RubrikPolaris
The Rubrik Security Cloud integration will fetch the Rubrik Anomaly Event and is rich with commands to perform the on-demand scans, backups, recoveries and many more features to manage and protect the organizational data.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- RubrikPolaris
Configuration parameters
- service_account_json — Service Account JSON
- url — Rubrik Account (e.g. ${rubrikAccount}.my.rubrik.com)
- email — Email
- isFetch — Fetch incidents
- incidentType — Incident type
- rsc_fetch_types — RSC Fetch Types
- event_types — Event types to fetch as incidents
- event_severities — Event severities to fetch as incidents
- threat_monitoring_match_types — Threat Monitoring Match Types
- threat_monitoring_object_types — Threat Monitoring Object Types
- first_fetch — First fetch time
- incidentFetchInterval — Incidents Fetch Interval
- max_fetch — Fetch Limit (Maximum of 1000)
- radar_critical_severity_mapping — Event Critical Severity Level Mapping
- radar_warning_severity_mapping — Event Warning Severity Level Mapping
- threat_monitoring_severity_mapping — Threat Monitoring Object Severity Level Mapping
- dspm_violation_status — DSPM Violation Statuses
- dspm_violation_sensitivity — DSPM Violation Sensitivity Levels
- dspm_violation_severity — DSPM Violation Severity Levels
- dspm_violation_category — DSPM Violation Categories
- dspm_violation_object_type — DSPM Violation Object Types
- ir_violation_policy_type — IR Violation Policy Types
- ir_violation_status — IR Violation Statuses
- ir_violation_severity — IR Violation Severity Levels
- ir_violation_category — IR Violation Categories
- ir_violation_identity_provider — IR Violation Identity Providers
- ir_violation_identity_tag — IR Violation Identity Tags
- sensitive_data_object_sensitivity — Sensitive Data Object Sensitivity Levels
- sensitive_data_object_type — Sensitive Data Object Types
- integration_reliability — Source Reliability
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (61)
- domain — Retrieve the sensitive information available for the given domain(s).
- ip — Retrieve the sensitive information available for the given IP address(es).
- rubrik-advance-ioc-scan — Start a new advance threat hunt.
- rubrik-anomaly-csv-analysis-v2 — Request for the analysis and directly download the anomaly CSV analyzed file.
- rubrik-cdm-cluster-connection-state — Find the CDM Connection State of a CDM Cluster.
- rubrik-cdm-cluster-location — Find the CDM GeoLocation of a CDM Cluster.
- rubrik-data-security-violation-csv-download — Download all files at risk as CSV file for the specified data security violation.
- rubrik-data-security-violation-file-list — Retrieve the file information of data security violation based on the provided violation ID.
- rubrik-data-security-violation-get — Retrieve the details of DSPM violation based on the provided violation ID.
- rubrik-data-security-violation-list — Retrieve the list of DSPM violations.
- rubrik-data-security-violation-log-download — Download remediation logs as CSV file for the specified data security violation.
- rubrik-data-security-violation-status-update — Updates the status of the DSPM violation.
- rubrik-event-list — Retrieve the list of events.
- rubrik-gps-async-result — Retrieve the result of an asynchronous request. This command will retrieve the result of requests made by commands "rubrik-gps-snapshot-files-download", "rubrik-gps-vm-livemount", "rubrik-gps-vm-export", "rubrik-gps-vm-snapshot-create" and "rubrik-gps-vm-recover-files".
- rubrik-gps-cluster-list — Retrieve the list of the available rubrik clusters.
- rubrik-gps-sla-domain-list — Enumerates the available SLA Domains to apply to the on-demand snapshot as a retention policy.
- rubrik-gps-snapshot-files-download — Request to download the snapshot file from the backup. Note: To know about the file information and which file can be downloaded, use the "rubrik-gps-snapshot-files-list" command. To know about the status of the downloadable files, use the "rubrik-gps-async-result" command.
- rubrik-gps-snapshot-files-list — Retrieve the list of the available files that can be downloaded. Note: To initiate the file download request use the "rubrik-gps-snapshot-files-download" command.
- rubrik-gps-vm-datastore-list — Retrieve the list of the available datastores on a Vsphere Host.
- rubrik-gps-vm-export — Request to initiate an export of a snapshot of a virtual machine. Note: To know about the exported VM's status, use the "rubrik-gps-async-result" command.
- rubrik-gps-vm-host-list — Retrieve the list of available Vsphere Hosts.
- rubrik-gps-vm-livemount — Performs a live mount of a virtual machine snapshot. Note: To know about the live mount status, use the "rubrik-gps-async-result" command.
- rubrik-gps-vm-recover-files — Recovers files from a snapshot backup, back into a system. Note: To know about the recovery status, use the "rubrik-gps-async-result" command.
- rubrik-gps-vm-snapshot-create — Triggers an on-demand snapshot of a system. Note: To know about the status of the on-demand snapshot creation, use the "rubrik-gps-async-result" command.
- rubrik-identity-resilience-violation-get — Retrieves the details of the Identity Resilience (IR) violation based on the provided violation ID.
- rubrik-identity-resilience-violation-list — Retrieves the list of Identity Resilience (IR) violations.
- rubrik-identity-resilience-violation-status-update — Updates the status of the Identity Resilience (IR) violation.
- rubrik-ioc-scan-list-v2 — List details of the Turbo and Advance Threat Hunt.
- rubrik-ioc-scan-results-v2 — Retrieve details of the Turbo and Advance Threat Hunt.
- rubrik-polaris-object-list — Retrieve the list of Rubrik objects, based on the provided filters.
- rubrik-polaris-object-search — Search for Rubrik discovered objects of any type, return zero or more matches.
- rubrik-polaris-object-snapshot-list — Retrieve Rubrik snapshot(s) of an object, based on the provided object ID.
- rubrik-polaris-vm-object-metadata-get — Retrieve details for a Vsphere object based on the provided object ID.
- rubrik-polaris-vm-object-snapshot-list — Search for a Rubrik snapshot of an object based on the provided snapshot ID, exact timestamp, or specific value like earliest/latest, or closest before/after a timestamp.
- rubrik-polaris-vm-objects-list — Retrieve a list of all the objects of the Vsphere Vm known to the Rubrik.
- rubrik-radar-analysis-status — Check the Radar Event for updates.
- rubrik-radar-anomaly-csv-analysis — Request for the analysis and retrieve the download link or directly download file for the Radar CSV analyzed file.
- rubrik-radar-anomaly-status-update — Updates the status of the Anomaly detection. Note: Run the "rubrik-radar-suspicious-file-list" command first to check the resolution status of the Anomaly Detection snapshot before executing this command.
- rubrik-radar-ioc-scan — Triggers an IOC scan of a system. Note: To know the results of the scan use the "rubrik-radar-ioc-scan-results" command and to list the running/completed IOC scans on a cluster use the "rubrik-radar-ioc-scan-list" command.
- rubrik-radar-ioc-scan-list — Lists the running/completed IOC scans on a cluster. Note: To know the results of the scan use the "rubrik-radar-ioc-scan-results" command. To initiate a scan use the "rubrik-radar-ioc-scan" command.
- rubrik-radar-ioc-scan-results — Retrieves the results of IOC scan of a system. Note: To initiate a scan use the "rubrik-radar-ioc-scan" command and to list the running/completed scans on a cluster use the "rubrik-radar-ioc-scan-list" command.
- rubrik-radar-suspicious-file-list — Retrieve the suspicious list of files for a snapshot ID with detected file anomalies.
- rubrik-sensitive-data-object-file-get — Retrieve the file information for the provided file path in the object.
- rubrik-sensitive-data-object-get — Retrieve the details of the object based on the provided object ID and snapshot ID.
- rubrik-sonar-csv-download — Request to download the Sonar CSV Snapshot results file. Note: To know the ID and status of the download, use the "rubrik-user-downloads-list" command. To download the file, use the "rubrik-sonar-csv-result-download" command.
- rubrik-sonar-csv-result-download — Retrieve the download link for the requested Sonar CSV Snapshot file.
- rubrik-sonar-file-context-list — Retrieve the context of the file, folder, or file share for the provided object and the file details.
- rubrik-sonar-ondemand-scan — Trigger an on-demand scan of a system. Supports "Vsphere VM" object type only. Note: To know the scan status use the "rubrik-sonar-ondemand-scan-status" command. To download the completed request use the "rubrik-sonar-ondemand-scan-result" command.
- rubrik-sonar-ondemand-scan-result — Retrieve the download link for the requested scanned file.
- rubrik-sonar-ondemand-scan-status — Retrieve the status of a scanned system. Note: To download the completed request use the "rubrik-sonar-ondemand-scan-result" command.
- rubrik-sonar-policies-list — Retrieve the list of all the available Sonar policies.
- rubrik-sonar-policy-analyzer-groups-list — List the analyzer group policies.
- rubrik-sonar-sensitive-hits — Find data classification hits on an object.
- rubrik-sonar-user-access-get — Retrieve the user access information based on the provided user ID.
- rubrik-sonar-user-access-list — Retrieve the user access information.
- rubrik-threat-monitoring-matched-file-get — Get the matched file for the Threat Monitoring object.
- rubrik-threat-monitoring-matched-file-list — List the matched files for the Threat Monitoring object.
- rubrik-threat-monitoring-matched-object-get — Get the matched object for Threat Monitoring.
- rubrik-threat-monitoring-matched-object-list — List the matched objects for Threat Monitoring.
- rubrik-turbo-ioc-scan — Start a new turbo threat hunt.
- rubrik-user-downloads-list — Retrieve the user downloads. This would return the current and past download history. Note: To download the requested Sonar CSV Snapshot results file use the "rubrik-sonar-csv-result-download" command.