category: Email provider: CheckPoint Software Technologies Ltd. commonfields: id: CheckPointHEC version: -1 configuration: - section: Connect display: Smart API URL or Check Point Infinity API URL name: url defaultvalue: "" type: 15 options: - https://smart-api-production-1-us.avanan.net - https://smart-api-production-1-eu.avanan.net - https://smart-api-production-5-ap.avanan.net - https://smart-api-production-1-ca.avanan.net - https://smart-api-production-1-euw2.avanan.net - https://smart-api-production-1-mec1.avanan.net - https://smart-api-production-1-aps1.avanan.net - https://smart-api-production-1-apse1.avanan.net - https://cloudinfra-gw-us.portal.checkpoint.com - https://cloudinfra-gw.portal.checkpoint.com - https://cloudinfra-gw.ca.portal.checkpoint.com - https://cloudinfra-gw.ap.portal.checkpoint.com - https://cloudinfra-gw.uk.portal.checkpoint.com - https://cloudinfra-gw.ae.portal.checkpoint.com - https://cloudinfra-gw.in.portal.checkpoint.com - https://cloudinfra-gw.sg.portal.checkpoint.com required: true additionalinfo: The URL of the Smart API or Check Point Infinity API. - section: Collect display: Fetch incidents name: isFetch type: 8 required: false - section: Collect display: Incident type name: incidentType type: 13 required: false - section: Connect display: "" name: client_id type: 9 required: true displaypassword: Client ID hiddenusername: true additionalinfo: The client ID of the Smart API or Check Point Infinity API. - display: "" section: Connect displaypassword: Client Secret name: client_secret type: 9 required: true hiddenusername: true additionalinfo: The client secret of the Smart API or Check Point Infinity API. - display: "First fetch time" name: first_fetch type: 0 required: false section: Collect defaultvalue: 1 hour additionalinfo: The time range for the first fetch. The default is 1 hour. - display: SaaS Application name: saas_apps section: Collect type: 16 required: false options: - Microsoft Exchange - Gmail additionalinfo: Get incidents from the selected SaaS. - display: State section: Collect name: event_state type: 16 required: false options: - New - Remediated - Detected - Exception - Dismissed additionalinfo: Get incidents with only the selected states. - display: Severity section: Collect name: event_severity type: 16 required: false options: - Critical - High - Medium - Low - Very Low additionalinfo: Get incidents with only the selected severities. - display: Threat Type section: Collect name: threat_type type: 16 required: false options: - DLP - Malware - Phishing - Anomaly - Suspicious Phishing - Suspicious Malware - Shadow IT - Alert - Spam - Malicious URL - Malicious URL Click - Graymail additionalinfo: Get incidents with only the selected types. - display: Maximum number of incidents per fetch name: max_fetch defaultvalue: "10" type: 0 required: false section: Collect additionalinfo: The maximum number of incidents to retrieve per fetch. - section: Collect display: Collect restore requests name: collect_restore_requests type: 8 required: false additionalinfo: Collect restore requests as incidents. - section: Collect display: Include denied requests name: include_denied_requests type: 8 required: false additionalinfo: Include denied restore requests in the results, do not check with "Include accepted requests". - display: Include accepted requests name: include_accepted_requests type: 8 required: false section: Collect additionalinfo: Include accepted restore requests in the results, do not check with "Include denied requests". - display: Trust any certificate (not secure) additionalinfo: Trust server certificate. name: insecure type: 8 required: false section: Connect advanced: true - section: Connect additionalinfo: Use system proxy settings. advanced: true display: Use system proxy settings name: proxy type: 8 required: false - display: Incidents Fetch Interval section: Collect additionalinfo: The interval in minutes to fetch incidents. The default is 1 minute. name: incidentFetchInterval defaultvalue: "1" type: 19 required: false description: The Best Way to Protect Enterprise Email & Collaboration from phishing, malware, account takeover, data loss, etc. display: 'Check Point Harmony Email and Collaboration (HEC)' name: CheckPointHEC script: commands: - name: checkpointhec-get-entity arguments: - name: entity description: Entity id to retrieve. required: true description: Retrieve specific entity. outputs: - contextPath: CheckPointHEC.Entity.internetMessageId description: Email message id in internet. type: String - contextPath: CheckPointHEC.Entity.received description: Datetime email was received in iso 8601 format. type: String - contextPath: CheckPointHEC.Entity.size description: Email size. type: String - contextPath: CheckPointHEC.Entity.emailLinks description: Links in email. - contextPath: CheckPointHEC.Entity.attachmentCount description: Number of attachments in email. type: Number - contextPath: CheckPointHEC.Entity.attachments description: File attachments in email. - contextPath: CheckPointHEC.Entity.mode description: Internal policy rule. type: String - contextPath: CheckPointHEC.Entity.recipients description: Recipient email addresses. - contextPath: CheckPointHEC.Entity.subject description: Email subject. type: String - contextPath: CheckPointHEC.Entity.fromEmail description: Email sender. type: String - contextPath: CheckPointHEC.Entity.fromDomain description: Domain where the email was sent from. type: String - contextPath: CheckPointHEC.Entity.fromUser description: Sender user details. - contextPath: CheckPointHEC.Entity.fromName description: Sender name. type: String - contextPath: CheckPointHEC.Entity.to description: Email main recipients. - contextPath: CheckPointHEC.Entity.toUser description: User details for main recipients. - contextPath: CheckPointHEC.Entity.cc description: Email carbon copy recipients. - contextPath: CheckPointHEC.Entity.ccUser description: User details for carbon copy recipients. - contextPath: CheckPointHEC.Entity.bcc description: Email blind carbon copy recipients. - contextPath: CheckPointHEC.Entity.bccUser description: User details for blind carbon copy recipients. - contextPath: CheckPointHEC.Entity.replyToEmail description: Email reply. type: String - contextPath: CheckPointHEC.Entity.replyToNickname description: Email reply nickname. type: String - contextPath: CheckPointHEC.Entity.isRead description: Email has been read. type: Boolean - contextPath: CheckPointHEC.Entity.isDeleted description: Email has been deleted. type: Boolean - contextPath: CheckPointHEC.Entity.isIncoming description: Email is from external organization. type: Boolean - contextPath: CheckPointHEC.Entity.isInternal description: Email is from same organization. type: Boolean - contextPath: CheckPointHEC.Entity.isOutgoing description: Email is to an external organization. type: Boolean - contextPath: CheckPointHEC.Entity.isQuarantined description: Email has been quarantined. type: Boolean - contextPath: CheckPointHEC.Entity.isQuarantineNotification description: Email is a notification of another quarantined email. type: Boolean - contextPath: CheckPointHEC.Entity.isRestored description: Email is restored from quarantine. type: Boolean - contextPath: CheckPointHEC.Entity.isRestoreRequested description: Email is a request to restore. type: Boolean - contextPath: CheckPointHEC.Entity.isRestoreDeclined description: Email is a declined restore request. type: Boolean - contextPath: CheckPointHEC.Entity.saasSpamVerdict description: Spam verdict. type: String - contextPath: CheckPointHEC.Entity.SpfResult description: Sender Policy Framework check result. type: String - contextPath: CheckPointHEC.Entity.restoreRequestTime description: Restore request datetime in iso 8601 format. type: String - contextPath: CheckPointHEC.Entity.isUserExposed description: Email reached user inbox. type: Boolean - name: checkpointhec-get-events arguments: - name: start_date description: Start date in ISO 8601 format. required: true - name: end_date description: End date in ISO 8601 format, now by default. required: false - name: saas_apps description: SaaS application to retrieve events from. auto: PREDEFINED predefined: - Microsoft Exchange - Gmail isArray: true required: false - name: states description: Event states to be retrieved. auto: PREDEFINED predefined: - New - Remediated - Detected - Exception - Dismissed isArray: true required: false - name: severities description: Severity levels to be retrieved. auto: PREDEFINED predefined: - Critical - High - Medium - Low - Very Low isArray: true required: false - name: threat_types description: Threat types to be retrieved. auto: PREDEFINED predefined: - DLP - Malware - Phishing - Anomaly - Suspicious Phishing - Suspicious Malware - Shadow IT - Alert - Spam - Malicious URL - Malicious URL Click isArray: true required: false - name: limit description: Number of events to be returned. required: false description: Retrieve security events. outputs: - contextPath: CheckPointHEC.Event.eventId description: Security event id. type: String - contextPath: CheckPointHEC.Event.customerId description: Customer portal name. type: String - contextPath: CheckPointHEC.Event.saas description: SaaS internal name. type: String - contextPath: CheckPointHEC.Event.entityId description: Email entity id related to the security event. type: String - contextPath: CheckPointHEC.Event.state description: Security event state. type: String - contextPath: CheckPointHEC.Event.type description: Security event threat type. type: String - contextPath: CheckPointHEC.Event.confidenceIndicator description: Security event threat type. type: String - contextPath: CheckPointHEC.Event.eventCreated description: Security event creation date. type: String - contextPath: CheckPointHEC.Event.severity description: Security event severity 1 - 5. type: String - contextPath: CheckPointHEC.Event.description description: Security event description. type: String - contextPath: CheckPointHEC.Event.data description: Security event data information. type: String - contextPath: CheckPointHEC.Event.additionalData description: Security event additional data information if available. type: String - contextPath: CheckPointHEC.Event.availableEventActions description: Actions available for the security event. - contextPath: CheckPointHEC.Event.actions description: Performed actions related to the security event. - contextPath: CheckPointHEC.Event.senderAddress description: Sender of email related to the security event. type: String - contextPath: CheckPointHEC.Event.entityLink description: Email link. type: String - name: checkpointhec-get-scan-info arguments: - name: entity description: Scanned entity id. required: true - name: include_clean defaultValue: 'False' description: Include clean scans. type: Boolean auto: PREDEFINED predefined: - 'True' - 'False' required: false description: Retrieve specific email scan with positive threats. outputs: - contextPath: CheckPointHEC.ScanResult.ap description: Anti-phishing scan results. - contextPath: CheckPointHEC.ScanResult.dlp description: Data Loss Prevention scan results. - contextPath: CheckPointHEC.ScanResult.clicktimeProtection description: Click Time Protection scan results. - contextPath: CheckPointHEC.ScanResult.shadowIt description: Shadow IT scan results. - contextPath: CheckPointHEC.ScanResult.av description: Antivirus scan results. - name: checkpointhec-search-emails description: Search for emails. arguments: - name: date_last description: Emails not older than (1 day, 2 weeks, etc.). The arguments `date_last` and `date_from` with `date_to` are mutually exclusive and cannot be specified together in the same request. - name: date_from description: Start date to get emails in ISO 8601 format. The arguments `date_last` and `date_from` with `date_to` are mutually exclusive and cannot be specified together in the same request. - name: date_to description: End date to get emails in ISO 8601 format. The arguments `date_last` and `date_from` with `date_to` are mutually exclusive and cannot be specified together in the same request. - name: saas description: SaaS application to retrieve emails from. auto: PREDEFINED predefined: - Microsoft Exchange - Gmail - name: direction description: Email precedence. auto: PREDEFINED predefined: - Internal - Incoming - Outgoing - name: subject_contains description: Emails with subject containing the given value. The arguments `subject_contains` and `subject_match` are mutually exclusive and cannot be specified together in the same request. - name: subject_match description: Emails with subject matching the given value. The arguments `subject_contains` and `subject_match` are mutually exclusive and cannot be specified together in the same request. - name: sender_contains description: Emails with sender email containing the given value. The arguments `sender_contains` and `sender_match` are mutually exclusive and cannot be specified together in the same request. - name: sender_match description: Emails with sender email matching the given value. The arguments `sender_contains` and `sender_match` are mutually exclusive and cannot be specified together in the same request. - name: domain description: Emails with sender domain matching the given value. - name: cp_detection description: Detection by Check Point. isArray: true auto: PREDEFINED predefined: - Phishing - Suspected Phishing - Malware - Suspected Malware - Spam - Clean - DLP - Malicious URL Click - Malicious URL - name: ms_detection description: Detection by Microsoft. isArray: true auto: PREDEFINED predefined: - Malware - High Confidence Phishing - Phishing - High Confidence Spam - Spam - Bulk - Clean - name: detection_op description: Detection operator. auto: PREDEFINED predefined: - OR - AND - name: server_ip description: Sender server ip. - name: recipients_contains description: Emails with recipients containing the given value. The arguments `recipients_contains` and `recipients_match` are mutually exclusive and cannot be specified together in the same request. - name: recipients_match description: Emails with recipients matching the given value. The arguments `recipients_contains` and `recipients_match` are mutually exclusive and cannot be specified together in the same request. - name: links description: Emails with links in body matching the given value. - name: message_id description: Get specific email by id. - name: cp_quarantined_state description: Quarantine authored by Check Point. auto: PREDEFINED predefined: - Quarantined (Any source) - Not Quarantined - Quarantined by Check Point - Quarantined by CP Analyst - Quarantined by Admin - name: ms_quarantined_state description: Quarantine authored by Microsoft. auto: PREDEFINED predefined: - Quarantined - Not Quarantined - Not Quarantined Delivered to Inbox - Not Quarantined Delivered to Junk - name: quarantined_state_op description: Quarantine state operator. auto: PREDEFINED predefined: - OR - AND - name: name_contains description: Emails with sender name containing the given value. The arguments `name_contains` and `name_match` are mutually exclusive and cannot be specified together in the same request. - name: name_match description: Emails with sender name matching the given value. The arguments `name_contains` and `name_match` are mutually exclusive and cannot be specified together in the same request. - name: client_ip description: Sender client IP. - name: attachment_md5 description: Attachment MD5 checksum. outputs: - contextPath: CheckPointHEC.Entity.internetMessageId description: Email message id in internet. type: String - contextPath: CheckPointHEC.Entity.received description: Datetime email was received in iso 8601 format. type: String - contextPath: CheckPointHEC.Entity.size description: Email size. type: String - contextPath: CheckPointHEC.Entity.emailLinks description: Links in email. - contextPath: CheckPointHEC.Entity.attachmentCount description: Number of attachments in email. type: Number - contextPath: CheckPointHEC.Entity.attachments description: File attachments in email. - contextPath: CheckPointHEC.Entity.mode description: Internal policy rule. type: String - contextPath: CheckPointHEC.Entity.recipients description: Recipient email addresses. - contextPath: CheckPointHEC.Entity.subject description: Email subject. type: String - contextPath: CheckPointHEC.Entity.fromEmail description: Email sender. type: String - contextPath: CheckPointHEC.Entity.fromDomain description: Domain where the email was sent from. type: String - contextPath: CheckPointHEC.Entity.fromUser description: Sender user details. - contextPath: CheckPointHEC.Entity.fromName description: Sender name. type: String - contextPath: CheckPointHEC.Entity.to description: Email main recipients. - contextPath: CheckPointHEC.Entity.toUser description: User details for main recipients. - contextPath: CheckPointHEC.Entity.cc description: Email carbon copy recipients. - contextPath: CheckPointHEC.Entity.ccUser description: User details for carbon copy recipients. - contextPath: CheckPointHEC.Entity.bcc description: Email blind carbon copy recipients. - contextPath: CheckPointHEC.Entity.bccUser description: User details for blind carbon copy recipients. - contextPath: CheckPointHEC.Entity.replyToEmail description: Email reply. type: String - contextPath: CheckPointHEC.Entity.replyToNickname description: Email reply nickname. type: String - contextPath: CheckPointHEC.Entity.isRead description: Email has been read. type: Boolean - contextPath: CheckPointHEC.Entity.isDeleted description: Email has been deleted. type: Boolean - contextPath: CheckPointHEC.Entity.isIncoming description: Email is from external organization. type: Boolean - contextPath: CheckPointHEC.Entity.isInternal description: Email is from same organization. type: Boolean - contextPath: CheckPointHEC.Entity.isOutgoing description: Email is to an external organization. type: Boolean - contextPath: CheckPointHEC.Entity.isQuarantined description: Email has been quarantined. type: Boolean - contextPath: CheckPointHEC.Entity.isQuarantineNotification description: Email is a notification of another quarantined email. type: Boolean - contextPath: CheckPointHEC.Entity.isRestored description: Email is restored from quarantine. type: Boolean - contextPath: CheckPointHEC.Entity.isRestoreRequested description: Email is a request to restore. type: Boolean - contextPath: CheckPointHEC.Entity.isRestoreDeclined description: Email is a declined restore request. type: Boolean - contextPath: CheckPointHEC.Entity.saasSpamVerdict description: Spam verdict. type: String - contextPath: CheckPointHEC.Entity.SpfResult description: Sender Policy Framework check result. type: String - contextPath: CheckPointHEC.Entity.restoreRequestTime description: Restore request datetime in iso 8601 format. type: String - contextPath: CheckPointHEC.Entity.isUserExposed description: Email reached user inbox. type: Boolean - name: checkpointhec-send-action arguments: - name: entity description: One or multiple Email ids to apply action over. required: true isArray: true - name: saas description: SaaS application to apply action over. required: true auto: PREDEFINED predefined: - Microsoft Exchange - Gmail - name: action description: Action to perform. required: true auto: PREDEFINED predefined: - quarantine - restore - decline_restore_request - name: restore_decline_reason description: Reason to decline restore request. required: false description: Action for one or more emails. outputs: - contextPath: CheckPointHEC.Task.task description: Task id of the sent action. type: String - name: checkpointhec-get-action-result arguments: - name: task description: Task id to retrieve. required: true description: Get task info related to a sent action. outputs: - contextPath: CheckPointHEC.ActionResult.actions description: Action information for each sent entity. - contextPath: CheckPointHEC.ActionResult.created description: Date when action was created in iso 8601 format. type: String - contextPath: CheckPointHEC.ActionResult.customer description: Customer portal name. type: String - contextPath: CheckPointHEC.ActionResult.failed description: Number of failed actions. type: Number - contextPath: CheckPointHEC.ActionResult.id description: Action task id. type: Number - contextPath: CheckPointHEC.ActionResult.name description: Action name. type: String - contextPath: CheckPointHEC.ActionResult.owner description: Action owner. type: String - contextPath: CheckPointHEC.ActionResult.progress description: Number of actions in progress. type: Number - contextPath: CheckPointHEC.ActionResult.sequential description: Actions are in sequence. type: Boolean - contextPath: CheckPointHEC.ActionResult.status description: Action status. type: String - contextPath: CheckPointHEC.ActionResult.succeed description: Number of succeed actions. type: Number - contextPath: CheckPointHEC.ActionResult.total description: Total of actions. type: Number - contextPath: CheckPointHEC.ActionResult.type description: Action internal name. type: String - contextPath: CheckPointHEC.ActionResult.updated description: Date when action last updated in iso 8601 format. type: String - name: checkpointhec-send-notification arguments: - name: entity description: Email entity id. required: true - name: emails description: List of emails to send notification. isArray: true required: true description: Send notification about user exposition for the specific entity to the list of emails. outputs: - contextPath: CheckPointHEC.Notification.ok description: Result of the operation. type: Boolean - name: checkpointhec-report-mis-classification description: Report email mis-classification. arguments: - name: entities description: Email entity ids. required: true isArray: true - name: classification description: New classification. required: true auto: PREDEFINED predefined: - Clean Email - Spam - Phishing - Legit Marketing Email - name: confident description: Confidence level. required: true auto: PREDEFINED predefined: - Not so sure - Medium Confidence - High Confidence - name: checkpointhec-get-ap-exceptions description: Get Anti-Phishing and Anti-Spam exceptions or exception. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - whitelist - blacklist - spam_whitelist required: true - name: exc_id description: Exception id to retrieve. required: false outputs: - contextPath: CheckPointHEC.AntiPhishingException.added_by description: Exception added by user id. type: Number - contextPath: CheckPointHEC.AntiPhishingException.affected_count description: Affected count. type: String - contextPath: CheckPointHEC.AntiPhishingException.allowed_links description: Allowed links. type: String - contextPath: CheckPointHEC.AntiPhishingException.attachment_md5 description: Email attachment MD5. type: String - contextPath: CheckPointHEC.AntiPhishingException.auto_classify_as description: Auto classify as. type: String - contextPath: CheckPointHEC.AntiPhishingException.comment description: Exception description. type: String - contextPath: CheckPointHEC.AntiPhishingException.customer_domain description: Customer name. type: String - contextPath: CheckPointHEC.AntiPhishingException.edited_by description: Exception edited by. type: String - contextPath: CheckPointHEC.AntiPhishingException.email_link description: Email link. type: String - contextPath: CheckPointHEC.AntiPhishingException.email_link_matching description: Email link field condition. type: String - contextPath: CheckPointHEC.AntiPhishingException.entity_id description: Entity id. type: Number - contextPath: CheckPointHEC.AntiPhishingException.exception_type description: Exception type. type: String - contextPath: CheckPointHEC.AntiPhishingException.expiration_time description: Exception expiration time. type: String - contextPath: CheckPointHEC.AntiPhishingException.from_domain description: From domain. type: String - contextPath: CheckPointHEC.AntiPhishingException.from_domain_ends_with description: From domain field ends with. type: String - contextPath: CheckPointHEC.AntiPhishingException.from_domain_matching description: From domain field condition. type: String - contextPath: CheckPointHEC.AntiPhishingException.from_email description: Email sender. type: String - contextPath: CheckPointHEC.AntiPhishingException.from_email_matching description: From email field condition. type: String - contextPath: CheckPointHEC.AntiPhishingException.from_name_matching description: From name field condition. type: String - contextPath: CheckPointHEC.AntiPhishingException.headers description: Email headers. type: String - contextPath: CheckPointHEC.AntiPhishingException.ignoring_spf_check description: Ignore SPF check. type: Boolean - contextPath: CheckPointHEC.AntiPhishingException.insert_time description: Exception creation time. type: String - contextPath: CheckPointHEC.AntiPhishingException.max_confidence description: Maximum confidence. type: String - contextPath: CheckPointHEC.AntiPhishingException.max_confidence_spam description: Maximum confidence for spam. type: String - contextPath: CheckPointHEC.AntiPhishingException.message_headers description: Message headers. type: String - contextPath: CheckPointHEC.AntiPhishingException.nickname description: Sender name. type: String - contextPath: CheckPointHEC.AntiPhishingException.owner_email description: Exception owner email. type: String - contextPath: CheckPointHEC.AntiPhishingException.override description: Override. type: Boolean - contextPath: CheckPointHEC.AntiPhishingException.recipient description: Email recipient. type: String - contextPath: CheckPointHEC.AntiPhishingException.recipient_matching description: Recipient field condition. type: String - contextPath: CheckPointHEC.AntiPhishingException.sender_client_ip description: Sender client IP. type: String - contextPath: CheckPointHEC.AntiPhishingException.sender_ip description: Sender IP. type: String - contextPath: CheckPointHEC.AntiPhishingException.signature_key description: Signature key. type: String - contextPath: CheckPointHEC.AntiPhishingException.subject description: Email subject. type: String - contextPath: CheckPointHEC.AntiPhishingException.subject_matching description: Subject field condition. type: String - contextPath: CheckPointHEC.AntiPhishingException.update_time description: Exception update. type: String - contextPath: CheckPointHEC.AntiPhishingException.user_label description: User label. type: String - name: checkpointhec-create-ap-exception description: Create Anti-Phishing and Anti-Spam exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - whitelist - blacklist - spam_whitelist required: true - name: entity_id description: Entity id. required: false - name: attachment_md5 description: Attachment MD5 checksum. required: false - name: from_email description: Email sender. required: false - name: nickname description: Sender name. required: false - name: recipient description: Email recipient. required: false - name: sender_client_ip description: Sender client IP. required: false - name: from_domain_ends_with description: From domain ends with. required: false - name: sender_ip description: Sender IP. required: false - name: email_link description: Email link or links separated by comma. required: false - name: subject description: Email subject. required: false - name: comment description: Exception comment. required: false - name: action_needed description: Action needed. required: false - name: ignoring_spf_check description: Ignoring SPF check. required: false - name: subject_matching description: Subject field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: email_link_matching description: Email link field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: from_name_matching description: From name field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: from_domain_matching description: From domain field condition. auto: PREDEFINED predefined: - contains - ends_with - exact required: false - name: from_email_matching description: From email field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: recipient_matching description: Recipient field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: checkpointhec-update-ap-exception description: Update Anti-Phishing and Anti-Spam exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - whitelist - blacklist - spam_whitelist required: true - name: exc_id description: Exception id. required: true - name: entity_id description: Entity id. required: false - name: attachment_md5 description: Attachment MD5 checksum. required: false - name: from_email description: Email sender. required: false - name: nickname description: Sender name. required: false - name: recipient description: Email recipient. required: false - name: sender_client_ip description: Sender client IP. required: false - name: from_domain_ends_with description: From domain ends with. required: false - name: sender_ip description: Sender IP. required: false - name: email_link description: Email link or links separated by comma. required: false - name: subject description: Email subject. required: false - name: comment description: Exception comment. required: false - name: action_needed description: Action needed. required: false - name: ignoring_spf_check description: Ignoring SPF check. required: false - name: subject_matching description: Subject field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: email_link_matching description: Email link field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: from_name_matching description: From name field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: from_domain_matching description: From domain field condition. auto: PREDEFINED predefined: - contains - ends_with - exact required: false - name: from_email_matching description: From email field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: recipient_matching description: Recipient field condition. auto: PREDEFINED predefined: - matching - contains - exact required: false - name: checkpointhec-delete-ap-exception description: Delete Anti-Phishing and Anti-Spam exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - whitelist - blacklist - spam_whitelist required: true - name: exc_id description: Exception id. required: true - name: checkpointhec-get-cp2-exception description: Get Anti-Malware exception. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - hash - macro_hash - file_type - ppat_sender_name required: true - name: exc_str description: Exception id to retrieve. required: true outputs: - contextPath: CheckPointHEC.AntiMalwareException.insert_time description: Exception insert time. type: String - contextPath: CheckPointHEC.AntiMalwareException.farm_customer_exception_type description: Farm, customer and exception type info. type: String - contextPath: CheckPointHEC.AntiMalwareException.exception_str description: Exception string, for id purposes. type: String - contextPath: CheckPointHEC.AntiMalwareException.created_by_email description: Exception email creator. type: String - contextPath: CheckPointHEC.AntiMalwareException.comment description: Exception comment. type: String - contextPath: CheckPointHEC.AntiMalwareException.exception_payload description: Exception payload information. type: String - name: checkpointhec-create-cp2-exception description: Create Anti-Malware exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - macro_hash - file_type - ppat_sender_name required: true - name: exc_str description: Exception string. required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: comment description: Exception comment. required: false - name: exc_payload_condition description: Exception payload condition. auto: PREDEFINED predefined: - with_or_without_link - with_link - without_link required: false - name: file_name description: File name. required: false - name: created_by_email description: Exception creator email. required: false - name: is_exclusive description: Exclusive exception. auto: PREDEFINED predefined: - yes - no required: false - name: checkpointhec-update-cp2-exception description: Update Anti-Malware exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - macro_hash - file_type - ppat_sender_name required: true - name: exc_str description: Exception string. required: true - name: comment description: Exception comment. required: false - name: exc_payload_condition description: Exception payload condition. auto: PREDEFINED predefined: - with_or_without_link - with_link - without_link required: false - name: checkpointhec-delete-cp2-exception description: Delete Anti-Malware exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - macro_hash - file_type - ppat_sender_name required: true - name: exc_str description: Exception string. required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: checkpointhec-get-cp2-exceptions description: Get Anti-Malware exceptions. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - hash - macro_hash - file_type - ppat_sender_name required: true - name: filter_str description: Search string. required: false - name: filter_index description: Search index. auto: PREDEFINED predefined: - insert_time - entity_type_id - exception_str - file_name - created_by_email - comment required: false - name: sort_dir description: Sort direction. auto: PREDEFINED predefined: - asc - desc required: false - name: last_evaluated_key description: Last evaluated key. required: false - name: insert_time_gte description: Insert time field condition. auto: PREDEFINED predefined: - yes - no required: false - name: limit description: Number of exceptions to retrieve. required: false outputs: - contextPath: CheckPointHEC.AntiMalwareException.insert_time description: Exception insert time. type: String - contextPath: CheckPointHEC.AntiMalwareException.farm_customer_exception_type description: Farm, customer and exception type info. type: String - contextPath: CheckPointHEC.AntiMalwareException.exception_str description: Exception string, for id purposes. type: String - contextPath: CheckPointHEC.AntiMalwareException.created_by_email description: Exception email creator. type: String - contextPath: CheckPointHEC.AntiMalwareException.comment description: Exception comment. type: String - contextPath: CheckPointHEC.AntiMalwareException.exception_payload description: Exception payload information. type: String - name: checkpointhec-delete-cp2-exceptions description: Delete Anti-Malware exceptions. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - macro_hash - file_type - ppat_sender_name required: true - name: exc_str_list description: List of exception strings to delete. isArray: true required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: checkpointhec-get-anomaly-exceptions description: Get Anomaly exceptions. outputs: - contextPath: CheckPointHEC.AnomalyException.id description: Anomaly exception id. type: String - contextPath: CheckPointHEC.AnomalyException.anomaly_type description: Anomaly type. type: String - contextPath: CheckPointHEC.AnomalyException.insert_time description: Anomaly exception creation time. type: String - contextPath: CheckPointHEC.AnomalyException.update_time description: Anomaly exception update time. type: String - contextPath: CheckPointHEC.AnomalyException.added_by description: Anomaly exception creator. type: String - contextPath: CheckPointHEC.AnomalyException.event_id description: Security event id. type: String - contextPath: CheckPointHEC.AnomalyException.customer_domain description: Customer domain. type: String - contextPath: CheckPointHEC.AnomalyException.comments description: Anomaly exception comment. type: String - contextPath: CheckPointHEC.AnomalyException.enabled description: Anomaly exception enabled. type: Boolean - contextPath: CheckPointHEC.AnomalyException.exception_rule description: Anomaly exception rule. type: String - contextPath: CheckPointHEC.AnomalyException.expiration_date description: Anomaly exception expiration date. type: String - name: checkpointhec-create-anomaly-exception description: Create Anomaly exception. arguments: - name: request_json description: Anomaly exception request json. required: true type: keyValue - name: added_by description: User id exception creator. required: false - name: checkpointhec-delete-anomaly-exceptions description: Delete Anomaly exceptions. arguments: - name: rule_ids description: Exceptions to delete. isArray: true required: true - name: checkpointhec-get-ctp-lists description: Get Click Time Protection lists. outputs: - contextPath: CheckPointHEC.CTPList.listid description: List id. type: String - contextPath: CheckPointHEC.CTPList.listname description: List name. type: String - contextPath: CheckPointHEC.CTPList.listitem description: List item in the list. - name: checkpointhec-get-ctp-list description: Get Click Time Protection list. arguments: - name: list_id description: List id to retrieve. required: true outputs: - contextPath: CheckPointHEC.CTPList.listid description: List id. type: String - contextPath: CheckPointHEC.CTPList.listname description: List name. type: String - contextPath: CheckPointHEC.CTPList.listitem description: List of items in the list. type: String - name: checkpointhec-get-ctp-list-items description: Get Click Time Protection list items. outputs: - contextPath: CheckPointHEC.CTPListItem.created_at description: List item creation time. type: String - contextPath: CheckPointHEC.CTPListItem.created_by description: List item creator. type: String - contextPath: CheckPointHEC.CTPListItem.listid description: List id. type: String - contextPath: CheckPointHEC.CTPListItem.listitemid description: List item id. type: String - contextPath: CheckPointHEC.CTPListItem.listitemname description: List item name. type: String - contextPath: CheckPointHEC.CTPListItem.listname description: List name. type: String - name: checkpointhec-get-ctp-list-item description: Get Click Time Protection list item. arguments: - name: item_id description: Item id to retrieve. required: true outputs: - contextPath: CheckPointHEC.CTPListItem.created_at description: List item creation time. type: String - contextPath: CheckPointHEC.CTPListItem.created_by description: List item creator. type: String - contextPath: CheckPointHEC.CTPListItem.listid description: List id. type: String - contextPath: CheckPointHEC.CTPListItem.listitemid description: List item id. type: String - contextPath: CheckPointHEC.CTPListItem.listitemname description: List item name. type: String - contextPath: CheckPointHEC.CTPListItem.listname description: List name. type: String - name: checkpointhec-create-ctp-list-item description: Create Click Time Protection list item. arguments: - name: list_id description: List id. required: true - name: list_item_name description: List item name. required: true - name: created_by description: List item creator. required: true - name: checkpointhec-update-ctp-list-item description: Update Click Time Protection list item. arguments: - name: item_id description: Item id to update. required: true - name: list_id description: List id. required: true - name: list_item_name description: List item name. required: true - name: created_by description: List item creator. required: true - name: checkpointhec-delete-ctp-list-item description: Delete Click Time Protection list item. arguments: - name: item_id description: Item id to delete. required: true - name: checkpointhec-delete-ctp-list-items description: Delete Click Time Protection list items. arguments: - name: list_item_ids description: List of item ids to delete. isArray: true required: true - name: checkpointhec-delete-ctp-lists description: Delete Click Time Protection lists. - name: checkpointhec-get-avurl-exception description: Get Avanan URL exception. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - allow-url - allow-domain - block-url - block-domain required: true - name: exc_str description: Exception id to retrieve. required: true outputs: - contextPath: CheckPointHEC.AvananURLException.insert_time description: Exception insert time. type: String - contextPath: CheckPointHEC.AvananURLException.farm_customer_exception_type description: Farm, customer and exception type info. type: String - contextPath: CheckPointHEC.AvananURLException.exception_str description: Exception string, for id purposes. type: String - contextPath: CheckPointHEC.AvananURLException.created_by_email description: Exception email creator. type: String - contextPath: CheckPointHEC.AvananURLException.comment description: Exception comment. type: String - contextPath: CheckPointHEC.AvananURLException.exception_payload description: Exception payload information. type: String - name: checkpointhec-create-avurl-exception description: Create Avanan URL exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - allow-url - allow-domain - block-url - block-domain required: true - name: exc_str description: Exception string. required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: comment description: Exception comment. required: false - name: exc_payload_condition description: Exception payload condition. auto: PREDEFINED predefined: - with_or_without_link - with_link - without_link required: false - name: file_name description: File name. required: false - name: created_by_email description: Exception creator email. required: false - name: is_exclusive description: Exclusive exception. auto: PREDEFINED predefined: - yes - no required: false - name: checkpointhec-update-avurl-exception description: Update Avanan URL exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - allow-url - allow-domain - block-url - block-domain required: true - name: exc_str description: Exception string. required: true - name: comment description: Exception comment. required: false - name: exc_payload_condition description: Exception payload condition. auto: PREDEFINED predefined: - with_or_without_link - with_link - without_link required: false - name: checkpointhec-delete-avurl-exception description: Delete Avanan URL exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - allow-url - allow-domain - block-url - block-domain required: true - name: exc_str description: Exception string. required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: checkpointhec-get-avurl-exceptions description: Get Avanan URL exceptions. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - allow-url - allow-domain - block-url - block-domain required: true - name: filter_str description: Search string. required: false - name: filter_index description: Search index. auto: PREDEFINED predefined: - insert_time - entity_type_id - exception_str - file_name - created_by_email - comment required: false - name: sort_dir description: Sort direction. auto: PREDEFINED predefined: - asc - desc required: false - name: last_evaluated_key description: Last evaluated key. required: false - name: insert_time_gte description: Insert time field condition. auto: PREDEFINED predefined: - yes - no required: false - name: limit description: Number of exceptions to retrieve. required: false outputs: - contextPath: CheckPointHEC.AvananURLException.insert_time description: Exception insert time. type: String - contextPath: CheckPointHEC.AvananURLException.farm_customer_exception_type description: Farm, customer and exception type info. type: String - contextPath: CheckPointHEC.AvananURLException.exception_str description: Exception string, for id purposes. type: String - contextPath: CheckPointHEC.AvananURLException.created_by_email description: Exception email creator. type: String - contextPath: CheckPointHEC.AvananURLException.comment description: Exception comment. type: String - contextPath: CheckPointHEC.AvananURLException.exception_payload description: Exception payload information. type: String - name: checkpointhec-delete-avurl-exceptions description: Delete Avanan URL exceptions. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - allow-url - allow-domain - block-url - block-domain required: true - name: exc_str_list description: List of exception strings to delete. isArray: true required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: checkpointhec-get-avdlp-exception description: Get Avanan DLP exception. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - hash - text_content - sender_email - recipient_email required: true - name: exc_str description: Exception id to retrieve. required: true outputs: - contextPath: CheckPointHEC.AvananDLPException.insert_time description: Exception insert time. type: String - contextPath: CheckPointHEC.AvananDLPException.farm_customer_exception_type description: Farm, customer and exception type info. type: String - contextPath: CheckPointHEC.AvananDLPException.exception_str description: Exception string, for id purposes. type: String - contextPath: CheckPointHEC.AvananDLPException.created_by_email description: Exception email creator. type: String - contextPath: CheckPointHEC.AvananDLPException.comment description: Exception comment. type: String - contextPath: CheckPointHEC.AvananDLPException.exception_payload description: Exception payload information. type: String - name: checkpointhec-create-avdlp-exception description: Create Avanan DLP exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - text_content - sender_email - recipient_email required: true - name: exc_str description: Exception string. required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: comment description: Exception comment. required: false - name: exc_payload_condition description: Exception payload condition. auto: PREDEFINED predefined: - with_or_without_link - with_link - without_link required: false - name: file_name description: File name. required: false - name: created_by_email description: Exception creator email. required: false - name: is_exclusive description: Exclusive exception. auto: PREDEFINED predefined: - yes - no required: false - name: checkpointhec-update-avdlp-exception description: Update Avanan URL exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - text_content - sender_email - recipient_email required: true - name: exc_str description: Exception string. required: true - name: comment description: Exception comment. required: false - name: exc_payload_condition description: Exception payload condition. auto: PREDEFINED predefined: - with_or_without_link - with_link - without_link required: false - name: checkpointhec-delete-avdlp-exception description: Delete Avanan URL exception. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - text_content - sender_email - recipient_email required: true - name: exc_str description: Exception string. required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: checkpointhec-get-avdlp-exceptions description: Get Avanan DLP exceptions. arguments: - name: exc_type description: List name of exceptions to retrieve. auto: PREDEFINED predefined: - hash - text_content - sender_email - recipient_email required: true - name: filter_str description: Search string. required: false - name: filter_index description: Search index. auto: PREDEFINED predefined: - insert_time - entity_type_id - exception_str - file_name - created_by_email - comment required: false - name: sort_dir description: Sort direction. auto: PREDEFINED predefined: - asc - desc required: false - name: last_evaluated_key description: Last evaluated key. required: false - name: insert_time_gte description: Insert time field condition. auto: PREDEFINED predefined: - yes - no required: false - name: limit description: Number of exceptions to retrieve. required: false outputs: - contextPath: CheckPointHEC.AvananDLPException.insert_time description: Exception insert time. type: String - contextPath: CheckPointHEC.AvananDLPException.farm_customer_exception_type description: Farm, customer and exception type info. type: String - contextPath: CheckPointHEC.AvananDLPException.exception_str description: Exception string, for id purposes. type: String - contextPath: CheckPointHEC.AvananDLPException.created_by_email description: Exception email creator. type: String - contextPath: CheckPointHEC.AvananDLPException.comment description: Exception comment. type: String - contextPath: CheckPointHEC.AvananDLPException.exception_payload description: Exception payload information. type: String - name: checkpointhec-delete-avdlp-exceptions description: Delete Avanan DLP exceptions. arguments: - name: exc_type description: Exception type. auto: PREDEFINED predefined: - hash - text_content - sender_email - recipient_email required: true - name: exc_str_list description: List of exception strings to delete. isArray: true required: true - name: entity_type description: Entity type. required: false - name: entity_id description: Entity id. required: false - name: checkpointhec-download-email description: Download email file. arguments: - name: entity_id description: Email entity id, currently available in the incident's mirror external id. required: true - name: original defaultValue: 'False' type: Boolean description: Whether to download original email or with modifications. auto: PREDEFINED predefined: - 'True' - 'False' required: false - name: checkpointhec-download-large-email description: Download large email file. arguments: - name: entity_id description: Email entity id, currently available in the incident's mirror external id. required: true isfetch: true runonce: false script: '-' type: python subtype: python3 dockerimage: demisto/python3:3.12.13.10116658 fromversion: 6.9.0 tests: - No tests (auto formatted) sectionorder: - Connect - Collect