ExpanseV2
Deprecated. Use Cortex Xpanse integration instead. > The Xpanse integration for Cortex XSOAR leverages the Expander API to create incidents from Cortex Xpanse issues. It also leverages Cortex Xpanse's unparalleled view of the Internet to enrich IPs, domains and certificates using information from assets discovered by Cortex Xpanse Expander and risky flows detected by Cortex Xpanse Behavior.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- ExpanseV2
Configuration parameters
- url — Your server URL (required)
- credentials —
- apikey — API Key
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- max_fetch — Maximum number of incidents per fetch
- first_fetch — First fetch time
- priority — Fetch Xpanse issues with Priority
- activity_status — Fetch Xpanse issues with Activity Status
- progress_status — Fetch Xpanse issues with Progress Status
- business_unit — Fetch issues with Business Units (comma separated string)
- tag — Fetch issues with Tags (comma separated string)
- issue_type — Fetch issue with Types (comma separated string)
- cloud_management_status — Fetch Xpanse issues with Cloud Management Status
- mirror_direction — Incident Mirroring Direction
- sync_owners — Sync Incident Owners
- incoming_tags — Tag(s) for mirrored comments
- sync_tags — Mirror out Entries with tag(s)
- integrationReliability — Source Reliability
- feedExpirationPolicy —
- feedExpirationInterval —
Commands (42)
- certificate — Provides data enrichment for an X509 Certificate from Xpanse.
- cidr — Provides data enrichment for CIDR blocks using Xpanse IP Range.
- domain — Provides data enrichment for domains.
- expanse-assign-pocs-to-asset — Assign Point of Contacts to an Xpanse asset.
- expanse-assign-pocs-to-certificate — Assign pocs to an Xpanse certificate.
- expanse-assign-pocs-to-domain — Assign pocs to an Xpanse domain.
- expanse-assign-pocs-to-iprange — Assign Point of Contacts to an Xpanse IP range.
- expanse-assign-tags-to-asset — Assign tags to an Xpanse asset.
- expanse-assign-tags-to-certificate — Assign tags to an Xpanse certificate.
- expanse-assign-tags-to-domain — Assign tags to an Xpanse domain.
- expanse-assign-tags-to-iprange — Assign tags to an Xpanse IP range.
- expanse-create-poc — Create a new Point of Contact in Xpanse.
- expanse-create-tag — Create a new tag in Xpanse.
- expanse-get-associated-domains — Returns all the Xpanse domains which have been seen with the specified certificate or IP address.
- expanse-get-certificate — Retrieve Xpanse certificates by MD5 hash or search parameters.
- expanse-get-cloud-resource — Retrieve a specified cloud resource from Xpanse.
- expanse-get-cloud-resources — Retrieve cloud resources from Xpanse.
- expanse-get-domain — Retrieve Xpanse domains by domain name or search parameters.
- expanse-get-domains-for-certificate — Returns all domains which have been seen with the specified certificate.
- expanse-get-iprange — Retrieve Xpanse IP ranges by asset id or search parameters.
- expanse-get-issue — Retrieve Xpanse issue by issue ID.
- expanse-get-issue-comments — Retrieve issue comments (subset of updates).
- expanse-get-issue-updates — Retrieve updates for an Xpanse issue.
- expanse-get-issues — Retrieve issues.
- expanse-get-risky-flows — (Deprecated) Retrieve risky flows detected by Xpanse Behavior.
- expanse-get-service — Retrieve Xpanse service by service ID.
- expanse-get-services — Retrieve all Xpanse services matching the supplied parameters.
- expanse-list-businessunits — List available business units from Xpanse.
- expanse-list-pocs — List available Point of Contacts from Xpanse.
- expanse-list-providers — List available providers from Xpanse.
- expanse-list-risk-rules — (Deprecated) List risk rules from Xpanse Behavior.
- expanse-list-tags — List available tags from Xpanse.
- expanse-unassign-pocs-from-asset — Unassign Point of Contacts from an Xpanse Asset.
- expanse-unassign-pocs-from-certificate — Unassign pocs from an Xpanse certificate.
- expanse-unassign-pocs-from-domain — Unassign pocs from an Xpanse domain.
- expanse-unassign-pocs-from-iprange — Unassign Point of Contacts from an Xpanse IP range.
- expanse-unassign-tags-from-asset — Unassign tags from an Xpanse Asset.
- expanse-unassign-tags-from-certificate — Unassign tags from an Xpanse certificate.
- expanse-unassign-tags-from-domain — Unassign tags from an Xpanse domain.
- expanse-unassign-tags-from-iprange — Unassign tags from an Xpanse IP range.
- expanse-update-issue — Update a property of an Xpanse issue.
- ip — Provides data enrichment for IPs.