We’ve added the following new integrations, steps, and improvements:
Abnormal Security
Carbon Black
Datadog
Elastic Security
Entro Security
Exabeam
Extraction Utils
GitHub
Mensatek
Microsoft Azure AD
Microsoft Intune
Microsoft Outlook
misp
Moveworks
NVIDIA AI Enterprise
Palo Alto Networks Cortex XDR
Panorays
Silent Push
Slack Custom App
Stellar Cyber
sysdig
ThreatFox
Trend Micro
Zendesk
Abnormal Security
A new step was added to the Abnormal Security integration:
Get Case Analysis: Provides the analysis and timeline details of a case.
Carbon Black
A new step was added to the Carbon Black integration:
Update Alerts v7: Update all alerts that match the search criteria of the request. Use the Job Details step to check the progress of the update.
Datadog
Several new steps were added to the Datadog integration:
Update Security Signal State: Change the triage state of a security signal.
List Security Signals: Returns security signals that match a search query.
Elastic Security
A new step was added to the Elastic Security integration:
Get Authorization Details: Retrieve information about the authenticated user.
Entro Security
A new Entro Security steps integration is now available on the Integrations page.
The following steps are available:
Add Comment To Risk: Add a new comment to a risk.
List Risks: Lists risks with ability to filter.
Get All Comments From Risk: Retrieves all the comments anyone left on a specific risk.
Get Risk Status: Retrieves the risk status.
Get Risk Change Log: Retireves all the changes the risk went through.
Get Risk Details: Returns the risk information by risk ID.
Get Secrets Available Types: Retrieves all the available secret types the user has.
Get Risk Owner: Getting the owner of the Risk.
Update Risk Owner: Updates the owner of the risk.
Get Risk Available Types: Retrieves all the available risk types the user has.
Get Risk Available Sources: Retrieves all the available sources the user has.
Exabeam
A new step was added to the Exabeam integration:
Search Events: Quickly perform search queries across multiple years-worth of logs and events.
Extraction Utils
The Extract domain from email step has a new optional parameter:
File or string: The email address we're extracting the domain from.
GitHub
A new step was added to the GitHub integration:
Run GraphQL query: Run a GitHub GraphQL query.
Mensatek
A new Mensatek steps integration is now available on the Integrations page.
The following steps are available:
Send SMS: Send an SMS using Mensatek service.
Get Credits: Returns the number of remaining credits in a Mensatek Account.
Get SMS Delivery Report: Returns the delivery report for a given SMS Message ID.
Microsoft Azure AD
The Get User by ID step has several new optional parameters:
User properties: List of non-default user properties to be returned (OData query).
Timeout: Timeout for request in seconds. By default, timeout is 30 seconds.
Max retries: The maximum number of times a step will be retried. By default (-1), the step will keep retrying for up to 50 seconds.
Retry delay: Initial delay before retry attempts in seconds, exponential backoff calculation will be applied over this value.
Microsoft Intune
Several new steps were added to the Microsoft Intune integration:
Remote Lock Device: The Remote lock device action locks the device. To unlock the device, the device owner enters their passcode.
Reboot Device: The Restart device action causes the device you choose to be restarted (within 5 minutes). The device owner isn't automatically notified of the restart, and they might lose work.
Microsoft Outlook
A new step was added to the Microsoft Outlook integration:
Outlook Next Page URL: Used for pagination of all Outlook steps to return next page from multiple steps based on the @odata.nextLink header.
The Get Message step has several new optional parameters:
PAGE_SIZE: Number of records to return per page.
SKIP: Number of records to skip (used in conjunction with
PAGE_SIZE
).
misp
Several new steps were added to the misp integration:
Search Attributes: Get a filtered and paginated list of attributes.
Get Event by ID: Retrieves event information.
List Events: List MISP Events.
List Attributes: Get a list of attributes.
Moveworks
A new step was added to the Moveworks integration:
Send Message New-Custom: Sends the provided message to the specified list of recipients via the Moveworks Bot.
NVIDIA AI Enterprise
A new NVIDIA AI Enterprise steps integration is now available on the Integrations page.
The following steps are available:
Create Chat Completion: Creates a completion for the provided chat and parameters.
Create Prompt Completion: Creates a completion for the provided prompt and parameters.
Palo Alto Networks Cortex XDR
A new step was added to the Palo Alto Networks Cortex XDR integration:
Update Incident: Update XDR Incident.
Panorays
A new Panorays steps integration is now available on the Integrations page.
The following steps are available:
Get Company Posture: Get data about the posture in the portfolio.
Get Company Findings: Get list of the data and information about findings in the portfolio.
List Company Assets: Get list of company assets based on a defined filter.
Get Supplier Posture: Get data about the requested supplier's posture in the portfolio.
List Suppliers: Get list of suppliers based on a defined filter.
Add Supplier: Add a new supplier to the portfolio.
Silent Push
A new step was added to the Silent Push integration:
Live Endpoint Scan: Initiate a live on-demand scan of a URL.
Slack Custom App
A new step was added to the Slack Custom App integration:
Get File Info: Gets information about a file.
Stellar Cyber
Several new steps were added to the Stellar Cyber integration:
List Sensors: Query the DP for a detailed list of its managed sensors, including Data Sensors, Security Data Sensors, Modular Data Sensors, and Server Sensors (agents).
List Case Alerts: List all alerts associated with a case.
List Case Scores: Retrieve the case score activities.
sysdig
A new sysdig steps integration is now available on the Integrations page.
The following steps are available:
Search for Inventory Resources: Search for Inventory Resources based on the given filter.
Get Users: Fetches the list of users. Use additional filters as required.
ThreatFox
A new step was added to the ThreatFox integration:
Get tag list: Returns a list of tags known to ThreatFox.
The Query Recent IOCs step has a new optional parameter:
Number of days: Number of days to filter IOCs for (based on first_seen) Min: 1, Max: 7. Default: 3
Trend Micro
Several new steps were added to the Trend Micro integration:
List Alerts: Displays information about workbench alerts that match the specified criteria.
Get Alert Details: Displays information about the specified alert.
Zendesk
Several new steps were added to the Zendesk integration:
List Ticket Fields: Returns a list of all system and custom ticket fields in your account.
List SLA Policies: Lists SLA policies.
List Ticket Metrics: Returns a list of tickets with their metrics.
The Update Ticket step has several new optional parameters:
Is public comment: Is true if any comments are public, false otherwise.
File upload tokens: Upload File Tokens from Upload File step to add to the ticket.
Custom fields array: Custom Fields JSON array.