MS-ISAC
This API queries alerts and alert data from the MS-ISAC API to enrich and query alerts from the platform.
Utilities · MS-ISAC
Details
| ID | MS-ISAC |
|---|---|
| Provider | CIS |
| Category | Utilities |
| From Version | 5.5.0 |
| Docker Image | demisto/python3:3.12.8.3720084 |
| Supported Modules | Agentix XSIAM |
README
This API queries alerts and alert data from the MS-ISAC API to enrich and query alerts from the platform
This integration was integrated and tested with version 1.2 (7/1/25) of the MS-ISAC API.
Configure MS-ISAC in Cortex
| Parameter | Description | Required |
|---|---|---|
| API Key | Key provided by MS-ISAC according to the detailed Instructions | True |
| Server URL | This is the URL provided by MS-ISAC for the base of all endpoints | True |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
msisac-get-alert
Retrieve alert data by its ID
Base Command
msisac-get-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert_id | The ID of the MS-ISAC alert. | True |
Context Output
| Path | Type | Description |
|---|---|---|
| MSISAC.Alert.alertId | string | The id for this alert |
| MSISAC.Alert.affectedIp | string | The internal IP that is associated with the traffic |
| MSISAC.Alert.alertedAt | string | The timestamp when the alert happened |
| MSISAC.Alert.applicationProtocol | string | The protocol associated with the traffic |
| MSISAC.Alert.category | string | The category of the alert |
| MSISAC.Alert.createdAt | string | The timestamp when the alert was created |
| MSISAC.Alert.destinationIp | string | The destination IP of the traffic |
| MSISAC.Alert.destinationPort | number | The destination port number of the traffic |
| MSISAC.Alert.encodedPayload | string | The encoded payload of the traffic |
| MSISAC.Alert.httpHostname | string | The HTTP hostname of the traffic |
| MSISAC.Alert.httpMethod | string | The HTTP method of the traffic |
| MSISAC.Alert.httpStatus | number | The HTTP status code of the traffic |
| MSISAC.Alert.httpUrl | string | The HTTP url of the traffic |
| MSISAC.Alert.logicalSensor | string | The name for the sensor that triggered the event |
| MSISAC.Alert.mitreTactic | string | The mitre tactic associated with the traffic |
| MSISAC.Alert.mitreTechnique | string | The mitre technique associated with the traffic |
| MSISAC.Alert.signatureDirection | string | The direction of the traffic flow |
| MSISAC.Alert.signatureId | number | The signature id of the traffic |
| MSISAC.Alert.signatureName | string | The signature name of the traffic |
| MSISAC.Alert.sourceIp | string | The source IP of the traffic |
| MSISAC.Alert.sourcePort | number | The source port number of the traffic |
| MSISAC.Alert.transportProtocol | string | The transport protocol of the traffic |
msisac-retrieve-cases
Retrieves a list of MS-ISAC cases created since the given timestamp.
Base Command
msisac-retrieve-cases
Input
| Argument Name | Description | Required |
|---|---|---|
| timestamp | Needs to be in “2025-07-01T00:00:00” format, in UTC. If no timestamp is given, command will return cases from the last 72 hours. | False |
Context Output
| Path | Type | Description |
|---|---|---|
| MSISAC.RetrievedCases.caseId | string | ID for the retrieved MS-ISAC case |
| MSISAC.RetrievedCases.affectedIp | string | The internal IP that is associated with the traffic |
| MSISAC.RetrievedCases.alertIds | list | The MSISAC alert ids associated with the case |
| MSISAC.RetrievedCases.createdAt | string | The timestamp when the case was created. This is associated with the timestamp input parameter |
| MSISAC.RetrievedCases.logicalSensorName | string | The name for the sensor that triggered the event |
| MSISAC.RetrievedCases.modifiedAt | string | The timestamp for when the case was last modified |
| MSISAC.RetrievedCases.severity | string | The severity of the case |
Configuration parameters
apikey— (required)url— Server URL (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsincidentType— Incident typeisFetch— Fetch incidentsincidentFetchInterval— Incidents Fetch Intervalfirst_fetch— First Fetch Time
Commands (4)
-
msisac-get-alertRetrieve alert data by its ID.
-
msisac-get-eventDeprecatedRetrieve alert data by its ID.
-
msisac-retrieve-casesRetrieves a list of MS-ISAC cases since the given timestamp. If no timestamp is given, command will return cases from the last 72 hours.
-
msisac-retrieve-eventsDeprecatedRetrieves a list of MS-ISAC events for a given number of days (one or greater).
Prerequisites ----------------- The MS-ISAC API site is not available to the public. The site is secured in a number of ways, including restriction of access to the site by IP and the use of OAuth 2.0 to implement two-factor authentication. In order to access the site, your organization's primary point of contact must request access by contacting the MS-ISAC SOC. When contacting the MS-ISAC SOC to request API access, please include the following information: * The name and email of the direct point of contact (who the account will belong to) Organization name * The IP address or address range that will be connecting to the API site (your public IP) * The names of the sensors you would like on the service (this can be ALL or a subset of your sensors) Once your information has been verified, your IP will be whitelisted for API access. An organization and user account will be created and you will receive login credentials