CybelAngel
CybelAngel is a digital risk protection platform that detects and manages data leaks and cyber threats.
CybelAngel is a leading digital risk protection platform that helps organizations detect and manage digital threats. The CybelAngel connector for Swimlane Turbine enables seamless integration to automate the retrieval of incident reports and update their statuses, enhancing incident management workflows. By leveraging this integration, Swimlane Turbine users can efficiently manage digital risks, streamline incident response processes, and ensure timely updates to incident statuses, all without writing a single line of code.
Prerequisites
Before you can use the CybelAngel connector for Turbine, you'll need access to the CybelAngel API. This requires the following:
- an HTTP Bearer token authentication using the following parameters:
- URL: The endpoint URL for accessing CybelAngel's API.
- Token: A valid bearer token for authenticating API requests.
- and OAuth2 authorization using the following parameters:
- URL: The endpoint URL for accessing CybelAngel's OAuth2 service.
- Client ID: The client identifier issued during application registration.
- Client Secret: The secret key associated with the client ID.
- Token URL: The URL used to obtain the OAuth2 access token.
- Audience: The intended audience for the OAuth2 token.
Asset Configuration
The CybelAngel connector requires an HTTP bearer token.
API docs
Additional Documentation
Configurations
HTTP Bearer Authentication
Authenticates using bearer token.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The API token | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | ο»Ώ | string | Required |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
audience | The audience for the token request. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Get Token
Retrieve a CybelAngel OAuth2 access token and its expiry time, serving as the initial step in workflows requiring authentication.
Output
Parameter | Type | Description |
|---|---|---|
access_token | string | The OAuth2 bearer token to pass to subsequent actions. |
expires_at | string | ISO 8601 timestamp indicating when the token expires (~1 hour from creation). Pass this alongside access_token to each action. |
Output Example
{"access_token":"string","expires_at":"string"}
Retrieve last incident reports
Fetches the latest incident reports from CybelAngel within a specified date range, requiring 'start-date' and 'end-date' parameters.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
access_token | string | Optional | Optional. A pre-fetched OAuth2 bearer token from the Get Token action. If provided and not expired, it will be reused instead of fetching a new token. |
expires_at | string | Optional | Optional. The expiry timestamp of the access_token (ISO 8601). Required when access_token is provided. |
parameters.start-date | string | Required | Parameters for the Retrieve last incident reports action |
parameters.end-date | string | Required | Parameters for the Retrieve last incident reports action |
Input Example
{"parameters":{"start-date":"2021-10-22T02:46:14.195826","end-date":"2021-10-22T03:30:14.195826"}}
Output
Parameter | Type | Description |
|---|---|---|
id | string | Unique identifier |
report_content | string | Response content |
url | string | URL endpoint for the request |
abstract | string | Output field: abstract |
category | string | Output field: category |
created_at | string | Output field: created_at |
detected_at | string | Output field: detected_at |
updated_at | string | Output field: updated_at |
incident_id | string | Unique identifier |
incident_type | string | Unique identifier |
investigation_id | string | Unique identifier |
ip | string | Output field: ip |
keywords | array | Output field: keywords |
keywords.name | string | Name of the resource |
attachments | array | Output field: attachments |
attachments.file_name | string | Name of the resource |
attachments.file | string | Output field: attachments.file |
liveness | object | Output field: liveness |
liveness.online | boolean | Output field: liveness.online |
liveness.last_checked_at | string | Output field: liveness.last_checked_at |
origins | array | Output field: origins |
origins.type | string | Type of the resource |
origins.value | string | Value for the parameter |
port | object | Output field: port |
registrant_email | string | Output field: registrant_email |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"31b023bc-a213-4ede-9cee-c8896381840f","report_content":"### \n CVE\n\n\n### \n 3/4 Major\n\n\n#### \n Incident report - T8XR4H\n\n\n#### 2021/09/22\n...","url":"https://platform.cybelangel.com/#/reports/31b023bc-a213-4ede-9cee-c8896381840f","abstract":"Our service detected an open web server with a banner matching one of your keywo...","category":"","created_at":"2021-09-22T02:46:14.195826","detected_at":"2021-09-22T02:50:...
Update Report Status
Update a specific incident report's status in CybelAngel using the provided report ID and status value.
Endpoint
- URL: api/v1/reports/{{report_id}}/status
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
access_token | string | Optional | Optional. A pre-fetched OAuth2 bearer token from the Get Token action. If provided and not expired, it will be reused instead of fetching a new token. |
expires_at | string | Optional | Optional. The expiry timestamp of the access_token (ISO 8601). Required when access_token is provided. |
path_parameters.report_id | string | Required | The unique identifier of the report to update |
status | string | Optional | The new status for the report |
Input Example
{"json_body":{"status":"in_progress"},"path_parameters":{"report_id":"31b023bc-a213-4ede-9cee-c8896381840f"}}
Output
Parameter | Type | Description |
|---|---|---|
result | string | Result of the operation |
id | string | Unique identifier |
status | string | Status value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"result":"updated","id":"670e7227-74c9-4579-b6e3-f91ad0169a08","status":"draft"}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |