category: Endpoint provider: Cobalt Strike commonfields: id: Covalence For Security Providers version: -1 sectionorder: - Connect - Collect configuration: - additionalinfo: Set to true if connections are made through a broker defaultvalue: 'false' display: Broker name: broker type: 8 required: false section: Connect - additionalinfo: Covalence's host (IP or domain) or broker's socket (ip:port) if using broker display: Host name: host required: true type: 0 section: Connect - display: Credentials name: credentials required: true type: 9 section: Connect - additionalinfo: If set to false, will trust any certificate (not secure) defaultvalue: 'false' display: Verify SSL name: verify_ssl type: 8 section: Connect required: false - additionalinfo: Timeout in seconds defaultvalue: '15' display: Timeout name: timeout type: 0 required: false section: Collect - additionalinfo: When fetching incidents for the first time, this parameter specifies in days how far the integration looks for incidents. For instance if set to "2", it will pull all alerts in Covalence for the last 2 days and will create corresponding incidents. defaultvalue: '1' display: First run time range name: first_run_time_range type: 0 section: Collect required: false - additionalinfo: Maximum number of alerts to be fetch per fetch command. It is advised to not fetch more than 200 alerts. defaultvalue: '200' display: Fetch limit name: fetch_limit type: 0 required: false section: Collect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - display: Fetch incidents name: isFetch type: 8 section: Collect required: false - display: Incidents Fetch Interval name: incidentFetchInterval type: 19 required: false section: Collect - defaultvalue: 7 days display: First fetch timestamp (