TrustwaveFusion
The Trustwave Fusion platform connects your organization’s digital footprint to a robust security cloud comprised of the Trustwave data lake, advanced analytics, actionable threat intelligence and a wide range of Trustwave services including Trustwave SpiderLabs , elite team of security specialists. Your team will benefit from deep visibility and the advanced security expertise necessary for protecting assets and eradicating threats as they arise.
Data Enrichment & Threat Intelligence · Trustwave Fusion
Details
| ID | TrustwaveFusion |
|---|---|
| Provider | LevelBlue |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
The Trustwave Fusion platform connects your organization’s digital footprint
to a robust security cloud comprised of the Trustwave data lake, advanced
analytics, actionable threat intelligence and a wide range of Trustwave
services including Trustwave SpiderLabs , elite team of security
specialists. Your team will benefit from deep visibility and the advanced
security expertise necessary for protecting assets and eradicating threats as
they arise.
This integration was integrated and tested with version 1.0.68 of TrustwaveFusion
Configure TrustwaveFusion in Cortex
| Parameter | Description | Required |
|---|---|---|
| Fusion API URL | True | |
| API Key | The API Key to use for connection | True |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Fetch incidents | False | |
| Incident type | False | |
| Maximum number of incidents per fetch | False | |
| First fetch time | Format: [number] [time unit]. e.g., 12 hours, 7 days, 2 seconds etc. | False |
| Ticket Types | Types of tickets to fetch | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
trustwave-get-ticket
Get a single ticket
Base Command
trustwave-get-ticket
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Ticket ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Ticket.number | String | The Ticket ID |
| Trustwave.Ticket.subject | String | The ticket title. |
| Trustwave.Ticket.status | String | The status of the ticket |
| Trustwave.Ticket.description | String | The detailed ticket description. |
| Trustwave.Ticket.category | String | Ticket category |
| Trustwave.Ticket.createdBy | String | User that created the ticket. |
| Trustwave.Ticket.createdOn | Date | The ticket creation time. |
| Trustwave.Ticket.customerName | String | The name of the customer. |
| Trustwave.Ticket.findings.classification | String | Category for finding related to the ticket. |
| Trustwave.Ticket.findings.classificationCode | String | Category code for finding related to the ticket. |
| Trustwave.Ticket.findings.findingId | String | Id finding related to the ticket. |
| Trustwave.Ticket.formatted_notes | String | Human readable Notes for the ticket. |
| Trustwave.Ticket.impact | String | Ticket impact (HIGH, MEDIUM, LOW) |
| Trustwave.Ticket.notes.actor | String | User that added the note (comment) |
| Trustwave.Ticket.notes.text | String | The note (comment) text. |
| Trustwave.Ticket.notes.timestamp | Date | Time when the note (comment) was created. |
| Trustwave.Ticket.priority | String | Ticket priority (CRITICAL, HIGH, MEDIUM, LOW) |
| Trustwave.Ticket.subCategory | String | Ticket sub-category. |
| Trustwave.Ticket.type | String | The ticket type (CASE, INCIDENT, CHANGE) |
| Trustwave.Ticket.updatedOn | Date | When the ticket was last updated. |
| Trustwave.Ticket.urgency | String | The ticket urgency (HIGH, MEDIUM, LOW) |
Command example
!trustwave-get-ticket id="INA1976568"
Context Example
{
"Trustwave": {
"Ticket": {
"assetIds": [],
"category": "Threat Detection & Response",
"createdBy": "dummyuser",
"createdOn": "2021-12-08T17:16:27.000+00:00",
"customerName": "Sample Customer",
"description": "Ticket description.",
"findings": [
{
"classification": null,
"classificationCode": "UnauthorizedAccessOrIntrusionAttempt.",
"findingId": "765432:THREAT:@AXv0k6GhG2zTcaogE1vG"
}
],
"formatted_notes": "2021-12-08T17:16:27.000+00:00 Created by: dummyuser\nNOTE:\nNote A\n----------------\n2021-12-08T17:17:57.000+00:00 Created by: dummyuser\nNOTE:\nNote B\n----------------\n2021-12-09T16:43:31.000+00:00 Created by: dummy_user\nNOTE:\nNote C",
"impact": "HIGH",
"notes": [
{
"actor": "dummyuser",
"text": "Note A",
"timestamp": "2021-12-08T17:16:27.000+00:00"
},
{
"actor": "dummyuser",
"text": "Note B",
"timestamp": "2021-12-08T17:17:57.000+00:00"
},
{
"actor": "dummy_user",
"text": "Note C",
"timestamp": "2021-12-09T16:43:31.000+00:00"
}
],
"number": "INA1976568",
"priority": "HIGH",
"status": "ON_HOLD",
"subCategory": "Threat Operations",
"subject": "Test incident #354",
"type": "INCIDENT",
"updatedOn": "2021-12-09T16:43:48.000+00:00",
"urgency": "MEDIUM"
}
}
}
Human Readable Output
field value assetIds category Threat Detection & Response createdBy dummyuser createdOn 2021-12-08T17:16:27.000+00:00 customerName Sample Customer description Ticket description. findings {‘classification’: None, ‘classificationCode’: ‘UnauthorizedAccessOrIntrusionAttempt.’, ‘findingId’: ‘765432:THREAT:@AXv0k6GhG2zTcaogE1vG’} impact HIGH notes {‘actor’: ‘dummyuser’, ‘text’: ‘Note A’, ‘timestamp’: ‘2021-12-08T17:16:27.000+00:00’},
{‘actor’: ‘dummyuser’, ‘text’: ‘Note B’, ‘timestamp’: ‘2021-12-08T17:17:57.000+00:00’},
{‘actor’: ‘dummy_u….[Truncated]number INA1976568 priority HIGH status ON_HOLD subCategory Threat Operations subject Test incident #354 type INCIDENT updatedOn 2021-12-09T16:43:48.000+00:00 urgency MEDIUM formatted_notes 2021-12-08T17:16:27.000+00:00 Created by: dummyuser
NOTE:
Note A
—————-
2021-12-08T17:17:57.000+00:00 Created by: dummyuser
NOTE:
Note B
—————-
2021-12-09T1….[Truncated]
trustwave-search-tickets
Search tickets
Base Command
trustwave-search-tickets
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Ticket ID. | Optional |
| subject | Ticket Subject. | Optional |
| type | Ticket type to query. Possible values are: INCIDENT, CASE, CHANGE. | Optional |
| status | Ticket status. Possible values are: NEW, OPEN, IN_PROGRESS, AWAITING_INFO, ON_HOLD, RESOLVED, CLOSED, CANCELED, SCHEDULED. | Optional |
| priority | Ticket priority. Possible values are: CRITICAL, HIGH, MEDIUM, LOW. | Optional |
| impact | Ticket impact. Possible values are: HIGH, MEDIUM, LOW. | Optional |
| urgency | Ticket urgency. Possible values are: HIGH, MEDIUM, LOW. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Ticket.number | String | The Ticket ID |
| Trustwave.Ticket.subject | String | The ticket title. |
| Trustwave.Ticket.status | String | The status of the ticket |
| Trustwave.Ticket.description | String | The detailed ticket description. |
| Trustwave.Ticket.category | String | Ticket category. |
| Trustwave.Ticket.createdBy | String | User that created the ticket. |
| Trustwave.Ticket.createdOn | Date | The time when the ticket was created. |
| Trustwave.Ticket.customerName | String | The name of the customer. |
| Trustwave.Ticket.formatted_notes | String | Human readable notes. |
| Trustwave.Ticket.impact | String | Ticket impact (HIGH, MEDIUM, LOW) |
| Trustwave.Ticket.notes.actor | String | User that added the note (comment) |
| Trustwave.Ticket.notes.text | String | The note (comment) text. |
| Trustwave.Ticket.notes.timestamp | Date | Time when the note (comment) was created. |
| Trustwave.Ticket.priority | String | Ticket priority (CRITICAL, HIGH, MEDIUM, LOW) |
| Trustwave.Ticket.subCategory | String | Ticket sub-category. |
| Trustwave.Ticket.type | String | The ticket type (CASE, INCIDENT, CHANGE) |
| Trustwave.Ticket.updatedOn | Date | When the ticket was last updated. |
| Trustwave.Ticket.urgency | String | The ticket urgency (HIGH, MEDIUM, LOW) |
Command example
!trustwave-search-tickets limit=2 type=INCIDENT
Context Example
{
"Trustwave": {
"Ticket": [
{
"assetIds": [
"765432:managed-device#DEVICE:AW8Qp1Bextjwd2cF57Mk"
],
"category": "Technology Management",
"createdBy": "cpe_outage_service",
"createdOn": "2021-11-29T10:56:45.000+00:00",
"customerName": "Sample Customer",
"description": "",
"findings": [],
"formatted_notes": "2021-11-29T10:56:44.000+00:00 Created by: cpe_outage_service\nNOTE:\nNOTE A",
"impact": "HIGH",
"notes": [
{
"actor": "cpe_outage_service",
"text": "NOTE A",
"timestamp": "2021-11-29T10:56:44.000+00:00"
}
],
"number": "INA1077007",
"priority": "HIGH",
"status": "CLOSED",
"subCategory": "Cellular Backup",
"subject": "Alert: device is using cellular",
"type": "INCIDENT",
"updatedOn": "2021-12-29T00:00:08.000+00:00",
"urgency": "MEDIUM"
},
{
"assetIds": [],
"category": "Threat Detection & Response",
"createdBy": "dummyuser",
"createdOn": "2021-12-08T17:16:27.000+00:00",
"customerName": "Sample Customer",
"description": "Ticket description",
"findings": [
{
"classification": null,
"classificationCode": "UnauthorizedAccessOrIntrusionAttempt.",
"findingId": "765432:THREAT:@AXv0k6GhG2zTcaogE1vG"
}
],
"formatted_notes": "2021-12-08T17:16:27.000+00:00 Created by: dummyuser\nNOTE:\nSample Note.\n----------------\n2021-12-08T17:17:57.000+00:00 Created by: dummyuser\nNOTE:\nSample note #2.\n----------------\n2021-12-09T16:43:31.000+00:00 Created by: dummy_user\nNOTE:\nSample note #3",
"impact": "HIGH",
"notes": [
{
"actor": "dummyuser",
"text": "Sample Note.",
"timestamp": "2021-12-08T17:16:27.000+00:00"
},
{
"actor": "dummyuser",
"text": "Sample note #2.",
"timestamp": "2021-12-08T17:17:57.000+00:00"
},
{
"actor": "dummy_user",
"text": "Sample note #3",
"timestamp": "2021-12-09T16:43:31.000+00:00"
}
],
"number": "INA1077535",
"priority": "HIGH",
"status": "ON_HOLD",
"subCategory": "Threat Operations",
"subject": "MCAS - Impossible travel activity",
"type": "INCIDENT",
"updatedOn": "2021-12-09T16:43:48.000+00:00",
"urgency": "MEDIUM"
}
]
}
}
Human Readable Output
Results
assetIds category createdBy createdOn customerName description findings formatted_notes impact notes number priority status subCategory subject type updatedOn urgency 765432:managed-device#DEVICE:AW8Qp1Bextjwd2cF57Mk Technology Management cpe_outage_service 2021-11-29T10:56:45.000+00:00 Sample Customer 2021-11-29T10:56:44.000+00:00 Created by: cpe_outage_service
NOTE:
NOTE AHIGH {‘actor’: ‘cpe_outage_service’, ‘text’: ‘NOTE A’, ‘timestamp’: ‘2021-11-29T10:56:44.000+00:00’} INA1077007 HIGH CLOSED Cellular Backup Alert: device is using cellular INCIDENT 2021-12-29T00:00:08.000+00:00 MEDIUM Threat Detection & Response dummyuser 2021-12-08T17:16:27.000+00:00 Sample Customer Ticket description {‘classification’: None, ‘classificationCode’: ‘UnauthorizedAccessOrIntrusionAttempt.’, ‘findingId’: ‘765432:THREAT:@AXv0k6GhG2zTcaogE1vG’} 2021-12-08T17:16:27.000+00:00 Created by: dummyuser
NOTE:
Sample Note.
—————-
2021-12-08T17:17:57.000+00:00 Created by: dummyuser
NOTE:
Sample note #2.
—————-
2021-12-09T16:43:31.000+00:00 Created by: dummy_user
NOTE:
Sample note #3HIGH {‘actor’: ‘dummyuser’, ‘text’: ‘Sample Note.’, ‘timestamp’: ‘2021-12-08T17:16:27.000+00:00’},
{‘actor’: ‘dummyuser’, ‘text’: ‘Sample note #2.’, ‘timestamp’: ‘2021-12-08T17:17:57.000+00:00’},
{‘actor’: ‘dummy_user’, ‘text’: ‘Sample note #3’, ‘timestamp’: ‘2021-12-09T16:43:31.000+00:00’}INA1077535 HIGH ON_HOLD Threat Operations MCAS - Impossible travel activity INCIDENT 2021-12-09T16:43:48.000+00:00 MEDIUM
trustwave-add-ticket-comment
Add a comment to a ticket
Base Command
trustwave-add-ticket-comment
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Incident ID. | Required |
| comment | Comment text. | Required |
Context Output
There is no context output for this command.
Command example
!trustwave-add-ticket-comment id=INA1051028 comment="test from xsoar"
Human Readable Output
Success
trustwave-close-ticket
Close a ticket
Base Command
trustwave-close-ticket
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Incident ID. | Required |
| comment | Comment text. | Required |
Context Output
There is no context output for this command.
Command example
!trustwave-close-ticket id="INA1051028" comment="Comment"
Human Readable Output
Success
trustwave-get-updated-tickets
Get updated tickets.
Base Command
trustwave-get-updated-tickets
Input
| Argument Name | Description | Required |
|---|---|---|
| since | Absolute or relative date to check for updates. | Required |
| fetch_limit | Maximum number of tickets to fetch. Default is 100. | Optional |
| ticket_types | Ticket type to query. Possible values are: INCIDENT, CASE, CHANGE. Default is INCIDENT. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Ticket.number | String | The Ticket ID |
| Trustwave.Ticket.subject | String | The ticket title. |
| Trustwave.Ticket.status | String | The status of the ticket |
| Trustwave.Ticket.description | String | The detailed ticket description. |
| Trustwave.Ticket.category | String | Ticket category. |
| Trustwave.Ticket.createdBy | String | User that created the ticket. |
| Trustwave.Ticket.createdOn | Date | The time when the ticket was created. |
| Trustwave.Ticket.customerName | String | The name of the customer. |
| Trustwave.Ticket.formatted_notes | String | Human readable notes. |
| Trustwave.Ticket.impact | String | Ticket impact (HIGH, MEDIUM, LOW) |
| Trustwave.Ticket.notes.actor | String | User that added the note (comment) |
| Trustwave.Ticket.notes.text | String | The note (comment) text. |
| Trustwave.Ticket.notes.timestamp | Date | Time when the note (comment) was created. |
| Trustwave.Ticket.priority | String | Ticket priority (CRITICAL, HIGH, MEDIUM, LOW) |
| Trustwave.Ticket.subCategory | String | Ticket sub-category. |
| Trustwave.Ticket.type | String | The ticket type (CASE, INCIDENT, CHANGE) |
| Trustwave.Ticket.updatedOn | Date | When the ticket was last updated. |
| Trustwave.Ticket.urgency | String | The ticket urgency (HIGH, MEDIUM, LOW) |
Command example
!trustwave-get-updated-tickets fetch_limit=2 since=2021-12-09T16:43:48.000+00:00
Context Example
{
"Trustwave": {
"Ticket": [
{
"assetIds": [
"765432:managed-device#DEVICE:AW8Qp1Bextjwd2cF57Mk"
],
"category": "Technology Management",
"createdBy": "cpe_outage_service",
"createdOn": "2021-11-29T10:56:45.000+00:00",
"customerName": "Sample Customer",
"description": "",
"findings": [],
"formatted_notes": "2021-11-29T10:56:44.000+00:00 Created by: cpe_outage_service\nNOTE:\nNOTE A",
"impact": "HIGH",
"notes": [
{
"actor": "cpe_outage_service",
"text": "NOTE A",
"timestamp": "2021-11-29T10:56:44.000+00:00"
}
],
"number": "INA1077007",
"priority": "HIGH",
"status": "CLOSED",
"subCategory": "Cellular Backup",
"subject": "Alert: device is using cellular",
"type": "INCIDENT",
"updatedOn": "2021-12-29T00:00:08.000+00:00",
"urgency": "MEDIUM"
},
{
"assetIds": [],
"category": "Threat Detection & Response",
"createdBy": "dummyuser",
"createdOn": "2021-12-08T17:16:27.000+00:00",
"customerName": "Sample Customer",
"description": "Ticket description",
"findings": [
{
"classification": null,
"classificationCode": "UnauthorizedAccessOrIntrusionAttempt.",
"findingId": "765432:THREAT:@AXv0k6GhG2zTcaogE1vG"
}
],
"formatted_notes": "2021-12-08T17:16:27.000+00:00 Created by: dummyuser\nNOTE:\nSample Note.\n----------------\n2021-12-08T17:17:57.000+00:00 Created by: dummyuser\nNOTE:\nSample note #2.\n----------------\n2021-12-09T16:43:31.000+00:00 Created by: dummy_user\nNOTE:\nSample note #3",
"impact": "HIGH",
"notes": [
{
"actor": "dummyuser",
"text": "Sample Note.",
"timestamp": "2021-12-08T17:16:27.000+00:00"
},
{
"actor": "dummyuser",
"text": "Sample note #2.",
"timestamp": "2021-12-08T17:17:57.000+00:00"
},
{
"actor": "dummy_user",
"text": "Sample note #3",
"timestamp": "2021-12-09T16:43:31.000+00:00"
}
],
"number": "INA1077535",
"priority": "HIGH",
"status": "ON_HOLD",
"subCategory": "Threat Operations",
"subject": "MCAS - Impossible travel activity",
"type": "INCIDENT",
"updatedOn": "2021-12-09T16:43:48.000+00:00",
"urgency": "MEDIUM"
}
]
}
}
Human Readable Output
Results
assetIds category createdBy createdOn customerName description findings formatted_notes impact notes number priority status subCategory subject type updatedOn urgency 765432:managed-device#DEVICE:AW8Qp1Bextjwd2cF57Mk Technology Management cpe_outage_service 2021-11-29T10:56:45.000+00:00 Sample Customer 2021-11-29T10:56:44.000+00:00 Created by: cpe_outage_service
NOTE:
NOTE AHIGH {‘actor’: ‘cpe_outage_service’, ‘text’: ‘NOTE A’, ‘timestamp’: ‘2021-11-29T10:56:44.000+00:00’} INA1077007 HIGH CLOSED Cellular Backup Alert: device is using cellular INCIDENT 2021-12-29T00:00:08.000+00:00 MEDIUM Threat Detection & Response dummyuser 2021-12-08T17:16:27.000+00:00 Sample Customer Ticket description {‘classification’: None, ‘classificationCode’: ‘UnauthorizedAccessOrIntrusionAttempt.’, ‘findingId’: ‘765432:THREAT:@AXv0k6GhG2zTcaogE1vG’} 2021-12-08T17:16:27.000+00:00 Created by: dummyuser
NOTE:
Sample Note.
—————-
2021-12-08T17:17:57.000+00:00 Created by: dummyuser
NOTE:
Sample note #2.
—————-
2021-12-09T16:43:31.000+00:00 Created by: dummy_user
NOTE:
Sample note #3HIGH {‘actor’: ‘dummyuser’, ‘text’: ‘Sample Note.’, ‘timestamp’: ‘2021-12-08T17:16:27.000+00:00’},
{‘actor’: ‘dummyuser’, ‘text’: ‘Sample note #2.’, ‘timestamp’: ‘2021-12-08T17:17:57.000+00:00’},
{‘actor’: ‘dummy_user’, ‘text’: ‘Sample note #3’, ‘timestamp’: ‘2021-12-09T16:43:31.000+00:00’}INA1077535 HIGH ON_HOLD Threat Operations MCAS - Impossible travel activity INCIDENT 2021-12-09T16:43:48.000+00:00 MEDIUM
trustwave-search-findings
Search for Findings
Base Command
trustwave-search-findings
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Finding ID. | Optional |
| limit | Maximum number of Findings to return. Default is 100. | Optional |
| name | Name of the Finding. | Optional |
| classification | Finding Classification. | Optional |
| summary | Finding summary. | Optional |
| detail | Finding detail. | Optional |
| priority | Finding priority. Possible values are: CRITICAL, HIGH, MEDIUM, LOW. | Optional |
| severity | Finding severity. | Optional |
| created_since | created_since. | Optional |
| updated_since | Updated since. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Finding.classification | String | Category for the finding |
| Trustwave.Finding.createdOn | Date | Time when the finding was created. |
| Trustwave.Finding.customerName | String | Customer name for the finding. |
| Trustwave.Finding.destination | String | Destination for finding. |
| Trustwave.Finding.detail | String | Detailed description of the finding. |
| Trustwave.Finding.id | String | The finding ID |
| Trustwave.Finding.priority | Number | The priority of the finding. |
| Trustwave.Finding.severity | Number | The severity of the finding. |
| Trustwave.Finding.source | String | SOAR actions taken for finding. |
| Trustwave.Finding.status.description | String | Current status of the Finding. |
| Trustwave.Finding.summary | String | The name of the finding. |
| Trustwave.Finding.type | String | The type of finding (e.g. THREAT, VULNERABILITY) |
| Trustwave.Finding.updatedOn | Date | Time when the finding was last updated. |
Command example
!trustwave-search-findings limit="2" summary="MS Graph Alert Detection Rule" type=threat updatedSince=2021-12-08T17:17:56.000+00:00
Context Example
{
"Trustwave": {
"Finding": [
{
"classification": null,
"createdOn": "2021-09-17T16:26:11.731+00:00",
"customerName": "Sample Customer",
"destination": null,
"detail": "MCAS - Impossible travel activity",
"id": "765432:THREAT:@AXv0k6GhG2zTcaogE1vG",
"priority": 4,
"severity": 4,
"source": null,
"status": {
"description": "Security Incident"
},
"summary": "MS Graph Alert Detection Rule",
"type": "THREAT",
"updatedOn": "2021-12-08T17:17:56.504+00:00"
},
{
"classification": null,
"createdOn": "2021-10-26T22:33:17.567+00:00",
"customerName": "Sample Customer",
"destination": null,
"detail": "ASC, MSTIC - Windows registry persistence method detected pqa VM_RegistryPersistencyKey",
"id": "765432:THREAT:@AXy-u5fVt3G3ZYM6G5cH",
"priority": 2,
"severity": 2,
"source": null,
"status": {
"description": "False Positive"
},
"summary": "MS Graph Alert Detection Rule",
"type": "THREAT",
"updatedOn": "2021-12-16T17:21:31.384+00:00"
}
]
}
}
Human Readable Output
Results
classification createdOn customerName destination detail id priority severity source status summary type updatedOn 2021-09-17T16:26:11.731+00:00 Sample Customer MCAS - Impossible travel activity 765432:THREAT:@AXv0k6GhG2zTcaogE1vG 4 4 description: Security Incident MS Graph Alert Detection Rule THREAT 2021-12-08T17:17:56.504+00:00 2021-10-26T22:33:17.567+00:00 Sample Customer ASC, MSTIC - Windows registry persistence method detected pqa VM_RegistryPersistencyKey 765432:THREAT:@AXy-u5fVt3G3ZYM6G5cH 2 2 description: False Positive MS Graph Alert Detection Rule THREAT 2021-12-16T17:21:31.384+00:00
trustwave-get-finding
Get a Finding
Base Command
trustwave-get-finding
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Finding ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Finding.analystNotes.actor | String | User that created the analyst note. |
| Trustwave.Finding.analystNotes.text | String | Analyst note text. |
| Trustwave.Finding.analystNotes.timestamp | Date | Time when the note was created |
| Trustwave.Finding.assetsIds | String | Assets impacted by the finding |
| Trustwave.Finding.classification | String | Category for the finding |
| Trustwave.Finding.createdOn | Date | Time when the finding was created. |
| Trustwave.Finding.customerName | String | Customer name for the finding. |
| Trustwave.Finding.destination | String | Destination for finding. |
| Trustwave.Finding.detail | String | Detailed description of the finding. |
| Trustwave.Finding.eventsIds | String | List of event ID associated with the finding. |
| Trustwave.Finding.id | String | The finding ID |
| Trustwave.Finding.parentId | String | The ID of the parent of the finding. |
| Trustwave.Finding.priority | Number | The priority of the finding. |
| Trustwave.Finding.severity | Number | The severity of the finding. |
| Trustwave.Finding.source | String | Source for finding |
| Trustwave.Finding.status.description | String | Current status of the Finding. |
| Trustwave.Finding.summary | String | The name of the finding. |
| Trustwave.Finding.type | String | The type of finding (e.g. THREAT, VULNERABILITY) |
| Trustwave.Finding.updatedOn | Date | Time when the finding was last updated. |
Command example
!trustwave-get-finding id="765432:THREAT:@AXv0k6GhG2zTcaogE1vG"
Context Example
{
"Trustwave": {
"Finding": {
"analystNotes": [
{
"actor": "dummyuser",
"text": "Note A",
"timestamp": "2021-12-08T17:17:56.790+00:00"
}
],
"assetsIds": [
"765432:PERSON:AXsNy0R8CfYgZQumlNdv"
],
"childFindingIds": [],
"classification": null,
"createdOn": "2021-09-17T16:26:11.731+00:00",
"customerName": "Sample Customer",
"destination": null,
"detail": "MCAS - Impossible travel activity",
"eventsIds": [
"34c0e1b2-96e6-4a25-be3d-80d0671a5d8f"
],
"id": "765432:THREAT:@AXv0k6GhG2zTcaogE1vG",
"parentId": null,
"priority": 4,
"severity": 4,
"source": null,
"status": {
"description": "Security Incident"
},
"summary": "MS Graph Alert Detection Rule",
"type": "THREAT",
"updatedOn": "2021-12-08T17:17:56.504+00:00"
}
}
}
Human Readable Output
Results
analystNotes assetsIds childFindingIds classification createdOn customerName destination detail eventsIds id parentId priority severity source status summary type updatedOn {‘actor’: ‘dummyuser’, ‘text’: ‘Note A’, ‘timestamp’: ‘2021-12-08T17:17:56.790+00:00’} 765432:PERSON:AXsNy0R8CfYgZQumlNdv 2021-09-17T16:26:11.731+00:00 Sample Customer MCAS - Impossible travel activity 34c0e1b2-96e6-4a25-be3d-80d0671a5d8f 765432:THREAT:@AXv0k6GhG2zTcaogE1vG 4 4 description: Security Incident MS Graph Alert Detection Rule THREAT 2021-12-08T17:17:56.504+00:00
trustwave-get-asset
Get an Asset
Base Command
trustwave-get-asset
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Asset ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Asset.cidr | String | Network address in CIDR notation. |
| Trustwave.Asset.createdOn | Date | Time when the asset was created. |
| Trustwave.Asset.customerName | String | The customer name for the asset. |
| Trustwave.Asset.id | String | The asset ID. |
| Trustwave.Asset.ips | String | List of IP addresses for the asset. |
| Trustwave.Asset.lastActivity | Date | Time of the last activity associated with the asset. |
| Trustwave.Asset.name | String | The name of the asset. |
| Trustwave.Asset.networkInterfaces.gateway | String | Gateway address for the asset network interface. |
| Trustwave.Asset.networkInterfaces.hostnames | String | List of hostname for the asset network interface |
| Trustwave.Asset.networkInterfaces.ip | String | IP address for the asset network interface |
| Trustwave.Asset.networkInterfaces.macAddress | String | MAC address for the asset network interface |
| Trustwave.Asset.networkInterfaces.macVendor | String | Vendor associated with the MAC address for the asset network interface |
| Trustwave.Asset.networkInterfaces.subnet | String | Network subnet the asset network interface |
| Trustwave.Asset.os | String | Asset operating system. |
| Trustwave.Asset.services.applicationName | String | Service name. |
| Trustwave.Asset.services.applicationProtocol | String | Service protocol. |
| Trustwave.Asset.services.port | Number | Service port |
| Trustwave.Asset.services.transportProtocol | String | Service transport. |
| Trustwave.Asset.status | String | Asset status. |
| Trustwave.Asset.type | String | The type of asset. |
| Trustwave.Asset.updatedOn | Date | Time when the asset was last updated. |
| Trustwave.Asset.uri | String | URI of the asset. |
Command example
!trustwave-get-asset id="765432:DNA#DEVICE:AW2X-hCmXdgvNlcDpVGf"
Context Example
{
"Trustwave": {
"Asset": {
"cidr": null,
"createdOn": "2019-10-04T18:13:30.941+00:00",
"customerName": "Sample Customer",
"id": "765432:DNA#DEVICE:AW2X-hCmXdgvNlcDpVGf",
"ips": [
"10.103.201.47"
],
"lastActivity": null,
"name": "host.example.com",
"networkInterfaces": [
{
"gateway": null,
"hostnames": [
"host.example.com"
],
"ip": "10.103.201.47",
"macAddress": null,
"macVendor": null,
"subnet": null
}
],
"notes": [],
"os": null,
"services": [
{
"applicationName": null,
"applicationProtocol": null,
"port": 80,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "sunrpcportmap",
"port": 111,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "sunrpcportmap",
"port": 111,
"transportProtocol": "udp"
},
{
"applicationName": null,
"applicationProtocol": "ntp",
"port": 123,
"transportProtocol": "udp"
},
{
"applicationName": null,
"applicationProtocol": "snmp",
"port": 161,
"transportProtocol": "udp"
},
{
"applicationName": null,
"applicationProtocol": null,
"port": 443,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "mysql",
"port": 3306,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": null,
"port": 5672,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "snmp",
"port": 16161,
"transportProtocol": "udp"
}
],
"status": null,
"tags": [],
"type": "Device",
"updatedOn": "2019-10-04T19:09:59.907+00:00",
"uri": null
}
}
}
Human Readable Output
Results
cidr createdOn customerName id ips lastActivity name networkInterfaces notes os services status tags type updatedOn uri 2019-10-04T18:13:30.941+00:00 Sample Customer 765432:DNA#DEVICE:AW2X-hCmXdgvNlcDpVGf 10.103.201.47 host.example.com {‘gateway’: None, ‘hostnames’: [‘host.example.com’], ‘ip’: ‘10.103.201.47’, ‘macAddress’: None, ‘macVendor’: None, ‘subnet’: None} {‘applicationName’: None, ‘applicationProtocol’: None, ‘port’: 80, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘sunrpcportmap’, ‘port’: 111, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘sunrpcportmap’, ‘port’: 111, ‘transportProtocol’: ‘udp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘ntp’, ‘port’: 123, ‘transportProtocol’: ‘udp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘snmp’, ‘port’: 161, ‘transportProtocol’: ‘udp’},
{‘applicationName’: None, ‘applicationProtocol’: None, ‘port’: 443, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘mysql’, ‘port’: 3306, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: None, ‘port’: 5672, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘snmp’, ‘port’: 16161, ‘transportProtocol’: ‘udp’}Device 2019-10-04T19:09:59.907+00:00
trustwave-search-assets
Search for Assets
Base Command
trustwave-search-assets
Input
| Argument Name | Description | Required |
|---|---|---|
| id | Asset ID. | Optional |
| limit | Maximum number of Assets to return. Default is 100. | Optional |
| name | Name of the Asset. | Optional |
| os | OS for the Asset. | Optional |
| tags | Asset Tags to search for. | Optional |
| port | port. | Optional |
| app_protocol | Application Protocol. | Optional |
| transport | Transport Protocol. | Optional |
| type | Asset Type. | Optional |
| created_since | created_since. | Optional |
| updated_since | Updated since. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Trustwave.Asset.cidr | String | Network address in CIDR notation. |
| Trustwave.Asset.createdOn | Date | Time when the asset was created. |
| Trustwave.Asset.customerName | String | The customer name for the asset. |
| Trustwave.Asset.id | String | The asset ID. |
| Trustwave.Asset.ips | String | List of IP addresses for the asset. |
| Trustwave.Asset.lastActivity | Date | Time of the last activity associated with the asset. |
| Trustwave.Asset.name | String | The name of the asset. |
| Trustwave.Asset.networkInterfaces.gateway | String | Gateway address for the asset network interface. |
| Trustwave.Asset.networkInterfaces.hostnames | String | List of hostname for the asset network interface |
| Trustwave.Asset.networkInterfaces.ip | String | IP address for the asset network interface |
| Trustwave.Asset.networkInterfaces.macAddress | String | MAC address for the asset network interface |
| Trustwave.Asset.networkInterfaces.macVendor | String | Vendor associated with the MAC address for the asset network interface |
| Trustwave.Asset.networkInterfaces.subnet | String | Network subnet the asset network interface |
| Trustwave.Asset.os | String | Asset operating system. |
| Trustwave.Asset.status | String | Asset status. |
| Trustwave.Asset.type | String | The type of asset. |
| Trustwave.Asset.updatedOn | Date | Time when the asset was last updated. |
| Trustwave.Asset.uri | String | URI of the asset. |
Command example
!trustwave-search-assets limit=2 type="DEVICE" name="host.example.com"
Context Example
{
"Trustwave": {
"Asset": {
"cidr": null,
"createdOn": "2019-10-04T18:13:30.941+00:00",
"customerName": "Sample Customer",
"id": "765432:DNA#DEVICE:AW2X-hCmXdgvNlcDpVGf",
"ips": [
"10.103.201.47"
],
"lastActivity": null,
"name": "host.example.com",
"networkInterfaces": [
{
"gateway": null,
"hostnames": [
"host.example.com"
],
"ip": "10.103.201.47",
"macAddress": null,
"macVendor": null,
"subnet": null
}
],
"notes": [],
"os": null,
"services": [
{
"applicationName": null,
"applicationProtocol": null,
"port": 80,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "sunrpcportmap",
"port": 111,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "sunrpcportmap",
"port": 111,
"transportProtocol": "udp"
},
{
"applicationName": null,
"applicationProtocol": "ntp",
"port": 123,
"transportProtocol": "udp"
},
{
"applicationName": null,
"applicationProtocol": "snmp",
"port": 161,
"transportProtocol": "udp"
},
{
"applicationName": null,
"applicationProtocol": null,
"port": 443,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "mysql",
"port": 3306,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": null,
"port": 5672,
"transportProtocol": "tcp"
},
{
"applicationName": null,
"applicationProtocol": "snmp",
"port": 16161,
"transportProtocol": "udp"
}
],
"status": null,
"tags": [],
"type": "Device",
"updatedOn": "2019-10-04T19:09:59.907+00:00",
"uri": null
}
}
}
Human Readable Output
Results
cidr createdOn customerName id ips lastActivity name networkInterfaces notes os services status tags type updatedOn uri 2019-10-04T18:13:30.941+00:00 Sample Customer 765432:DNA#DEVICE:AW2X-hCmXdgvNlcDpVGf 10.103.201.47 host.example.com {‘gateway’: None, ‘hostnames’: [‘host.example.com’], ‘ip’: ‘10.103.201.47’, ‘macAddress’: None, ‘macVendor’: None, ‘subnet’: None} {‘applicationName’: None, ‘applicationProtocol’: None, ‘port’: 80, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘sunrpcportmap’, ‘port’: 111, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘sunrpcportmap’, ‘port’: 111, ‘transportProtocol’: ‘udp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘ntp’, ‘port’: 123, ‘transportProtocol’: ‘udp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘snmp’, ‘port’: 161, ‘transportProtocol’: ‘udp’},
{‘applicationName’: None, ‘applicationProtocol’: None, ‘port’: 443, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘mysql’, ‘port’: 3306, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: None, ‘port’: 5672, ‘transportProtocol’: ‘tcp’},
{‘applicationName’: None, ‘applicationProtocol’: ‘snmp’, ‘port’: 16161, ‘transportProtocol’: ‘udp’}Device 2019-10-04T19:09:59.907+00:00
Configuration parameters
url— Fusion API URL (required)apikey— API Key (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsisFetch— Fetch incidentsincidentType— Incident typeincidentFetchInterval— Incidents Fetch Intervalmax_fetch— Maximum number of incidents per fetchfirst_fetch— First fetch timeticket_types— Ticket Types
Commands (9)
-
trustwave-add-ticket-commentAdd a comment to a ticket.
-
trustwave-close-ticketClose a ticket.
-
trustwave-get-assetGet an Asset.
-
trustwave-get-findingGet a Finding.
-
trustwave-get-ticketGet a single ticket.
-
trustwave-get-updated-ticketsGet updated tickets.
-
trustwave-search-assetsSearch for Assets.
-
trustwave-search-findingsSearch for Findings.
-
trustwave-search-ticketsSearch tickets.
category: Data Enrichment & Threat Intelligence sectionorder: - Connect - Collect provider: LevelBlue commonfields: id: TrustwaveFusion version: -1 configuration: - defaultvalue: https://api.fusion.trustwave.com display: Fusion API URL name: url required: true type: 0 section: Connect - additionalinfo: The API Key to use for connection display: API Key name: apikey required: true type: 4 section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 advanced: true section: Collect - defaultvalue: '100' display: Maximum number of incidents per fetch name: max_fetch type: 0 required: false section: Collect - additionalinfo: 'Format: [number] [time unit]. e.g., 12 hours, 7 days, 2 seconds etc.' defaultvalue: 5 days display: First fetch time name: first_fetch type: 0 required: false section: Collect - additionalinfo: Types of tickets to fetch defaultvalue: INCIDENT display: Ticket Types name: ticket_types options: - CASE - INCIDENT - CHANGE type: 16 required: false section: Collect description: |- The Trustwave Fusion platform connects your organization’s digital footprint to a robust security cloud comprised of the Trustwave data lake, advanced analytics, actionable threat intelligence and a wide range of Trustwave services including Trustwave SpiderLabs , elite team of security specialists. Your team will benefit from deep visibility and the advanced security expertise necessary for protecting assets and eradicating threats as they arise. display: TrustwaveFusion name: TrustwaveFusion script: commands: - arguments: - default: true defaultValue: description: Ticket ID. name: id required: true description: Get a single ticket. name: trustwave-get-ticket outputs: - contextPath: Trustwave.Ticket.number description: 'The Ticket ID.' type: String - contextPath: Trustwave.Ticket.subject description: 'The ticket title.' type: String - contextPath: Trustwave.Ticket.status description: 'The status of the ticket.' type: String - contextPath: Trustwave.Ticket.description description: 'The detailed ticket description.' type: String - contextPath: Trustwave.Ticket.category description: 'Ticket category.' type: String - contextPath: Trustwave.Ticket.createdBy description: 'User that created the ticket.' type: String - contextPath: Trustwave.Ticket.createdOn description: 'The ticket creation time.' type: Date - contextPath: Trustwave.Ticket.customerName description: 'The name of the customer.' type: String - contextPath: Trustwave.Ticket.findings.classification description: 'Category for finding related to the ticket.' type: String - contextPath: Trustwave.Ticket.findings.classificationCode description: 'Category code for finding related to the ticket.' type: String - contextPath: Trustwave.Ticket.findings.findingId description: 'Id finding related to the ticket.' type: String - contextPath: Trustwave.Ticket.formatted_notes description: 'Human readable Notes for the ticket.' type: String - contextPath: Trustwave.Ticket.impact description: 'Ticket impact (HIGH, MEDIUM, LOW).' type: String - contextPath: Trustwave.Ticket.notes.actor description: 'User that added the note (comment).' type: String - contextPath: Trustwave.Ticket.notes.text description: 'The note (comment) text.' type: String - contextPath: Trustwave.Ticket.notes.timestamp description: 'Time when the note (comment) was created.' type: Date - contextPath: Trustwave.Ticket.priority description: 'Ticket priority (CRITICAL, HIGH, MEDIUM, LOW).' type: String - contextPath: Trustwave.Ticket.subCategory description: 'Ticket sub-category.' type: String - contextPath: Trustwave.Ticket.type description: 'The ticket type (CASE, INCIDENT, CHANGE).' type: String - contextPath: Trustwave.Ticket.updatedOn description: 'When the ticket was last updated.' type: Date - contextPath: Trustwave.Ticket.urgency description: 'The ticket urgency (HIGH, MEDIUM, LOW).' type: String - arguments: - defaultValue: description: Ticket ID. name: id - defaultValue: description: Ticket Subject. name: subject - auto: PREDEFINED defaultValue: description: Ticket type to query. isArray: true name: type predefined: - INCIDENT - CASE - CHANGE - auto: PREDEFINED defaultValue: description: Ticket status. isArray: true name: status predefined: - NEW - OPEN - IN_PROGRESS - AWAITING_INFO - ON_HOLD - RESOLVED - CLOSED - CANCELED - SCHEDULED - auto: PREDEFINED defaultValue: description: Ticket priority. isArray: true name: priority predefined: - CRITICAL - HIGH - MEDIUM - LOW - auto: PREDEFINED defaultValue: description: Ticket impact. isArray: true name: impact predefined: - HIGH - MEDIUM - LOW - auto: PREDEFINED defaultValue: description: Ticket urgency. isArray: true name: urgency predefined: - HIGH - MEDIUM - LOW description: Search tickets. name: trustwave-search-tickets outputs: - contextPath: Trustwave.Ticket.number description: 'The Ticket ID.' type: String - contextPath: Trustwave.Ticket.subject description: 'The ticket title.' type: String - contextPath: Trustwave.Ticket.status description: 'The status of the ticket.' type: String - contextPath: Trustwave.Ticket.description description: 'The detailed ticket description.' type: String - contextPath: Trustwave.Ticket.category description: 'Ticket category.' type: String - contextPath: Trustwave.Ticket.createdBy description: 'User that created the ticket.' type: String - contextPath: Trustwave.Ticket.createdOn description: 'The time when the ticket was created.' type: Date - contextPath: Trustwave.Ticket.customerName description: 'The name of the customer.' type: String - contextPath: Trustwave.Ticket.formatted_notes description: 'Human readable notes.' type: String - contextPath: Trustwave.Ticket.impact description: 'Ticket impact (HIGH, MEDIUM, LOW).' type: String - contextPath: Trustwave.Ticket.notes.actor description: 'User that added the note (comment).' type: String - contextPath: Trustwave.Ticket.notes.text description: 'The note (comment) text.' type: String - contextPath: Trustwave.Ticket.notes.timestamp description: 'Time when the note (comment) was created.' type: Date - contextPath: Trustwave.Ticket.priority description: 'Ticket priority (CRITICAL, HIGH, MEDIUM, LOW).' type: String - contextPath: Trustwave.Ticket.subCategory description: 'Ticket sub-category.' type: String - contextPath: Trustwave.Ticket.type description: 'The ticket type (CASE, INCIDENT, CHANGE).' type: String - contextPath: Trustwave.Ticket.updatedOn description: 'When the ticket was last updated.' type: Date - contextPath: Trustwave.Ticket.urgency description: 'The ticket urgency (HIGH, MEDIUM, LOW).' type: String - arguments: - defaultValue: description: Incident ID. name: id required: true - defaultValue: description: Comment text. name: comment required: true description: Add a comment to a ticket. name: trustwave-add-ticket-comment - arguments: - defaultValue: description: Incident ID. name: id required: true - defaultValue: description: Comment text. name: comment required: true description: Close a ticket. name: trustwave-close-ticket - arguments: - defaultValue: description: Absolute or relative date to check for updates. name: since required: true - defaultValue: 100 description: Maximum number of tickets to fetch. name: fetch_limit - auto: PREDEFINED defaultValue: INCIDENT description: Ticket type to query. isArray: true name: ticket_types predefined: - INCIDENT - CASE - CHANGE description: Get updated tickets. name: trustwave-get-updated-tickets outputs: - contextPath: Trustwave.Ticket.number description: 'The Ticket ID.' type: String - contextPath: Trustwave.Ticket.subject description: 'The ticket title.' type: String - contextPath: Trustwave.Ticket.status description: 'The status of the ticket.' type: String - contextPath: Trustwave.Ticket.description description: 'The detailed ticket description.' type: String - contextPath: Trustwave.Ticket.category description: 'Ticket category.' type: String - contextPath: Trustwave.Ticket.createdBy description: 'User that created the ticket.' type: String - contextPath: Trustwave.Ticket.createdOn description: 'The time when the ticket was created.' type: Date - contextPath: Trustwave.Ticket.customerName description: 'The name of the customer.' type: String - contextPath: Trustwave.Ticket.formatted_notes description: 'Human readable notes.' type: String - contextPath: Trustwave.Ticket.impact description: 'Ticket impact (HIGH, MEDIUM, LOW).' type: String - contextPath: Trustwave.Ticket.notes.actor description: 'User that added the note (comment).' type: String - contextPath: Trustwave.Ticket.notes.text description: 'The note (comment) text.' type: String - contextPath: Trustwave.Ticket.notes.timestamp description: 'Time when the note (comment) was created.' type: Date - contextPath: Trustwave.Ticket.priority description: 'Ticket priority (CRITICAL, HIGH, MEDIUM, LOW).' type: String - contextPath: Trustwave.Ticket.subCategory description: 'Ticket sub-category.' type: String - contextPath: Trustwave.Ticket.type description: 'The ticket type (CASE, INCIDENT, CHANGE).' type: String - contextPath: Trustwave.Ticket.updatedOn description: 'When the ticket was last updated.' type: Date - contextPath: Trustwave.Ticket.urgency description: 'The ticket urgency (HIGH, MEDIUM, LOW).' type: String - arguments: - defaultValue: description: Finding ID. name: id - defaultValue: 100 description: Maximum number of Findings to return. name: limit - defaultValue: description: Name of the Finding. name: name - defaultValue: description: Finding Classification. name: classification - defaultValue: description: Finding summary. name: summary - defaultValue: description: Finding detail. name: detail - defaultValue: description: Finding priority. isArray: true name: priority auto: PREDEFINED predefined: - CRITICAL - HIGH - MEDIUM - LOW - defaultValue: description: Finding severity. isArray: true name: severity - defaultValue: description: created_since. name: created_since - defaultValue: description: Updated since. name: updated_since description: Search for Findings. name: trustwave-search-findings outputs: - contextPath: Trustwave.Finding.classification description: 'Category for the finding.' type: String - contextPath: Trustwave.Finding.createdOn description: 'Time when the finding was created.' type: Date - contextPath: Trustwave.Finding.customerName description: 'Customer name for the finding.' type: String - contextPath: Trustwave.Finding.destination description: 'Destination for finding.' type: String - contextPath: Trustwave.Finding.detail description: 'Detailed description of the finding.' type: String - contextPath: Trustwave.Finding.id description: 'The finding ID.' type: String - contextPath: Trustwave.Finding.priority description: 'The priority of the finding.' type: Number - contextPath: Trustwave.Finding.severity description: 'The severity of the finding.' type: Number - contextPath: Trustwave.Finding.source description: 'SOAR actions taken for finding.' type: String - contextPath: Trustwave.Finding.status.description description: 'Current status of the Finding.' type: String - contextPath: Trustwave.Finding.summary description: 'The name of the finding.' type: String - contextPath: Trustwave.Finding.type description: 'The type of finding (e.g. THREAT, VULNERABILITY).' type: String - contextPath: Trustwave.Finding.updatedOn description: 'Time when the finding was last updated.' type: Date - arguments: - default: true defaultValue: description: Finding ID. name: id required: true description: Get a Finding. name: trustwave-get-finding outputs: - contextPath: Trustwave.Finding.analystNotes.actor description: 'User that created the analyst note.' type: String - contextPath: Trustwave.Finding.analystNotes.text description: 'Analyst note text.' type: String - contextPath: Trustwave.Finding.analystNotes.timestamp description: 'Time when the note was created.' type: Date - contextPath: Trustwave.Finding.assetsIds description: 'Assets impacted by the finding.' type: String - contextPath: Trustwave.Finding.classification description: 'Category for the finding.' type: String - contextPath: Trustwave.Finding.createdOn description: 'Time when the finding was created.' type: Date - contextPath: Trustwave.Finding.customerName description: 'Customer name for the finding.' type: String - contextPath: Trustwave.Finding.destination description: 'Destination for finding.' type: String - contextPath: Trustwave.Finding.detail description: 'Detailed description of the finding.' type: String - contextPath: Trustwave.Finding.eventsIds description: 'List of event ID associated with the finding.' type: String - contextPath: Trustwave.Finding.id description: 'The finding ID.' type: String - contextPath: Trustwave.Finding.parentId description: 'The ID of the parent of the finding.' type: String - contextPath: Trustwave.Finding.priority description: 'The priority of the finding.' type: Number - contextPath: Trustwave.Finding.severity description: 'The severity of the finding.' type: Number - contextPath: Trustwave.Finding.source description: 'Source for finding.' type: String - contextPath: Trustwave.Finding.status.description description: 'Current status of the Finding.' type: String - contextPath: Trustwave.Finding.summary description: 'The name of the finding.' type: String - contextPath: Trustwave.Finding.type description: 'The type of finding (e.g. THREAT, VULNERABILITY).' type: String - contextPath: Trustwave.Finding.updatedOn description: 'Time when the finding was last updated.' type: Date - arguments: - default: true defaultValue: description: Asset ID. name: id required: true description: Get an Asset. name: trustwave-get-asset outputs: - contextPath: Trustwave.Asset.cidr description: 'Network address in CIDR notation.' type: String - contextPath: Trustwave.Asset.createdOn description: 'Time when the asset was created.' type: Date - contextPath: Trustwave.Asset.customerName description: 'The customer name for the asset.' type: String - contextPath: Trustwave.Asset.id description: 'The asset ID.' type: String - contextPath: Trustwave.Asset.ips description: 'List of IP addresses for the asset.' type: String - contextPath: Trustwave.Asset.lastActivity description: 'Time of the last activity associated with the asset.' type: Date - contextPath: Trustwave.Asset.name description: 'The name of the asset.' type: String - contextPath: Trustwave.Asset.networkInterfaces.gateway description: 'Gateway address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.hostnames description: 'List of hostname for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.ip description: 'IP address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.macAddress description: 'MAC address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.macVendor description: 'Vendor associated with the MAC address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.subnet description: 'Network subnet the asset network interface.' type: String - contextPath: Trustwave.Asset.os description: 'Asset operating system.' type: String - contextPath: Trustwave.Asset.services.applicationName description: 'Service name.' type: String - contextPath: Trustwave.Asset.services.applicationProtocol description: 'Service protocol.' type: String - contextPath: Trustwave.Asset.services.port description: 'Service port.' type: Number - contextPath: Trustwave.Asset.services.transportProtocol description: 'Service transport.' type: String - contextPath: Trustwave.Asset.status description: 'Asset status.' type: String - contextPath: Trustwave.Asset.type description: 'The type of asset.' type: String - contextPath: Trustwave.Asset.updatedOn description: 'Time when the asset was last updated.' type: Date - contextPath: Trustwave.Asset.uri description: 'URI of the asset.' type: String - arguments: - default: true defaultValue: description: Asset ID. name: id - defaultValue: 100 description: Maximum number of Assets to return. name: limit - defaultValue: description: Name of the Asset. name: name - defaultValue: description: OS for the Asset. isArray: true name: os - defaultValue: description: Asset Tags to search for. isArray: true name: tags - defaultValue: description: port. isArray: true name: port - defaultValue: description: Application Protocol. isArray: true name: app_protocol - defaultValue: description: Transport Protocol. isArray: true name: transport - defaultValue: description: Asset Type. isArray: true name: type - defaultValue: description: created_since. name: created_since - defaultValue: description: Updated since. name: updated_since description: Search for Assets. name: trustwave-search-assets outputs: - contextPath: Trustwave.Asset.cidr description: 'Network address in CIDR notation.' type: String - contextPath: Trustwave.Asset.createdOn description: 'Time when the asset was created.' type: Date - contextPath: Trustwave.Asset.customerName description: 'The customer name for the asset.' type: String - contextPath: Trustwave.Asset.id description: 'The asset ID.' type: String - contextPath: Trustwave.Asset.ips description: 'List of IP addresses for the asset.' type: String - contextPath: Trustwave.Asset.lastActivity description: 'Time of the last activity associated with the asset.' type: Date - contextPath: Trustwave.Asset.name description: 'The name of the asset.' type: String - contextPath: Trustwave.Asset.networkInterfaces.gateway description: 'Gateway address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.hostnames description: 'List of hostname for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.ip description: 'IP address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.macAddress description: 'MAC address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.macVendor description: 'Vendor associated with the MAC address for the asset network interface.' type: String - contextPath: Trustwave.Asset.networkInterfaces.subnet description: 'Network subnet the asset network interface.' type: String - contextPath: Trustwave.Asset.os description: 'Asset operating system.' type: String - contextPath: Trustwave.Asset.status description: 'Asset status.' type: String - contextPath: Trustwave.Asset.type description: 'The type of asset.' type: String - contextPath: Trustwave.Asset.updatedOn description: 'Time when the asset was last updated.' type: Date - contextPath: Trustwave.Asset.uri description: 'URI of the asset.' type: String dockerimage: demisto/python3:3.12.13.10116658 isfetch: true script: '' subtype: python3 type: python fromversion: 5.0.0 tests: - No tests (auto formatted)