Skip to content

hyasinfosec/splunk-soar-hyasprotect

 
 

Repository files navigation

Hyas Protect

Publisher: Hyas
Connector Version: 1.1.0
Product Vendor: Hyas
Product Name: Hyas Protect
Product Version Supported (regex): ".*"
Minimum Product Version: 5.2.0

This app implements investigative actions that return Hyas Protect Verdict for the given Indicators

Port Details

The app uses HTTP/ HTTPS protocol for communicating with the Hyas Protect server. Below are the default ports used by the Splunk SOAR Connector.

Service Name Transport Protocol Port
http tcp 80
https tcp 443

Configuration Variables

The below configuration variables are required for this Connector to operate. These variables are specified when configuring a Hyas Protect asset in SOAR.

VARIABLE REQUIRED TYPE DESCRIPTION
apikey required password API KEY

Supported Actions

test connectivity - Validate the asset configuration for connectivity using supplied configuration
ip verdict - Perform this action to get the Hyas Verdict for IP
domain verdict - Perform this action to get the Hyas Verdict for Domain
fqdn verdict - Perform this action to get the Hyas Verdict for FQDN
nameserver verdict - Perform this action to get the Hyas Verdict for Nameserver

action: 'test connectivity'

Validate the asset configuration for connectivity using supplied configuration

Type: test
Read only: True

Action Parameters

No parameters are required for this action

Action Output

No Output

action: 'ip verdict'

Perform this action to get the Hyas Verdict for IP

Type: investigate
Read only: True

Action Parameters

PARAMETER REQUIRED DESCRIPTION TYPE CONTAINS
ip required IP to get Hyas Verdict string ip ipv6

Action Output

DATA PATH TYPE CONTAINS
action_result.parameter.ip string ip ipv6
action_result.*.Verdict string
action_result.*.Reasons string
action_result.status string
action_result.message string
summary.total_objects numeric
summary.total_objects_successful numeric

action: 'domain verdict'

Perform this action to get the Hyas Verdict for Domain

Type: investigate
Read only: True

Action Parameters

PARAMETER REQUIRED DESCRIPTION TYPE CONTAINS
domain required Domain to get Hyas Verdict string domain

Action Output

DATA PATH TYPE CONTAINS
action_result.parameter.domain string domain
action_result.*.Verdict string
action_result.*.Reasons string
action_result.status string
action_result.message string
summary.total_objects numeric
summary.total_objects_successful numeric

action: 'fqdn verdict'

Perform this action to get the Hyas Verdict for FQDN

Type: investigate
Read only: True

Action Parameters

PARAMETER REQUIRED DESCRIPTION TYPE CONTAINS
fqdn required FQDN to get Hyas Verdict string

Action Output

DATA PATH TYPE CONTAINS
action_result.parameter.fqdn string
action_result.*.Verdict string
action_result.*.Reasons string
action_result.status string
action_result.message string
summary.total_objects numeric
summary.total_objects_successful numeric

action: 'nameserver verdict'

Perform this action to get the Hyas Verdict for Nameserver

Type: investigate
Read only: True

Action Parameters

PARAMETER REQUIRED DESCRIPTION TYPE CONTAINS
nameserver required Nameserver to get Hyas Verdict string domain

Action Output

DATA PATH TYPE CONTAINS
action_result.parameter.nameserver string domain
action_result.*.Verdict string
action_result.*.Reasons string
action_result.status string
action_result.message string
summary.total_objects numeric
summary.total_objects_successful numeric

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • Python 77.5%
  • HTML 22.5%