Cyberhaven
Fetches DLP incidents from the Cyberhaven data security platform and enables investigation of events and data lineage.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Cyberhaven
Configuration parameters
- url — Server URL (e.g., https://example.cyberhaven.io) (required)
- credentials — (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- first_fetch — First fetch time
- max_fetch — Max Fetch
- status_filter — Status of incidents to fetch
- severity_filter — Severity of incidents to fetch
- outgoing_mirroring — Enable Outgoing Mirroring (from XSOAR to Cyberhaven)
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (4)
- cyberhaven-event-details-get — Retrieves full details for one or more Cyberhaven events by ID.
- cyberhaven-event-lineage-get — Retrieves the data lineage chain between two Cyberhaven event IDs.
- cyberhaven-incident-list — List and search Cyberhaven DLP incidents with optional filters.
- cyberhaven-incident-update — Update the status, assignment, or close reason of a Cyberhaven incident.