Orca Security
Orca Security is a Cloud Posture Management product that alerts customers on vulnerabilities, configuration issues, and lateral movement challenges.
Prerequisites
This connector requires either an email and password or just an API token.
Capabilities
This connector provides the following capabilities:
- Get Alerts
- Get Alert by ID
- Get Assets
- Get Asset by ID
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
api_token | The API token | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Provide system account email here. | string | Required |
password | Password | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Get Alert ID
Retrieve information about an alert.
Endpoint
- URL: api/alerts/{{alert_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.alert_id | string | Required | Parameters for the Get Alert ID action |
Input Example
{"path_parameters":{"alert_id":1808008}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
status | string | Status value |
data_grouped | boolean | Response data |
total_supported_items | string | Output field: total_supported_items |
total_ungrouped_items | number | Output field: total_ungrouped_items |
total_items | number | Output field: total_items |
data | array | Response data |
data.file_name | string | Response data |
data.file | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Date":"Mon, 03 Jul 2023 07:14:22 GMT","Content-Type":"application/json","Content-Length":"141","Connection":"keep-alive","Server":"-","Vary":"Accept, Cookie, Origin","Allow":"GET, HEAD, OPTIONS","Access-Control-Expose-Headers":"x-orca-request-id","X-Orca-Request-Id":"5ad6b9ec-11e2-4554-a019-52d5fe404098","X-Amzn-Trace-Id":"Root=1-64a27546-5879da2e06884d6f6bb7bcb9","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","Referrer-Policy":"same-origin"},...
Get Alerts
Retrieve information about alerts.
Endpoint
- URL: api/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.asset_unique_id | string | Optional | Parameters for the Get Alerts action |
parameters.cloud_provider_id | string | Optional | Parameters for the Get Alerts action |
parameters.asset_type | string | Optional | Parameters for the Get Alerts action |
parameters.asset_state | string | Optional | Parameters for the Get Alerts action |
parameters.asset_labels | string | Optional | Parameters for the Get Alerts action |
parameters.type | string | Optional | Parameters for the Get Alerts action |
parameters.category | string | Optional | Parameters for the Get Alerts action |
parameters.alert_labels | string | Optional | Parameters for the Get Alerts action |
parameters.asset_role_names | string | Optional | Parameters for the Get Alerts action |
parameters.asset_ingress_ports | string | Optional | Parameters for the Get Alerts action |
parameters.asset_availability_zones | string | Optional | Parameters for the Get Alerts action |
parameters.asset_regions | string | Optional | Parameters for the Get Alerts action |
parameters.asset_vpcs | string | Optional | Parameters for the Get Alerts action |
parameters.asset_tags_info_list | string | Optional | Parameters for the Get Alerts action |
parameters.asset_orca_tags_info_list | string | Optional | Parameters for the Get Alerts action |
parameters.asset_custom_tags_info_list | string | Optional | Parameters for the Get Alerts action |
parameters.state.status | string | Optional | Parameters for the Get Alerts action |
parameters.state.orca_score | number | Optional | Parameters for the Get Alerts action |
parameters.state.risk_level | string | Optional | Parameters for the Get Alerts action |
parameters.state.score | number | Optional | Parameters for the Get Alerts action |
parameters.state.severity | string | Optional | Parameters for the Get Alerts action |
parameters.limit | string | Optional | Parameters for the Get Alerts action |
Input Example
{"parameters":{"asset_unique_id":"Asset Unique Id","cloud_provider_id":"Cloud Provider Id","asset_type":"Asset Type","asset_state":"Asset State","asset_labels":"Asset Labels","type":"Type","category":"Category","alert_labels":"Alert Labels","asset_role_names":"Asset Role Names","asset_ingress_ports":"Asset Ingress Ports","asset_availability_zones":"Asset Availability Zones","asset_regions":"Asset Regions","asset_vpcs":"Asset vpcs","asset_tags_info_list":"Asset Tags Info List","asset_orca_tags_info_list":"Asset Orca Tags Info List","asset_custom_tags_info_list":"Asset Custom Tags Info List","state.status":"State Status","state.orca_score":10,"state.risk_level":"critical","state.score":20,"state.severity":"State Severity","limit":"900"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
status | string | Status value |
total_items | number | Output field: total_items |
total_ungrouped_items | number | Output field: total_ungrouped_items |
data_grouped | boolean | Response data |
total_supported_items | string | Output field: total_supported_items |
data | array | Response data |
data.group_val | string | Response data |
data.asset_type_string | string | Response data |
data.data | object | Response data |
data.data.recommendation | string | Response data |
data.data.details | string | Response data |
data.data.title | string | Response data |
data.alert_labels | array | Response data |
data.configuration | object | Response data |
data.is_compliance | boolean | Response data |
data.group_type_string | string | Response data |
data.description | string | Response data |
data.recommendation | string | Response data |
data.source | string | Response data |
data.group_type | string | Response data |
data.cluster_type | string | Response data |
data.type | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Date":"Mon, 03 Jul 2023 07:14:22 GMT","Content-Type":"application/json","Content-Length":"141","Connection":"keep-alive","Server":"-","Vary":"Accept, Cookie, Origin","Allow":"GET, HEAD, OPTIONS","Access-Control-Expose-Headers":"x-orca-request-id","X-Orca-Request-Id":"5ad6b9ec-11e2-4554-a019-52d5fe404098","X-Amzn-Trace-Id":"Root=1-64a27546-5879da2e06884d6f6bb7bcb9","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","Referrer-Policy":"same-origin"},...
Get Asset Unique ID
Retrieve information about an asset.
Endpoint
- URL: api/assets/{{asset_unique_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.asset_unique_id | string | Required | Parameters for the Get Asset Unique ID action |
Input Example
{"path_parameters":{"asset_unique_id":1808008}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
status | string | Status value |
data_grouped | boolean | Response data |
total_supported_items | string | Output field: total_supported_items |
total_ungrouped_items | number | Output field: total_ungrouped_items |
total_items | number | Output field: total_items |
data | array | Response data |
data.file_name | string | Response data |
data.file | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Date":"Mon, 03 Jul 2023 07:14:22 GMT","Content-Type":"application/json","Content-Length":"141","Connection":"keep-alive","Server":"-","Vary":"Accept, Cookie, Origin","Allow":"GET, HEAD, OPTIONS","Access-Control-Expose-Headers":"x-orca-request-id","X-Orca-Request-Id":"5ad6b9ec-11e2-4554-a019-52d5fe404098","X-Amzn-Trace-Id":"Root=1-64a27546-5879da2e06884d6f6bb7bcb9","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","Referrer-Policy":"same-origin"},...
Get Assets
Retrieve information about assets.
Endpoint
- URL: api/assets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.asset_unique_id | string | Optional | Parameters for the Get Assets action |
parameters.cloud_provider_id | string | Optional | Parameters for the Get Assets action |
parameters.asset_type | string | Optional | Parameters for the Get Assets action |
parameters.asset_state | string | Optional | Parameters for the Get Assets action |
parameters.asset_labels | string | Optional | Parameters for the Get Assets action |
parameters.type | string | Optional | Parameters for the Get Assets action |
parameters.internet_facing | string | Optional | Parameters for the Get Assets action |
parameters.tags_info_list | string | Optional | Parameters for the Get Assets action |
parameters.orca_tags_info_list | string | Optional | Parameters for the Get Assets action |
parameters.custom_tags_info_list | string | Optional | Parameters for the Get Assets action |
parameters.compute.regions | string | Optional | Parameters for the Get Assets action |
parameters.compute.vpcs | string | Optional | Parameters for the Get Assets action |
parameters.state.orca_score | number | Optional | Parameters for the Get Assets action |
parameters.state.risk_level | string | Optional | Parameters for the Get Assets action |
parameters.state.score | number | Optional | Parameters for the Get Assets action |
parameters.state.severity | string | Optional | Parameters for the Get Assets action |
Input Example
{"parameters":{"asset_unique_id":"Asset Unique Id","cloud_provider_id":"Cloud Provider Id","asset_type":"Asset Type","asset_state":"Asset State","asset_labels":"Asset Labels","type":"Type","internet_facing":"Internet Facing","tags_info_list":"Tags Info List","orca_tags_info_list":"Orca Tags Info List","custom_tags_info_list":"Custom Tags Info List","compute.regions":"Compute Regions","compute.vpcs":"Compute vpcs","state.orca_score":0,"state.risk_level":"critical","state.score":1,"state.severity":"State Severity"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
version | string | Output field: version |
status | string | Status value |
total_items | number | Output field: total_items |
total_ungrouped_items | number | Output field: total_ungrouped_items |
data_grouped | boolean | Response data |
total_supported_items | string | Output field: total_supported_items |
data | array | Response data |
data.Vm | object | Response data |
data.Vm.ImageName | string | Response data |
data.Vm.ImageOwnerId | string | Response data |
data.Vm.ImageIsPublic | string | Response data |
data.Vm.ImageId | string | Response data |
data.Vm.ImageDescription | string | Response data |
data.Vm.InstanceType | string | Response data |
data.Vm.Name | string | Response data |
data.Compute | object | Response data |
data.Compute.SecurityGroups | array | Response data |
data.Compute.DistributionInfoSite | string | Response data |
data.Compute.VpcList | object | Response data |
data.Compute.VpcList.models | array | Response data |
data.Compute.VpcList.models.model | object | Response data |
data.Compute.VpcList.remaining | number | Response data |
data.Compute.PrivateDnss | array | Response data |
Output Example
{"status_code":200,"response_headers":{"Date":"Mon, 03 Jul 2023 07:14:22 GMT","Content-Type":"application/json","Content-Length":"141","Connection":"keep-alive","Server":"-","Vary":"Accept, Cookie, Origin","Allow":"GET, HEAD, OPTIONS","Access-Control-Expose-Headers":"x-orca-request-id","X-Orca-Request-Id":"5ad6b9ec-11e2-4554-a019-52d5fe404098","X-Amzn-Trace-Id":"Root=1-64a27546-5879da2e06884d6f6bb7bcb9","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","Referrer-Policy":"same-origin"},...
Response Headers
Header | Description | Example |
|---|---|---|
Access-Control-Expose-Headers | HTTP response header: Access-Control-Expose-Headers | x-orca-request-id |
Allow | HTTP response header: Allow | GET, HEAD, OPTIONS |
Connection | HTTP response header: Connection | keep-alive |
Content-Length | The length of the response body in bytes | 141 |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Mon, 03 Jul 2023 07:14:22 GMT |
Referrer-Policy | HTTP response header: Referrer-Policy | same-origin |
Server | Information about the software used by the origin server | - |
Vary | HTTP response header: Vary | Accept, Cookie, Origin |
X-Amzn-Trace-Id | HTTP response header: X-Amzn-Trace-Id | Root=1-64a27546-5879da2e06884d6f6bb7bcb9 |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | DENY |
X-Orca-Request-Id | HTTP response header: X-Orca-Request-Id | 5ad6b9ec-11e2-4554-a019-52d5fe404098 |