AI SOC Interfaces
This document lists the interface contracts available in the AI SOC Solution. For general information about what interfaces are and how to use them, see Working with InterfacesWorking with Interfaces. For complete data model field definitions, see Turbine Schema Reference (AI SOC)Turbine Schema Reference (AI SOC).
AI SOC Interfaces
The AI SOC Solution provides the following interfaces for building components and playbooks. These interfaces use the extended Turbine Schema fields defined in Turbine Schema Reference (AI SOC)Turbine Schema Reference (AI SOC).
Alert to Alert
Purpose: Converts alert objects while preserving all alert data. Use this interface for alert normalization, enrichment, and transformation workflows.
Input schema: Full Alert object (see Turbine Schema Reference (AI SOC)Turbine Schema Reference (AI SOC))
Output schema: Full Alert object (same structure as input)
Use cases:
- Alert data normalization and transformation
- Alert enrichment pipelines
- Cross-platform alert data exchange
Alert Triage Ingestion to Array of Alert
Purpose: Ingests alerts from alerting tools (SIEM, EDR, AV) using time-based search parameters and returns an array of standardized alert objects.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
organization | String | Optional | The organization impacted by the alerts |
start_time | String | Optional | How far back to search for alerts (for example, "4 hours ago," "-30 minutes") |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
alerts | Array of Alert objects | No | Array of standardized Alert objects |
Use cases:
- Scheduled alert ingestion from SIEM or XDR systems
- Time-based alert polling
Alert Search Params to Array of Alerts
Purpose: Searches for alerts using configurable parameters and returns an array of extended Turbine Schema alert objects with support for provider-specific fields.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
alert_search_parameters | Object | No | Search parameters object (structure varies by provider) |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
extended_teds_alerts | Array | No | Array of extended alert objects |
extended_teds_alerts[].teds_alert | Object | No | Full Alert object |
extended_teds_alerts[].extended_fields | Object | No | Additional provider-specific fields not covered by Turbine Schema |
Use cases:
- Search-based alert ingestion from SIEM or XDR systems
- Pulling alerts matching specific criteria (time range, severity, and similar filters)
- Ingestion pipelines that need both standardized and provider-specific data
Email Search Params to Array of Emails
Purpose: Searches for emails using configurable parameters and returns an array of extended Turbine Schema email objects with optional phishing report data.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
email_search_parameters | Object | No | Search parameters object |
email_search_parameters.filter | String | No | Filter expression for email search |
email_search_parameters.max_emails_to_return | String | No | Maximum number of emails to return |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
extended_teds_emails | Array | No | Array of extended email objects |
extended_teds_emails[].teds_email | Object | No | Full Email object (including report_description and reporter for phishing reports) |
extended_teds_emails[].teds_email.report_description | String | No | Description of the reported phishing incident |
extended_teds_emails[].teds_email.reporter | Object | No | User who submitted the phishing report |
extended_teds_emails[].teds_email.reporter.user_email_address | String | No | Reporter email address |
extended_teds_emails[].teds_email.reporter.user_id | String | No | Reporter user ID |
extended_teds_emails[].teds_email.reporter.user_name | String | No | Reporter username |
extended_teds_emails[].extended_fields | Object | No | Additional provider-specific fields not covered by Turbine Schema |
Use cases:
- Search-based phishing email ingestion
- Pulling emails matching specific criteria from email security platforms
- Phishing triage workflows that need both Turbine Schema-standardized and provider-specific data