NodeZero
Integrates with the NodeZero autonomous penetration testing platform to fetch weaknesses discovered during pentest operations. Automatically ingests HIGH and CRITICAL severity weaknesses as incidents for tracking and remediation.
Vulnerability Management · NodeZero
Details
| ID | NodeZero |
|---|---|
| Provider | Horizon3.ai |
| Category | Vulnerability Management |
| From Version | 6.1.0 |
| Docker Image | demisto/py3-tools:1.0.0.10895515 |
| Supported Modules | Agentix XSIAM |
README
NodeZero
Integrates with the NodeZero autonomous penetration testing platform to fetch weaknesses discovered during pentest operations. Automatically ingests HIGH and CRITICAL severity weaknesses as incidents for tracking and remediation.
Configure NodeZero on Cortex XSOAR
- Navigate to Settings > Integrations > Servers & Services.
- Search for NodeZero.
- Click Add instance to create and configure a new integration instance.
| Parameter | Description | Required |
|---|---|---|
| Server URL | The NodeZero API server URL. | True |
| API Key | The API Key required to authenticate to the NodeZero service. | True |
| Trust any certificate (not secure) | When selected, certificates are not checked. | False |
| Use system proxy settings | Runs the integration instance using the proxy server (HTTP or HTTPS) that you defined in the server configuration. | False |
| Fetch incidents | When selected, the integration fetches incidents. | False |
| Incident type | The incident type to create for fetched incidents. | False |
| Maximum number of weaknesses to fetch | Maximum number of incidents to fetch per run. Default is 200. | False |
| First fetch time | How far back to fetch on first run (e.g., “7 days”, “3 days”). Default is 7 days. | False |
| Incidents Fetch Interval | How often to fetch new incidents (in minutes). Default is 10080 (7 days). | False |
- Click Test to validate the URLs, token, and connection.
Fetch Incidents
The integration fetches HIGH and CRITICAL severity weaknesses from NodeZero pentest operations as incidents. Each weakness is converted to an XSOAR incident with the following mappings:
| NodeZero Field | XSOAR Incident Field |
|---|---|
| uuid | dbotMirrorId |
| created_at | occurred |
| severity | severity (CRITICAL=4, HIGH=3) |
| vuln_id | externalid |
| affected_asset_display_name | sourcehostname |
| ip | sourceip |
| score | nodezeroweaknessscore |
| vuln_category | nodezeroweaknesscategory |
| has_proof | nodezeroweaknessproven |
| attack_paths_count | nodezeroattackpathscount |
| vuln_cisa_kev | nodezerocisakov |
| vuln_known_ransomware_campaign_use | nodezeroransomwareuse |
| op_id | nodezeroopid |
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message is displayed in the War Room with the command details.
nodezero-get-weaknesses
Retrieves HIGH and CRITICAL weaknesses discovered by NodeZero pentests.
Base Command
nodezero-get-weaknesses
Input
| Argument Name | Description | Required |
|---|---|---|
| since_date | Fetch weaknesses created on or after this date (ISO 8601, e.g. 2024-01-01T00:00:00). Defaults to 7 days ago. | Optional |
| limit | Maximum number of weaknesses to return (1–1000). Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| NodeZero.Weakness.uuid | String | Unique identifier of the weakness. |
| NodeZero.Weakness.created_at | Date | Timestamp when the weakness was first discovered. |
| NodeZero.Weakness.vuln_id | String | Vulnerability identifier (e.g. CVE ID). |
| NodeZero.Weakness.vuln_name | String | Full vulnerability name. |
| NodeZero.Weakness.vuln_short_name | String | Short vulnerability name. |
| NodeZero.Weakness.vuln_category | String | Vulnerability category. |
| NodeZero.Weakness.vuln_cisa_kev | Boolean | Whether the vulnerability is in the CISA Known Exploited Vulnerabilities catalog. |
| NodeZero.Weakness.vuln_known_ransomware_campaign_use | Boolean | Whether the vulnerability is known to be used in ransomware campaigns. |
| NodeZero.Weakness.ip | String | IP address of the affected asset. |
| NodeZero.Weakness.has_proof | Boolean | Whether NodeZero has proof of exploitability. |
| NodeZero.Weakness.score | Number | Weakness severity score. |
| NodeZero.Weakness.severity | String | Weakness severity level (HIGH or CRITICAL). |
| NodeZero.Weakness.affected_asset_uuid | String | UUID of the affected asset. |
| NodeZero.Weakness.affected_asset_display_name | String | Display name of the affected asset. |
| NodeZero.Weakness.attack_paths_count | Number | Number of attack paths through this weakness. |
| NodeZero.Weakness.op_id | String | ID of the pentest operation that discovered this weakness. |
Command example
!nodezero-get-weaknesses limit=5
Human Readable Output
NodeZero Weaknesses
uuid severity vuln_name ip score has_proof abc-123 CRITICAL Example Vuln 10.0.0.1 9.8 true
Deduplication
The integration uses ID-based deduplication to prevent duplicate incidents:
- On first run, weaknesses from the last N days (configured via “First fetch time”) are fetched.
- On subsequent runs, the integration queries weaknesses since the most recent
created_attimestamp from the previous fetch. - UUIDs of weaknesses at the latest timestamp are tracked to avoid re-fetching them if they appear in the next query window.
This ensures that even if multiple weaknesses share the same timestamp, they are only ingested once.
Known Limitations
- Only HIGH and CRITICAL severity weaknesses are fetched.
- The integration uses a GraphQL API with JWT-based authentication.
- JWT tokens are cached and automatically refreshed before expiration.
Troubleshooting
If you encounter authentication errors, verify that:
- The API Key is correct and has not expired.
- The Server URL is accessible from the XSOAR server.
- SSL certificates are valid (or “Trust any certificate” is enabled for testing).
Configuration parameters
url— Server URL (required)credentials— API Key (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsisFetch— Fetch incidentsincidentType— Incident typemax_fetch— Maximum number of weaknesses to fetchfirst_fetch— First fetch timeincidentFetchInterval— Incidents Fetch Interval
Commands (1)
-
nodezero-get-weaknessesRetrieves HIGH and CRITICAL weaknesses discovered by NodeZero pentests.
category: Vulnerability Management provider: Horizon3.ai sectionorder: - Connect - Collect commonfields: id: NodeZero version: -1 configuration: - display: Server URL name: url defaultvalue: https://api.horizon3ai.com type: 0 required: true additionalinfo: The NodeZero API server URL. section: Connect - display: API Key displaypassword: API Key name: credentials type: 9 required: true hiddenusername: true additionalinfo: The API Key required to authenticate to the NodeZero service. section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 defaultvalue: 'false' required: false section: Connect advanced: true - display: Use system proxy settings name: proxy type: 8 defaultvalue: 'false' required: false section: Connect advanced: true - display: Fetch incidents name: isFetch type: 8 defaultvalue: 'false' required: false section: Collect - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Maximum number of weaknesses to fetch name: max_fetch type: 0 defaultvalue: '200' required: false additionalinfo: Maximum number of incidents to fetch per run. section: Collect - display: First fetch time name: first_fetch type: 0 defaultvalue: 7 days required: false additionalinfo: How far back to fetch on first run (e.g., "7 days", "3 days"). section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval type: 19 defaultvalue: '10080' required: false section: Collect description: Integrates with the NodeZero autonomous penetration testing platform to fetch weaknesses discovered during pentest operations. Automatically ingests HIGH and CRITICAL severity weaknesses as incidents for tracking and remediation. display: NodeZero name: NodeZero script: commands: - name: nodezero-get-weaknesses description: Retrieves HIGH and CRITICAL weaknesses discovered by NodeZero pentests. arguments: - name: since_date description: 'Fetch weaknesses created on or after this date (ISO 8601, e.g. 2024-01-01T00:00:00). Defaults to 7 days ago.' required: false - name: limit description: Maximum number of weaknesses to return (1–1000). required: false defaultValue: '50' outputs: - contextPath: NodeZero.Weakness.uuid description: Unique identifier of the weakness. type: String - contextPath: NodeZero.Weakness.created_at description: Timestamp when the weakness was first discovered. type: Date - contextPath: NodeZero.Weakness.vuln_id description: Vulnerability identifier (e.g. CVE ID). type: String - contextPath: NodeZero.Weakness.vuln_name description: Full vulnerability name. type: String - contextPath: NodeZero.Weakness.vuln_short_name description: Short vulnerability name. type: String - contextPath: NodeZero.Weakness.vuln_category description: Vulnerability category. type: String - contextPath: NodeZero.Weakness.vuln_cisa_kev description: Whether the vulnerability is in the CISA Known Exploited Vulnerabilities catalog. type: Boolean - contextPath: NodeZero.Weakness.vuln_known_ransomware_campaign_use description: Whether the vulnerability is known to be used in ransomware campaigns. type: Boolean - contextPath: NodeZero.Weakness.ip description: IP address of the affected asset. type: String - contextPath: NodeZero.Weakness.has_proof description: Whether NodeZero has proof of exploitability. type: Boolean - contextPath: NodeZero.Weakness.score description: Weakness severity score. type: Number - contextPath: NodeZero.Weakness.severity description: Weakness severity level (HIGH or CRITICAL). type: String - contextPath: NodeZero.Weakness.affected_asset_uuid description: UUID of the affected asset. type: String - contextPath: NodeZero.Weakness.affected_asset_display_name description: Display name of the affected asset. type: String - contextPath: NodeZero.Weakness.attack_paths_count description: Number of attack paths through this weakness. type: Number - contextPath: NodeZero.Weakness.op_id description: ID of the pentest operation that discovered this weakness. type: String dockerimage: demisto/py3-tools:1.0.0.10895515 isfetch: true runonce: false script: '-' subtype: python3 type: python defaultclassifier: NodeZero - Classifier defaultmapperin: NodeZero - Incoming Mapper fromversion: 6.1.0 marketplaces: - xsoar - marketplacev2 - platform supportedModules: - agentix - xsiam tests: - No tests (auto formatted)