Publisher: Hyas
Connector Version: 1.2.0
Product Vendor: Hyas
Product Name: Hyas Insight
Product Version Supported (regex): ".*"
Minimum Product Version: 5.3.4
This app implements investigative actions that return Hyas Insight Records for the given Indicators
The below configuration variables are required for this Connector to operate. These variables are specified when configuring a Hyas Insight asset in SOAR.
VARIABLE | REQUIRED | TYPE | DESCRIPTION |
---|---|---|---|
apikey | required | password | API KEY |
test connectivity - Validate the asset configuration for connectivity using supplied configuration
lookup commandcontrol domain - Perform this action to get the C2 Domain Lookup Data for Hyas Insight
lookup commandcontrol email - Perform this action to get the C2 Email address Lookup Data for Hyas Insight
lookup commandcontrol ip - Perform this action to get the C2 IP Lookup Data for Hyas Insight
lookup commandcontrol hash - Perform this action to get the C2 Hash Lookup Data for Hyas Insight
lookup whois domain - Perform this action to get the Whois Domain Lookup Data for Hyas Insight
lookup whois email - Perform this action to get the Whois Email address Lookup Data for Hyas Insight
lookup whois phone - Perform this action to get the Whois Phone number Lookup Data for Hyas Insight
lookup dynamicdns email - Perform this action to get the Dynamicdns Email address Lookup Data for Hyas Insight
lookup dynamicdns ip - Perform this action to get the Dynamicdns IP address Lookup Data for Hyas Insight
lookup dynamicdns domain - Perform this action to get the Dynamicdns Domain Lookup Data for Hyas Insight
lookup sinkhole ip - Perform this action to get the Sinkhole IP address Lookup Data for Hyas Insight
lookup passivehash ip - Perform this action to get the Passivehash IP address Lookup Data for Hyas Insight
lookup passivehash domain - Perform this action to get the Passivehash Domain Lookup Data for Hyas Insight
lookup ssl certificate ip - Perform this action to get the SSL Certificate Lookup Data for Hyas Insight
lookup passivedns domain - Perform this action to get the Passivedns Domain Lookup Data for Hyas Insight
lookup current whois domain - Perform this action to get the Whois current Domain Lookup Data for Hyas Insight
lookup passivedns ip - Perform this action to get the Passivedns IP address Lookup Data for Hyas Insight
lookup malware information hash - Perform this action to get the Malware Information Lookup Data for Hyas Insight
lookup malware record hash - Perform this action to get the Malware Record hash Lookup Data for Hyas Insight
lookup malware record ip - Perform this action to get the Malware Record IP address Lookup Data for Hyas Insight
lookup malware record domain - Perform this action to get the Malware Record Domain Lookup Data for Hyas Insight
lookup os indicator hash - Perform this action to get the OS Indicator Lookup Data for Hyas Insight
lookup ssl certificate hash - Perform this action to get the SSL Certificate hash Lookup Data for Hyas Insight
lookup ssl certificate domain - Perform this action to get the SSL Certificate Domain Lookup Data for Hyas Insight
lookup devicegeo ip - Perform this action to get the Mobile Geolocation Information IP address Lookup Data for Hyas Insight
lookup os indicator domain - Perform this action to get the OS Indicator Domain Lookup Data for Hyas Insight
lookup os indicator ip - Perform this action to get the OS Indicator Lookup Data for IP address Hyas Insight
Validate the asset configuration for connectivity using supplied configuration
Type: test
Read only: True
No parameters are required for this action
No Output
Perform this action to get the C2 Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the C2 Email address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
required | Email address to get Lookup Data for Hyas Insight | string | email |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.email | string | email |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the C2 IP Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ip | required | IP address to get Lookup Data for Hyas Insight | string | ip ipv4 ipv6 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ip | string | ip ipv4 ipv6 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the C2 Hash Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
hash | required | Hash to get Lookup Data for Hyas Insight | string | sha256 hash |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.hash | string | sha256 hash |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Whois Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Whois Email address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
required | Email address to get Lookup Data for Hyas Insight | string | email |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.email | string | email |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Whois Phone number Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
phone | required | Phone number to get Lookup Data for Hyas Insight | string | phone phone number |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.phone | string | number |
action_result.parameter.phone | string | phone phone number |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Dynamicdns Email address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
required | Email address to get Lookup Data for Hyas Insight | string | email |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.email | string | email |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Dynamicdns IP address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ip | required | IP address to get Lookup Data for Hyas Insight | string | ip ipv6 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ip | string | ip ipv6 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Dynamicdns Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Sinkhole IP address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ipv4 | required | IP address to get Lookup Data for Hyas Insight | string | ip |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ipv4 | string | ip |
action_result.parameter.ipv4 | string | ip |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Passivehash IP address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ipv4 | required | IP address to get Lookup Data for Hyas Insight | string | ip |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ipv4 | string | ip |
action_result.parameter.ipv4 | string | ip |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Passivehash Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the SSL Certificate Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ip | required | IP address to get Lookup Data for Hyas Insight | string | ip ipv6 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ip | string | ip ipv6 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Passivedns Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Whois current Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Passivedns IP address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ipv4 | required | IP address to get Lookup Data for Hyas Insight | string | ip ipv6 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ipv4 | string | ip |
action_result.parameter.ipv4 | string | ip ipv6 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Malware Information Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
hash | required | Hash to get lookup data for Hyas Insight | string | md5 hash |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.hash | string | md5 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Malware Record hash Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
hash | required | Hash to get the lookup data for Hyas Insight | string | hash md5 sha256 sha1 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.hash | string | hash md5 sha256 sha1 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Malware Record IP address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ipv4 | required | IP address to get the lookup data for Hyas Insight | string | ip ipv4 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.parameter.ipv4 | string | ip ipv4 |
action_result.status | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Malware Record Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get the lookup data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the OS Indicator Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
hash | required | Hash to get lookup data for Hyas Insight | string | hash md5 sha1 sha256 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.hash | string | hash md5 sha1 sha256 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the SSL Certificate hash Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
hash | required | Hash to get lookup data for Hyas Insight | string | md5 hash sha1 sha256 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.hash | string | ip |
action_result.parameter.hash | string | md5 hash sha1 sha256 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the SSL Certificate Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get Lookup Data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the Mobile Geolocation Information IP address Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ip | required | IP address to get the lookup data for Hyas Insight | string | ip ipv4 ipv6 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.ip | string | ip ipv4 ipv6 |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the OS Indicator Domain Lookup Data for Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
domain | required | Domain to get lookup data for Hyas Insight | string | domain |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.status | string | |
action_result.parameter.domain | string | domain |
action_result.data | string | |
action_result.summary | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |
Perform this action to get the OS Indicator Lookup Data for IP address Hyas Insight
Type: investigate
Read only: True
PARAMETER | REQUIRED | DESCRIPTION | TYPE | CONTAINS |
---|---|---|---|---|
ip | required | IP address to get the lookup data for Hyas Insight | string | ip ipv4 ipv6 |
DATA PATH | TYPE | CONTAINS |
---|---|---|
action_result.parameter.ip | string | ip ipv4 ipv6 |
action_result.status | string | |
action_result.message | string | |
summary.total_objects | numeric | |
summary.total_objects_successful | numeric |