Stamus

[Get Declaration of Compromises from Stamus Security Platform and build Incidents. Then get related artifacts, events and Host Insight information].

Network Security · Stamus

Details

IDStamus
ProviderStamus Networks
CategoryNetwork Security
From Version6.9.0
Docker Imagedemisto/python3:3.12.13.10116658

README

[Get Declaration of Compromises from Stamus Security Platform and build Incidents. Then get related artifacts, events and Host Insight information]
This integration was integrated and tested with version 39.0.1 of Stamus Security Platform

Configure Stamus in Cortex

Parameter Description Required
Stamus Central Server   True
API Key The API Key to use for connection True
Trust any certificate (not secure)   False
Use system proxy settings   False
Incident type   False
Fetch incidents   False
Maximum number of incidents per fetch   False
First fetch time   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

stamus-check-ioc


[Get events with IOC key/value filter]

Base Command

stamus-check-ioc

Input

Argument Name Description Required
indicator_key [Indicator of Compromise key]. Required
indicator_value [Indicator of Compromise value]. Required

Context Output

Path Type Description
StamusIntegration.IOC String [Fetch events matching an IOC.]
StamusIntegration.IOC.timestamp String [Timestamp of the event]
StamusIntegration.IOC.src_ip String [Source IP of the event]
StamusIntegration.IOC.dest_ip String [Destination IP of the event]
StamusIntegration.IOC.event_type String [Type of the event - can be multitude, example: HTTP,SMB,DNS,Flow,TLS,KRB5,FTP etc]

stamus-get-host-insight


[Get Host Insights information]

Base Command

stamus-get-host-insight

Input

Argument Name Description Required
ip [IP to get Host Insights information]. Required

Context Output

Path Type Description
StamusIntegration.HostInsights String [Fetch information about a host known by Host Insight module]
StamusIntegration.HostInsights.ip String [Stamus Host Insights IP address]
StamusIntegration.HostInsights.host_id.client_service.first_seen String [Timestamp of first time seen]
StamusIntegration.HostInsights.host_id.client_service String [Client network service detected]
StamusIntegration.HostInsights.host_id.services.proto String [Network services protocol]
StamusIntegration.HostInsights.host_id.services.port String [Network services port]
StamusIntegration.HostInsights.host_id.services.values.first_seen String [Network services for the corresponding application protocol first time seen]
StamusIntegration.HostInsights.host_id.services.values.last_seen String [Network services for the corresponding application protocol last time seen]
StamusIntegration.HostInsights.host_id.services.values.app_proto String [Network services application layer protocol]
StamusIntegration.HostInsights.host_id.services.services_count Number [Number of network services detected on the host]
StamusIntegration.HostInsights.host_id.client_service.name String [Type of client network service detected - can be HTTP,KRB5,TLS,DCERPC,SMB etc]
StamusIntegration.HostInsights.host_id.hostname.host String [Hostname detected on the host]
StamusIntegration.HostInsights.host_id.username.user String [Username detected loggin in on the host]
StamusIntegration.HostInsights.host_id.http.user_agent.agent String [HTTP User-Agent detected being used from the host]
StamusIntegration.HostInsights.host_id.tls.ja3.hash String [TLS JA3 hash detected being used from the host]
StamusIntegration.HostInsights.host_id.tls.ja3s.hash String [TLS JA3S hash detected being used from the host]

stamus-get-doc-events


[Get events for a Declaration of Compromise using the Stamus ID]

Base Command

stamus-get-doc-events

Input

Argument Name Description Required
id [Stamus ID used to get related information]. Required

Context Output

Path Type Description
StamusIntegration.RelatedEvents String [Get events for a Declaration of Compromise.]
StamusIntegration.RelatedEvents.timestamp String [Timestamp of the Stamus event]
StamusIntegration.RelatedEvents.stamus.asset String [Stamus asset]
StamusIntegration.RelatedEvents.offender String [Offender, against the Stamus asset]
StamusIntegration.RelatedEvents.killchain String [Killchain stage]
StamusIntegration.RelatedEvents.method String [Stamus method triggered]
StamusIntegration.RelatedEvents.info String [Extra Information]
StamusIntegration.RelatedEvents.src_ip String [Source IP of the event]
StamusIntegration.RelatedEvents.dest_ip String [Destination IP of the event]
StamusIntegration.RelatedEvents.app_proto String [Application protocol of the event]

Configuration parameters

  • url — Stamus Central Server (required)
  • credentials — (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • isFetch — Fetch incidents
  • max_fetch — Maximum number of incidents per fetch
  • first_fetch — First fetch time

Commands (3)

  • stamus-check-ioc

    [Get events with IOC key/value filter].

  • stamus-get-doc-events

    [Get events for a Declaration of Compromise using the Stamus ID].

  • stamus-get-host-insight

    [Get Host Insights information].

category: Network Security
sectionorder:
- Connect
- Collect
provider: Stamus Networks
commonfields:
  id: Stamus
  version: -1
configuration:
- defaultvalue: https://example.com/
  display: Stamus Central Server
  name: url
  required: true
  type: 0
  section: Connect
- displaypassword: API Key
  additionalinfo: The API Key to use for connection
  name: credentials
  required: true
  hiddenusername: true
  type: 9
  section: Connect
- display: Trust any certificate (not secure)
  name: insecure
  required: false
  type: 8
  section: Connect
- display: Use system proxy settings
  name: proxy
  required: false
  type: 8
  section: Connect
- display: Incident type
  name: incidentType
  required: false
  type: 13
  defaultvalue: 'Stamus Networks DoC'
  section: Collect
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  section: Collect
  advanced: true
- display: Fetch incidents
  name: isFetch
  required: false
  type: 8
  section: Collect
- defaultvalue: '200'
  display: Maximum number of incidents per fetch
  name: max_fetch
  required: false
  type: 0
  section: Collect
- defaultvalue: 3 days
  display: First fetch time
  name: first_fetch
  required: false
  type: 0
  section: Collect
description: '[Get Declaration of Compromises from Stamus Security Platform and build Incidents. Then get related artifacts, events and Host Insight information].'
display: 'Stamus'
name: Stamus
script:
  commands:
  - arguments:
    - name: indicator_key
      default: false
      description: '[Indicator of Compromise key].'
      isArray: false
      required: true
      secret: false
    - name: indicator_value
      default: false
      description: '[Indicator of Compromise value].'
      isArray: false
      required: true
      secret: false
    deprecated: false
    description: '[Get events with IOC key/value filter].'
    execution: false
    name: stamus-check-ioc
    outputs:
    - contextPath: StamusIntegration.IOC
      description: '[Fetch events matching an IOC].'
      type: String
    - contextPath: StamusIntegration.IOC.timestamp
      description: '[Timestamp of the event].'
      type: String
    - contextPath: StamusIntegration.IOC.src_ip
      description: '[Source IP of the event].'
      type: String
    - contextPath: StamusIntegration.IOC.dest_ip
      description: '[Destination IP of the event].'
      type: String
    - contextPath: StamusIntegration.IOC.event_type
      description: '[Type of the event - can be multitude, example: HTTP,SMB,DNS,Flow,TLS,KRB5,FTP etc].'
      type: String
  - arguments:
    - default: false
      description: '[IP to get Host Insights information].'
      isArray: false
      name: ip
      required: true
      secret: false
    deprecated: false
    description: '[Get Host Insights information].'
    execution: false
    name: stamus-get-host-insight
    outputs:
    - contextPath: StamusIntegration.HostInsights
      description: '[Fetch information about a host known by Host Insight module].'
      type: String
    - contextPath: StamusIntegration.HostInsights.ip
      description: '[Stamus Host Insights IP address].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.client_service.first_seen
      description: '[Timestamp of first time seen].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.client_service
      description: '[Client network service detected].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.services.proto
      description: '[Network services protocol].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.services.port
      description: '[Network services port].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.services.values.first_seen
      description: '[Network services for the corresponding application protocol first time seen].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.services.values.last_seen
      description: '[Network services for the corresponding application protocol last time seen].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.services.values.app_proto
      description: '[Network services application layer protocol].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.services.services_count
      description: '[Number of network services detected on the host].'
      type: Number
    - contextPath: StamusIntegration.HostInsights.host_id.client_service.name
      description: '[Type of client network service detected - can be HTTP,KRB5,TLS,DCERPC,SMB etc].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.hostname.host
      description: '[Hostname detected on the host].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.username.user
      description: '[Username detected loggin in on the host].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.http\.user_agent.agent
      description: '[HTTP User-Agent detected being used from the host].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.tls\.ja3.hash
      description: '[TLS JA3 hash detected being used from the host].'
      type: String
    - contextPath: StamusIntegration.HostInsights.host_id.tls\.ja3s.hash
      description: '[TLS JA3S hash detected being used from the host].'
      type: String
  - arguments:
    - default: false
      description: '[Stamus ID used to get related information].'
      isArray: false
      name: id
      required: true
      secret: false
    deprecated: false
    description: '[Get events for a Declaration of Compromise using the Stamus ID].'
    execution: false
    name: stamus-get-doc-events
    outputs:
    - contextPath: StamusIntegration.RelatedEvents
      description: '[Get events for a Declaration of Compromise].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.timestamp
      description: '[Timestamp of the Stamus event].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.stamus.asset
      description: '[Stamus asset].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.offender
      description: '[Offender, against the Stamus asset].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.killchain
      description: '[Killchain stage].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.method
      description: '[Stamus method triggered].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.info
      description: '[Extra Information].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.src_ip
      description: '[Source IP of the event].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.dest_ip
      description: '[Destination IP of the event].'
      type: String
    - contextPath: StamusIntegration.RelatedEvents.app_proto
      description: '[Application protocol of the event].'
      type: String
  isfetch: true
  runonce: false
  script: '-'
  type: python
  subtype: python3
  dockerimage: demisto/python3:3.12.13.10116658
fromversion: 6.9.0
defaultmapperin: Stamus Networks incoming mapper
tests:
- No tests (auto formatted)