Securonix
Use the Securonix integration to manage incidents, threats, lookup tables, whitelists and watchlists.
- Category
- Analytics & SIEM
- Pack
- Securonix
Configuration parameters
- host — Host (Overrides the default hostname, https://{tenant}.net/Snypr)
- tenant — Tenant (required)
- username — Username (required)
- password — Password (required)
- entity_type_to_fetch — Type of entity to fetch
- tenant_name — Tenant Name
- isFetch — Fetch incidents
- incident_status — Incidents to fetch
- default_severity — Set default incident severity
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- fetch_time — First fetch time range
- max_fetch — The maximum number of incidents to fetch each time.
- mirror_direction — Incident Mirroring Direction
- close_incident — Close respective Securonix incident after fetching
- close_states_of_securonix — Securonix workflow state(s) that can be considered as Close state in XSOAR for Incoming mirroring
- active_state_action_mapping — Securonix action name to map with XSOAR's active state for Outgoing mirroring
- active_state_status_mapping — Securonix status to map with XSOAR's active state for Outgoing mirroring
- closed_state_action_mapping — Securonix action name to map with XSOAR's closed state for Outgoing mirroring
- closed_state_status_mapping — Securonix status to map with XSOAR's closed state for Outgoing mirroring
- comment_tag — Comment Entry Tag
- securonix_retry_count — Securonix Retry Count
- securonix_retry_delay — Securonix Retry Delay
- securonix_retry_delay_type — Securonix Retry Delay Type
- unsecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (36)
- securonix-add-comment-to-incident — Adds a comment to the specified incident.
- securonix-add-entity-to-watchlist — Adds an entity to a watchlist.
- securonix-check-entity-in-watchlist — Checks if the specified entity is in a watchlist.
- securonix-create-incident — Creates an incident. For more information about the required arguments, see the Securonix documentation.
- securonix-create-watchlist — Creates a watchlist in Securonix.
- securonix-get-default-assignee-for-workflow — Gets the default assignee for the specified workflow.
- securonix-get-incident — Gets details of the specified incident.
- securonix-get-incident-available-actions — Gets a list of available actions for the specified incident.
- securonix-get-incident-status — Gets the status of the specified incident.
- securonix-get-incident-workflow — Gets the workflow of the specified incident.
- securonix-get-watchlist — Gets information for the specified watchlist.
- securonix-incident-activity-history-get — Retrieves incident activity history for a specified incident.
- securonix-incident-attachment-get — Retrieves the attachments available on the Securonix platform.
- securonix-list-activity-data — Gets a list of activity data for the specified resource group.
- securonix-list-incidents — Gets a list of incidents.
- securonix-list-policies — Gets a list of all policies.
- securonix-list-possible-threat-actions — Gets a list available threat actions.
- securonix-list-resource-groups — Gets a list of resource groups.
- securonix-list-users — Gets a list of users.
- securonix-list-violation-data — Gets a list activity data for an account name.
- securonix-list-watchlists — Gets a list of watchlists.
- securonix-list-workflows — Gets a list of all available workflows.
- securonix-lookup-table-config-and-data-delete — Deletes a lookup table with its data and configuration.
- securonix-lookup-table-create — Creates a lookup table.
- securonix-lookup-table-entries-delete — Deletes the entries from the lookup table.
- securonix-lookup-table-entries-list — Retrieves the entries stored in a specified lookup table.
- securonix-lookup-table-entry-add — Add entries to the provided lookup table.
- securonix-lookup-tables-list — Retrieves a list of lookup tables available within the Securonix platform.
- securonix-perform-action-on-incident — Performs an action on the specified incident.
- securonix-threats-list — Retrieve a list of threats violated within a specified time range and get details about the threat models and policies violated.
- securonix-whitelist-create — Creates a whitelist in Securonix.
- securonix-whitelist-entry-add — Add entity or attribute to the specified whitelist entry.
- securonix-whitelist-entry-delete — Remove entity or attribute from the specified whitelist entry.
- securonix-whitelist-entry-list — Gets information for the specified whitelist.
- securonix-whitelists-get — Gets a list of whitelists.
- securonix-xsoar-state-mapping-get — Returns the state mapping of XSOAR with Securonix.