SpyCloud
With the SpyCloud integration data from breaches can be pulled and further processed in Playbooks. Filtering parameters can be used to filter the data set.
- Category
- Analytics & SIEM
- Pack
- SpyCloud
Configuration parameters
- url — Base URL of SpyCloud (required)
- apikey — API Key of SpyCloud (required)
Commands (5)
- spycloud-domain-data — Get all the data from a monitored domain and the breaches occurred that relates with it. Can be scoped by domain, type and severity
- spycloud-email-data — Get all the data from a monitored email address and the breaches occurred that relates with it. Can be scoped by date, severity and breach
- spycloud-get-breach-data — Retrieves the breach details. While very similar to list-breaches, this command obtains one specific breach, which is easier for automation tasks
- spycloud-list-breaches — Lists the breaches identified. By default this lists all breaches known in Spycloud. With the arguments it's possible to scope the results on date and keywords.
- spycloud-watchlist-data — Get all the data from a watchlist.