WithSecureEventCollector
WithSecure event collector integration for Cortex XSIAM.
Analytics & SIEM · WithSecure
Details
| ID | WithSecureEventCollector |
|---|---|
| Provider | WithSecure Corporation |
| Category | Analytics & SIEM |
| From Version | 6.8.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | XSIAM |
README
WithSecure event collector integration for Cortex XSIAM.
This integration was integrated and tested with version 1.0 of WithSecure API
Authentication Process
To create a Client ID and Client Secret, see this documentation.
Configure WithSecure Event Collector in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL | True | |
| Client ID | Client ID and Client Secret. | True |
| Client Secret | True | |
| First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year) | False | |
| Maximum number of events per fetch, Max 1000 | False | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
with-secure-get-events
Manual command used to fetch events and display them.
Base Command
with-secure-get-events
Input
| Argument Name | Description | Required |
|---|---|---|
| fetch_from | The date to start collecting the events from. | Optional |
| limit | The maximum amount of events to return. | Optional |
Context Output
There is no context output for this command.
Command example
!with-secure-get-events limit=2 fetch_from="90 days"
Human Readable Output
With Secure Events
| action | clientTimestamp | details | device | engine | id | organization | persistenceTimestamp | serverTimestamp | severity |
|---|---|---|---|---|---|---|---|---|---|
| created | 2023-03-15T21:58:34Z | incidentPublicId: 4550314-13 fingerprint: 10e34c3d5a3b531505140351b515e5d0f563b761 initialDetectionTimestamp: 1678917621712 risk: MEDIUM categories: LATERAL_MOVEMENT incidentId: b7ffb469-44c2-4cc0-9adb-6a3663bba393 clientTimestamp: 1678917514000 resolution: UNCONFIRMED userSam: NT AUTHORITY\SYSTEM |
name: WIN10-TMPLT id: 45581e9d-266c-4676-9f55-1ff36f7519f9 |
edr | dae559cd-37fe-3fc8-8fb1-7098c8a4d368_0 | name: Palo Alto_comp id: b856d1ab-29c1-4803-b9b5-91ec7b24f94c |
2023-03-15T22:00:22.985Z | 2023-03-15T22:00:22.574Z | critical |
| created | 2023-03-15T14:01:29Z | incidentPublicId: 4550314-5 fingerprint: 3a653902d97ee6aa241b3e4ae18b0c01a32b97fe initialDetectionTimestamp: 1678891152183 risk: HIGH categories: SYSTEM_OR_TOOL_MISUSE incidentId: 3b519e5d-addd-440f-b2b6-d8ab5bb0f4ff clientTimestamp: 1678888889000 resolution: UNCONFIRMED userSam: A-WIN81X64-TEMP\admin |
name: A-WIN81X64-TEMP id: fb939719-e4b5-4fb0-bfd9-3e7079833cec |
edr | 1efd19d1-64db-3a56-b8fd-8da2cb87dc20_0 | name: Palo Alto_comp id: b856d1ab-29c1-4803-b9b5-91ec7b24f94c |
2023-03-15T14:39:15.695Z | 2023-03-15T14:39:13.022Z | critical |
Configuration parameters
url— Server URL (required)credentials— Client ID (required)first_fetch_time— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)limit— Maximum number of events per fetch. Max 1000insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
with-secure-get-eventsManual command used to fetch events and display them.
## WithSecure Help ### WithSecure Endpoint Protection WithSecure Endpoint Protection is a cloud-based platform that provides effective endpoint protection against ransomware and advanced attacks. ### Authentication Process To create a Client ID and Client Secret: 1. Login as EPP administrator in [Elements Security Center](https://elements.withsecure.com/). 2. Open API client view under the Management section. 3. Change your scope to the organization for which you want to create new pair of credentials. If you are a partner and you want to create credentials for company, then you have to change the scope to the organization, for which credentials should be issued. 4. Click **Add new**. 5. Insert the description of the new client credentials and choose whether the client should be restricted to reading data, or should also be allowed to edit it. Deselect the "Read-only" checkbox if the new credentials pair will be used for clients that send requests, which modify data on the server. For example, trigger a new remote operation. If the "Read-only" checkbox is unchecked, then the client can request an authentication token with the connect.api.write scope. 6. After the new pair of credentials is created, follow the displayed instructions. Remember to save the secret value in a safe place, because you won't be able to access that value again. 7. Select **I have copied and stored the secret** checkbox and click **Done**. 8. The new item should become visible in the list. API Documentation: [Authentication Reference](https://connect.withsecure.com/getting-started/elements#:~:text=API%20deprecation%20policy.-,Getting%20client%20credentials,-To%20use%20Elements).