Details
| ID | PICUS |
|---|---|
| Provider | PicusSecurity |
| Category | Network Security |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.10.12.63474 |
| Supported Modules | Agentix XSIAM |
README
Continuous Breach And Attack Simulation
Configure PICUS in Cortex
| Parameter | Description | Required |
|---|---|---|
| PICUS URL | For example : https://192.168.100.100/ | True |
| API Key - Refresh Token | Picus Interface - SETTINGS - ADVANCED - API TOKEN - Generate and Show Token | True |
| Trust any certificate (not secure) | ||
| Use system proxy settings |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
picus-vector-compare
Attack Result - Makes a comparison of the given vector’s results. Example Command: !picus-vector-compare begin_date=2020-01-20 end_date=2021-01-20 trusted=Trusted_Peer1 untrusted=Untrusted_Peer1
Base Command
picus-vector-compare
Input
| Argument Name | Description | Required |
|---|---|---|
| begin_date | Result begin date. | Required |
| end_date | Result end date. | Required |
| trusted | Victem Peer. | Required |
| untrusted | Attacker Peer. | Required |
Context Output
There is no context output for this command.
picus-attack-result-list
Returns the list of the attack results have optional parameters for pagination and filtration. \nExample Command:\n !picus-attack-result-list attack_result=insecure begin_date=2020-01-01 end_date=2020-09-05 vector1=Trusted-Peer1 vector2=Untrusted-Peer1
Base Command
picus-attack-result-list
Input
| Argument Name | Description | Required |
|---|---|---|
| attack_result | Attack results that should be filtered. Secure or Insecure. Possible values are: secure, insecure. Default is insecure. | Required |
| begin_date | Threat release date filter start of the date range. | Required |
| console_output_info | Default: false - Process Results of Scenario Details have console output information which can be in large sizes so this data is disabled by default. Default is False. | Optional |
| end_date | string Default: “Today’s date formatted YYYY-mm-dd” Threat release date filter end of the date range if a begin date is given and end date not, default will be used. | Required |
| from_time | Default: “null” allowed time formats RFC822, RFC822Z, RFC1123, RFC1123Z, RFC850, RFC3339. Default is null. | Optional |
| page | Default: 1 Requested page number. Default is 1. | Optional |
| size | Default: 50 Requested data size. Default is 50. | Optional |
| threat_parameters | “threat_parameters”: { “begin_date”: “2018-10-29”, “categories”: [ [ “Malicious Code” ], [ “Attack Scenario”, “Defense Evasion”, “Indicator Removal from Tools” ] ],. | Optional |
| vector1 | Array of objects (PeerPairParams) Vectors.(Trusted Peer). | Required |
| vector2 | Array of objects (PeerPairParams) Vectors.(Untrusted Peer). | Required |
Context Output
There is no context output for this command.
picus-specific-threats-results
Returns the list of the attack results of a single threat have optional parameters for pagination and filtration. Example Command: !picus-specific-threats-results threat_id=666059
Base Command
picus-specific-threats-results
Input
| Argument Name | Description | Required |
|---|---|---|
| cve | CVE code of the threat to be filtered. | Optional |
| md5 | The md5 of the threat. | Optional |
| page | integer <int64> - Default: 1 Requested page number. Default is 1. | Optional |
| sha256 | SHA256 hash of the threat. | Optional |
| size | integer <int64> - Default: 50 Requested data size. Default is 50. | Optional |
| threat_id | integer <int64> PID of the threat. | Required |
Context Output
There is no context output for this command.
picus-peer-list
Returns the peer list with current statuses
Base Command
picus-peer-list
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
picus-attack-all-vectors
Schedules given attack on all possible vectors
Base Command
picus-attack-all-vectors
Input
| Argument Name | Description | Required |
|---|---|---|
| threat_id | Example: threat_id=100682 PID of the threat. | Required |
Context Output
There is no context output for this command.
picus-attack-single
Schedules a single attack on requested vector
Base Command
picus-attack-single
Input
| Argument Name | Description | Required |
|---|---|---|
| threat_id | Example: threat_id=666059 PID of the threat. | Required |
| variant | Example: variant=HTTP. | Required |
| vector1 | Example: trusted=Trusted-Peer-Name Trusted peer name, if type is overall, it is not necessary. | Required |
| vector2 | Example: untrusted=Untrusted-Peer-Name Untrusted peer name, if type is overall, it is not necessary. | Required |
Context Output
There is no context output for this command.
picus-trigger-update
Triggers the update mechanism manually, returns if the update-command is taken successfully
Base Command
picus-trigger-update
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
picus-version
Returns the current version and the update time config
Base Command
picus-version
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
picus-mitigation-list
Returns the list of the mitigations of threats\nhave optional parameters for pagination and filtration, this route may not be used associated with your license. Example Command: !picus-mitigation-list begin_date=2021-01-01 end_date=2021-02-01 threat_id=528370 products=”McAfee IPS” signature_id=0x40208a00
Base Command
picus-mitigation-list
Input
| Argument Name | Description | Required |
|---|---|---|
| begin_date | Threat release date filter start of the date range. | Required |
| end_date | Default: “Today’s date formatted YYYY-mm-dd” Threat release date filter end of the date range if a begin date is given and end date not, default will be used. | Required |
| page | integer <int64> Default: 1 Requested page number. Default is 1. | Optional |
| products | Array of strings - Products info of the mitigation. Possible values are: , . | Required |
| signature_id | ID of the signature. | Required |
| size | integer <int64> - Default: 50 Requested data size. Default is 50. | Optional |
| threat_id | integer <int64> - PID of the threat. | Required |
Context Output
There is no context output for this command.
picus-mitre-matrix
Returns the mitre matrix metadata takes no parameters
Base Command
picus-mitre-matrix
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
picus-sigma-rules-list
Returns the list of the sigma rules of scenario actions have optional parameters for pagination and filtration, this route may not be used associated with your license
Base Command
picus-sigma-rules-list
Input
| Argument Name | Description | Required |
|---|---|---|
| size | Size of Displayed Rule. Default is 100. | Optional |
| page | Page of Displayed Rule. Default is 1. | Optional |
Context Output
There is no context output for this command.
picus-vector-list
Returns the list of the vectors all disabled and enabled ones have optional parameters for pagination
Base Command
picus-vector-list
Input
| Argument Name | Description | Required |
|---|---|---|
| add_user_details | boolean - Add vectors’ assigned user details to the response. Default is True. | Optional |
| page | Default: 1 Requested page number. Default is 1. | Optional |
| size | Default: 50 Requested data size. Default is 50. | Optional |
Context Output
There is no context output for this command.
Configuration parameters
server— PICUS URL (required)apikey— API Key - Refresh Token (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (12)
-
picus-attack-all-vectorsSchedules given attack on all possible vectors
-
picus-attack-result-listReturns the list of the attack results have optional parameters for pagination and filtration. \nExample Command:\n !picus-attack-result-list attack_result=insecure begin_date=2020-01-01 end_date=2020-09-05 vector1=Trusted-Peer1 vector2=Untrusted-Peer1
-
picus-attack-singleSchedules a single attack on requested vector
-
picus-mitigation-listReturns the list of the mitigations of threats\nhave optional parameters for pagination and filtration, this route may not be used associated with your license. Example Command: !picus-mitigation-list begin_date=2021-01-01 end_date=2021-02-01 threat_id=528370 products="McAfee IPS" signature_id=0x40208a00
-
picus-mitre-matrixReturns the mitre matrix metadata takes no parameters
-
picus-peer-listReturns the peer list with current statuses
-
picus-sigma-rules-listReturns the list of the sigma rules of scenario actions have optional parameters for pagination and filtration, this route may not be used associated with your license
-
picus-specific-threats-resultsReturns the list of the attack results of a single threat have optional parameters for pagination and filtration. Example Command: !picus-specific-threats-results threat_id=666059
-
picus-trigger-updateTriggers the update mechanism manually, returns if the update-command is taken successfully
-
picus-vector-compareAttack Result - Makes a comparison of the given vector's results. Example Command: !picus-vector-compare begin_date=2020-01-20 end_date=2021-01-20 trusted=Trusted_Peer1 untrusted=Untrusted_Peer1
-
picus-vector-listReturns the list of the vectors all disabled and enabled ones have optional parameters for pagination
-
picus-versionReturns the current version and the update time config
category: Network Security provider: PicusSecurity commonfields: id: PICUS version: -1 configuration: - additionalinfo: 'For example : https://192.168.100.100/' defaultvalue: https://|HOST| display: PICUS URL name: server required: true type: 0 - additionalinfo: Picus Interface - SETTINGS - ADVANCED - API TOKEN - Generate and Show Token display: API Key - Refresh Token name: apikey required: true type: 4 - defaultvalue: "false" display: Trust any certificate (not secure) name: insecure type: 8 required: false - defaultvalue: "false" display: Use system proxy settings name: proxy type: 8 required: false description: Deprecated. Use PicusAutomation instead. display: PICUS (Deprecated) name: PICUS deprecated: true script: commands: - arguments: - description: Result begin date name: begin_date required: true - description: Result end date name: end_date required: true - description: Victem Peer name: trusted required: true - description: Attacker Peer name: untrusted required: true description: 'Attack Result - Makes a comparison of the given vector''s results. Example Command: !picus-vector-compare begin_date=2020-01-20 end_date=2021-01-20 trusted=Trusted_Peer1 untrusted=Untrusted_Peer1' name: picus-vector-compare - arguments: - auto: PREDEFINED defaultValue: insecure description: Attack results that should be filtered. Secure or Insecure name: attack_result predefined: - secure - insecure required: true - description: Threat release date filter start of the date range name: begin_date required: true - defaultValue: "False" description: 'Default: false - Process Results of Scenario Details have console output information which can be in large sizes so this data is disabled by default' name: console_output_info - description: "\t string Default: \"Today's date formatted YYYY-mm-dd\" Threat release date filter end of the date range if a begin date is given and end date not, default will be used" name: end_date required: true - defaultValue: "null" description: 'Default: "null" allowed time formats RFC822, RFC822Z, RFC1123, RFC1123Z, RFC850, RFC3339' name: from_time - defaultValue: "1" description: 'Default: 1 Requested page number' name: page - default: true defaultValue: "50" description: 'Default: 50 Requested data size' name: size - description: '"threat_parameters": { "begin_date": "2018-10-29", "categories": [ [ "Malicious Code" ], [ "Attack Scenario", "Defense Evasion", "Indicator Removal from Tools" ] ],' name: threat_parameters - description: ' Array of objects (PeerPairParams) Vectors.(Trusted Peer)' name: vector1 required: true - description: ' Array of objects (PeerPairParams) Vectors.(Untrusted Peer)' name: vector2 required: true description: Returns the list of the attack results have optional parameters for pagination and filtration. \nExample Command:\n !picus-attack-result-list attack_result=insecure begin_date=2020-01-01 end_date=2020-09-05 vector1=Trusted-Peer1 vector2=Untrusted-Peer1 name: picus-attack-result-list - arguments: - description: CVE code of the threat to be filtered name: cve - description: The md5 of the threat name: md5 - defaultValue: "1" description: 'integer <int64> - Default: 1 Requested page number' name: page - description: SHA256 hash of the threat name: sha256 - defaultValue: "50" description: 'integer <int64> - Default: 50 Requested data size' name: size - description: integer <int64> PID of the threat name: threat_id required: true description: 'Returns the list of the attack results of a single threat have optional parameters for pagination and filtration. Example Command: !picus-specific-threats-results threat_id=666059' name: picus-specific-threats-results - arguments: [] description: Returns the peer list with current statuses name: picus-peer-list - arguments: - description: 'Example: threat_id=100682 PID of the threat' name: threat_id required: true description: Schedules given attack on all possible vectors name: picus-attack-all-vectors - arguments: - description: 'Example: threat_id=666059 PID of the threat' name: threat_id required: true - description: 'Example: variant=HTTP' name: variant required: true - description: 'Example: trusted=Trusted-Peer-Name Trusted peer name, if type is overall, it is not necessary' name: vector1 required: true - description: 'Example: untrusted=Untrusted-Peer-Name Untrusted peer name, if type is overall, it is not necessary' name: vector2 required: true description: Schedules a single attack on requested vector name: picus-attack-single - arguments: [] description: Triggers the update mechanism manually, returns if the update-command is taken successfully name: picus-trigger-update - arguments: [] description: Returns the current version and the update time config name: picus-version - arguments: - description: Threat release date filter start of the date range name: begin_date required: true - description: 'Default: "Today''s date formatted YYYY-mm-dd" Threat release date filter end of the date range if a begin date is given and end date not, default will be used' name: end_date required: true - defaultValue: "1" description: "integer <int64> Default: 1 Requested page number" name: page - auto: PREDEFINED description: Array of strings - Products info of the mitigation isArray: true name: products predefined: - "" - "" required: true - description: ID of the signature name: signature_id required: true - defaultValue: "50" description: "integer <int64> - Default: 50 Requested data size" name: size - description: integer <int64> - PID of the threat name: threat_id required: true description: 'Returns the list of the mitigations of threats\nhave optional parameters for pagination and filtration, this route may not be used associated with your license. Example Command: !picus-mitigation-list begin_date=2021-01-01 end_date=2021-02-01 threat_id=528370 products="McAfee IPS" signature_id=0x40208a00' name: picus-mitigation-list - arguments: [] description: Returns the mitre matrix metadata takes no parameters name: picus-mitre-matrix - arguments: - defaultValue: "100" description: Size of Displayed Rule name: size - default: true defaultValue: "1" description: Page of Displayed Rule name: page description: Returns the list of the sigma rules of scenario actions have optional parameters for pagination and filtration, this route may not be used associated with your license name: picus-sigma-rules-list - arguments: - defaultValue: "True" description: boolean - Add vectors' assigned user details to the response name: add_user_details - defaultValue: "1" description: 'Default: 1 Requested page number' name: page - defaultValue: "50" description: 'Default: 50 Requested data size' name: size description: Returns the list of the vectors all disabled and enabled ones have optional parameters for pagination name: picus-vector-list dockerimage: demisto/python3:3.10.12.63474 script: '' subtype: python3 type: python fromversion: 6.0.0 tests: - No tests (auto formatted)