category: Endpoint provider: Arctic Wolf sectionorder: - Connect - Collect commonfields: id: Cylance Protect v2 version: -1 configuration: - defaultvalue: https://protectapi.cylance.com display: Server URL name: server required: true type: 0 section: Connect - display: Application ID name: app_id type: 0 section: Connect hidden: true required: false - display: Application Secret name: app_secret type: 4 section: Connect hidden: true required: false - display: Tenant API Key name: tid type: 4 section: Connect hidden: true required: false - display: Application ID name: app_creds type: 9 section: Connect displaypassword: Application Secret required: false - name: api_key type: 9 section: Connect hiddenusername: true displaypassword: Tenant API Key required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - display: Trust any certificate (not secure) name: unsecure type: 8 section: Connect advanced: true required: false - display: Fetch incidents name: isFetch type: 8 section: Collect required: false supportedModules: - agentix - xsiam - display: Incident type name: incidentType type: 13 section: Connect required: false supportedModules: - agentix - xsiam - defaultvalue: "-59" display: File Threshold name: file_threshold type: 0 section: Connect advanced: true required: false - defaultvalue: "1" display: Incidents Fetch Interval name: incidentFetchInterval type: 19 section: Collect advanced: true required: false supportedModules: - agentix - xsiam description: Manage Endpoints using Cylance protect. display: Cylance Protect v2 name: Cylance Protect v2 script: commands: - arguments: - description: The page number parameter is optional. When the value is not specified, the default is 1. name: pageNumber - description: The page size parameter is optional. When the value is not specified, the default is 10. Max is 200. name: pageSize description: Allows a caller to request a page with a list of Console device resources that belongings to a tenant, sorted by registration (created) date in descending order (most recent device registered listed first). name: cylance-protect-get-devices outputs: - contextPath: CylanceProtect.Device.AgentVersion description: The CylancePROTECT Agent version installed on the device. type: string - contextPath: CylanceProtect.Device.DateFirstRegistered description: The date and time (in UTC) when the device record was created. type: date - contextPath: CylanceProtect.Device.ID description: The device’s unique identifier. type: string - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.Hostname description: The device name. type: string - contextPath: CylanceProtect.Device.Policy.ID description: Device policy ID. type: string - contextPath: CylanceProtect.Device.State description: Machine state. type: string - contextPath: CylanceProtect.Device.Policy.Name description: Device policy name. type: string - contextPath: CylanceProtect.Device.Hostname description: The device name. type: string - contextPath: CylanceProtect.Device.MACAddress description: The list of MAC addresses for the device. type: unknown - contextPath: CylanceProtect.Device.IPAddress description: The list of IP addresses for the device. type: Unknown - arguments: - default: true description: The device ID. name: id required: true description: Allows a caller to request a specific device resource belonging to a Tenant. name: cylance-protect-get-device outputs: - contextPath: CylanceProtect.Device.AgentVersion description: The CylancePROTECT Agent version installed on the device. type: date - contextPath: CylanceProtect.Device.DateFirstRegistered description: The date and time (in UTC) when the device record was created. type: date - contextPath: CylanceProtect.Device.BackgroundDetection description: If true, the Agent is currently running. type: boolean - contextPath: CylanceProtect.Device.DateLastModified description: The date and time (in UTC) when the device record was last modified. type: date - contextPath: CylanceProtect.Device.DateOffline description: The date and time (in UTC) when the device last communicated with the Console. type: date - contextPath: CylanceProtect.Device.Hostname description: The hostname for the device. type: string - contextPath: CylanceProtect.Device.ID description: The unique identifier for the device. type: string - contextPath: CylanceProtect.Device.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.IsSafe description: If true, there are no outstanding threats. type: boolean - contextPath: CylanceProtect.Device.UpdateAvailable description: If true, there is available update for the device. type: boolean - contextPath: CylanceProtect.Device.State description: Machine state. type: string - contextPath: Endpoint.Hostname description: Device hostname. type: string - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.OSVersion description: Device OS version. type: string - contextPath: CylanceProtect.Device.OSVersion description: Device OS version. type: string - contextPath: CylanceProtect.Device.Name description: Device name. type: string - arguments: - default: true description: The hostname (DNS name). name: hostname required: true description: Allows a caller to request a specific device resource belonging to a Tenant by hostname. name: cylance-protect-get-device-by-hostname outputs: - contextPath: CylanceProtect.Device.AgentVersion description: The CylancePROTECT Agent version installed on the device. type: String - contextPath: CylanceProtect.Device.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: CylanceProtect.Device.Hostname description: The hostname for the device. type: string - contextPath: CylanceProtect.Device.OSVersion description: Device OS version. type: string - contextPath: CylanceProtect.Device.UpdateAvailable description: If true, there is available update for the device. type: boolean - contextPath: CylanceProtect.Device.BackgroundDetection description: If true, the Agent is currently running. type: boolean - contextPath: CylanceProtect.Device.DateFirstRegistered description: The date and time (in UTC) when the device record was created. type: date - contextPath: CylanceProtect.Device.DateLastModified description: The date and time (in UTC) when the device record was last modified. type: date - contextPath: CylanceProtect.Device.DateOffline description: The date and time (in UTC) when the device last communicated with the Console. type: date - contextPath: CylanceProtect.Device.IsSafe description: If true, there are no outstanding threats. type: boolean - contextPath: CylanceProtect.Device.LastLoggedInUser description: Last logged in user. type: string - contextPath: CylanceProtect.Device.State description: Machine state. type: string - contextPath: CylanceProtect.Device.ID description: The unique identifier for the device. type: string - contextPath: CylanceProtect.Device.Name description: Device name. type: string - contextPath: CylanceProtect.Device.UpdateType description: Device update type. type: string - contextPath: CylanceProtect.Device.Policy.ID description: Device policy ID. type: string - contextPath: CylanceProtect.Device.Policy.Name description: Device policy name. type: string - contextPath: Endpoint.Hostname description: Device hostname. type: string - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.OSVersion description: Device OS version. type: string - arguments: - default: true description: The device ID. name: id required: true - description: The device name. name: name - description: The policy ID. name: policyId - description: Zones IDs to add. isArray: true name: addZones - description: Zones IDs to remove. isArray: true name: removeZones description: Allows a caller to update a specific Console device resource belonging to a Tenant. name: cylance-protect-update-device - arguments: - default: true description: The device ID. name: id required: true - description: If the threat score is less than or equal to the threshold, then file will be considered malicious. If the threshold is not specified, the default file threshold that was configured in the instance settings will be used. name: threshold - description: The page number. If not specified, the default is 1. name: pageNumber - description: The page size. If not specified, the default is 10. name: pageSize description: Allows a caller to request a page with a list of threats found on a specific device. name: cylance-protect-get-device-threats outputs: - contextPath: File.Classification description: The Cylance threat classification. type: string - contextPath: File.CylanceScore description: The Cylance score assigned to the threat. type: number - contextPath: File.DateFound description: The date and time (in UTC) when the threat was found on the device. type: string - contextPath: File.FilePath description: The file path where the threat was found on the device. type: string - contextPath: File.FileStatus description: The current status of the file on the device. This can be one of the following:Default (0), Quarantined (1), Whitelisted (2), Suspicious (3), FileRemoved (4), Corrupt (5). type: number - contextPath: File.Name description: The name of the threat. type: string - contextPath: File.SHA256 description: The SHA256 hash of the threat. type: string - contextPath: File.Sha256 description: The SHA256 hash of the threat. type: string - contextPath: File.MD5 description: The SHA256 hash of the threat. type: string - contextPath: File.SubClassification description: The Cylance threat sub-classification. type: string - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - description: The page number. If not specified, the default is 1. name: pageNumber - description: The page size. If not specified, the default is 10. Maximum is 200. name: pageSize description: Allows the caller to get a list of tenant policies. name: cylance-protect-get-policies outputs: - contextPath: CylanceProtect.Policies.DateAdded description: The date and time (in UTC) when the Console policy resource was first created. type: string - contextPath: CylanceProtect.Policies.DateModified description: The date and time (in UTC) when the Console policy resource was last modified. type: string - contextPath: CylanceProtect.Policies.DeviceCount description: The number of devices assigned to this policy. type: number - contextPath: CylanceProtect.Policies.Id description: The unique ID for the policy resource. type: string - contextPath: CylanceProtect.Policies.Name description: The name of the policy. type: string - contextPath: CylanceProtect.Policies.ZoneCount description: The number of zones assigned to this policy. type: number - arguments: - description: The name of the zone. name: name required: true - description: The unique ID for the policy assigned to the Zone. name: policy_id required: true - auto: PREDEFINED description: The criticality value of the Zone. name: criticality predefined: - Low - Medium - High required: true description: Creates (adds) a zone to your Console. name: cylance-protect-create-zone - arguments: - description: The page number parameter is optional. When the value is not specified, the default is 1. name: pageNumber - description: The page size parameter is optional. When the value is not specified, the default is 10. Max is 200. name: pageSize description: Request zone information for your organization. This will return the top 100 records. name: cylance-protect-get-zones outputs: - contextPath: CylanceProtect.Zones.Criticality description: The value of the zone (Low, Medium, or High). type: string - contextPath: CylanceProtect.Zones.DateCreated description: The date and time (in UTC) when the zone was created. type: string - contextPath: CylanceProtect.Zones.DateModified description: The date and time (in UTC) when the zone was last modified. type: string - contextPath: CylanceProtect.Zones.Id description: The unique ID of the zone. type: string - contextPath: CylanceProtect.Zones.Name description: The name of the zone. type: string - contextPath: CylanceProtect.Zones.PolicyId description: The unique ID of the policy assigned to the zone. type: string - contextPath: CylanceProtect.Zones.UpdateType description: The update type for the zone. type: string - contextPath: CylanceProtect.Zones.ZoneRuleId description: The unique ID for the zone rule created for the zone. type: string - arguments: - default: true description: The zone ID. name: id required: true description: Request zone information for a specific zone in your organization. name: cylance-protect-get-zone outputs: - contextPath: CylanceProtect.Zones.Criticality description: The value of the zone (Low, Medium, or High). type: string - contextPath: CylanceProtect.Zones.DateCreated description: The date and time (in UTC) when the zone was created. type: string - contextPath: CylanceProtect.Zones.DateModified description: The date and time (in UTC) when the zone was last modified. type: string - contextPath: CylanceProtect.Zones.Id description: The unique ID of the zone. type: string - contextPath: CylanceProtect.Zones.Name description: The name of the zone. type: string - contextPath: CylanceProtect.Zones.PolicyId description: The unique ID of the policy assigned to the zone. type: string - contextPath: CylanceProtect.Zones.UpdateType description: The update type for the zone. type: string - contextPath: CylanceProtect.Zones.ZoneRuleId description: The unique ID for the zone rule created for the zone. type: string - arguments: - default: true description: The zone ID. name: id required: true - description: The name of the zone. name: name - description: The unique ID for the policy assigned to the Zone. name: policyId - auto: PREDEFINED description: The criticality value of the zone. Can be "Low", "Medium", or "High". name: criticality predefined: - Low - Medium - High description: Updates a zone in your organization. name: cylance-protect-update-zone - arguments: - default: true description: The SHA256 hash of the threat. name: sha256 required: true description: Requests threat details for a specific threat. name: cylance-protect-get-threat outputs: - contextPath: File.AutoRun description: Indicates if the file is set to automatically run on system startup. type: boolean - contextPath: File.AvIndustry description: The score provided by the Anti-Virus industry. type: number - contextPath: File.CertIssuer description: The ID for the certificate issuer. type: string - contextPath: File.CertPublisher description: The ID for the certificate publisher. type: string - contextPath: File.CertTimestamp description: The date and time (in UTC) when the file was signed using the certificate. type: string - contextPath: File.Classification description: The threat classification for the threat. type: string - contextPath: File.CylanceScore description: The Cylance Score assigned to the threat. type: number - contextPath: File.DetectedBy description: The name of the Cylance module that detected the threat. type: string - contextPath: File.FileSize description: The size of the file. type: number - contextPath: File.GlobalQuarantine description: Identifies if the threat is on the Global Quarantine list. type: boolean - contextPath: File.MD5 description: The MD5 hash for the threat. type: string - contextPath: File.Name description: The name of the threat. type: string - contextPath: File.Running description: Identifies if the threat is executing, or another executable loaded or called it. type: boolean - contextPath: File.Safelisted description: Identifies if the threat is on the Safe List. type: boolean - contextPath: File.SHA256 description: The SHA256 hash for the threat. type: string - contextPath: File.Signed description: Identifies the file as signed or not signed. type: boolean - contextPath: File.SubClassification description: The threat sub-classification for the threat. type: string - contextPath: File.UniqueToCylance description: Whether the threat was identified by Cylance, and not by other anti-virus sources. type: boolean - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - default: true description: The SHA256 hash of the threat. name: sha256 required: true - description: The page number parameter is optional. When the value is not specified, the default is 1. name: pageNumber - description: The page size parameter is optional. When the value is not specified, the default is 10. Max is 200. name: pageSize description: Allows a caller to request a list of devices on a specific threat. name: cylance-protect-get-threat-devices outputs: - contextPath: CylanceProtect.Threat.Devices.ID description: The device ID. type: string - contextPath: CylanceProtect.Threat.Devices.DateFound description: The date and time (in UTC) when the threat was found on the device. type: date - contextPath: CylanceProtect.Threat.Devices.AgentVersion description: The agent version installed on the device. type: string - contextPath: CylanceProtect.Threat.Devices.FileStatus description: Current quarantine status of the file on the device. Default (0), Quarantined (1), Whitelisted (2), Suspicious (3), FileRemoved (4), Corrupt (5). type: number - contextPath: Endpoint.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: Endpoint.MACAddress description: The list of MAC addresses for the device. type: Unknown - contextPath: Endpoint.Hostname description: The device name for the device. type: string - contextPath: CylanceProtect.Threat.Devices.PolicyID description: The unique identifier of the policy assigned to the device. If no policy is assigned, will be null. type: string - contextPath: CylanceProtect.Threat.Devices.State description: The state of the device. Can be "Offline" or "Online". type: string - contextPath: File.SHA256 description: The SHA256 hash of the threat. type: string - contextPath: File.Path description: The path where the file was found on the device. type: string - contextPath: CylanceProtect.Threat.Devices.Hostname description: The device name for the device. type: string - contextPath: CylanceProtect.Threat.Devices.IPAddress description: The list of IP addresses for the device. type: Unknown - contextPath: CylanceProtect.Threat.Devices.MACAddress description: The list of MAC addresses for the device. type: Unknown - arguments: - description: Threat data report token. name: token required: true description: Produces a CSV threat data report of the indicators. name: cylance-protect-get-indicators-report - arguments: - description: The page size. If not specified, the default is 10. Maximum is 200. name: pageSize - description: The page number. If not specified, the default is 1. name: pageNumber description: Returns information about Cylance Protect threats. name: cylance-protect-get-threats outputs: - contextPath: File.Classification description: The threat classification for the threat. type: string - contextPath: File.SubClassification description: The threat sub-classification for the threat. type: string - contextPath: File.SHA256 description: The SHA256 hash for the threat. type: string - contextPath: File.Sha256 description: The SHA256 hash for the threat. type: string - contextPath: File.Safelisted description: Identifies if the threat is on the Safe List. type: boolean - contextPath: File.Name description: The name of the threat. type: string - contextPath: File.LastFound description: The date and time (in UTC) when the file was last found. type: string - contextPath: File.CylanceScore description: The Cylance Score assigned to the threat. type: number - contextPath: File.GlobalQuarantine description: Identifies if the threat is on the Global Quarantine list. type: string - contextPath: File.UniqueToCylance description: The threat was identified by Cylance but not by other anti-virus sources. type: string - contextPath: File.FileSize description: The size of the file. type: number - contextPath: File.MD5 description: The MD5 hash of the threat. type: string - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - description: The SHA256 hash of the convicted threat. name: threat_id required: true - auto: PREDEFINED description: The requested status update for the convicted threat. Can be "Quarantine" or "Waive". name: event predefined: - Quarantine - Waive required: true - description: ID of device to be updated. name: device_id required: true description: Updates the status of a convicted threat. Can be "Quarantine" or "Waive". execution: true name: cylance-protect-update-device-threats - arguments: - auto: PREDEFINED description: The type of the list for which to retrieve the ashes. Can be "GlobalQuarantine" or "GlobalSafe". name: listTypeId predefined: - GlobalQuarantine - GlobalSafe required: true - description: The page number. If not specified, the default is 1. name: pageNumber - description: The page size. If not specified, the default is 10. Maximum is 200. name: pageSize description: Returns a list of global list resources for a tenant. name: cylance-protect-get-list outputs: - contextPath: File.Added description: The timestamp when the file was added to the list. type: string - contextPath: File.AddedBy description: The tenant user ID who added the file to the list. type: string - contextPath: File.AvIndustry description: The score provided by the anti-virus industry. type: number - contextPath: File.Category description: The category for the list specified (Global Safe list only). type: string - contextPath: File.Classification description: The Cylance threat classification. type: string - contextPath: File.CylanceScore description: The Cylance score assigned to the threat. type: number - contextPath: File.ListType description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". type: string - contextPath: File.MD5 description: The MD5 hash of the threat. type: string - contextPath: File.SHA256 description: The SHA256 hash of the threat. type: string - contextPath: File.Sha256 description: The SHA256 hash of the threat. type: string - contextPath: File.Name description: The name of the threat. type: string - contextPath: DBotScore.Indicator description: The tested indicator. type: string - contextPath: DBotScore.Type description: The indicator type. type: string - contextPath: DBotScore.Vendor description: Vendor used to calculate the score. type: string - contextPath: DBotScore.Score description: The actual score. type: number - arguments: - description: The SHA256 hash for the file to download. name: sha256 required: true - description: File threshold to determine the file reputation. name: threshold - auto: PREDEFINED defaultValue: "no" description: If "yes" the file is unzipped and returned to the War Room. name: unzip predefined: - "yes" - "no" description: Downloads the threat (file) attached to a specific SHA256 hash. name: cylance-protect-download-threat outputs: - contextPath: File.SHA256 description: SHA256 hash of the file. type: string - contextPath: File.Sha256 description: SHA256 hash of the file. type: string - contextPath: File.Name description: File name. type: string - contextPath: File.Size description: File size. type: number - contextPath: File.Safelisted description: Whether the file is on the Safe List. type: boolean - contextPath: File.Timestamp description: Timestamp. type: string - contextPath: File.MD5 description: MD5 hash of the file. type: string - contextPath: DBotScore.Indicator description: The Indicator. type: string - contextPath: DBotScore.Score description: The DBot score. type: number - contextPath: DBotScore.Type description: The Indicator type. type: string - contextPath: DBotScore.Vendor description: The DBot score vendor. type: string - contextPath: File.Malicious.Vendor description: For malicious files, the vendor that made the decision. type: string - contextPath: File.Malicious.Description description: For malicious files, the reason for the vendor to make the decision. type: string - arguments: - description: SHA256 hash to add to the GlobalSafe list or GlobalQuarantine list. name: sha256 required: true - auto: PREDEFINED description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". name: listType predefined: - GlobalQuarantine - GlobalSafe required: true - defaultValue: Added by Demisto description: The reason why the file was added to the list. name: reason - auto: PREDEFINED defaultValue: None description: This field is required only if the list_type value is Global Safe. Can be "Admin Tool", "Commercial Software", "Drivers", "Internal Application", "Operating System", "Security Software", or "None". Default is "None". name: category predefined: - Admin Tool - Commercial Software - Drivers - Internal Application - Operating System - Security Software - None description: Adds a convicted threat for a particular tenant to either the Global Quarantine list or the Global Safe list. name: cylance-protect-add-hash-to-list outputs: - contextPath: File.SHA256 description: The SHA256 hash for the threat. type: string - contextPath: File.Cylance.ListType description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". type: string - contextPath: File.Cylance.Category description: This field is required only if the list_type value is Global Safe. Can be "Admin Tool", "Commercial Software", "Drivers", "Internal Application", "Operating System", "Security Software", or "None". type: string - arguments: - description: The SHA256 hash of the threat. name: sha256 required: true - auto: PREDEFINED description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". name: listType predefined: - GlobalSafe - GlobalQuarantine required: true description: Removes a convicted threat for a particular tenant from either the Global Quarantine list or the Global Safe list. execution: true name: cylance-protect-delete-hash-from-lists outputs: - contextPath: File.SHA256 description: SHA256 hash of the file. type: string - contextPath: File.Cylance.ListType description: The list type to which the threat belongs. Can be "GlobalQuarantine" or "GlobalSafe". type: string - arguments: - description: The Tenant policy ID to the service endpoint. name: policyID required: true description: Returns details for a single policy. name: cylance-protect-get-policy-details outputs: - contextPath: Cylance.Policy.ID description: The ID of the policy. type: string - contextPath: Cylance.Policy.Name description: The name of the policy. type: string - contextPath: Cylance.Policy.Timestamp description: The date and time (in UTC) that the policy was created. type: string - arguments: - description: The unique identifiers for the devices to be deleted. The maximum number of Device IDs per request is 20. isArray: true name: deviceIds required: true - defaultValue: "20" description: The number of devices to delete per batch. The default is 20, which is also the maximum number of devices that can be deleted per request. name: batch_size description: Delete one or more devices from an organization. execution: true name: cylance-protect-delete-devices outputs: - contextPath: Cylance.Device.Id description: The unique identifier of the deletion request. type: string - contextPath: Cylance.Device.Name description: Device name. type: string - contextPath: Cylance.Device.Deleted description: A boolean to check if the device was deleted. type: boolean - name: cylance-optics-create-instaquery arguments: - name: name description: |- InstaQuery name ok test. required: true - name: description description: InstaQuery description. required: true - name: artifact description: InstaQuery artifact, select from the list. required: true auto: PREDEFINED predefined: - File - Process - NetworkConnection - RegistryKey - name: match_value_type description: InstaQuery value type to match, select from the list. required: true auto: PREDEFINED predefined: - File.Path - File.Md5 - File.Sha2 - File.Owner - File.CreationDateTime - Process.Name - Process.Commandline - Process.PrimaryImagePath - Process.PrimaryImageMd5 - Process.StartDateTime - NetworkConnection.DestAddr - NetworkConnection.DestPort - RegistryKey.ProcessName - RegistryKey.ProcessPrimaryImagePath - RegistryKey.ValueName - RegistryKey.FilePath - RegistryKey.FileMd5 - RegistryKey.IsPersistencePoint - name: match_values description: Value to search in InstaQuery. required: true - name: zone description: Zone of the object. required: true - name: match_type description: Match type fuzzy or exact. required: true auto: PREDEFINED predefined: - Fuzzy - Exact description: Create a cylance InstaQuery to search for artifacts in one or multiple zones. outputs: - contextPath: InstaQuery.New.id description: The unique identifier of the created InstaQuery. type: string - contextPath: InstaQuery.New.created_at description: The Date and Time that the InstaQuery was created. type: date - contextPath: InstaQuery.New.progress description: The progress of the InstaQuery. type: string - name: cylance-optics-get-instaquery-result arguments: - name: query_id description: InstaQuery ID. required: true description: Get a cylance InstaQuery search result. outputs: - contextPath: InstaQuery.Results.result description: The InstaQuery results. type: string - name: cylance-optics-list-instaquery arguments: - name: page_number description: The page number to collect. If not specified, the default is 1. defaultValue: "1" - name: page_size description: The page size. If not specified, the default is 20. defaultValue: "20" description: Get a list of all current InstaQueries. outputs: - contextPath: InstaQuery.List description: The list of InstaQuery. type: string dockerimage: demisto/auth-utils:1.0.0.11671917 isfetch: true script: '' subtype: python3 type: python tests: - Cylance Protect v2 Test fromversion: 5.0.0