_mock): """ Given A user ID When Calling https://us.api.knowbe4.com/v1/users/1/risk_score_history Then Make sure the data returned for user """ mock_response_data = util_load_json( "test_data/user_risk_score_history_response.json" ) from KnowBe4KMSAT import kmsat_users_risk_score_history_list_command requests_mock.get( f"{REPORTING_BASE_URL}/users/1/risk_score_history", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"user_id": 1} result = kmsat_users_risk_score_history_list_command(client, args) assert result.outputs_prefix == "KMSAT.UsersRiskScoreHistory" assert result.outputs_key_field == "" assert result.outputs == mock_response_data def test_phishing_security_tests_list(requests_mock): """ Given no params When Calling https://us.api.knowbe4.com/v1/phishing/security_tests Then Make sure the data contains campaign_id with expected values """ mock_response_data = util_load_json( "test_data/groups_risk_score_history_response.json" ) from KnowBe4KMSAT import kmsat_phishing_security_tests_list_command requests_mock.get( f"{REPORTING_BASE_URL}/phishing/security_tests", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: Dict = {} result = kmsat_phishing_security_tests_list_command(client, args) assert result.outputs_prefix == "KMSAT.PhishingSecurity" assert result.outputs_key_field == "campaign_id" assert result.outputs == mock_response_data def test_phishing_security_tests_recipients_list(requests_mock): """ Given A phishing security test ID When Calling https://us.api.knowbe4.com/v1/phishing/security_tests/1/recipients Then Make sure the data contains recipient_id with expected values """ mock_response_data = util_load_json( "test_data/phishing_security_tests_recipients_response.json" ) from KnowBe4KMSAT import kmsat_phishing_security_tests_recipients_list_command requests_mock.get( f"{REPORTING_BASE_URL}/phishing/security_tests/1/recipients", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"pst_id": 1} result = kmsat_phishing_security_tests_recipients_list_command(client, args) assert result.outputs_prefix == "KMSAT.PhishingSecurityPST" assert result.outputs_key_field == "recipient_id" assert result.outputs == mock_response_data def test_phishing_security_tests_failed_recipients_list(requests_mock): """ Given A phishing security test ID When Calling https://us.api.knowbe4.com/v1/phishing/campaigns/1/security_tests Then Make sure the data contains recipient_id with expected values """ mock_response_data = util_load_json( "test_data/phishing_security_tests_failed_recipients_response.json" ) from KnowBe4KMSAT import kmsat_phishing_security_tests_failed_recipients_list_command requests_mock.get( f"{REPORTING_BASE_URL}/phishing/security_tests/1/recipients", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"pst_id": 1} result = kmsat_phishing_security_tests_failed_recipients_list_command(client, args) valid_response = { "data": mock_response_data, "meta": { "filtered_items_in_page": 1, "items_total": 1, "paging_end": True } } assert result.outputs_prefix == "KMSAT.PhishingSecurityPST" assert result.outputs_key_field == "recipient_id" assert result.outputs == valid_response def test_phishing_campaigns_security_tests_list(requests_mock): """ Given A campaign ID When Calling https://us.api.knowbe4.com/v1/phishing/campaigns/1/security_tests Then Make sure the data is returned for the campaign """ mock_response_data = util_load_json( "test_data/phishing_security_tests_failed_recipients_response.json" ) from KnowBe4KMSAT import kmsat_phishing_campaign_security_tests_list_command requests_mock.get( f"{REPORTING_BASE_URL}/phishing/campaigns/1/security_tests", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"campaign_id": 1} result = kmsat_phishing_campaign_security_tests_list_command(client, args) assert result.outputs_prefix == "KMSAT.CampaignPST" assert result.outputs_key_field == "" assert result.outputs == mock_response_data def test_training_campaigns_list(requests_mock): """ Given no params When Calling https://us.api.knowbe4.com/v1/training/campaigns Then Make sure the data contains campaign_id with expected values """ mock_response_data = util_load_json( "test_data/training_campaigns_response.json" ) from KnowBe4KMSAT import kmsat_training_campaigns_list_command requests_mock.get( f"{REPORTING_BASE_URL}/training/campaigns", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_training_campaigns_list_command(client, args) assert result.outputs_prefix == "KMSAT.TrainingCampaigns" assert result.outputs_key_field == "campaign_id" assert result.outputs == mock_response_data def test_training_enrollments_list(requests_mock): """ Given no params When Calling https://us.api.knowbe4.com/v1/training/enrollments Then Make sure the data contains enrollment_id with expected values """ mock_response_data = util_load_json( "test_data/training_enrollments_response.json" ) from KnowBe4KMSAT import kmsat_training_enrollments_list_command requests_mock.get( f"{REPORTING_BASE_URL}/training/enrollments", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_training_enrollments_list_command(client, args) valid_response = { "data": mock_response_data, "meta": { "filtered_items_in_page": 0, "items_total": 4, "paging_end": True } } assert result.outputs_prefix == "KMSAT.TrainingEnrollments" assert result.outputs_key_field == "enrollment_id" assert result.outputs == valid_response def test_status_training_enrollments_list(requests_mock): """ Given A status Calling https://us.api.knowbe4.com/v1/training/enrollments Then Make sure the data contains enrollment_id with expected values """ mock_response_data = util_load_json( "test_data/training_enrollments_response.json" ) from KnowBe4KMSAT import kmsat_training_enrollments_list_command requests_mock.get( f"{REPORTING_BASE_URL}/training/enrollments", json=mock_response_data, status_code=200, ) client = Client( REPORTING_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) expectedStatus: str = "Passed" args: dict = {"status": expectedStatus} result = kmsat_training_enrollments_list_command(client, args) assert result.outputs_prefix == "KMSAT.TrainingEnrollments" assert result.outputs_key_field == "enrollment_id" assert len(result.outputs["data"]) == 2 assert len(mock_response_data) > 2 for enrollment in result.outputs["data"]: assert enrollment["status"] == expectedStatus responseMeta = result.outputs["meta"] assert responseMeta["filtered_items_in_page"] == 2 assert responseMeta["items_total"] == len(mock_response_data) assert responseMeta["paging_end"] def test_get_user_event_types(requests_mock): """ Given no params When Calling https://api.events.knowbe4.com/event_types Then Make sure the data array contains event_types with expected values """ mock_response_data = util_load_json("test_data/user_event_types_response.json") from KnowBe4KMSAT import kmsat_user_event_types_list_command requests_mock.get( f"{USER_EVENT_BASE_URL}/event_types", json=mock_response_data, status_code=200 ) userEventClient = UserEventClient( USER_EVENT_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_user_event_types_list_command(userEventClient, args) assert result.outputs_prefix == "KMSAT.UserEventTypes" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data["data"] def test_get_user_events(requests_mock): """ Given no params When Calling https://api.events.knowbe4.com/events Then Make sure the data array contains user events """ mock_response_data = util_load_json("test_data/user_events_response.json") from KnowBe4KMSAT import kmsat_user_events_list_command requests_mock.get( f"{USER_EVENT_BASE_URL}/events", json=mock_response_data, status_code=200 ) userEventClient = UserEventClient( USER_EVENT_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_user_events_list_command(userEventClient, args) assert requests_mock.last_request.headers['X-KB4-Integration'] == "Cortex XSOAR KMSAT" assert result.outputs_prefix == "KMSAT.UserEvents" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data["data"] def test_get_user_event(requests_mock): """ Given an event ID When Calling https://api.events.knowbe4.com/events/{id} Then Make sure the data contains the user event """ eventId: str = "513f46ac-c3d7-4682-ad0d-0c149c0728a2" mock_response_data = util_load_json("test_data/user_event_response.json") from KnowBe4KMSAT import kmsat_user_event_list_command requests_mock.get( f"{USER_EVENT_BASE_URL}/events/{eventId}", json=mock_response_data, status_code=200 ) userEventClient = UserEventClient( USER_EVENT_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"id": eventId} result = kmsat_user_event_list_command(userEventClient, args) assert requests_mock.last_request.headers['X-KB4-Integration'] == "Cortex XSOAR KMSAT" assert result.outputs_prefix == "KMSAT.UserEvent" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data["data"] def test_delete_user_event(requests_mock): """ Given an Event ID When Calling https://api.events.knowbe4.com/events/{id} Then Make sure the data array contains user events """ eventId: str = "123-456-789" from KnowBe4KMSAT import kmsat_user_event_delete_command requests_mock.delete(f"{USER_EVENT_BASE_URL}/events/{eventId}", status_code=204) userEventClient = UserEventClient( USER_EVENT_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"id": eventId} result = kmsat_user_event_delete_command(userEventClient, args) assert result.readable_output == f"Successfully deleted event: {eventId}" def test_get_user_event_status(requests_mock): """ Given an Event ID When Calling https://api.events.knowbe4.com/statuses/{id} Then Make sure the data contains the user events """ eventId: str = "abcdefgh-843c-4fc8-bb2f-decf89876f7b" mock_response_data = util_load_json("test_data/user_event_status_response.json") from KnowBe4KMSAT import kmsat_user_event_status_list_command requests_mock.get( f"{USER_EVENT_BASE_URL}/statuses/{eventId}", json=mock_response_data, status_code=200 ) userEventClient = UserEventClient( USER_EVENT_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {"id": eventId} result = kmsat_user_event_status_list_command(userEventClient, args) assert requests_mock.last_request.headers['X-KB4-Integration'] == "Cortex XSOAR KMSAT" assert result.outputs_prefix == "KMSAT.UserEventStatus" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data["data"] def test_get_user_event_statuses(requests_mock): """ Given no params When Calling https://api.events.knowbe4.com/statuses Then Make sure the data contains the list of user event requests """ mock_response_data = util_load_json("test_data/user_event_statuses_response.json") from KnowBe4KMSAT import kmsat_user_event_statuses_list_command requests_mock.get( f"{USER_EVENT_BASE_URL}/statuses", json=mock_response_data, status_code=200 ) userEventClient = UserEventClient( USER_EVENT_BASE_URL, verify=False, proxy=False, headers={ "Authorization": "Bearer abc123xyz", "Content-Type": "application/json", }, ) args: dict = {} result = kmsat_user_event_statuses_list_command(userEventClient, args) assert requests_mock.last_request.headers['X-KB4-Integration'] == "Cortex XSOAR KMSAT" assert result.outputs_prefix == "KMSAT.UserEventStatuses" assert result.outputs_key_field == "id" assert result.outputs == mock_response_data["data"] def test_get_pagination(): """ Given A page number and the number of results per page. When Calling get_pagination() Then Make sure the data returns with page and per_page """ from KnowBe4KMSAT import get_pagination args = {"page": 1, "per_page": 10} assert get_pagination(args) == args