Cyborg Security
Cyborg Security is a cybersecurity platform that enhances threat detection and response through advanced threat hunting and intelligence capabilities.
Cyborg Security offers advanced threat hunting capabilities, enabling organizations to proactively identify and mitigate potential threats. By integrating with Swimlane Turbine, users can automate the creation and management of hunt packages and templates, streamline threat intelligence retrieval, and enhance security analysis with real-time data. This integration empowers security teams to efficiently manage threat data, automate responses, and improve overall security posture without the need for extensive coding.
This Connector integrates Cyborg Security's Rest API with Swimlane Turbine.
Asset Setup or Prerequisites
Before you can use the Cyborg Security connector for Turbine, you'll need access to the Cyborg Security API. This requires the following:
- an API key authentication using the following parameters:
- URL: The endpoint URL for accessing Cyborg Security's API.
- API Key: A unique key provided by Cyborg Security for API access.
- HTTP Basic authentication using the following parameters:
- URL: The endpoint URL for accessing Cyborg Security's API.
- Username: Your Cyborg Security account username.
- Password: Your Cyborg Security account password.
Capabilities
This Connector provides the following capabilities:
- Add Hunt Package by Template ID
- Create Hunt Template
- Get ES Query Search
- Get Search Recent Updates
- Get Threat Actors
- Get Threat Reports
Notes
- For more information on Cyborg Security is found at: Cyborg Security API Documentation
Additional Documentation
Configurations
Cyborg Security API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
Authorization | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Cyborg Security HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Hunter Account Username | string | Required |
password | Hunter Account Password | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add Hunt Package by Template ID
Add a hunt package in Cyborg Security using a template ID. Requires path parameter 'id' and JSON body with 'huntPackageUUID', 'tool', 'category', and 'content'.
Endpoint
- URL: /v2/hunt-template/{{id}}/add-hunt-packages
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Hunt template ID. |
huntPackageUUID | string | Optional | Unique identifier |
tool | string | Optional | Parameter for Add Hunt Package by Template ID |
category | string | Optional | Parameter for Add Hunt Package by Template ID |
content | object | Optional | Response content |
content.query | string | Required | Response content |
content.category | string | Required | Response content |
content.notes | string | Required | Response content |
Input Example
{"json_body":{"huntPackageUUID":"","tool":"","category":"","content":{"query":"","category":"","notes":""}},"path_parameters":{"id":"581"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
name | string | Name of the resource |
id | string | Unique identifier |
huntPackagesAdded | number | Output field: huntPackagesAdded |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Mon, 19 Feb 2023 20:37:23 GMT"},"reason":"OK","json_body":{"name":"string","id":"string","huntPackagesAdded":0}}
Create Hunt Template
Create a hunt template in Cyborg Security using parameters like name, hypothesis, description, priority, default assignee, and hunt packages.
Endpoint
- URL: /v2/hunt-template
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
name | string | Optional | Name of the resource |
hypothesis | string | Optional | Parameter for Create Hunt Template |
description | string | Optional | Parameter for Create Hunt Template |
priority | string | Optional | Parameter for Create Hunt Template |
defaultAssignee | object | Optional | Parameter for Create Hunt Template |
defaultAssignee.id | string | Required | Unique identifier |
defaultAssignee.firstName | string | Required | Name of the resource |
defaultAssignee.lastName | string | Required | Name of the resource |
defaultAssignee.email | string | Required | Parameter for Create Hunt Template |
defaultAssignee.role | string | Required | Parameter for Create Hunt Template |
defaultAssignee.isFirstLogin | boolean | Required | Parameter for Create Hunt Template |
defaultAssignee.resetPasswordToken | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.resetPasswordTokenExpire | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.createdAt | string | Required | Parameter for Create Hunt Template |
defaultAssignee.company | object | Required | Parameter for Create Hunt Template |
defaultAssignee.company.name | string | Optional | Name of the resource |
defaultAssignee.company.industry | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.company.city | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.company.state | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.company.country | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.company.expires | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.company.memberSince | string | Optional | Parameter for Create Hunt Template |
defaultAssignee.company.status | object | Optional | Status value |
huntPackages | array | Optional | Parameter for Create Hunt Template |
Input Example
{"json_body":{"name":"","hypothesis":"","description":"","priority":"Low","defaultAssignee":{"id":"","firstName":"","lastName":"","email":"","role":"administrator","isFirstLogin":true,"resetPasswordToken":"","resetPasswordTokenExpire":"2024-03-11T10:39:29.714Z","createdAt":"2024-03-11T10:39:29.714Z","company":{"name":"","industry":"","city":"","state":"","country":"","expires":"2024-03-11T10:39:29.714Z","memberSince":"2024-03-11T10:39:29.714Z","status":{}}},"huntPackages":[null]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":201,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Mon, 19 Feb 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Get ES Query Search
Search and fetch data in Cyborg Security using input query parameters.
Endpoint
- URL: /es/query
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.term | array | Optional | Parameters for the Get ES Query Search action |
parameters.indexes | array | Optional | Parameters for the Get ES Query Search action |
parameters.tools | array | Optional | Parameters for the Get ES Query Search action |
parameters.platform_types | array | Optional | Parameters for the Get ES Query Search action |
parameters.goals | array | Optional | Parameters for the Get ES Query Search action |
parameters.dependencies | array | Optional | Parameters for the Get ES Query Search action |
parameters.threat_names | array | Optional | Parameters for the Get ES Query Search action |
parameters.threat_categories | array | Optional | Parameters for the Get ES Query Search action |
parameters.threat_types | array | Optional | Parameters for the Get ES Query Search action |
parameters.attack_surfaces | array | Optional | Parameters for the Get ES Query Search action |
parameters.target_oses | array | Optional | Parameters for the Get ES Query Search action |
parameters.actors | array | Optional | Parameters for the Get ES Query Search action |
parameters.tooling | array | Optional | Parameters for the Get ES Query Search action |
parameters.diamond_models | array | Optional | Parameters for the Get ES Query Search action |
parameters.kill_chains | array | Optional | Parameters for the Get ES Query Search action |
parameters.mitre_technique_names | array | Optional | Parameters for the Get ES Query Search action |
parameters.mitre_tactic_names | array | Optional | Parameters for the Get ES Query Search action |
parameters.mitre_technique_ids | array | Optional | Parameters for the Get ES Query Search action |
parameters.source_countries | array | Optional | Parameters for the Get ES Query Search action |
parameters.source_regions | array | Optional | Parameters for the Get ES Query Search action |
parameters.target_countries | array | Optional | Parameters for the Get ES Query Search action |
parameters.target_regions | array | Optional | Parameters for the Get ES Query Search action |
parameters.target_industries | array | Optional | Parameters for the Get ES Query Search action |
parameters.exploit_or_vulns | array | Optional | Parameters for the Get ES Query Search action |
parameters.motivations | array | Optional | Parameters for the Get ES Query Search action |
Input Example
{"parameters":{"term":[""],"indexes":["cyborg_content"],"tools":[""],"platform_types":[""],"goals":[""],"dependencies":[""],"threat_names":[""],"threat_categories":[""],"threat_types":[""],"attack_surfaces":[""],"target_oses":[""],"actors":[""],"tooling":[""],"diamond_models":[""],"kill_chains":[""],"mitre_technique_names":[""],"mitre_tactic_names":[""],"mitre_technique_ids":[""],"source_countries":[""],"source_regions":[""],"target_countries":[""],"target_regions":[""],"target_industries":[""],"exploit_or_vulns":[""],"motivations":[""],"severities":[""],"campaigns":[""],"days":1,"sort":"type_asc","size":2,"page":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
total | number | Output field: total |
results | object | Result of the operation |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Mon, 19 Feb 2023 20:37:23 GMT"},"reason":"OK","json_body":{"total":0,"results":{}}}
Get Search Recent Updates
Retrieve the most recent updates from Cyborg Security's search functionality.
Endpoint
- URL: /es/recent-updates
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.days | number | Optional | Days for getting updated cyborg items. |
parameters.size | number | Optional | Size of recent updated cyborg items. |
parameters.index | string | Optional | Cyborg index |
Input Example
{"parameters":{"days":10,"size":100,"index":"cyborg_collections"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 12 Mar 2024 09:35:32 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Access-Control-Allow-Origin":"*","X-DNS-Prefetch-Control":"off","X-Frame-Options":"SAMEORIGIN","Strict-Transport-Security":"max-age=15724800; includeSubDomains","X-Download-Options":"noopen","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","ETag":"W/\"15c8-ko2VhcZVs9W0gSpEy054DW6pZKg\"","Vary":...
Get Threat Actors
Get a list of threat actors from Cyborg Security to enhance your security analysis and response strategies.
Endpoint
- URL: /es/cyborg-collection/emergingThreats
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 12 Mar 2024 09:20:49 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Access-Control-Allow-Origin":"*","X-DNS-Prefetch-Control":"off","X-Frame-Options":"SAMEORIGIN","Strict-Transport-Security":"max-age=15724800; includeSubDomains","X-Download-Options":"noopen","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","ETag":"W/\"112f1-WVvNA/bu+lbMB+e0wKIPJmZLgYw\"","Vary"...
Get Threat Reports
Get threat reports from Cyborg Security using specified UUIDs to enhance your security insights.
Endpoint
- URL: /es/cyborg-threat-profile/list
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.uuids | array | Required | Parameters for the Get Threat Reports action |
Input Example
{"parameters":{"uuids":["cyborg_threat_profiles"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
profile_id | string | Unique identifier |
profile_name | string | Name of the resource |
profile_type | string | Type of the resource |
status | string | Status value |
also_known_as | array | Output field: also_known_as |
overview | string | Output field: overview |
targeting | string | Output field: targeting |
delivery | string | Output field: delivery |
installation | string | Output field: installation |
persistence | string | Output field: persistence |
modules | string | Output field: modules |
communication | string | Output field: communication |
references | array | Output field: references |
last_updated | string | Output field: last_updated |
impact | array | Output field: impact |
context | object | Output field: context |
context.actors | array | Output field: context.actors |
context.motivations | array | Output field: context.motivations |
context.tooling | array | Output field: context.tooling |
context.operations | array | Output field: context.operations |
context.target_regions | array | Output field: context.target_regions |
context.source_regions | array | Output field: context.source_regions |
context.target_countries | array | Output field: context.target_countries |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Mon, 19 Feb 2023 20:37:23 GMT"},"reason":"OK","json_body":{"profile_id":"string","profile_name":"string","profile_type":"string","status":"string","also_known_as":["string"],"overview":"string","targeting":"string","delivery":"string","installation":"string","persistence":"string","modules":"string","communication":"string","references":["string"],"last_updated":"string","impact":["string"]}}
Response Headers
Header | Description | Example |
|---|---|---|
Access-Control-Allow-Origin | HTTP response header: Access-Control-Allow-Origin | * |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Tue, 12 Mar 2024 09:35:32 GMT |
ETag | An identifier for a specific version of a resource | W/"112f1-WVvNA/bu+lbMB+e0wKIPJmZLgYw" |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=15724800; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-DNS-Prefetch-Control | HTTP response header: X-DNS-Prefetch-Control | off |
X-Download-Options | HTTP response header: X-Download-Options | noopen |
X-Frame-Options | HTTP response header: X-Frame-Options | SAMEORIGIN |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 1; mode=block |