Symantec Email Security Cloud

Symantec Email Security.cloud is a hosted service that filters email messages and helps protect organizations from malware (including targeted attacks and phishing), spam, and unwanted bulk email. The service offers encryption and data protection options to help control sensitive information sent by email and supports multiple mailbox types from various vendors.

Email · SymantecEmailSecurity

Details

IDSymantec Email Security Cloud
ProviderBroadcom
CategoryEmail
From Version5.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Symantec Email Security.cloud is a hosted service that filters email messages and helps protect organizations from malware (including targeted attacks and phishing), spam, and unwanted bulk email. The service offers encryption and data protection options to help control sensitive information sent by email and supports multiple mailbox types from various vendors.
This integration was integrated and tested with version 10.6.6 of Symantec Email Security Cloud.

Use cases

  1. IOC Management: Manage IOCs for email threats across domains: list, add, update, delete, or renew IOCs.
  2. Data Feeds: Retrieve threat data (e.g., malware, spam, clicks) for insights into email security events.
  3. Email Queue Monitoring: View queue statistics per domain to monitor email processing and delays.
  4. Quarantine Actions: List, preview, release, or delete quarantined emails to manage potentially harmful content.
  5. Allow and Block Lists: Maintain lists for permitted or restricted senders/domains: retrieve, add/update, or delete items.
  6. Fetch Incidents: Auto-fetch incidents and quarantine-specific threats to streamline response and compliance.

Configure Symantec Email Security Cloud on Cortex XSOAR

  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for Symantec Email Security Cloud.
  3. Click Add instance to create and configure a new integration instance.

    Parameter Description Required
    Server URL - IOC    
    Server URL - Data Feeds    
    Server URL - Email Queue    
    Server URL - Quarantine The Quarantine API is available for the United States (us) and European Union (eu).  
    Username Relevant to: Server URL - IOC, Server URL - Email Queue, Server URL - Quarantine False
    Password   False
    Quarantine Username Relevant to: Server URL - Quarantine False
    Password   False
    Use system proxy settings    
    Trust any certificate (not secure)    
    Fetch incidents    
    Incident type    
    Maximum number of incidents per fetch Maximum number of incidents per fetch. Default is 50. The maximum is 200.  
    First Fetch Time    
    Fetch Type The API to fetch incidents from: Data Feeds, Quarantine or both.  
    Severity - Email Data Feed Filter the incidents by their severity. When left empty will fetch all.  
    Type - Email Data Feed    
    Include Delivery - Email Data Feed Only relevant to `all` feed. Contains metadata that describes both inbound and outbound email delivery to provide visibility into email tracing, TLS compliance, and routing.  
    Query - Email Quarantine A search criterion that can be used to filter emails that match only certain conditions based on email metadata.  
    Type - Email Quarantine A string used to filter emails based on the quarantine type.  
    Admin Domain - mail Quarantine Returns the emails quarantined for users in a particular domain. If this parameter is present and has a valid domain name, then items from only that domain are returned. If it has a value of `ALL`, then all domains administered by the user are searched and emails quarantined for users in those domains are returned. Note: Can only be used by an administrator user.  
  4. Click Test to validate the URLs, token, and connection.

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

symantec-email-security-ioc-list


List the IOCs that apply to a specific domain or to all domains.

Base Command

symantec-email-security-ioc-list

Input

Argument Name Description Required
domain Run the command for a specific domain, for all domains use ‘global’. Run symantec-email-security-email-queue-list to get a list of available domains. Default is global. Optional
limit The maximum number of records to return. Default is 50. Optional
all_results Whether to retrieve all the results by overriding the default limit. Possible values are: true, false. Optional

Context Output

Path Type Description
SymantecEmailSecurity.IOC.iocBlackListId String ID of the IOC.
SymantecEmailSecurity.IOC.iocType String Type of the IOC value.
SymantecEmailSecurity.IOC.iocValue String Value of the IOC.
SymantecEmailSecurity.IOC.status String Whether the IOC is active.
SymantecEmailSecurity.IOC.description String Description of the IOC.
SymantecEmailSecurity.IOC.emailDirection String Email direction. Can be one of: I=Inbound, O=Outbound or B=Both.
SymantecEmailSecurity.IOC.remediationAction String Remediation Action. Can be one of: B=Block and delete, Q=Quarantine, M=Redirect, T=Tag subject or H=Append header.
SymantecEmailSecurity.IOC.expiryDate String Retention period for an IOC until it is removed from the system.

Command example

Human Readable Output

IOC(s)

ID Type Value Status Description Email Direction Remediation Action Expiry Date
00000000-0000-0000-0000-000000000000 subject Test Active Test inbound quarantine 2024-01-01 00:00:00.0
00000000-0000-0000-0000-000000000000 url https://www.example.com Active url to block outbound append header 2024-01-01 00:00:00.0

symantec-email-security-ioc-action


Add, update, delete, and renew multiple IOCs through the entry_id or a single IOC through the rest of the parameters.

Base Command

symantec-email-security-ioc-action

Input

Argument Name Description Required
domain Run the command for a specific domain, for all domains use ‘global’. Run symantec-email-security-email-queue-list to get a list of available domains. Default is global. Optional
action Defines the action for IOCs: ‘merge’ to merge or update IOCs in the database by their type and value without inputting ioc_id; ‘replace’ to delete and replace all IOCs in the database without inputting upload_ioc_json; ‘ioc’ to add, update, delete, or renew multiple IOCs each with their own action, use this only when entering an entry_id; ‘add’ to add an IOC without inputting ioc_id. Possible values are: merge, replace, upload_ioc_json, add, update, delete, renew. Required
entry_id Entry ID of a JSON file to pass multiple IOCs. Only accepts action=merge/replace/ioc. Example value: [{“APIRowAction”: “U”, “IocBlacklistId”: xxxx, “IocType”: “url”, “IocValue”: “https://www.example.com”, “Description”: “Hello World!”}]. More about IOCs can be found in: https://techdocs.broadcom.com/content/dam/broadcom/techdocs/us/en/dita/symantec-security-software/email-security/email-security-cloud/content/Indicators-of-Compromise-(IOC)-Blacklist-API-Guide.pdf. Optional
ioc_id ID of the IOC. Can’t be used with action=merge\replace`add`. Optional
ioc_type Type of the IOC. Possible values are: attachmentname, md5attachment, sha2attachment, bodysenderdomain, bodysenderemail, bodysendertopleveldomain, envelopesenderdomain, envelopesenderemail, envelopesendertopleveldomain, senderipaddress, senderiprange, recipientdomain, recipientemail, subject, url. Optional
ioc_value Value of the IOC. Optional
description Description of the IOC. Optional
email_direction Email direction to filter IOCs. Possible values are: inbound, outbound, both. Optional
remediation_action Remediation action to be done on an IOC. Possible values are: block_and_delete, quarantine, redirect, tag_subject, append_header. Optional

Context Output

There is no context output for this command.

Command example

!symantec-email-security-ioc-action action=add ioc_type=subject ioc_value=Test123 description=test email_direction=inbound remediation_action=block_and_delete

Human Readable Output

All IOC(s) were uploaded successfully

symantec-email-security-ioc-renew


Renew all IOCs previously uploaded and still in the database, whether active or inactive, for a specific domain or all domains. The default retention period for IOCs is 7 days and the maximum is 30 days. After 30 days IOCs are retained in an inactive state for another 14 days. If an organization receives new email containing previously block listed IOCs, then the IOCs can renewed in the block list within this grace period. Thereafter, IOCs are removed from the system and must be uploaded again to remain in the block list.

Base Command

symantec-email-security-ioc-renew

Input

Argument Name Description Required
domain Run the command for a specific domain, for all domains use ‘global’. Run symantec-email-security-email-queue-list to get a list of available domains. Default is global. Optional

Context Output

There is no context output for this command.

Command example

Human Readable Output

Email Data Feed(s)

Message Size Subject Envelope From Envelope To Sender IP Sender Mail Server File/URLs With Risk Incidents
10000 New Email Quarantine Account bounce-newaccount-verp-00000000000000000000@eu.quarantine.symantec.com hello@world 0.0.0.0 0.0.0.0.googleusercontent.com Unknown00000000.data-None,
https://www.example.com-1
{‘Severity’: ‘LOW’, ‘Security Service’: ‘Anti-Malware’, ‘Detection Method’: ‘Skeptic Heuristics’, ‘Verdict’: ‘Malware’, ‘Action’: ‘Block’}

symantec-email-security-email-queue-list


Returns a list of domains owned by the customer, with queue statistics for each domain.

Base Command

symantec-email-security-email-queue-list

Input

Argument Name Description Required
domains Comma-separated list of domains to retrieve. Leave empty to retrieve all domains. Optional
limit The maximum number of records to return. Default is 50. Optional
all_results Whether to retrieve all the results by overriding the default limit. Possible values are: true, false. Optional

Context Output

Path Type Description
SymantecEmailSecurity.EmailQueue.TotalMessagesInbound Number Total number of inbound messages in the queue, for all domains.
SymantecEmailSecurity.EmailQueue.TotalMessagesOutbound Number Total number of outbound messages in the queue, for all domains.
SymantecEmailSecurity.EmailQueue.MeanTimeInQueueInbound Number Average (mean) queue wait for inbound messages, for all domains. Measured in seconds.
SymantecEmailSecurity.EmailQueue.MeanTimeInQueueOutbound Number Average (mean) queue wait for outbound messages, for all domains. Measured in seconds.
SymantecEmailSecurity.EmailQueue.LongestTimeInInbound Number How long the oldest message in the inbound queue has been queued, across all domains. Measured in seconds.
SymantecEmailSecurity.EmailQueue.LongestTimeInOutbound Number How long the oldest message in the outbound queue has been queued, across all domains. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.Name String Name of the domain.
SymantecEmailSecurity.EmailQueue.Domains.ReceiveQueueCountInbound Number Number of inbound messages waiting to be processed.
SymantecEmailSecurity.EmailQueue.Domains.ReceiveQueueCountOutbound Number Number of outbound messages waiting to be processed.
SymantecEmailSecurity.EmailQueue.Domains.DeliveryQueueCountInbound Number Number of inbound messages that have been processed and are waiting to be delivered.
SymantecEmailSecurity.EmailQueue.Domains.DeliveryQueueCountOutbound Number Number of outbound messages that have been processed and are waiting to be delivered.
SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInReceiveQueueInbound Number Oldest inbound message in the queue waiting to be processed. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInReceiveQueueOutbound Number Oldest outbound message in the queue waiting to be processed. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInDeliveryQueueInbound Number Oldest inbound message waiting to be delivered after processing. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInDeliveryQueueOutbound Number Oldest outbound message waiting to be delivered after processing. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInReceiveQueueInbound Number Average (mean) wait time for inbound messages waiting to be processed. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInReceiveQueueOutbound Number Average (mean) wait time for outbound messages waiting to be processed. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInDeliveryQueueInbound Number Average (mean) wait time for inbound messages waiting to be delivered after processing. Measured in seconds.
SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInDeliveryQueueOutbound Number Average (mean) wait time for outbound messages waiting to be delivered after processing. Measured in seconds.

Command example

Human Readable Output

Email Queue Statistic(s)

Totalmessagesinbound Totalmessagesoutbound Meantimeinqueueinbound Meantimeinqueueoutbound Longesttimeininbound Longesttimeinoutbound
0 0 0 0 0 0

Domain Statistic(s)

Name Receivequeuecountinbound Receivequeuecountoutbound Deliveryqueuecountinbound Deliveryqueuecountoutbound
lior.sb 0 0 0 0

symantec-email-security-quarantine-email-list


Retrieves the metadata for quarantined emails belonging to the authenticated user. If the user is an administrator, the API provides options to retrieve the metadata for emails quarantined for another user under his administration.

Base Command

symantec-email-security-quarantine-email-list

Input

Argument Name Description Required
q A search criterion that can be used to filter emails that match only certain conditions based on email metadata. The search syntax is built by a field name and search value enclosed by parenthesis and the operators: ‘OR’, ‘AND’ to combine multiple search criteria’s or values, example: (email_subject:test). Acceptable field names are: ‘dlp_message_id’, ‘email_envelope_sender’, ‘email_envelope_sender.raw’, ‘email_sender’, ‘email_envelope_recipient’, ‘email_envelope_recipient.raw’, ‘email_subject’, ‘email_subject.raw’. See the section called “Search String Syntax” on page 16 in: https://techdocs.broadcom.com/content/dam/broadcom/techdocs/us/en/dita/symantec-security-software/email-security/email-security-cloud/content/EmailQuarantineAPIGuide.pdf. Optional
sort_column Specifies the column to use for sorting. Defaults to email_date_received. Optional
sort_order Specifies the order in which to sort. Possible values are: desc, asc. Default is desc. Optional
after A time stamp value used to select only SUDULS items that were created after this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Optional
before A time stamp value used to select only SUDULS items that were created before this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Optional
filter_type A string used to filter emails based on the quarantine type. By default includes the emails quarantined for all types. COMPLIANCE: Includes Content control, DLP and Image control emails. DLP: Includes only DLP emails. Possible values are: SPAM, NEWSLETTER, CI, CO, II, IO, COMPLIANCE, DLP. Optional
include_deleted Specifies whether to include items marked as deleted in the search results. Possible values are: true, false. Optional
user_email Return only the quarantined emails of the user whose email address is specified. Note: Can only be used by an administrator user. Optional
admin_domain Returns the emails quarantined for users in a particular domain. If this parameter is present and has a valid domain name, then items from only that domain are returned. If it has a value of ALL, then all domains administered by the user are searched and emails quarantined for users in those domains are returned. Note: Can only be used by an administrator user. Optional
limit The maximum number of records to return. Default is 50. Optional
page The page number to retrieve records from. Optional
page_size The maximum number of records to return per page. Default is 50. Max is 10,000. Optional

Context Output

Path Type Description
SymantecEmailSecurity.QuarantineEmail.id String ID of the item.
SymantecEmailSecurity.QuarantineEmail.metadata.email_date_received Date Date the email was received.
SymantecEmailSecurity.QuarantineEmail.metadata.quarantine_info.direction String Direction of the email.
SymantecEmailSecurity.QuarantineEmail.metadata.quarantine_info.quarantine_type String Quarantine type of the email, can be one of: SPAM, NEWSLETTER, CI, CO, II, IO, COMPLIANCE, DLP.
SymantecEmailSecurity.QuarantineEmail.metadata.email_is_viewed Bool Whether the email was viewed.
SymantecEmailSecurity.QuarantineEmail.metadata.email_is_released Bool Whether the email was released.
SymantecEmailSecurity.QuarantineEmail.metadata.quarantine_reason String Reason why the email was quarantined.
SymantecEmailSecurity.QuarantineEmail.metadata.email_sender String Sender of the email.
SymantecEmailSecurity.QuarantineEmail.metadata.service_type String Service type used for the email.
SymantecEmailSecurity.QuarantineEmail.metadata.master_recipient String Recipient of the email.
SymantecEmailSecurity.QuarantineEmail.metadata.user_id Number ID of the user.
SymantecEmailSecurity.QuarantineEmail.metadata.email_envelope_sender String Address to respond to in case of bounce messages or errors.
SymantecEmailSecurity.QuarantineEmail.metadata.email_subject String Subject of the email.
SymantecEmailSecurity.QuarantineEmail.metadata.email_size Number Size of the email.
SymantecEmailSecurity.QuarantineEmail.metadata.email_envelope_recipient String The RCPT TO address.
SymantecEmailSecurity.QuarantineEmail.actions.view_subject Bool Whether the subject can be viewed.
SymantecEmailSecurity.QuarantineEmail.actions.delete_message Bool Whether the email can be deleted.
SymantecEmailSecurity.QuarantineEmail.actions.preview_message Bool Whether the email can be previewed.
SymantecEmailSecurity.QuarantineEmail.actions.release_message Bool Whether the email can be released.

Command example

Human Readable Output

Quarantine Email(s)

ID Date Received Direction Quarantine Type Is Released Quarantine Reason Sender Master Recipient Subject
000 2024-10-06 09:20:41.148000+00:00 inbound CI true CC Example (example@example.com) example@example.com a
001 2024-10-06 13:37:51.295000+00:00 inbound CI false CC Example (example@example.com) example@example.com a
002 2024-10-06 13:37:55.373000+00:00 inbound CI false CC Example (example@example.com) example@example.com a
003 2024-10-06 13:38:00.677000+00:00 inbound CI true CC Example (example@example.com) example@example.com a
004 2024-10-06 13:40:11.087000+00:00 inbound CI false CC Example (example@example.com) example@example.com a

symantec-email-security-quarantine-email-preview


Retrieves the contents of the email specified in the request. To preview an email the compliance policy must allow it.

Base Command

symantec-email-security-quarantine-email-preview

Input

Argument Name Description Required
message_id The message ID of the email to preview. Run symantec-email-security-email-queue-list to get a list of message IDs. Required

Context Output

Path Type Description
SymantecEmailSecurity.QuarantineEmailPreview.message_id String ID of the message.
SymantecEmailSecurity.QuarantineEmailPreview.headers.authentication-results String Authentication status of the email.
SymantecEmailSecurity.QuarantineEmailPreview.headers.content-type String The MIME type of the email content, defining how the content is structured.
SymantecEmailSecurity.QuarantineEmailPreview.headers.date Date The date and time when the email was sent.
SymantecEmailSecurity.QuarantineEmailPreview.headers.dkim-signature String The DKIM signature used to verify the authenticity of the email.
SymantecEmailSecurity.QuarantineEmailPreview.headers.feedback-id String A unique identifier used for tracking feedback and reporting issues related to the email.
SymantecEmailSecurity.QuarantineEmailPreview.headers.from String The sender’s email address and name.
SymantecEmailSecurity.QuarantineEmailPreview.headers.mailfrom String The envelope sender email address.
SymantecEmailSecurity.QuarantineEmailPreview.headers.message-id String Unique identifier for the email message.
SymantecEmailSecurity.QuarantineEmailPreview.headers.mime-version String The MIME version used for the email.
SymantecEmailSecurity.QuarantineEmailPreview.headers.received String Information about the servers the email passed through.
SymantecEmailSecurity.QuarantineEmailPreview.headers.reply-to String The email address where replies to the message should be sent.
SymantecEmailSecurity.QuarantineEmailPreview.headers.subject String The subject line of the email.
SymantecEmailSecurity.QuarantineEmailPreview.headers.to String The recipient’s email address.
SymantecEmailSecurity.QuarantineEmailPreview.headers.x-brightmail-tracker String Tracking data for Brightmail filtering.
SymantecEmailSecurity.QuarantineEmailPreview.headers.x-originating-ip String IP address of the original sender.
SymantecEmailSecurity.QuarantineEmailPreview.attachments.name String The name of the file attached to the email.
SymantecEmailSecurity.QuarantineEmailPreview.attachments.type String The type of the file attached to the email.
SymantecEmailSecurity.QuarantineEmailPreview.bodypart.type String The type of the email’s body part.
SymantecEmailSecurity.QuarantineEmailPreview.bodypart.content String The content of the email’s body part.

Command example

!symantec-email-security-quarantine-email-preview message_id=000

Context Example

{
    "SymantecEmailSecurity": {
        "QuarantineEmailPreview": {
            "attachments": [
                {
                    "name": "hello",
                    "type": "world"
                }
            ],
            "bodypart": [
                {
                    "content": "xxx",
                    "type": "text/plain; charset=\"UTF-8\""
                },
                {
                    "content": "xxx",
                    "type": "text/html; charset=\"UTF-8\""
                }
            ],
            "headers": {
                "authentication-results": "xxx",
                "content-type": "multipart/alternative;",
                "date": "Wed, 02 Oct 2024 04:37:01 +0000",
                "dkim-signature": "v=1; a=rsa-sha256;",
                "feedback-id": "xxx",
                "from": "xxx",
                "mailfrom": "example@example.com",
                "message-id": "123",
                "mime-version": "1.0",
                "received": "xxx",
                "reply-to": "xxx",
                "subject": "xxx",
                "to": "xxx",
                "x-atlassian-mail-message-id": "xxx",
                "x-atlassian-mail-transaction-id": "xxx",
                "x-brightmail-tracker": "xxx",
                "x-msfbl": "xxx",
                "x-originating-ip": "[0.0.0.0]",
                "x-spamquarantineinfo": "spam detected heuristically",
                "x-spamquarantinereason": "Yes, hits=1.2 required=7.0 tests=newsletters: ,  newsletters: Newsletter detected: 5.12 >"
            },
            "message_id": "000"
        }
    }
}

Human Readable Output

Quarantine Email Preview

Date From To Subject
Wed, 02 Oct 2024 04:37:01 +0000 xxx xxx xxx

Attachments

Name Type
hello world

Body Parts

Content
xxx
xxx

symantec-email-security-quarantine-email-release


Releases the set of quarantined emails specified in the request.

Base Command

symantec-email-security-quarantine-email-release

Input

Argument Name Description Required
message_ids Comma-separated list of emails message IDs to release. Run symantec-email-security-quarantine-email-list to get a list of message IDs. Required
recipient An email address to which the mails have to be released instead of the recipient user’s address. Optional
headers Comma-separated list of x-headers that will be added to the message on release. Optional
encrypt If true adds an ‘x-encrypted-quarantine-release: true’ to the released email. Customers have to configure a corresponding DP rule that triggers encryption. Possible values are: true, false. Optional

Context Output

There is no context output for this command.

Command example

!symantec-email-security-quarantine-email-release message_ids=000

Human Readable Output

Successfully released all messages

symantec-email-security-quarantine-email-delete


Deletes the set of quarantined emails specified in the request. The items are marked as deleted in the backend data store, but are not physically deleted.

Base Command

symantec-email-security-quarantine-email-delete

Input

Argument Name Description Required
message_ids Comma-separated list of quarantined emails message IDs to delete. Run symantec-email-security-quarantine-email-list to get a list of message IDs. Required

Context Output

There is no context output for this command.

Command example

!symantec-email-security-quarantine-email-delete message_ids=000

Human Readable Output

Successfully deleted all messages

symantec-email-security-item-allow-list


Retrieve the allow list items.

Base Command

symantec-email-security-item-allow-list

Input

Argument Name Description Required
q A string that at least some part of the allow list item must contain. Optional
sort_column Specifies the column to use for sorting. Possible values are: date, type, description. Default is date. Optional
sort_order Specifies the order in which to sort. Possible values are: desc, asc. Default is desc. Optional
after A time stamp value used to select only SUDULS items that were created after this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Optional
before A time stamp value used to select only SUDULS items that were created before this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Optional
limit The maximum number of records to return. Default is 50. Optional
page The page number to retrieve records from. Optional
page_size The maximum number of records to return per page. Default is 50. Optional

Context Output

Path Type Description
SymantecEmailSecurity.AllowList.id String ID of the item.
SymantecEmailSecurity.AllowList.value String An email address or a domain name.
SymantecEmailSecurity.AllowList.description String Description of the item.
SymantecEmailSecurity.AllowList.type String Email or domain.
SymantecEmailSecurity.AllowList.date_created Date Date at which the item was created.
SymantecEmailSecurity.AllowList.date_amended Date Date at which the item was amended.

Command example

Human Readable Output

Allow List Item(s)

Description
Test
url to block

symantec-email-security-item-allow-list-update


Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to add or update an item to the allow list.

Base Command

symantec-email-security-item-allow-list-update

Input

Argument Name Description Required
suduls_user Email address of the user for whom the entry should be added in the allow list. Required
item_id ID of SUDULS item to be added/updated. Only required when updating an existing item. Run symantec-email-security-item-allow-list to get a list of items. Optional
email_or_domain Email address or domain to be added in the allow list. Required
description Description of the item to be added to the allow list. Required

Context Output

There is no context output for this command.

Command example

!symantec-email-security-item-allow-list-update suduls_user=lior description=sb email_or_domain=lior.sb item_id=000

Human Readable Output

The items were successfully merged

symantec-email-security-item-allow-list-delete


Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to delete an item from the allow list.

Base Command

symantec-email-security-item-allow-list-delete

Input

Argument Name Description Required
item_id ID of SUDULS item to be deleted. Run symantec-email-security-item-allow-list to get a list of items. Required

Context Output

There is no context output for this command.

Command example

!symantec-email-security-item-allow-list-delete item_id=000

Human Readable Output

The items were successfully deleted

symantec-email-security-item-block-list


Retrieve the block list items.

Base Command

symantec-email-security-item-block-list

Input

Argument Name Description Required
q A string that at least some part of the block list item must contain. Optional
sort_column Specifies the column to use for sorting. Default is date. Optional
sort_order Specifies the order in which to sort. Default is desc. Optional
after A time stamp value used to select only SUDULS items that were created after this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Optional
before A time stamp value used to select only SUDULS items that were created before this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Optional
limit The maximum number of records to return. Default is 50. Optional
page The page number to retrieve records from. Optional
page_size The maximum number of records to return per page. Default is 50. Optional

Context Output

Path Type Description
SymantecEmailSecurity.BlockList.id String ID of the item.
SymantecEmailSecurity.BlockList.value String An email address or a domain name.
SymantecEmailSecurity.BlockList.description String Description of the item.
SymantecEmailSecurity.BlockList.type String Email or domain.
SymantecEmailSecurity.BlockList.date_created Date Date at which the item was created.
SymantecEmailSecurity.BlockList.date_amended Date Date at which the item was amended.

Command example

Human Readable Output

Block List Item(s)

Description
Test
url to block

symantec-email-security-item-block-list-update


Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to add or update an item to the block list.

Base Command

symantec-email-security-item-block-list-update

Input

Argument Name Description Required
suduls_user Email address of the user for whom the entry should be added in the block list. Required
item_id ID of SUDULS item to be added/updated. Only required when updating an existing item. Run symantec-email-security-item-block-list to get a list of items. Optional
email_or_domain Email address or domain to be added to the block list. Required
description Description of the item to be added to the block list. Required

Context Output

There is no context output for this command.

Command example

!symantec-email-security-item-block-list-update suduls_user=lior description=sb email_or_domain=lior.sb item_id=000

Human Readable Output

The items were successfully merged

symantec-email-security-item-block-list-delete


Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to delete an item from the block list.

Base Command

symantec-email-security-item-block-list-delete

Input

Argument Name Description Required
item_id ID of SUDULS item to be deleted. Run symantec-email-security-item-block-list to get a list of items. Required

Context Output

There is no context output for this command.

Command example

!symantec-email-security-item-block-list-delete item_id=000

Human Readable Output

The items were successfully deleted

Configuration parameters

  • url_ioc — Server URL - IOC
  • url_data_feeds — Server URL - Data Feeds
  • url_email_queue — Server URL - Email Queue
  • url_quarantine — Server URL - Quarantine
  • credentials — Username
  • quarantine_credentials — Quarantine Username
  • proxy — Use system proxy settings
  • insecure — Trust any certificate (not secure)
  • isFetch — Fetch incidents
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • max_fetch — Maximum number of incidents per fetch
  • first_fetch — First Fetch Time
  • fetch_type — Fetch Type
  • severity — Severity - Email Data Feed
  • type — Type - Email Data Feed
  • include_delivery — Include Delivery - Email Data Feed
  • query_quarantine — Query - Email Quarantine
  • type_quarantine — Type - Email Quarantine
  • admin_domain_quarantine — Admin Domain - mail Quarantine

Commands (15)

  • symantec-email-security-data-list

    Retrieves data feeds from Symantec Email Security.cloud. Available feeds: 'all' (metadata for all scanned email), 'malware' (malware-containing email data), 'threat-isolation' (events from URL and Attachment Isolation), 'clicktime' (metadata from end-user clicks on rewritten URLs), 'anti-spam' (spam detection metadata), and 'ec-reports' (contextual information about emails blocked by Anti-Malware service).

  • symantec-email-security-email-queue-list

    Returns a list of domains owned by the customer, with queue statistics for each domain.

  • symantec-email-security-ioc-action

    Add, update, delete, and renew multiple IOCs through the `entry_id` or a single IOC through the rest of the parameters.

  • symantec-email-security-ioc-list

    List the IOCs that apply to a specific domain or to all domains.

  • symantec-email-security-ioc-renew

    Renew all IOCs previously uploaded and still in the database, whether active or inactive, for a specific domain or all domains. The default retention period for IOCs is 7 days and the maximum is 30 days. After 30 days IOCs are retained in an inactive state for another 14 days. If an organization receives new email containing previously block listed IOCs, then the IOCs can renewed in the block list within this grace period. Thereafter, IOCs are removed from the system and must be uploaded again to remain in the block list.

  • symantec-email-security-item-allow-list

    Retrieve the allow list items.

  • symantec-email-security-item-allow-list-delete

    Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to delete an item from the allow list.

  • symantec-email-security-item-allow-list-update

    Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to add or update an item to the allow list.

  • symantec-email-security-item-block-list

    Retrieve the block list items.

  • symantec-email-security-item-block-list-delete

    Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to delete an item from the block list.

  • symantec-email-security-item-block-list-update

    Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to add or update an item to the block list.

  • symantec-email-security-quarantine-email-delete

    Deletes the set of quarantined emails specified in the request. The items are marked as deleted in the backend data store, but are not physically deleted.

  • symantec-email-security-quarantine-email-list

    Retrieves the metadata for quarantined emails belonging to the authenticated user. If the user is an administrator, the API provides options to retrieve the metadata for emails quarantined for another user under his administration.

  • symantec-email-security-quarantine-email-preview

    Retrieves the contents of the email specified in the request. To preview an email the compliance policy must allow it.

  • symantec-email-security-quarantine-email-release

    Releases the set of quarantined emails specified in the request.

category: Email
provider: Broadcom
sectionorder:
- Connect
- Collect
commonfields:
  id: Symantec Email Security Cloud
  version: -1
configuration:
- name: url_ioc
  display: Server URL - IOC
  type: 0
  defaultvalue: "https://iocapi.emailsecurity.symantec.com"
  section: Connect
- name: url_data_feeds
  display: Server URL - Data Feeds
  type: 0
  defaultvalue: "https://datafeeds.emailsecurity.symantec.com"
  section: Connect
- name: url_email_queue
  display: Server URL - Email Queue
  type: 0
  defaultvalue: "https://emailqueue.emailsecurity.symantec.com"
  section: Connect
- name: url_quarantine
  display: Server URL - Quarantine
  additionalinfo: The Quarantine API is available for the United States (us) and European Union (eu).
  type: 0
  defaultvalue: "https://api.eu.quarantine.symantec.com"
  section: Connect
- name: credentials
  display: Username
  additionalinfo: 'Relevant to: Server URL - IOC, Server URL - Email Queue, Server URL - Quarantine'
  type: 9
  required: false
  section: Connect
- name: quarantine_credentials
  display: Quarantine Username
  additionalinfo: 'Relevant to: Server URL - Quarantine'
  type: 9
  required: false
  section: Connect
- name: proxy
  display: Use system proxy settings
  type: 8
  section: Connect
- name: insecure
  display: Trust any certificate (not secure)
  type: 8
  section: Connect
- name: isFetch
  display: Fetch incidents
  type: 8
  section: Collect
- name: incidentType
  display: Incident type
  type: 13
  section: Collect
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  section: Collect
  advanced: true
- name: max_fetch
  display: Maximum number of incidents per fetch
  additionalinfo: Maximum number of incidents per fetch. Default is 50. The maximum is 200.
  type: 0
  section: Collect
  defaultvalue: 50
- name: first_fetch
  display: First Fetch Time
  type: 0
  section: Collect
  defaultvalue: 3 days
- name: fetch_type
  display: Fetch Type
  additionalinfo: 'The API to fetch incidents from: Data Feeds, Quarantine or both.'
  type: 15
  defaultvalue: both
  section: Collect
  options:
  - both
  - email_data_feed
  - email_quarantine
- name: severity
  display: Severity - Email Data Feed
  additionalinfo: Filter the incidents by their severity. When left empty will fetch all.
  type: 16
  section: Collect
  options:
  - unknown
  - low
  - medium
  - high
  - critical
- name: type
  display: Type - Email Data Feed
  type: 15
  section: Collect
  defaultvalue: all
  options:
  - all
  - malware
  - threat-isolation
  - clicktime
  - anti-spam
  - ec-reports
- name: include_delivery
  display: Include Delivery - Email Data Feed
  additionalinfo: Only relevant to `all` feed. Contains metadata that describes both inbound and outbound email delivery to provide visibility into email tracing, TLS compliance, and routing.
  type: 8
  section: Collect
- name: query_quarantine
  display: Query - Email Quarantine
  additionalinfo: A search criterion that can be used to filter emails that match only certain conditions based on email metadata.
  type: 0
  section: Collect
- name: type_quarantine
  display: Type - Email Quarantine
  additionalinfo: A string used to filter emails based on the quarantine type.
  type: 15
  section: Collect
  options:
  - SPAM
  - NEWSLETTER
  - CI
  - CO
  - II
  - IO
  - COMPLIANCE
  - DLP
- name: admin_domain_quarantine
  display: Admin Domain - mail Quarantine
  additionalinfo: 'Returns the emails quarantined for users in a particular domain. If this parameter is present and has a valid domain name, then items from only that domain are returned. If it has a value of `ALL`, then all domains administered by the user are searched and emails quarantined for users in those domains are returned. Note: Can only be used by an administrator user.'
  type: 0
  section: Collect
description: Symantec Email Security.cloud is a hosted service that filters email messages and helps protect organizations from malware (including targeted attacks and phishing), spam, and unwanted bulk email. The service offers encryption and data protection options to help control sensitive information sent by email and supports multiple mailbox types from various vendors.
display: Symantec Email Security Cloud
name: Symantec Email Security Cloud
script:
  commands:
  - name: symantec-email-security-ioc-list
    description: List the IOCs that apply to a specific domain or to all domains.
    arguments:
    - name: domain
      description: Run the command for a specific domain, for all domains use 'global'. Run `symantec-email-security-email-queue-list` to get a list of available domains.
      defaultValue: global
      default: true
    - name: limit
      description: The maximum number of records to return.
      defaultValue: '50'
    - name: all_results
      description: Whether to retrieve all the results by overriding the default limit.
      auto: PREDEFINED
      predefined:
      - 'true'
      - 'false'
    outputs:
    - contextPath: SymantecEmailSecurity.IOC.iocBlackListId
      description: ID of the IOC.
      type: String
    - contextPath: SymantecEmailSecurity.IOC.iocType
      description: Type of the IOC value.
      type: String
    - contextPath: SymantecEmailSecurity.IOC.iocValue
      description: Value of the IOC.
      type: String
    - contextPath: SymantecEmailSecurity.IOC.status
      description: Whether the IOC is active.
      type: String
    - contextPath: SymantecEmailSecurity.IOC.description
      description: Description of the IOC.
      type: String
    - contextPath: SymantecEmailSecurity.IOC.emailDirection
      description: 'Email direction. Can be one of: I=Inbound, O=Outbound or B=Both.'
      type: String
    - contextPath: SymantecEmailSecurity.IOC.remediationAction
      description: 'Remediation Action. Can be one of: B=Block and delete, Q=Quarantine, M=Redirect, T=Tag subject or H=Append header.'
      type: String
    - contextPath: SymantecEmailSecurity.IOC.expiryDate
      description: Retention period for an IOC until it is removed from the system.
      type: String
  - name: symantec-email-security-ioc-action
    description: Add, update, delete, and renew multiple IOCs through the `entry_id` or a single IOC through the rest of the parameters.
    arguments:
    - name: domain
      description: Run the command for a specific domain, for all domains use 'global'. Run `symantec-email-security-email-queue-list` to get a list of available domains.
      defaultValue: global
    - name: action
      description: 'Defines the action for IOCs: ''merge'' to merge or update IOCs in the database by their type and value without inputting `ioc_id`; ''replace'' to delete and replace all IOCs in the database without inputting `upload_ioc_json`; ''ioc'' to add, update, delete, or renew multiple IOCs each with their own action, use this only when entering an `entry_id`; ''add'' to add an IOC without inputting `ioc_id`.'
      auto: PREDEFINED
      predefined:
      - merge
      - replace
      - upload_ioc_json
      - add
      - update
      - delete
      - renew
      required: true
      default: true
    - name: entry_id
      description: 'Entry ID of a JSON file to pass multiple IOCs. Only accepts `action=merge/replace/ioc`. Example value: [{"APIRowAction": "U", "IocBlacklistId": xxxx, "IocType": "url", "IocValue": "https://www.example.com", "Description": "Hello World!"}]. More about IOCs can be found in: https://techdocs.broadcom.com/content/dam/broadcom/techdocs/us/en/dita/symantec-security-software/email-security/email-security-cloud/content/Indicators-of-Compromise-(IOC)-Blacklist-API-Guide.pdf'
    - name: ioc_id
      description: ID of the IOC. Can't be used with action=`merge`\replace\`add`.
    - name: ioc_type
      description: Type of the IOC.
      auto: PREDEFINED
      predefined:
      - attachmentname
      - md5attachment
      - sha2attachment
      - bodysenderdomain
      - bodysenderemail
      - bodysendertopleveldomain
      - envelopesenderdomain
      - envelopesenderemail
      - envelopesendertopleveldomain
      - senderipaddress
      - senderiprange
      - recipientdomain
      - recipientemail
      - subject
      - url
    - name: ioc_value
      description: Value of the IOC.
    - name: description
      description: Description of the IOC.
    - name: email_direction
      description: Email direction to filter IOCs.
      auto: PREDEFINED
      predefined:
      - inbound
      - outbound
      - both
    - name: remediation_action
      description: Remediation action to be done on an IOC.
      auto: PREDEFINED
      predefined:
      - block_and_delete
      - quarantine
      - redirect
      - tag_subject
      - append_header
  - name: symantec-email-security-ioc-renew
    description: Renew all IOCs previously uploaded and still in the database, whether active or inactive, for a specific domain or all domains. The default retention period for IOCs is 7 days and the maximum is 30 days. After 30 days IOCs are retained in an inactive state for another 14 days. If an organization receives new email containing previously block listed IOCs, then the IOCs can renewed in the block list within this grace period. Thereafter, IOCs are removed from the system and must be uploaded again to remain in the block list.
    arguments:
    - name: domain
      description: Run the command for a specific domain, for all domains use 'global'. Run `symantec-email-security-email-queue-list` to get a list of available domains.
      defaultValue: global
      default: true
  - name: symantec-email-security-data-list
    description: 'Retrieves data feeds from Symantec Email Security.cloud. Available feeds: ''all'' (metadata for all scanned email), ''malware'' (malware-containing email data), ''threat-isolation'' (events from URL and Attachment Isolation), ''clicktime'' (metadata from end-user clicks on rewritten URLs), ''anti-spam'' (spam detection metadata), and ''ec-reports'' (contextual information about emails blocked by Anti-Malware service).'
    arguments:
    - name: feed_type
      description: The type of the email data feed to retrieve.
      defaultValue: all
      auto: PREDEFINED
      predefined:
      - all
      - malware
      - threat-isolation
      - clicktime
      - anti-spam
      - ec-reports
      default: true
    - name: start_from
      description: 'Start time for reading metadata. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute. Max start time is 1095 days before current date.'
      defaultValue: 3 days
    - name: include_delivery
      description: Only relevant to `all` feed. Contains metadata that describes both inbound and outbound email delivery to provide visibility into email tracing, TLS compliance, and routing.
      auto: PREDEFINED
      predefined:
      - 'false'
      - 'true'
    - name: fetch_only_incidents
      description: Whether to fetch only incident fields.
      auto: PREDEFINED
      predefined:
      - 'true'
      - 'false'
    - name: limit
      description: The maximum number of records to return.
      defaultValue: '50'
    - name: all_results
      description: Whether to retrieve all the results by overriding the default limit.
      auto: PREDEFINED
      predefined:
      - 'true'
      - 'false'
    outputs:
    - contextPath: SymantecEmailSecurity.Data.emailInfo.xMsgRef
      description: Unique message reference identifier.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.longMsgRef
      description: Detailed message reference path.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.messageId
      description: Email's unique message identifier.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.isOutbound
      description: Indicates if the email is outbound.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.messageSize
      description: Size of the email message in bytes.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.mailProcessingStartTime
      description: Start time of email processing.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.subject
      description: Subject line of the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.envFrom
      description: Envelope sender of the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.envTo
      description: Envelope receiver of the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.headerFrom
      description: Header sender of the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.rawHeaderFrom
      description: Raw header sender information.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.headerReplyTo
      description: Reply-to address in email header.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.senderIp
      description: IP address of the email sender.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.senderMailserver
      description: Mail server of the email sender.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.country
      description: Country of the email sender.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.HELOString
      description: HELO string from the mail server.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.avQuarantinePenId
      description: Quarantine pen ID for antivirus.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults
      description: Authentication results of the email.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.nodeType
      description: Type of node for files and links.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.fileNameOrURL
      description: File name or URL in the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.fileSize
      description: Size of the file in the email.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.fileType
      description: Type of the file in the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.md5
      description: MD5 hash of the file.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.sha256
      description: SHA-256 hash of the file.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.urlCategories
      description: Categories of URLs in the email.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.urlRiskScore
      description: Risk score of URLs in the email.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.index
      description: Index of the file/link in email.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.parentIndex
      description: Parent index of the file/link in email.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.filesAndLinks.linkSource
      description: Source of the link in the email.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsAdvertised
      description: Indicates if TLS was advertised.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsUsed
      description: Indicates if TLS was used.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsPolicy
      description: Policy for using TLS.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsProtocol
      description: Protocol used for TLS.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsCipher
      description: Cipher used for TLS.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsKeyLength
      description: Key length used for TLS.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsFallbackReason
      description: Reason for TLS fallback.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsForwardSecrecy
      description: Indicates if forward secrecy was used.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.tlsInfo.tlsNegotiationFailed
      description: Indicates if TLS negotiation failed.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.emailInfo.newDomainAge
      description: Age of the new domain.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.emailInfo.timeInCynicSandboxMs
      description: Time spent in Cynic sandbox in ms.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.incidents
      description: Associated incidents.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.clicktimeInfo.xMsgRef
      description: Unique click message reference.
      type: String
    - contextPath: SymantecEmailSecurity.Data.clicktimeInfo.squrlClickerIp
      description: IP address of the URL clicker.
      type: String
    - contextPath: SymantecEmailSecurity.Data.clicktimeInfo.squrlRecipient
      description: Recipient of the clicked URL.
      type: String
    - contextPath: SymantecEmailSecurity.Data.clicktimeInfo.url
      description: Clicked URL.
      type: String
    - contextPath: SymantecEmailSecurity.Data.clicktimeInfo.dateUrlAccess
      description: Timestamp of URL access.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.clicktimeInfo.risk
      description: Risk level of the URL.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.incident
      description: Associated incident details.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.timestamp
      description: Timestamp of the event.
      type: Date
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.event
      description: Type of event logged.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.source_ip
      description: Source IP address of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.url
      description: URL involved in the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.referer_url
      description: Referer URL of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.request_method
      description: HTTP request method used.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.user_agent
      description: User agent string of the request.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.destination_ip
      description: Destination IP address of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.action
      description: Action taken for the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.action_reason
      description: Reason for the action taken.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.text
      description: Text description of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.rule_id
      description: ID of the rule applied.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.rule_name
      description: Name of the rule applied.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.service
      description: Service involved in the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.mime_type
      description: MIME type of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.password_supplied
      description: Indicates if a password was supplied.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.file_type
      description: Type of file involved.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.content_type
      description: Content type of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.host
      description: Host involved in the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.geoip_country_name
      description: Country name from GeoIP lookup.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.top_level_url
      description: Top-level URL involved.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.response_status_code
      description: HTTP response status code.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.resource_type
      description: Type of resource involved.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.total_bytes
      description: Total bytes transferred.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.total_bytes_sent
      description: Total bytes sent.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.md5
      description: MD5 hash of the content.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.sha256
      description: SHA-256 hash of the content.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.file_path
      description: File path of the content.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.file_name
      description: File name of the content.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.details
      description: Details of the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.url_risk
      description: Risk score of the URL.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.tenant_id
      description: Tenant ID associated with the event.
      type: String
    - contextPath: SymantecEmailSecurity.Data.fireglass_log.xMsgRef
      description: Unique Fireglass message reference.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.raw_header
      description: Raw authentication results header.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.dkim
      description: DKIM verification result.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.dkim_signing_domain
      description: Domain used for DKIM signing.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.spf
      description: SPF verification result.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.dmarc
      description: DMARC verification result.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.dmarc_policy
      description: DMARC policy applied.
      type: String
    - contextPath: SymantecEmailSecurity.Data.emailInfo.authResults.dmarc_override_action
      description: Action overridden by DMARC policy.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.xMsgRef
      description: Unique incident message reference.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.addressContexts.name
      description: Name in incident address context.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.addressContexts.domain
      description: Domain in incident address context.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.addressContexts.isSender
      description: Indicates if address is sender.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.incidents.severity
      description: Severity level of the incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.securityService
      description: Security service involved.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.detectionMethod
      description: Method used for detection.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.verdict
      description: Verdict of the incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.action
      description: Action taken for the incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.reason
      description: Reason for the action.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.nodeType
      description: Type of node in incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.fileNameOrURL
      description: File name or URL in incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.fileSize
      description: Size of the file in incident.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.fileType
      description: Type of file in incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.md5
      description: MD5 hash of the file.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.sha256
      description: SHA-256 hash of the file.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.malwareName
      description: Name of the detected malware.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.malwareCategory
      description: Category of the detected malware.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.urlCategories
      description: Categories of URLs in the incident.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.urlRiskScore
      description: Risk score of URLs in the incident.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.index
      description: Index of the file/link in incident.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.parentIndex
      description: Parent index of the file/link in incident.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.xMsgRef
      description: Unique incident file message reference.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.filesAndLinks.linkSource
      description: Source of the link in incident.
      type: String
    - contextPath: SymantecEmailSecurity.Data.incidents.dmasDelivered
      description: Indicates if DMAS was delivered.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.incidents.dmasInfo
      description: DMAS information related to the incident.
      type: Unknown
    - contextPath: SymantecEmailSecurity.Data.attacks.affectedUsers.key
      description: Affected user email address.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.affectedUsers.value
      description: Number of affected users.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.affectedUsers.type
      description: Type of affected users.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.affectedUsersByDomain.key
      description: Domain of affected users.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.affectedUsersByDomain.value
      description: Number of affected users by domain.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.affectedUsersByDomain.type
      description: Type of affected users by domain.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.geoIpSources.key
      description: GeoIP source country code.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.geoIpSources.value
      description: Percentage of attacks from GeoIP source.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.geoIpSources.type
      description: Type of GeoIP source data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.globalTimeline.key
      description: Date in global attack timeline.
      type: Date
    - contextPath: SymantecEmailSecurity.Data.attacks.globalTimeline.value
      description: Number of global attacks on date.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.globalTimeline.type
      description: Type of global timeline data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.ipSources.key
      description: IP address of attack source.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.ipSources.value
      description: Percentage of attacks from IP source.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.ipSources.type
      description: Type of IP source data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.localTimeline.key
      description: Date in local attack timeline.
      type: Date
    - contextPath: SymantecEmailSecurity.Data.attacks.localTimeline.value
      description: Number of local attacks on date.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.localTimeline.type
      description: Type of local timeline data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.threatNames.key
      description: Name of the detected threat.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.threatNames.value
      description: Percentage of attacks with this threat.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.threatNames.type
      description: Type of threat data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.traitImportance.ioc
      description: Indicator of compromise.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.traitImportance.value
      description: Value of the trait.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.traitImportance.weight
      description: Weight of the trait.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.traitImportance.type
      description: Type of trait data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.avgMailboxesGlobal
      description: Average global mailboxes affected.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.attackVolumeGlobal
      description: Global volume of attacks.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.attackVolumeLocal
      description: Local volume of attacks.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.attackedMailboxesGlobal
      description: Number of globally attacked mailboxes.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.attackedMailboxesLocal
      description: Number of locally attacked mailboxes.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.attackedOrgsGlobal
      description: Number of globally attacked organizations.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.attacks.attackDescription
      description: Description of the attack.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.attackType
      description: Type of attack.
      type: String
    - contextPath: SymantecEmailSecurity.Data.attacks.cluster
      description: Cluster identifier for the attack.
      type: String
    - contextPath: SymantecEmailSecurity.Data.topAttacked.key
      description: Email address of top attacked user.
      type: String
    - contextPath: SymantecEmailSecurity.Data.topAttacked.value
      description: Number of attacks on top user.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.topAttacked.type
      description: Type of attack count data.
      type: String
    - contextPath: SymantecEmailSecurity.Data.reportWindowStartTime
      description: Start time of the report window.
      type: Number
    - contextPath: SymantecEmailSecurity.Data.reportWindowEndTime
      description: End time of the report window.
      type: Number
  - name: symantec-email-security-email-queue-list
    description: Returns a list of domains owned by the customer, with queue statistics for each domain.
    arguments:
    - name: domains
      description: Comma-separated list of domains to retrieve. Leave empty to retrieve all domains.
      isArray: true
      default: true
    - name: limit
      description: The maximum number of records to return.
      defaultValue: '50'
    - name: all_results
      description: Whether to retrieve all the results by overriding the default limit.
      auto: PREDEFINED
      predefined:
      - 'true'
      - 'false'
    outputs:
    - contextPath: SymantecEmailSecurity.EmailQueue.TotalMessagesInbound
      description: Total number of inbound messages in the queue, for all domains.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.TotalMessagesOutbound
      description: Total number of outbound messages in the queue, for all domains.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.MeanTimeInQueueInbound
      description: Average (mean) queue wait for inbound messages, for all domains. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.MeanTimeInQueueOutbound
      description: Average (mean) queue wait for outbound messages, for all domains. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.LongestTimeInInbound
      description: How long the oldest message in the inbound queue has been queued, across all domains. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.LongestTimeInOutbound
      description: How long the oldest message in the outbound queue has been queued, across all domains. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.Name
      description: Name of the domain.
      type: String
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.ReceiveQueueCountInbound
      description: Number of inbound messages waiting to be processed.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.ReceiveQueueCountOutbound
      description: Number of outbound messages waiting to be processed.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.DeliveryQueueCountInbound
      description: Number of inbound messages that have been processed and are waiting to be delivered.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.DeliveryQueueCountOutbound
      description: Number of outbound messages that have been processed and are waiting to be delivered.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInReceiveQueueInbound
      description: Oldest inbound message in the queue waiting to be processed. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInReceiveQueueOutbound
      description: Oldest outbound message in the queue waiting to be processed. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInDeliveryQueueInbound
      description: Oldest inbound message waiting to be delivered after processing. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.LongestTimeInDeliveryQueueOutbound
      description: Oldest outbound message waiting to be delivered after processing. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInReceiveQueueInbound
      description: Average (mean) wait time for inbound messages waiting to be processed. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInReceiveQueueOutbound
      description: Average (mean) wait time for outbound messages waiting to be processed. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInDeliveryQueueInbound
      description: Average (mean) wait time for inbound messages waiting to be delivered after processing. Measured in seconds.
      type: Number
    - contextPath: SymantecEmailSecurity.EmailQueue.Domains.MeanTimeInDeliveryQueueOutbound
      description: Average (mean) wait time for outbound messages waiting to be delivered after processing. Measured in seconds.
      type: Number
  - name: symantec-email-security-quarantine-email-list
    description: Retrieves the metadata for quarantined emails belonging to the authenticated user. If the user is an administrator, the API provides options to retrieve the metadata for emails quarantined for another user under his administration.
    arguments:
    - name: query
      description: 'A search criterion that can be used to filter emails that match only certain conditions based on email metadata. The search syntax is built by a field name and search value enclosed by parenthesis and the operators: ''OR'', ''AND'' to combine multiple search criteria''s or values, example: (email_subject:test). Acceptable field names are: ''dlp_message_id'', ''email_envelope_sender'', ''email_envelope_sender.raw'', ''email_sender'', ''email_envelope_recipient'', ''email_envelope_recipient.raw'', ''email_subject'', ''email_subject.raw''. See the section called “Search String Syntax” on page 16 in: https://techdocs.broadcom.com/content/dam/broadcom/techdocs/us/en/dita/symantec-security-software/email-security/email-security-cloud/content/EmailQuarantineAPIGuide.pdf.'
    - name: sort_column
      description: Specifies the column to use for sorting. Defaults to `email_date_received`.
    - name: sort_order
      description: Specifies the order in which to sort.
      defaultValue: desc
      auto: PREDEFINED
      predefined:
      - desc
      - asc
    - name: after
      description: 'A time stamp value used to select only SUDULS items that were created after this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute.'
    - name: before
      description: 'A time stamp value used to select only SUDULS items that were created before this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute.'
    - name: filter_type
      description: 'A string used to filter emails based on the quarantine type. By default includes the emails quarantined for all types. COMPLIANCE: Includes Content control, DLP and Image control emails. DLP: Includes only DLP emails.'
      auto: PREDEFINED
      predefined:
      - SPAM
      - NEWSLETTER
      - CI
      - CO
      - II
      - IO
      - COMPLIANCE
      - DLP
    - name: include_deleted
      description: Specifies whether to include items marked as deleted in the search results.
      auto: PREDEFINED
      predefined:
      - 'true'
      - 'false'
    - name: user_email
      description: 'Return only the quarantined emails of the user whose email address is specified. Note: Can only be used by an administrator user.'
    - name: admin_domain
      description: 'Returns the emails quarantined for users in a particular domain. If this parameter is present and has a valid domain name, then items from only that domain are returned. If it has a value of `ALL`, then all domains administered by the user are searched and emails quarantined for users in those domains are returned. Note: Can only be used by an administrator user.'
    - name: limit
      description: The maximum number of records to return.
      defaultValue: 50
    - name: page
      description: The page number to retrieve records from.
    - name: page_size
      description: The maximum number of records to return per page. Default is 50. Max is 10,000.
    outputs:
    - contextPath: SymantecEmailSecurity.QuarantineEmail.id
      description: ID of the item.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_date_received
      description: Date the email was received.
      type: Date
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.quarantine_info.direction
      description: Direction of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.quarantine_info.quarantine_type
      description: 'Quarantine type of the email, can be one of: SPAM, NEWSLETTER, CI, CO, II, IO, COMPLIANCE, DLP.'
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_is_viewed
      description: Whether the email was viewed.
      type: Bool
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_is_released
      description: Whether the email was released.
      type: Bool
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.quarantine_reason
      description: Reason why the email was quarantined.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_sender
      description: Sender of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.service_type
      description: Service type used for the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.master_recipient
      description: Recipient of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.user_id
      description: ID of the user.
      type: Number
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_envelope_sender
      description: Address to respond to in case of bounce messages or errors.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_subject
      description: Subject of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_size
      description: Size of the email.
      type: Number
    - contextPath: SymantecEmailSecurity.QuarantineEmail.metadata.email_envelope_recipient
      description: The RCPT TO address.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmail.actions.view_subject
      description: Whether the subject can be viewed.
      type: Bool
    - contextPath: SymantecEmailSecurity.QuarantineEmail.actions.delete_message
      description: Whether the email can be deleted.
      type: Bool
    - contextPath: SymantecEmailSecurity.QuarantineEmail.actions.preview_message
      description: Whether the email can be previewed.
      type: Bool
    - contextPath: SymantecEmailSecurity.QuarantineEmail.actions.release_message
      description: Whether the email can be released.
      type: Bool
  - name: symantec-email-security-quarantine-email-preview
    description: Retrieves the contents of the email specified in the request. To preview an email the compliance policy must allow it.
    arguments:
    - name: message_id
      description: The message ID of the email to preview. Run `symantec-email-security-email-queue-list` to get a list of message IDs.
      required: true
      default: true
    outputs:
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.message_id
      description: ID of the message.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.authentication-results
      description: Authentication status of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.content-type
      description: The MIME type of the email content, defining how the content is structured.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.date
      description: The date and time when the email was sent.
      type: Date
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.dkim-signature
      description: The DKIM signature used to verify the authenticity of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.feedback-id
      description: A unique identifier used for tracking feedback and reporting issues related to the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.from
      description: The sender's email address and name.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.mailfrom
      description: The envelope sender email address.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.message-id
      description: Unique identifier for the email message.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.mime-version
      description: The MIME version used for the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.received
      description: Information about the servers the email passed through.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.reply-to
      description: The email address where replies to the message should be sent.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.subject
      description: The subject line of the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.to
      description: The recipient's email address.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.x-brightmail-tracker
      description: Tracking data for Brightmail filtering.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.headers.x-originating-ip
      description: IP address of the original sender.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.attachments.name
      description: The name of the file attached to the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.attachments.type
      description: The type of the file attached to the email.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.bodypart.type
      description: The type of the email's body part.
      type: String
    - contextPath: SymantecEmailSecurity.QuarantineEmailPreview.bodypart.content
      description: The content of the email's body part.
      type: String
  - name: symantec-email-security-quarantine-email-release
    description: Releases the set of quarantined emails specified in the request.
    arguments:
    - name: message_ids
      description: Comma-separated list of emails message IDs to release. Run `symantec-email-security-quarantine-email-list` to get a list of message IDs.
      required: true
      isArray: true
      default: true
    - name: recipient
      description: An email address to which the mails have to be released instead of the recipient user's address.
    - name: headers
      description: Comma-separated list of x-headers that will be added to the message on release.
      isArray: true
    - name: encrypt
      description: 'If true adds an ''x-encrypted-quarantine-release: true'' to the released email. Customers have to configure a corresponding DP rule that triggers encryption.'
      auto: PREDEFINED
      predefined:
      - 'true'
      - 'false'
  - name: symantec-email-security-quarantine-email-delete
    description: Deletes the set of quarantined emails specified in the request. The items are marked as deleted in the backend data store, but are not physically deleted.
    arguments:
    - name: message_ids
      description: Comma-separated list of quarantined emails message IDs to delete. Run `symantec-email-security-quarantine-email-list` to get a list of message IDs.
      required: true
      isArray: true
      default: true
  - name: symantec-email-security-item-allow-list
    description: Retrieve the allow list items.
    arguments:
    - name: query
      description: A string that at least some part of the allow list item must contain.
    - name: sort_column
      description: Specifies the column to use for sorting.
      defaultValue: date
      auto: PREDEFINED
      predefined:
      - date
      - type
      - description
    - name: sort_order
      description: Specifies the order in which to sort.
      defaultValue: desc
      auto: PREDEFINED
      predefined:
      - desc
      - asc
    - name: after
      description: 'A time stamp value used to select only SUDULS items that were created after this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute.'
    - name: before
      description: 'A time stamp value used to select only SUDULS items that were created before this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute.'
    - name: limit
      description: The maximum number of records to return.
      defaultValue: 50
    - name: page
      description: The page number to retrieve records from.
    - name: page_size
      description: The maximum number of records to return per page. Default is 50.
    outputs:
    - contextPath: SymantecEmailSecurity.AllowList.id
      description: ID of the item.
      type: String
    - contextPath: SymantecEmailSecurity.AllowList.value
      description: An email address or a domain name.
      type: String
    - contextPath: SymantecEmailSecurity.AllowList.description
      description: Description of the item.
      type: String
    - contextPath: SymantecEmailSecurity.AllowList.type
      description: Email or domain.
      type: String
    - contextPath: SymantecEmailSecurity.AllowList.date_created
      description: Date at which the item was created.
      type: Date
    - contextPath: SymantecEmailSecurity.AllowList.date_amended
      description: Date at which the item was amended.
      type: Date
  - name: symantec-email-security-item-allow-list-update
    description: Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to add or update an item to the allow list.
    arguments:
    - name: suduls_user
      description: Email address of the user for whom the entry should be added in the allow list.
      required: true
      default: true
    - name: item_id
      description: ID of SUDULS item to be added/updated. Only required when updating an existing item. Run `symantec-email-security-item-allow-list` to get a list of items.
    - name: email_or_domain
      description: Email address or domain to be added in the allow list.
      required: true
    - name: description
      description: Description of the item to be added to the allow list.
      required: true
  - name: symantec-email-security-item-allow-list-delete
    description: Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to delete an item from the allow list.
    arguments:
    - name: item_id
      description: ID of SUDULS item to be deleted. Run `symantec-email-security-item-allow-list` to get a list of items.
      required: true
      default: true
  - name: symantec-email-security-item-block-list
    description: Retrieve the block list items.
    arguments:
    - name: query
      description: A string that at least some part of the block list item must contain.
    - name: sort_column
      description: Specifies the column to use for sorting.
      defaultValue: date
    - name: sort_order
      description: Specifies the order in which to sort.
      defaultValue: desc
    - name: after
      description: 'A time stamp value used to select only SUDULS items that were created after this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute.'
    - name: before
      description: 'A time stamp value used to select only SUDULS items that were created before this time. Accepted formats: any substring of yyyy-mm-ddThh:mm:ssZ, epoch 1720617001, relative 1 day 2h 3 minute.'
    - name: limit
      description: The maximum number of records to return.
      defaultValue: 50
    - name: page
      description: The page number to retrieve records from.
    - name: page_size
      description: The maximum number of records to return per page. Default is 50.
    outputs:
    - contextPath: SymantecEmailSecurity.BlockList.id
      description: ID of the item.
      type: String
    - contextPath: SymantecEmailSecurity.BlockList.value
      description: An email address or a domain name.
      type: String
    - contextPath: SymantecEmailSecurity.BlockList.description
      description: Description of the item.
      type: String
    - contextPath: SymantecEmailSecurity.BlockList.type
      description: Email or domain.
      type: String
    - contextPath: SymantecEmailSecurity.BlockList.date_created
      description: Date at which the item was created.
      type: Date
    - contextPath: SymantecEmailSecurity.BlockList.date_amended
      description: Date at which the item was amended.
      type: Date
  - name: symantec-email-security-item-block-list-update
    description: Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to add or update an item to the block list.
    arguments:
    - name: suduls_user
      description: Email address of the user for whom the entry should be added in the block list.
      required: true
      default: true
    - name: item_id
      description: ID of SUDULS item to be added/updated. Only required when updating an existing item. Run `symantec-email-security-item-block-list` to get a list of items.
    - name: email_or_domain
      required: true
      description: Email address or domain to be added to the block list.
    - name: description
      description: Description of the item to be added to the block list.
      required: true
  - name: symantec-email-security-item-block-list-delete
    description: Allows a SUDULS (allow quarantine users to maintain their own lists of email addresses or domains) user to delete an item from the block list.
    arguments:
    - name: item_id
      description: ID of SUDULS item to be deleted. Run `symantec-email-security-item-block-list` to get a list of items.
      required: true
      default: true
  type: python
  subtype: python3
  dockerimage: demisto/python3:3.12.13.10116658
  isfetch: true
  script: ''
fromversion: 5.0.0
tests:
- SymantecEmailSecurity_TestPlaybook