SafewalkReports

Safewalk server integration.

Analytics & SIEM · Altipeak

Details

IDSafewalkReports
ProviderProtectimus
CategoryAnalytics & SIEM
From Version6.0.0
Docker Imagedemisto/python3:3.12.8.3296088
Supported ModulesAgentix XSIAM

README

Safewalk server integration
This integration was integrated and tested with version 3 of SafewalkReports

Configure SafewalkReports in Cortex

Parameter Description Required
Server URL (e.g. https://soar.monstersofhack.com)   True
Fetch incidents   False
Incident type   False
API Key   True
Trust any certificate (not secure)   False
Use system proxy settings   False
Fetch indicators   False
Incidents Fetch Interval   False
    False
    False
    False
Indicator Reputation Indicators from this integration instance will be marked with this reputation False
Source Reliability Reliability of the source providing the intelligence data True
    False
    False
Feed Fetch Interval   False
Bypass exclusion list When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. False
Tags Supports CSV values. False
Traffic Light Protocol Color The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

safewalk-get-associated-users


safewalk-get-associated-users

Base Command

safewalk-get-associated-users

Input

Argument Name Description Required
devicetype devicetype. Optional

Context Output

Path Type Description
Safewalk.reports.associated_users.data.id String users data id
Safewalk.reports.associated_users.data.label String users data label

Human Readable Output

safewalk-get-authentication-methods-distribution


safewalk-get-authentication-methods-distribution

Base Command

safewalk-get-authentication-methods-distribution

Input

| Argument Name | Description | Required |
| — | — | — |

Context Output

Path Type Description
Safewalk.reports.device_auth_distribution.data.id String device_auth_distribution.data.id
Safewalk.reports.device_auth_distribution.data.label String device_auth_distribution.data.label
Safewalk.reports.device_auth_distribution.data.type String device_auth_distribution.data.type
Safewalk.reports.device_auth_distribution.data Number device_auth_distribution.data

Human Readable Output

safewalk-get-authentication-rate-per-device


safewalk-get-authentication-rate-per-device

Base Command

safewalk-get-authentication-rate-per-device

Input

| Argument Name | Description | Required |
| — | — | — |

Context Output

Path Type Description
Safewalk.reports.device_auth_rate.data.id String device_auth_rate.data.id
Safewalk.reports.device_auth_rate.data.label String device_auth_rate.data.label
Safewalk.reports.device_auth_rate.data.type String device_auth_rate.data.type
Safewalk.reports.device_auth_rate.data Number device_auth_rate.data

Human Readable Output

safewalk-get-least-active-users


safewalk-get-least-active-users

Base Command

safewalk-get-least-active-users

Input

Argument Name Description Required
sincedate sincedate. Optional
userinformation userinformation. Optional

Context Output

Path Type Description
Safewalk.reports.inactive_users.data.id String inactive_users.data.id
Safewalk.reports.inactive_users.data.label String inactive_users.data.label

Human Readable Output

safewalk-get-licenses-inventory


safewalk-get-licenses-inventory

Base Command

safewalk-get-licenses-inventory

Input

| Argument Name | Description | Required |
| — | — | — |

Context Output

Path Type Description
Safewalk.reports.licensesinventory.total Number licenses inventory total
Safewalk.reports.licensesinventory.data.id String icenses inventory data id
Safewalk.reports.licensesinventory.data.label String licenses inventory data label
Safewalk.reports.licensesinventory.data.type String licenses inventory data type
Safewalk.reports.licensesinventory.data Number licenses inventory data

Human Readable Output

safewalk-get-licenses-usage


safewalk-get-licenses-usage

Base Command

safewalk-get-licenses-usage

Input

Argument Name Description Required
begindate begindate. Optional
enddate enddate. Optional

Context Output

Path Type Description
Safewalk.reports.licensesusage.total Number licenses usage total
Safewalk.reports.licensesusage.data.id String licenses usage data id
Safewalk.reports.licensesusage.data.label String licenses usage data label
Safewalk.reports.licensesusage.data.type String licenses usage data type
Safewalk.reports.licensesusage.data Number licenses usage data

Human Readable Output

safewalk-get-most-active-users


safewalk-get-most-active-users

Base Command

safewalk-get-most-active-users

Input

Argument Name Description Required
days days. Optional
limit limit. Optional
userinformation userinformation. Optional

Context Output

Path Type Description
Safewalk.reports.mostactiveusers.data.id String mostactiveusers.data.id
Safewalk.reports.mostactiveusers.data.label String mostactiveusers.data.label
Safewalk.reports.mostactiveusers.data.type String mostactiveusers.data.type
Safewalk.reports.mostactiveusers.data String mostactiveusers.data

Human Readable Output

safewalk-get-physical-tokens-inventory


safewalk-get-physical-tokens-inventory

Base Command

safewalk-get-physical-tokens-inventory

Input

| Argument Name | Description | Required |
| — | — | — |

Context Output

Path Type Description
Safewalk.reports.physicaltokeninventory.total Number physicaltokeninventory.total
Safewalk.reports.physicaltokeninventory.data.id String physicaltokeninventory.data.id
Safewalk.reports.physicaltokeninventory.data.label String physicaltokeninventory.data.label
Safewalk.reports.physicaltokeninventory.data.type String physicaltokeninventory.data.type
Safewalk.reports.physicaltokeninventory.data Number physicaltokeninventory.data

Human Readable Output

safewalk-get-registered-devices-distribution


safewalk-get-registered-devices-distribution

Base Command

safewalk-get-registered-devices-distribution

Input

| Argument Name | Description | Required |
| — | — | — |

Context Output

Path Type Description
Safewalk.reports.registereddevices.total Number registereddevices.total
Safewalk.reports.registereddevices.data.id String registereddevices.data.id
Safewalk.reports.registereddevices.data.label String registereddevices.data.label
Safewalk.reports.registereddevices.data.type String registereddevices.data.type
Safewalk.reports.registereddevices.data Number registereddevices.data

Human Readable Output

safewalk-get-registration


safewalk-get-registration

Base Command

safewalk-get-registration

Input

Argument Name Description Required
begindate begindate. Optional
enddate enddate. Optional
userinformation userinformation. Optional

Context Output

Path Type Description
Safewalk.reports.registration.total Number registration.total
Safewalk.reports.registration.data.id String registration.data.id
Safewalk.reports.registration.data.label String registration.data.label
Safewalk.reports.registration.data.type String registration.data.type

Human Readable Output

safewalk-get-users-associations-indicators


safewalk-get-users-associations-indicators

Base Command

safewalk-get-users-associations-indicators

Input

| Argument Name | Description | Required |
| — | — | — |

Context Output

Path Type Description
Safewalk.reports.usersassociations.total Number usersassociations.total
Safewalk.reports.usersassociations.data.id String usersassociations.data.id
Safewalk.reports.usersassociations.data.label String usersassociations.data.label
Safewalk.reports.usersassociations.data.type String usersassociations.data.type
Safewalk.reports.usersassociations.data Number usersassociations.data

Human Readable Output

Configuration parameters

  • url — Server URL (e.g. https://soar.monstersofhack.com) (required)
  • isFetch — Fetch incidents
  • incidentType — Incident type
  • apikey — API Key (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • feed — Fetch indicators
  • incidentFetchInterval — Incidents Fetch Interval
  • first_fetch — First fetch
  • max_fetch — Maximum number of incidents per fetch
  • fetch_query_filter — Fetch Query Filter
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • feedBypassExclusionList — Bypass exclusion list
  • feedTags — Tags
  • tlp_color — Traffic Light Protocol Color

Commands (11)

  • safewalk-get-associated-users

    safewalk-get-associated-users.

  • safewalk-get-authentication-methods-distribution

    safewalk-get-authentication-methods-distribution.

  • safewalk-get-authentication-rate-per-device

    safewalk-get-authentication-rate-per-device.

  • safewalk-get-least-active-users

    safewalk-get-least-active-users.

  • safewalk-get-licenses-inventory

    safewalk-get-licenses-inventory.

  • safewalk-get-licenses-usage

    safewalk-get-licenses-usage.

  • safewalk-get-most-active-users

    safewalk-get-most-active-users.

  • safewalk-get-physical-tokens-inventory

    safewalk-get-physical-tokens-inventory.

  • safewalk-get-registered-devices-distribution

    safewalk-get-registered-devices-distribution.

  • safewalk-get-registration

    safewalk-get-registration.

  • safewalk-get-users-associations-indicators

    safewalk-get-users-associations-indicators.

commonfields:
  id: SafewalkReports
  version: -1
name: SafewalkReports
display: Safewalk Reports
category: Analytics & SIEM
provider: Protectimus
description: Safewalk server integration.
configuration:
- display: Server URL (e.g. https://soar.monstersofhack.com)
  name: url
  defaultvalue: https://safwalk-server.company.com:8443
  type: 0
  required: true
- display: Fetch incidents
  name: isFetch
  type: 8
  required: false
- display: Incident type
  name: incidentType
  type: 13
  required: false
- display: API Key
  name: apikey
  defaultvalue: 5169775c23fc37acb6a281f11717709ebe1c75b7
  type: 4
  required: true
- display: Trust any certificate (not secure)
  name: insecure
  defaultvalue: "false"
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
- display: Fetch indicators
  name: feed
  type: 8
  required: false
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: "1"
  type: 19
  required: false
- display: First fetch
  name: first_fetch
  defaultvalue: 0 minutes
  type: 0
  required: false
- display: Maximum number of incidents per fetch
  name: max_fetch
  defaultvalue: "50"
  type: 0
  required: false
- display: Fetch Query Filter
  name: fetch_query_filter
  defaultvalue: ACCESS_DENIED,USER_DOES_NOT_EXIST,INVALID_OTP
  type: 0
  required: false
- name: feedReputation
  display: Indicator Reputation
  type: 18
  options:
  - None
  - Good
  - Suspicious
  - Bad
  additionalinfo: Indicators from this integration instance will be marked with this reputation
  required: false
- name: feedReliability
  display: Source Reliability
  type: 15
  required: true
  options:
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  additionalinfo: Reliability of the source providing the intelligence data
- name: feedExpirationPolicy
  display: ''
  type: 17
  options:
  - never
  - interval
  - indicatorType
  - suddenDeath
  required: false
- name: feedExpirationInterval
  display: ''
  type: 1
  required: false
- name: feedFetchInterval
  display: Feed Fetch Interval
  type: 19
  required: false
- name: feedBypassExclusionList
  display: Bypass exclusion list
  type: 8
  additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.
  required: false
- name: feedTags
  display: Tags
  type: 0
  additionalinfo: Supports CSV values.
  required: false
- name: tlp_color
  display: Traffic Light Protocol Color
  options:
  - RED
  - AMBER
  - GREEN
  - WHITE
  type: 15
  additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed
  required: false
script:
  commands:
  - name: safewalk-get-associated-users
    outputs:
    - contextPath: Safewalk.reports.associated_users.data.id
      description: 'users data id.'
      type: String
    - contextPath: Safewalk.reports.associated_users.data.label
      description: 'users data label.'
      type: String
    arguments:
    - name: devicetype
      description: devicetype.
    description: safewalk-get-associated-users.
  - name: safewalk-get-authentication-methods-distribution
    outputs:
    - contextPath: Safewalk.reports.device_auth_distribution.data.id
      description: 'device_auth_distribution.data.id'
      type: String
    - contextPath: Safewalk.reports.device_auth_distribution.data.label
      description: 'device_auth_distribution.data.label'
      type: String
    - contextPath: Safewalk.reports.device_auth_distribution.data.type
      description: 'device_auth_distribution.data.type'
      type: String
    - contextPath: Safewalk.reports.device_auth_distribution.data
      description: 'device_auth_distribution.data'
      type: Number
    arguments: []
    description: safewalk-get-authentication-methods-distribution.
  - name: safewalk-get-authentication-rate-per-device
    outputs:
    - contextPath: Safewalk.reports.device_auth_rate.data.id
      description: 'device_auth_rate.data.id'
      type: String
    - contextPath: Safewalk.reports.device_auth_rate.data.label
      description: 'device_auth_rate.data.label'
      type: String
    - contextPath: Safewalk.reports.device_auth_rate.data.type
      description: 'device_auth_rate.data.type'
      type: String
    - contextPath: Safewalk.reports.device_auth_rate.data
      description: 'device_auth_rate.data'
      type: Number
    arguments: []
    description: safewalk-get-authentication-rate-per-device.
  - name: safewalk-get-least-active-users
    outputs:
    - contextPath: Safewalk.reports.inactive_users.data.id
      description: 'inactive_users.data.id'
      type: String
    - contextPath: Safewalk.reports.inactive_users.data.label
      description: 'inactive_users.data.label'
      type: String
    arguments:
    - name: sincedate
      description: sincedate.
    - name: userinformation
      description: userinformation.
    description: safewalk-get-least-active-users.
  - name: safewalk-get-licenses-inventory
    outputs:
    - contextPath: Safewalk.reports.licensesinventory.total
      description: 'licenses inventory total.'
      type: Number
    - contextPath: Safewalk.reports.licensesinventory.data.id
      description: 'icenses inventory data id.'
      type: String
    - contextPath: Safewalk.reports.licensesinventory.data.label
      description: 'licenses inventory data label.'
      type: String
    - contextPath: Safewalk.reports.licensesinventory.data.type
      description: 'licenses inventory data type.'
      type: String
    - contextPath: Safewalk.reports.licensesinventory.data
      description: 'licenses inventory data.'
      type: Number
    arguments: []
    description: safewalk-get-licenses-inventory.
  - name: safewalk-get-licenses-usage
    outputs:
    - contextPath: Safewalk.reports.licensesusage.total
      description: 'licenses usage total.'
      type: Number
    - contextPath: Safewalk.reports.licensesusage.data.id
      description: 'licenses usage data id.'
      type: String
    - contextPath: Safewalk.reports.licensesusage.data.label
      description: 'licenses usage data label.'
      type: String
    - contextPath: Safewalk.reports.licensesusage.data.type
      description: 'licenses usage data type.'
      type: String
    - contextPath: Safewalk.reports.licensesusage.data
      description: 'licenses usage data.'
      type: Number
    arguments:
    - name: begindate
      description: begindate.
    - name: enddate
      description: enddate.
    description: safewalk-get-licenses-usage.
  - name: safewalk-get-most-active-users
    outputs:
    - contextPath: Safewalk.reports.mostactiveusers.data.id
      description: 'mostactiveusers.data.id'
      type: String
    - contextPath: Safewalk.reports.mostactiveusers.data.label
      description: 'mostactiveusers.data.label'
      type: String
    - contextPath: Safewalk.reports.mostactiveusers.data.type
      description: 'mostactiveusers.data.type'
      type: String
    - contextPath: Safewalk.reports.mostactiveusers.data
      description: 'mostactiveusers.data'
      type: String
    arguments:
    - name: days
      description: days.
    - name: limit
      description: limit.
    - name: userinformation
      description: userinformation.
    description: safewalk-get-most-active-users.
  - name: safewalk-get-physical-tokens-inventory
    outputs:
    - contextPath: Safewalk.reports.physicaltokeninventory.total
      description: 'physicaltokeninventory.total'
      type: Number
    - contextPath: Safewalk.reports.physicaltokeninventory.data.id
      description: 'physicaltokeninventory.data.id'
      type: String
    - contextPath: Safewalk.reports.physicaltokeninventory.data.label
      description: 'physicaltokeninventory.data.label'
      type: String
    - contextPath: Safewalk.reports.physicaltokeninventory.data.type
      description: 'physicaltokeninventory.data.type'
      type: String
    - contextPath: Safewalk.reports.physicaltokeninventory.data
      description: 'physicaltokeninventory.data'
      type: Number
    arguments: []
    description: safewalk-get-physical-tokens-inventory.
  - name: safewalk-get-registered-devices-distribution
    outputs:
    - contextPath: Safewalk.reports.registereddevices.total
      description: 'registereddevices.total'
      type: Number
    - contextPath: Safewalk.reports.registereddevices.data.id
      description: 'registereddevices.data.id'
      type: String
    - contextPath: Safewalk.reports.registereddevices.data.label
      description: 'registereddevices.data.label'
      type: String
    - contextPath: Safewalk.reports.registereddevices.data.type
      description: 'registereddevices.data.type'
      type: String
    - contextPath: Safewalk.reports.registereddevices.data
      description: 'registereddevices.data'
      type: Number
    arguments: []
    description: safewalk-get-registered-devices-distribution.
  - name: safewalk-get-registration
    outputs:
    - contextPath: Safewalk.reports.registration.total
      description: 'registration.total'
      type: Number
    - contextPath: Safewalk.reports.registration.data.id
      description: 'registration.data.id'
      type: String
    - contextPath: Safewalk.reports.registration.data.label
      description: 'registration.data.label'
      type: String
    - contextPath: Safewalk.reports.registration.data.type
      description: 'registration.data.type'
      type: String
    arguments:
    - name: begindate
      description: begindate.
    - name: enddate
      description: enddate.
    - name: userinformation
      description: userinformation.
    description: safewalk-get-registration.
  - name: safewalk-get-users-associations-indicators
    outputs:
    - contextPath: Safewalk.reports.usersassociations.total
      description: 'usersassociations.total'
      type: Number
    - contextPath: Safewalk.reports.usersassociations.data.id
      description: 'usersassociations.data.id'
      type: String
    - contextPath: Safewalk.reports.usersassociations.data.label
      description: 'usersassociations.data.label'
      type: String
    - contextPath: Safewalk.reports.usersassociations.data.type
      description: 'usersassociations.data.type'
      type: String
    - contextPath: Safewalk.reports.usersassociations.data
      description: 'usersassociations.data'
      type: Number
    arguments: []
    description: safewalk-get-users-associations-indicators.
  dockerimage: demisto/python3:3.12.8.3296088
  isfetch: true
  runonce: false
  script: '-'
  subtype: python3
  type: python
  isFetchSamples: true
fromversion: 6.0.0
tests:
- No tests (auto formatted)