SecurityAdvisor Deprecated
Deprecated. No available replacement.
Messaging and Conferencing · SecurityAdvisor (Deprecated)
Details
| ID | SecurityAdvisor |
|---|---|
| Provider | KnowBe4 |
| Category | Messaging and Conferencing |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.9.8.24399 |
| Supported Modules | Agentix |
README
Use SecurityAdvisor integration to coach your end users on cyber security threats they face.
SecurityAdvisor advisor contextual coaching platform allows you to perform targeted coaching to users therefore making them more likely to change their behavior and reduce the number of incidents.
For example, a user whose system is often targeted for malware can be coached with a malware context, a phishing target educated about phishing.
Our training is quick & relevant not more than 5 minutes and has shown to reduce incidents from targeted user by 90% due to better security awareness and hygine.
Use Cases
- A user is targeted with a phishing attack. Use coach-end-user end user command with this user’s email address and “phishing” context to send them a training on Email Phishing.
- A malware is found on user’s machine due to unsafe browsing habbits. Use coach-end-user end user command with this user’s email address and “malware” context to send them a training on staying safe online.
- A user is targeted with ransomware attack. Use coach-end-user end user command with this user’s email address and “ransomware” context to send them a training on staying safe online.
- You can create conditional coaching conditions like send coaching is the user has scored less than 80 in a particular coaching context.
You can add coach-end-user command (see commands below) to any section of your playbook to trigger these notifications.
Prerequisites
You need an API key for this integration.
- Log in to www.securityadvisor.io.
- Navigate to the My Profile section or contact support@securityadvisor.io.
Configure SecurityAdvisor on Cortex XSOAR
- Navigate to Settings > Integrations > Servers & Services.
- Search for SecurityAdvisor.
- Click Add instance to create and configure a new integration instance.
- Name: a textual name for the integration instance.
- use system proxy
- trust any certificate
- API Endpoint URL = “https://www.securityadvisor.io/
- API Key = See Prerequisites above to get your API key
- Click Test to validate the URLs, token, and connection.
Commands
You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
- coach-end-user
1. Coach an end user
Sends a contextual message to a single user. This command takes a user email address as “user” input. This is where the training email is sent.
The “context” input has four predefined settings:
- malware: Coach user on malware
- phishing: Coach user on phishing
- ransomware: Coach user on ransomware
- spam: Coach user to avoid spam
Base Command
coach-end-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user | User email address. | Required |
| context | Coaching context. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| SecurityAdvisor.CoachUser.coaching_date | string | Time when coaching was sent or completed. |
| SecurityAdvisor.CoachUser.coaching_status | string | User coaching status for context. “Pending” means that coaching has been sent and is pending. “Done” means the user has completed the coaching. |
| SecurityAdvisor.CoachUser.coaching_score | string | User’s coaching score (out of 100). |
| SecurityAdvisor.CoachUser.context | string | Coaching context. |
Command Example
coach-end-user user="track@securityadvisor.io" context="phishing"
Context Example
{
"SecurityAdvisor.CoachUser": {
"coaching_date": "2019-10-04T21:04:19.480425",
"coaching_status": "Pending",
"coaching_score": "",
"user": "track@securityadvisor.io",
"context": "phishing",
"message": "Coaching Sent"
}
}
SecurityAdvisorBot says
| coaching_date | coaching_status | coaching_score | user | context | message |
|---|---|---|---|---|---|
| 2019-10-04T21:04:19.480425 | Pending | track@securityadvisor.io | phishing | Coaching Sent |
Configuration parameters
proxy— Use system proxy settingsinsecure— Trust any certificate (not secure)url— API Endpoint URL (required)apikey— API Key
Commands (1)
-
coach-end-usersends contextual message to single user
import SecurityAdvisor URL_SUFFIX = 'apis/coachuser/' BASE_URL = 'https://www.securityadvisor.io/' CONTEXT_JSON = { "SecurityAdvisor.CoachUser": { "coaching_date": "2019-10-04T21:04:19.480425", "coaching_status": "Pending", "coaching_score": "", "user": "track@securityadvisor.io", "context": "phishing", "message": "Coaching Sent" } } RESPONSE_JSON = { "coaching_date": "2019-10-04T21:04:19.480425", "coaching_status": "Pending", "coaching_score": "", "user": "track@securityadvisor.io", "context": "phishing", "message": "Coaching Sent" } HEADERS = { 'Content-Type': 'application/json', 'Accept': 'application/json', 'Authorization': 'Token ' + 'MOCKEY' } def test_coach_end_user_command(requests_mock): """Unit test for coach-end-user command Args: requests_mock ([type]): [description] """ mock_reponse = RESPONSE_JSON requests_mock.post(BASE_URL + URL_SUFFIX, json=mock_reponse) client = SecurityAdvisor.Client( base_url=BASE_URL, verify=False, proxy=False, headers=HEADERS ) args = {"user": "track@securityadvisor.io", "context": "phishing"} _, _, result = SecurityAdvisor.coach_end_user_command(client, args) assert result == RESPONSE_JSON def test_module_command(requests_mock): """Unit test for test-module command Args: requests_mock ([type]): [description] """ mock_reponse = RESPONSE_JSON requests_mock.post(BASE_URL + URL_SUFFIX, json=mock_reponse) client = SecurityAdvisor.Client( base_url=BASE_URL, verify=False, proxy=False, headers=HEADERS ) response = SecurityAdvisor.test_module(client) assert response == "ok"