TaegisXDR Deprecated

Deprecated. Use TaegisXDR v2 instead.

Data Enrichment & Threat Intelligence · Secureworks

Details

IDTaegisXDR
ProviderSophos
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/python3:3.10.12.65389
Supported ModulesAgentix XSIAM

README

Configure Taegis XDR in Cortex

Parameter Description Required
Taegis Environment The environment to utilize True
Client ID Client ID as described in the Taegis Documentation True
Client Secret Client Secret as described in the Taegis Documentation True
Use system proxy settings Defines whether the system proxy is used or not False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

taegis-archive-investigation

Base Command

!taegis-archive-investigation

Inputs

Argument Name Description Required
id The investigation id to archive True

Command Example

!taegis-archive-investigation id=c207ca4c-8a78-4408-a056-49f05d6eb77d

Context Example

{
    "TaegisXDR": {
        "ArchivedInvestigation": {
            "id": "c207ca4c-8a78-4408-a056-49f05d6eb77d"
        }
    }
}

taegis-create-comment

Base Command

!taegis-create-comment

Inputs

Argument Name Description Required
comment The comment string to add to the investigation True
parent_id The investigation ID to add the comment to True

Command Example

!taegis-create-comment comment="This is a test comment" parent_id="219da0ee-8642-4363-827c-8a6fbd479082"

Context Example

{
    "TaegisXDR": {
        "CommentCreate": {
            "id": "593fa115-abad-4a52-9fc4-2ec403a8a1e4"
        }
    }
}

taegis-create-investigation

Base Command

!taegis-create-investigation

Inputs

Argument Name Description Required
description The subject or description of the investigation True
priority The priority for the investigiation [Default: 3] False

Command Example

!taegis-create-investigation priority=1 description="XSOAR Created Investigation"

Context Example

{
    "TaegisXDR": {
        "Investigation": {
            "id": "593fa115-abad-4a52-9fc4-2ec403a8a1e4"
        }
    }
}

taegis-execute-playbook

Base Command

!taegis-execute-playbook

Inputs

Argument Name Description Required
id Playbook instance ID to execute True
inputs JSON object of inputs to pass into the playbook execution False

Command Example

!taegis-execute-playbook id=UGxheWJvb2tJbnN0YW5jZTphZDNmNzBlZi1mN2U0LTQ0OWYtODJiMi1hYWQwMjQzZTA2NTg=
!taegis-execute-playbook id=UGxheWJvb2tJbnN0YW5jZTphZDNmNzBlZi1mN2U0LTQ0OWYtODJiMi1hYWQwMjQzZTA2NTg= inputs=`{'myvar': 'myval'}`

Context Example

{
    "id": "UGxheWJvb2tFeGVjdXRpb246NGYwZDZiNGQtNWNiZS00NDkxLTg3YzYtMDZkNjkxYzMwMTg4"
}

taegis-fetch-alerts

Base Command

!taegis-fetch-alerts

Input

Argument Name Description Default Required
ids A list of alerts by IDs 936c1cc1-db8f-430c-837c-1c914fcca35a False
limit Number of results to when ids is not defined 10 False
offset The result to start from when ids is not defined 0 False
cql_query The query to utilize when searching for Alerts from alert severity >= 0.6 and status='OPEN' False

Command Examples

!taegis-fetch-alerts ids=`["6594e97f-a898-5b28-82b2-ea03293cdaa1"]`

Context Example

{
    "TaegisXDR": {
        "Alerts": [
            {
                "id": "c4f33b53-eaba-47ac-8272-199af0f7935b",
                "metadata": {
                    "title": "Test Alert",
                    "description": "This is a test alert",
                    "severity": 0.5,
                }
            }
        ]
    }
}

taegis-fetch-assets

Base Command

!taegis-fetch-assets

Input

Argument Name Description Default Required
page   0 False
page_size   10 False
endpoint_type     False
host_id ID of the asset to fetch e43b545a-580a-4047-b489-4338c1cc4ba1 False
hostname     False
investigation_id     False
ip_address     False
mac_address     False
os_family     False
os_version     False
sensor_version     False
username     False

Command Examples

!taegis-fetch-assets
!taegis-fetch-assets page=1 page_size=5
!taegis-fetch-assets hostname=MyHostname01
!taegis-fetch-assets host_id=e43b545a-580a-4047-b489-4338c1cc4ba1

Context Example

{
    "TaegisXDR": {
        "Assets": [
            {
              "id": "",
              "ingestTime": "",
              "createdAt": "",
              "updatedAt": "",
              "deletedAt": "",
              "biosSerial": "",
              "firstDiskSerial": "",
              "systemVolumeSerial": "",
              "sensorVersion": "",
              "endpointPlatform": "",
              "hostnames": [{"id": ", "hostname": ""],
              "architecture": "",
              "osFamily": "",
              "osVersion": "",
              "osDistributor": "",
              "osRelease": "",
              "systemType": "",
              "osCodename": "",
              "kernelRelease": "",
              "kernelVersion": "",
              "tags": [ "key": "", "tag": ""],
              "endpointType": "",
              "hostId": "",
              "sensorId": "",
            }
        ]
    }
}

taegis-fetch-comment

Base Command

!taegis-fetch-comment

Inputs

Argument Name Description Required
id The ID of the comment to fetch True

Command Example

!taegis-fetch-comment id=ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f

Context Example

{
    "TaegisXDR": {
        "Comment": {
            "author_user": {
                "email_normalized": "myuser@email.com",
                "given_name": "John",
                "family_name": "Smith",
                "id": "auth0|000000000000000000000001",
            },
            "id": "ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f",
            "comment": "This is a comment in an investigation",
            "created_at": "2022-01-01T13:04:57.17234Z",
            "deleted_at": None,
            "modified_at": None,
            "parent_id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
            "parent_type": "investigation",
        }
    }
}

taegis-fetch-comments

Base Command

!taegis-create-comments

Inputs

Argument Name Description Required
parent_id The investigation ID to fetch comments for True

Command Example

!taegis-fetch-comments parent_id=c2e09554-833e-41a1-bc9d-8160aec0d70d

Context Example

{
    "TaegisXDR": {
        "Comments": [
            {
                "author_user": {
                    "email_normalized": "myuser@email.com",
                    "given_name": "John",
                    "family_name": "Smith",
                    "id": "auth0|000000000000000000000001",
                },
                "id": "ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f",
                "comment": "This is a comment in an investigation",
                "created_at": "2022-01-01T13:04:57.17234Z",
                "deleted_at": None,
                "modified_at": None,
                "parent_id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
                "parent_type": "investigation",
            },
            {
                "author_user": {
                    "email_normalized": "myuser@email.com",
                    "given_name": "John",
                    "family_name": "Smith",
                    "id": "auth0|000000000000000000000001",
                },
                "id": "ff9ca818-4749-4ccb-883a-2ccc6f6c1234",
                "comment": "This is another comment",
                "created_at": "2022-01-02T13:04:57.17234Z",
                "deleted_at": None,
                "modified_at": None,
                "parent_id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
                "parent_type": "investigation",
            }
        ]
    }
}

taegis-fetch-endpoint

Base Command

!taegis-fetch-endpoint

Inputs

Argument Name Description Required
id Endpoint ID to fetch True

Command Example

!taegis-fetch-endpoint id=ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f

Context Example

{
    "TaegisXDR": {
        "assetEndpointInfo": {
            "hostId": "",
            "hostName": "",
            "actualIsolationStatus": "",
            "allowedDomain": "",
            "desiredIsolationStatus": "",
            "firstConnectTime": "",
            "moduleHealth": {
                "enabled": ""
                "lastRunningTime": "",
                "moduleDisplayName": "",
            }
            "lastConnectAddress": "",
            "lastConnectTime": "",
            "sensorVersion": ""
        }
    }
}

taegis-fetch-investigation

Base Command

!taegis-fetch-investigation

Inputs

Argument Name Description Required
id Investigation ID to lookup True

Command Example

!taegis-fetch-investigation id=936c1cc1-db8f-430c-837c-1c914fcca35a

Context Example

{
    "TaegisXDR": {
        "Investigations": [
            {
                "archived_at": None,
                "created_at": "2022-02-02T13:53:35Z",
                "description": "Test Investigation",
                "id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
                "key_findings": "",
                "priority": 2,
                "service_desk_id": "",
                "service_desk_type": "",
                "status": "Open",
                "alerts2": [],
                "url": "https://ctpx.secureworks.com/investigations/c2e09554-833e-41a1-bc9d-8160aec0d70d",
            }
        ]
    }
}

taegis-fetch-investigation-alerts

Base Command

!taegis-fetch-investigation-alerts

Inputs

Argument Name Description Required
id Investigation ID to lookup True

Command Example

!taegis-fetch-investigation-alerts id=936c1cc1-db8f-430c-837c-1c914fcca35a

Context Example

{
    "TaegisXDR": {
        "InvestigationAlerts": [
            {
                "id": "c4f33b53-eaba-47ac-8272-199af0f7935b",
                "description": "Test Alert",
                "message": "This is a test alert",
                "severity": 0.5,
            }
        ]
    }
}

taegis-fetch-investigations

Base Command

!taegis-fetch-investigations

Inputs

Argument Name Description Required
page   False
page_size   False

Command Example

!taegis-fetch-investigations

Context Example

{
    "TaegisXDR": {
        "Investigations": [
            {
                "description": "Test Investigation",
                "id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
                "key_findings": "",
                "priority": 2,
                "service_desk_id": "",
                "service_desk_type": "",
                "status": "Open"
            }
        ]
    }
}

taegis-fetch-playbook-execution

Base Command

!taegis-fetch-playbook-execution

Inputs

Argument Name Description Required
id Playbook execution ID to fetch True

Command Example

!taegis-fetch-playbook-execution id=UGxheWJvb2tFeGVjdXRpb246NGYwZDZiNGQtNWNiZS00NDkxLTg3YzYtMDZkNjkxYzMwMTg4

Context Example

{
    "TaegisXDR": {
        "PlaybookExecution": {
            "createdAt": "2022-01-01T13:51:24Z",
            "executionTime": 1442,
            "id": "UGxheWJvb2tFeGVjdXRpb246NGYwZDZiNGQtNWNiZS00NDkxLTg3YzYtMDZkNjkxYzMwMTg4",
            "inputs": {
                "alert": {
                    "message": "Test Alert",
                }
            },
            "instance": {
                "name": "Test Alert Instance",
                "playbook": {
                    "name": "Taegis.PagerDutyAlertEvent"
                }
            },
            "outputs": "d6b65662-c1da-4109-8553-c5664918c952",
            "state": "Completed",
            "updatedAt": "2022-01-01T13:51:31Z"
        }
    }
}

taegis-fetch-users

Base Command

!taegis-fetch-users

Inputs

Argument Name Description Required
id The id of the user, in auth0 format False
email The email of the user False
status The users to find based on status False
page   False
page_size   False

Command Example

!taegis-fetch-users id="auth0|123456"

Context Example

{
    "TaegisXDR": {
        "Users": [
            {
                "email": "myuser@email.com",
                "family_name": "Smith",
                "given_name": "John",
                "status": "Registered",
                "user_id": "auth0|123456"
            }
        ]
    }
}

taegis-isolate-asset

Base Command

!taegis-isolate-asset

Input

Argument Name Description Default Required
id ID of the asset to isolate e43b545a-580a-4047-b489-4338c1cc4ba1 True
reason The reason for the isolation See ticket 12345 True

Command Examples

!taegis-isolate-asset id="e43b545a-580a-4047-b489-4338c1cc4ba1" reason="See ticket 12345"

Context Example

{
    "TaegisXDR": {
        "AssetIsolation": {
            "id": "e43b545a-580a-4047-b489-4338c1cc4ba1"
        }
    }
}

taegis-update-alert-status

Base Command

!taegis-update-alert-status

Input

Argument Name Description Default Required
ids A comma-separated list of alerts by IDs alert://priv:crowdstrike:11772:1666269058114:59284e28-4ec8-542b-a4a1-452c3688bc1a True
status The status to update the alert(s) with FALSE_POSITIVE True
reason A comment/reason for the alert status update See ticket 13245 False
Permitted Status Values
  • FALSE_POSITIVE
  • NOT_ACTIONABLE
  • OPEN
  • TRUE_POSITIVE_BENIGN
  • TRUE_POSITIVE_MALICIOUS

Command Examples

!taegis-update-alert-status ids="alert://priv:crowdstrike:11772:1677742145475:07e2d9cc-0a04-55ec-890a-97f39d63698e" status=NOT_ACTIONABLE reason="Test Reason"

Context Example

{
    "TaegisXDR": {
        "AlertStatusUpdate": {
            "reason": "feedback updates successfully applied",
            "resolution_status": "SUCCESS"
        }
    }
}

taegis-update-comment

Base Command

!taegis-update-comment

Inputs

Argument Name Description Required
comment The comment string to add to the investigation True
id The comment ID to update True

Command Example

!taegis-update-comment id="ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f" comment="Newly updated comment"

Context Example

{
    "TaegisXDR": {
        "CommentUpdate": {
            "id": "593fa115-abad-4a52-9fc4-2ec403a8a1e4"
        }
    }
}

taegis-update-investigation

Base Command

!taegis-update-investigation

Inputs

Argument Name Description Required
id Investigation ID to update True
key_findings   False
prioirity The priority of the Investigation (1-5) False
service_desk_id An ID or ticket # to relate to an Investigation False
service_desk_type The type of id related to an investigation (e.g. Jira) False
status The current status of the Investigation False
assignee_id The id of a user to assign, in auth0|12345 format False

Note: At least 1 of the above inputs (in addition to id) must be defined

Permitted Status Values
  • Active
  • Awaiting Action
  • Closed: Authorized Activity
  • Closed: Confirmed Security Incident
  • Closed: False Positive Alert
  • Closed: Inconclusive
  • Closed: Informational
  • Closed: Not Vulnerable
  • Closed: Threat Mitigated
  • Open
  • Suspended

Command Example

!taegis-update-investigation id="936c1cc1-db8f-430c-837c-1c914fcca35a" priority=3 status="Open" service_desk_id="XDR-1234" service_desk_type="Jira"

Context Example

{
    "TaegisXDR": {
        "InvestigationUpdate": {
            "id": "c2e09554-833e-41a1-bc9d-8160aec0d70d"
        }
    }
}

taegis-unarchive-investigation

Base Command

!taegis-unarchive-investigation

Inputs

Argument Name Description Required
id The investigation id to unarchive True

Command Example

!taegis-unarchive-investigation id=c207ca4c-8a78-4408-a056-49f05d6eb77d

Context Example

{
    "TaegisXDR": {
        "UnarchivedInvestigation": {
            "id": "c207ca4c-8a78-4408-a056-49f05d6eb77d"
        }
    }
}

Configuration parameters

  • environment — Taegis Environment (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • client_id — Client ID (required)
  • client_secret — Client Secret (required)
  • isFetch — Fetch incidents
  • max_fetch — Maximum number of incidents per fetch
  • first_fetch — First fetch time interval
  • incidentFetchInterval — Incidents Fetch Interval
  • incidentType — Incident type
  • include_assets — Include Assets in Fetch

Commands (18)

  • taegis-archive-investigation

    Archive an investigation

  • taegis-create-comment

    Create a comment on an investigation

  • taegis-create-investigation

    Create an Investigation within Taegis

  • taegis-execute-playbook

    Executes a Taegis playbook instance

  • taegis-fetch-alerts

    List Taegis alerts by ID

  • taegis-fetch-assets

    Fetch assets based on search criteria

  • taegis-fetch-comment

    Fetch comment by comment ID

  • taegis-fetch-comments

    Fetch comments by Parent Type and ID

  • taegis-fetch-endpoint

    Fetch endpoint information

  • taegis-fetch-investigation

    Fetch all investigations or a specific investigation

  • taegis-fetch-investigation-alerts

    Fetch Alert IDs related to a specific investigation

  • taegis-fetch-playbook-execution

    Fetch the results of a Taegis playbook instance execution

  • taegis-fetch-users

    Fetch a user by ID or email address

  • taegis-isolate-asset

    Isolate a specific asset

  • taegis-unarchive-investigation

    Unarchive an investigation

  • taegis-update-alert-status

    Update the status of an alert

  • taegis-update-comment

    Update an existing comment

  • taegis-update-investigation

    Update an existing investigation

commonfields:
  id: TaegisXDR
  version: -1
name: TaegisXDR
display: TaegisXDR (Deprecated)
deprecated: true
category: Data Enrichment & Threat Intelligence
provider: Sophos
description: Deprecated. Use TaegisXDR v2 instead.
configuration:
- display: Taegis Environment
  name: environment
  type: 15
  required: true
  options:
  - US1
  - US2
  - EU
  additionalinfo: Used to determine the URL and API endpoint to utilize for your tenant
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  defaultvalue: "false"
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
- display: Client ID
  name: client_id
  type: 4
  required: true
- display: Client Secret
  name: client_secret
  type: 4
  required: true
- display: Fetch incidents
  name: isFetch
  type: 8
  required: false
- name: max_fetch
  defaultvalue: '15'
  display: Maximum number of incidents per fetch
  type: 0
  additionalinfo: The maximum limit is 200.
  required: false
- name: first_fetch
  defaultvalue: 3 days
  display: First fetch time interval
  type: 0
  additionalinfo: 'Date or relative timestamp to start fetching incidents from. For Alert, incidents will be fetched based on triggered date. For Event, the incidents will be fetched based on event time. (Formats accepted:  2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.).'
  required: false
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: "1"
  type: 19
  required: false
- display: Incident type
  name: incidentType
  type: 13
  required: false
- display: Include Assets in Fetch
  name: include_assets
  defaultvalue: "true"
  type: 8
  additionalinfo: An error can occur when the API is slow or there are a large numbers of assets being added to a new incident/investigation. Disabling this will fetch incidents without including asset information, allowing time for the investigation creation to be completed.
  required: false
script:
  script: ''
  type: python
  commands:
  - name: taegis-fetch-alerts
    arguments:
    - name: ids
      description: A list of alert IDs or string of comma-separated alert IDs to return
      isArray: true
    - name: cql_query
      description: The Taegis CQL query to for searching Alerts
    - name: limit
      default: true
      description: Number of results to return per page
      defaultValue: "10"
    - name: offset
      description: The results to start with
      defaultValue: "0"
    outputs:
    - contextPath: TaegisXDR.Alerts
      description: List of Taegis alerts
    description: List Taegis alerts by ID
  - name: taegis-fetch-investigation
    arguments:
    - name: id
      description: The investigation ID to lookup
    - name: page
      description: The page number for fetching investigations
      defaultValue: "0"
    - name: page_size
      description: Number of investigations to return
      defaultValue: "10"
    - name: status
      description: A list of statuses to use when searching for investigations
      isArray: true
    outputs:
    - contextPath: TaegisXDR.Investigations
      description: Dictionary of the located Taegis investigation
    description: Fetch all investigations or a specific investigation
  - name: taegis-create-investigation
    arguments:
    - name: description
      required: true
      description: The description of the investigation
    - name: priority
      required: true
      default: true
      auto: PREDEFINED
      predefined:
      - "1"
      - "2"
      - "3"
      - "4"
      - "5"
      description: The priority of the investigation (1-5)
      defaultValue: "2"
    outputs:
    - contextPath: TaegisXDR.Investigation
      description: The investigation ID that was created
    description: Create an Investigation within Taegis
  - name: taegis-update-investigation
    arguments:
    - name: id
      required: true
      description: The investigation ID to update
    - name: priority
      description: The priority of the investigation (1-5)
    - name: key_findings
      description: The Key Findings field of the investigation
    - name: status
      auto: PREDEFINED
      predefined:
      - Open
      - Active
      - Awaiting Action
      - Suspended
      - 'Closed: Authorized Activity'
      - 'Closed: Confirmed Security Incident'
      - 'Closed: False Positive Alert'
      - 'Closed: Inconclusive'
      - 'Closed: Informational'
      - 'Closed: Not Vulnerable'
      - 'Closed: Threat Mitigated'
      description: New status for the investigation
    - name: service_desk_id
      description: An ticket or ID for to an external system for reference
    - name: service_desk_type
      description: The type of service desk id (e.g. XSOAR)
    - name: assignee_id
      description: The auth0 ID of a user, in 'auth0|12345' format
    outputs:
    - contextPath: TaegisXDR.InvestigationUpdate
      description: ID of the updated Taegis investigation
    description: Update an existing investigation
  - name: taegis-fetch-investigation-alerts
    arguments:
    - name: id
      required: true
      description: The investigation ID related to the alerts
    - name: page
      description: Page number of the investigation alerts
      defaultValue: "0"
    - name: page_size
      description: Number of alerts per investigation query
      defaultValue: "10"
    outputs:
    - contextPath: TaegisXDR.InvestigationAlerts
      description: List of alerts related to a Taegis investigation
    description: Fetch Alert IDs related to a specific investigation
  - name: taegis-execute-playbook
    arguments:
    - name: id
      required: true
      description: The ID of the playbook instance to execute
    - name: inputs
      description: JSON Object of optional playbook inputs
    outputs:
    - contextPath: TaegisXDR.Execution
      description: The playbook execution ID
      type: string
    description: Executes a Taegis playbook instance
    execution: true
  - name: taegis-fetch-playbook-execution
    arguments:
    - name: id
      required: true
      description: Playbook execution ID
    outputs:
    - contextPath: TaegisXDR.PlaybookExecution
      description: Returns related execution information
    description: Fetch the results of a Taegis playbook instance execution
  - name: taegis-fetch-comment
    arguments:
    - name: id
      required: true
      description: The ID of the comment to fetch
    outputs:
    - contextPath: TaegisXDR.Comment
      description: Return the comment
    description: Fetch comment by comment ID
  - name: taegis-fetch-comments
    arguments:
    - name: parent_id
      required: true
      description: The ID of the parent related to the comments
    - name: parent_type
      description: The parent type that the comments belong to
      defaultValue: investigation
    outputs:
    - contextPath: TaegisXDR.Comments
      description: A list of comments to return
    description: Fetch comments by Parent Type and ID
  - name: taegis-create-comment
    arguments:
    - name: comment
      required: true
      description: The comment string to add to the parent
    - name: parent_id
      required: true
      description: The parent that the comment is being added to
    - name: parent_type
      description: The parent type that the comment is being added to
      defaultValue: investigation
    outputs:
    - contextPath: TaegisXDR.CommentCreate
      description: The created comment information
    description: Create a comment on an investigation
  - name: taegis-update-comment
    arguments:
    - name: id
      required: true
      description: The ID of the comment to update
    - name: comment
      required: true
      description: String to update/replace the comment with
    outputs:
    - contextPath: TaegisXDR.CommentUpdate
      description: The comment update results
    description: Update an existing comment
  - name: taegis-fetch-users
    arguments:
    - name: id
      description: The auth0 ID, in 'auth0|12345' format
    - name: email
      description: The email address to search for
    - name: status
      description: Search by user status
    - name: page
      description: Page for results
      defaultValue: "0"
    - name: page_size
      description: Results to return per page
      defaultValue: "10"
    outputs:
    - contextPath: TaegisXDR.Users
      description: The located user(s)
    description: Fetch a user by ID or email address
  - name: taegis-archive-investigation
    arguments:
    - name: id
      required: true
      description: ID of investigation to update
    outputs:
    - contextPath: TaegisXDR.ArchivedInvestigation
      description: The results from archiving an investigation
    description: Archive an investigation
  - name: taegis-unarchive-investigation
    arguments:
    - name: id
      required: true
      description: ID of investigation to update
    outputs:
    - contextPath: TaegisXDR.UnarchivedInvestigation
      description: The results from unarchiving an investigation
    description: Unarchive an investigation
  - name: taegis-update-alert-status
    arguments:
    - name: ids
      required: true
      description: A list of alert IDs or string of comma-separated alert IDs to return
      isArray: true
    - name: status
      required: true
      auto: PREDEFINED
      predefined:
      - FALSE_POSITIVE
      - NOT_ACTIONABLE
      - OPEN
      - TRUE_POSITIVE_BENIGN
      - TRUE_POSITIVE_MALICIOUS
      description: The status to update the alert with
    - name: reason
      description: A simple comment/reason for the status change
    outputs:
    - contextPath: TaegisXDR.AlertStatusUpdate
      description: The result of the alert status update
    description: Update the status of an alert
  - name: taegis-fetch-assets
    arguments:
    - name: page
      description: Search results page number
      defaultValue: "0"
    - name: page_size
      description: The number of results per-page
      defaultValue: "10"
    - name: endpoint_type
      description: Filter assets by asset type
    - name: host_id
      description: Filter assets by host ID
    - name: hostname
      description: Filter assets by hostname
    - name: investigation_id
      description: Filter assets by related investigation ID
    - name: ip_address
      description: Filter assets by IP address
    - name: mac_address
      description: Filter assets by MAC address
    - name: os_family
      description: Filter assets by OS family
    - name: os_version
      description: Filter assets by OS version
    - name: sensor_version
      description: Filter assets by sensor version
    - name: username
      description: Filter assets by username
    outputs:
    - contextPath: TaegisXDR.Assets
      description: A list of located assets
    description: Fetch assets based on search criteria
  - name: taegis-isolate-asset
    arguments:
    - name: id
      required: true
      description: Asset ID to isolate
    - name: reason
      required: true
      description: A reason for the isolation
    outputs:
    - contextPath: TaegisXDR.AssetIsolation
      description: Results from the asset isolation
    description: Isolate a specific asset
  - name: taegis-fetch-endpoint
    arguments:
    - name: id
      required: true
      description: The endpoint ID to fetch
    outputs:
    - contextPath: TaegisXDR.Endpoint
      description: Results from fetching the endpoint information
    description: Fetch endpoint information
  dockerimage: demisto/python3:3.10.12.65389
  subtype: python3
  isfetch: true
  isFetchSamples: true
fromversion: 5.5.0
tests:
- No tests (auto formatted)