Digital Shadows
Digital Shadows is a digital risk protection platform that helps organizations monitor and manage their digital footprint.
Digital Shadows is a leading threat intelligence platform that provides comprehensive insights into digital risks. This connector allows Swimlane Turbine users to seamlessly integrate with Digital Shadows, enabling automated retrieval and analysis of data breaches, incidents, and vulnerabilities. By leveraging this integration, users can enhance their security posture through real-time threat detection and response, streamline incident management, and gain actionable intelligence to protect their digital assets.
Prerequisites
Before you can use the Digital Shadows connector for Turbine, you'll need access to the Digital Shadows API. This requires the following:
- HTTP Basic authentication using the following parameters:
- URL: The endpoint URL for accessing Digital Shadows API.
- API Key: A unique key provided by Digital Shadows for API access.
- API Secret: A secret associated with the API Key for secure authentication.
Asset information
The asset requires a url, API Key as username, API Secret as password for authentication.
Capabilities
This connector provides the following capabilities:
- Data Breaches
- Incidents
- Indicators
- IP Ports
- Ssl/Tls
- Vulnerabilities
- Reporting
- Search
- Tags
Notes
- Search action requires query_type to filter data by malicious score and set verdict.
- The documentation is only available on the digital shadows box itself under Learning -> Api Documentation
Additional Documentation
Configurations
Digital Shadows HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | API Key as username | string | Required |
password | API Secret as password | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Get Data Breach By ID
Retrieve detailed information about a specific data breach in Digital Shadows using its unique ID as a path parameter.
Endpoint
- URL: api/data-breach/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Get Data Breach By ID action |
Input Example
{"path_parameters":{"id":287732637809}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | number | Unique identifier |
title | string | Output field: title |
occurred | string | Output field: occurred |
modified | string | Output field: modified |
incident | object | Unique identifier |
incident.id | number | Unique identifier |
incident.scope | string | Unique identifier |
incident.type | string | Unique identifier |
incident.severity | string | Unique identifier |
incident.title | string | Unique identifier |
incident.closedSource | boolean | Unique identifier |
externalSource | boolean | Output field: externalSource |
dataClasses | array | Response data |
domainCount | number | Count value |
recordCount | number | Count value |
sourceUrl | string | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 17:09:47 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=QnZmRLbFSKbxdgJGoG/ZNiUJ11dnpOZeTRK3POUUkwXUfzTVIAkUrY+H1I6dXNMugjI7zOU1s...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"396GONJBAQRTU","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Data Breach Record by ID
Retrieve a data breach record from Digital Shadows using its unique ID provided as a path parameter.
Endpoint
- URL: api/data-breach-record/{{id}}/reviews
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Get Data Breach Record by ID action |
Input Example
{"path_parameters":{"id":287732637809}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 16:52:05 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=Ndi1u9SiirXIFNnBbbhfmdHbJKnkmyL/DUz6A60tB+lsWhB7R5gZ35SWdyIu8OQVSMHpDt1zL...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"5EOD3SN9TFAVK","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Data Breach Summary
Retrieve a summary of all data breaches for the current client in Digital Shadows, excluding those supported by the Exposed Credential alert.
Endpoint
- URL: api/data-breach-summary
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.published | string | Optional | Parameters for the Get Data Breach Summary action |
Input Example
{"parameters":{"published":"TODAY"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
totalBreaches | number | Output field: totalBreaches |
totalUsernames | number | Name of the resource |
usernamesPerDomain | array | Name of the resource |
usernamesPerDomain.file_name | string | Name of the resource |
usernamesPerDomain.file | string | Name of the resource |
breachesPerDomain | array | Output field: breachesPerDomain |
breachesPerDomain.file_name | string | Name of the resource |
breachesPerDomain.file | string | Output field: breachesPerDomain.file |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 16:32:22 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=Q8htdo0MIYq5rw87gEowgPNqFQcmOcp9jiaNhTxgF3qWp2CA9vxTzdQ3k7DDN1LTIdMj87SDL...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"165AJMB6P6DSM","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Incident by ID
Retrieve a specific incident from Digital Shadows using its unique ID provided as a path parameter.
Endpoint
- URL: api/incidents/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Get Incident by ID action |
Input Example
{"path_parameters":{"id":138538846}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | number | Unique identifier |
scope | string | Output field: scope |
type | string | Type of the resource |
subType | string | Type of the resource |
severity | string | Output field: severity |
title | string | Output field: title |
published | string | Output field: published |
closedSource | boolean | Output field: closedSource |
modified | string | Output field: modified |
occurred | string | Output field: occurred |
verified | string | Output field: verified |
tags | array | Output field: tags |
tags.id | number | Unique identifier |
tags.name | string | Name of the resource |
tags.type | string | Type of the resource |
version | number | Output field: version |
score | number | Score value |
entitySummary | object | Output field: entitySummary |
entitySummary.source | string | Output field: entitySummary.source |
entitySummary.domain | string | Output field: entitySummary.domain |
entitySummary.sourceDate | string | Date value |
entitySummary.screenshot | object | Output field: entitySummary.screenshot |
entitySummary.screenshot.id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 06:55:11 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=0l4xStO19HtAEkcWniqwe6JyGafi0EVDNEUrX6PD17r/2OxyNFgujHtLt+9687rqrZ6OEqAtW...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"83KCMOD6D4K91","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Incident CEF by Event
Retrieve client incidents in Common Event Format (CEF) for the current client using Digital Shadows.
Endpoint
- URL: api/incident-cef-events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.startTime | string | Optional | Parameters for the Get Incident CEF by Event action |
parameters.maxResults | number | Optional | Parameters for the Get Incident CEF by Event action |
parameters.eventType | string | Optional | Parameters for the Get Incident CEF by Event action |
Input Example
{"parameters":{"startTime":"TODAY","maxResults":50,"eventType":"ca101070-6b2c-48ed-ae27-7f629ebbfc4f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
format | string | Output field: format |
version | string | Output field: version |
timestamp | string | Output field: timestamp |
count | number | Count value |
events | array | Output field: events |
links | array | Output field: links |
links.rel | string | Output field: links.rel |
links.href | string | Output field: links.href |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 09:44:27 GMT","Content-Type":"application/json;charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=938wrrUH7/ZomvSQyuvdCVjyDa5MuUki6VR0O5gQ6f81IXzEN8RUCqXubiMtYpAVFsDZjPPGp...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"B9SF50A7L77QV","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 J...
Get Find Incident
Find and retrieve incidents from Digital Shadows for analysis and response.
Endpoint
- URL: api/incidents/find
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.since | string | Optional | Parameters for the Get Find Incident action |
parameters.sort.property | string | Optional | Parameters for the Get Find Incident action |
parameters.sort.direction | string | Optional | Parameters for the Get Find Incident action |
parameters.detailed | boolean | Optional | Parameters for the Get Find Incident action |
headers | object | Optional | HTTP headers for the request |
headers.Content-Type | string | Optional | HTTP headers for the request |
headers.Accept | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"since":"2023-07-31T22:24:23.221Z","sort.property":"published","sort.direction":"DESCENDING","detailed":true},"headers":{"Content-Type":"application/vnd.polaris-v47+json","Accept":"application/vnd.polaris-v47+json"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.id | number | Unique identifier |
content.scope | string | Response content |
content.type | string | Type of the resource |
content.subType | string | Type of the resource |
content.severity | string | Response content |
content.title | string | Response content |
content.published | string | Response content |
content.closedSource | boolean | Response content |
content.modified | string | Response content |
content.occurred | string | Response content |
content.verified | string | Response content |
content.tags | array | Response content |
content.tags.id | number | Unique identifier |
content.tags.name | string | Name of the resource |
content.tags.type | string | Type of the resource |
content.version | number | Response content |
content.score | number | Response content |
content.entitySummary | object | Response content |
content.entitySummary.source | string | Response content |
content.entitySummary.domain | string | Response content |
content.entitySummary.sourceDate | string | Response content |
content.entitySummary.screenshot | object | Response content |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 07:26:54 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=o+M2mjLEXKi7IAgehiDjvKIZXQ72Unft6l+w5M0utsJ7pvcQ+UnH2cERmzZoeq35HwXubweaa...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"4GQVGEGICE4LR","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Incident Find Triage by ID
Retrieve the triage-item-id for a given incident ID in Digital Shadows using the specified path parameter 'id'.
Endpoint
- URL: api/incidents/{{id}}/find-triage-item-id
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Get Incident Find Triage by ID action |
Input Example
{"path_parameters":{"id":138538846}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 07:01:29 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=BMHsLaXb5fatd6N8GHBskaSmJi+mjEqUBK8CKNMEVJmb8AavPiRYk4pIQxx21xHdmhfMa3Vp3...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"EI0ALIUT27DP5","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Incident Reviews by ID
Retrieve all review updates for a given incident in Digital Shadows.
Endpoint
- URL: api/incidents/{{id}}/reviews
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Optional | Parameters for the Get Incident Reviews by ID action |
Input Example
{"path_parameters":{"id":138538846}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 07:05:11 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=TX/nbe+kToN2o9EzGleSI3FV2Fszn5E9M/cvm0u2ZKudQK7SKtzGtZCzgrfcjOvfnohOQebFl...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"EF0Q1KS39V44R","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get ip Ports Reviews by ID
Retrieve all review updates for a given port inspection in Digital Shadows using the incident ID.
Endpoint
- URL: api/ip-ports/{{id}}/reviews
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Optional | Parameters for the Get ip Ports Reviews by ID action |
parameters.incidentId | number | Required | Parameters for the Get ip Ports Reviews by ID action |
Input Example
{"parameters":{"incidentId":136492687},"path_parameters":{"id":126096551}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 13:27:26 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=37QkPMMhNxaw5TJdlEq1e8PqjkCeYdbHnfVE+LGmbBn2Dnlt8FRl4TsqKWbAcpuBvq1pYMahq...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"4B5IURVAELCJU","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Get Tags Batch
Batch retrieve specific tags by their ID in Digital Shadows using the provided parameters.
Endpoint
- URL: api/tags/batch
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.id | number | Required | Parameters for the Get Tags Batch action |
parameters.detailed | boolean | Optional | Parameters for the Get Tags Batch action |
Input Example
{"parameters":{"id":126096551,"detailed":false}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Aug 2023 09:05:09 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=5syW3b6YhnMm05v5n9cWiUfzBYdvrw/D/Tb6bc+HQv8TXBeu9mX/eLzejdGevnWlM8wCLucDk...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"2JTN99OR00BH3","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Data Breach by Find
Identify and retrieve information on data breaches using Digital Shadows.
Endpoint
- URL: api/data-breach/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Data Breach by Find |
filter.published | string | Optional | Parameter for Post Data Breach by Find |
filter.username | string | Optional | Name of the resource |
filter.domainNamesOnRecords | array | Optional | Name of the resource |
filter.severities | array | Optional | Parameter for Post Data Breach by Find |
filter.statuses | array | Optional | Status value |
filter.alerted | boolean | Optional | Parameter for Post Data Breach by Find |
filter.minimumTotalRecords | number | Optional | Parameter for Post Data Breach by Find |
filter.repostedCredentials | array | Optional | Parameter for Post Data Breach by Find |
sort | object | Optional | Parameter for Post Data Breach by Find |
sort.property | string | Optional | Parameter for Post Data Breach by Find |
sort.direction | string | Optional | Parameter for Post Data Breach by Find |
pagination | object | Optional | Parameter for Post Data Breach by Find |
pagination.size | number | Optional | Parameter for Post Data Breach by Find |
pagination.offset | number | Optional | Parameter for Post Data Breach by Find |
pagination.containingId | string | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"published":"TODAY","username":"[email protected]","domainNamesOnRecords":["example"],"severities":["VERY_HIGH"],"statuses":["UNREAD"],"alerted":false,"minimumTotalRecords":20,"repostedCredentials":["ORIGINAL"]},"sort":{"property":"domainName","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.id | number | Unique identifier |
content.title | string | Response content |
content.occurred | string | Response content |
content.modified | string | Response content |
content.published | string | Response content |
content.incident | object | Unique identifier |
content.incident.id | number | Unique identifier |
content.incident.scope | string | Unique identifier |
content.incident.type | string | Unique identifier |
content.incident.severity | string | Unique identifier |
content.incident.title | string | Unique identifier |
content.incident.closedSource | boolean | Unique identifier |
content.externalSource | boolean | Response content |
content.domainCount | number | Response content |
content.recordCount | number | Response content |
content.sourceUrl | string | URL endpoint for the request |
content.organisationUsernameCount | number | Name of the resource |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Aug 2023 09:48:45 GMT","Content-Type":"application/json;charset=UTF-8","Content-Length":"190","Connection":"keep-alive","Set-Cookie":"AWSALB=+/DcA5V+lXHM7PY31Rx0wWEfjjEvP9aTFmyBU/ITP5FURSXBIWD39/2QZD1cAspwsxCmSyarA...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"CKBBOBGVHTE6N","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT"...
Post Data Breach by ID
Find data breach records in Digital Shadows by providing the ID as a path parameter.
Endpoint
- URL: api/data-breach/{{id}}/records
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Post Data Breach by ID action |
filter | object | Optional | Parameter for Post Data Breach by ID |
filter.published | string | Optional | Parameter for Post Data Breach by ID |
filter.distinction | string | Optional | Parameter for Post Data Breach by ID |
filter.username | string | Optional | Name of the resource |
filter.password | string | Optional | Parameter for Post Data Breach by ID |
filter.domainName | string | Optional | Name of the resource |
filter.domainNames | array | Optional | Name of the resource |
filter.reviewStatuses | array | Optional | Status value |
sort | object | Optional | Parameter for Post Data Breach by ID |
sort.property | string | Optional | Parameter for Post Data Breach by ID |
sort.direction | string | Optional | Parameter for Post Data Breach by ID |
pagination | object | Optional | Parameter for Post Data Breach by ID |
pagination.size | number | Optional | Parameter for Post Data Breach by ID |
pagination.offset | number | Optional | Parameter for Post Data Breach by ID |
pagination.containingId | string | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"published":"TODAY","distinction":"NEW_USERNAME","username":"[email protected]","password":"$2y$10$ES2KJfnSHR6e6L8qJbN22eQks03dUDZ/b238QgJFdPtf7RO1kVhbW","domainName":"example","domainNames":["example.com"],"reviewStatuses":["CLOSED"]},"sort":{"property":"username","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}},"path_parameters":{"id":126096551}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 17:18:04 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=PJVALlI/CVYZad+G+gr2NpKLAIXCIfbpm6f0Xrganqc8eGyjSLdkimEvnO620v8Nn/8RLLlF6...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"CH0A8JUUCC5BJ","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Data Breach Record by Find
Find and retrieve data breach records using Digital Shadows.
Endpoint
- URL: api/data-breach-record/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Data Breach Record by Find |
filter.published | string | Optional | Parameter for Post Data Breach Record by Find |
filter.distinction | string | Optional | Parameter for Post Data Breach Record by Find |
filter.username | string | Optional | Name of the resource |
filter.password | string | Optional | Parameter for Post Data Breach Record by Find |
filter.domainName | string | Optional | Name of the resource |
filter.domainNames | array | Optional | Name of the resource |
filter.reviewStatuses | array | Optional | Status value |
sort | object | Optional | Parameter for Post Data Breach Record by Find |
sort.property | string | Optional | Parameter for Post Data Breach Record by Find |
sort.direction | string | Optional | Parameter for Post Data Breach Record by Find |
pagination | object | Optional | Parameter for Post Data Breach Record by Find |
pagination.size | number | Optional | Parameter for Post Data Breach Record by Find |
pagination.offset | number | Optional | Parameter for Post Data Breach Record by Find |
pagination.containingId | string | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"published":"TODAY","distinction":"NEW_USERNAME","username":"[email protected]","password":"$2y$10$ES2KJfnSHR6e6L8qJbN22eQks03dUDZ/b238QgJFdPtf7RO1kVhbW","domainName":"example","domainNames":["example.com"],"reviewStatuses":["CLOSED"]},"sort":{"property":"username","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 16:36:45 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=wK6V3ztOw9gwCKaCQFcKx/9o7sktFg8STL9cj5kmSmn+YrSons/DsStOsMjLxEypieaEobe5q...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"E7RNJ1KIS42S4","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Data Breach Record by ID
Snapshot the review status of a data breach record in Digital Shadows using the specified ID as a path parameter.
Endpoint
- URL: api/data-breach-record/{{id}}/reviews
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Post Data Breach Record by ID action |
note | string | Optional | Parameter for Post Data Breach Record by ID |
status | string | Optional | Status value |
version | number | Optional | Parameter for Post Data Breach Record by ID |
Input Example
{"json_body":{"note":"Optional textual note to include with this status change","status":"CLOSED","version":1},"path_parameters":{"id":287732637809}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 14:43:40 GMT","Connection":"keep-alive","Set-Cookie":"AWSALB=8ziD+pXOh8e7iITGZrxQhbABKgebcLNOS/Zq4vRCLTgG4FGd1w/L+MlYlz5l7qhZn//ZejNT/...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"DDDHMC4K09CP","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT","Pragma":"no-cache","X-RateLimit-Limit":"240","X-RateLimit-Remaining":"...
Post Data Breach Username by FIND
Find unique usernames discovered across all data breaches using Digital Shadows.
Endpoint
- URL: api/data-breach-usernames/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Data Breach Username by FIND |
filter.published | string | Optional | Parameter for Post Data Breach Username by FIND |
filter.domainNames | array | Optional | Name of the resource |
filter.username | string | Optional | Name of the resource |
filter.reviewStatuses | array | Optional | Status value |
sort | object | Optional | Parameter for Post Data Breach Username by FIND |
sort.property | string | Optional | Parameter for Post Data Breach Username by FIND |
sort.direction | string | Optional | Parameter for Post Data Breach Username by FIND |
pagination | object | Optional | Parameter for Post Data Breach Username by FIND |
pagination.size | number | Optional | Parameter for Post Data Breach Username by FIND |
pagination.offset | number | Optional | Parameter for Post Data Breach Username by FIND |
pagination.containingId | string | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"published":"TODAY","domainNames":["example.com"],"username":"example","reviewStatuses":["CLOSED"]},"sort":{"property":"username","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Thu, 10 Aug 2023 16:29:10 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=U1rEvgT5uTV9lq4rIUJT0Oo5OR1xVoVNDYYcJamuNHeCsx4g+xnnN4pmjxUiJSlpW+95R4vTQ...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"3L2L1DE5PO5SK","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Find Indicators
Retrieve indicators from Digital Shadows based on specified criteria in the view object.
Endpoint
- URL: api/indicators/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Content-Type | string | Optional | HTTP headers for the request |
headers.Accept | string | Optional | HTTP headers for the request |
filter | object | Optional | Parameter for Post Find Indicators |
filter.ids | array | Optional | Unique identifier |
filter.indicatorIds | array | Optional | Unique identifier |
filter.types | array | Optional | Type of the resource |
filter.value | string | Optional | Value for the parameter |
filter.actorThreats | array | Optional | Parameter for Post Find Indicators |
filter.actorThreats.id | number | Optional | Unique identifier |
filter.malwareThreats | array | Optional | Parameter for Post Find Indicators |
filter.malwareThreats.id | number | Optional | Unique identifier |
filter.attributionTags | array | Optional | Parameter for Post Find Indicators |
filter.attributionTags.id | number | Optional | Unique identifier |
filter.malwareAttributions | array | Optional | Parameter for Post Find Indicators |
filter.malwareAttributions.id | number | Optional | Unique identifier |
filter.lastUpdated | string | Optional | Parameter for Post Find Indicators |
filter.sourceType | string | Optional | Type of the resource |
filter.sourceIdentifier | string | Optional | Unique identifier |
filter.externalIds | array | Optional | Unique identifier |
sort | object | Optional | Parameter for Post Find Indicators |
sort.property | string | Optional | Parameter for Post Find Indicators |
sort.direction | string | Optional | Parameter for Post Find Indicators |
pagination | object | Optional | Parameter for Post Find Indicators |
pagination.size | number | Optional | Parameter for Post Find Indicators |
Input Example
{"json_body":{"filter":{"ids":[3245578877],"indicatorIds":[43567],"types":["URL"],"value":"http://zzepms.com/askinstall52.exe","actorThreats":[{"id":2323566775}],"malwareThreats":[{"id":3257889966}],"attributionTags":[{"id":2345536778}],"malwareAttributions":[{"id":3466267887}],"lastUpdated":"2021-06-21T00:04:17.000Z","sourceType":"URLHAUS","sourceIdentifier":"https://urlhaus.abuse.ch/url/1385034/","externalIds":[8456]},"sort":{"property":"domainName","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}},"headers":{"Content-Type":"application/vnd.polaris-v47+json","Accept":"application/vnd.polaris-v47+json"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.id | string | Unique identifier |
content.type | string | Type of the resource |
content.value | string | Value for the parameter |
content.sourceIdentifier | string | Unique identifier |
content.sourceType | string | Type of the resource |
content.lastUpdated | string | Response content |
content.attributionTag | object | Response content |
content.attributionTag.id | number | Unique identifier |
content.attributionTag.name | string | Name of the resource |
content.attributionTag.type | string | Type of the resource |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 08:14:52 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=wVFkB0/nKRzc1cZp8h7xLOzZmDL17BJKfEDF1JApBPUre1rmteGyrPtVY+YY97GBWgFlb0ltw...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"GRN0MEKEOU7K","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:0...
Post Find Incident
Locate and retrieve incident details from Digital Shadows to enhance security insights.
Endpoint
- URL: api/incidents/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Content-Type | string | Optional | HTTP headers for the request |
headers.Accept | string | Optional | HTTP headers for the request |
filter | object | Optional | Parameter for Post Find Incident |
filter.identifier | number | Optional | Unique identifier |
filter.severities | array | Optional | Parameter for Post Find Incident |
filter.tags | array | Optional | Parameter for Post Find Incident |
filter.tags.id | number | Optional | Unique identifier |
filter.tags.name | string | Optional | Name of the resource |
filter.tags.type | string | Optional | Type of the resource |
filter.tags.threat | object | Optional | Parameter for Post Find Incident |
filter.tags.threat.id | number | Optional | Unique identifier |
filter.tags.parent | object | Optional | Parameter for Post Find Incident |
filter.tags.parent.id | number | Optional | Unique identifier |
filter.tags.domain | string | Optional | Parameter for Post Find Incident |
filter.tags.created | string | Optional | Parameter for Post Find Incident |
filter.tagOperator | string | Optional | Parameter for Post Find Incident |
filter.dateRange | string | Optional | Parameter for Post Find Incident |
filter.dateRangeField | string | Optional | Parameter for Post Find Incident |
filter.incidentTypes | array | Optional | Unique identifier |
filter.incidentTaggedTypes | array | Optional | Unique identifier |
filter.incidentTaggedTypes.id | number | Optional | Unique identifier |
filter.incidentTaggedTypes.name | string | Optional | Unique identifier |
filter.incidentTaggedTypes.type | string | Optional | Unique identifier |
filter.incidentTaggedTypes.threat | object | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"identifier":138536302,"severities":["VERY_HIGH"],"tags":[{"id":332,"name":"Phishing Attempt","type":"BRAND_PROTECTION","threat":{"id":138475352},"parent":{"id":138534893},"domain":"roghtmove.uk","created":"2023-08-03T04:45:50.892Z"}],"tagOperator":"New","dateRange":"2023-08-02T20:35:06.655Z","dateRangeField":"LAST","incidentTypes":["NEW"],"incidentTaggedTypes":[{"id":138463718,"name":"Phishing Attempt","type":"BRAND_PROTECTION","threat":{"id":138448482},"parent":{"id":138448482},"domain":"roghtmove.uk","created":"2023-08-03T04:45:50.892Z"}],"types":[{"type":"IMPERSONATING_DOMAIN","subTypes":["PHISHING_ATTEMPT"]}],"domainName":"example","domainSelection":"roghtmove.uk","datePeriod":"TODAYS","from":"2023-08-03T04:45:50.892Z","until":"2023-08-03T04:45:50.892Z","alerted":false,"withTakedown":false,"withoutTakedown":false,"withContentRemoved":false,"withoutContentRemoved":false,"statuses":["UNREAD"],"repostedCredentials":["example"]},"sort":{"property":"domainName","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"},"subscribed":false,"subscribedOnly":false},"headers":{"Content-Type":"application/vnd.polaris-v47+json","Accept":"application/vnd.polaris-v47+json"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.id | number | Unique identifier |
content.scope | string | Response content |
content.type | string | Type of the resource |
content.subType | string | Type of the resource |
content.severity | string | Response content |
content.title | string | Response content |
content.published | string | Response content |
content.closedSource | boolean | Response content |
content.modified | string | Response content |
content.occurred | string | Response content |
content.verified | string | Response content |
content.tags | array | Response content |
content.tags.id | number | Unique identifier |
content.tags.name | string | Name of the resource |
content.tags.type | string | Type of the resource |
content.version | number | Response content |
content.score | number | Response content |
content.entitySummary | object | Response content |
content.entitySummary.source | string | Response content |
content.entitySummary.domain | string | Response content |
content.entitySummary.sourceDate | string | Response content |
content.entitySummary.screenshot | object | Response content |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 08:14:52 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=wVFkB0/nKRzc1cZp8h7xLOzZmDL17BJKfEDF1JApBPUre1rmteGyrPtVY+YY97GBWgFlb0ltw...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"GRN0MEKEOU7K","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:0...
Post Incident Pipeline
Retrieve the incident pipeline data in Digital Shadows, providing an overview of the curation process used to extract incidents.
Endpoint
- URL: api/incidents/pipeline
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Incident Pipeline |
filter.dateRange | string | Optional | Parameter for Post Incident Pipeline |
Input Example
{"json_body":{"filter":{"dateRange":"TODAY"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
from | string | Output field: from |
until | string | Output field: until |
stages | array | Output field: stages |
stages.type | string | Type of the resource |
stages.counts | array | Output field: stages.counts |
stages.counts.type | string | Type of the resource |
stages.counts.current | number | Output field: stages.counts.current |
stages.counts.previous | number | Output field: stages.counts.previous |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 09:15:56 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=V8zxA3ViWVijWnJsN9vrxjZBL5Q+ej5f5V4DRv5qBB3hUT7InYdhKd3+H+hpEOendCGJLgb4J...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"393B1DACC0BLN","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Incident Reviews by ID
Snapshot the review status of an incident in Digital Shadows using the incident ID as a path parameter.
Endpoint
- URL: api/incidents/{{id}}/reviews
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Post Incident Reviews by ID action |
note | string | Optional | Parameter for Post Incident Reviews by ID |
status | string | Optional | Status value |
version | number | Optional | Parameter for Post Incident Reviews by ID |
Input Example
{"json_body":{"note":"Optional textual note to include with this status change","status":"CLOSED","version":2},"path_parameters":{"id":287732637809}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | number | Unique identifier |
version | number | Output field: version |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 07:17:50 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=Vvl9BkVv8VjVcQR4Ob2bSFhGG4B4AFdI52IrmdQ5WQgr6R66+iuGwbrk98HtQU/DOTMlkGLRA...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"296LUNFBF8H14","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Incident Summary
Post an aggregated summary of incident information in Digital Shadows to generate comprehensive reports and statistics.
Endpoint
- URL: api/incidents/summary
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Incident Summary |
filter.identifier | number | Optional | Unique identifier |
filter.severities | array | Optional | Parameter for Post Incident Summary |
filter.tags | array | Optional | Parameter for Post Incident Summary |
filter.tags.id | number | Optional | Unique identifier |
filter.tags.name | string | Optional | Name of the resource |
filter.tags.type | string | Optional | Type of the resource |
filter.tags.threat | object | Optional | Parameter for Post Incident Summary |
filter.tags.threat.id | number | Optional | Unique identifier |
filter.tags.parent | object | Optional | Parameter for Post Incident Summary |
filter.tags.parent.id | number | Optional | Unique identifier |
filter.tags.domain | string | Optional | Parameter for Post Incident Summary |
filter.tags.created | string | Optional | Parameter for Post Incident Summary |
filter.tagOperator | string | Optional | Parameter for Post Incident Summary |
filter.dateRange | string | Optional | Parameter for Post Incident Summary |
filter.dateRangeField | string | Optional | Parameter for Post Incident Summary |
filter.incidentTypes | array | Optional | Unique identifier |
filter.incidentTaggedTypes | array | Optional | Unique identifier |
filter.incidentTaggedTypes.id | number | Optional | Unique identifier |
filter.incidentTaggedTypes.name | string | Optional | Unique identifier |
filter.incidentTaggedTypes.type | string | Optional | Unique identifier |
filter.incidentTaggedTypes.threat | object | Optional | Unique identifier |
filter.incidentTaggedTypes.threat.id | number | Optional | Unique identifier |
filter.incidentTaggedTypes.parent | object | Optional | Unique identifier |
filter.incidentTaggedTypes.parent.id | number | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"identifier":138538846,"severities":["VERY_HIGH"],"tags":[{"id":138538846,"name":"Example","type":"Example","threat":{"id":138538846},"parent":{"id":138538846},"domain":"Example","created":"2023-08-09T14:50:43.403Z"}],"tagOperator":"example","dateRange":"P13D","dateRangeField":"Sample","incidentTypes":["New"],"incidentTaggedTypes":[{"id":138538846,"name":"digital","type":"Shadows","threat":{"id":238765129},"parent":{"id":243126891},"domain":"Example","created":"2023-08-09T14:50:43.403Z"}],"types":[{"type":"string","subTypes":["string"]}],"domainName":"string","domainSelection":"string","datePeriod":"string","from":"2023-08-09T14:50:43.403Z","until":"2023-08-09T14:50:43.403Z","alerted":false,"withTakedown":false,"withoutTakedown":false,"withContentRemoved":false,"withoutContentRemoved":false,"statuses":["UNREAD"],"repostedCredentials":["example"]},"sort":{"property":"domainName","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"},"groupByKey":"High","groupByKeys":["LOW"],"temporalGrouping":{"type":"Shadows","timeSpan":"New","mode":"High"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
keySet | array | Output field: keySet |
keyLabels | array | Output field: keyLabels |
ranges | array | Output field: ranges |
ranges.rangeStart | string | Output field: ranges.rangeStart |
ranges.rangeEnd | string | Output field: ranges.rangeEnd |
ranges.groupedIncidentCounts | array | Unique identifier |
ranges.groupedIncidentCounts.file_name | string | Unique identifier |
ranges.groupedIncidentCounts.file | string | Unique identifier |
ranges.total | number | Output field: ranges.total |
regularTimeSpan | string | Output field: regularTimeSpan |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 09:36:59 GMT","Content-Type":"application/json;charset=UTF-8","Content-Length":"136","Connection":"keep-alive","Set-Cookie":"AWSALB=+J1qhF/qnR/uV7c7qMzNwYyfW4UAOlSo78LIKhzdPXhxyAggHV0YkpW98WJDRqUuQDacLl/YR...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"43DJQKNAFEO9A","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT"...
Post Ip Ports Find
Locate and retrieve information about open ports associated with specific IP addresses using Digital Shadows.
Endpoint
- URL: api/ip-ports/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Ip Ports Find |
filter.detectedOpen | string | Optional | Parameter for Post Ip Ports Find |
filter.published | string | Optional | Parameter for Post Ip Ports Find |
filter.severities | array | Optional | Parameter for Post Ip Ports Find |
filter.alerted | boolean | Optional | Parameter for Post Ip Ports Find |
filter.ipAddress | string | Optional | Parameter for Post Ip Ports Find |
filter.ipRange | object | Optional | Parameter for Post Ip Ports Find |
filter.ipRange.lowerAddress | string | Optional | Parameter for Post Ip Ports Find |
filter.ipRange.upperAddress | string | Optional | Parameter for Post Ip Ports Find |
filter.ipRange.maskBits | number | Optional | Parameter for Post Ip Ports Find |
filter.domainName | string | Optional | Name of the resource |
filter.markedClosed | boolean | Optional | Parameter for Post Ip Ports Find |
filter.detectedClosed | boolean | Optional | Parameter for Post Ip Ports Find |
filter.portNumbers | array | Optional | Parameter for Post Ip Ports Find |
filter.incidentTypes | array | Optional | Unique identifier |
filter.incidentTypes.type | string | Optional | Unique identifier |
filter.incidentTypes.subTypes | array | Optional | Unique identifier |
sort | object | Optional | Parameter for Post Ip Ports Find |
sort.property | string | Optional | Parameter for Post Ip Ports Find |
sort.direction | string | Optional | Parameter for Post Ip Ports Find |
pagination | object | Optional | Parameter for Post Ip Ports Find |
pagination.size | number | Optional | Parameter for Post Ip Ports Find |
pagination.offset | number | Optional | Parameter for Post Ip Ports Find |
pagination.containingId | string | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"detectedOpen":"Example","published":"TODAY","severities":["VERY_HIGH"],"alerted":false,"ipAddress":"Example123.2","ipRange":{"lowerAddress":"Example","upperAddress":"Example","maskBits":50},"domainName":"Example","markedClosed":false,"detectedClosed":false,"portNumbers":[5600],"incidentTypes":[{"type":"DATA_LEAKAGE","subTypes":["BRAND_MISUSE"]}]},"sort":{"property":"ipAddress","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 13:13:59 GMT","Content-Type":"application/json;charset=UTF-8","Content-Length":"306","Connection":"keep-alive","Set-Cookie":"AWSALB=1Uy7zgeeqgGuAKPN7PiiUFj27DsCrfxejFARijgDqp387HBPEETBmCU4nY3i45spuwnCcvHW9...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"8C3BUSB4MJUCG","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT"...
Post Ip Ports Reviews by ID
Snapshot the review status of a port inspection in Digital Shadows by posting IP and port reviews using their unique identifiers.
Endpoint
- URL: api/ip-ports/{id}/reviews
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Optional | Parameters for the Post Ip Ports Reviews by ID action |
incident | object | Optional | Unique identifier |
incident.id | number | Optional | Unique identifier |
incident.scope | string | Optional | Unique identifier |
status | string | Optional | Status value |
version | number | Optional | Parameter for Post Ip Ports Reviews by ID |
Input Example
{"json_body":{"incident":{"id":136492687,"scope":"OPEN"},"status":"NEW","version":1},"path_parameters":{"id":126096551}}
POST Risk Detection Pipeline Counts
Provide data for the pipeline graphic on the SearchLight portal home page, supporting risk detection reporting in Digital Shadows.
Endpoint
- URL: api/risk-detection-pipeline/counts
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
visible | array | Optional | Parameter for POST Risk Detection Pipeline Counts |
filter | object | Optional | Parameter for POST Risk Detection Pipeline Counts |
filter.timeRange | string | Optional | Parameter for POST Risk Detection Pipeline Counts |
filter.classifications | array | Optional | Parameter for POST Risk Detection Pipeline Counts |
filter.triageStates | array | Optional | Parameter for POST Risk Detection Pipeline Counts |
Input Example
{"json_body":{"visible":["New"],"filter":{"timeRange":"2023-09-09T14:50:43.403Z","classifications":["Incident"],"triageStates":["UNREAD"]}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
coverageCounts | object | Output field: coverageCounts |
coverageCounts.documentsCount | number | Count value |
coverageCounts.technicalSourcesCount | number | Count value |
coverageCounts.darkWebCount | number | Count value |
coverageCounts.surfaceWebCount | number | Count value |
footprintCounts | object | Output field: footprintCounts |
footprintCounts.documentsCount | number | Count value |
footprintCounts.technicalSourcesCount | number | Count value |
footprintCounts.darkWebCount | number | Count value |
footprintCounts.surfaceWebCount | number | Count value |
alertAndIncidentCounts | object | Unique identifier |
alertAndIncidentCounts.documentsCount | number | Unique identifier |
alertAndIncidentCounts.technicalSourcesCount | number | Unique identifier |
alertAndIncidentCounts.darkWebCount | number | Unique identifier |
alertAndIncidentCounts.surfaceWebCount | number | Unique identifier |
rangeStart | string | Output field: rangeStart |
calculatedRangeStart | string | Output field: calculatedRangeStart |
calculatedRangeEnd | string | Output field: calculatedRangeEnd |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Aug 2023 09:13:04 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Connection":"keep-alive","Set-Cookie":"AWSALB=pvlak1LtoUr5UyqGvHm4MXH7klx/70T4w/I3mSehSlM67SNwHXzjpGoRuA3gQn8mpOgeWNpGA...","Vary":"Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-H...","X-Correlation-Id":"ETT21O2MRVV52","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:...
Post Search Find
Perform a general search against incidents, threats, and closed sources in Digital Shadows.
Endpoint
- URL: api/search/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Search Find |
filter.tags | array | Optional | Parameter for Post Search Find |
filter.tags.id | number | Optional | Unique identifier |
filter.tags.name | string | Optional | Name of the resource |
filter.tags.type | string | Optional | Type of the resource |
filter.tags.threat | object | Optional | Parameter for Post Search Find |
filter.tags.threat.id | number | Optional | Unique identifier |
filter.tags.parent | object | Optional | Parameter for Post Search Find |
filter.tags.parent.id | number | Optional | Unique identifier |
filter.tags.domain | string | Optional | Parameter for Post Search Find |
filter.tags.created | string | Optional | Parameter for Post Search Find |
filter.types | array | Optional | Type of the resource |
filter.dateRange | string | Optional | Parameter for Post Search Find |
filter.incidentTypes | array | Optional | Unique identifier |
filter.incidentSubtypes | array | Optional | Unique identifier |
filter.incidentSeverities | array | Optional | Unique identifier |
filter.webPageNetworks | array | Optional | Parameter for Post Search Find |
filter.forumPostNetworks | array | Optional | Parameter for Post Search Find |
filter.marketplaceListingNetworks | array | Optional | Parameter for Post Search Find |
filter.marketplaces | array | Optional | Parameter for Post Search Find |
filter.chatServers | array | Optional | Parameter for Post Search Find |
filter.chatChannels | array | Optional | Parameter for Post Search Find |
filter.threatLevelTypes | array | Optional | Type of the resource |
filter.webPageSiteCategories | array | Optional | Parameter for Post Search Find |
filter.forumPostSiteCategories | array | Optional | Parameter for Post Search Find |
Input Example
{"json_body":{"filter":{"tags":[{"id":136492687,"name":"Exampole","type":"0","threat":{"id":238765129},"parent":{"id":243126891},"domain":"0","created":"2023-08-09T14:50:43.403Z"}],"types":["BLOG_POST"],"dateRange":"TODAY","incidentTypes":["DATA_LEAKAGE"],"incidentSubtypes":["CREDENTIAL_COMPROMISE"],"incidentSeverities":["VERY_HIGH"],"webPageNetworks":["INTERNET"],"forumPostNetworks":["INTERNET"],"marketplaceListingNetworks":["INTERNET"],"marketplaces":["ALPHABAY"],"chatServers":["CHAT_MESSAGE "],"chatChannels":["CHAT_MESSAGE"],"threatLevelTypes":["VERY_HIGH"],"webPageSiteCategories":["ACTIVIST"],"forumPostSiteCategories":["ACTIVIST"],"blogNames":["BLOG_POST"],"datePeriod":"2023-09-09T14:50:43.403Z","from":"2023-08-09T14:50:43.403Z","until":"2023-08-09T14:50:43.403Z"},"sort":{"property":"ipAddress","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"},"query":"www.example.com or 8.8.8.8 or 536b5bec4148f0d623f603c1ba0f0a3c","facets":["RESULTS_TYPE_FILTERED"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
total | number | Output field: total |
verdict | string | Output field: verdict |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Mon, 14 Aug 2023 08:47:20 GMT","Content-Type":"application/json;charset=UTF-8","Content-Length":"136","Connection":"keep-alive","Set-Cookie":"AWSALB=ywrDtKQzMC0k6swJu30J6Ov5leMLUia7SNWsAElJG2ap/bIoh3wEjHJb5lnyogkNzC/X3oWSU...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"BNB97JSTLG9VH","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT"...
Post Secure Socket Find
Locate and identify secure sockets using Digital Shadows to enhance security posture.
Endpoint
- URL: api/secure-socket/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post Secure Socket Find |
filter.domain | string | Optional | Parameter for Post Secure Socket Find |
filter.published | string | Optional | Parameter for Post Secure Socket Find |
filter.detected | string | Optional | Parameter for Post Secure Socket Find |
filter.expiry | string | Optional | Parameter for Post Secure Socket Find |
filter.ipRange | object | Optional | Parameter for Post Secure Socket Find |
filter.ipRange.lowerAddress | string | Optional | Parameter for Post Secure Socket Find |
filter.ipRange.upperAddress | string | Optional | Parameter for Post Secure Socket Find |
filter.ipRange.maskBits | number | Optional | Parameter for Post Secure Socket Find |
filter.ipAddress | string | Optional | Parameter for Post Secure Socket Find |
filter.revoked | boolean | Optional | Parameter for Post Secure Socket Find |
filter.grade | string | Optional | Parameter for Post Secure Socket Find |
filter.grades | array | Optional | Parameter for Post Secure Socket Find |
filter.issues | array | Optional | Parameter for Post Secure Socket Find |
filter.determinedResolved | boolean | Optional | Parameter for Post Secure Socket Find |
filter.markedClosed | boolean | Optional | Parameter for Post Secure Socket Find |
filter.severities | array | Optional | Parameter for Post Secure Socket Find |
filter.statuses | array | Optional | Status value |
filter.alerted | boolean | Optional | Parameter for Post Secure Socket Find |
filter.incidentTypes | array | Optional | Unique identifier |
filter.incidentTypes.type | string | Optional | Unique identifier |
filter.incidentTypes.subTypes | array | Optional | Unique identifier |
sort | object | Optional | Parameter for Post Secure Socket Find |
sort.property | string | Optional | Parameter for Post Secure Socket Find |
sort.direction | string | Optional | Parameter for Post Secure Socket Find |
Input Example
{"json_body":{"filter":{"domain":"Example","published":"TODAY","detected":"NEW","expiry":"LAST","ipRange":{"lowerAddress":"example","upperAddress":"example","maskBits":123},"ipAddress":"Example123.com","revoked":false,"grade":"A","grades":["high"],"issues":["new"],"determinedResolved":false,"markedClosed":false,"severities":["VERY_HIGH"],"statuses":["UNREAD"],"alerted":false,"incidentTypes":[{"type":"Shadows","subTypes":["Example"]}]},"sort":{"property":"domainName","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 10:41:48 GMT","Content-Type":"application/json;charset=UTF-8","Content-Length":"187","Connection":"keep-alive","Set-Cookie":"AWSALB=RKcl1G5FpJrMnDCj2aJKY8uiD2KHB8YYckbw+6JgwpKIo8ec3JtyxE1iTb4wfzTcexs9nCuIR...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"F12LE5N9K2MPS","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT"...
Post vulnerability Find
Find and identify vulnerabilities using Digital Shadows to enhance security posture.
Endpoint
- URL: api/vulnerability/find
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
filter | object | Optional | Parameter for Post vulnerability Find |
filter.detected | string | Optional | Parameter for Post vulnerability Find |
filter.published | string | Optional | Parameter for Post vulnerability Find |
filter.severities | array | Optional | Parameter for Post vulnerability Find |
filter.alerted | boolean | Optional | Parameter for Post vulnerability Find |
filter.ipRange | object | Optional | Parameter for Post vulnerability Find |
filter.ipRange.lowerAddress | string | Optional | Parameter for Post vulnerability Find |
filter.ipRange.upperAddress | string | Optional | Parameter for Post vulnerability Find |
filter.ipRange.maskBits | number | Optional | Parameter for Post vulnerability Find |
filter.ipAddress | string | Optional | Parameter for Post vulnerability Find |
filter.domainName | string | Optional | Name of the resource |
filter.cveIdentifiers | array | Optional | Unique identifier |
filter.markedClosed | boolean | Optional | Parameter for Post vulnerability Find |
filter.detectedClosed | boolean | Optional | Parameter for Post vulnerability Find |
filter.incidentTypes | array | Optional | Unique identifier |
filter.incidentTypes.type | string | Optional | Unique identifier |
filter.incidentTypes.subTypes | array | Optional | Unique identifier |
sort | object | Optional | Parameter for Post vulnerability Find |
sort.property | string | Optional | Parameter for Post vulnerability Find |
sort.direction | string | Optional | Parameter for Post vulnerability Find |
pagination | object | Optional | Parameter for Post vulnerability Find |
pagination.size | number | Optional | Parameter for Post vulnerability Find |
pagination.offset | number | Optional | Parameter for Post vulnerability Find |
pagination.containingId | string | Optional | Unique identifier |
Input Example
{"json_body":{"filter":{"detected":"Example","published":"TODAY","severities":["VERY_HIGH"],"alerted":false,"ipRange":{"lowerAddress":"example.com","upperAddress":"Example.com","maskBits":23},"ipAddress":"example123","domainName":"New","cveIdentifiers":["example"],"markedClosed":false,"detectedClosed":false,"incidentTypes":[{"type":"DATA_LEAKAGE","subTypes":["BRAND_MISUSE"]}]},"sort":{"property":"ipAddress","direction":"ASCENDING"},"pagination":{"size":10,"offset":20,"containingId":"?"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
content | array | Response content |
content.file_name | string | Name of the resource |
content.file | string | Response content |
currentPage | object | Output field: currentPage |
currentPage.offset | number | Output field: currentPage.offset |
currentPage.size | number | Output field: currentPage.size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx","Date":"Fri, 11 Aug 2023 10:54:24 GMT","Content-Type":"application/json;charset=UTF-8","Content-Length":"302","Connection":"keep-alive","Set-Cookie":"AWSALB=Md0PTP8QFv/if/WeVr1FzmNI6rWtfxGbHvdrQmM+K6nlBcbmVaakg5xMo6y1QIPlB3E9efha8...","Vary":"Origin, Access-Control-Request-Method, Access-Control-Request-Headers","X-Correlation-Id":"7IHLF53RDJE9O","Cache-Control":"no-cache, no-store, must-revalidate","Expires":"Thu, 01 Jan 1970 00:00:00 GMT"...
Response Headers
Header | Description | Example |
|---|---|---|
Cache-Control | Directives for caching mechanisms | no-cache, no-store, must-revalidate |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Length | The length of the response body in bytes | 306 |
Content-Type | The media type of the resource | application/json;charset=UTF-8 |
Date | The date and time at which the message was originated | Fri, 11 Aug 2023 07:01:29 GMT |
Expires | The date/time after which the response is considered stale | Thu, 01 Jan 1970 00:00:00 GMT |
Pragma | HTTP response header: Pragma | no-cache |
Referrer-Policy | HTTP response header: Referrer-Policy | origin,strict-origin, origin,strict-origin |
Server | Information about the software used by the origin server | nginx |
Set-Cookie | HTTP response header: Set-Cookie | AWSALB=+J1qhF/qnR/uV7c7qMzNwYyfW4UAOlSo78LIKhzdPXhxyAggHV0YkpW98WJDRqUuQDacLl/YR5MauVtx477EaYB/x0QIgDOR81vHE+uaRE1GvyO9Bm5+8REtYmwd; Expires=Fri, 18 Aug 2023 09:36:59 GMT; Path=/, AWSALBCORS=+J1qhF/qnR/uV7c7qMzNwYyfW4UAOlSo78LIKhzdPXhxyAggHV0YkpW98WJDRqUuQDacLl/YR5MauVtx477EaYB/x0QIgDOR81vHE+uaRE1GvyO9Bm5+8REtYmwd; Expires=Fri, 18 Aug 2023 09:36:59 GMT; Path=/; SameSite=None; Secure |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000 ; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Origin, Access-Control-Request-Method, Access-Control-Request-Headers |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Correlation-Id | A unique identifier for correlating requests | 296LUNFBF8H14 |
X-RateLimit-default-Limit | HTTP response header: X-RateLimit-default-Limit | 60 |
X-RateLimit-default-Period | HTTP response header: X-RateLimit-default-Period | 60 |
X-RateLimit-default-Remaining | HTTP response header: X-RateLimit-default-Remaining | 60 |
X-RateLimit-Limit | The number of requests allowed in the current rate limit window | 60 |
X-RateLimit-Period | HTTP response header: X-RateLimit-Period | 60 |
X-RateLimit-Remaining | The number of requests remaining in the current rate limit window | 239 |
X-RateLimit-Reset | The time at which the current rate limit window resets | 1692006540 |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 1; mode=block |