commonfields: id: RedCanary version: -1 name: RedCanary display: Red Canary category: Deception & Breach Simulation provider: Zscaler sectionorder: - Connect - Collect description: Red Canary collects endpoint data using Carbon Black Response and CrowdStrike Falcon. The collected data is standardized into a common schema which allows teams to detect, analyze and respond to security incidents. configuration: - display: Domain (for example, https://demisto.my.redcanary.co) name: domain defaultvalue: "" type: 0 required: true section: Connect - display: API Key name: api_key defaultvalue: "" type: 4 hidden: true required: false section: Connect - name: api_key_creds type: 9 displaypassword: API Key hiddenusername: true required: false section: Connect - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - display: Fetch acknowledged incidents additionalinfo: "By default, only unacknowledged incidents are fetched. Set to true to fetch all incidents." name: isFetchAcknowledged type: 8 required: false defaultvalue: 'false' section: Collect - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - display: First fetch timestamp (