category: Data Enrichment & Threat Intelligence provider: Palo Alto Networks sectionorder: - Connect - Collect commonfields: id: ExpanseV2 version: -1 configuration: - defaultvalue: https://expander.expanse.co display: Your server URL name: url required: true type: 0 - name: credentials type: 9 displaypassword: API Key hiddenusername: true section: Connect required: false - display: API Key name: apikey type: 4 additionalinfo: Xpanse API Key to use to connect. hidden: true section: Connect required: false - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - display: Fetch incidents name: isFetch type: 8 section: Collect required: false - display: Incident type name: incidentType type: 13 section: Connect required: false - defaultvalue: '10' display: Maximum number of incidents per fetch name: max_fetch type: 0 section: Collect required: false - defaultvalue: 3 days display: First fetch time name: first_fetch type: 0 section: Collect required: false - display: Fetch Xpanse issues with Priority name: priority options: - Low - Medium - High - Critical type: 16 section: Collect advanced: true required: false - defaultvalue: Active display: Fetch Xpanse issues with Activity Status name: activity_status options: - Active - Inactive type: 16 section: Collect advanced: true required: false - display: Fetch Xpanse issues with Progress Status name: progress_status options: - New - Investigating - InProgress - AcceptableRisk - Resolved type: 16 section: Collect advanced: true required: false - display: Fetch issues with Business Units (comma separated string) name: business_unit type: 0 section: Collect advanced: true required: false - display: Fetch issues with Tags (comma separated string) name: tag type: 0 section: Collect advanced: true required: false - display: Fetch issue with Types (comma separated string) name: issue_type type: 0 section: Collect advanced: true required: false - display: Fetch Xpanse issues with Cloud Management Status name: cloud_management_status options: - NotApplicable - ManagedCloud - UnmanagedCloud type: 16 section: Collect advanced: true required: false - defaultvalue: None display: Incident Mirroring Direction name: mirror_direction options: - None - Incoming - Outgoing - Both type: 15 section: Collect required: false - defaultvalue: 'false' display: Sync Incident Owners name: sync_owners type: 8 section: Collect advanced: true required: false - additionalinfo: Assign these XSOAR tags (comma separated list) to the incoming comments mirrored from the Xpanse Issue (must be different from the sync_tags to prevent loops). defaultvalue: FromExpanse display: Tag(s) for mirrored comments name: incoming_tags type: 0 section: Collect advanced: true required: false - additionalinfo: Mirror XSOAR entries with these XSOAR tags (comma separate list) to the corresponding Xpanse Issue as comments (must be different from the incoming_tags to prevent loops). display: Mirror out Entries with tag(s) name: sync_tags type: 0 section: Collect advanced: true required: false - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged type: 15 section: Collect required: false - defaultvalue: indicatorType name: feedExpirationPolicy display: '' options: - never - interval - indicatorType - suddenDeath type: 17 section: Collect advanced: true required: false - defaultvalue: '20160' name: feedExpirationInterval display: '' type: 1 section: Collect advanced: true required: false description: Deprecated. Use Cortex Xpanse integration instead. > The Xpanse integration for Cortex XSOAR leverages the Expander API to create incidents from Cortex Xpanse issues. It also leverages Cortex Xpanse's unparalleled view of the Internet to enrich IPs, domains and certificates using information from assets discovered by Cortex Xpanse Expander and risky flows detected by Cortex Xpanse Behavior. deprecated: true display: Cortex Xpanse Legacy (Deprecated) name: ExpanseV2 script: commands: - arguments: - description: ID of the Xpanse service to retrieve. name: service_id required: true description: Retrieve Xpanse service by service ID. name: expanse-get-service outputs: - contextPath: Expanse.Service.activityStatus description: Activity status of service, whether the service is active or inactive. type: String - contextPath: Expanse.Service.annotations.tags.id description: The Internal Xpanse tag id of the customer added tag. type: String - contextPath: Expanse.Service.annotations.tags.name description: The tag name of the customer added tag. type: String - contextPath: Expanse.Service.assets.assetKey description: Key used to access the asset in the respective Xpanse asset API. type: String - contextPath: Expanse.Service.assets.assetType description: The type of asset the issue primarily relates to. type: String - contextPath: Expanse.Service.assets.displayName description: A friendly name for the asset. type: String - contextPath: Expanse.Service.assets.id description: Internal Xpanse ID the asset. type: String - contextPath: Expanse.Service.assets.referenceReason.id description: ID for asset reference type. type: String - contextPath: Expanse.Service.assets.referenceReason.name description: Description for asset reference reason. type: String - contextPath: Expanse.Service.businessUnits.id description: The internal Xpanse ID for the business unit the affected asset belongs to. type: String - contextPath: Expanse.Service.businessUnits.name description: The name of the business unit the affected asset belongs to. type: String - contextPath: Expanse.Service.certificates.assetId description: Internal Asset ID of certificate. type: String - contextPath: Expanse.Service.certificates.firstObserved description: First observation of certificate. type: Date - contextPath: Expanse.Service.certificates.lastObserved description: Most recent observation of certificate. type: Date - contextPath: Expanse.Service.certificates.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.id description: The Internal Xpanse certificate ID. type: String - contextPath: Expanse.Service.certificates.certificate.issuer description: The issuer in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerCountry description: The issuer country in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerEmail description: The issuer email in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerLocality description: The issuer locality in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerName description: The issuer name in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerOrg description: The issuer org in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerOrgUnit description: The issuer org unit in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerState description: The issuer state in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.md5Hash description: The md5hash in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.pemSha1 description: The pemSha1 in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.pemSha256 description: The pemSha256 in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKey description: The public key in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKeyBits description: The public key bits in the certificate. type: Number - contextPath: Expanse.Service.certificates.certificate.publicKeyModulus description: The public key modulus in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate. type: Number - contextPath: Expanse.Service.certificates.certificate.publicKeySpki description: The public key Spki in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.serialNumber description: The serial number in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.signatureAlgorithm description: The signature algorithm in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subject description: The subject in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectAlternativeNames description: The subject alternative names in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectCountry description: The subject country in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectEmail description: The subject email in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectLocality description: The subject locality in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectName description: The subject name in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectOrg description: The subject org in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectOrgUnit description: The subject org unit in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectState description: The subject state in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.validNotAfter description: The valid not after date in the certificate. type: Date - contextPath: Expanse.Service.certificates.certificate.validNotBefore description: The valid not before date in the certificate. type: Date - contextPath: Expanse.Service.certificates.certificate.version description: The version in the certificate. type: String - contextPath: Expanse.Service.classifications.details.firstObserved description: When the service instance was first observed. type: Date - contextPath: Expanse.Service.classifications.details.lastObserved description: When the service instance was last observed. type: Date - contextPath: Expanse.Service.classifications.details.value.applicationServerSoftware description: Application Server Software value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpOpenResponse description: BGP Open value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpNotificationResponse.data description: BGP Notification Data value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpNotificationResponse.errorCode description: BGP Notification Error Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpNotificationResponse.errorSubCode description: BGP Notification Sub-Error Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bindVersions description: Bind version value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.certificateId description: Certificate Id value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.connectResponse.statusCode description: Connect Response Status Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.connectResponse.responseLines description: Connect Response Response value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.credSspProtocol description: Cred SSP Protocol of the service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.exchanges.request.arguments description: Exchange Request Arguments value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.exchanges.request.command description: Exchange Request Command value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.exchanges.response.statusCode description: Connect Response Status Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.exchanges.response.responseLines description: Connect Response Response value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.extraInfo description: Extra Info about the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.htmlPasswordAction description: HTML Password Action value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.htmlPasswordField description: HTML Password Field value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.htmlPasswordAction description: HTML Password Action value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpAuthenticationMethods description: HTTP Authentication Methods value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpAuthenticationRealm description: HTTP Authentication Realm value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpHeaders.name description: HTTP Header name included in the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpHeaders.value description: HTTP Header value included in the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpStatusCode description: HTTP Status code of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.isEncrypted description: Is Encrypted service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.isImplicit description: Is Implicit service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.loadBalancer description: Load Balancer value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.loadBalancerPool description: Load Balancer Pool value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.nativeRdpAlgorithms description: Native RDP Algorithms of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.nativeRdpProtocol description: Native RDP Algorithms of the service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.serverSoftware description: Detected Server Software the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.serverVersion description: Server Version details for the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.sslProtocol description: SSL Protocol for the service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.validWhenScanned description: Whether a certificate on the service was valid at scan time. type: Boolean - contextPath: Expanse.Service.classifications.details.value.version description: Version details for the service classification. type: String - contextPath: Expanse.Service.classifications.firstObserved description: First observation of the service classification. type: Date - contextPath: Expanse.Service.classifications.id description: Service classification ID. type: String - contextPath: Expanse.Service.classifications.lastObserved description: Last observation of the service classification. type: Date - contextPath: Expanse.Service.classifications.name description: Service classification name. type: String - contextPath: Expanse.Service.cloudManagementStatus.id description: The Internal ID of the cloud management status. type: String - contextPath: Expanse.Service.cloudManagementStatus.name description: Name of the cloud management status. type: String - contextPath: Expanse.Service.domain.assetId description: The Internal Asset ID of the domain related to the service. type: String - contextPath: Expanse.Service.domain.domain description: The domain name related to the service. type: String - contextPath: Expanse.Service.domain.firstObserved description: The first observation of a domain related to the service. type: Date - contextPath: Expanse.Service.domain.lastObserved description: The last observation of a domain related to the service. type: Date - contextPath: Expanse.Service.discoveryInfo.type description: Whether the service was directly discovered or colocated. type: String - contextPath: Expanse.Service.firstObserved description: First observation of the service. type: Date - contextPath: Expanse.Service.id description: The internal Xpanse ID of the service. type: String - contextPath: Expanse.Service.ips.assetId description: The Internal Asset ID of the ip related to the service. type: String - contextPath: Expanse.Service.ips.firstObserved description: First observation of the ip related to the service. type: Date - contextPath: Expanse.Service.ips.geolocation.city description: Geolocation city of the ip related to the service. type: String - contextPath: Expanse.Service.ips.geolocation.countryCode description: Geolocation country of the ip related to the service. type: String - contextPath: Expanse.Service.ips.geolocation.latitude description: Geolocation latitude of the ip related to the service. type: Number - contextPath: Expanse.Service.ips.geolocation.longitude description: Geolocation longitude of the ip related to the service. type: Number - contextPath: Expanse.Service.ips.geolocation.regionCode description: Geolocation region of the ip related to the service. type: String - contextPath: Expanse.Service.ips.geolocation.timeZone description: Geolocation timeZone of the ip related to the service. type: String - contextPath: Expanse.Service.ips.ip description: IPv4 Address of the ip related to the service. type: String - contextPath: Expanse.Service.ips.lastObserved description: Last observation of the ip related to the service. type: Date - contextPath: Expanse.Service.ips.provider.id description: Provider ID of the ip related to the service. type: String - contextPath: Expanse.Service.ips.provider.name description: provider name of the ip related to the service. type: String - contextPath: Expanse.Service.ips.transportProtocol description: Transport protocol of the ip related to the service. type: String - contextPath: Expanse.Service.lastObserved description: Last observation of the service. type: Date - contextPath: Expanse.Service.name description: Summary of the service observation. type: String - contextPath: Expanse.Service.portNumber description: Summary of the service observation. type: Number - contextPath: Expanse.Service.tlsVersions.cipherSuite description: Cipher suite of the TLS version observed on the service. type: String - contextPath: Expanse.Service.tlsVersions.firstObserved description: First observation of the TLS version observed on the service. type: Date - contextPath: Expanse.Service.tlsVersions.lastObserved description: Last observation of the TLS version observed on the service. type: Date - contextPath: Expanse.Service.tlsVersions.tlsVersion description: TLS version observed on the service. type: String - arguments: - description: Maximum number of services to retrieve. name: limit - description: Returns only results whose contents match the given query. Query can be any generic string (ex. telnet). name: content_search - description: Returns only results that were found on the given providers (comma separated string). isArray: true name: provider - description: Returns only results with a business unit whose name falls in the provided list (comma separated string). isArray: true name: business_unit - description: Returns only results whose service type name (or classification ID) matches one of the given types (comma separated string). isArray: true name: service_type - description: Returns results whose identifier includes an IP matching the query. Search for results in a given IP/CIDR block using a single IP (d.d.d.d), a dashed IP range (d.d.d.d-d.d.d.d), a CIDR block (d.d.d.d/m), a partial CIDR (d.d.), or a wildcard (d.d.*.d). name: inet_search - description: Returns results whose identifier includes a domain matching the query. name: domain_search - description: Returns only results whose identifier includes one of the given port numbers (comma separated list). isArray: true name: port_number - description: Returns only results whose discovery type matches one of the given values (comma separated string, options are 'ColocatedOnIp', 'DirectlyDiscovered'). isArray: true name: discovery_type - description: Returns only results whose country code matches one of the given ISO-3166 two character country codes (comma separated list). isArray: true name: country_code - description: Returns only results whose activity status matches one of the given values. (comma separated string, options are 'Active', 'Inactive'). isArray: true name: activity_status - description: Returns only results that are associated with the provided tag names (comma separated string). isArray: true name: tag - auto: PREDEFINED description: Returns only results whose cloud management status is the following:(comma-separated string, options are 'NotApplicable', 'ManagedCloud', 'UnmanagedCloud'). isArray: true name: cloud_management_status predefined: - NotApplicable - ManagedCloud - UnmanagedCloud - auto: PREDEFINED defaultValue: firstObserved description: Sort by specified properties. name: sort predefined: - firstObserved - -firstObserved - lastObserved - -lastObserved - name - -name description: Retrieve all Xpanse services matching the supplied parameters. name: expanse-get-services outputs: - contextPath: Expanse.Service.activityStatus description: Activity status of service, whether the service is active or inactive. type: String - contextPath: Expanse.Service.annotations.tags.id description: The Internal Xpanse tag id of the customer added tag. type: String - contextPath: Expanse.Service.annotations.tags.name description: The tag name of the customer added tag. type: String - contextPath: Expanse.Service.assets.assetKey description: Key used to access the asset in the respective Xpanse asset API. type: String - contextPath: Expanse.Service.assets.assetType description: The type of asset the issue primarily relates to. type: String - contextPath: Expanse.Service.assets.displayName description: A friendly name for the asset. type: String - contextPath: Expanse.Service.assets.id description: Internal Xpanse ID the asset. type: String - contextPath: Expanse.Service.assets.referenceReason.id description: ID for asset reference type. type: String - contextPath: Expanse.Service.assets.referenceReason.name description: Description for asset reference reason. type: String - contextPath: Expanse.Service.businessUnits.id description: The internal Xpanse ID for the business unit the affected asset belongs to. type: String - contextPath: Expanse.Service.businessUnits.name description: The name of the business unit the affected asset belongs to. type: String - contextPath: Expanse.Service.certificates.assetId description: Internal Asset ID of certificate. type: String - contextPath: Expanse.Service.certificates.firstObserved description: First observation of certificate. type: Date - contextPath: Expanse.Service.certificates.lastObserved description: Most recent observation of certificate. type: Date - contextPath: Expanse.Service.certificates.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.id description: The Internal Xpanse certificate ID. type: String - contextPath: Expanse.Service.certificates.certificate.issuer description: The issuer in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerCountry description: The issuer country in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerEmail description: The issuer email in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerLocality description: The issuer locality in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerName description: The issuer name in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerOrg description: The issuer org in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerOrgUnit description: The issuer org unit in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.issuerState description: The issuer state in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.md5Hash description: The md5hash in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.pemSha1 description: The pemSha1 in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.pemSha256 description: The pemSha256 in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKey description: The public key in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKeyBits description: The public key bits in the certificate. type: Number - contextPath: Expanse.Service.certificates.certificate.publicKeyModulus description: The public key modulus in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate. type: Number - contextPath: Expanse.Service.certificates.certificate.publicKeySpki description: The public key Spki in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.serialNumber description: The serial number in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.signatureAlgorithm description: The signature algorithm in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subject description: The subject in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectAlternativeNames description: The subject alternative names in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectCountry description: The subject country in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectEmail description: The subject email in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectLocality description: The subject locality in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectName description: The subject name in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectOrg description: The subject org in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectOrgUnit description: The subject org unit in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.subjectState description: The subject state in the certificate. type: String - contextPath: Expanse.Service.certificates.certificate.validNotAfter description: The valid not after date in the certificate. type: Date - contextPath: Expanse.Service.certificates.certificate.validNotBefore description: The valid not before date in the certificate. type: Date - contextPath: Expanse.Service.certificates.certificate.version description: The version in the certificate. type: String - contextPath: Expanse.Service.classifications.details.firstObserved description: When the service instance was first observed. type: Date - contextPath: Expanse.Service.classifications.details.lastObserved description: When the service instance was last observed. type: Date - contextPath: Expanse.Service.classifications.details.value.applicationServerSoftware description: Application Server Software value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpOpenResponse description: BGP Open value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpNotificationResponse.data description: BGP Notification Data value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpNotificationResponse.errorCode description: BGP Notification Error Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bgpNotificationResponse.errorSubCode description: BGP Notification Sub-Error Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.bindVersions description: Bind version value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.certificateId description: Certificate Id value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.connectResponse.statusCode description: Connect Response Status Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.connectResponse.responseLines description: Connect Response Response value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.credSspProtocol description: Cred SSP Protocol of the service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.exchanges.request.arguments description: Exchange Request Arguments value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.exchanges.request.command description: Exchange Request Command value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.exchanges.response.statusCode description: Connect Response Status Code value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.exchanges.response.responseLines description: Connect Response Response value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.extraInfo description: Extra Info about the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.htmlPasswordAction description: HTML Password Action value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.htmlPasswordField description: HTML Password Field value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.htmlPasswordAction description: HTML Password Action value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpAuthenticationMethods description: HTTP Authentication Methods value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpAuthenticationRealm description: HTTP Authentication Realm value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpHeaders.name description: HTTP Header name included in the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpHeaders.value description: HTTP Header value included in the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.httpStatusCode description: HTTP Status code of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.isEncrypted description: Is Encrypted service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.isImplicit description: Is Implicit service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.loadBalancer description: Load Balancer value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.loadBalancerPool description: Load Balancer Pool value of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.nativeRdpAlgorithms description: Native RDP Algorithms of the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.nativeRdpProtocol description: Native RDP Algorithms of the service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.serverSoftware description: Detected Server Software the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.serverVersion description: Server Version details for the service classification. type: String - contextPath: Expanse.Service.classifications.details.value.sslProtocol description: SSL Protocol for the service classification. type: Boolean - contextPath: Expanse.Service.classifications.details.value.validWhenScanned description: Whether a certificate on the service was valid at scan time. type: Boolean - contextPath: Expanse.Service.classifications.details.value.version description: Version details for the service classification. type: String - contextPath: Expanse.Service.classifications.firstObserved description: First observation of the service classification. type: Date - contextPath: Expanse.Service.classifications.id description: Service classification ID. type: String - contextPath: Expanse.Service.classifications.lastObserved description: Last observation of the service classification. type: Date - contextPath: Expanse.Service.classifications.name description: Service classification name. type: String - contextPath: Expanse.Service.cloudManagementStatus.id description: The Internal ID of the cloud management status. type: String - contextPath: Expanse.Service.cloudManagementStatus.name description: Name of the cloud management status. type: String - contextPath: Expanse.Service.domain.assetId description: The Internal Asset ID of the domain related to the service. type: String - contextPath: Expanse.Service.domain.domain description: The domain name related to the service. type: String - contextPath: Expanse.Service.domain.firstObserved description: The first observation of a domain related to the service. type: Date - contextPath: Expanse.Service.domain.lastObserved description: The last observation of a domain related to the service. type: Date - contextPath: Expanse.Service.discoveryInfo.type description: Whether the service was directly discovered or colocated. type: String - contextPath: Expanse.Service.firstObserved description: First observation of the service. type: Date - contextPath: Expanse.Service.id description: The internal Xpanse ID of the service. type: String - contextPath: Expanse.Service.ips.assetId description: The Internal Asset ID of the ip related to the service. type: String - contextPath: Expanse.Service.ips.firstObserved description: First observation of the ip related to the service. type: Date - contextPath: Expanse.Service.ips.geolocation.city description: Geolocation city of the ip related to the service. type: String - contextPath: Expanse.Service.ips.geolocation.countryCode description: Geolocation country of the ip related to the service. type: String - contextPath: Expanse.Service.ips.geolocation.latitude description: Geolocation latitude of the ip related to the service. type: Number - contextPath: Expanse.Service.ips.geolocation.longitude description: Geolocation longitude of the ip related to the service. type: Number - contextPath: Expanse.Service.ips.geolocation.regionCode description: Geolocation region of the ip related to the service. type: String - contextPath: Expanse.Service.ips.geolocation.timeZone description: Geolocation timeZone of the ip related to the service. type: String - contextPath: Expanse.Service.ips.ip description: IPv4 Address of the ip related to the service. type: String - contextPath: Expanse.Service.ips.lastObserved description: Last observation of the ip related to the service. type: Date - contextPath: Expanse.Service.ips.provider.id description: Provider ID of the ip related to the service. type: String - contextPath: Expanse.Service.ips.provider.name description: provider name of the ip related to the service. type: String - contextPath: Expanse.Service.ips.transportProtocol description: Transport protocol of the ip related to the service. type: String - contextPath: Expanse.Service.lastObserved description: Last observation of the service. type: Date - contextPath: Expanse.Service.name description: Summary of the service observation. type: String - contextPath: Expanse.Service.portNumber description: Summary of the service observation. type: Number - contextPath: Expanse.Service.tlsVersions.cipherSuite description: Cipher suite of the TLS version observed on the service. type: String - contextPath: Expanse.Service.tlsVersions.firstObserved description: First observation of the TLS version observed on the service. type: Date - contextPath: Expanse.Service.tlsVersions.lastObserved description: Last observation of the TLS version observed on the service. type: Date - contextPath: Expanse.Service.tlsVersions.tlsVersion description: TLS version observed on the service. type: String - arguments: - description: Maximum number of issues to retrieve. name: limit - description: Returns only results whose contents match the given query. name: content_search - description: Returns only results that were found on the given providers (comma separated string). isArray: true name: provider - description: Returns only results with a business unit whose name falls in the provided list (comma separated string). isArray: true name: business_unit - description: Returns only results whose assignee's username matches one of the given usernames. Use "Unassigned" to fetch issues that are not assigned to any user. isArray: true name: assignee - description: Returns only results whose issue type name matches one of the given types (comma separated string). isArray: true name: issue_type - description: Returns results whose identifier includes an IP matching the query. Search for results in a given IP/CIDR block using a single IP (d.d.d.d), a dashed IP range (d.d.d.d-d.d.d.d), a CIDR block (d.d.d.d/m), a partial CIDR (d.d.), or a wildcard (d.d.*.d). name: inet_search - description: Returns results whose identifier includes a domain matching the query. name: domain_search - description: Returns only results whose identifier includes one of the given port numbers (comma separated list). isArray: true name: port_number - description: Returns only results whose priority matches one of the given values (comma separated string, options are 'Low', 'Medium', 'High', 'Critical'). isArray: true name: priority - description: Returns only results whose progress status matches one of the given values (comma separated string, options are 'New', 'Investigating', 'InProgress', 'AcceptableRisk', 'Resolved'). isArray: true name: progress_status - auto: PREDEFINED description: Returns only results whose activity status matches one of the given values. isArray: true name: activity_status predefined: - Active - Inactive - description: Returns only results that are associated with the provided tag names (comma separated string). isArray: true name: tag - description: Returns only results created before the provided timestamp (ISO8601 format YYYY-MM-DDTHH:MM:SSZ). name: created_before - description: Returns only results created after the provided timestamp (ISO8601 format YYYY-MM-DDTHH:MM:SSZ). name: created_after - description: Returns only results modified before the provided timestamp (ISO8601 format YYYY-MM-DDTHH:MM:SSZ). name: modified_before - description: Returns only results modified after the provided timestamp (ISO8601 format YYYY-MM-DDTHH:MM:SSZ). name: modified_after - auto: PREDEFINED description: Returns only results whose cloud management status is the following. (comma separated string, options are 'NotApplicable', 'ManagedCloud', 'UnmanagedCloud'). isArray: true name: cloud_management_status predefined: - NotApplicable - ManagedCloud - UnmanagedCloud - auto: PREDEFINED defaultValue: created description: Sort by specified properties. isArray: true name: sort predefined: - created - -created - modified - -modified - activityStatus - -assigneeUsername - priority - -priority - progressStatus - -progressStatus - activityStatus - -activityStatus - headline - -headline description: Retrieve issues. name: expanse-get-issues outputs: - contextPath: Expanse.Issue.activityStatus description: Activity status of issue, whether the issue is active or inactive. type: String - contextPath: Expanse.Issue.annotations.tags.id description: The Internal Xpanse tag id of the customer added tag. type: String - contextPath: Expanse.Issue.annotations.tags.name description: The tag name of the customer added tag. type: String - contextPath: Expanse.Issue.assets.assetKey description: Key used to access the asset in the respective Xpanse asset API. type: String - contextPath: Expanse.Issue.assets.assetType description: The type of asset the issue primarily relates to. type: String - contextPath: Expanse.Issue.assets.displayName description: A friendly name for the asset. type: String - contextPath: Expanse.Issue.assets.id description: Internal Xpanse ID the asset. type: String - contextPath: Expanse.Issue.assigneeUsername description: The username of the user that has been assigned to the issue. type: String - contextPath: Expanse.Issue.businessUnits.id description: The internal Xpanse ID for the business unit the affected asset belongs to. type: String - contextPath: Expanse.Issue.businessUnits.name description: The name of the business unit the affected asset belongs to. type: String - contextPath: Expanse.Issue.category description: The general category of the issue. type: String - contextPath: Expanse.Issue.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate. type: String - contextPath: Expanse.Issue.certificate.id description: The Internal Xpanse certificate ID. type: String - contextPath: Expanse.Issue.certificate.issuer description: The issuer in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerCountry description: The issuer country in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerEmail description: The issuer email in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerLocality description: The issuer locality in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerName description: The issuer name in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerOrg description: The issuer org in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerOrgUnit description: The issuer org unit in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerState description: The issuer state in the certificate. type: String - contextPath: Expanse.Issue.certificate.md5Hash description: The md5hash in the certificate. type: String - contextPath: Expanse.Issue.certificate.pemSha1 description: The pemSha1 in the certificate. type: String - contextPath: Expanse.Issue.certificate.pemSha256 description: The pemSha256 in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKey description: The public key in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKeyBits description: The public key bits in the certificate. type: Number - contextPath: Expanse.Issue.certificate.publicKeyModulus description: The public key modulus in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate. type: Number - contextPath: Expanse.Issue.certificate.publicKeySpki description: The public key Spki in the certificate. type: String - contextPath: Expanse.Issue.certificate.serialNumber description: The serial number in the certificate. type: String - contextPath: Expanse.Issue.certificate.signatureAlgorithm description: The signature algorithm in the certificate. type: String - contextPath: Expanse.Issue.certificate.subject description: The subject in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectAlternativeNames description: The subject alternative names in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectCountry description: The subject country in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectEmail description: The subject email in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectLocality description: The subject locality in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectName description: The subject name in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectOrg description: The subject org in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectOrgUnit description: The subject org unit in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectState description: The subject state in the certificate. type: String - contextPath: Expanse.Issue.certificate.validNotAfter description: The valid not after date in the certificate. type: Date - contextPath: Expanse.Issue.certificate.validNotBefore description: The valid not before date in the certificate. type: Date - contextPath: Expanse.Issue.certificate.version description: The version in the certificate. type: String - contextPath: Expanse.Issue.cloudManagementStatus.id description: The id of the cloud management status. type: String - contextPath: Expanse.Issue.cloudManagementStatus.name description: The name of the cloud management status. type: String - contextPath: Expanse.Issue.created description: When the issue instance was created. type: Date - contextPath: Expanse.Issue.domain description: Domain name of the issue. type: String - contextPath: Expanse.Issue.headline description: A brief summary of the issue. type: String - contextPath: Expanse.Issue.helpText description: Why Xpanse this type of issue should be avoided. type: String - contextPath: Expanse.Issue.id description: The internal Xpanse ID of the issue. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.id description: The Internal Xpanse certificate ID in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuer description: The issuer in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerCountry description: The issuer country in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerEmail description: The issuer email in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerLocality description: The issuer locality in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerName description: The issuer name in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerOrg description: The issuer org in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerOrgUnit description: The issuer org unit in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerState description: The issuer state in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.md5Hash description: The md5hash in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.pemSha1 description: The pemSha1 in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.pemSha256 description: The pemSha256 in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKey description: The public key in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyBits description: The public key bits in the certificate in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyModulus description: The public key modulus in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeySpki description: The public key Spki in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.serialNumber description: The serial number in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.signatureAlgorithm description: The signature algorithm in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subject description: The subject in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectAlternativeNames description: The subject alternative names in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectCountry description: The subject country in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectEmail description: The subject email in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectLocality description: The subject locality in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectName description: The subject name in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectOrg description: The subject org in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectOrgUnit description: The subject org unit in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectState description: The subject state in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.validNotAfter description: The valid not after date in the certificate in the initial observation. type: Date - contextPath: Expanse.Issue.initialEvidence.certificate.validNotBefore description: The valid not before date in the certificate in the initial observation. type: Date - contextPath: Expanse.Issue.initialEvidence.certificate.version description: The version in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.cipherSuite description: The cipher suite in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.configuration._type description: The type of configuration data in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.configuration.validWhenScanned description: Whether the configuration was valid in the initial observation. type: Boolean - contextPath: Expanse.Issue.initialEvidence.discoveryType description: The discovery type in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.domain description: The domain name in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.evidenceType description: The evidence type of the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.exposureId description: The exposure ID in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.exposureType description: The exposure type in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.geolocation.latitude description: The latitude in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.geolocation.longitude description: The longitude in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.geolocation.city description: The city name in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.geolocation.regionCode description: The region code in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.geolocation.countryCode description: The country code in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.ip description: The IPv4 address in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.portNumber description: The port number in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.portProtocol description: The port protocol in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.serviceId description: The Service ID in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.serviceProperties.serviceProperties.name description: The service property name in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.serviceProperties.serviceProperties.reason description: The service property reason in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.timestamp description: The timestamp of the initial observation. type: Date - contextPath: Expanse.Issue.initialEvidence.tlsVersion description: The TLS version found in the initial observation. type: String - contextPath: Expanse.Issue.ip description: The IPv4 address last associated with the issue. type: String - contextPath: Expanse.Issue.issueType.archived description: Whether the issue type is archived. type: Boolean - contextPath: Expanse.Issue.issueType.id description: The ID of the issue type. type: String - contextPath: Expanse.Issue.issueType.name description: The name of the issue type. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.id description: The Internal Xpanse certificate ID in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuer description: The issuer in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerCountry description: The issuer country in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerEmail description: The issuer email in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerLocality description: The issuer locality in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerName description: The issuer name in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerOrg description: The issuer org in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerOrgUnit description: The issuer org unit in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerState description: The issuer state in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.md5Hash description: The md5hash in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.pemSha1 description: The pemSha1 in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.pemSha256 description: The pemSha256 in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKey description: The public key in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyBits description: The public key bits in the certificate in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyModulus description: The public key modulus in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeySpki description: The public key Spki in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.serialNumber description: The serial number in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.signatureAlgorithm description: The signature algorithm in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subject description: The subject in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectAlternativeNames description: The subject alternative names in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectCountry description: The subject country in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectEmail description: The subject email in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectLocality description: The subject locality in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectName description: The subject name in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectOrg description: The subject org in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectOrgUnit description: The subject org unit in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectState description: The subject state in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.validNotAfter description: The valid not after date in the certificate in the most recent observation. type: Date - contextPath: Expanse.Issue.latestEvidence.certificate.validNotBefore description: The valid not before date in the certificate in the most recent observation. type: Date - contextPath: Expanse.Issue.latestEvidence.certificate.version description: The version in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.cipherSuite description: The cipher suite detected during the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.configuration._type description: The type of configuration data in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.configuration.validWhenScanned description: Whether the configuration was valid in the most recent observation. type: Boolean - contextPath: Expanse.Issue.latestEvidence.discoveryType description: The discovery type in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.domain description: The domain name in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.evidenceType description: The evidence type of the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.exposureId description: The exposure ID in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.exposureType description: The exposure type in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.geolocation.latitude description: The latitude in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.geolocation.longitude description: The latitude in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.geolocation.city description: The city name in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.geolocation.regionCode description: The region code in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.geolocation.countryCode description: The country code in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.ip description: The IPv4 address in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.portNumber description: The port number in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.portProtocol description: The port protocol in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.serviceId description: The Service ID in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.serviceProperties.serviceProperties.name description: The service property name in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.serviceProperties.serviceProperties.reason description: The service property reason in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.timestamp description: The timestamp of the most recent observation. type: Date - contextPath: Expanse.Issue.latestEvidence.tlsVersion description: The TLS version found in the most recent observation. type: String - contextPath: Expanse.Issue.modified description: The timestamp of when the issue was last modified. type: Date - contextPath: Expanse.Issue.portNumber description: The port number the issue was detected on. type: Number - contextPath: Expanse.Issue.portProtocol description: The port protocol the issue was detected on. type: String - contextPath: Expanse.Issue.priority description: The priority of the issue. type: String - contextPath: Expanse.Issue.progressStatus description: The progress status of the issue. type: String - contextPath: Expanse.Issue.providers.id description: The ID of the provider the issue was detected on. type: String - contextPath: Expanse.Issue.providers.name description: The name of the provider the issue was detected on. type: String - arguments: - description: Expanse issue ID to retrieve updates for. name: issue_id required: true - description: Update types to retrieve (comma separated string. Valid options are 'Assignee', 'Comment', 'Priority', 'ProgressStatus', 'ActivityStatus'). name: update_types - description: Returns only updates created after the provided timestamp (ISO8601 format YYYY-MM-DDTHH:MM:SSZ). name: created_after - description: Maximum number of results to retrieve. name: limit description: Retrieve updates for an Xpanse issue. name: expanse-get-issue-updates outputs: - contextPath: Expanse.IssueUpdate.created description: The timestamp of when the Issue update occurred. type: Date - contextPath: Expanse.IssueUpdate.id description: The unique ID of the issue update event. type: String - contextPath: Expanse.IssueUpdate.issue_id description: The unique ID of the issue that was updated. type: String - contextPath: Expanse.IssueUpdate.previousValue description: The previous value of the field that was updated. type: String - contextPath: Expanse.IssueUpdate.updateType description: The type of update that occurred, valid types are ProgressStatus, ActivityStatus, Priority, Assignee, and Comment. type: String - contextPath: Expanse.IssueUpdate.user.username description: The username of the user who made the update. type: String - contextPath: Expanse.IssueUpdate.value description: The new value of the field that was updated. type: String - arguments: - description: Expanse issue ID to retrieve updates for. name: issue_id required: true - description: Returns only comments created after the provided timestamp (ISO8601 format YYYY-MM-DDTHH:MM:SSZ). name: created_after description: Retrieve issue comments (subset of updates). name: expanse-get-issue-comments outputs: - contextPath: Expanse.IssueComment.created description: The timestamp of when the Issue update occurred. type: Date - contextPath: Expanse.IssueComment.id description: The unique ID of the issue update event. type: String - contextPath: Expanse.IssueComment.issue_id description: The unique ID of the issue that was updated. type: String - contextPath: Expanse.IssueComment.previousValue description: The previous value of the field that was updated. type: String - contextPath: Expanse.IssueComment.updateType description: The type of update that occurred, valid types are ProgressStatus, ActivityStatus, Priority, Assignee, and Comment. type: String - contextPath: Expanse.IssueComment.user.username description: The username of the user who made the update. type: String - contextPath: Expanse.IssueComment.value description: The new value of the field that was updated. type: String - arguments: - description: Xpanse issue ID to update. name: issue_id required: true - auto: PREDEFINED defaultValue: 'false' description: Type of update. isArray: true name: update_type predefined: - Assignee - Comment - Priority - ProgressStatus required: true - description: Updated value. name: value required: true description: Update a property of an Xpanse issue. name: expanse-update-issue outputs: - contextPath: Expanse.IssueUpdate.created description: The timestamp of when the Issue update occurred. type: Date - contextPath: Expanse.IssueUpdate.id description: The unique ID of the issue update event. type: String - contextPath: Expanse.IssueUpdate.issue_id description: The unique ID of the issue that was updated. type: String - contextPath: Expanse.IssueUpdate.previousValue description: The previous value of the field that was updated. type: String - contextPath: Expanse.IssueUpdate.updateType description: The type of update that occurred, valid types are ProgressStatus, ActivityStatus, Priority, Assignee, and Comment. type: String - contextPath: Expanse.IssueUpdate.user.username description: The username of the user who made the update. type: String - contextPath: Expanse.IssueUpdate.value description: The new value of the field that was updated. type: String - arguments: - description: ID of the Xpanse issue to retrieve. name: issue_id required: true description: Retrieve Xpanse issue by issue ID. name: expanse-get-issue outputs: - contextPath: Expanse.Issue.activityStatus description: Activity status of issue, whether the issue is active or inactive. type: String - contextPath: Expanse.Issue.annotations.tags.id description: The Internal Xpanse tag id of the customer added tag. type: String - contextPath: Expanse.Issue.annotations.tags.name description: The tag name of the customer added tag. type: String - contextPath: Expanse.Issue.assets.assetKey description: Key used to access the asset in the respective Xpanse asset API. type: String - contextPath: Expanse.Issue.assets.assetType description: The type of asset the issue primarily relates to. type: String - contextPath: Expanse.Issue.assets.displayName description: A friendly name for the asset. type: String - contextPath: Expanse.Issue.assets.id description: Internal Xpanse ID the asset. type: String - contextPath: Expanse.Issue.assigneeUsername description: The username of the user that has been assigned to the issue. type: String - contextPath: Expanse.Issue.businessUnits.id description: The internal Xpanse ID for the business unit the affected asset belongs to. type: String - contextPath: Expanse.Issue.businessUnits.name description: The name of the business unit the affected asset belongs to. type: String - contextPath: Expanse.Issue.category description: The general category of the issue. type: String - contextPath: Expanse.Issue.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate. type: String - contextPath: Expanse.Issue.certificate.id description: The Internal Xpanse certificate ID. type: String - contextPath: Expanse.Issue.certificate.issuer description: The issuer in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerCountry description: The issuer country in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerEmail description: The issuer email in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerLocality description: The issuer locality in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerName description: The issuer name in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerOrg description: The issuer org in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerOrgUnit description: The issuer org unit in the certificate. type: String - contextPath: Expanse.Issue.certificate.issuerState description: The issuer state in the certificate. type: String - contextPath: Expanse.Issue.certificate.md5Hash description: The md5hash in the certificate. type: String - contextPath: Expanse.Issue.certificate.pemSha1 description: The pemSha1 in the certificate. type: String - contextPath: Expanse.Issue.certificate.pemSha256 description: The pemSha256 in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKey description: The public key in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKeyBits description: The public key bits in the certificate. type: Number - contextPath: Expanse.Issue.certificate.publicKeyModulus description: The public key modulus in the certificate. type: String - contextPath: Expanse.Issue.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate. type: Number - contextPath: Expanse.Issue.certificate.publicKeySpki description: The public key Spki in the certificate. type: String - contextPath: Expanse.Issue.certificate.serialNumber description: The serial number in the certificate. type: String - contextPath: Expanse.Issue.certificate.signatureAlgorithm description: The signature algorithm in the certificate. type: String - contextPath: Expanse.Issue.certificate.subject description: The subject in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectAlternativeNames description: The subject alternative names in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectCountry description: The subject country in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectEmail description: The subject email in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectLocality description: The subject locality in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectName description: The subject name in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectOrg description: The subject org in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectOrgUnit description: The subject org unit in the certificate. type: String - contextPath: Expanse.Issue.certificate.subjectState description: The subject state in the certificate. type: String - contextPath: Expanse.Issue.certificate.validNotAfter description: The valid not after date in the certificate. type: Date - contextPath: Expanse.Issue.certificate.validNotBefore description: The valid not before date in the certificate. type: Date - contextPath: Expanse.Issue.certificate.version description: The version in the certificate. type: String - contextPath: Expanse.Issue.cloudManagementStatus.id description: The ID of the cloud management status. type: String - contextPath: Expanse.Issue.cloudManagementStatus.name description: The name of the cloud management status. type: String - contextPath: Expanse.Issue.created description: When the issue instance was created. type: Date - contextPath: Expanse.Issue.domain description: Domain name of the issue. type: String - contextPath: Expanse.Issue.headline description: A brief summary of the issue. type: String - contextPath: Expanse.Issue.helpText description: Why Xpanse this type of issue should be avoided. type: String - contextPath: Expanse.Issue.id description: The internal Xpanse ID of the issue. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.id description: The Internal Xpanse certificate ID in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuer description: The issuer in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerCountry description: The issuer country in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerEmail description: The issuer email in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerLocality description: The issuer locality in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerName description: The issuer name in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerOrg description: The issuer org in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerOrgUnit description: The issuer org unit in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.issuerState description: The issuer state in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.md5Hash description: The md5hash in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.pemSha1 description: The pemSha1 in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.pemSha256 description: The pemSha256 in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKey description: The public key in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyBits description: The public key bits in the certificate in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyModulus description: The public key modulus in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.certificate.publicKeySpki description: The public key Spki in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.serialNumber description: The serial number in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.signatureAlgorithm description: The signature algorithm in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subject description: The subject in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectAlternativeNames description: The subject alternative names in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectCountry description: The subject country in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectEmail description: The subject email in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectLocality description: The subject locality in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectName description: The subject name in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectOrg description: The subject org in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectOrgUnit description: The subject org unit in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.subjectState description: The subject state in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.certificate.validNotAfter description: The valid not after date in the certificate in the initial observation. type: Date - contextPath: Expanse.Issue.initialEvidence.certificate.validNotBefore description: The valid not before date in the certificate in the initial observation. type: Date - contextPath: Expanse.Issue.initialEvidence.certificate.version description: The version in the certificate in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.cipherSuite description: The cipher suite in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.configuration._type description: The type of configuration data in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.configuration.validWhenScanned description: Whether the configuration was valid in the initial observation. type: Boolean - contextPath: Expanse.Issue.initialEvidence.discoveryType description: The discovery type in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.domain description: The domain name in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.evidenceType description: The evidence type of the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.exposureId description: The exposure ID in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.exposureType description: The exposure type in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.geolocation.latitude description: The latitude in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.geolocation.longitude description: The longitude in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.geolocation.city description: The city name in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.geolocation.regionCode description: The region code in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.geolocation.countryCode description: The country code in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.ip description: The IPv4 address in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.portNumber description: The port number in the initial observation. type: Number - contextPath: Expanse.Issue.initialEvidence.portProtocol description: The port protocol in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.serviceId description: The Service ID in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.serviceProperties.serviceProperties.name description: The service property name in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.serviceProperties.serviceProperties.reason description: The service property reason in the initial observation. type: String - contextPath: Expanse.Issue.initialEvidence.timestamp description: The timestamp of the initial observation. type: Date - contextPath: Expanse.Issue.initialEvidence.tlsVersion description: The TLS version found in the initial observation. type: String - contextPath: Expanse.Issue.ip description: The IPv4 address last associated with the issue. type: String - contextPath: Expanse.Issue.issueType.archived description: Whether the issue type is archived. type: Boolean - contextPath: Expanse.Issue.issueType.id description: The ID of the issue type. type: String - contextPath: Expanse.Issue.issueType.name description: The name of the issue type. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.id description: The Internal Xpanse certificate ID in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuer description: The issuer in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerCountry description: The issuer country in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerEmail description: The issuer email in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerLocality description: The issuer locality in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerName description: The issuer name in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerOrg description: The issuer org in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerOrgUnit description: The issuer org unit in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.issuerState description: The issuer state in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.md5Hash description: The md5hash in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.pemSha1 description: The pemSha1 in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.pemSha256 description: The pemSha256 in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKey description: The public key in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyBits description: The public key bits in the certificate in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyModulus description: The public key modulus in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.certificate.publicKeySpki description: The public key Spki in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.serialNumber description: The serial number in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.signatureAlgorithm description: The signature algorithm in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subject description: The subject in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectAlternativeNames description: The subject alternative names in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectCountry description: The subject country in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectEmail description: The subject email in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectLocality description: The subject locality in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectName description: The subject name in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectOrg description: The subject org in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectOrgUnit description: The subject org unit in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.subjectState description: The subject state in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.certificate.validNotAfter description: The valid not after date in the certificate in the most recent observation. type: Date - contextPath: Expanse.Issue.latestEvidence.certificate.validNotBefore description: The valid not before date in the certificate in the most recent observation. type: Date - contextPath: Expanse.Issue.latestEvidence.certificate.version description: The version in the certificate in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.cipherSuite description: The cipher suite detected during the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.configuration._type description: The type of configuration data in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.configuration.validWhenScanned description: Whether the configuration was valid in the most recent observation. type: Boolean - contextPath: Expanse.Issue.latestEvidence.discoveryType description: The discovery type in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.domain description: The domain name in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.evidenceType description: The evidence type of the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.exposureId description: The exposure ID in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.exposureType description: The exposure type in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.geolocation.latitude description: The latitude in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.geolocation.longitude description: The latitude in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.geolocation.city description: The city name in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.geolocation.regionCode description: The region code in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.geolocation.countryCode description: The country code in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.ip description: The IPv4 address in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.portNumber description: The port number in the most recent observation. type: Number - contextPath: Expanse.Issue.latestEvidence.portProtocol description: The port protocol in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.serviceId description: The Service ID in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.serviceProperties.serviceProperties.name description: The service property name in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.serviceProperties.serviceProperties.reason description: The service property reason in the most recent observation. type: String - contextPath: Expanse.Issue.latestEvidence.timestamp description: The timestamp of the most recent observation. type: Date - contextPath: Expanse.Issue.latestEvidence.tlsVersion description: The TLS version found in the most recent observation. type: String - contextPath: Expanse.Issue.modified description: The timestamp of when the issue was last modified. type: Date - contextPath: Expanse.Issue.portNumber description: The port number the issue was detected on. type: Number - contextPath: Expanse.Issue.portProtocol description: The port protocol the issue was detected on. type: String - contextPath: Expanse.Issue.priority description: The priority of the issue. type: String - contextPath: Expanse.Issue.progressStatus description: The progress status of the issue. type: String - contextPath: Expanse.Issue.providers.id description: The ID of the provider the issue was detected on. type: String - contextPath: Expanse.Issue.providers.name description: The name of the provider the issue was detected on. type: String - arguments: - description: Maximum number of results to retrieve. name: limit description: List available business units from Xpanse. name: expanse-list-businessunits outputs: - contextPath: Expanse.BusinessUnit.id description: Business unit ID. type: String - contextPath: Expanse.BusinessUnit.name description: Business unit name. type: String - arguments: - description: Maximum number of results to retrieve. name: limit description: List available providers from Xpanse. name: expanse-list-providers outputs: - contextPath: Expanse.Provider.id description: Provider ID. type: String - contextPath: Expanse.Provider.name description: Provider name. type: String - arguments: - description: Maximum number of results to retrieve. name: limit description: List available Point of Contacts from Xpanse. name: expanse-list-pocs outputs: - contextPath: Expanse.PointOfContact.created description: The date in which the Point of Contact was first created. type: Date - contextPath: Expanse.PointOfContact.email description: Email address of Point of Contact. type: String - contextPath: Expanse.PointOfContact.firstName description: First Name of Point of Contact. type: String - contextPath: Expanse.PointOfContact.id description: Internal ID of Point of Contact. type: String - contextPath: Expanse.PointOfContact.lastName description: Last Name of Point of Contact. type: String - contextPath: Expanse.PointOfContact.modified description: The date in which the Point of Contact was last modified. type: Date - contextPath: Expanse.PointOfContact.phone description: Phone number of Point of Contact. type: String - contextPath: Expanse.PointOfContact.role description: Role of Point of Contact. type: String - arguments: - description: Email for Point of Contact. name: email required: true - description: First name of Point of Contact. Should be less than 64 characters. name: first_name - description: Last name of Point of Contact. Should be less than 64 characters. name: last_name - description: Phone number of Point of Contact. Should be a numeric string (ex. 15551234567). name: phone - description: Role of Point of Contact. Should be less than 64 characters. name: role description: Create a new Point of Contact in Xpanse. name: expanse-create-poc outputs: - contextPath: Expanse.PointOfContact.created description: The date in which the Point of Contact was first created. type: Date - contextPath: Expanse.PointOfContact.email description: Email address of Point of Contact. type: String - contextPath: Expanse.PointOfContact.firstName description: First Name of Point of Contact. type: String - contextPath: Expanse.PointOfContact.id description: Internal ID of Point of Contact. type: String - contextPath: Expanse.PointOfContact.lastName description: Last Name of Point of Contact. type: String - contextPath: Expanse.PointOfContact.modified description: The date in which the Point of Contact was last modified. type: Date - contextPath: Expanse.PointOfContact.phone description: Phone number of Point of Contact. type: String - contextPath: Expanse.PointOfContact.role description: Role of Point of Contact. type: String - arguments: - auto: PREDEFINED description: Type of Xpanse asset to assign the poc to. name: asset_type predefined: - IpRange - Certificate - Domain - CloudResource - Network - Device - ResponsiveIP required: true - description: ID of the asset to assign the poc to. name: asset_id required: true - description: IDs of the pocs to assign to the asset (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Email Addresses of the pocs to assign to the asset (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Assign Point of Contacts to an Xpanse asset. name: expanse-assign-pocs-to-asset - arguments: - auto: PREDEFINED description: Type of Xpanse asset to unassign the pocs from. name: asset_type predefined: - IpRange - Certificate - Domain - CloudResource - Network - Device - ResponsiveIP required: true - description: ID of the asset to unassign the pocs from. name: asset_id required: true - description: IDs of the pocs to unassign from the asset (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Names of the pocs to unassign from the asset (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Unassign Point of Contacts from an Xpanse Asset. name: expanse-unassign-pocs-from-asset - arguments: - description: ID of the IP range to assign pocs to. name: asset_id required: true - description: IDs of the pocs to assign to the IP range (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Emails of the pocs to assign to the IP range (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Assign Point of Contacts to an Xpanse IP range. name: expanse-assign-pocs-to-iprange - arguments: - description: ID of the IP range to unassign pocs from. name: asset_id required: true - description: IDs of the pocs to unassign from the IP range (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Names of the pocs to unassign from the IP range (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Unassign Point of Contacts from an Xpanse IP range. name: expanse-unassign-pocs-from-iprange - arguments: - description: ID of the certificate to assign pocs to. name: asset_id required: true - description: IDs of the pocs to assign to the certificate (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Emails of the pocs to assign to the certificate (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Assign pocs to an Xpanse certificate. name: expanse-assign-pocs-to-certificate - arguments: - description: ID of the certificate to assign pocs to. name: asset_id required: true - description: IDs of the pocs to unassign from the certificate (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Emails of the pocs to unassign from the certificate (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Unassign pocs from an Xpanse certificate. name: expanse-unassign-pocs-from-certificate - arguments: - description: ID of the domain to assign pocs to. name: asset_id required: true - description: IDs of the pocs to assign to the domain (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Emails of the pocs to assign to the domain (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Assign pocs to an Xpanse domain. name: expanse-assign-pocs-to-domain - arguments: - description: ID of the domain to unassign pocs from. name: asset_id required: true - description: IDs of the pocs to unassign from the domain (comma separated string). If used in combination with 'poc_emails' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: pocs - description: Emails of the pocs to unassign from the domain (comma separated string). If used in combination with 'pocs' the lists of pocs are merged. At least one poc ID or poc email must be provided. isArray: true name: poc_emails description: Unassign pocs from an Xpanse domain. name: expanse-unassign-pocs-from-domain - arguments: - description: Maximum number of results to retrieve. name: limit description: List available tags from Xpanse. name: expanse-list-tags outputs: - contextPath: Expanse.Tag.created description: The date in which the tag was first created. type: Date - contextPath: Expanse.Tag.description description: The description associated with the tag. type: String - contextPath: Expanse.Tag.disabled description: If the tag should be hidden as a tag option in the Expander UI. type: Boolean - contextPath: Expanse.Tag.id description: The Xpanse ID for the tag. type: String - contextPath: Expanse.Tag.modified description: The date in which metadata about the tag was last modified. type: Date - contextPath: Expanse.Tag.name description: The display name for the tag. type: String - contextPath: Expanse.Tag.tenantId description: The tenant ID associated with the tag. type: String - arguments: - auto: PREDEFINED description: Type of Xpanse asset to assign the tag to. name: asset_type predefined: - IpRange - Certificate - Domain - CloudResource - Network - Device - ResponsiveIP required: true - description: ID of the asset to assign the tags to. name: asset_id required: true - description: IDs of the tags to assign to the asset (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to assign to the asset (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Assign tags to an Xpanse asset. name: expanse-assign-tags-to-asset - arguments: - auto: PREDEFINED description: Type of Xpanse asset to unassign the tags from. name: asset_type predefined: - IpRange - Certificate - Domain - CloudResource - Network - Device - ResponsiveIP required: true - description: ID of the asset to unassign the tags from. name: asset_id required: true - description: IDs of the tags to unassign from the asset (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to unassign from the asset (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Unassign tags from an Xpanse Asset. name: expanse-unassign-tags-from-asset - arguments: - description: ID of the IP range to assign tags to. name: asset_id required: true - description: IDs of the tags to assign to the IP range (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to assign to the IP range (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Assign tags to an Xpanse IP range. name: expanse-assign-tags-to-iprange - arguments: - description: ID of the IP range to unassign tags from. name: asset_id required: true - description: IDs of the tags to unassign from the IP range (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to unassign from the IP range (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Unassign tags from an Xpanse IP range. name: expanse-unassign-tags-from-iprange - arguments: - description: ID of the certificate to assign tags to. name: asset_id required: true - description: IDs of the tags to assign to the certificate (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to assign to the certificate (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Assign tags to an Xpanse certificate. name: expanse-assign-tags-to-certificate - arguments: - description: ID of the certificate to assign tags to. name: asset_id required: true - description: IDs of the tags to unassign from the certificate (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to unassign from the certificate (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Unassign tags from an Xpanse certificate. name: expanse-unassign-tags-from-certificate - arguments: - description: ID of the domain to assign tags to. name: asset_id required: true - description: IDs of the tags to assign to the domain (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to assign to the domain (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Assign tags to an Xpanse domain. name: expanse-assign-tags-to-domain - arguments: - description: ID of the domain to unassign tags from. name: asset_id required: true - description: IDs of the tags to unassign from the domain (comma separated string). If used in combination with 'tag_names' the lists of tags are merged. isArray: true name: tags - description: Names of the tags to unassign from the domain (comma separated string). If used in combination with 'tags' the lists of tags are merged. isArray: true name: tag_names description: Unassign tags from an Xpanse domain. name: expanse-unassign-tags-from-domain - arguments: - description: Name of the tag (less than 128 characters). name: name required: true - description: Description of the tag (less than 512 characters). name: description description: Create a new tag in Xpanse. name: expanse-create-tag outputs: - contextPath: Expanse.Tag.created description: The date in which the tag was first created. type: Date - contextPath: Expanse.Tag.description description: The description associated with the tag. type: String - contextPath: Expanse.Tag.disabled description: If the tag should be hidden as a tag option in the Expander UI. type: Boolean - contextPath: Expanse.Tag.id description: The Xpanse ID for the tag. type: String - contextPath: Expanse.Tag.modified description: The date in which metadata about the tag was last modified. type: Date - contextPath: Expanse.Tag.name description: The display name for the tag. type: String - contextPath: Expanse.Tag.tenantId description: The tenant ID associated with the tag. type: String - arguments: - description: Asset ID of the Xpanse IP range to retrieve. If provided, other search parameters are ignored. name: id - description: Returns only results whose Business Unit's ID falls in the provided list. (comma separated string). Cannot be used with the 'business_unit_names' argument. isArray: true name: business_units - description: Returns only results whose Business Unit's ID falls in the provided list. (comma separated string). Cannot be used with the 'business_units' argument. isArray: true name: business_unit_names - description: Search for given IP/CIDR block using a single IP (d.d.d.d), a dashed IP range (d.d.d.d-d.d.d.d), a CIDR block (d.d.d.d/m), a partial CIDR (d.d.), or a wildcard (d.d.*.d). name: inet - description: Returns only results whose Tag ID falls in the provided list. (comma separated string). Cannot be used with the 'tag_names' argument. isArray: true name: tags - description: Returns only results whose Tag name falls in the provided list. (comma separated string). Cannot be used with the 'tags' argument. isArray: true name: tag_names - auto: PREDEFINED defaultValue: none description: Include "none" or any of the following options in the response (comma separated) - annotations, severityCounts, attributionReasons, relatedRegistrationInformation, locationInformation. name: include predefined: - annotations - severityCounts - attributionReasons - relatedRegistrationInformation - locationInformation - description: Maximum number of results to retrieve. name: limit description: Retrieve Xpanse IP ranges by asset id or search parameters. name: expanse-get-iprange outputs: - contextPath: Expanse.IPRange.annotations.additionalNotes description: Customer provided annotation details for an IP range. type: String - contextPath: Expanse.IPRange.annotations.contacts description: Customer provided point-of-contact details for an IP range. type: String - contextPath: Expanse.IPRange.annotations.tags description: Customer provided tags for an IP range. type: String - contextPath: Expanse.IPRange.attributionReasons.reason description: The reasons why an IP range is attributed to the customer. type: String - contextPath: Expanse.IPRange.businessUnits.id description: Business Units that the IP range has been assigned to. type: String - contextPath: Expanse.IPRange.businessUnits.name description: Business Units that the IP range has been assigned to. type: String - contextPath: Expanse.IPRange.created description: The date that the IP range was added to the Expander instance. type: Date - contextPath: Expanse.IPRange.id description: Internal Xpanse ID for the IP Range. type: String - contextPath: Expanse.IPRange.ipVersion description: The IP version of the IP range. type: String - contextPath: Expanse.IPRange.locationInformation.geolocation.city description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.locationInformation.geolocation.countryCode description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.locationInformation.geolocation.latitude description: The IP range geolocation. type: Number - contextPath: Expanse.IPRange.locationInformation.geolocation.longitude description: The IP range geolocation. type: Number - contextPath: Expanse.IPRange.locationInformation.geolocation.regionCode description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.locationInformation.ip description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.modified description: The date on which the IP range was last ingested into Expander. type: Date - contextPath: Expanse.IPRange.rangeIntroduced description: The date that the IP range was added to the Expander instance. type: Date - contextPath: Expanse.IPRange.rangeSize description: The number of IP addresses in the IP range. type: Number - contextPath: Expanse.IPRange.rangeType description: If the IP range is Xpanse-generated parent range or a customer-generated custom range. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.country description: The country within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.endAddress description: The end address within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.handle description: The handle within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.ipVersion description: The IP version within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.name description: The name within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.parentHandle description: The parent handle within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.address description: The address within the registry entities of the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.email description: The email within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.events.action description: The events action within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.events.actor description: The events actor within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.events.date description: The events date within the registry entities of the e IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.firstRegistered description: The first registered date within the registry entities of the e IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.formattedName description: The formatted name within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.handle description: The handle within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.id description: The ID within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.lastChanged description: The last changed date within the registry entities of the e IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.org description: The org within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.phone description: The phone number within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.relatedEntityHandles description: The related entity handles within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.remarks description: The remarks within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.roles description: The roles within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.statuses description: The statuses within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.remarks description: The remarks within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.startAddress description: The start address within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.updatedDate description: The last update date within the IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.whoisServer description: The Whois server within the IP range registration information. type: String - contextPath: Expanse.IPRange.responsiveIpCount description: The number of IPs responsive on the public Internet within the IP range. type: Number - contextPath: Expanse.IPRange.severityCounts.count description: The number of exposures observed on the IP range. type: Number - contextPath: Expanse.IPRange.severityCounts.type description: The severity level of the exposures observed on the IP range. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - arguments: - description: Domain name to retrieve (exact match). If provided, other search parameters are ignored. name: domain - description: Last date the domain was observed by Xpanse (Format is YYYY-MM-DD). name: last_observed_date - description: Search domain names that match the specified substring. name: search - description: Maximum number of entries to retrieve. name: limit - auto: PREDEFINED description: Retrieve only domains with or without DNS resolution. name: has_dns_resolution predefined: - 'true' - 'false' - auto: PREDEFINED description: Retrieve only domains with or without an active service discovered by Xpanse. name: has_active_service predefined: - 'true' - 'false' - auto: PREDEFINED description: Retrieve only domains with or without cloud resources discovered by Xpanse. name: has_related_cloud_resources predefined: - 'true' - 'false' - description: Returns only results whose Tag ID falls in the provided list. (comma separated string). Cannot be used with the 'tag_names' argument. name: tags - description: Returns only results whose Tag name falls in the provided list. (comma separated string). Cannot be used with the 'tags' argument. name: tag_names - description: Returns only results whose Business Unit's ID falls in the provided list. (comma separated string). Cannot be used with the 'business_unit_names' argument. name: business_units - description: Returns only results whose Business Unit's name falls in the provided list. (comma separated string). Cannot be used with the 'business_units' argument. name: business_unit_names - description: Returns only results whose Provider's ID falls in the provided list. (comma separated string). Cannot be used with the 'provider_names' argument. name: providers - description: Returns only results whose Provider's name falls in the provided list. (comma separated string). Cannot be used with the 'providers' argument. name: provider_names description: Retrieve Xpanse domains by domain name or search parameters. name: expanse-get-domain outputs: - contextPath: Expanse.Domain.annotations.note description: Customer provided annotation details for a domain. type: String - contextPath: Expanse.Domain.annotations.contacts.id description: ID for customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.annotations.contacts.name description: Customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.annotations.tags.id description: ID for customer added tag on a domain in Expander. type: String - contextPath: Expanse.Domain.annotations.tags.name description: Customer added tag on a domain in Expander. type: String - contextPath: Expanse.Domain.businessUnits.id description: Business Units that the domain has been assigned to. type: String - contextPath: Expanse.Domain.businessUnits.name description: Business Units that the domain has been assigned to. type: String - contextPath: Expanse.Domain.businessUnits.tenantId description: Tenant ID for business Units that the domain has been assigned to. type: String - contextPath: Expanse.Domain.dateAdded description: The date that the domain was added to the Expander instance. type: Date - contextPath: Expanse.Domain.details.recentIps.assetKey description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.assetType description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.businessUnits.id description: Business Units for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.businessUnits.name description: Business Units for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.businessUnits.tenantId description: Tenant information for business Units that the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.commonName description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.domain description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.ip description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.lastObserved description: Additional details for the recent IPs that the domain resolved to. type: Date - contextPath: Expanse.Domain.details.recentIps.provider.id description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.provider.name description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.tenant.id description: Tenant information for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.tenant.name description: Tenant information for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.tenant.tenantId description: Tenant information for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.type description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.dnsResolutionStatus description: Latest DNS resolution status. type: String - contextPath: Expanse.Domain.firstObserved description: The date that the domain was first observed. type: Date - contextPath: Expanse.Domain.hasLinkedCloudResources description: Whether the domain has any linked cloud resources associated with it. type: Boolean - contextPath: Expanse.Domain.id description: Internal Xpanse ID for Domain. type: String - contextPath: Expanse.Domain.domain description: The domain value. type: String - contextPath: Expanse.Domain.isCollapsed description: Whether or not the subdomains of the domain are collapsed. type: Boolean - contextPath: Expanse.Domain.isPaidLevelDomain description: Whether or not the domain is a PLD. type: Boolean - contextPath: Expanse.Domain.lastObserved description: The date that the domain was most recently observed. type: Date - contextPath: Expanse.Domain.lastSampledIp description: The last observed IPv4 address for the domain. type: String - contextPath: Expanse.Domain.lastSubdomainMetadata.collapseType description: Sub-domain metadata. type: String - contextPath: Expanse.Domain.lastSubdomainMetadata.numSubdomains description: Sub-domain metadata. type: Number - contextPath: Expanse.Domain.lastSubdomainMetadata.numDistinctIps description: Sub-domain metadata. type: Number - contextPath: Expanse.Domain.lastSubdomainMetadata.date description: Sub-domain metadata. type: Date - contextPath: Expanse.Domain.providers.id description: Information about the hosting provider of the IP the domain resolves to. type: String - contextPath: Expanse.Domain.providers.name description: Information about the hosting provider of the IP the domain resolves to. type: String - contextPath: Expanse.Domain.serviceStatus description: Detected service statuses for the domain. type: String - contextPath: Expanse.Domain.sourceDomain description: The source domain for the domain object. type: String - contextPath: Expanse.Domain.tenant.id description: Tenant information for the domain. type: String - contextPath: Expanse.Domain.tenant.name description: Tenant information for the domain. type: String - contextPath: Expanse.Domain.tenant.tenantId description: Tenant information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.city description: The admin city in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.country description: The admin country in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.emailAddress description: The admin email address in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.faxExtension description: The admin fax extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.faxNumber description: The admin fax number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.name description: The admin name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.organization description: The admin organization in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.phoneExtension description: The admin phone extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.phoneNumber description: The admin phone number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.postalCode description: The admin postal code in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.province description: The admin province in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.registryId description: The admin registry ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.street description: The admin street in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.creationDate description: The creation date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.whois.dnssec description: The dnssec in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.domain description: The domain in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.domainStatuses description: The domain statuses in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.nameServers description: The name servers in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.city description: The registrant city in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.country description: The registrant country in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.emailAddress description: The registrant email address in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.faxExtension description: The registrant fax extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.faxNumber description: The registrant fax number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.name description: The registrant name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.organization description: The registrant organization in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.phoneExtension description: The registrant phone extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.phoneNumber description: The registrant phone number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.postalCode description: The registrant postal code in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.province description: The registrant province in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.registryId description: The registrant registry ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.street description: The registrant street in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.abuseContactEmail description: The registrar abuse contact email in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.abuseContactPhone description: The registrar abuse contact phone in the Whois information for the domain''. type: String - contextPath: Expanse.Domain.whois.registrar.formattedName description: The registrar formatted name Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.ianaId description: The registrar iana ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.name description: The registrar name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.registrationExpirationDate description: The registrar registration expiration date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.whois.registrar.url description: The registrar URL in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.whoisServer description: The registrar Whois server in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registryDomainId description: The registry domain ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registryExpiryDate description: The registry expiry date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.whois.reseller description: The reseller in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.city description: The tech city in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.country description: The tech country in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.emailAddress description: The tech email address in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.faxExtension description: The tech fax extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.faxNumber description: The tech fax number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.name description: The tech name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.organization description: The tech organization in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.phoneExtension description: The tech phone extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.phoneNumber description: The tech phone number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.postalCode description: The tech postal code in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.province description: The tech province in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.registryId description: The tech registry ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.street description: The tech street in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.updatedDate description: The updated date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.details.cloudResources.id description: The cloud resource ID. type: String - contextPath: Expanse.Domain.details.cloudResources.tenant.id description: Tenant information for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.tenant.name description: Tenant information for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.tenant.tenantId description: Tenant information for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.businessUnits.id description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.businessUnits.name description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.businessUnits.tenantId description: Tenant information businessUnits that the cloud resource as been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.dateAdded description: The date that the cloud resource was added to the Expander instance. type: Date - contextPath: Expanse.Domain.details.cloudResources.firstObserved description: The date that the cloud resource was first observed. type: Date - contextPath: Expanse.Domain.details.cloudResources.lastObserved description: The date that the domain was most recently observed. type: Date - contextPath: Expanse.Domain.details.cloudResources.instanceId description: Instance ID for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.type description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.ips description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.domain description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.provider.id description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.provider.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.region description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.vpc.id description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.vpc.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.accountIntegration.id description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.accountIntegration.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.assetKey description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.assetType description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.businessUnits.id description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.businessUnits.name description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.businessUnits.tenantId description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.commonName description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.domain description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.ip description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.lastObserved description: Additional details for the recent IPs linked to the linked cloud resource. type: Date - contextPath: Expanse.Domain.details.cloudResources.recentIps.provider.id description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.provider.name description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.tenant.id description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.tenant.name description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.tenant.tenantId description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.type description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.note description: Customer provided annotation details for a domain. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.contacts.id description: ID for customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.contacts.name description: Customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.tags.id description: ID for customer added tag on a domain in Expander. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.tags.name description: Customer added tag on a domain in Expander. type: String - contextPath: Domain.Name description: 'The domain name, for example: "google.com".' type: String - contextPath: Domain.DNS description: A list of IP objects resolved by DNS. type: String - contextPath: Domain.DetectionEngines description: The total number of engines that checked the indicator. type: Number - contextPath: Domain.PositiveDetections description: The number of engines that positively detected the indicator as malicious. type: Number - contextPath: Domain.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.UpdatedDate description: The date that the domain was last updated. type: String - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.DomainStatus description: The status of the domain. type: Date - contextPath: Domain.NameServers description: Name servers of the domain. type: String - contextPath: Domain.Organization description: The organization of the domain. type: String - contextPath: Domain.Subdomains description: Subdomains of the domain. type: String - contextPath: Domain.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.Registrant.Country description: The country of the registrant. type: String - contextPath: Domain.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.WHOIS.DomainStatus description: The status of the domain. type: String - contextPath: Domain.WHOIS.NameServers description: Name servers of the domain. type: String - contextPath: Domain.WHOIS.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.WHOIS.UpdatedDate description: The date that the domain was last updated. type: Date - contextPath: Domain.WHOIS.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.WHOIS.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Phone description: The phone number of the registrant. type: String - contextPath: Domain.WHOIS.Registrar.Name description: 'The name of the registrar, for example: "GoDaddy".' type: String - contextPath: Domain.WHOIS.Registrar.AbuseEmail description: The email address of the contact for reporting abuse. type: String - contextPath: Domain.WHOIS.Registrar.AbusePhone description: The phone number of contact for reporting abuse. type: String - contextPath: Domain.WHOIS.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.WHOIS.History description: List of Whois objects. type: String - contextPath: Domain.Malicious.Vendor description: The vendor reporting the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: A description explaining why the domain was reported as malicious. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - arguments: - description: The common name of the certificate to search domains for. Fuzzy matching is done on this name, however query times can grow quite large when searching for short strings. Ex. "*.myhost.com" is a better search term than "host". name: common_name - description: The IP address to search domains for. name: ip - description: Maximum number of matching certificates to retrieve. name: limit - description: Maximum number of domains per certificate to retrieve. name: domains_limit description: Returns all the Xpanse domains which have been seen with the specified certificate or IP address. name: expanse-get-associated-domains outputs: - contextPath: Expanse.AssociatedDomain.name description: Name of the domain. type: String - contextPath: Expanse.AssociatedDomain.IP description: IP Address the domain resolved to. type: String - contextPath: Expanse.AssociatedDomain.certificate description: Xpanse ID of the certificate associated to this domain. type: String - contextPath: Domain.Name description: 'The domain name, for example: "google.com".' type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - arguments: - description: MD5 Hash of the certificate. If provided, other search parameters are ignored. name: md5_hash - description: Last date the domain was observed by Xpanse (Format is YYYY-MM-DD), to be used with domain argument. name: last_observed_date - description: Search for certificates with the specified substring in common name. name: search - description: Maximum number of entries to retrieve. name: limit - auto: PREDEFINED description: Retrieve only certificates actively/not actively advertised. name: has_certificate_advertisement predefined: - 'true' - 'false' - auto: PREDEFINED description: Retrieve only certificates with or without an active service discovered by Xpanse. name: has_active_service predefined: - 'true' - 'false' - auto: PREDEFINED description: Retrieve only certificates with or without cloud resources discovered by Xpanse. name: has_related_cloud_resources predefined: - 'true' - 'false' - description: Returns only results whose Tag ID falls in the provided list. (comma separated string). Cannot be used with the 'tag_names' argument. name: tags - description: Returns only results whose Tag name falls in the provided list. (comma separated string). Cannot be used with the 'tags' argument. name: tag_names - description: Returns only results whose Business Unit's ID falls in the provided list. (comma separated string). Cannot be used with the 'business_unit_names' argument. name: business_units - description: Returns only results whose Business Unit's name falls in the provided list. (comma separated string). Cannot be used with the 'business_units' argument. name: business_unit_names - description: Returns only results whose Provider's ID falls in the provided list. (comma separated string). Cannot be used with the 'provider_names' argument. name: providers - description: Returns only results whose Provider's name falls in the provided list. (comma separated string). Cannot be used with the 'providers' argument. name: provider_names description: Retrieve Xpanse certificates by MD5 hash or search parameters. name: expanse-get-certificate outputs: - contextPath: Expanse.Certificate.annotations.note description: Customer provided annotation details for a certificate. type: String - contextPath: Expanse.Certificate.annotations.contacts.id description: ID for customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.annotations.contacts.name description: Customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.annotations.tags.id description: ID for customer added tag on a certificate in Expander. type: String - contextPath: Expanse.Certificate.annotations.tags.name description: Customer added tag on a certificate in Expander. type: String - contextPath: Expanse.Certificate.businessUnits.id description: Business Units that the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.businessUnits.name description: Business Units that the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.businessUnits.tenantId description: Tenant information for business units that the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate. type: String - contextPath: Expanse.Certificate.certificate.id description: The certificate ID. type: String - contextPath: Expanse.Certificate.certificate.issuer description: The issuer in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerCountry description: The issuer country in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerEmail description: The issuer email in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerLocality description: The issuer locality in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerName description: The issuer name in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerOrg description: The issuer org in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerOrgUnit description: The issuer org unit in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerState description: The issuer state in the certificate. type: String - contextPath: Expanse.Certificate.certificate.md5Hash description: The md5hash in the certificate. type: String - contextPath: Expanse.Certificate.certificate.pemSha1 description: The pemSha1 in the certificate. type: String - contextPath: Expanse.Certificate.certificate.pemSha256 description: The pemSha256 in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKey description: The public key in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKeyBits description: The public key bits in the certificate. type: Number - contextPath: Expanse.Certificate.certificate.publicKeyModulus description: The public key modulus in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate. type: Number - contextPath: Expanse.Certificate.certificate.publicKeySpki description: The public key Spki in the certificate. type: String - contextPath: Expanse.Certificate.certificate.serialNumber description: The serial number in the certificate. type: String - contextPath: Expanse.Certificate.certificate.signatureAlgorithm description: The signature algorithm in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subject description: The subject in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectAlternativeNames description: The subject alternative names in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectCountry description: The subject country in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectEmail description: The subject email in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectLocality description: The subject locality in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectName description: The subject name in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectOrg description: The subject org in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectOrgUnit description: The subject org unit in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectState description: The subject state in the certificate. type: String - contextPath: Expanse.Certificate.certificate.validNotAfter description: The valid not after date in the certificate. type: Date - contextPath: Expanse.Certificate.certificate.validNotBefore description: The valid not before date in the certificate. type: Date - contextPath: Expanse.Certificate.certificate.version description: The version in the certificate. type: String - contextPath: Expanse.Certificate.certificateAdvertisementStatus description: Certificate advertisement statuses. type: String - contextPath: Expanse.Certificate.commonName description: Common Name for the certificate. type: String - contextPath: Expanse.Certificate.dateAdded description: The date that the certificate was added to the Expander instance. type: Date - contextPath: Expanse.Certificate.details.base64Encoded description: Additional details for the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.assetKey description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.assetType description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.businessUnits.id description: Business Units that the recent IPs linked to the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.details.recentIps.businessUnits.name description: Business Units that the recent IPs linked to the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.details.recentIps.businessUnits.tenantId description: Tenant information for business Units that the recent IPs linked to the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.details.recentIps.commonName description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.domain description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.ip description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.lastObserved description: Additional details for the recent IPs linked to the certificate. type: Date - contextPath: Expanse.Certificate.details.recentIps.provider.id description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.provider.name description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.tenant.id description: Tenant information for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.tenant.name description: Tenant information for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.tenant.tenantId description: Tenant information for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.type description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.firstObserved description: The date that the certificate was first observed. type: Date - contextPath: Expanse.Certificate.hasLinkedCloudResources description: Whether the certificate has any linked cloud resources associated with it. type: Boolean - contextPath: Expanse.Certificate.id description: Internal Xpanse ID for Certificate. type: String - contextPath: Expanse.Certificate.lastObserved description: The date that the certificate was most recently observed. type: Date - contextPath: Expanse.Certificate.properties description: Xpanse tagged properties of the certificate. type: String - contextPath: Expanse.Certificate.providers.id description: The Provider information for the certificate. type: String - contextPath: Expanse.Certificate.providers.name description: The Provider information for the certificate. type: String - contextPath: Expanse.Certificate.serviceStatus description: Detected service statuses for the certificate. type: String - contextPath: Expanse.Certificate.tenant.id description: Tenant information for the certificate. type: String - contextPath: Expanse.Certificate.tenant.name description: Tenant information for the certificate. type: String - contextPath: Expanse.Certificate.tenant.tenantId description: Tenant information for the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.id description: The cloud resource ID. type: String - contextPath: Expanse.Certificate.details.cloudResources.tenant.id description: Tenant information for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.tenant.name description: Tenant information for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.tenant.tenantId description: Tenant information for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.businessUnits.id description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.businessUnits.name description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.businessUnits.tenantId description: Tenant information businessUnits that the cloud resource as been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.dateAdded description: The date that the cloud resource was added to the Expander instance. type: Date - contextPath: Expanse.Certificate.details.cloudResources.firstObserved description: The date that the cloud resource was first observed. type: Date - contextPath: Expanse.Certificate.details.cloudResources.lastObserved description: The date that the certificate was most recently observed. type: Date - contextPath: Expanse.Certificate.details.cloudResources.instanceId description: Instance ID for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.type description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.ips description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.domain description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.provider.id description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.provider.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.region description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.vpc.id description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.vpc.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.accountIntegration.id description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.accountIntegration.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.assetKey description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.assetType description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.businessUnits.id description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.businessUnits.name description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.businessUnits.tenantId description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.commonName description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.domain description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.ip description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.lastObserved description: Additional details for the recent IPs linked to the linked cloud resource. type: Date - contextPath: Expanse.Certificate.details.cloudResources.recentIps.provider.id description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.provider.name description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.tenant.id description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.tenant.name description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.tenant.tenantId description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.type description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.note description: Customer provided annotation details for a certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.contacts.id description: ID for customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.contacts.name description: Customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.tags.id description: ID for customer added tag on a certificate in Expander. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.tags.name description: Customer added tag on a certificate in Expander. type: String - contextPath: Certificate.Name description: Name (CN or SAN) appearing in the certificate. type: String - contextPath: Certificate.SubjectDN description: | The Subject Distinguished Name of the certificate. This field includes the Common Name of the certificate. type: String - contextPath: Certificate.PEM description: Certificate in PEM format. type: String - contextPath: Certificate.IssuerDN description: The Issuer Distinguished Name of the certificate. type: String - contextPath: Certificate.SerialNumber description: The Serial Number of the certificate. type: String - contextPath: Certificate.ValidityNotAfter description: End of certificate validity period. type: Date - contextPath: Certificate.ValidityNotBefore description: Start of certificate validity period. type: Date - contextPath: Certificate.SubjectAlternativeName.Value description: Name of the SAN. type: String - contextPath: Certificate.SHA256 description: SHA256 Fingerprint of the certificate in DER format. type: String - contextPath: Certificate.SHA1 description: SHA1 Fingerprint of the certificate in DER format. type: String - contextPath: Certificate.MD5 description: MD5 Fingerprint of the certificate in DER format. type: String - contextPath: Certificate.PublicKey.Algorithm description: Algorithm used for public key of the certificate. type: String - contextPath: Certificate.PublicKey.Length description: Length in bits of the public key of the certificate. type: Number - contextPath: Certificate.PublicKey.Modulus description: Modulus of the public key for RSA keys. type: String - contextPath: Certificate.PublicKey.Exponent description: Exponent of the public key for RSA keys. type: Number - contextPath: Certificate.PublicKey.PublicKey description: The public key for DSA/Unknown keys. type: String - contextPath: Certificate.SPKISHA256 description: SHA256 fingerprint of the certificate Subject Public Key Info. type: String - contextPath: Certificate.Signature.Algorithm description: Algorithm used in the signature of the certificate. type: String - contextPath: Certificate.Malicious.Vendor description: The vendor that reported the file as malicious. type: String - contextPath: Certificate.Malicious.Description description: A description explaining why the file was determined to be malicious. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - arguments: - default: true description: | MD5, SHA-1, SHA-256 or SHA-512 hash of the certificate to enrich. If MD5 is given, the command will check directly with Xpanse API otherwise the script looks first for an indicator with the given hash to retrieve the corresponding MD5 hash. isArray: true name: certificate - auto: PREDEFINED description: | If set to true, the command updates the Xpanse custom fields of the indicator. Only if an indicator already exists. name: set_expanse_fields predefined: - 'true' - 'false' description: Provides data enrichment for an X509 Certificate from Xpanse. name: certificate outputs: - contextPath: Expanse.Certificate.annotations.note description: Customer provided annotation details for a certificate. type: String - contextPath: Expanse.Certificate.annotations.contacts.id description: ID for customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.annotations.contacts.name description: Customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.annotations.tags.id description: ID for customer added tag on a certificate in Expander. type: String - contextPath: Expanse.Certificate.annotations.tags.name description: Customer added tag on a certificate in Expander. type: String - contextPath: Expanse.Certificate.businessUnits.id description: Business Units that the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.businessUnits.name description: Business Units that the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.businessUnits.tenantId description: Tenant information for business units that the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.certificate.formattedIssuerOrg description: The formatted issuer org in the certificate. type: String - contextPath: Expanse.Certificate.certificate.id description: The certificate ID. type: String - contextPath: Expanse.Certificate.certificate.issuer description: The issuer in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerAlternativeNames description: The issuer alternative names in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerCountry description: The issuer country in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerEmail description: The issuer email in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerLocality description: The issuer locality in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerName description: The issuer name in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerOrg description: The issuer org in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerOrgUnit description: The issuer org unit in the certificate. type: String - contextPath: Expanse.Certificate.certificate.issuerState description: The issuer state in the certificate. type: String - contextPath: Expanse.Certificate.certificate.md5Hash description: The md5hash in the certificate. type: String - contextPath: Expanse.Certificate.certificate.pemSha1 description: The pemSha1 in the certificate. type: String - contextPath: Expanse.Certificate.certificate.pemSha256 description: The pemSha256 in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKey description: The public key in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKeyAlgorithm description: The public key algorithm in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKeyBits description: The public key bits in the certificate. type: Number - contextPath: Expanse.Certificate.certificate.publicKeyModulus description: The public key modulus in the certificate. type: String - contextPath: Expanse.Certificate.certificate.publicKeyRsaExponent description: The public key RSA exponent in the certificate. type: Number - contextPath: Expanse.Certificate.certificate.publicKeySpki description: The public key Spki in the certificate. type: String - contextPath: Expanse.Certificate.certificate.serialNumber description: The serial number in the certificate. type: String - contextPath: Expanse.Certificate.certificate.signatureAlgorithm description: The signature algorithm in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subject description: The subject in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectAlternativeNames description: The subject alternative names in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectCountry description: The subject country in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectEmail description: The subject email in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectLocality description: The subject locality in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectName description: The subject name in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectOrg description: The subject org in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectOrgUnit description: The subject org unit in the certificate. type: String - contextPath: Expanse.Certificate.certificate.subjectState description: The subject state in the certificate. type: String - contextPath: Expanse.Certificate.certificate.validNotAfter description: The valid not after date in the certificate. type: Date - contextPath: Expanse.Certificate.certificate.validNotBefore description: The valid not before date in the certificate. type: Date - contextPath: Expanse.Certificate.certificate.version description: The version in the certificate. type: String - contextPath: Expanse.Certificate.certificateAdvertisementStatus description: Certificate advertisement statuses. type: String - contextPath: Expanse.Certificate.commonName description: Common Name for the certificate. type: String - contextPath: Expanse.Certificate.dateAdded description: The date that the certificate was added to the Expander instance. type: Date - contextPath: Expanse.Certificate.details.base64Encoded description: Additional details for the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.assetKey description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.assetType description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.businessUnits.id description: Business Units that the recent IPs linked to the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.details.recentIps.businessUnits.name description: Business Units that the recent IPs linked to the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.details.recentIps.businessUnits.tenantId description: Tenant information for business Units that the recent IPs linked to the certificate has been assigned to. type: String - contextPath: Expanse.Certificate.details.recentIps.commonName description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.domain description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.ip description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.lastObserved description: Additional details for the recent IPs linked to the certificate. type: Date - contextPath: Expanse.Certificate.details.recentIps.provider.id description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.provider.name description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.tenant.id description: Tenant information for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.tenant.name description: Tenant information for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.tenant.tenantId description: Tenant information for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.details.recentIps.type description: Additional details for the recent IPs linked to the certificate. type: String - contextPath: Expanse.Certificate.firstObserved description: The date that the certificate was first observed. type: Date - contextPath: Expanse.Certificate.hasLinkedCloudResources description: Whether the certificate has any linked cloud resources associated with it. type: Boolean - contextPath: Expanse.Certificate.id description: Internal Xpanse ID for Certificate. type: String - contextPath: Expanse.Certificate.lastObserved description: The date that the certificate was most recently observed. type: Date - contextPath: Expanse.Certificate.properties description: Xpanse tagged properties of the certificate. type: String - contextPath: Expanse.Certificate.providers.id description: The Provider information for the certificate. type: String - contextPath: Expanse.Certificate.providers.name description: The Provider information for the certificate. type: String - contextPath: Expanse.Certificate.serviceStatus description: Detected service statuses for the certificate. type: String - contextPath: Expanse.Certificate.tenant.id description: Tenant information for the certificate. type: String - contextPath: Expanse.Certificate.tenant.name description: Tenant information for the certificate. type: String - contextPath: Expanse.Certificate.tenant.tenantId description: Tenant information for the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.id description: The cloud resource ID. type: String - contextPath: Expanse.Certificate.details.cloudResources.tenant.id description: Tenant information for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.tenant.name description: Tenant information for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.tenant.tenantId description: Tenant information for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.businessUnits.id description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.businessUnits.name description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.businessUnits.tenantId description: Tenant information businessUnits that the cloud resource as been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.dateAdded description: The date that the cloud resource was added to the Expander instance. type: Date - contextPath: Expanse.Certificate.details.cloudResources.firstObserved description: The date that the cloud resource was first observed. type: Date - contextPath: Expanse.Certificate.details.cloudResources.lastObserved description: The date that the certificate was most recently observed. type: Date - contextPath: Expanse.Certificate.details.cloudResources.instanceId description: Instance ID for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.type description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.ips description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.domain description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.provider.id description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.provider.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.region description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.vpc.id description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.vpc.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.accountIntegration.id description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.accountIntegration.name description: Additional details for the cloud resource linked to the certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.assetKey description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.assetType description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.businessUnits.id description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.businessUnits.name description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.businessUnits.tenantId description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.commonName description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.domain description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.ip description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.lastObserved description: Additional details for the recent IPs linked to the linked cloud resource. type: Date - contextPath: Expanse.Certificate.details.cloudResources.recentIps.provider.id description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.provider.name description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.tenant.id description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.tenant.name description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.tenant.tenantId description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.recentIps.type description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.note description: Customer provided annotation details for a certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.contacts.id description: ID for customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.contacts.name description: Customer provided contact details for a certificate. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.tags.id description: ID for customer added tag on a certificate in Expander. type: String - contextPath: Expanse.Certificate.details.cloudResources.annotations.tags.name description: Customer added tag on a certificate in Expander. type: String - contextPath: Certificate.Name description: Name (CN or SAN) appearing in the certificate. type: String - contextPath: Certificate.SubjectDN description: | The Subject Distinguished Name of the certificate. This field includes the Common Name of the certificate. type: String - contextPath: Certificate.PEM description: Certificate in PEM format. type: String - contextPath: Certificate.IssuerDN description: The Issuer Distinguished Name of the certificate. type: String - contextPath: Certificate.SerialNumber description: The Serial Number of the certificate. type: String - contextPath: Certificate.ValidityNotAfter description: End of certificate validity period. type: Date - contextPath: Certificate.ValidityNotBefore description: Start of certificate validity period. type: Date - contextPath: Certificate.SubjectAlternativeName.Value description: Name of the SAN. type: String - contextPath: Certificate.SHA256 description: SHA256 Fingerprint of the certificate in DER format. type: String - contextPath: Certificate.SHA1 description: SHA1 Fingerprint of the certificate in DER format. type: String - contextPath: Certificate.MD5 description: MD5 Fingerprint of the certificate in DER format. type: String - contextPath: Certificate.PublicKey.Algorithm description: Algorithm used for public key of the certificate. type: String - contextPath: Certificate.PublicKey.Length description: Length in bits of the public key of the certificate. type: Number - contextPath: Certificate.PublicKey.Modulus description: Modulus of the public key for RSA keys. type: String - contextPath: Certificate.PublicKey.Exponent description: Exponent of the public key for RSA keys. type: Number - contextPath: Certificate.PublicKey.PublicKey description: The public key for DSA/Unknown keys. type: String - contextPath: Certificate.SPKISHA256 description: SHA256 fingerprint of the certificate Subject Public Key Info. type: String - contextPath: Certificate.Signature.Algorithm description: Algorithm used in the signature of the certificate. type: String - contextPath: Certificate.Malicious.Vendor description: The vendor that reported the file as malicious. type: String - contextPath: Certificate.Malicious.Description description: A description explaining why the file was determined to be malicious. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - arguments: - description: Maximum number of cloud resources to retrieve. name: limit - description: Last date the cloud resource was observed by Xpanse (Format is YYYY-MM-DD). name: last_observed_date - description: A domain search string to find related cloud resources. name: domain - description: An IP search string to find related cloud resources. name: ip - description: A search string of provider IDs to find cloud resources hosted by specific providers. isArray: true name: providers - description: A search string of provider names to find cloud resources hosted by specific providers. isArray: true name: provider_names - description: A search string of business unit IDs to find cloud resources belonging to a specific business unit. isArray: true name: business_units - description: A search string of business unit names to find cloud resources belonging to a specific business unit. isArray: true name: business_unit_names - description: A search string of tag IDs to find cloud resources that have been assigned a specific tag. isArray: true name: tags - description: A search string of tag names to find cloud resources that have been assigned a specific tag. isArray: true name: tag_names - description: A search string of asset types to find cloud resources of a specific type. isArray: true name: types - description: A search string of regions to find cloud resources that are hosted in a specific region. isArray: true name: regions description: Retrieve cloud resources from Xpanse. name: expanse-get-cloud-resources outputs: - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: Expanse.CloudResource.accountIntegration.id description: The ID of the cloud resource account integration. type: String - contextPath: Expanse.CloudResource.accountIntegration.name description: The name of the cloud resource account integration. type: String - contextPath: Expanse.CloudResource.annotations.note description: Note metadata on the cloud resource. type: String - contextPath: Expanse.CloudResource.businessUnits.id description: The internal ID of the business unit that the cloud resource belongs to. type: String - contextPath: Expanse.CloudResource.businessUnits.name description: The name of the business unit that the cloud resource belongs to. type: String - contextPath: Expanse.CloudResource.businessUnits.tenantId description: The internal tenant ID of the business unit that the cloud resource belongs to. type: String - contextPath: Expanse.CloudResource.dateAdded description: The date that the cloud resource was added. type: Date - contextPath: Expanse.CloudResource.details description: Details about the cloud resource. type: String - contextPath: Expanse.CloudResource.domain description: Domain name associated with the cloud resource. type: String - contextPath: Expanse.CloudResource.firstObserved description: The date that the cloud resource was first observed. type: Date - contextPath: Expanse.CloudResource.id description: The internal ID for the cloud resource. type: String - contextPath: Expanse.CloudResource.instanceId description: The instance ID of the cloud resource. type: String - contextPath: Expanse.CloudResource.ips description: IPs associated with the cloud resource. type: String - contextPath: Expanse.CloudResource.lastObserved description: The date that the cloud resource was most recently observed. type: Date - contextPath: Expanse.CloudResource.name description: The friendly name of the cloud resource. type: String - contextPath: Expanse.CloudResource.provider.id description: The ID of the provider where the cloud resource is hosted. type: String - contextPath: Expanse.CloudResource.provider.name description: The name of the provider where the cloud resource is hosted. type: String - contextPath: Expanse.CloudResource.region description: The region where the cloud resouce is hosted. type: String - contextPath: Expanse.CloudResource.serviceStatus description: Whether the cloud resource has any known associated services. type: String - contextPath: Expanse.CloudResource.sourceDetails description: The integration source of the cloud resource. type: String - contextPath: Expanse.CloudResource.tenant.id description: The internal tenant ID of the cloud resource. type: String - contextPath: Expanse.CloudResource.tenant.name description: The tenant name of the cloud resouce. type: String - contextPath: Expanse.CloudResource.tenant.tenantId description: The internal tenant ID of the cloud resource. type: String - contextPath: Expanse.CloudResource.type description: The type of cloud resource. type: String - contextPath: Expanse.CloudResource.vpc.id description: Any associated VPC ID. type: String - contextPath: Expanse.CloudResource.vpc.name description: Any associated VPC names. type: String - arguments: - description: The ID of the cloud resource. name: id required: true description: Retrieve a specified cloud resource from Xpanse. name: expanse-get-cloud-resource outputs: - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: Expanse.CloudResource.accountIntegration.id description: The ID of the cloud resource account integration. type: String - contextPath: Expanse.CloudResource.accountIntegration.name description: The name of the cloud resource account integration. type: String - contextPath: Expanse.CloudResource.annotations.note description: Note metadata on the cloud resource. type: String - contextPath: Expanse.CloudResource.businessUnits.id description: The internal ID of the business unit that the cloud resource belongs to. type: String - contextPath: Expanse.CloudResource.businessUnits.name description: The name of the business unit that the cloud resource belongs to. type: String - contextPath: Expanse.CloudResource.businessUnits.tenantId description: The internal tenant ID of the business unit that the cloud resource belongs to. type: String - contextPath: Expanse.CloudResource.dateAdded description: The date that the cloud resource was added. type: Date - contextPath: Expanse.CloudResource.details description: Details about the cloud resource. type: String - contextPath: Expanse.CloudResource.domain description: Domain name associated with the cloud resource. type: String - contextPath: Expanse.CloudResource.firstObserved description: The date that the cloud resource was first observed. type: Date - contextPath: Expanse.CloudResource.id description: The internal ID for the cloud resource. type: String - contextPath: Expanse.CloudResource.instanceId description: The instance ID of the cloud resource. type: String - contextPath: Expanse.CloudResource.ips description: IPs associated with the cloud resource. type: String - contextPath: Expanse.CloudResource.lastObserved description: The date that the cloud resource was most recently observed. type: Date - contextPath: Expanse.CloudResource.name description: The friendly name of the cloud resource. type: String - contextPath: Expanse.CloudResource.provider.id description: The ID of the provider where the cloud resource is hosted. type: String - contextPath: Expanse.CloudResource.provider.name description: The name of the provider where the cloud resource is hosted. type: String - contextPath: Expanse.CloudResource.region description: The region where the cloud resouce is hosted. type: String - contextPath: Expanse.CloudResource.serviceStatus description: Whether the cloud resource has any known associated services. type: String - contextPath: Expanse.CloudResource.sourceDetails description: The integration source of the cloud resource. type: String - contextPath: Expanse.CloudResource.tenant.id description: The internal tenant ID of the cloud resource. type: String - contextPath: Expanse.CloudResource.tenant.name description: The tenant name of the cloud resouce. type: String - contextPath: Expanse.CloudResource.tenant.tenantId description: The internal tenant ID of the cloud resource. type: String - contextPath: Expanse.CloudResource.type description: The type of cloud resource. type: String - contextPath: Expanse.CloudResource.vpc.id description: Any associated VPC ID. type: String - contextPath: Expanse.CloudResource.vpc.name description: Any associated VPC names. type: String - arguments: - description: Maximum number of flows to retrieve. name: limit - description: Retrieve only flows matching this risk rule ID. name: risk_rule - description: Filter by internal IP range. Supported formats a.b.c.d, a.b.c.d/e, a.b.c.d-a.b.c.d, a., a.*. name: internal_ip_range - description: Filter by tag names (comma separated string). isArray: true name: tag_names - description: Created Before date (supports ISO8601 format). name: created_before - description: Created After date (supports ISO8601 format). name: created_after deprecated: true description: (Deprecated) Retrieve risky flows detected by Xpanse Behavior. name: expanse-get-risky-flows outputs: - contextPath: Expanse.RiskyFlow.acked description: Whether the risky flow was acked. type: Boolean - contextPath: Expanse.RiskyFlow.businessUnit.id description: The business unit id of the asset involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.businessUnit.name description: The business unit name of the asset involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.created description: The timestamp when the risky flow was found and created by Xpanse. type: Date - contextPath: Expanse.RiskyFlow.externalAddress description: The external IPv4 address involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.externalCountryCode description: The external country code of the IPv4 involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.externalCountryCodes description: The external country codes of the IPv4 involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.externalPort description: The external port of the communication involved in the risky flow. type: Number - contextPath: Expanse.RiskyFlow.flowDirection description: The direction of the risky flow. type: String - contextPath: Expanse.RiskyFlow.id description: The internal ID of the risky flow. type: String - contextPath: Expanse.RiskyFlow.internalAddress description: The internal IPv4 address involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.internalCountryCode description: The internal country code of the IPv4 involved in the risky flow''. type: String - contextPath: Expanse.RiskyFlow.internalCountryCodes description: The internal country codes of the IPv4 involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.internalPort description: The internal port of the communication involved in the risky flow. type: Number - contextPath: Expanse.RiskyFlow.internalTags.ipRange description: Any tags associated with with the internal asset involved in the risky flow. type: String - contextPath: Expanse.RiskyFlow.observationTimestamp description: The timestamp when the risky flow took place. type: Date - contextPath: Expanse.RiskyFlow.protocol description: The protocol of the risky flow. type: String - contextPath: Expanse.RiskyFlow.riskRule.additionalDataFields description: Additional data fields associated with the risk rule for the risky flow. type: String - contextPath: Expanse.RiskyFlow.riskRule.description description: The risk rule description for the risky flow. type: String - contextPath: Expanse.RiskyFlow.riskRule.id description: The risk rule ID for the risky flow. type: String - contextPath: Expanse.RiskyFlow.riskRule.name description: The risk rule name for the risky flow. type: String - contextPath: Expanse.RiskyFlow.tenantBusinessUnitId description: The tenant ID that the risky flow affects. type: String - contextPath: Expanse.RiskyFlow.internalDomains description: The internal domains associated with the risky flow. type: String - contextPath: Expanse.RiskyFlow.internalExposureTypes description: The known exposure types associated with the asset involved in the risky flow. type: String - arguments: - description: Maximum number of entries to retrieve. name: limit deprecated: true description: (Deprecated) List risk rules from Xpanse Behavior. name: expanse-list-risk-rules outputs: - contextPath: Expanse.RiskRule.abbreviatedName description: The abbreviated name of the risk rule. type: String - contextPath: Expanse.RiskRule.businessUnits.id description: The business unit ID that the risk rule applies to. type: String - contextPath: Expanse.RiskRule.dataFields description: The data fields of the risk rule. type: String - contextPath: Expanse.RiskRule.description description: The description of the risk rule. type: String - contextPath: Expanse.RiskRule.direction description: The directionality of the risk rule. type: String - contextPath: Expanse.RiskRule.id description: The risk rule ID. type: String - contextPath: Expanse.RiskRule.name description: The risk rule name. type: String - arguments: - default: true description: The domain name to enrich. isArray: true name: domain required: true description: Provides data enrichment for domains. name: domain outputs: - contextPath: Expanse.Domain.annotations.note description: Customer provided annotation details for a domain. type: String - contextPath: Expanse.Domain.annotations.contacts.id description: ID for customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.annotations.contacts.name description: Customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.annotations.tags.id description: ID for customer added tag on a domain in Expander. type: String - contextPath: Expanse.Domain.annotations.tags.name description: Customer added tag on a domain in Expander. type: String - contextPath: Expanse.Domain.businessUnits.id description: Business Units that the domain has been assigned to. type: String - contextPath: Expanse.Domain.businessUnits.name description: Business Units that the domain has been assigned to. type: String - contextPath: Expanse.Domain.businessUnits.tenantId description: Tenant ID for business Units that the domain has been assigned to. type: String - contextPath: Expanse.Domain.dateAdded description: The date that the domain was added to the Expander instance. type: Date - contextPath: Expanse.Domain.details.recentIps.assetKey description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.assetType description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.businessUnits.id description: Business Units for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.businessUnits.name description: Business Units for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.businessUnits.tenantId description: Tenant information for business Units that the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.commonName description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.domain description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.ip description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.lastObserved description: Additional details for the recent IPs that the domain resolved to. type: Date - contextPath: Expanse.Domain.details.recentIps.provider.id description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.provider.name description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.tenant.id description: Tenant information for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.tenant.name description: Tenant information for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.tenant.tenantId description: Tenant information for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.details.recentIps.type description: Additional details for the recent IPs that the domain resolved to. type: String - contextPath: Expanse.Domain.dnsResolutionStatus description: Latest DNS resolution status. type: String - contextPath: Expanse.Domain.firstObserved description: The date that the domain was first observed. type: Date - contextPath: Expanse.Domain.hasLinkedCloudResources description: Whether the domain has any linked cloud resources associated with it. type: Boolean - contextPath: Expanse.Domain.id description: Internal Xpanse ID for Domain. type: String - contextPath: Expanse.Domain.domain description: The domain value. type: String - contextPath: Expanse.Domain.isCollapsed description: Whether or not the subdomains of the domain are collapsed. type: Boolean - contextPath: Expanse.Domain.isPaidLevelDomain description: Whether or not the domain is a PLD. type: Boolean - contextPath: Expanse.Domain.lastObserved description: The date that the domain was most recently observed. type: Date - contextPath: Expanse.Domain.lastSampledIp description: The last observed IPv4 address for the domain. type: String - contextPath: Expanse.Domain.lastSubdomainMetadata.collapseType description: Sub-domain metadata. type: String - contextPath: Expanse.Domain.lastSubdomainMetadata.numSubdomains description: Sub-domain metadata. type: Number - contextPath: Expanse.Domain.lastSubdomainMetadata.numDistinctIps description: Sub-domain metadata. type: Number - contextPath: Expanse.Domain.lastSubdomainMetadata.date description: Sub-domain metadata. type: Date - contextPath: Expanse.Domain.providers.id description: Information about the hosting provider of the IP the domain resolves to. type: String - contextPath: Expanse.Domain.providers.name description: Information about the hosting provider of the IP the domain resolves to. type: String - contextPath: Expanse.Domain.serviceStatus description: Detected service statuses for the domain. type: String - contextPath: Expanse.Domain.sourceDomain description: The source domain for the domain object. type: String - contextPath: Expanse.Domain.tenant.id description: Tenant information for the domain. type: String - contextPath: Expanse.Domain.tenant.name description: Tenant information for the domain. type: String - contextPath: Expanse.Domain.tenant.tenantId description: Tenant information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.city description: The admin city in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.country description: The admin country in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.emailAddress description: The admin email address in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.faxExtension description: The admin fax extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.faxNumber description: The admin fax number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.name description: The admin name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.organization description: The admin organization in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.phoneExtension description: The admin phone extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.phoneNumber description: The admin phone number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.postalCode description: The admin postal code in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.province description: The admin province in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.registryId description: The admin registry ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.admin.street description: The admin street in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.creationDate description: The creation date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.whois.dnssec description: The dnssec in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.domain description: The domain in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.domainStatuses description: The domain statuses in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.nameServers description: The name servers in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.city description: The registrant city in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.country description: The registrant country in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.emailAddress description: The registrant email address in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.faxExtension description: The registrant fax extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.faxNumber description: The registrant fax number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.name description: The registrant name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.organization description: The registrant organization in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.phoneExtension description: The registrant phone extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.phoneNumber description: The registrant phone number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.postalCode description: The registrant postal code in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.province description: The registrant province in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.registryId description: The registrant registry ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrant.street description: The registrant street in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.abuseContactEmail description: The registrar abuse contact email in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.abuseContactPhone description: The registrar abuse contact phone in the Whois information for the domain''. type: String - contextPath: Expanse.Domain.whois.registrar.formattedName description: The registrar formatted name Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.ianaId description: The registrar iana ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.name description: The registrar name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.registrationExpirationDate description: The registrar registration expiration date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.whois.registrar.url description: The registrar URL in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registrar.whoisServer description: The registrar Whois server in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registryDomainId description: The registry domain ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.registryExpiryDate description: The registry expiry date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.whois.reseller description: The reseller in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.city description: The tech city in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.country description: The tech country in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.emailAddress description: The tech email address in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.faxExtension description: The tech fax extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.faxNumber description: The tech fax number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.name description: The tech name in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.organization description: The tech organization in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.phoneExtension description: The tech phone extension in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.phoneNumber description: The tech phone number in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.postalCode description: The tech postal code in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.province description: The tech province in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.registryId description: The tech registry ID in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.tech.street description: The tech street in the Whois information for the domain. type: String - contextPath: Expanse.Domain.whois.updatedDate description: The updated date in the Whois information for the domain. type: Date - contextPath: Expanse.Domain.details.cloudResources.id description: The cloud resource ID. type: String - contextPath: Expanse.Domain.details.cloudResources.tenant.id description: Tenant information for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.tenant.name description: Tenant information for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.tenant.tenantId description: Tenant information for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.businessUnits.id description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.businessUnits.name description: Business Units that the cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.businessUnits.tenantId description: Tenant information businessUnits that the cloud resource as been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.dateAdded description: The date that the cloud resource was added to the Expander instance. type: Date - contextPath: Expanse.Domain.details.cloudResources.firstObserved description: The date that the cloud resource was first observed. type: Date - contextPath: Expanse.Domain.details.cloudResources.lastObserved description: The date that the domain was most recently observed. type: Date - contextPath: Expanse.Domain.details.cloudResources.instanceId description: Instance ID for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.type description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.ips description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.domain description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.provider.id description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.provider.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.region description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.vpc.id description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.vpc.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.accountIntegration.id description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.accountIntegration.name description: Additional details for the cloud resource linked to the domain. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.assetKey description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.assetType description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.businessUnits.id description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.businessUnits.name description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.businessUnits.tenantId description: Business Units that the recent IPs linked to the linked cloud resource has been assigned to. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.commonName description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.domain description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.ip description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.lastObserved description: Additional details for the recent IPs linked to the linked cloud resource. type: Date - contextPath: Expanse.Domain.details.cloudResources.recentIps.provider.id description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.provider.name description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.tenant.id description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.tenant.name description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.tenant.tenantId description: Tenant information for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.recentIps.type description: Additional details for the recent IPs linked to the linked cloud resource. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.note description: Customer provided annotation details for a domain. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.contacts.id description: ID for customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.contacts.name description: Customer provided contact details for a domain. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.tags.id description: ID for customer added tag on a domain in Expander. type: String - contextPath: Expanse.Domain.details.cloudResources.annotations.tags.name description: Customer added tag on a domain in Expander. type: String - contextPath: Domain.Name description: 'The domain name, for example: "google.com".' type: String - contextPath: Domain.DNS description: A list of IP objects resolved by DNS. type: String - contextPath: Domain.DetectionEngines description: The total number of engines that checked the indicator. type: Number - contextPath: Domain.PositiveDetections description: The number of engines that positively detected the indicator as malicious. type: Number - contextPath: Domain.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.UpdatedDate description: The date that the domain was last updated. type: String - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.DomainStatus description: The status of the domain. type: Date - contextPath: Domain.NameServers description: Name servers of the domain. type: String - contextPath: Domain.Organization description: The organization of the domain. type: String - contextPath: Domain.Subdomains description: Subdomains of the domain. type: String - contextPath: Domain.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.Registrant.Country description: The country of the registrant. type: String - contextPath: Domain.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.WHOIS.DomainStatus description: The status of the domain. type: String - contextPath: Domain.WHOIS.NameServers description: Name servers of the domain. type: String - contextPath: Domain.WHOIS.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.WHOIS.UpdatedDate description: The date that the domain was last updated. type: Date - contextPath: Domain.WHOIS.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.WHOIS.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Phone description: The phone number of the registrant. type: String - contextPath: Domain.WHOIS.Registrar.Name description: 'The name of the registrar, for example: "GoDaddy".' type: String - contextPath: Domain.WHOIS.Registrar.AbuseEmail description: The email address of the contact for reporting abuse. type: String - contextPath: Domain.WHOIS.Registrar.AbusePhone description: The phone number of contact for reporting abuse. type: String - contextPath: Domain.WHOIS.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.WHOIS.History description: List of Whois objects. type: String - contextPath: Domain.Malicious.Vendor description: The vendor reporting the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: A description explaining why the domain was reported as malicious. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - arguments: - default: true description: The IP to enrich. isArray: true name: ip required: true description: Provides data enrichment for IPs. name: ip outputs: - contextPath: Expanse.IP.ip description: The IPv4 address of the asset. type: String - contextPath: Expanse.IP.assetKey description: Key used to access the asset in the respective Xpanse asset API. type: String - contextPath: Expanse.IP.assetType description: The type of asset. type: String - contextPath: Expanse.IP.businessUnits.id description: The internal Xpanse ID for the business unit the asset belongs to. type: String - contextPath: Expanse.IP.businessUnits.name description: The name of the business unit the asset belongs to. type: String - contextPath: Expanse.IP.businessUnits.tenantId description: The ID of the tenant that the asset belongs to. type: String - contextPath: Expanse.IP.commonName description: The certificate common name of the asset. type: String - contextPath: Expanse.IP.domain description: The domain name of the asset. type: String - contextPath: Expanse.IP.lastObserved description: The last observed IPv4 address of the asset. type: Date - contextPath: Expanse.IP.provider.id description: The ID of the provider the asset was detected on. type: String - contextPath: Expanse.IP.provider.name description: The name of the provider the asset was detected on. type: String - contextPath: Expanse.IP.tenant.id description: The internal Xpanse ID of the tenant that the asset belongs to. type: String - contextPath: Expanse.IP.tenant.name description: The name of the tenant that the asset belongs to. type: String - contextPath: Expanse.IP.tenant.tenantId description: The ID of the tenant that the asset belongs to. type: String - contextPath: Expanse.IP.type description: The type of asset that the IPv4 address relates to. type: String - contextPath: IP.Address description: IP address. type: String - contextPath: IP.ASN description: 'The autonomous system name for the IP address, for example: "AS8948".' type: String - contextPath: IP.Hostname description: The hostname that is mapped to this IP address. type: String - contextPath: IP.Geo.Location description: 'The geolocation where the IP address is located, in the format: latitude:longitude.' type: String - contextPath: IP.Geo.Country description: The country in which the IP address is located. type: String - contextPath: IP.Geo.Description description: Additional information about the location. type: String - contextPath: IP.DetectionEngines description: The total number of engines that checked the indicator. type: Number - contextPath: IP.PositiveDetections description: The number of engines that positively detected the indicator as malicious. type: Number - contextPath: IP.Malicious.Vendor description: The vendor reporting the IP address as malicious. type: String - contextPath: IP.Malicious.Description description: A description explaining why the IP address was reported as malicious. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - arguments: - default: true description: The CIDR block to enrich. isArray: true name: cidr - defaultValue: severityCounts,annotations,attributionReasons,relatedRegistrationInformation,locationInformation description: Include "none" or any of the following options (comma separated) - annotations, severityCounts, attributionReasons, relatedRegistrationInformation, locationInformation. name: include description: Provides data enrichment for CIDR blocks using Xpanse IP Range. name: cidr outputs: - contextPath: Expanse.IPRange.annotations.additionalNotes description: Customer provided annotation details for an IP range. type: String - contextPath: Expanse.IPRange.annotations.contacts description: Customer provided point-of-contact details for an IP range. type: String - contextPath: Expanse.IPRange.annotations.tags description: Customer provided tags for an IP range. type: String - contextPath: Expanse.IPRange.attributionReasons.reason description: The reasons why an IP range is attributed to the customer. type: String - contextPath: Expanse.IPRange.businessUnits.id description: Business Units that the IP range has been assigned to. type: String - contextPath: Expanse.IPRange.businessUnits.name description: Business Units that the IP range has been assigned to. type: String - contextPath: Expanse.IPRange.created description: The date that the IP range was added to the Expander instance. type: Date - contextPath: Expanse.IPRange.id description: Internal Xpanse ID for the IP Range. type: String - contextPath: Expanse.IPRange.ipVersion description: The IP version of the IP range. type: String - contextPath: Expanse.IPRange.locationInformation.geolocation.city description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.locationInformation.geolocation.countryCode description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.locationInformation.geolocation.latitude description: The IP range geolocation. type: Number - contextPath: Expanse.IPRange.locationInformation.geolocation.longitude description: The IP range geolocation. type: Number - contextPath: Expanse.IPRange.locationInformation.geolocation.regionCode description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.locationInformation.ip description: The IP range geolocation. type: String - contextPath: Expanse.IPRange.modified description: The date on which the IP range was last ingested into Expander. type: Date - contextPath: Expanse.IPRange.rangeIntroduced description: The date that the IP range was added to the Expander instance. type: Date - contextPath: Expanse.IPRange.rangeSize description: The number of IP addresses in the IP range. type: Number - contextPath: Expanse.IPRange.rangeType description: If the IP range is Xpanse-generated parent range or a customer-generated custom range. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.country description: The country within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.endAddress description: The end address within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.handle description: The handle within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.ipVersion description: The IP version within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.name description: The name within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.parentHandle description: The parent handle within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.address description: The address within the registry entities of the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.email description: The email within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.events.action description: The events action within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.events.actor description: The events actor within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.events.date description: The events date within the registry entities of the e IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.firstRegistered description: The first registered date within the registry entities of the e IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.formattedName description: The formatted name within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.handle description: The handle within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.id description: The ID within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.lastChanged description: The last changed date within the registry entities of the e IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.org description: The org within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.phone description: The phone number within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.relatedEntityHandles description: The related entity handles within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.remarks description: The remarks within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.roles description: The roles within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.registryEntities.statuses description: The statuses within the registry entities of the e IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.remarks description: The remarks within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.startAddress description: The start address within the IP range registration information. type: String - contextPath: Expanse.IPRange.relatedRegistrationInformation.updatedDate description: The last update date within the IP range registration information. type: Date - contextPath: Expanse.IPRange.relatedRegistrationInformation.whoisServer description: The Whois server within the IP range registration information. type: String - contextPath: Expanse.IPRange.responsiveIpCount description: The number of IPs responsive on the public Internet within the IP range. type: Number - contextPath: Expanse.IPRange.severityCounts.count description: The number of exposures observed on the IP range. type: Number - contextPath: Expanse.IPRange.severityCounts.type description: The severity level of the exposures observed on the IP range. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - arguments: - default: true description: The certificate common name. Fuzzy matching is done on this name, however query times can grow quite large when searching for short strings. Ex. "*.myhost.com" is a better search term than "host". name: common_name required: true description: Returns all domains which have been seen with the specified certificate. name: expanse-get-domains-for-certificate outputs: - contextPath: Expanse.IPDomains.SearchTerm description: The common name that was searched. type: String - contextPath: Expanse.IPDomains.TotalDomainCount description: The number of domains found matching the specified certificate. type: Number - contextPath: Expanse.IPDomains.FlatDomainList description: An array of all domain names found. This is truncated at 50. type: Unknown - contextPath: Expanse.IPDomains.DomainList description: An array of domain objects. This is truncated at 50. type: Unknown dockerimage: demisto/python3:3.12.8.1983910 isfetch: true runonce: false script: '-' subtype: python3 type: python isremotesyncin: true isremotesyncout: true tests: - ExpanseV2 Test defaultmapperin: ExpanseV2-mapper defaultclassifier: ExpanseV2 fromversion: 6.0.0