VectraXDR

This integration allows to create incidents based on Vectra XDR Entities.

Network Security · Vectra XDR

Details

IDVectraXDR
ProviderVectra AI
CategoryNetwork Security
From Version6.8.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Overview

Vectra XDR pack empowers the SOC to create incidents using Vectra AI’s Attack Signal Intelligence. This integration was integrated and tested with Vectra API v3.3.

This integration supports only cloud instances of Vectra XDR. To configure an instance provide Server URL, Client ID and Client Secret Key.

Use cases

  1. Fetch entities and their detections from Vectra XDR.
  2. List and Describe Entities and Detections.
  3. List, Create, Update, and Resolve Entity Assignments.
  4. List Assignment Outcomes.
  5. List, Create, Update, and Delete Entity notes.
  6. List, Update, and Remove Entity tags.
  7. List, Assign, and Unassign members in Group.
  8. Mark and Unmark Entity’s detections as fixed.
  9. Download PCAP of detection.

Configure Vectra XDR on Cortex XSOAR

  1. Navigate to Settings > Integrations > Servers & Services.
  2. Search for Vectra XDR.
  3. Click Add instance to create and configure a new integration instance.
Parameter Description Required
Server URL URL of the Vectra AI platform. True
Client ID Identifies a client or application for authentication and authorization in the Vectra AI platform. True
Client Secret Key Secret key used for secure communication with the Vectra AI platform. True
Trust any certificate (not secure) When checked, no SSL certificates check will be done when interacting with the Vectra XDR API. It’s insecure. (Default - unchecked) False
Use system proxy settings Use the system proxy settings to reach with the Vectra XDR API. False
Fetch incidents   False
Max Fetch The maximum number of entities to fetch each time. If the value is greater than 200, it will be considered as 200. The maximum is 200. False
First Fetch Time The date or relative timestamp from which to begin fetching entities.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
False
Mirroring Direction The mirroring direction in which to mirror the entities. You can mirror “Incoming” (from Vectra to XSOAR), “Outgoing” (from XSOAR to Vectra), or in both directions. Cortex XSOAR only parameter. False
Re-Fetch closed incidents via mirroring If selected, new incidents will be created (via Outgoing Mirroring). If not selected, it reopens previously closed incidents (via Incoming Mirroring).

Note: This flow is triggered only when the relevant entity is still active and the previously fetched incident is closed.
False
Mirror tag for notes The tag value should be used to mirror the entity note by adding the same tag in the notes. False
Entity Type Entity Type(Host, Account). False
Prioritized Retrieve only prioritize entities based on the configuration on the Vectra platform. If not selected will fetch all entities. False
Tags Retrieve entities that contain any of the tags specified. Supports comma-separated values. False
Detection Category Retrieve detections belonging to a specified category. False
Detection Type Retrieve detections belonging to a specified detection type. False
Specify the numeric value of “Urgency Score” for mapping the Low Incident Severity. If the entity’s urgency score is equal to or less than the configured threshold, it would be considered as a “Low” Severity Incident. Default is 30. False
Specify the numeric value of “Urgency Score” for mapping the Medium Incident Severity. If the entity’s urgency score is equal to or less than the configured threshold, it would be considered as a “Medium” Severity Incident.Default is 50. False
Specify the numeric value of “Urgency Score” for mapping the High Incident Severity. If the entity’s urgency score is equal to or less than the configured threshold,
it would be considered as a “High” Severity Incident and if urgency score greater than threshold, it would be considered as a “Critical” Severity Incident. Default is 80.
False
Incident type   False
  1. Click Test to validate the URLs, token, and connection.

Configuration for fetching Vectra XDR Entity as an XSOAR Incident

To fetch Vectra XDR Entity follow the next steps:

  1. Select Fetches incidents.
  2. Under Classifier, select “N/A”.
  3. Under Incident type, select “Vectra XDR Entity”.
  4. Under Mapper (incoming), select “Vectra XDR - Incoming Mapper” for default mapping.
  5. Enter connection parameters. (Server URL, Client ID & Client Secret Key)
  6. Select SSL certificate validation and Proxy if required.
  7. Update “Max Fetch” & “First Fetch Time” based on your requirements.
  8. Select the Incident Mirroring Direction:
    1. Incoming - Mirrors changes from the Vectra XDR Entity into the Cortex XSOAR incident.
    2. Outgoing - Mirrors changes from the Cortex XSOAR incident to the Vectra XDR Entity.
    3. Incoming And Outgoing - Mirrors changes both Incoming and Outgoing directions on incidents.
  9. Check the “Re-Fetch closed incidents via mirroring” option if you want to prevent reopening of closed incidents and refetch them via mirroring on modification of an entity.
  10. Enter the relevant tag name for mirror notes.
    Note: This value is mapped to the dbotMirrorTags incident field in Cortex XSOAR, which defines how Cortex XSOAR handles notes when you tag them in the War Room. This is required for mirroring notes from Cortex XSOAR to Vectra XDR.
  11. Provide appropriate values for filtering Entities, such as Entity Type, Prioritization, and Tags. Additionally, specify filters for detections, including Detection Category and Detection Type.
    Note: Filters for Entities and Detections are combined using ‘OR’ logic, while filters within the same category(Entity, Detections) are combined using ‘AND’.
  12. Adjust the Urgency Score to categorize Entity severity in Cortex XSOAR. There are three fields for this mapping:
    1. Input a value for ‘Low’ severity. Scores up to this limit are labelled as Low.
    2. The next value is for ‘Medium’ severity. Scores up to this limit are labelled as Medium.
    3. The third value is for ‘High’ severity. Scores up to this limit are labelled as High. Any score above this is marked as ‘Critical’ severity.

Notes for mirroring:

  • This feature is compliant with XSOAR version 6.0 and above.
  • When mirroring incidents, you can make changes in Vectra that will be reflected in Cortex XSOAR, or vice versa.
  • Any tags removed from the Vectra entity will not be removed in the XSOAR incident, as XSOAR doesn’t allow the removal of the tags field via the backend. However, tags removed from the XSOAR incident UI will be removed from the Vectra entity.
  • New notes from the XSOAR incident will be created as notes in the Vectra entity. Updates to existing notes in the XSOAR incident will not be reflected in the Vectra entity.
  • New notes from the Vectra entity will be created as notes in the XSOAR incident. Updates to existing notes in the Vectra entity will create new notes in the XSOAR incident.
  • If a closed XSOAR incident is tied to a specific entity and new detections for that entity arise or existing detections become active again:
    • If “Re-Fetch closed Incidents while Mirroring” checkbox is not selected and “Incoming Mirroring” is enabled, the incident will be automatically reopened.
    • If “Re-Fetch closed Incidents while Mirroring” checkbox is selected and “Outgoing Mirroring” is enabled, a new incident will be created for the entity.
  • When a XSOAR incident is closed but there are still active detections on the Vectra side, and the entity is subsequently updated:
    • If “Re-Fetch closed Incidents while Mirroring” checkbox is not selected and “Incoming Mirroring” is enabled, the corresponding XSOAR incident for that entity will be reopened.
    • If “Re-Fetch closed Incidents while Mirroring” checkbox is selected and “Outgoing Mirroring” is enabled, a new incident will be created for the entity.
  • The mirroring settings apply only for incidents that are fetched after applying the settings.
  • The mirroring is strictly tied to Incident type “Vectra XDR Entity” & Incoming mapper “Vectra XDR - Incoming Mapper” If you want to change or use your custom incident type/mapper then make sure changes related to these are present.
  • If you want to use the mirror mechanism and you’re using custom mappers, then the incoming mapper must contain the following fields: dbotMirrorDirection, dbotMirrorId, dbotMirrorInstance, and dbotMirrorTags.
  • To use a custom mapper, you must first duplicate the mapper and update the fields in the copy of the mapper. (Refer to the “Create a custom mapper consisting of the default Vectra XDR mapper” section for more information.)
  • Following new fields are introduced in the response of the incident to enable the mirroring:
    • mirror_direction: This field determines the mirroring direction for the incident. It is a required field for XSOAR to enable mirroring support.
    • mirror_tags: This field determines what would be the tag needed to mirror the XSOAR entry out to Vectra XDR. It is a required field for XSOAR to enable mirroring support.
    • mirror_instance: This field determines from which instance the XSOAR incident was created. It is a required field for XSOAR to enable mirroring support.

Create a custom mapper consisting of the default Vectra XDR mapper

  1. Go to the settings -> Object setup -> Incidents.
  2. Navigate to the “Classification and Mapping” tab.
  3. Select the Mapper “Vectra XDR - Incoming Mapper”.
  4. Create a copy of that mapper and click on it. (You can rename the mapper.)
  5. Under the Incident Type dropdown, verify that the type of Mapper is “Vectra XDR Entity”.
  6. Click on “Choose data path” and map it to the custom field:
    • Find the context field you want to map to this incident field on the right side and click on its value.
    • Then you will see the path you’ve selected under your newly added field
    • Note: You can also type the path manually.
  7. Click “Save Version”.
  8. Created mapper will appear in the drop-down for the “Mapper (incoming)” integration instance settings fields.
  9. Select the newly added mapper at the time of instance configuration.

Create a custom layout consisting of the default Vectra XDR layout

  1. Go to the settings -> Object setup -> Incidents.
  2. Navigate to the “Layouts” tab.
  3. Select the layout “Vectra XDR Entity”.
  4. Create a copy of that layout and click on it. (You can rename the layout.)
  5. Select the newly created layout and click on edit.
    • To create a new section, drag and drop the “New Section” widget into the layout.
    • To add a new field to the layout, navigate to the “Fields and Buttons” section and search for the field. Drag and drop the field widget in the layout.
  6. Once done, select “Save Version”.
  7. Navigate to the “Incident Type” tab and select “Vectra XDR Entity” type and detach it.
  8. Attach the newly created layout.
  9. Reattach the same “Incident Type” again else this incident type will not receive any new updates.

Note: It is recommended to use out-of-the-box mappers, layout & incident types for better visualization and meaningful mappings. If you are changing any out-of-the-box mappers/layout then it might not render all the fields as per the expectation.

Troubleshooting

Receive Notification on an Incident Fetch Error

The administrator and Cortex XSOAR users on the recipient’s list receive a notification when an integration experiences an incident fetch error. Cortex XSOAR users can select their notification method, such as email, from their user preferences. Refer to Cortex XSOAR 6.13 documentation or Cortex XSOAR 8 Cloud documentation or Cortex XSOAR 8.7 On-prem documentation for more information.

The following are tips for handling issues with mirroring incidents between Vectra XDR and Cortex XSOAR.

Issue Recommendation
Mirroring is not working. Open Context Data and search for dbot. Confirm the dbot fields are configured correctly either through the mapper for that specific incident type or using setIncident. Specifically, make sure the integration instance is configured correctly for the mirroring direction (incoming, outgoing, both) - dbotMirrorId, dbotMirrorDirection, dbotMirrorInstance, dbotMirrorTags.
Required fields are not getting sent or not visible in UI. This may be a mapping issue, specifically if you have used a custom mapper make sure you’ve covered all the out of box mapper fields.
Notes from XSOAR have not been mirrored in Vectra XDR Tag is required for mirroring notes from Cortex XSOAR to Vectra XDR. There might be a reason the note is not tagged as the tag needs to be added manually in XSOAR.
Click Actions > Tags and add the “note” tag (OR the specific tag name which was set up on Instance Configuration).

Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

vectra-user-list


Returns a list of users.

Base Command

vectra-user-list

Input

Argument Name Description Required
username Filter by username. Optional
role Filter users with the specified role. Possible values are: Admin, Read-Only, Restricted Admin, Security Analyst, Setting Admin, Super Admin. Optional
last_login_timestamp Return only the users which have a last login timestamp equal to or after the given timestamp.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
Optional

Context Output

Path Type Description
Vectra.User.id Number The ID of the User.
Vectra.User.user_id Number The ID of the User.
Vectra.User.username String Username of the user.
Vectra.User.email String The email associated with the user.
Vectra.User.role String The role associated with the user.
Vectra.User.last_login_timestamp String Last login timestamp in UTC format of the user.
Vectra.User.last_login String Last login timestamp of the user.

Command example


#### Context Example

```json
{
  "Vectra": {
    "User": [
      {
        "id": 59,
        "user_id": 59,
        "username": "user.name1",
        "email": "",
        "role": "Security Analyst",
        "last_login_timestamp": "2023-08-22T09:24:44Z",
        "last_login": "2023-08-22T09:24:44Z"
      },
      {
        "id": 32,
        "user_id": 32,
        "username": "user.name2",
        "email": "",
        "role": "Super Admin",
        "last_login_timestamp": "2023-07-02T18:41:19Z",
        "last_login": "2023-07-02T18:41:19Z"
      },
      {
        "id": 23,
        "user_id": 23,
        "username": "vectra_mdr",
        "email": "",
        "role": "Vectra MDR"
      }
    ]
  }
}

Human Readable Output

Users Table

User ID User Name Role Last Login Timestamp
59 user.name1 Security Analyst 2023-08-22T09:24:44Z
32 user.name2 Super Admin 2023-07-02T18:41:19Z
23 vectra_mdr Vectra MDR  

vectra-entity-list


Returns a list of entities.

Base Command

vectra-entity-list

Input

Argument Name Description Required
prioritized Fetch only entities whose priority score is above the configured priority threshold will be included in the response. Possible values are: true, false. Optional
entity_type Specify the type of the entity. Possible values are: account, host. Optional
name Filter by matching entity name. Optional
tags Filter by a tag or a comma-separated list of tags. Optional
state Filter on entity activation state. Possible values are: active, inactive. Optional
ordering Orders records by last timestamp or urgency score. Default sorting is by urgency score in descending order. Use the minus symbol (-) to sort scores in descending order. Multiple ordering fields can be specified with a comma-separated list (e.g., ordering=urgency_score,-name). Optional
last_detection_timestamp Return only the entities which have a last detection timestamp equal to or after the given timestamp.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
Optional
page Enables the caller to specify a particular page of results. Default is 1. Optional
page_size Specify the desired page size for the request. Maximum is 5000. Default is 50. Optional
last_modified_timestamp Return only the entities which have a last modified timestamp equal to or after the given timestamp.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
Optional

Context Output

Path Type Description
Vectra.Entity.id Number ID of the entity.
Vectra.Entity.name String Name of the entity.
Vectra.Entity.breadth_contrib Number Breadth contribution of the entity.
Vectra.Entity.importance Number Entity importance.
Vectra.Entity.type String Type of the entity.
Vectra.Entity.is_prioritized Boolean Entity is prioritized or not.
Vectra.Entity.severity String Severity of the entity.
Vectra.Entity.urgency_score Number Urgency score of the entity.
Vectra.Entity.velocity_contrib Number Velocity contribution of the entity.
Vectra.Entity.detection_set String Set of detections related to entity.
Vectra.Entity.last_detection_timestamp Date Time of the last detection activity related to entity.
Vectra.Entity.notes.id String Notes of the entity.
Vectra.Entity.notes.dateCreated String Created date of the Note.
Vectra.Entity.notes.dateModified String Modified date of the Note.
Vectra.Entity.notes.createdBy String Created user of the Note.
Vectra.Entity.notes.ModifiedBy String Modified user of the Note.
Vectra.Entity.notes.note String Note of the entity.
Vectra.Entity.attack_rating Number Attack Ratting of the entity.
Vectra.Entity.privilege_level String Privilege Level of the entity.
Vectra.Entity.privilege_category String Privilege Category of the entity.
Vectra.Entity.attack_profile String Attack Profile of the entity.
Vectra.Entity.sensors Unknown Sensors of the entity.
Vectra.Entity.state String State of the entity.
Vectra.Entity.tags Unknown Tags of the entity.
Vectra.Entity.url String Url link of the entity.
Vectra.Entity.host_type Unknown Host type of the entity.
Vectra.Entity.account_type String Account type of the entity.

Command example

!vectra-entity-list entity_type=account page=1 page_size=4 tags=test,test1 prioritized=true state=active

Context Example

{
  "Vectra.Entity(val.id && val.id == obj.id)": [
    {
      "id": 334,
      "name": "account_name",
      "breadth_contrib": 2,
      "entity_importance": 1,
      "importance": 2,
      "entity_type": "account",
      "type": "account",
      "is_prioritized": true,
      "severity": "Critical",
      "urgency_score": 100,
      "velocity_contrib": 2,
      "detection_set": [
        "http://server_url.com/api/v3.3/detections/1933",
        "http://server_url.com/api/v3.3/detections/1934"
      ],
      "last_detection_timestamp": "2023-05-15T09:39:24Z",
      "last_modified_timestamp": "2023-07-27T08:56:09Z",
      "notes": [],
      "attack_rating": 10,
      "attack_profile": "AWS Threat Actor",
      "sensors": [
        "test"
      ],
      "state": "active",
      "tags": [
        "test"
      ],
      "url": "http://server_url.com/api/v3.3/accounts/334",
      "account_type": [
        "o365"
      ]
    },
    {
      "id": 335,
      "name": "account_name_1",
      "breadth_contrib": 2,
      "entity_importance": 1,
      "importance": 2,
      "entity_type": "account",
      "type": "account",
      "is_prioritized": true,
      "severity": "Critical",
      "urgency_score": 80,
      "velocity_contrib": 2,
      "detection_set": [
        "http://server_url.com/api/v3.3/detections/1935",
        "http://server_url.com/api/v3.3/detections/1937"
      ],
      "last_detection_timestamp": "2023-05-15T09:41:24Z",
      "last_modified_timestamp": "2023-07-27T08:56:09Z",
      "notes": [],
      "attack_rating": 6,
      "attack_profile": "attack1",
      "sensors": [],
      "state": "active",
      "tags": [
        "test",
        "test1"
      ],
      "url": "http://server_url.com/api/v3.3/accounts/335",
      "account_type": [
        "o365"
      ]
    },
    {
      "id": 337,
      "name": "account_name_2",
      "breadth_contrib": 2,
      "entity_importance": 1,
      "importance": 1,
      "entity_type": "account",
      "type": "account",
      "is_prioritized": true,
      "severity": "Critical",
      "urgency_score": 40,
      "velocity_contrib": 2,
      "detection_set": [
        "http://server_url.com/api/v3.3/detections/1835",
        "http://server_url.com/api/v3.3/detections/1837"
      ],
      "last_detection_timestamp": "2023-05-15T09:40:24Z",
      "last_modified_timestamp": "2023-07-27T08:56:09Z",
      "notes": [],
      "attack_rating": 9,
      "attack_profile": "attack2",
      "sensors": [],
      "state": "active",
      "tags": [
        "test1"
      ],
      "url": "http://server_url.com/api/v3.3/accounts/337",
      "account_type": [
        "aws"
      ]
    },
    {
      "id": 339,
      "name": "account_name_3",
      "breadth_contrib": 2,
      "entity_importance": 1,
      "importance": 2,
      "entity_type": "account",
      "type": "account",
      "is_prioritized": true,
      "severity": "Critical",
      "urgency_score": 21,
      "velocity_contrib": 2,
      "detection_set": [
        "http://server_url.com/api/v3.3/detections/1735",
        "http://server_url.com/api/v3.3/detections/1737"
      ],
      "last_detection_timestamp": "2023-05-15T09:44:24Z",
      "last_modified_timestamp": "2023-07-27T08:56:09Z",
      "notes": [],
      "attack_rating": 5,
      "attack_profile": "attack3",
      "sensors": [],
      "state": "active",
      "tags": [
        "test"
      ],
      "url": "http://server_url.com/api/v3.3/accounts/339",
      "account_type": [
        "o365"
      ]
    }
  ]
}

Human Readable Output

Entities Table (Showing Page 1 out of 1)

ID Name Entity Type Urgency Score Entity Importance Last Detection Timestamp Last Modified Timestamp Detections IDs Prioritize State Tags
334 account_name account 100 High 2023-05-15T09:39:24Z 2023-07-18T09:44:24Z 1933, 1934 true active test
335 account_name_1 account 80 High 2023-05-15T09:41:24Z 2023-07-17T09:44:24Z 1935, 1937 true active test, test1
337 account_name_2 account 40 Medium 2023-05-15T09:40:24Z 2023-07-16T09:44:24Z 1835, 1837 true active test1
339 account_name_3 account 21 High 2023-05-15T09:44:24Z 2023-07-15T09:44:24Z 1735, 1737 true active test

vectra-entity-describe


Describes an entity by ID.

Base Command

vectra-entity-describe

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: host and account. Required

Context Output

Path Type Description
Vectra.Entity.id Number ID of the entity.
Vectra.Entity.name String Name of the entity.
Vectra.Entity.breadth_contrib Number Breadth contribution of the entity.
Vectra.Entity.importance Number Entity importance.
Vectra.Entity.type String Type of the entity.
Vectra.Entity.is_prioritized Boolean Entity is prioritized or not.
Vectra.Entity.severity String Severity of the entity.
Vectra.Entity.urgency_score Number Urgency score of the entity.
Vectra.Entity.velocity_contrib Number Velocity contribution of the entity.
Vectra.Entity.detection_set String Set of detections related to the entity.
Vectra.Entity.last_detection_timestamp Date Time of the last detection activity related to the entity.
Vectra.Entity.last_modified_timestamp Date Time of the last modification activity related to the entity.
Vectra.Entity.notes.id String Notes of the entity.
Vectra.Entity.notes.dateCreated String Created date of the Note.
Vectra.Entity.notes.dateModified String Modified date of the Note.
Vectra.Entity.notes.createdBy String Created user of the Note.
Vectra.Entity.notes.ModifiedBy String Modified user of the Note.
Vectra.Entity.notes.note String Note of the entity.
Vectra.Entity.attack_rating Number Attack Ratting of the entity.
Vectra.Entity.privilege_level String Privilege Level of the entity.
Vectra.Entity.privilege_category String Privilege Category of the entity.
Vectra.Entity.attack_profile String Attack Profile of the entity.
Vectra.Entity.sensors Unknown Sensors of the entity.
Vectra.Entity.state String State of the entity.
Vectra.Entity.tags Unknown Tags of the entity.
Vectra.Entity.url String Url link of the entity.
Vectra.Entity.host_type Unknown Host type of the entity.
Vectra.Entity.account_type Unknown Account type of the entity.

Command example

!vectra-entity-describe entity_type=account entity_id=334

Context Example

{
  "Vectra.Entity(val.id && val.id == obj.id && val.type && val.type == obj.type)": {
    "id": 334,
    "name": "account_name",
    "breadth_contrib": 2,
    "entity_importance": 1,
    "importance": 2,
    "entity_type": "account",
    "type": "account",
    "is_prioritized": true,
    "severity": "Critical",
    "urgency_score": 100,
    "velocity_contrib": 2,
    "detection_set": [
      "http://server_url.com/api/v3.3/detections/1933",
      "http://server_url.com/api/v3.3/detections/1934"
    ],
    "last_detection_timestamp": "2023-05-15T09:39:24Z",
    "last_modified_timestamp": "2023-07-28T05:25:47Z",
    "notes": [],
    "attack_rating": 10,
    "attack_profile": "test_attack",
    "sensors": [
      "test"
    ],
    "state": "active",
    "tags": [
      "test"
    ],
    "url": "http://server_url.com/api/v3.3/accounts/334",
    "account_type": [
      "o365"
    ]
  }
}

Human Readable Output

Entity detail

Entity ID: 334

Name Entity Type Urgency Score Entity Importance Last Detection Timestamp Last Modified Timestamp Detections IDs Prioritize State Tags
account_name account 100 High 2023-05-15T09:39:24Z 2023-07-28T05:25:47Z 1933, 1934 true active test

vectra-entity-detection-list


Returns a list of detections for a specified entity.

Base Command

vectra-entity-detection-list

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required
page Enables the caller to specify a particular page of results. Default is 1. Optional
page_size Specify the desired page size for the request. Maximum is 5000. Default is 50. Optional
detection_category The category of the detection. Possible values are: Command & Control, Botnet, Reconnaissance, Lateral Movement, Exfiltration, Info. Optional
detection_type Filter by detection type. Optional
last_timestamp Return only the detections which have a last timestamp equal to or after the given timestamp.
Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours.
Example: 2023-04-25T00:00:00Z, 2023-04-25, 2 days, 5 hours, 01 Mar 2023, 01 Feb 2023 04:45:33, 15 Jun.
Optional
detection_name Filter by detection name. Optional
state Filter by state. Default is active. Optional
tags Filter by a tag or a comma-separated list of tags. Optional

Context Output

Path Type Description
Vectra.Entity.Detections.id Number Entity detection ID.
Vectra.Entity.Detections.assigned_date Unknown Date assigned to the detection.
Vectra.Entity.Detections.assigned_to Unknown User or entity assigned to the detection.
Vectra.Entity.Detections.category String Category of the detection.
Vectra.Entity.Detections.certainty Number Certainty level of the detection.
Vectra.Entity.Detections.c_score Number Confidence score of the detection.
Vectra.Entity.Detections.description String Description of the detection.
Vectra.Entity.Detections.detection String Detection information.
Vectra.Entity.Detections.detection_category String Category of the detection.
Vectra.Entity.Detections.detection_type String Type of the detection.
Vectra.Entity.Detections.grouped_details.external_target.ip String IP address of the external target in the detection group.
Vectra.Entity.Detections.grouped_details.external_target.name String Name of the external target in the detection group.
Vectra.Entity.Detections.grouped_details.num_sessions Number Number of sessions in the detection group.
Vectra.Entity.Detections.grouped_details.bytes_received Number Total bytes received in the detection group.
Vectra.Entity.Detections.grouped_details.bytes_sent Number Total bytes sent in the detection group.
Vectra.Entity.Detections.grouped_details.ja3_hashes String JA3 hashes in the detection group.
Vectra.Entity.Detections.grouped_details.ja3s_hashes String JA3S hashes in the detection group.
Vectra.Entity.Detections.grouped_details.sessions.tunnel_type String Tunnel type used in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.protocol String Protocol used in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.app_protocol String Application protocol used in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_port Number Destination port in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_ip String Destination IP address in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.bytes_received Number Total bytes received in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.bytes_sent Number Total bytes sent in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.first_timestamp Date First timestamp of the sessions in the detection group.
Vectra.Entity.Detections.grouped_details.sessions.last_timestamp Date Last timestamp of the sessions in the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_geo Unknown Geolocation of the destination IP in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lat Unknown Latitude of the destination IP in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lon Unknown Longitude of the destination IP in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.first_timestamp Date First timestamp of the detection group.
Vectra.Entity.Detections.grouped_details.last_timestamp Date Last timestamp of the detection group.
Vectra.Entity.Detections.grouped_details.dst_ips String Destination IP addresses in the detection group.
Vectra.Entity.Detections.grouped_details.dst_ports Number Destination ports in the detection group.
Vectra.Entity.Detections.grouped_details.target_domains String Target domains in the detection group.
Vectra.Entity.Detections.is_targeting_key_asset Boolean Indicates if the detection is targeting a key asset.
Vectra.Entity.Detections.last_timestamp Date Last timestamp of the detection.
Vectra.Entity.Detections.note Unknown Note associated with the detection.
Vectra.Entity.Detections.note_modified_by Unknown User or entity who last modified the note.
Vectra.Entity.Detections.note_modified_timestamp Unknown Timestamp when the note was last modified.
Vectra.Entity.Detections.notes Unknown Additional notes related to the detection.
Vectra.Entity.Detections.sensor_name String Name of the sensor associated with the detection.
Vectra.Entity.Detections.src_account.id Number ID of the source account associated with the detection.
Vectra.Entity.Detections.src_account.name String Name of the source account associated with the detection.
Vectra.Entity.Detections.src_account.url String URL of the source account associated with the detection.
Vectra.Entity.Detections.src_account.threat Number Threat level of the source account associated with the detection.
Vectra.Entity.Detections.src_account.certainty Number Certainty level of the source account associated with the detection.
Vectra.Entity.Detections.src_account.privilege_level Number Privilege level of the source account associated with the detection.
Vectra.Entity.Detections.src_account.privilege_category String Privilege category of the source account associated with the detection.
Vectra.Entity.Detections.src_host.id Number ID of the source host in the detection.
Vectra.Entity.Detections.src_host.ip String IP address of the source host in the detection.
Vectra.Entity.Detections.src_host.name String Name of the source host in the detection.
Vectra.Entity.Detections.src_host.url String URL associated with the source host in the detection.
Vectra.Entity.Detections.src_host.is_key_asset Boolean Indicates if the source host is a key asset.
Vectra.Entity.Detections.src_host.groups Unknown Groups associated with the source host in the detection.
Vectra.Entity.Detections.src_host.threat Number Threat level associated with the source host in the detection.
Vectra.Entity.Detections.src_host.certainty Number Certainty level associated with the source host in the detection.
Vectra.Entity.Detections.src_ip String Source IP address in the detection.
Vectra.Entity.Detections.state String State of the detection.
Vectra.Entity.Detections.summary.num_events Number Total number of events related to the detection.
Vectra.Entity.Detections.summary.bytes_received Number Total bytes received in the detection summary.
Vectra.Entity.Detections.summary.bytes_sent Number Total bytes sent in the detection summary.
Vectra.Entity.Detections.summary.cnc_server String CNC server associated with the detection summary.
Vectra.Entity.Detections.summary.num_events Number Total number of events related to the detection.
Vectra.Entity.Detections.summary.probable_owner Unknown Probable owner of the detection summary.
Vectra.Entity.Detections.summary.sessions Number Total sessions in the detection summary.
Vectra.Entity.Detections.tags Unknown Tags associated with the detection.
Vectra.Entity.Detections.threat Number Threat level of the detection.
Vectra.Entity.Detections.t_score Number T-score of the detection.
Vectra.Entity.Detections.type String Type of the detection.
Vectra.Entity.Detections.url String URL associated with the detection.

Command example

!vectra-entity-detection-list entity_id=1

Context Example

{
  "Vectra.Entity.Detections(val.id && val.id == obj.id)": [
    {
      "id": 132,
      "category": "exfiltration",
      "certainty": 70,
      "c_score": 70,
      "description": "",
      "detection": "Data Smuggler",
      "detection_category": "exfiltration",
      "detection_type": "smuggler",
      "grouped_details": [
        {
          "event_id": "ec2162c7-e526-4446-a549-71558743a1d7",
          "event_name": "UpdateAssumeRolePolicy",
          "aws_account_id": "aws_account_id",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"roleName\": \"stratus-red-team-backdoor-r-role\", \"policyDocument\": \"{\\\"Version\\\": \\\"2012-10-17\\\", \\\"Statement\\\": {\\\"Effect\\\": \\\"Allow\\\", \\\"Principal\\\": {\\\"AWS\\\": \\\"arn:aws:iam::123456789012:root\\\"}, \\\"Action\\\": \\\"sts:AssumeRole\\\"}}\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_id",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "stratus-red-team_06e15b96-ee6b-482c-aff4-4f2f4a46a67c"
          ],
          "last_timestamp": "2023-06-06T17:01:04Z"
        },
        {
          "event_id": "89a098eb-1198-4e2a-9fa4-ef568ae39403",
          "event_name": "UpdateAssumeRolePolicy",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"policyDocument\": \"{\\\"Version\\\": \\\"2012-10-17\\\", \\\"Statement\\\": {\\\"Effect\\\": \\\"Allow\\\", \\\"Principal\\\": {\\\"AWS\\\": \\\"arn:aws:iam::123456789012:root\\\"}, \\\"Action\\\": \\\"sts:AssumeRole\\\"}}\", \"roleName\": \"stratus-red-team-backdoor-r-role\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "stratus-red-team_a24eac3a-4fee-46ce-bc37-b4e675343fc9"
          ],
          "last_timestamp": "2023-06-06T15:40:43Z"
        }
      ],
      "is_targeting_key_asset": false,
      "last_timestamp": "2023-06-06T17:01:04Z",
      "notes": [],
      "sensor_name": "mafosb50",
      "src_account": {
        "id": 21,
        "name": "account_name",
        "url": "http://server_url.com/api/v3.3/accounts/21",
        "threat": 76,
        "certainty": 35
      },
      "src_ip": "0.0.0.0",
      "state": "active",
      "tags": [],
      "threat": 80,
      "t_score": 80,
      "type": "account",
      "url": "http://server_url.com/api/v3.3/detections/132"
    },
    {
      "id": 135,
      "category": "lateral_movement",
      "certainty": 50,
      "c_score": 50,
      "description": "",
      "detection": "AWS Suspect Admin Privilege Granting",
      "detection_category": "lateral_movement",
      "detection_type": "aws_admin_privilege_granted",
      "grouped_details": [
        {
          "event_id": "85d88db5-cf2d-4b6e-9411-d3119d9920e0",
          "event_name": "AttachRolePolicy",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"roleName\":\"stratus-red-team-backdoor-r-role\",\"policyArn\":\"arn:aws:iam::aws:policy/AdministratorAccess\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_5077134d-32ea-4403-996b-de30d7f278d7 HashiCorp-terraform-exec/0.17.3"
          ],
          "last_timestamp": "2023-06-06T17:00:46Z"
        },
        {
          "event_id": "ca157e7c-9a53-4012-9288-e6ac1c488fbc",
          "event_name": "AttachRolePolicy",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"roleName\":\"stratus-red-team-backdoor-r-role\",\"policyArn\":\"arn:aws:iam::aws:policy/AdministratorAccess\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_01be8427-d1b5-4c18-8edb-0301c8e66c8e HashiCorp-terraform-exec/0.17.3"
          ],
          "last_timestamp": "2023-06-06T15:40:07Z"
        }
      ],
      "is_targeting_key_asset": false,
      "last_timestamp": "2023-06-06T17:00:46Z",
      "notes": [],
      "sensor_name": "mafosb50",
      "src_account": {
        "id": 21,
        "name": "account_name",
        "url": "http://server_url.com/api/v3.3/accounts/21",
        "threat": 76,
        "certainty": 35
      },
      "src_ip": "0.0.0.0",
      "state": "fixed",
      "summary": {
      },
      "tags": [],
      "threat": 60,
      "t_score": 60,
      "type": "account",
      "url": "http://server_url.com/api/v3.3/detections/135"
    },
    {
      "id": 140,
      "category": "reconnaissance",
      "certainty": 40,
      "c_score": 40,
      "description": "",
      "detection": "RPC Targeted Recon",
      "detection_category": "reconnaissance",
      "detection_type": "rpc_recon_1to1",
      "grouped_details": [
        {
          "event_id": "cf9f469b-0a8e-47c6-85eb-5a0486292e58",
          "event_name": "ModifySnapshotAttribute",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-west-2",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"snapshotId\":\"snap-0f7d022a2f4f67e08\",\"createVolumePermission\":{\"add\":{\"items\":[{\"userId\":\"012345678912\"}]}},\"attributeType\":\"CREATE_VOLUME_PERMISSION\"}"
          ],
          "response_elements": [
            "{\"requestId\":\"350c1eb8-b696-4d94-88d4-a764a0eed08b\",\"_return\":true}"
          ],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "stratus-red-team_a4dd596b-7a8d-4e77-a74d-13f19adf4403"
          ],
          "last_timestamp": "2023-06-06T15:46:28Z"
        }
      ],
      "is_targeting_key_asset": false,
      "last_timestamp": "2023-06-06T15:46:28Z",
      "notes": [],
      "sensor_name": "mafosb50",
      "src_account": {
        "id": 21,
        "name": "account_name",
        "url": "http://server_url.com/api/v3.3/accounts/21",
        "threat": 76,
        "certainty": 35
      },
      "src_ip": "0.0.0.0",
      "state": "fixed",
      "summary": {
      },
      "tags": [],
      "threat": 60,
      "t_score": 60,
      "type": "account",
      "url": "http://server_url.com/api/v3.3/detections/140"
    }
  ]
}

Human Readable Output

Detections Table (Showing Page 1 out of 1)

ID Detection Name Detection Type Category Account Name Src IP Threat Score Certainty Score Number Of Events State Last Timestamp
132 Data Smuggler smuggler exfiltration account_name 0.0.0.0 80 70 0 active 2023-06-06T17:01:04Z
135 AWS Suspect Admin Privilege Granting aws_admin_privilege_granted lateral_movement account_name 0.0.0.0 60 50 0 fixed 2023-06-06T17:00:46Z
140 RPC Targeted Recon rpc_recon_1to1 reconnaissance account_name 0.0.0.0 60 40 0 fixed 2023-06-06T15:46:28Z

vectra-detection-describe


Returns a list of detections for the specified detection ID(s).

Base Command

vectra-detection-describe

Input

Argument Name Description Required
detection_ids Specify the ID(s) of the detections. Required
page Enables the caller to specify a particular page of results. Default is 1. Optional
page_size Specify the desired page size for the request. Maximum is 5000. Default is 50. Optional

Context Output

Path Type Description
Vectra.Entity.Detections.id Number Entity detection ID.
Vectra.Entity.Detections.assigned_date Unknown Date assigned to the detection.
Vectra.Entity.Detections.assigned_to Unknown User or entity assigned to the detection.
Vectra.Entity.Detections.category String Category of the detection.
Vectra.Entity.Detections.certainty Number Certainty level of the detection.
Vectra.Entity.Detections.c_score Number Confidence score of the detection.
Vectra.Entity.Detections.description String Description of the detection.
Vectra.Entity.Detections.detection String Detection information.
Vectra.Entity.Detections.detection_category String Category of the detection.
Vectra.Entity.Detections.detection_type String Type of the detection.
Vectra.Entity.Detections.grouped_details.external_target.ip String IP address of the external target in the detection group.
Vectra.Entity.Detections.grouped_details.external_target.name String Name of the external target in the detection group.
Vectra.Entity.Detections.grouped_details.num_sessions Number Number of sessions in the detection group.
Vectra.Entity.Detections.grouped_details.bytes_received Number Total bytes received in the detection group.
Vectra.Entity.Detections.grouped_details.bytes_sent Number Total bytes sent in the detection group.
Vectra.Entity.Detections.grouped_details.ja3_hashes String JA3 hashes in the detection group.
Vectra.Entity.Detections.grouped_details.ja3s_hashes String JA3S hashes in the detection group.
Vectra.Entity.Detections.grouped_details.sessions.tunnel_type String Tunnel type used in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.protocol String Protocol used in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.app_protocol String Application protocol used in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_port Number Destination port in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_ip String Destination IP address in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.bytes_received Number Total bytes received in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.bytes_sent Number Total bytes sent in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.first_timestamp Date First timestamp of the sessions in the detection group.
Vectra.Entity.Detections.grouped_details.sessions.last_timestamp Date Last timestamp of the sessions in the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_geo Unknown Geolocation of the destination IP in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lat Unknown Latitude of the destination IP in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lon Unknown Longitude of the destination IP in the sessions of the detection group.
Vectra.Entity.Detections.grouped_details.first_timestamp Date First timestamp of the detection group.
Vectra.Entity.Detections.grouped_details.last_timestamp Date Last timestamp of the detection group.
Vectra.Entity.Detections.grouped_details.dst_ips String Destination IP addresses in the detection group.
Vectra.Entity.Detections.grouped_details.dst_ports Number Destination ports in the detection group.
Vectra.Entity.Detections.grouped_details.target_domains String Target domains in the detection group.
Vectra.Entity.Detections.is_targeting_key_asset Boolean Indicates if the detection is targeting a key asset.
Vectra.Entity.Detections.last_timestamp Date Last timestamp of the detection.
Vectra.Entity.Detections.note Unknown Note associated with the detection.
Vectra.Entity.Detections.note_modified_by Unknown User or entity who last modified the note.
Vectra.Entity.Detections.note_modified_timestamp Unknown Timestamp when the note was last modified.
Vectra.Entity.Detections.notes Unknown Additional notes related to the detection.
Vectra.Entity.Detections.sensor_name String Name of the sensor associated with the detection.
Vectra.Entity.Detections.src_account.id Number ID of the source account associated with the detection.
Vectra.Entity.Detections.src_account.name String Name of the source account associated with the detection.
Vectra.Entity.Detections.src_account.url String URL of the source account associated with the detection.
Vectra.Entity.Detections.src_account.threat Number Threat level of the source account associated with the detection.
Vectra.Entity.Detections.src_account.certainty Number Certainty level of the source account associated with the detection.
Vectra.Entity.Detections.src_account.privilege_level Number Privilege level of the source account associated with the detection.
Vectra.Entity.Detections.src_account.privilege_category String Privilege category of the source account associated with the detection.
Vectra.Entity.Detections.src_host.id Number ID of the source host in the detection.
Vectra.Entity.Detections.src_host.ip String IP address of the source host in the detection.
Vectra.Entity.Detections.src_host.name String Name of the source host in the detection.
Vectra.Entity.Detections.src_host.url String URL associated with the source host in the detection.
Vectra.Entity.Detections.src_host.is_key_asset Boolean Indicates if the source host is a key asset.
Vectra.Entity.Detections.src_host.groups Unknown Groups associated with the source host in the detection.
Vectra.Entity.Detections.src_host.threat Number Threat level associated with the source host in the detection.
Vectra.Entity.Detections.src_host.certainty Number Certainty level associated with the source host in the detection.
Vectra.Entity.Detections.src_ip String Source IP address in the detection.
Vectra.Entity.Detections.state String State of the detection.
Vectra.Entity.Detections.summary.num_events Number Total number of events related to the detection.
Vectra.Entity.Detections.summary.bytes_received Number Total bytes received in the detection summary.
Vectra.Entity.Detections.summary.bytes_sent Number Total bytes sent in the detection summary.
Vectra.Entity.Detections.summary.cnc_server String CNC server associated with the detection summary.
Vectra.Entity.Detections.summary.num_events Number Total number of events related to the detection.
Vectra.Entity.Detections.summary.probable_owner Unknown Probable owner of the detection summary.
Vectra.Entity.Detections.summary.sessions Number Total sessions in the detection summary.
Vectra.Entity.Detections.tags Unknown Tags associated with the detection.
Vectra.Entity.Detections.threat Number Threat level of the detection.
Vectra.Entity.Detections.t_score Number T-score of the detection.
Vectra.Entity.Detections.type String Type of the detection.
Vectra.Entity.Detections.url String URL associated with the detection.

Command example

!vectra-detection-describe detection_ids=132,135,140

Context Example

{
  "Vectra.Entity.Detections(val.id && val.id == obj.id)": [
    {
      "id": 132,
      "category": "exfiltration",
      "certainty": 70,
      "c_score": 70,
      "description": "",
      "detection": "Data Smuggler",
      "detection_category": "exfiltration",
      "detection_type": "smuggler",
      "grouped_details": [
        {
          "event_id": "ec2162c7-e526-4446-a549-71558743a1d7",
          "event_name": "UpdateAssumeRolePolicy",
          "aws_account_id": "aws_account_id",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"roleName\": \"stratus-red-team-backdoor-r-role\", \"policyDocument\": \"{\\\"Version\\\": \\\"2012-10-17\\\", \\\"Statement\\\": {\\\"Effect\\\": \\\"Allow\\\", \\\"Principal\\\": {\\\"AWS\\\": \\\"arn:aws:iam::123456789012:root\\\"}, \\\"Action\\\": \\\"sts:AssumeRole\\\"}}\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_id",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "stratus-red-team_06e15b96-ee6b-482c-aff4-4f2f4a46a67c"
          ],
          "last_timestamp": "2023-06-06T17:01:04Z"
        },
        {
          "event_id": "89a098eb-1198-4e2a-9fa4-ef568ae39403",
          "event_name": "UpdateAssumeRolePolicy",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"policyDocument\": \"{\\\"Version\\\": \\\"2012-10-17\\\", \\\"Statement\\\": {\\\"Effect\\\": \\\"Allow\\\", \\\"Principal\\\": {\\\"AWS\\\": \\\"arn:aws:iam::123456789012:root\\\"}, \\\"Action\\\": \\\"sts:AssumeRole\\\"}}\", \"roleName\": \"stratus-red-team-backdoor-r-role\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "stratus-red-team_a24eac3a-4fee-46ce-bc37-b4e675343fc9"
          ],
          "last_timestamp": "2023-06-06T15:40:43Z"
        }
      ],
      "is_targeting_key_asset": false,
      "last_timestamp": "2023-06-06T17:01:04Z",
      "notes": [],
      "sensor_name": "mafosb50",
      "src_account": {
        "id": 21,
        "name": "account_name",
        "url": "http://server_url.com/api/v3.3/accounts/21",
        "threat": 76,
        "certainty": 35
      },
      "src_ip": "0.0.0.0",
      "state": "active",
      "summary": {
      },
      "tags": [],
      "threat": 80,
      "t_score": 80,
      "type": "account",
      "url": "http://server_url.com/api/v3.3/detections/132"
    },
    {
      "id": 135,
      "category": "lateral_movement",
      "certainty": 50,
      "c_score": 50,
      "description": "",
      "detection": "AWS Suspect Admin Privilege Granting",
      "detection_category": "lateral_movement",
      "detection_type": "aws_admin_privilege_granted",
      "grouped_details": [
        {
          "event_id": "85d88db5-cf2d-4b6e-9411-d3119d9920e0",
          "event_name": "AttachRolePolicy",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"roleName\":\"stratus-red-team-backdoor-r-role\",\"policyArn\":\"arn:aws:iam::aws:policy/AdministratorAccess\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_5077134d-32ea-4403-996b-de30d7f278d7 HashiCorp-terraform-exec/0.17.3"
          ],
          "last_timestamp": "2023-06-06T17:00:46Z"
        },
        {
          "event_id": "ca157e7c-9a53-4012-9288-e6ac1c488fbc",
          "event_name": "AttachRolePolicy",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-east-1",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"roleName\":\"stratus-red-team-backdoor-r-role\",\"policyArn\":\"arn:aws:iam::aws:policy/AdministratorAccess\"}"
          ],
          "response_elements": [],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_01be8427-d1b5-4c18-8edb-0301c8e66c8e HashiCorp-terraform-exec/0.17.3"
          ],
          "last_timestamp": "2023-06-06T15:40:07Z"
        }
      ],
      "is_targeting_key_asset": false,
      "last_timestamp": "2023-06-06T17:00:46Z",
      "notes": [],
      "sensor_name": "mafosb50",
      "src_account": {
        "id": 21,
        "name": "account_name",
        "url": "http://server_url.com/api/v3.3/accounts/21",
        "threat": 76,
        "certainty": 35
      },
      "src_ip": "0.0.0.0",
      "state": "fixed",
      "summary": {
      },
      "tags": [],
      "threat": 60,
      "t_score": 60,
      "type": "account",
      "url": "http://server_url.com/api/v3.3/detections/135"
    },
    {
      "id": 140,
      "category": "reconnaissance",
      "certainty": 40,
      "c_score": 40,
      "description": "",
      "detection": "RPC Targeted Recon",
      "detection_category": "reconnaissance",
      "detection_type": "rpc_recon_1to1",
      "grouped_details": [
        {
          "event_id": "cf9f469b-0a8e-47c6-85eb-5a0486292e58",
          "event_name": "ModifySnapshotAttribute",
          "aws_account_id": "884414556547",
          "src_external_host": {
            "ip": "0.0.0.0"
          },
          "aws_region": "us-west-2",
          "access_key_id": [
            "123456"
          ],
          "identity_type": "Federated Account",
          "assumed_role": "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960",
          "request_parameters": [
            "{\"snapshotId\":\"snap-0f7d022a2f4f67e08\",\"createVolumePermission\":{\"add\":{\"items\":[{\"userId\":\"012345678912\"}]}},\"attributeType\":\"CREATE_VOLUME_PERMISSION\"}"
          ],
          "response_elements": [
            "{\"requestId\":\"350c1eb8-b696-4d94-88d4-a764a0eed08b\",\"_return\":true}"
          ],
          "role_sequence": [
            "account_name",
            "AWSReservedSSO_AdministratorAccess_a670eb90f07e2960"
          ],
          "user_agent": [
            "stratus-red-team_a4dd596b-7a8d-4e77-a74d-13f19adf4403"
          ],
          "last_timestamp": "2023-06-06T15:46:28Z"
        }
      ],
      "is_targeting_key_asset": false,
      "last_timestamp": "2023-06-06T15:46:28Z",
      "notes": [],
      "sensor_name": "mafosb50",
      "src_account": {
        "id": 21,
        "name": "account_name",
        "url": "http://server_url.com/api/v3.3/accounts/21",
        "threat": 76,
        "certainty": 35
      },
      "src_ip": "0.0.0.0",
      "state": "fixed",
      "summary": {
      },
      "tags": [],
      "threat": 60,
      "t_score": 60,
      "type": "account",
      "url": "http://server_url.com/api/v3.3/detections/140"
    }
  ]
}

Human Readable Output

Detections Table (Showing Page 1 out of 1)

ID Detection Name Detection Type Category Account Name Src IP Threat Score Certainty Score Number Of Events State Last Timestamp
132 Data Smuggler smuggler exfiltration account_name 0.0.0.0 80 70 0 active 2023-06-06T17:01:04Z
135 AWS Suspect Admin Privilege Granting aws_admin_privilege_granted lateral_movement account_name 0.0.0.0 60 50 0 fixed 2023-06-06T17:00:46Z
140 RPC Targeted Recon rpc_recon_1to1 reconnaissance account_name 0.0.0.0 60 40 0 fixed 2023-06-06T15:46:28Z

vectra-entity-note-add


Add a note to the entity.

Base Command

vectra-entity-note-add

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required
note Note to be added in the specified entity_id. Required

Context Output

Path Type Description
Vectra.Entity.Notes.entity_id String The ID of the entity associated with the note.
Vectra.Entity.Notes.note_id Number The ID of the note.
Vectra.Entity.Notes.date_created Date The date when the note was created.
Vectra.Entity.Notes.date_modified Unknown The date when the note was last modified.
Vectra.Entity.Notes.created_by String The user who created the note.
Vectra.Entity.Notes.modified_by Unknown The user who last modified the note.
Vectra.Entity.Notes.note String The content of the note.

Command example

!vectra-entity-note-add entity_id=1 entity_type=account note="test note"

Context Example

{
  "Vectra.Entity.Notes(val.entity_id && val.entity_id == obj.entity_id && val.note_id && val.note_id == obj.note_id)": {
    "date_created": "2023-06-21T06:19:15.224449Z",
    "created_by": "test_user",
    "note": "test_note",
    "note_id": 19,
    "entity_id": 1
  }
}

Human Readable Output

The note has been successfully added to the entity

Returned Note ID: 19

vectra-detection-note-add


Add a note to the detection.

Base Command

vectra-detection-note-add

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required
note Note to be added in the specified detection_id. Required

Context Output

Path Type Description
Vectra.Detection.Notes.detection_id String ID of the detection associated with the note.
Vectra.Detection.Notes.note_id Number ID of the note.
Vectra.Detection.Notes.id Number ID of the note.
Vectra.Detection.Notes.date_created Date Date when the note was created (ISO8601).
Vectra.Detection.Notes.created_by String User who created the note.
Vectra.Detection.Notes.note String Content of the note.

Command example

!vectra-detection-note-add detection_id=1 note="test note"

Context Example

{
  "Vectra.Detection.Notes(val.detection_id && val.detection_id == obj.detection_id && val.note_id && val.note_id == obj.note_id)": {
    "date_created": "2023-06-21T06:19:15.224449Z",
    "created_by": "test_user",
    "note": "test note",
    "note_id": 19,
    "id": 19,
    "detection_id": 1
  }
}

Human Readable Output

The note has been successfully added to the detection

Returned Note ID: 19

vectra-entity-note-update


Update a note in the entity.

Base Command

vectra-entity-note-update

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required
note_id Specify the ID of the note. Required
note Note to be updated for the specified note_id. Required

Context Output

Path Type Description
Vectra.Entity.Notes.entity_id String ID of the entity associated with the note.
Vectra.Entity.Notes.note_id Number ID of the note.
Vectra.Entity.Notes.date_created Date Date when the note was created.
Vectra.Entity.Notes.date_modified Unknown Date when the note was last modified.
Vectra.Entity.Notes.created_by String User who created the note.
Vectra.Entity.Notes.modified_by Unknown User who last modified the note.
Vectra.Entity.Notes.note String Content of the note.

Command example

!vectra-entity-note-update entity_id=1 entity_type=account note_id=1 note="note modified"

Context Example

{
  "Vectra.Entity.Notes(val.entity_id && val.entity_id == obj.entity_id && val.note_id && val.note_id == obj.note_id)": {
    "date_created": "2023-06-16T04:55:58Z",
    "date_modified": "2023-06-22T04:57:09Z",
    "created_by": "test_user",
    "modified_by": "test_user",
    "note": "note modified",
    "note_id": 8,
    "entity_id": 1
  }
}

Human Readable Output

The note has been successfully updated in the entity

vectra-detection-note-update


Update a note in the detection.

Base Command

vectra-detection-note-update

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required
note_id Specify the ID of the note. Required
note Note to be updated for the specified note_id. Required

Context Output

Path Type Description
Vectra.Detection.Notes.detection_id String ID of the detection associated with the note.
Vectra.Detection.Notes.note_id Number ID of the note.
Vectra.Detection.Notes.id Number ID of the note.
Vectra.Detection.Notes.date_created Date Date when the note was created (ISO8601).
Vectra.Detection.Notes.date_modified Date Date when the note was last modified (ISO8601).
Vectra.Detection.Notes.created_by String User who created the note.
Vectra.Detection.Notes.modified_by String User who last modified the note.
Vectra.Detection.Notes.note String Content of the note.

Command example

!vectra-detection-note-update detection_id=1 note_id=1 note="note modified"

Context Example

{
  "Vectra.Detection.Notes(val.detection_id && val.detection_id == obj.detection_id && val.note_id && val.note_id == obj.note_id)": {
    "date_created": "2023-06-16T04:55:58Z",
    "date_modified": "2023-06-22T04:57:09Z",
    "created_by": "test_user",
    "modified_by": "test_user",
    "note": "note modified",
    "note_id": 8,
    "id": 8,
    "detection_id": 1
  }
}

Human Readable Output

The note has been successfully updated in the detection

vectra-entity-note-remove


Remove a note from the entity.

Base Command

vectra-entity-note-remove

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required
note_id Specify the ID of the note. Required

Context Output

There is no context output for this command.

Command Example

!vectra-entity-note-remove entity_id=1 entity_type=account note_id=1"

Context Example

{}

Human Readable Output

The note has been successfully removed from the entity

vectra-detection-note-remove


Remove a note from the detection.

Base Command

vectra-detection-note-remove

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required
note_id Specify the ID of the note. Required

Context Output

There is no context output for this command.

Command Example

!vectra-detection-note-remove detection_id=1 note_id=1

Context Example

{}

Human Readable Output

The note has been successfully removed from the detection

vectra-detections-mark-fixed


Mark detection as fixed with provided detection IDs in argument.

Base Command

vectra-detections-mark-fixed

Input

Argument Name Description Required
detection_ids Provide a list of detection IDs separated by commas or a single detection ID. Required

Context Output

There is no context output for this command.

Command Example

!vectra-detections-mark-fixed detection_ids=1,2,3

Context Example

{}

Human Readable Output

The provided detection IDs have been successfully marked as fixed

vectra-detections-unmark-fixed


Unmark detection as fixed with provided detection IDs in argument.

Base Command

vectra-detections-unmark-fixed

Input

Argument Name Description Required
detection_ids Provide a list of detection IDs separated by commas or a single detection ID. Required

Context Output

There is no context output for this command.

Command Example

!vectra-detections-unmark-fixed detection_ids=1,2,3

Context Example

{}

Human Readable Output

The provided detection IDs have been successfully unmarked as fixed

vectra-entity-tag-add


Add tags in the entity.

Base Command

vectra-entity-tag-add

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: host, account. Required
tags Comma-separated values of tags to be included in the entity. Required

Context Output

Path Type Description
Vectra.Entity.Tags.tag_id String ID of the tag.
Vectra.Entity.Tags.entity_id String ID of the entity associated with the tag.
Vectra.Entity.Tags.entity_type String Type of the entity.
Vectra.Entity.Tags.tags Unknown A list of tags linked to an entity.

Command example

!vectra-entity-tag-add entity_id=1 entity_type=host tags="tag1, tag2"

Context Example

{
  "Vectra.Entity.Tags(val.tag_id && val.tag_id == obj.tag_id && val.entity_type && val.entity_type == obj.entity_type && val.entity_id && val.entity_id == obj.entity_id)": {
    "tag_id": "1",
    "tags": [
        "tag1",
        "tag2"
    ],
    "entity_type": "host",
    "entity_id": 1
  }
}

Human Readable Output

Tags have been successfully added to the entity

Updated list of tags: tag1, tag2

vectra-entity-tag-remove


Remove tags from the entity.

Base Command

vectra-entity-tag-remove

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: host, account. Required
tags Comma-separated values of tags to be removed from the entity. Required

Context Output

Path Type Description
Vectra.Entity.Tags.tag_id String ID of the tag.
Vectra.Entity.Tags.entity_id String ID of the entity associated with the tag.
Vectra.Entity.Tags.entity_type String Type of the entity.
Vectra.Entity.Tags.tags Unknown A list of tags linked to an entity.

Command example

!vectra-entity-tag-remove entity_id=1 entity_type=host tags="tag2"

Context Example

{
  "Vectra.Entity.Tags(val.tag_id && val.tag_id == obj.tag_id && val.entity_type && val.entity_type == obj.entity_type && val.entity_id && val.entity_id == obj.entity_id)": {
    "tag_id": "1",
    "tags": ["tag1"],
    "entity_type": "host",
    "entity_id": 1
  }
}

Human Readable Output

Specified tags have been successfully removed for the entity

Updated list of tags: tag1

vectra-entity-tag-list


Returns a list of tags for a specified entity.

Base Command

vectra-entity-tag-list

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: host, account. Required

Context Output

Path Type Description
Vectra.Entity.Tags.tag_id String ID of the tag.
Vectra.Entity.Tags.entity_id String ID of the entity associated with the tag.
Vectra.Entity.Tags.entity_type String Type of the entity.
Vectra.Entity.Tags.tags Unknown A list of tags linked to an entity.

Command example

!vectra-entity-tag-list entity_id=1 entity_type=host

Context Example

{
  "Vectra": {
    "Entity": {
      "Tags": {
        "tag_id": "1",
        "tags": [
            "tag1",
            "tag2"
        ],
        "entity_type": "host",
        "entity_id": 1
      }
    }
  }
}

Human Readable Output

List of tags: tag1, tag2

vectra-entity-assignment-add


Add an assignment for the entity.

Base Command

vectra-entity-assignment-add

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required
user_id Specify the ID of the user. Required

Context Output

Path Type Description
Vectra.Entity.Assignments.id Number ID of the assignment.
Vectra.Entity.Assignments.assignment_id Number ID of the assignment.
Vectra.Entity.Assignments.assigned_by.id Number ID of the user who assigned the entity.
Vectra.Entity.Assignments.assigned_by.username String Username of the user who assigned the entity.
Vectra.Entity.Assignments.date_assigned Date Date when the entity was assigned.
Vectra.Entity.Assignments.date_resolved Date Date when the entity was resolved.
Vectra.Entity.Assignments.events.assignment_id Number ID of the assignment event.
Vectra.Entity.Assignments.events.actor Number ID of the actor who performed the assignment event.
Vectra.Entity.Assignments.events.event_type String Type of assignment event.
Vectra.Entity.Assignments.events.datetime Date Date of the assignment event.
Vectra.Entity.Assignments.events.context.to Number ID of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_t_score Number Threat score of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_c_score Number Certainnity score of the entity that was assigned to.
Vectra.Entity.Assignments.outcome.id String ID of the assignment outcome.
Vectra.Entity.Assignments.outcome.builtin String Whether the assignment outcome is builtin or not.
Vectra.Entity.Assignments.outcome.user_selectable String Whether the assignment outcome is user selectable or not..
Vectra.Entity.Assignments.outcome.title String Title of the assignment outcome.
Vectra.Entity.Assignments.outcome.category String Category of the assignment outcome.
Vectra.Entity.Assignments.resolved_by.id Number ID of the user who resolved the entity.
Vectra.Entity.Assignments.resolved_by.username String Username of the user who resolved the entity.
Vectra.Entity.Assignments.triaged_detections Unknown Number of detections that have been triaged for the entity.
Vectra.Entity.Assignments.host_id Number ID of the host that the entity is associated with.
Vectra.Entity.Assignments.account_id Unknown ID of the account that the entity is associated with.
Vectra.Entity.Assignments.assigned_to.id Number ID of the user who is currently assigned to the entity.
Vectra.Entity.Assignments.assigned_to.username String Username of the user who is currently assigned to the entity.

Command Example

!vectra-entity-assignment-add entity_id=1 entity_type=account user_id=1

Context Example

{
  "Vectra.Entity.Assignments(val.assignment_id && val.assignment_id == obj.assignment_id)": {
    "assigned_by": {
      "id": 2,
      "username": "test_user_2"
    },
    "date_assigned": "2023-07-24T08:52:59.367115Z",
    "events": [
      {
        "assignment_id": 74,
        "actor": 65,
        "event_type": "created",
        "datetime": "2023-07-24T08:52:59Z",
        "context": {
          "to": 60,
          "entity_t_score": 0,
          "entity_c_score": 0
        }
      }
    ],
    "host_id": 10,
    "assigned_to": {
      "id": 1,
      "username": "test.user@mail.com"
    },
    "assignment_id": 1,
    "id":1
  }
}

Human Readable Output

The assignment has been successfully created

Assignment detail

Assignment ID Assigned By Assigned Date Assigned To Event Type
1 test_user_2 2023-07-24T08:52:59.367115Z test.user@mail.com created

vectra-entity-assignment-update


Update an assignment in the entity.

Base Command

vectra-entity-assignment-update

Input

Argument Name Description Required
assignment_id Specify the ID of the assignment. Required
user_id Specify the ID of the user. Required

Context Output

Path Type Description
Vectra.Entity.Assignments.id Number ID of the assignment.
Vectra.Entity.Assignments.assignment_id Number ID of the assignment.
Vectra.Entity.Assignments.assigned_by.id Number ID of the user who assigned the entity.
Vectra.Entity.Assignments.assigned_by.username String Username of the user who assigned the entity.
Vectra.Entity.Assignments.date_assigned Date Date when the entity was assigned.
Vectra.Entity.Assignments.date_resolved Date Date when the entity was resolved.
Vectra.Entity.Assignments.events.assignment_id Number ID of the assignment event.
Vectra.Entity.Assignments.events.actor Number ID of the actor who performed the assignment event.
Vectra.Entity.Assignments.events.event_type String Type of assignment event.
Vectra.Entity.Assignments.events.datetime Date Date of the assignment event.
Vectra.Entity.Assignments.events.context.to Number ID of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.from Number ID of the entity that was assigned.
Vectra.Entity.Assignments.events.context.entity_t_score Number Threat score of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_c_score Number Certainty score of the entity that was assigned to.
Vectra.Entity.Assignments.outcome.id String ID of the assignment outcome.
Vectra.Entity.Assignments.outcome.builtin String Whether the assignment outcome is builtin or not.
Vectra.Entity.Assignments.outcome.user_selectable String Whether the assignment outcome is user selectable or not..
Vectra.Entity.Assignments.outcome.title String Title of the assignment outcome.
Vectra.Entity.Assignments.outcome.category String Category of the assignment outcome.
Vectra.Entity.Assignments.resolved_by.id Number ID of the user who resolved the entity.
Vectra.Entity.Assignments.resolved_by.username String Username of the user who resolved the entity.
Vectra.Entity.Assignments.triaged_detections Unknown Number of detections that have been triaged for the entity.
Vectra.Entity.Assignments.host_id Number ID of the host that the entity is associated with.
Vectra.Entity.Assignments.account_id Unknown ID of the account that the entity is associated with.
Vectra.Entity.Assignments.assigned_to.id Number ID of the user who is currently assigned to the entity.
Vectra.Entity.Assignments.assigned_to.username String Username of the user who is currently assigned to the entity.

Command Example

!vectra-entity-assignment-update assignment_id=1 user_id=2

Context Example

{
  "Vectra.Entity.Assignments(val.assignment_id && val.assignment_id == obj.assignment_id)": {
    "assigned_by": {
      "id": 65,
      "username": "api_client"
    },
    "date_assigned": "2023-07-21T12:44:10Z",
    "events": [
      {
        "assignment_id": 1,
        "actor": 65,
        "event_type": "reassigned",
        "datetime": "2023-07-25T06:26:10Z",
        "context": {
          "from": 1,
          "to": 2,
          "entity_t_score": 68,
          "entity_c_score": 90
        }
      },
      {
        "assignment_id": 1,
        "actor": 65,
        "event_type": "created",
        "datetime": "2023-07-21T12:44:10Z",
        "context": {
          "to": 1,
          "entity_t_score": 68,
          "entity_c_score": 90
        }
      }
    ],
    "host_id": 97,
    "assigned_to": {
      "id": 2,
      "username": "test_user_2"
    },
    "assignment_id": 1,
    "id": 1
  }
}

Human Readable Output

The assignment has been successfully updated

Assignment detail

Assignment ID Assigned By Assigned Date Assigned To Event Type
1 api_client 2023-07-21T12:44:10Z test_user_2 reassigned

vectra-entity-assignment-resolve


Resolve an assignment in the entity.

Base Command

vectra-entity-assignment-resolve

Input

Argument Name Description Required
assignment_id Specify the ID of the assignment. Required
outcome Specify the Outcome for resolving an assignment in the entity. The custom outcome is allowed. Possible values are: Benign True Positive, Malicious True Positive, False Positive. Required
note A note to be added for resolving an assignment in the entity. Default is Updated by XSOAR. Optional
triage_as Triage rule for resolving an assignment in the entity. Optional
detection_ids Provide a list of detection IDs separated by commas or a single detection ID. Optional

Context Output

Path Type Description
Vectra.Entity.Assignments.id Number ID of the assignment.
Vectra.Entity.Assignments.assignment_id Number ID of the assignment.
Vectra.Entity.Assignments.assigned_by.id Number ID of the user who assigned the entity.
Vectra.Entity.Assignments.assigned_by.username String Username of the user who assigned the entity.
Vectra.Entity.Assignments.date_assigned Date Date when the entity was assigned.
Vectra.Entity.Assignments.date_resolved Date Date when the entity was resolved.
Vectra.Entity.Assignments.events.assignment_id Number ID of the assignment event.
Vectra.Entity.Assignments.events.actor Number ID of the actor who performed the assignment event.
Vectra.Entity.Assignments.events.event_type String Type of the assignment event.
Vectra.Entity.Assignments.events.datetime Date Date of the assignment event.
Vectra.Entity.Assignments.events.context.to Number ID of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_t_score Number Threat score of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_c_score Number Certainty score of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.triage_as String Triage status of the entity.
Vectra.Entity.Assignments.events.context.triaged_detection_ids Array IDs of the detections that have been triaged for the entity.
Vectra.Entity.Assignments.events.context.fixed_detection_ids Array IDs of the detections that have been fixed.
Vectra.Entity.Assignments.events.context.created_rule_ids Array IDs of the rules that have been created for the entity.
Vectra.Entity.Assignments.outcome.id Number ID of the assignment outcome.
Vectra.Entity.Assignments.outcome.builtin Boolean Whether the assignment outcome is builtin or not.
Vectra.Entity.Assignments.outcome.user_selectable Boolean Whether the assignment outcome is user selectable or not.
Vectra.Entity.Assignments.outcome.title String Title of the assignment outcome.
Vectra.Entity.Assignments.outcome.category String Category of the assignment outcome.
Vectra.Entity.Assignments.resolved_by.id Number ID of the user who resolved the entity.
Vectra.Entity.Assignments.resolved_by.username String Username of the user who resolved the entity.
Vectra.Entity.Assignments.triaged_detections Array Number of detections that have been triaged for the entity.
Vectra.Entity.Assignments.host_id Number ID of the account that the entity is associated with.
Vectra.Entity.Assignments.account_id Number ID of the host that the entity is associated with.
Vectra.Entity.Assignments.assigned_to.id Number ID of the user who is currently assigned to the entity.
Vectra.Entity.Assignments.assigned_to.username String Username of the user who is currently assigned to the entity.

Command Example

!vectra-entity-assignment-resolve assignment_id=116 outcome="Custom outcome" detection_ids=1431,1432,1433 triage_as="triage rule"

Context Example

{
  "Vectra.Entity.Assignments(val.assignment_id && val.assignment_id == obj.assignment_id)": {
    "assigned_by": {
      "id": 1,
      "username": "test_user@mail.com"
    },
    "date_assigned": "2023-07-27T12:33:44Z",
    "date_resolved": "2023-07-27T12:36:11Z",
    "events": [
      {
        "assignment_id": 116,
        "actor": 65,
        "event_type": "resolved",
        "datetime": "2023-07-27T12:36:11Z",
        "context": {
          "entity_t_score": 83,
          "entity_c_score": 84,
          "triage_as": "Triage by XSOAR",
          "triaged_detection_ids": [
            1432,
            1433,
            1431
          ],
          "created_rule_ids": [
            243,
            244,
            245
          ]
        }
      },
      {
        "assignment_id": 116,
        "actor": 65,
        "event_type": "created",
        "datetime": "2023-07-27T12:33:44Z",
        "context": {
          "to": 60,
          "entity_t_score": 63,
          "entity_c_score": 42
        }
      }
    ],
    "outcome": {
      "id": 6,
      "builtin": false,
      "user_selectable": true,
      "title": "Custom outcome",
      "category": "benign_true_positive"
    },
    "resolved_by": {
      "id": 2,
      "username": "test_user2@gmail.com"
    },
    "triaged_detections": [
      1432,
      1433,
      1431
    ],
    "account_id": 100,
    "assigned_to": {
      "id": 2,
      "username": "test_user2@gmail.com"
    },
    "assignment_id": 116
  }
}

Human Readable Output

The assignment has been successfully resolved

vectra-entity-detections-mark-fixed


Mark the detections of the entity as fixed with the provided entity ID in the argument.

Base Command

vectra-entity-detections-mark-fixed

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required

Context Output

There is no context output for this command.

Command Example

!vectra-entity-detections-mark-fixed entity_id=1 entity_type="account"

Context Example

{}

Human Readable Output

The detections (1431, 1432) of the provided entity ID have been successfully marked as fixed

vectra-detection-pcap-download


Download pcap of the detection.

Base Command

vectra-detection-pcap-download

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required

Context Output

Path Type Description
File.Size Number The size of the file.
File.SHA1 String The SHA1 hash of the file.
File.SHA256 String The SHA256 hash of the file.
File.SHA512 String The SHA512 hash of the file.
File.Name String The name of the file.
File.SSDeep String The SSDeep hash of the file.
File.EntryID String The entry ID of the file.
File.Info String File information.
File.Type String The file type.
File.MD5 String The MD5 hash of the file.
File.Extension String The file extension.

Command Example

!vectra-detection-pcap-download detection_id="116"

Context Example

{
    "File": {
      "EntryID": "1703@7e0f6637-f0a4-46b3-8c61-2f94b3432428",
      "Extension": "pcap",
      "Info": "pcap-ng capture file - version 1.0",
      "MD5": "709db6e1f8f5054ca57caf43ba248ed6",
      "Name": "IP-192.168.55.10_hidden_dns_tunnel_1382.pcap",
      "SHA1": "49fe55c6aef85549261b46dd2e54f8d485306ee5",
      "SHA256": "8615bde9332584b4fd4fe4dc2cc6fc4c75504f6d44667814456c089fd413aa4d",
      "SHA512": "3fa29be0e20884c850b62d2a99aa09b24488289ba0bc9aff37ebe982c21d3a78fb26d9c9ac7fbf2a0839ba649dc0a845f30e7f13de3a0c6284c3c2ac54102143",
      "SSDeep": "384:dN+Pm11R0XPmts64kZog9ZaikYngk+SnRxFyeyCEyuAOasucOcakca0/rHfcjOUI:dI+t25caEPjRSnmuNasxRana4DgOUDcX",
      "Size": 23988,
      "Type": "application/vnd.tcpdump.pcap"
  }
}

Human Readable Output

Uploaded file: IP-192.168.55.10_hidden_dns_tunnel_1382.pcap

Property Type Size Info MD5 SHA1 SHA256 SHA512 SSDeep
Value application/vnd.tcpdump.pcap 23,988 bytes pcap-ng capture file - version 1.0 709db6e1f8f5054ca57caf43ba248ed6 49fe55c6aef85549261b46dd2e54f8d485306ee5 8615bde9332584b4fd4fe4dc2cc6fc4c75504f6d44667814456c089fd413aa4d 3fa29be0e20884c850b62d2a99aa09b24488289ba0bc9aff37ebe982c21d3a78fb26d9c9ac7fbf2a0839ba649dc0a845f30e7f13de3a0c6284c3c2ac54102143 384:dN+Pm11R0XPmts64kZog9ZaikYngk+SnRxFyeyCEyuAOasucOcakca0/rHfcjOUI:dI+t25caEPjRSnmuNasxRana4DgOUDcX

vectra-assignment-list


Returns a list of all assignments.

Base Command

vectra-assignment-list

Input

Argument Name Description Required
entity_ids Specify the IDs of the entities. Comma-separated values supported. Optional
entity_type Specify the type of the entity. Possible values are: account, host. Optional
resolved Filter by resolved status. Possible values are: True, False. Optional
assignees Filter by user ids of the assignment. Comma-separated values supported. Optional
resolution Filter by outcome ids of the resolution. Comma-separated values supported. Optional
created_after Filter by created after the timestamp.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
Optional
page Enables the caller to specify a particular page of results. Default is 1. Optional
page_size Specify the desired page size for the request. Default is 50. Optional

Context Output

Path Type Description
Vectra.Entity.Assignments.id Number ID of the assignment.
Vectra.Entity.Assignments.assignment_id Number ID of the assignment.
Vectra.Entity.Assignments.assigned_by.id Number ID of the user who assigned the entity.
Vectra.Entity.Assignments.assigned_by.username String Username of the user who assigned the entity.
Vectra.Entity.Assignments.date_assigned Date Date when the entity was assigned.
Vectra.Entity.Assignments.date_resolved Date Date when the entity was resolved.
Vectra.Entity.Assignments.events.assignment_id Number ID of the assignment event.
Vectra.Entity.Assignments.events.actor Number ID of the actor who performed the assignment event.
Vectra.Entity.Assignments.events.event_type String Type of the assignment event.
Vectra.Entity.Assignments.events.datetime Date Date of the assignment event.
Vectra.Entity.Assignments.events.context.to Number ID of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_t_score Number Threat score of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.entity_c_score Number Certainty score of the entity that was assigned to.
Vectra.Entity.Assignments.events.context.triage_as String Triage status of the entity.
Vectra.Entity.Assignments.events.context.triaged_detection_ids Array IDs of the detections that have been triaged for the entity.
Vectra.Entity.Assignments.events.context.fixed_detection_ids Array IDs of the detections that have been fixed.
Vectra.Entity.Assignments.events.context.created_rule_ids Array IDs of the rules that have been created for the entity.
Vectra.Entity.Assignments.outcome.id Number ID of the assignment outcome.
Vectra.Entity.Assignments.outcome.builtin Boolean Whether the assignment outcome is builtin or not.
Vectra.Entity.Assignments.outcome.user_selectable Boolean Whether the assignment outcome is user selectable or not.
Vectra.Entity.Assignments.outcome.title String Title of the assignment outcome.
Vectra.Entity.Assignments.outcome.category String Category of the assignment outcome.
Vectra.Entity.Assignments.resolved_by.id Number ID of the user who resolved the entity.
Vectra.Entity.Assignments.resolved_by.username String Username of the user who resolved the entity.
Vectra.Entity.Assignments.triaged_detections Array Number of detections that have been triaged for the entity.
Vectra.Entity.Assignments.host_id Number ID of the host that the entity is associated with.
Vectra.Entity.Assignments.account_id Number ID of the account that the entity is associated with.
Vectra.Entity.Assignments.assigned_to.id Number ID of the user who is currently assigned to the entity.
Vectra.Entity.Assignments.assigned_to.username String Username of the user who is currently assigned to the entity.

Command Example


#### Context Example

```json
{
    "Vectra": {
      "Entity": {
        "Assignments": [
          {
            "id": 214,
            "assigned_by": {
              "id": 64,
              "username": "test.user4@mail.com"
            },
            "date_assigned": "2023-08-18T10:55:29Z",
            "events": [
              {
                "assignment_id": 214,
                "actor": 64,
                "event_type": "reassigned",
                "datetime": "2023-08-18T10:56:11Z",
                "context": {
                  "from": 39,
                  "to": 59,
                  "entity_t_score": 0,
                  "entity_c_score": 0
                }
              },
              {
                "assignment_id": 214,
                "actor": 64,
                "event_type": "created",
                "datetime": "2023-08-18T10:55:29Z",
                "context": {
                  "to": 39,
                  "entity_t_score": 0,
                  "entity_c_score": 0
                }
              }
            ],
            "host_id": 220,
            "assigned_to": {
              "id": 59,
              "username": "test.user2@mail.com"
            },
            "assignment_id": 214
          },
          {
            "id": 212,
            "assigned_by": {
              "id": 65,
              "username": "test.user4@mail.com"
            },
            "date_assigned": "2023-08-18T06:29:56Z",
            "date_resolved": "2023-08-18T06:32:09Z",
            "events": [
              {
                "assignment_id": 212,
                "actor": 65,
                "event_type": "resolved",
                "datetime": "2023-08-18T06:32:09Z",
                "context": {
                  "entity_t_score": 77,
                  "entity_c_score": 53
                }
              },
              {
                "assignment_id": 212,
                "actor": 65,
                "event_type": "reassigned",
                "datetime": "2023-08-18T06:31:02Z",
                "context": {
                  "from": 59,
                  "to": 60,
                  "entity_t_score": 77,
                  "entity_c_score": 53
                }
              },
              {
                "assignment_id": 212,
                "actor": 65,
                "event_type": "created",
                "datetime": "2023-08-18T06:29:56Z",
                "context": {
                  "to": 59,
                  "entity_t_score": 77,
                  "entity_c_score": 53
                }
              }
            ],
            "outcome": {
              "id": 1,
              "builtin": true,
              "user_selectable": true,
              "title": "Benign True Positive",
              "category": "benign_true_positive"
            },
            "resolved_by": {
              "id": 65,
              "username": "test.user4@mail.com"
            },
            "account_id": 108,
            "assigned_to": {
              "id": 60,
              "username": "test.user1@mail.com"
            },
            "assignment_id": 212
          }
        ]
      }
    }
  }

Human Readable Output

Assignments Table (Showing Page 1 out of 1)

Account ID Host ID Assignment ID Assigned By Assigned To Date Assigned Resolved By Date Resolved Outcome ID Outcome
  220 214 test.user4@mail.com test.user2@mail.com 2023-08-18T10:55:29Z        
108   212 test.user4@mail.com test.user1@mail.com 2023-08-18T06:29:56Z test.user4@mail.com 2023-08-18T06:32:09Z 1 Benign True Positive

vectra-assignment-outcome-list


Returns a list of all entity assignment outcomes.

Base Command

vectra-assignment-outcome-list

Input

Argument Name Description Required
page Enables the caller to specify a particular page of results. Default is 1. Optional
page_size Specify the desired page size for the request. Default is 50. Optional

Context Output

Path Type Description
Vectra.Entity.Assignments.Outcomes.id Number ID of the assignment outcome.
Vectra.Entity.Assignments.Outcomes.builtin Boolean Whether the assignment outcome is builtin or not.
Vectra.Entity.Assignments.Outcomes.user_selectable Boolean Whether the assignment outcome is user selectable or not.
Vectra.Entity.Assignments.Outcomes.title String Title of the assignment outcome.
Vectra.Entity.Assignments.Outcomes.category String Category of the assignment outcome.

Command Example

!vectra-assignment-outcome-list page=1 page_size=5

Context Example

{
  "Vectra": {
    "Entity": {
      "Assignments": {
        "Outcomes": [
          {
            "builtin": false,
            "category": "benign_true_positive",
            "id": 7,
            "title": "Custom outcome1",
            "user_selectable": true
          },
          {
            "builtin": true,
            "category": "false_positive",
            "id": 3,
            "title": "False Positive",
            "user_selectable": true
          },
          {
            "builtin": false,
            "category": "benign_true_positive",
            "id": 6,
            "title": "Custom outcome",
            "user_selectable": true
          },
          {
            "builtin": true,
            "category": "benign_true_positive",
            "id": 1,
            "title": "Benign True Positive",
            "user_selectable": true
          },
          {
            "builtin": true,
            "category": "malicious_true_positive",
            "id": 2,
            "title": "Malicious True Positive",
            "user_selectable": true
          }
        ]
      }
    }
  }
}

Human Readable Output

Assignment Outcomes Table (Showing Page 1 out of 1)

ID Title Category Built IN User Selectable
1 Benign True Positive benign_true_positive true true
2 Malicious True Positive malicious_true_positive true true
3 False Positive false_positive true true
6 Custom outcome benign_true_positive false true
7 Custom outcome1 benign_true_positive false true

vectra-entity-note-list


Returns a list of notes for a specified entity.

Base Command

vectra-entity-note-list

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: host, account. Required

Context Output

Path Type Description
Vectra.Entity.Notes.note_id Number ID of the note.
Vectra.Entity.Notes.id Number ID of the note.
Vectra.Entity.Notes.date_created Date Date when the note was created.
Vectra.Entity.Notes.date_modified Unknown Date when the note was last modified.
Vectra.Entity.Notes.created_by String User who created the note.
Vectra.Entity.Notes.modified_by Unknown User who last modified the note.
Vectra.Entity.Notes.note String Content of the note.
Vectra.Entity.Notes.entity_id String ID of the entity associated with the note.
Vectra.Entity.Notes.entity_type String Type of the entity associated with the note.

Command Example

!vectra-entity-note-list entity_id="107" entity_type="account"

Context Example

{
  "Vectra": {
    "Entity": {
      "Notes": [
        {
          "created_by": "test_user@mail.com",
          "date_created": "2023-08-25T07:09:08Z",
          "entity_id": 107,
          "entity_type": "account",
          "id": 1070,
          "modified_by": "test_user@mail.com",
          "note": "From XSOAR",
          "note_id": 1070
        },
        {
          "created_by": "test_user@mail.com",
          "date_created": "2023-08-25T07:08:58Z",
          "entity_id": 107,
          "entity_type": "account",
          "id": 1069,
          "modified_by": "test_user@mail.com",
          "note": "Test note",
          "note_id": 1069
        },
        {
          "created_by": "api_client",
          "date_created": "2023-08-16T05:23:33Z",
          "entity_id": 107,
          "entity_type": "account",
          "id": 922,
          "note": "[Mirrored From XSOAR] XSOAR Incident ID: 14228\n\nNote: **bold**\n\n_Italic_\n\n+Underline+\n\n~~strikethrough~~\n\nAdded By: admin",
          "note_id": 922
        }
      ]
    }
  }
}

Human Readable Output

Entity Notes Table

Note ID Note Created By Created Date Modified By Modified Date
1070 From XSOAR test_user@mail.com 2023-08-25T07:09:08Z test_user@mail.com 2023-08-25T08:10:08Z
1069 Test note test_user@mail.com 2023-08-25T07:08:58Z test_user@mail.com 2023-08-25T08:10:08Z
922 [Mirrored From XSOAR] XSOAR Incident ID: 14228
Note:XSOAR note
Added By: admin
api_client 2023-08-16T05:23:33Z    

vectra-group-list


Returns a list of all groups.

Base Command

vectra-group-list

Input

Argument Name Description Required
group_type Filter by group type. Possible values are: account, host, ip, domain. Optional
account_names Filter by Account Names. Supports comma-separated values.

Note: Only valid when the group_type parameter is set to “account”.
Optional
domains Filter by Domains. Supports comma-separated values.

Note: Only valid when the group_type parameter is set to “domain”.
Optional
host_ids Filter by Host IDs. Supports comma-separated values.

Note: Only valid when the group_type parameter is set to “host”.
Optional
host_names Filter by Host Names. Supports comma-separated values.

Note: Only valid when the group_type parameter is set to “host”.
Optional
importance Filter by group importance. Possible values are: high, medium, low, never_prioritize. Optional
ips Filter by IPs. Supports comma-separated values.

Note: Only valid when the group_type parameter is set to “ip”.
Optional
description Filter by group description. Optional
last_modified_timestamp Return only the groups which have a last modification timestamp equal to or after the given timestamp.

Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

For example: 01 May 2023, 01 Mar 2023 04:45:33, 2023-04-17T14:05:44Z.
Optional
last_modified_by Filters by the user ID who made the most recent modification to the group. Optional
group_name Filters by group name. Optional

Context Output

Path Type Description
Vectra.Group.group_id Number ID of the group.
Vectra.Group.id Number ID of the group.
Vectra.Group.name String Name of the group.
Vectra.Group.description String Description of the group.
Vectra.Group.last_modified Date Date when the group was last modified.
Vectra.Group.last_modified_by String Name of the user who last modified the group.
Vectra.Group.type String Type of the group.
Vectra.Group.members Unknown Members of the group.
Vectra.Group.members.id Number Entity ID of member.
Vectra.Group.members.name String Entity name of member.
Vectra.Group.members.is_key_asset Boolean Indicates key asset.
Vectra.Group.members.url String Entity URL of member.
Vectra.Group.members.uid String Entity UID of member.
Vectra.Group.rules.triage_category String Triage category of rule.
Vectra.Group.rules.id Number Id of the rule.
Vectra.Group.rules.description String Description of the rule.
Vectra.Group.importance String Importance level of the group.
Vectra.Group.cognito_managed Boolean Whether the group is managed by Cognito or not.

Command Example


#### Context Example

```json
{
  "Vectra": {
    "Group": [
      {
        "id": 1,
        "group_id": 1,
        "name": "Cognito - Box",
        "description": "Domains used by the Box service",
        "last_modified": "2023-05-31T13:57:53Z",
        "last_modified_by": "cognito",
        "type": "domain",
        "members": [
          "*.abc.com",
          "*.xyz.net"
        ],
        "rules": [
          {
            "triage_category": "Box",
            "id": 175,
            "description": "data storage to Box service"
          }
        ],
        "importance": "medium",
        "cognito_managed": true
      },
      {
        "id": 8,
        "group_id": 8,
        "name": "Cognito - IPAM",
        "description": "IPAM, created by Cognito",
        "last_modified": "2023-08-18T09:16:54Z",
        "last_modified_by": "cognito",
        "type": "host",
        "members": [
          {
            "is_key_asset": false,
            "id": 97,
            "name": "IP-0.0.0.0",
            "url": "https://server_url.com/api/v3.3/hosts/97"
          },
          {
            "is_key_asset": false,
            "id": 212,
            "name": "IP-0.0.0.1",
            "url": "https://server_url.com/api/v3.3/hosts/212"
          }
        ],
        "rules": [
          {
            "triage_category": "Expected IPAM Behavior",
            "id": 189,
            "description": "Expected behavior from these devices"
          },
          {
            "triage_category": "Expected IPAM Behavior",
            "id": 193,
            "description": "Expected behavior from these devices"
          }
        ],
        "importance": "medium"
      },
      {
        "id": 16,
        "group_id": 16,
        "name": "Cognito - Guest Wifi",
        "description": "IP space used by Guest Wifi",
        "last_modified": "2023-08-18T08:55:54Z",
        "last_modified_by": "cognito",
        "type": "ip",
        "members": [
          "0.0.0.0",
          "0.0.0.1"
        ],
        "importance": "medium",
        "cognito_managed": false
      },
      {
        "id": 22,
        "group_id": 22,
        "name": "Dev-Group-Account-High",
        "description": "",
        "last_modified": "2023-08-25T10:17:37Z",
        "last_modified_by": "cognito",
        "type": "account",
        "members": [
          {
            "uid": "O300:service-principal_00000000-0000-0000-0000-000000000001"
          },
          {
            "uid": "administrator@fictotech.com"
          }
        ],
        "importance": "high"
      }
    ]
  }
}

Human Readable Output

Groups Table

Group ID Name Group Type Description Importance Members Last Modified Timestamp
1 Cognito - Box domain Domains used by the Box service medium *.abc.com, *.xyz.net 2023-05-31T13:57:53Z
8 Cognito - IPAM host IPAM, created by Cognito medium 97, 212 2023-08-18T09:16:54Z
16 Cognito - Guest Wifi ip IP space used by Guest Wifi medium 0.0.0.0, 0.0.0.1 2023-08-18T08:55:54Z
22 Dev-Group-Account-High account   high O300:service-principal_00000000-0000-0000-0000-000000000001, administrator@fictotech.com 2023-08-25T10:17:37Z

vectra-group-assign


Assign members to the specified group.

Base Command

vectra-group-assign

Input

Argument Name Description Required
group_id Specify Group ID to assign members. Required
members Member values based on the group type. Supports comma-separated values.

Note:
If the group type is host, then the “Host IDs”.
If the group type is account, then “Account Names”.
If the group type is ip, then the list of “IPs”.
If the group type is domain, then the list of “Domains” .
Required

Context Output

Path Type Description
Vectra.Group.group_id Number ID of the group.
Vectra.Group.id Number ID of the group.
Vectra.Group.name String Name of the group.
Vectra.Group.description String Description of the group.
Vectra.Group.last_modified Date Date when the group was last modified.
Vectra.Group.last_modified_by String Name of the user who last modified the group.
Vectra.Group.type String Type of the group.
Vectra.Group.members Unknown Members of the group.
Vectra.Group.members.id Number Entity ID of member.
Vectra.Group.members.name String Entity name of member.
Vectra.Group.members.is_key_asset Boolean Indicates key asset.
Vectra.Group.members.url String Entity URL of member.
Vectra.Group.members.uid String Entity UID of member.
Vectra.Group.rules.triage_category String Triage category of rule.
Vectra.Group.rules.id Number Id of the rule.
Vectra.Group.rules.description String Description of the rule.

Command Example

!vectra-group-assign group_id=23 members="*.domain4.com,*.domain5.com"

Context Example

{
  "Vectra": {
    "Group": {
      "cognito_managed": false,
      "description": "xsoar-group-accout-test",
      "group_id": 23,
      "id": 23,
      "last_modified": "2023-09-04T11:59:15Z",
      "last_modified_by": "API Client a7f5be37",
      "members": [
        "*.domain1.net",
        "*.domain2.com",
        "*.domain3.com",
        "*.domain4.com",
        "*.domain5.com"
      ],
      "name": "xsoar-group-accout-test",
      "type": "domain"
    }
  }
}

Human Readable Output

Member(s) *.domain4.com, *.domain5.com have been assigned to the group

Updated group details

Group ID Name Group Type Description Members Last Modified Timestamp
1 xsoar-group-accout-test domain xsoar-group-accout-test *.domain1.net, *.domain2.com, *.domain3.com, *.domain4.com, *.domain5.com 2023-09-04T06:30:01Z

vectra-group-unassign


Unassign members from the specified group.

Base Command

vectra-group-unassign

Input

Argument Name Description Required
group_id Specify Group ID to unassign members. Required
members Member values based on the group type. Supports comma-separated values.

Note:
If the group type is host, then the “Host IDs”.
If the group type is account, then “Account Names”.
If the group type is ip, then the list of “IPs”.
If the group type is domain, then the list of “Domains” .
Required

Context Output

Path Type Description
Vectra.Group.group_id Number ID of the group.
Vectra.Group.id Number ID of the group.
Vectra.Group.name String Name of the group.
Vectra.Group.description String Description of the group.
Vectra.Group.last_modified Date Date when the group was last modified.
Vectra.Group.last_modified_by String Name of the user who last modified the group.
Vectra.Group.type String Type of the group.
Vectra.Group.members Unknown Members of the group.
Vectra.Group.members.id Number Entity ID of member.
Vectra.Group.members.name String Entity name of member.
Vectra.Group.members.is_key_asset Boolean Indicates key asset.
Vectra.Group.members.url String Entity URL of member.
Vectra.Group.members.uid String Entity UID of member.
Vectra.Group.rules.triage_category String Triage category of rule.
Vectra.Group.rules.id Number Id of the rule.
Vectra.Group.rules.description String Description of the rule.

Command Example

!vectra-group-unassign group_id=23 members="*.domain4.com,*.domain5.com"

Context Example

{
  "Vectra": {
    "Group": {
      "cognito_managed": false,
      "description": "xsoar-group-accout-test",
      "group_id": 23,
      "id": 23,
      "last_modified": "2023-09-04T12:03:02Z",
      "last_modified_by": "API Client a7f5be37",
      "members": ["*.domain1.net", "*.domain2.com", "*.domain3.com"],
      "name": "xsoar-group-accout-test",
      "type": "domain"
    }
  }
}

Human Readable Output

Member(s) *.domain4.com, *.domain5.com have been unassigned from the group

Updated group details

Group ID Name Group Type Description Members Last Modified Timestamp
1 xsoar-group-accout-test domain xsoar-group-accout-test *.domain1.net, *.domain2.com, *.domain3.com 2023-09-04T07:30:01Z

vectra-entity-detections-mark-asclosed


Mark the detections of the entity as closed with the provided entity ID in the argument.

Base Command

vectra-entity-detections-mark-asclosed

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required
close_reason Specify the close reason. Possible values are: benign, remediated. Required

Context Output

There is no context output for this command.

Command example

!vectra-entity-detections-mark-asclosed entity_id=1 entity_type=account close_reason=benign

Human Readable Output

The detections (34122, 35097) of the provided entity ID have been successfully closed as benign

vectra-detections-mark-asclosed


Mark detections as close with provided detection IDs in the argument.

Base Command

vectra-detections-mark-asclosed

Input

Argument Name Description Required
detection_ids Provide a list of detection IDs separated by commas or a single detection ID. Required
close_reason Specify the close reason. Possible values are: benign, remediated. Required

Context Output

There is no context output for this command.

Command example

!vectra-detections-mark-asclosed detection_ids=1,2,3 close_reason=benign

Human Readable Output

The provided detection IDs have been successfully closed as benign

vectra-detections-mark-asopen


Open detections with provided detection IDs in the argument.

Base Command

vectra-detections-mark-asopen

Input

Argument Name Description Required
detection_ids Provide a list of detection IDs separated by commas or a single detection ID. Required

Context Output

There is no context output for this command.

Command example

!vectra-detections-mark-asopen detection_ids=1,2,3

Human Readable Output

The provided detection IDs have been successfully re-opened

vectra-detection-tag-list


Returns a list of tags for a specified detection.

Base Command

vectra-detection-tag-list

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required

Context Output

Path Type Description
Vectra.Detection.Tags.tag_id String The ID of the tag.
Vectra.Detection.Tags.detection_id String The ID of the Detection associated with the tag.
Vectra.Detection.Tags.tags Unknown A list of tags linked to a detection.

Command example

!vectra-detection-tag-list detection_id=123

Context Example

{
    "Vectra": {
        "Detection": {
            "Tags": {
                "detection_id": 123,
                "tag_id": "123",
                "tags": [
                    "tag1",
                    "tag2"
                ]
            }
        }
    }
}

Human Readable Output

List of tags: tag1, tag2

vectra-detection-tag-add


Add tags to a detection.

Base Command

vectra-detection-tag-add

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required
tags Comma-separated values of tags to be added to the detection. Required

Context Output

Path Type Description
Vectra.Detection.Tags.tag_id String The ID of the tag.
Vectra.Detection.Tags.detection_id String The ID of the detection associated with the tag.
Vectra.Detection.Tags.tags Unknown A list of tags linked to a detection.

Command example

!vectra-detection-tag-add detection_id=1 tags="tag1,tag2"

Context Example

{
    "Vectra": {
        "Detection": {
            "Tags": {
                "detection_id": 1,
                "tag_id": 1,
                "tags": [
                    "tag",
                    "tag1",
                    "tag2"
                ]
            }
        }
    }
}

Human Readable Output

Tags have been successfully added to the detection

Updated list of tags: tag, tag1, tag2

vectra-detection-tag-remove


Remove tags from the detection.

Base Command

vectra-detection-tag-remove

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required
tags Comma-separated values of tags to be removed from the detection. Required

Context Output

Path Type Description
Vectra.Detection.Tags.tag_id String The ID of the tag.
Vectra.Detection.Tags.detection_id String The ID of the detection associated with the tag.
Vectra.Detection.Tags.tags Unknown A list of tags linked to a detection.

Command example

!vectra-detection-tag-remove detection_id="2" tags="tag3,tag4"

Context Example

{
    "Vectra": {
        "Detection": {
            "Tags": {
                "detection_id": 2,
                "tag_id": "2",
                "tags": [
                    "tag",
                    "tag1",
                    "tag2"
                ]
            }
        }
    }
}

Human Readable Output

Specified tags have been successfully removed for the detection

Updated list of tags: tag, tag1, tag2

vectra-detection-note-list


Returns a list of notes for a specified detection.

Base Command

vectra-detection-note-list

Input

Argument Name Description Required
detection_id Specify the ID of the detection. Required

Context Output

Path Type Description
Vectra.Detection.Notes.note_id Number ID of the note.
Vectra.Detection.Notes.id Number ID of the note.
Vectra.Detection.Notes.date_created Date Date when the note was created (ISO8601).
Vectra.Detection.Notes.date_modified Date Date when the note was last modified (ISO8601).
Vectra.Detection.Notes.created_by String User who created the note.
Vectra.Detection.Notes.modified_by String User who last modified the note.
Vectra.Detection.Notes.note String Content of the note.
Vectra.Detection.Notes.detection_id String ID of the detection associated with the note.

Command example

!vectra-detection-note-list detection_id=1

Context Example

{
  "Vectra": {
    "Detection": {
      "Notes": [
        {
          "created_by": "test_user@mail.com",
          "date_created": "2023-08-25T07:09:08Z",
          "detection_id": 1,
          "id": 1070,
          "modified_by": "test_user@mail.com",
          "note": "From XSOAR",
          "note_id": 1070
        },
        {
          "created_by": "test_user@mail.com",
          "date_created": "2023-08-25T07:08:58Z",
          "detection_id": 1,
          "id": 1069,
          "modified_by": "test_user@mail.com",
          "note": "Test note",
          "note_id": 1069
        },
        {
          "created_by": "api_client",
          "date_created": "2023-08-16T05:23:33Z",
          "detection_id": 1,
          "id": 922,
          "note": "[Mirrored From XSOAR] XSOAR Incident ID: 14228\n\nNote: **bold**\n\n_Italic_\n\n+Underline+\n\n~~strikethrough~~\n\nAdded By: admin",
          "note_id": 922
        }
      ]
    }
  }
}

vectra-entity-reset-fetch


Resets the given entity to refetch incidents.

Base Command

vectra-entity-reset-fetch

Input

Argument Name Description Required
entity_id Specify the ID of the entity. Required
entity_type Specify the type of the entity. Possible values are: account, host. Required

Context Output

There is no context output for this command.

Command example

!vectra-entity-reset-fetch entity_id=1 entity_type=host

Human Readable Output

Reset fetch status for 1-host

Configuration parameters

  • server_url — Server URL (required)
  • credentials — Client ID (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • isFetch — Fetch incidents
  • max_fetch — Max Fetch
  • first_fetch — First Fetch Time
  • mirror_direction — Mirroring Direction
  • refetch_closed_incidents — Re-Fetch closed incidents via mirroring
  • note_tag — Mirror tag for notes
  • entity_type — Entity Type
  • is_prioritized — Prioritized
  • tags — Tags
  • detection_category — Detection Category
  • detection_type — Detection Type
  • urgency_score_low_threshold — Specify the numeric value of "Urgency Score" for mapping the Low Incident Severity.
  • urgency_score_medium_threshold — Specify the numeric value of "Urgency Score" for mapping the Medium Incident Severity.
  • urgency_score_high_threshold — Specify the numeric value of "Urgency Score" for mapping the High Incident Severity.
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval

Commands (35)

  • vectra-assignment-list

    Returns a list of all assignments.

  • vectra-assignment-outcome-list

    Returns a list of all entity assignment outcomes.

  • vectra-detection-describe

    Returns a list of detections for the specified detection ID(s).

  • vectra-detection-note-add

    Add a note to the detection.

  • vectra-detection-note-list

    Returns a list of notes for a specified detection.

  • vectra-detection-note-remove

    Remove a note from the detection.

  • vectra-detection-note-update

    Update a note in the detection.

  • vectra-detection-pcap-download

    Download pcap of the detection.

  • vectra-detection-tag-add

    Add tags to a detection.

  • vectra-detection-tag-list

    Returns a list of tags for a specified detection.

  • vectra-detection-tag-remove

    Remove tags from the detection.

  • vectra-detections-mark-asclosed

    Mark detections as close with provided detection IDs in the argument.

  • vectra-detections-mark-asopen

    Open detections with provided detection IDs in the argument.

  • vectra-detections-mark-fixed

    Mark detection as fixed with provided detection IDs in argument.

  • vectra-detections-unmark-fixed

    Unmark detection as fixed with provided detection IDs in argument.

  • vectra-entity-assignment-add

    Add an assignment for the entity.

  • vectra-entity-assignment-resolve

    Resolve an assignment in the entity.

  • vectra-entity-assignment-update

    Update an assignment in the entity.

  • vectra-entity-describe

    Describes an entity by ID.

  • vectra-entity-detection-list

    Returns a list of detections for a specified entity.

  • vectra-entity-detections-mark-asclosed

    Mark the detections of the entity as closed with the provided entity ID in the argument.

  • vectra-entity-detections-mark-fixed

    Mark the detections of the entity as fixed with the provided entity ID in the argument.

  • vectra-entity-list

    Returns a list of entities.

  • vectra-entity-note-add

    Add a note to the entity.

  • vectra-entity-note-list

    Returns a list of notes for a specified entity.

  • vectra-entity-note-remove

    Remove a note from the entity.

  • vectra-entity-note-update

    Update a note in the entity.

  • vectra-entity-reset-fetch

    Resets the given entity to refetch incidents.

  • vectra-entity-tag-add

    Add tags in the entity.

  • vectra-entity-tag-list

    Returns a list of tags for a specified entity.

  • vectra-entity-tag-remove

    Remove tags from the entity.

  • vectra-group-assign

    Assign members to the specified group.

  • vectra-group-list

    Returns a list of all groups.

  • vectra-group-unassign

    Unassign members from the specified group.

  • vectra-user-list

    Returns a list of users.

category: Network Security
provider: Vectra AI
sectionorder:
- Connect
- Collect
commonfields:
  id: VectraXDR
  version: -1
configuration:
- additionalinfo: URL of the Vectra AI platform.
  display: Server URL
  name: server_url
  required: true
  type: 0
  section: Connect
- display: Client ID
  displaypassword: Client Secret Key
  name: credentials
  type: 9
  required: true
  section: Connect
- additionalinfo: When checked, no SSL certificates check will be done when interacting with the Vectra XDR API. It's insecure. (Default - unchecked)
  display: Trust any certificate (not secure)
  name: insecure
  required: false
  type: 8
  section: Connect
- additionalinfo: Use the system proxy settings to reach with the Vectra XDR API.
  display: Use system proxy settings
  name: proxy
  required: false
  type: 8
  section: Connect
- display: Fetch incidents
  name: isFetch
  required: false
  type: 8
  section: Collect
- additionalinfo: The maximum number of entities to fetch each time. If the value is greater than 200, it will be considered as 200. The maximum is 200.
  defaultvalue: '50'
  display: Max Fetch
  hidden: false
  name: max_fetch
  required: false
  type: 0
  section: Collect
- additionalinfo: "The date or relative timestamp from which to begin fetching entities.\n\nSupported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n    \nFor example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z."
  defaultvalue: 1 hour
  display: First Fetch Time
  hidden: false
  name: first_fetch
  required: false
  type: 0
  section: Collect
- additionalinfo: The mirroring direction in which to mirror the entities. You can mirror "Incoming" (from Vectra to XSOAR), "Outgoing" (from XSOAR to Vectra), or in both directions. Cortex XSOAR only parameter.
  display: Mirroring Direction
  hidden:
  - marketplacev2
  - platform
  name: mirror_direction
  options:
  - Incoming
  - Outgoing
  - Incoming And Outgoing
  required: false
  type: 15
  section: Collect
- additionalinfo: "If selected, new incidents will be created (via Outgoing Mirroring). If not selected, it reopens previously closed incidents (via Incoming Mirroring).\n\nNote: This flow is triggered only when the relevant entity is still active and the previously fetched incident is closed."
  defaultvalue: "false"
  display: Re-Fetch closed incidents via mirroring
  name: refetch_closed_incidents
  required: false
  type: 8
  section: Collect
- additionalinfo: The tag value should be used to mirror the entity note by adding the same tag in the notes.
  defaultvalue: note
  display: Mirror tag for notes
  hidden: false
  name: note_tag
  required: false
  type: 0
  section: Collect
- additionalinfo: Entity Type(Host, Account).
  display: Entity Type
  hidden: false
  name: entity_type
  options:
  - Account
  - Host
  required: false
  type: 16
  section: Collect
- additionalinfo: Retrieve only prioritize entities based on the configuration on the Vectra platform. If not selected will fetch all entities.
  defaultvalue: 'Yes'
  display: Prioritized
  hidden: false
  name: is_prioritized
  options:
  - 'Yes'
  - 'No'
  required: false
  type: 15
  section: Collect
- additionalinfo: Retrieve entities that contain any of the tags specified. Supports comma-separated values.
  display: Tags
  hidden: false
  name: tags
  required: false
  type: 0
  section: Collect
- additionalinfo: Retrieve detections belonging to a specified category.
  display: Detection Category
  hidden: false
  name: detection_category
  options:
  - Command & Control
  - Botnet
  - Reconnaissance
  - Lateral Movement
  - Exfiltration
  - Info
  required: false
  type: 15
  section: Collect
- additionalinfo: Retrieve detections belonging to a specified detection type.
  display: Detection Type
  hidden: false
  name: detection_type
  required: false
  type: 0
  section: Collect
- additionalinfo: If the entity's urgency score is equal to or less than the configured threshold, it would be considered as a "Low" Severity Incident. Default is 30.
  defaultvalue: '30'
  display: Specify the numeric value of "Urgency Score" for mapping the Low Incident Severity.
  hidden: false
  name: urgency_score_low_threshold
  required: false
  type: 0
  section: Collect
- additionalinfo: If the entity's urgency score is equal to or less than the configured threshold, it would be considered as a "Medium" Severity Incident.Default is 50.
  defaultvalue: '50'
  display: Specify the numeric value of "Urgency Score" for mapping the Medium Incident Severity.
  hidden: false
  name: urgency_score_medium_threshold
  required: false
  type: 0
  section: Collect
- additionalinfo: "If the entity's urgency score is equal to or less than the configured threshold, \nit would be considered as a \"High\" Severity Incident and if urgency score greater than threshold, it would be considered as a \"Critical\" Severity Incident. Default is 80."
  defaultvalue: '80'
  display: Specify the numeric value of "Urgency Score" for mapping the High Incident Severity.
  hidden: false
  name: urgency_score_high_threshold
  required: false
  type: 0
  section: Collect
- display: Incident type
  name: incidentType
  required: false
  type: 13
  section: Collect
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  section: Collect
  advanced: true
description: This integration allows to create incidents based on Vectra XDR Entities.
display: Vectra XDR
name: VectraXDR
script:
  commands:
  - arguments:
    - default: false
      description: Filter by username.
      isArray: false
      name: username
      required: false
      secret: false
    - auto: PREDEFINED
      default: false
      description: Filter users with the specified role.
      isArray: false
      name: role
      predefined:
      - Admin
      - Read-Only
      - Restricted Admin
      - Security Analyst
      - Setting Admin
      - Super Admin
      required: false
      secret: false
    - default: false
      description: |-
        Return only the users which have a last login timestamp equal to or after the given timestamp.

        Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

        For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
      isArray: false
      name: last_login_timestamp
      required: false
      secret: false
    deprecated: false
    description: Returns a list of users.
    execution: false
    name: vectra-user-list
    outputs:
    - contextPath: Vectra.User.id
      description: The ID of the User.
      type: Number
    - contextPath: Vectra.User.user_id
      description: The ID of the User.
      type: Number
    - contextPath: Vectra.User.username
      description: Username of the user.
      type: String
    - contextPath: Vectra.User.email
      description: The email associated with the user.
      type: String
    - contextPath: Vectra.User.role
      description: The role associated with the user.
      type: String
    - contextPath: Vectra.User.last_login_timestamp
      description: Last login timestamp in UTC format of the user.
      type: String
    - contextPath: Vectra.User.last_login
      description: Last login timestamp of the user.
      type: String
  - arguments:
    - auto: PREDEFINED
      default: false
      description: Fetch only entities whose priority score is above the configured priority threshold will be included in the response.
      isArray: false
      name: prioritized
      predefined:
      - 'true'
      - 'false'
      required: false
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: false
      secret: false
    - description: Filter by matching entity name.
      name: name
    - default: false
      description: Filter by a tag or a comma-separated list of tags.
      isArray: false
      name: tags
      required: false
      secret: false
    - auto: PREDEFINED
      default: false
      description: Filter on entity activation state.
      isArray: false
      name: state
      predefined:
      - active
      - inactive
      required: false
      secret: false
    - default: false
      description: Orders records by last timestamp or urgency score. Default sorting is by urgency score in descending order. Use the minus symbol (-) to sort scores in descending order. Multiple ordering fields can be specified with a comma-separated list (e.g., ordering=urgency_score,-name).
      isArray: false
      name: ordering
      required: false
      secret: false
    - default: false
      description: |-
        Return only the entities which have a last detection timestamp equal to or after the given timestamp.

        Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

        For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
      isArray: false
      name: last_detection_timestamp
      required: false
      secret: false
    - default: false
      defaultValue: '1'
      description: Enables the caller to specify a particular page of results.
      isArray: false
      name: page
      required: false
      secret: false
    - default: false
      defaultValue: '50'
      description: Specify the desired page size for the request. Maximum is 5000.
      isArray: false
      name: page_size
      required: false
      secret: false
    - default: false
      description: |-
        Return only the entities which have a last modified timestamp equal to or after the given timestamp.

        Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

        For example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z.
      isArray: false
      name: last_modified_timestamp
      required: false
      secret: false
    deprecated: false
    description: Returns a list of entities.
    execution: false
    name: vectra-entity-list
    outputs:
    - contextPath: Vectra.Entity.id
      description: ID of the entity.
      type: Number
    - contextPath: Vectra.Entity.name
      description: Name of the entity.
      type: String
    - contextPath: Vectra.Entity.breadth_contrib
      description: Breadth contribution of the entity.
      type: Number
    - contextPath: Vectra.Entity.importance
      description: Entity importance.
      type: Number
    - contextPath: Vectra.Entity.type
      description: Type of the entity.
      type: String
    - contextPath: Vectra.Entity.is_prioritized
      description: Entity is prioritized or not.
      type: Boolean
    - contextPath: Vectra.Entity.severity
      description: Severity of the entity.
      type: String
    - contextPath: Vectra.Entity.urgency_score
      description: Urgency score of the entity.
      type: Number
    - contextPath: Vectra.Entity.velocity_contrib
      description: Velocity contribution of the entity.
      type: Number
    - contextPath: Vectra.Entity.detection_set
      description: Set of detections related to entity.
      type: String
    - contextPath: Vectra.Entity.last_detection_timestamp
      description: Time of the last detection activity related to entity.
      type: Date
    - contextPath: Vectra.Entity.notes.id
      description: Notes of the entity.
      type: String
    - contextPath: Vectra.Entity.notes.dateCreated
      description: Created date of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.dateModified
      description: Modified date of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.createdBy
      description: Created user of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.ModifiedBy
      description: Modified user of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.note
      description: Note of the entity.
      type: String
    - contextPath: Vectra.Entity.attack_rating
      description: Attack Ratting of the entity.
      type: Number
    - contextPath: Vectra.Entity.privilege_level
      description: Privilege Level of the entity.
      type: String
    - contextPath: Vectra.Entity.privilege_category
      description: Privilege Category of the entity.
      type: String
    - contextPath: Vectra.Entity.attack_profile
      description: Attack Profile of the entity.
      type: String
    - contextPath: Vectra.Entity.sensors
      description: Sensors of the entity.
      type: Unknown
    - contextPath: Vectra.Entity.state
      description: State of the entity.
      type: String
    - contextPath: Vectra.Entity.tags
      description: Tags of the entity.
      type: Unknown
    - contextPath: Vectra.Entity.url
      description: Url link of the entity.
      type: String
    - contextPath: Vectra.Entity.host_type
      description: Host type of the entity.
      type: Unknown
    - contextPath: Vectra.Entity.account_type
      description: Account type of the entity.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - host
      - account
      required: true
      secret: false
    deprecated: false
    description: Describes an entity by ID.
    execution: false
    name: vectra-entity-describe
    outputs:
    - contextPath: Vectra.Entity.id
      description: ID of the entity.
      type: Number
    - contextPath: Vectra.Entity.name
      description: Name of the entity.
      type: String
    - contextPath: Vectra.Entity.breadth_contrib
      description: Breadth contribution of the entity.
      type: Number
    - contextPath: Vectra.Entity.importance
      description: Entity importance.
      type: Number
    - contextPath: Vectra.Entity.type
      description: Type of the entity.
      type: String
    - contextPath: Vectra.Entity.is_prioritized
      description: Entity is prioritized or not.
      type: Boolean
    - contextPath: Vectra.Entity.severity
      description: Severity of the entity.
      type: String
    - contextPath: Vectra.Entity.urgency_score
      description: Urgency score of the entity.
      type: Number
    - contextPath: Vectra.Entity.velocity_contrib
      description: Velocity contribution of the entity.
      type: Number
    - contextPath: Vectra.Entity.detection_set
      description: Set of detections related to the entity.
      type: String
    - contextPath: Vectra.Entity.last_detection_timestamp
      description: Time of the last detection activity related to the entity.
      type: Date
    - contextPath: Vectra.Entity.last_modified_timestamp
      description: Time of the last modification activity related to the entity.
      type: Date
    - contextPath: Vectra.Entity.notes.id
      description: Notes of the entity.
      type: String
    - contextPath: Vectra.Entity.notes.dateCreated
      description: Created date of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.dateModified
      description: Modified date of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.createdBy
      description: Created user of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.ModifiedBy
      description: Modified user of the Note.
      type: String
    - contextPath: Vectra.Entity.notes.note
      description: Note of the entity.
      type: String
    - contextPath: Vectra.Entity.attack_rating
      description: Attack Ratting of the entity.
      type: Number
    - contextPath: Vectra.Entity.privilege_level
      description: Privilege Level of the entity.
      type: String
    - contextPath: Vectra.Entity.privilege_category
      description: Privilege Category of the entity.
      type: String
    - contextPath: Vectra.Entity.attack_profile
      description: Attack Profile of the entity.
      type: String
    - contextPath: Vectra.Entity.sensors
      description: Sensors of the entity.
      type: Unknown
    - contextPath: Vectra.Entity.state
      description: State of the entity.
      type: String
    - contextPath: Vectra.Entity.tags
      description: Tags of the entity.
      type: Unknown
    - contextPath: Vectra.Entity.url
      description: Url link of the entity.
      type: String
    - contextPath: Vectra.Entity.host_type
      description: Host type of the entity.
      type: Unknown
    - contextPath: Vectra.Entity.account_type
      description: Account type of the entity.
      type: Unknown
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    - default: false
      defaultValue: '1'
      description: Enables the caller to specify a particular page of results.
      isArray: false
      name: page
      required: false
      secret: false
    - default: false
      defaultValue: '50'
      description: Specify the desired page size for the request. Maximum is 5000.
      isArray: false
      name: page_size
      required: false
      secret: false
    - auto: PREDEFINED
      default: false
      description: The category of the detection.
      isArray: false
      name: detection_category
      predefined:
      - Command & Control
      - Botnet
      - Reconnaissance
      - Lateral Movement
      - Exfiltration
      - Info
      required: false
      secret: false
    - default: false
      description: Filter by detection type.
      isArray: false
      name: detection_type
      required: false
      secret: false
    - default: false
      description: "Return only the detections which have a last timestamp equal to or after the given timestamp. \nFormats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours.\nExample: 2023-04-25T00:00:00Z, 2023-04-25, 2 days, 5 hours, 01 Mar 2023, 01 Feb 2023 04:45:33, 15 Jun."
      isArray: false
      name: last_timestamp
      required: false
      secret: false
    - default: false
      description: Filter by detection name.
      isArray: false
      name: detection_name
      required: false
      secret: false
    - default: false
      defaultValue: active
      description: Filter by state.
      isArray: false
      name: state
      required: false
      secret: false
    - default: false
      description: Filter by a tag or a comma-separated list of tags.
      isArray: false
      name: tags
      required: false
      secret: false
    deprecated: false
    description: Returns a list of detections for a specified entity.
    execution: false
    name: vectra-entity-detection-list
    outputs:
    - contextPath: Vectra.Entity.Detections.id
      description: Entity detection ID.
      type: Number
    - contextPath: Vectra.Entity.Detections.assigned_date
      description: Date assigned to the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.assigned_to
      description: User or entity assigned to the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.category
      description: Category of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.certainty
      description: Certainty level of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.c_score
      description: Confidence score of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.description
      description: Description of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.detection
      description: Detection information.
      type: String
    - contextPath: Vectra.Entity.Detections.detection_category
      description: Category of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.detection_type
      description: Type of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.external_target.ip
      description: IP address of the external target in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.external_target.name
      description: Name of the external target in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.num_sessions
      description: Number of sessions in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.bytes_received
      description: Total bytes received in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.bytes_sent
      description: Total bytes sent in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.ja3_hashes
      description: JA3 hashes in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.ja3s_hashes
      description: JA3S hashes in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.tunnel_type
      description: Tunnel type used in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.protocol
      description: Protocol used in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.app_protocol
      description: Application protocol used in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_port
      description: Destination port in the sessions of the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_ip
      description: Destination IP address in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.bytes_received
      description: Total bytes received in the sessions of the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.bytes_sent
      description: Total bytes sent in the sessions of the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.first_timestamp
      description: First timestamp of the sessions in the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.last_timestamp
      description: Last timestamp of the sessions in the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_geo
      description: Geolocation of the destination IP in the sessions of the detection group.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lat
      description: Latitude of the destination IP in the sessions of the detection group.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lon
      description: Longitude of the destination IP in the sessions of the detection group.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.grouped_details.first_timestamp
      description: First timestamp of the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.last_timestamp
      description: Last timestamp of the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.dst_ips
      description: Destination IP addresses in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.dst_ports
      description: Destination ports in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.target_domains
      description: Target domains in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.is_targeting_key_asset
      description: Indicates if the detection is targeting a key asset.
      type: Boolean
    - contextPath: Vectra.Entity.Detections.last_timestamp
      description: Last timestamp of the detection.
      type: Date
    - contextPath: Vectra.Entity.Detections.note
      description: Note associated with the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.note_modified_by
      description: User or entity who last modified the note.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.note_modified_timestamp
      description: Timestamp when the note was last modified.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.notes
      description: Additional notes related to the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.sensor_name
      description: Name of the sensor associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_account.id
      description: ID of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.name
      description: Name of the source account associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_account.url
      description: URL of the source account associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_account.threat
      description: Threat level of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.certainty
      description: Certainty level of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.privilege_level
      description: Privilege level of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.privilege_category
      description: Privilege category of the source account associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.id
      description: ID of the source host in the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_host.ip
      description: IP address of the source host in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.name
      description: Name of the source host in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.url
      description: URL associated with the source host in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.is_key_asset
      description: Indicates if the source host is a key asset.
      type: Boolean
    - contextPath: Vectra.Entity.Detections.src_host.groups
      description: Groups associated with the source host in the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.src_host.threat
      description: Threat level associated with the source host in the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_host.certainty
      description: Certainty level associated with the source host in the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_ip
      description: Source IP address in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.state
      description: State of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.summary.bytes_received
      description: Total bytes received in the detection summary.
      type: Number
    - contextPath: Vectra.Entity.Detections.summary.bytes_sent
      description: Total bytes sent in the detection summary.
      type: Number
    - contextPath: Vectra.Entity.Detections.summary.cnc_server
      description: CNC server associated with the detection summary.
      type: String
    - contextPath: Vectra.Entity.Detections.summary.num_events
      description: Total number of events related to the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.summary.probable_owner
      description: Probable owner of the detection summary.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.summary.sessions
      description: Total sessions in the detection summary.
      type: Number
    - contextPath: Vectra.Entity.Detections.tags
      description: Tags associated with the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.threat
      description: Threat level of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.t_score
      description: T-score of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.type
      description: Type of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.url
      description: URL associated with the detection.
      type: String
  - arguments:
    - default: false
      description: Specify the ID(s) of the detections.
      isArray: true
      name: detection_ids
      required: true
      secret: false
    - default: false
      defaultValue: '1'
      description: Enables the caller to specify a particular page of results.
      isArray: false
      name: page
      required: false
      secret: false
    - default: false
      defaultValue: '50'
      description: Specify the desired page size for the request. Maximum is 5000.
      isArray: false
      name: page_size
      required: false
      secret: false
    deprecated: false
    description: Returns a list of detections for the specified detection ID(s).
    execution: false
    name: vectra-detection-describe
    outputs:
    - contextPath: Vectra.Entity.Detections.id
      description: Entity detection ID.
      type: Number
    - contextPath: Vectra.Entity.Detections.assigned_date
      description: Date assigned to the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.assigned_to
      description: User or entity assigned to the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.category
      description: Category of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.certainty
      description: Certainty level of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.c_score
      description: Confidence score of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.description
      description: Description of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.detection
      description: Detection information.
      type: String
    - contextPath: Vectra.Entity.Detections.detection_category
      description: Category of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.detection_type
      description: Type of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.external_target.ip
      description: IP address of the external target in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.external_target.name
      description: Name of the external target in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.num_sessions
      description: Number of sessions in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.bytes_received
      description: Total bytes received in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.bytes_sent
      description: Total bytes sent in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.ja3_hashes
      description: JA3 hashes in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.ja3s_hashes
      description: JA3S hashes in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.tunnel_type
      description: Tunnel type used in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.protocol
      description: Protocol used in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.app_protocol
      description: Application protocol used in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_port
      description: Destination port in the sessions of the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_ip
      description: Destination IP address in the sessions of the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.bytes_received
      description: Total bytes received in the sessions of the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.bytes_sent
      description: Total bytes sent in the sessions of the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.first_timestamp
      description: First timestamp of the sessions in the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.last_timestamp
      description: Last timestamp of the sessions in the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_geo
      description: Geolocation of the destination IP in the sessions of the detection group.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lat
      description: Latitude of the destination IP in the sessions of the detection group.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.grouped_details.sessions.dst_geo_lon
      description: Longitude of the destination IP in the sessions of the detection group.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.grouped_details.first_timestamp
      description: First timestamp of the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.last_timestamp
      description: Last timestamp of the detection group.
      type: Date
    - contextPath: Vectra.Entity.Detections.grouped_details.dst_ips
      description: Destination IP addresses in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.grouped_details.dst_ports
      description: Destination ports in the detection group.
      type: Number
    - contextPath: Vectra.Entity.Detections.grouped_details.target_domains
      description: Target domains in the detection group.
      type: String
    - contextPath: Vectra.Entity.Detections.is_targeting_key_asset
      description: Indicates if the detection is targeting a key asset.
      type: Boolean
    - contextPath: Vectra.Entity.Detections.last_timestamp
      description: Last timestamp of the detection.
      type: Date
    - contextPath: Vectra.Entity.Detections.note
      description: Note associated with the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.note_modified_by
      description: User or entity who last modified the note.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.note_modified_timestamp
      description: Timestamp when the note was last modified.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.notes
      description: Additional notes related to the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.sensor_name
      description: Name of the sensor associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_account.id
      description: ID of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.name
      description: Name of the source account associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_account.url
      description: URL of the source account associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_account.threat
      description: Threat level of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.certainty
      description: Certainty level of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.privilege_level
      description: Privilege level of the source account associated with the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_account.privilege_category
      description: Privilege category of the source account associated with the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.id
      description: ID of the source host in the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_host.ip
      description: IP address of the source host in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.name
      description: Name of the source host in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.url
      description: URL associated with the source host in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.src_host.is_key_asset
      description: Indicates if the source host is a key asset.
      type: Boolean
    - contextPath: Vectra.Entity.Detections.src_host.groups
      description: Groups associated with the source host in the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.src_host.threat
      description: Threat level associated with the source host in the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_host.certainty
      description: Certainty level associated with the source host in the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.src_ip
      description: Source IP address in the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.state
      description: State of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.summary.bytes_received
      description: Total bytes received in the detection summary.
      type: Number
    - contextPath: Vectra.Entity.Detections.summary.bytes_sent
      description: Total bytes sent in the detection summary.
      type: Number
    - contextPath: Vectra.Entity.Detections.summary.cnc_server
      description: CNC server associated with the detection summary.
      type: String
    - contextPath: Vectra.Entity.Detections.summary.num_events
      description: Total number of events related to the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.summary.probable_owner
      description: Probable owner of the detection summary.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.summary.sessions
      description: Total sessions in the detection summary.
      type: Number
    - contextPath: Vectra.Entity.Detections.tags
      description: Tags associated with the detection.
      type: Unknown
    - contextPath: Vectra.Entity.Detections.threat
      description: Threat level of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.t_score
      description: T-score of the detection.
      type: Number
    - contextPath: Vectra.Entity.Detections.type
      description: Type of the detection.
      type: String
    - contextPath: Vectra.Entity.Detections.url
      description: URL associated with the detection.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    - default: false
      description: Note to be added in the specified entity_id.
      isArray: false
      name: note
      required: true
      secret: false
    deprecated: false
    description: Add a note to the entity.
    execution: false
    name: vectra-entity-note-add
    outputs:
    - contextPath: Vectra.Entity.Notes.entity_id
      description: ID of the entity associated with the note.
      type: String
    - contextPath: Vectra.Entity.Notes.note_id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Entity.Notes.date_created
      description: Date when the note was created.
      type: Date
    - contextPath: Vectra.Entity.Notes.date_modified
      description: Date when the note was last modified.
      type: Unknown
    - contextPath: Vectra.Entity.Notes.created_by
      description: User who created the note.
      type: String
    - contextPath: Vectra.Entity.Notes.modified_by
      description: User who last modified the note.
      type: Unknown
    - contextPath: Vectra.Entity.Notes.note
      description: Content of the note.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the detection.
      isArray: false
      name: detection_id
      required: true
      secret: false
    - default: false
      description: Note to be added in the specified detection_id.
      isArray: false
      name: note
      required: true
      secret: false
    deprecated: false
    description: Add a note to the detection.
    execution: false
    name: vectra-detection-note-add
    outputs:
    - contextPath: Vectra.Detection.Notes.detection_id
      description: ID of the detection associated with the note.
      type: String
    - contextPath: Vectra.Detection.Notes.note_id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Detection.Notes.id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Detection.Notes.date_created
      description: Date when the note was created  (ISO8601).
      type: Date
    - contextPath: Vectra.Detection.Notes.created_by
      description: User who created the note.
      type: String
    - contextPath: Vectra.Detection.Notes.note
      description: Content of the note.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    - default: false
      description: Specify the ID of the note.
      isArray: false
      name: note_id
      required: true
      secret: false
    - default: false
      description: Note to be updated for the specified note_id.
      isArray: false
      name: note
      required: true
      secret: false
    deprecated: false
    description: Update a note in the entity.
    execution: false
    name: vectra-entity-note-update
    outputs:
    - contextPath: Vectra.Entity.Notes.entity_id
      description: ID of the entity associated with the note.
      type: String
    - contextPath: Vectra.Entity.Notes.note_id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Entity.Notes.date_created
      description: Date when the note was created.
      type: Date
    - contextPath: Vectra.Entity.Notes.date_modified
      description: Date when the note was last modified.
      type: Unknown
    - contextPath: Vectra.Entity.Notes.created_by
      description: User who created the note.
      type: String
    - contextPath: Vectra.Entity.Notes.modified_by
      description: User who last modified the note.
      type: Unknown
    - contextPath: Vectra.Entity.Notes.note
      description: Content of the note.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the detection.
      isArray: false
      name: detection_id
      required: true
      secret: false
    - default: false
      description: Specify the ID of the note.
      isArray: false
      name: note_id
      required: true
      secret: false
    - default: false
      description: Note to be updated for the specified note_id.
      isArray: false
      name: note
      required: true
      secret: false
    deprecated: false
    description: Update a note in the detection.
    execution: false
    name: vectra-detection-note-update
    outputs:
    - contextPath: Vectra.Detection.Notes.detection_id
      description: ID of the detection associated with the note.
      type: String
    - contextPath: Vectra.Detection.Notes.note_id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Detection.Notes.id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Detection.Notes.date_created
      description: Date when the note was created (ISO8601).
      type: Date
    - contextPath: Vectra.Detection.Notes.date_modified
      description: Date when the note was last modified (ISO8601).
      type: Date
    - contextPath: Vectra.Detection.Notes.created_by
      description: User who created the note.
      type: String
    - contextPath: Vectra.Detection.Notes.modified_by
      description: User who last modified the note.
      type: String
    - contextPath: Vectra.Detection.Notes.note
      description: Content of the note.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    - default: false
      description: Specify the ID of the note.
      isArray: false
      name: note_id
      required: true
      secret: false
    deprecated: false
    description: Remove a note from the entity.
    execution: false
    name: vectra-entity-note-remove
  - arguments:
    - default: false
      description: Specify the ID of the detection.
      isArray: false
      name: detection_id
      required: true
      secret: false
    - default: false
      description: Specify the ID of the note.
      isArray: false
      name: note_id
      required: true
      secret: false
    deprecated: false
    description: Remove a note from the detection.
    execution: false
    name: vectra-detection-note-remove
  - arguments:
    - default: false
      description: Provide a list of detection IDs separated by commas or a single detection ID.
      isArray: false
      name: detection_ids
      required: true
      secret: false
    deprecated: false
    description: Mark detection as fixed with provided detection IDs in argument.
    execution: false
    name: vectra-detections-mark-fixed
  - arguments:
    - default: false
      description: Provide a list of detection IDs separated by commas or a single detection ID.
      isArray: false
      name: detection_ids
      required: true
      secret: false
    deprecated: false
    description: Unmark detection as fixed with provided detection IDs in argument.
    execution: false
    name: vectra-detections-unmark-fixed
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    - default: false
      description: Comma-separated values of tags to be included in the entity.
      isArray: true
      name: tags
      required: true
      secret: false
    deprecated: false
    description: Add tags in the entity.
    execution: false
    name: vectra-entity-tag-add
    outputs:
    - contextPath: Vectra.Entity.Tags.tag_id
      description: ID of the tag.
      type: String
    - contextPath: Vectra.Entity.Tags.entity_id
      description: ID of the entity associated with the tag.
      type: String
    - contextPath: Vectra.Entity.Tags.entity_type
      description: Type of the entity.
      type: String
    - contextPath: Vectra.Entity.Tags.tags
      description: A list of tags linked to an entity.
      type: Unknown
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      required: true
      secret: false
      auto: PREDEFINED
      predefined:
      - account
      - host
    - default: false
      description: Comma-separated values of tags to be removed from the entity.
      isArray: true
      name: tags
      required: true
      secret: false
    deprecated: false
    description: Remove tags from the entity.
    execution: false
    name: vectra-entity-tag-remove
    outputs:
    - contextPath: Vectra.Entity.Tags.tag_id
      description: ID of the tag.
      type: String
    - contextPath: Vectra.Entity.Tags.entity_id
      description: ID of the entity associated with the tag.
      type: String
    - contextPath: Vectra.Entity.Tags.entity_type
      description: Type of the entity.
      type: String
    - contextPath: Vectra.Entity.Tags.tags
      description: A list of tags linked to an entity.
      type: Unknown
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    deprecated: false
    description: Returns a list of tags for a specified entity.
    execution: false
    name: vectra-entity-tag-list
    outputs:
    - contextPath: Vectra.Entity.Tags.tag_id
      description: ID of the tag.
      type: String
    - contextPath: Vectra.Entity.Tags.entity_id
      description: ID of the entity associated with the tag.
      type: String
    - contextPath: Vectra.Entity.Tags.entity_type
      description: Type of the entity.
      type: String
    - contextPath: Vectra.Entity.Tags.tags
      description: A list of tags linked to an entity.
      type: Unknown
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    - default: false
      description: Specify the ID of the user.
      isArray: false
      name: user_id
      required: true
      secret: false
    deprecated: false
    description: Add an assignment for the entity.
    execution: false
    name: vectra-entity-assignment-add
    outputs:
    - contextPath: Vectra.Entity.Assignments.id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assignment_id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.id
      description: ID of the user who assigned the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.username
      description: Username of the user who assigned the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.date_assigned
      description: Date when the entity was assigned.
      type: Date
    - contextPath: Vectra.Entity.Assignments.date_resolved
      description: Date when the entity was resolved.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.assignment_id
      description: ID of the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.actor
      description: ID of the actor who performed the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.event_type
      description: Type of assignment event.
      type: String
    - contextPath: Vectra.Entity.Assignments.events.datetime
      description: Date of the assignment event.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.context.to
      description: ID of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_t_score
      description: Threat score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_c_score
      description: Certainty score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.outcome.id
      description: ID of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.builtin
      description: Whether the assignment outcome is builtin or not.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.user_selectable
      description: Whether the assignment outcome is user selectable or not.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.title
      description: Title of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.category
      description: Category of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.resolved_by.id
      description: ID of the user who resolved the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.resolved_by.username
      description: Username of the user who resolved the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.triaged_detections
      description: Number of detections that have been triaged for the entity.
      type: Unknown
    - contextPath: Vectra.Entity.Assignments.host_id
      description: ID of the host that the entity is associated with.
      type: Number
    - contextPath: Vectra.Entity.Assignments.account_id
      description: ID of the account that the entity is associated with.
      type: Unknown
    - contextPath: Vectra.Entity.Assignments.assigned_to.id
      description: ID of the user who is currently assigned to the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_to.username
      description: Username of the user who is currently assigned to the entity.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the assignment.
      isArray: false
      name: assignment_id
      required: true
      secret: false
    - default: false
      description: Specify the ID of the user.
      isArray: false
      name: user_id
      required: true
      secret: false
    deprecated: false
    description: Update an assignment in the entity.
    execution: false
    name: vectra-entity-assignment-update
    outputs:
    - contextPath: Vectra.Entity.Assignments.id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assignment_id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.id
      description: ID of the user who assigned the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.username
      description: Username of the user who assigned the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.date_assigned
      description: Date when the entity was assigned.
      type: Date
    - contextPath: Vectra.Entity.Assignments.date_resolved
      description: Date when the entity was resolved.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.assignment_id
      description: ID of the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.actor
      description: ID of the actor who performed the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.event_type
      description: Type of assignment event.
      type: String
    - contextPath: Vectra.Entity.Assignments.events.datetime
      description: Date of the assignment event.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.context.to
      description: ID of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.from
      description: ID of the entity that was assigned.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_t_score
      description: Threat score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_c_score
      description: Certainty score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.outcome.id
      description: ID of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.builtin
      description: Whether the assignment outcome is builtin or not.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.user_selectable
      description: Whether the assignment outcome is user selectable or not.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.title
      description: Title of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.category
      description: Category of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.resolved_by.id
      description: ID of the user who resolved the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.resolved_by.username
      description: Username of the user who resolved the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.triaged_detections
      description: Number of detections that have been triaged for the entity.
      type: Unknown
    - contextPath: Vectra.Entity.Assignments.host_id
      description: ID of the host that the entity is associated with.
      type: Number
    - contextPath: Vectra.Entity.Assignments.account_id
      description: ID of the account that the entity is associated with.
      type: Unknown
    - contextPath: Vectra.Entity.Assignments.assigned_to.id
      description: ID of the user who is currently assigned to the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_to.username
      description: Username of the user who is currently assigned to the entity.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the assignment.
      isArray: false
      name: assignment_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the Outcome for resolving an assignment in the entity. The custom outcome is allowed.
      isArray: false
      name: outcome
      predefined:
      - Benign True Positive
      - Malicious True Positive
      - False Positive
      required: true
      secret: false
    - default: false
      description: A note to be added for resolving an assignment in the entity.
      isArray: false
      name: note
      required: false
      secret: false
      defaultValue: Updated by XSOAR.
    - default: false
      description: Triage rule for resolving an assignment in the entity.
      isArray: false
      name: triage_as
      required: false
      secret: false
    - default: false
      description: Provide a list of detection IDs separated by commas or a single detection ID.
      isArray: false
      name: detection_ids
      required: false
      secret: false
    deprecated: false
    description: Resolve an assignment in the entity.
    execution: false
    name: vectra-entity-assignment-resolve
    outputs:
    - contextPath: Vectra.Entity.Assignments.id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assignment_id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.id
      description: ID of the user who assigned the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.username
      description: Username of the user who assigned the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.date_assigned
      description: Date when the entity was assigned.
      type: Date
    - contextPath: Vectra.Entity.Assignments.date_resolved
      description: Date when the entity was resolved.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.assignment_id
      description: ID of the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.actor
      description: ID of the actor who performed the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.event_type
      description: Type of the assignment event.
      type: String
    - contextPath: Vectra.Entity.Assignments.events.datetime
      description: Date of the assignment event.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.context.to
      description: ID of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_t_score
      description: Threat score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_c_score
      description: Certainty score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.triage_as
      description: Triage status of the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.events.context.triaged_detection_ids
      description: IDs of the detections that have been triaged for the entity.
      type: Array
    - contextPath: Vectra.Entity.Assignments.events.context.fixed_detection_ids
      description: IDs of the detections that have been fixed.
      type: Array
    - contextPath: Vectra.Entity.Assignments.events.context.created_rule_ids
      description: IDs of the rules that have been created for the entity.
      type: Array
    - contextPath: Vectra.Entity.Assignments.outcome.id
      description: ID of the assignment outcome.
      type: Number
    - contextPath: Vectra.Entity.Assignments.outcome.builtin
      description: Whether the assignment outcome is builtin or not.
      type: Boolean
    - contextPath: Vectra.Entity.Assignments.outcome.user_selectable
      description: Whether the assignment outcome is user selectable or not.
      type: Boolean
    - contextPath: Vectra.Entity.Assignments.outcome.title
      description: Title of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.category
      description: Category of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.resolved_by.id
      description: ID of the user who resolved the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.resolved_by.username
      description: Username of the user who resolved the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.triaged_detections
      description: Number of detections that have been triaged for the entity.
      type: Array
    - contextPath: Vectra.Entity.Assignments.host_id
      description: ID of the host that the entity is associated with.
      type: Number
    - contextPath: Vectra.Entity.Assignments.account_id
      description: ID of the account that the entity is associated with.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_to.id
      description: ID of the user who is currently assigned to the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_to.username
      description: Username of the user who is currently assigned to the entity.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the detection.
      isArray: false
      name: detection_id
      required: true
      secret: false
    deprecated: false
    description: Download pcap of the detection.
    execution: false
    name: vectra-detection-pcap-download
    outputs:
    - contextPath: File.Size
      description: The size of the file.
      type: Number
    - contextPath: File.SHA1
      description: The SHA1 hash of the file.
      type: String
    - contextPath: File.SHA256
      description: The SHA256 hash of the file.
      type: String
    - contextPath: File.SHA512
      description: The SHA512 hash of the file.
      type: String
    - contextPath: File.Name
      description: The name of the file.
      type: String
    - contextPath: File.SSDeep
      description: The SSDeep hash of the file.
      type: String
    - contextPath: File.EntryID
      description: The entry ID of the file.
      type: String
    - contextPath: File.Info
      description: File information.
      type: String
    - contextPath: File.Type
      description: The file type.
      type: String
    - contextPath: File.MD5
      description: The MD5 hash of the file.
      type: String
    - contextPath: File.Extension
      description: The file extension.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    deprecated: false
    description: Mark the detections of the entity as fixed with the provided entity ID in the argument.
    execution: false
    name: vectra-entity-detections-mark-fixed
  - arguments:
    - default: false
      description: Specify the IDs of the entities. Comma-separated values supported.
      isArray: false
      name: entity_ids
      required: false
      secret: false
    - default: false
      description: |-
        Specify the type of the entity.
      isArray: false
      name: entity_type
      required: false
      secret: false
      auto: PREDEFINED
      predefined:
      - account
      - host
    - default: false
      description: |-
        Filter by resolved status.
      isArray: false
      name: resolved
      required: false
      secret: false
      auto: PREDEFINED
      predefined:
      - 'True'
      - 'False'
    - default: false
      description: |-
        Filter by user ids of the assignment. Comma-separated values supported.
      isArray: false
      name: assignees
      required: false
      secret: false
    - default: false
      description: |-
        Filter by outcome ids of the resolution. Comma-separated values supported.
      isArray: false
      name: resolution
      required: false
      secret: false
    - default: false
      description: "Filter by created after the timestamp.\n\nSupported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n    \nFor example: 01 May 2023, 01 Mar 2021 04:45:33, 2022-04-17T14:05:44Z."
      isArray: false
      name: created_after
      required: false
      secret: false
    - default: false
      description: |-
        Enables the caller to specify a particular page of results.
      isArray: false
      name: page
      required: false
      secret: false
      defaultValue: '1'
    - default: false
      description: Specify the desired page size for the request.
      isArray: false
      name: page_size
      required: false
      secret: false
      defaultValue: '50'
    deprecated: false
    description: Returns a list of all assignments.
    execution: false
    name: vectra-assignment-list
    outputs:
    - contextPath: Vectra.Entity.Assignments.id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assignment_id
      description: ID of the assignment.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.id
      description: ID of the user who assigned the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_by.username
      description: Username of the user who assigned the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.date_assigned
      description: Date when the entity was assigned.
      type: Date
    - contextPath: Vectra.Entity.Assignments.date_resolved
      description: Date when the entity was resolved.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.assignment_id
      description: ID of the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.actor
      description: ID of the actor who performed the assignment event.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.event_type
      description: Type of the assignment event.
      type: String
    - contextPath: Vectra.Entity.Assignments.events.datetime
      description: Date of the assignment event.
      type: Date
    - contextPath: Vectra.Entity.Assignments.events.context.to
      description: ID of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_t_score
      description: Threat score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.entity_c_score
      description: Certainty score of the entity that was assigned to.
      type: Number
    - contextPath: Vectra.Entity.Assignments.events.context.triage_as
      description: Triage status of the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.events.context.triaged_detection_ids
      description: IDs of the detections that have been triaged for the entity.
      type: Array
    - contextPath: Vectra.Entity.Assignments.events.context.fixed_detection_ids
      description: IDs of the detections that have been fixed.
      type: Array
    - contextPath: Vectra.Entity.Assignments.events.context.created_rule_ids
      description: IDs of the rules that have been created for the entity.
      type: Array
    - contextPath: Vectra.Entity.Assignments.outcome.id
      description: ID of the assignment outcome.
      type: Number
    - contextPath: Vectra.Entity.Assignments.outcome.builtin
      description: Whether the assignment outcome is builtin or not.
      type: Boolean
    - contextPath: Vectra.Entity.Assignments.outcome.user_selectable
      description: Whether the assignment outcome is user selectable or not.
      type: Boolean
    - contextPath: Vectra.Entity.Assignments.outcome.title
      description: Title of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.outcome.category
      description: Category of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.resolved_by.id
      description: ID of the user who resolved the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.resolved_by.username
      description: Username of the user who resolved the entity.
      type: String
    - contextPath: Vectra.Entity.Assignments.triaged_detections
      description: Number of detections that have been triaged for the entity.
      type: Array
    - contextPath: Vectra.Entity.Assignments.host_id
      description: ID of the host that the entity is associated with.
      type: Number
    - contextPath: Vectra.Entity.Assignments.account_id
      description: ID of the account that the entity is associated with.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_to.id
      description: ID of the user who is currently assigned to the entity.
      type: Number
    - contextPath: Vectra.Entity.Assignments.assigned_to.username
      description: Username of the user who is currently assigned to the entity.
      type: String
  - arguments:
    - default: false
      description: Enables the caller to specify a particular page of results.
      isArray: false
      name: page
      required: false
      secret: false
      defaultValue: '1'
    - default: false
      description: "Specify the desired page size for the request."
      isArray: false
      name: page_size
      required: false
      secret: false
      defaultValue: '50'
    deprecated: false
    description: Returns a list of all entity assignment outcomes.
    execution: false
    name: vectra-assignment-outcome-list
    outputs:
    - contextPath: Vectra.Entity.Assignments.Outcomes.id
      description: ID of the assignment outcome.
      type: Number
    - contextPath: Vectra.Entity.Assignments.Outcomes.builtin
      description: Whether the assignment outcome is builtin or not.
      type: Boolean
    - contextPath: Vectra.Entity.Assignments.Outcomes.user_selectable
      description: Whether the assignment outcome is user selectable or not.
      type: Boolean
    - contextPath: Vectra.Entity.Assignments.Outcomes.title
      description: Title of the assignment outcome.
      type: String
    - contextPath: Vectra.Entity.Assignments.Outcomes.category
      description: Category of the assignment outcome.
      type: String
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - default: false
      description: "Specify the type of the entity."
      isArray: false
      name: entity_type
      required: true
      secret: false
      auto: PREDEFINED
      predefined:
      - host
      - account
    deprecated: false
    description: Returns a list of notes for a specified entity.
    execution: false
    name: vectra-entity-note-list
    outputs:
    - contextPath: Vectra.Entity.Notes.note_id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Entity.Notes.id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Entity.Notes.date_created
      description: Date when the note was created (ISO8601).
      type: Date
    - contextPath: Vectra.Entity.Notes.date_modified
      description: Date when the note was last modified (ISO8601).
      type: Unknown
    - contextPath: Vectra.Entity.Notes.created_by
      description: User who created the note.
      type: String
    - contextPath: Vectra.Entity.Notes.modified_by
      description: User who last modified the note.
      type: Unknown
    - contextPath: Vectra.Entity.Notes.note
      description: Content of the note.
      type: String
    - contextPath: Vectra.Entity.Notes.entity_id
      description: ID of the entity associated with the note.
      type: String
    - contextPath: Vectra.Entity.Notes.entity_type
      description: Type of the entity associated with the note.
      type: String
  - arguments:
    - description: Specify the ID of the detection.
      name: detection_id
      required: true
      default: false
      isArray: false
      secret: false
    description: Returns a list of notes for a specified detection.
    execution: false
    name: vectra-detection-note-list
    deprecated: false
    outputs:
    - contextPath: Vectra.Detection.Notes.note_id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Detection.Notes.id
      description: ID of the note.
      type: Number
    - contextPath: Vectra.Detection.Notes.date_created
      description: Date when the note was created (ISO8601).
      type: Date
    - contextPath: Vectra.Detection.Notes.date_modified
      description: Date when the note was last modified (ISO8601).
      type: Date
    - contextPath: Vectra.Detection.Notes.created_by
      description: User who created the note.
      type: String
    - contextPath: Vectra.Detection.Notes.modified_by
      description: User who last modified the note.
      type: String
    - contextPath: Vectra.Detection.Notes.note
      description: Content of the note.
      type: String
    - contextPath: Vectra.Detection.Notes.detection_id
      description: ID of the detection associated with the note.
      type: String
  - arguments:
    - description: Filter by group type.
      isArray: false
      name: group_type
      required: false
      auto: PREDEFINED
      default: false
      predefined:
      - account
      - host
      - ip
      - domain
      secret: false
    - description: |-
        Filter by Account Names. Supports comma-separated values.

        Note: Only valid when the group_type parameter is set to "account".
      name: account_names
      required: false
      default: false
      isArray: true
      secret: false
    - default: false
      description: |-
        Filter by Domains. Supports comma-separated values.

        Note: Only valid when the group_type parameter is set to "domain".
      isArray: true
      name: domains
      required: false
      secret: false
    - default: false
      description: |-
        Filter by Host IDs. Supports comma-separated values.

        Note: Only valid when the group_type parameter is set to "host".
      isArray: true
      name: host_ids
      required: false
      secret: false
    - default: false
      description: |-
        Filter by Host Names. Supports comma-separated values.

        Note: Only valid when the group_type parameter is set to "host".
      isArray: true
      name: host_names
      required: false
      secret: false
    - auto: PREDEFINED
      default: false
      description: Filter by group importance.
      isArray: false
      name: importance
      predefined:
      - high
      - medium
      - low
      - never_prioritize
      required: false
      secret: false
    - default: false
      description: |-
        Filter by IPs. Supports comma-separated values.

        Note: Only valid when the group_type parameter is set to "ip".
      isArray: true
      name: ips
      required: false
      secret: false
    - default: false
      description: Filter by group description.
      isArray: false
      name: description
      required: false
      secret: false
    - default: false
      description: |-
        Return only the groups which have a last modification timestamp equal to or after the given timestamp.

        Supported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.

        For example: 01 May 2023, 01 Mar 2023 04:45:33, 2023-04-17T14:05:44Z.
      isArray: false
      name: last_modified_timestamp
      required: false
      secret: false
    - default: false
      description: Filters by the user ID who made the most recent modification to the group.
      isArray: false
      name: last_modified_by
      required: false
      secret: false
    - default: false
      description: Filters by group name.
      isArray: false
      name: group_name
      required: false
      secret: false
    description: Returns a list of all groups.
    execution: false
    name: vectra-group-list
    deprecated: false
    outputs:
    - contextPath: Vectra.Group.group_id
      description: ID of the group.
      type: Number
    - contextPath: Vectra.Group.id
      description: ID of the group.
      type: Number
    - contextPath: Vectra.Group.name
      description: Name of the group.
      type: String
    - contextPath: Vectra.Group.description
      description: Description of the group.
      type: String
    - contextPath: Vectra.Group.last_modified
      description: Date when the group was last modified.
      type: Date
    - contextPath: Vectra.Group.last_modified_by
      description: Name of the user who last modified the group.
      type: String
    - contextPath: Vectra.Group.type
      description: Type of the group.
      type: String
    - contextPath: Vectra.Group.members
      description: Members of the group.
      type: Unknown
    - contextPath: Vectra.Group.members.id
      description: Entity ID of member.
      type: Number
    - contextPath: Vectra.Group.members.name
      description: Entity name of member.
      type: String
    - contextPath: Vectra.Group.members.is_key_asset
      description: Indicates key asset.
      type: Boolean
    - contextPath: Vectra.Group.members.url
      description: Entity URL of member.
      type: String
    - contextPath: Vectra.Group.members.uid
      description: Entity UID of member.
      type: String
    - contextPath: Vectra.Group.rules.triage_category
      description: Triage category of rule.
      type: String
    - contextPath: Vectra.Group.rules.id
      description: Id of the rule.
      type: Number
    - contextPath: Vectra.Group.rules.description
      description: Description of the rule.
      type: String
    - contextPath: Vectra.Group.importance
      description: Importance level of the group.
      type: String
    - contextPath: Vectra.Group.cognito_managed
      description: Whether the group is managed by Cognito or not.
      type: Boolean
  - arguments:
    - description: Specify Group ID to unassign members.
      isArray: false
      name: group_id
      required: true
      default: false
      secret: false
    - default: false
      description: "Member values based on the group type. Supports comma-separated values.\n\n Note: \nIf the group type is host, then the \"Host IDs\". \nIf the group type is account, then \"Account Names\".\nIf the group type is ip, then the list of \"IPs\".\nIf the group type is domain, then the list of \"Domains\" ."
      isArray: true
      name: members
      required: true
      secret: false
    description: Unassign members from the specified group.
    execution: false
    name: vectra-group-unassign
    deprecated: false
    outputs:
    - contextPath: Vectra.Group.group_id
      description: ID of the group.
      type: Number
    - contextPath: Vectra.Group.id
      description: ID of the group.
      type: Number
    - contextPath: Vectra.Group.name
      description: Name of the group.
      type: String
    - contextPath: Vectra.Group.description
      description: Description of the group.
      type: String
    - contextPath: Vectra.Group.last_modified
      description: Date when the group was last modified.
      type: Date
    - contextPath: Vectra.Group.last_modified_by
      description: Name of the user who last modified the group.
      type: String
    - contextPath: Vectra.Group.type
      description: Type of the group.
      type: String
    - contextPath: Vectra.Group.members
      description: Members of the group.
      type: Unknown
    - contextPath: Vectra.Group.members.id
      description: Entity ID of member.
      type: Number
    - contextPath: Vectra.Group.members.name
      description: Entity name of member.
      type: String
    - contextPath: Vectra.Group.members.is_key_asset
      description: Indicates key asset.
      type: Boolean
    - contextPath: Vectra.Group.members.url
      description: Entity URL of member.
      type: String
    - contextPath: Vectra.Group.members.uid
      description: Entity UID of member.
      type: String
    - contextPath: Vectra.Group.rules.triage_category
      description: Triage category of rule.
      type: String
    - contextPath: Vectra.Group.rules.id
      description: Id of the rule.
      type: Number
    - contextPath: Vectra.Group.rules.description
      description: Description of the rule.
      type: String
  - arguments:
    - description: Specify Group ID to assign members.
      name: group_id
      required: true
      default: false
      isArray: false
      secret: false
    - default: false
      description: "Member values based on the group type. Supports comma-separated values.\n\n Note: \nIf the group type is host, then the \"Host IDs\". \nIf the group type is account, then \"Account Names\".\nIf the group type is ip, then the list of \"IPs\".\nIf the group type is domain, then the list of \"Domains\" ."
      isArray: true
      name: members
      required: true
      secret: false
    deprecated: false
    description: Assign members to the specified group.
    execution: false
    name: vectra-group-assign
    outputs:
    - contextPath: Vectra.Group.group_id
      description: ID of the group.
      type: Number
    - contextPath: Vectra.Group.id
      description: ID of the group.
      type: Number
    - contextPath: Vectra.Group.name
      description: Name of the group.
      type: String
    - contextPath: Vectra.Group.description
      description: Description of the group.
      type: String
    - contextPath: Vectra.Group.last_modified
      description: Date when the group was last modified.
      type: Date
    - contextPath: Vectra.Group.last_modified_by
      description: Name of the user who last modified the group.
      type: String
    - contextPath: Vectra.Group.type
      description: Type of the group.
      type: String
    - contextPath: Vectra.Group.members
      description: Members of the group.
      type: Unknown
    - contextPath: Vectra.Group.members.id
      description: Entity ID of member.
      type: Number
    - contextPath: Vectra.Group.members.name
      description: Entity name of member.
      type: String
    - contextPath: Vectra.Group.members.is_key_asset
      description: Indicates key asset.
      type: Boolean
    - contextPath: Vectra.Group.members.url
      description: Entity URL of member.
      type: String
    - contextPath: Vectra.Group.members.uid
      description: Entity UID of member.
      type: String
    - contextPath: Vectra.Group.rules.triage_category
      description: Triage category of rule.
      type: String
    - contextPath: Vectra.Group.rules.id
      description: Id of the rule.
      type: Number
    - contextPath: Vectra.Group.rules.description
      description: Description of the rule.
      type: String
  - arguments:
    - description: Specify the ID of the entity.
      name: entity_id
      required: true
    - description: Specify the type of the entity.
      name: entity_type
      required: true
      auto: PREDEFINED
      predefined:
      - account
      - host
    - auto: PREDEFINED
      description: Specify the close reason.
      name: close_reason
      predefined:
      - benign
      - remediated
      required: true
    description: Mark the detections of the entity as closed with the provided entity ID in the argument.
    execution: false
    name: vectra-entity-detections-mark-asclosed
  - arguments:
    - description: Provide a list of detection IDs separated by commas or a single detection ID.
      name: detection_ids
      required: true
      isArray: true
    - description: Specify the close reason.
      name: close_reason
      required: true
      auto: PREDEFINED
      predefined:
      - benign
      - remediated
    description: Mark detections as close with provided detection IDs in the argument.
    execution: false
    name: vectra-detections-mark-asclosed
  - arguments:
    - description: Provide a list of detection IDs separated by commas or a single detection ID.
      isArray: true
      name: detection_ids
      required: true
    description: Open detections with provided detection IDs in the argument.
    execution: false
    name: vectra-detections-mark-asopen
  - arguments:
    - description: Specify the ID of the detection.
      name: detection_id
      required: true
    deprecated: false
    description: Returns a list of tags for a specified detection.
    execution: false
    name: vectra-detection-tag-list
    outputs:
    - contextPath: Vectra.Detection.Tags.tag_id
      description: The ID of the tag.
      type: String
    - contextPath: Vectra.Detection.Tags.detection_id
      description: The ID of the Detection associated with the tag.
      type: String
    - contextPath: Vectra.Detection.Tags.tags
      description: A list of tags linked to a detection.
      type: Unknown
  - arguments:
    - description: Specify the ID of the detection.
      name: detection_id
      required: true
    - description: Comma-separated values of tags to be added to the detection.
      isArray: true
      name: tags
      required: true
    description: Add tags to a detection.
    execution: false
    name: vectra-detection-tag-add
    outputs:
    - contextPath: Vectra.Detection.Tags.tag_id
      description: The ID of the tag.
      type: String
    - contextPath: Vectra.Detection.Tags.detection_id
      description: The ID of the detection associated with the tag.
      type: String
    - contextPath: Vectra.Detection.Tags.tags
      description: A list of tags linked to a detection.
      type: Unknown
  - arguments:
    - description: Specify the ID of the detection.
      name: detection_id
      required: true
    - description: Comma-separated values of tags to be removed from the detection.
      isArray: true
      name: tags
      required: true
      secret: false
    deprecated: false
    description: Remove tags from the detection.
    execution: false
    name: vectra-detection-tag-remove
    outputs:
    - contextPath: Vectra.Detection.Tags.tag_id
      description: The ID of the tag.
      type: String
    - contextPath: Vectra.Detection.Tags.detection_id
      description: The ID of the detection associated with the tag.
      type: String
    - contextPath: Vectra.Detection.Tags.tags
      description: A list of tags linked to a detection.
      type: Unknown
  - arguments:
    - default: false
      description: Specify the ID of the entity.
      isArray: false
      name: entity_id
      required: true
      secret: false
    - auto: PREDEFINED
      default: false
      description: Specify the type of the entity.
      isArray: false
      name: entity_type
      predefined:
      - account
      - host
      required: true
      secret: false
    deprecated: false
    description: Resets the given entity to refetch incidents.
    execution: false
    name: vectra-entity-reset-fetch
  dockerimage: demisto/python3:3.12.13.10116658
  feed: false
  isfetch: true
  isremotesyncin: true
  isremotesyncout: true
  longRunning: false
  longRunningPort: false
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- No tests (auto formatted)
marketplaces:
- xsoar
- marketplacev2
- platform
fromversion: 6.8.0