category: Authentication & Identity Management provider: BeyondTrust commonfields: id: BeyondTrust Password Safe version: -1 configuration: - display: Server URL (e.g https://192.168.0.1) name: url required: true type: 0 - display: Username name: credentials required: true type: 9 - display: API Key name: key type: 4 hidden: true required: false - name: credentials_key type: 9 displaypassword: API Key hiddenusername: true required: false - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy type: 8 required: false - display: Fetch credentials name: isFetchCredentials type: 8 required: false - display: System Name (optional for fetch credentials) name: system_name type: 0 required: false description: Unified password and session management for seamless accountability and control over privileged accounts. display: BeyondTrust Password Safe name: BeyondTrust Password Safe script: commands: - description: "Generates a list of active BeyondTrust requests." name: beyondtrust-list-release-requests outputs: - contextPath: BeyondTrust.Request.AccessType description: The type of access requested (View, RDP, SSH, App). type: String - contextPath: BeyondTrust.Request.AccountID description: ID of the managed account. type: Number - contextPath: BeyondTrust.Request.AccountName description: Name of the managed account. type: String - contextPath: BeyondTrust.Request.AliasID description: Alias ID of the managed account. type: Number - contextPath: BeyondTrust.Request.ApplicationID description: ID of the application for an application-based request. type: Number - contextPath: BeyondTrust.Request.ApprovedDate description: The date which the account is approved. type: Date - contextPath: BeyondTrust.Request.ExpiresDate description: The date which the account is expired. type: Date - contextPath: BeyondTrust.Request.Reason description: The reason for the request. type: String - contextPath: BeyondTrust.Request.RequestID description: The ID of the request. type: Number - contextPath: BeyondTrust.Request.RequestorName description: The name of the requestor. type: String - contextPath: BeyondTrust.Request.Status description: Status of requests to return. type: String - contextPath: BeyondTrust.Request.SystemID description: ID of the managed system to request. type: Number - contextPath: BeyondTrust.Request.SystemName description: Name of the managed system to request. type: String arguments: [] - description: Returns a list of managed accounts that the current user has permissions to request. name: beyondtrust-get-managed-accounts outputs: - contextPath: BeyondTrust.Account.PlatformID description: ID of the managed system platform. type: Number - contextPath: BeyondTrust.Account.SystemID description: ID of the managed system. type: Number - contextPath: BeyondTrust.Account.SystemName description: Name of the managed system. type: String - contextPath: BeyondTrust.Account.DomainName description: ID of the managed account. type: Number - contextPath: BeyondTrust.Account.AccountName description: Name of the managed account. type: String - contextPath: BeyondTrust.Account.InstanceName description: Database instance name of a database-type managed system. type: String - contextPath: BeyondTrust.Account.DefualtReleaseDuration description: Default release duration. type: Number - contextPath: BeyondTrust.Account.MaximumReleaseDuration description: Maximum release duration. type: Number - contextPath: BeyondTrust.Account.LastChangeDate description: The date and time of the last password change. type: Date - contextPath: BeyondTrust.Account.NexeChangeDate description: The date and time of the next scheduled password change. type: Date - contextPath: BeyondTrust.Account.IsChanging description: True if the account credentials are in the process of changing, otherwise false. type: Boolean - contextPath: BeyondTrust.Account.IsISAAccess description: True if the account is for Information Systems Administrator (ISA) access, otherwise false. type: Boolean - contextPath: BeyondTrust.Account.AccountID description: ID of the managed account. type: Number arguments: [] - description: Returns a list of managed systems. name: beyondtrust-get-managed-systems outputs: - contextPath: BeyondTrust.System.Port description: The port used to connect to the host. If null and the related Platform.PortFlag is true, Password Safe uses Platform.DefaultPort for communication. type: Number - contextPath: BeyondTrust.System.Timeout description: Connection timeout – Length of time in seconds before a slow or unresponsive connection to the system fails. type: String - contextPath: BeyondTrust.System.ResetPasswordOnMismatchFlag description: True to queue a password change when scheduled password test fails, otherwise false. type: Boolean - contextPath: BeyondTrust.System.ChangeFrequencyDays description: When ChangeFrequencyType is “xdays”, the frequency with which the password changes (between 1-90 days). type: Number - contextPath: BeyondTrust.System.ISAReleaseDuration description: Default Information Systems Administrator (ISA) release duration. type: Number - contextPath: BeyondTrust.System.FunctionalAccountID description: ID of the functional account used for local Managed Account password changes. type: Number - contextPath: BeyondTrust.System.ChangeFrequencyType description: 'The change frequency for scheduled password changes: "first"– Changes are scheduled for the first day of the month; "last"– Changes are scheduled for the last day of the month; "xdays"– Changes are scheduled every "x" days (see ChangeFrequencyDays).' type: String - contextPath: BeyondTrust.System.DirectoryID description: ID of the directory. Is set if the Managed System is a Directory. type: Number - contextPath: BeyondTrust.System.ManagedAssetID description: ID of the Managed System. type: Number - contextPath: BeyondTrust.System.AssetID description: ID of the asset. Is set if the Managed System is an Asset or a Database. type: Number - contextPath: BeyondTrust.System.PlatformID description: ID of the Managed System Platform. type: Number - contextPath: BeyondTrust.System.ElevationCommand description: Elevation command to use (sudo, pbrun, or pmrun). type: String - contextPath: BeyondTrust.System.CheckPasswordFlag description: True to enable password testing, otherwise false. type: Boolean - contextPath: BeyondTrust.System.CloudID description: ID of the Cloud System. Is set if the Managed System is a Cloud System. type: Number - contextPath: BeyondTrust.System.DSSKeyRuleID description: ID of the default DSS Key Rule assigned to Managed Accounts that were created under this Managed System. type: Number - contextPath: BeyondTrust.System.PasswordRuleID description: ID of the default Password Rule assigned to Managed Accounts that were created under this Managed System. type: Number - contextPath: BeyondTrust.System.NetBiosName description: Domain NetBIOS name. Setting this value will allow Password Safe to fall back to the NetBIOS name, if needed. type: String - contextPath: BeyondTrust.System.DatabaseID description: ID of the database. Is set if the Managed System is a Database. type: Number - contextPath: BeyondTrust.System.MaxReleaseDuration description: Default maximum release duration. type: Number - contextPath: BeyondTrust.System.ChangePasswordAfterAnyReleaseFlag description: True to change passwords on release of a request, otherwise false. type: Boolean - contextPath: BeyondTrust.System.SystemName description: Name of the related entity (Asset, Directory, Database, or Cloud). type: String - contextPath: BeyondTrust.System.ReleaseDuration description: Default release duration. type: Number - contextPath: BeyondTrust.System.ContactEmail description: Email address of the user that manages the system. type: String - contextPath: BeyondTrust.System.Description description: The description of the system. type: String - contextPath: BeyondTrust.System.ChangeTime description: Time (UTC) that password changes are scheduled to occur. type: String - contextPath: BeyondTrust.System.AutoManagementFlag description: True if password auto-management is enabled, otherwise false. type: Boolean - contextPath: BeyondTrust.System.LoginAccountID description: ID of the Functional Account used for SSH session logins. type: Number arguments: [] - arguments: - auto: PREDEFINED description: The type of access requested (View, RDP, SSH). Defualt is "View". name: access_type predefined: - View - RDP - SSH - description: ID of the Managed System to request. Get the ID from get-managed accounts command. name: system_id required: true - description: ID of the Managed Account to request. Get the ID from get-managed accounts command. name: account_id required: true - description: The request duration (in minutes). name: duration_minutes required: true - description: The reason for the request. name: reason - auto: PREDEFINED description: The conflict resolution option to use if an existing request is found for the same user, system and account ("reuse" or "renew"). name: conflict_option predefined: - reuse - renew description: Creates a new credentials release request. name: beyondtrust-create-release-request outputs: - contextPath: BeyondTrust.Request.Credentials description: The credentials for the requested ID. type: String - contextPath: BeyondTrust.Request.RequestID description: The request ID. type: Number - arguments: - description: ID of the request to release. name: request_id required: true - description: A reason or comment why the request is being released. name: reason description: Checks-in/releases a request before it expires. name: beyondtrust-check-in-credentials - arguments: - description: ID of the Request for which to retrieve the credentials. name: request_id required: true description: Retrieves the credentials for an approved and active (not expired) credentials release request. name: beyondtrust-get-credentials outputs: - contextPath: BeyondTrust.Request.Credentials description: The credentials for the requested ID. type: string - arguments: - description: ID of the account for which to set the credentials. name: account_id required: true - description: The new password to set. If not given, generates a new, random password. name: password - description: The new public key to set on the host. This is required if PrivateKey is given and updateSystem=true. name: public_key - description: The private key to set (provide Passphrase if encrypted). name: private_key - description: The passphrase to use for an encrypted private key. name: pass_phrase - auto: PREDEFINED defaultValue: 'true' description: Whether to update the credentials on the referenced system. name: update_system predefined: - 'true' - 'false' description: Updates the credentials for a Managed Account, optionally applying the change to the Managed System. name: beyondtrust-change-credentials dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '' type: python subtype: python3 tests: - BeyondTrust-Test fromversion: 5.0.0