DarkmonCreateIncidents

Creates one XSOAR incident per item using a name_template and field_map (comma-separated 'field=path' pairs).

python · Darkmon

Details

IDDarkmonCreateIncidents
Languagepython
From Version6.8.0
Docker Imagedemisto/python3:3.12.13.10116658
Tagsdarkmon

README

Creates one XSOAR incident per item using a name_template and field_map (comma-separated ‘field=path’ pairs).

Script Data


Name Description
Script Type python3
Tags darkmon
Cortex XSOAR Version 6.5.0

Used In


This script is used in the following playbooks and scripts.

  • Darkmon - Compromised Credentials Sweep
  • Darkmon - Ransomware Mentions Watch
  • Darkmon - Brand-Targeted NRD Watch
  • Darkmon - Critical CVE Pipeline
  • Darkmon - Compromised Employee Auto-Disable

Inputs


Argument Name Description
items Items to process.
id_field Field name to use as the dedup key.
seen_list Name of the XSOAR List storing already-seen IDs.
domain_filter_list Optional - list of customer domains to filter username matches.
domain_match_field Field on each item to match against domain_filter_list.
allowlist Optional list of usernames/DNs that must NEVER be actioned.
allowlist_match_field Field to match against the allowlist.
incident_type Incident type for newly created incidents.
severity Severity (1=Low, 2=Medium, 3=High, 4=Critical).
name_template Incident name template (supports ${field} interpolation).
field_map Comma-separated ‘fieldCli=sourcePath’ pairs.
emails Email addresses to fan out per VIP fetch.
domains  
brands_list  
max_distance  
min_cvss  
tech_stack_list  

Outputs


Path Description Type
NewAccounts   unknown
CreatedIncidents   unknown
Count   number
Typosquats   unknown
FilteredCVEs   unknown
VIPCreated   number
import DarkmonCreateIncidents
import demistomock as demisto  # noqa: F401


def test_main_no_items(mocker):
    """
    Given:
        - No items passed to the script

    When:
        - main() is called with an empty items list

    Then:
        - return_results is called with zero CreatedIncidents
    """
    mocker.patch.object(
        demisto,
        "args",
        return_value={
            "items": [],
            "incident_type": "Darkmon Alert",
            "name_template": "Alert: ${id}",
            "severity": "2",
        },
    )
    mocker.patch.object(demisto, "executeCommand", return_value=[{"Contents": "", "Type": 1}])
    mock_return = mocker.patch.object(DarkmonCreateIncidents, "return_results")

    DarkmonCreateIncidents.main()

    mock_return.assert_called_once()
    result = mock_return.call_args[0][0]
    assert result.get("CreatedIncidents") == [] or result.get("Count") == 0