Port0 Soc0 Connector
Port0 Soc0 is a security operations platform that streamlines threat detection, investigation, and response.
Port0 Soc0 is a comprehensive security operations platform designed to streamline threat detection and response. This connector enables seamless integration with Swimlane Turbine, allowing users to automate investigations, manage detections, and interact with security agents efficiently. By leveraging Port0 Soc0's capabilities, Swimlane Turbine users can enhance their security workflows, reduce manual intervention, and improve response times to potential threats.
Supported Version
Supports the latest version (v1).
Additional Documents
Prerequisites
Before you can use the Port0 Soc0 connector for Turbine, you'll need access to the Port0 Soc0 API. This requires the following:
- an API key authentication using the following parameters:
- URL: The endpoint for accessing Port0 Soc0 services.
- API Key: A unique key provided by Port0 Soc0 for authenticating API requests.
Authentication Methods
API Key Authentication Method.
API key authentication using the following parameters:
- URL: The endpoint URL for accessing the Port0 Soc0 API.
- API Key: A unique key provided by Port0 Soc0 for authenticating API requests.
Capabilities
This Port0 Soc0 Connector provides the following capabilities:
- Create Custom Investigation
- Create Investigation
- Get Investigation by ID
- Get Message Token Count
- List Detections
- List Investigations
- Send Message to Soc0
Create Custom Investigation
- Start an investigation for a detection that lives outside Soc0, supplying its metadata inline.
Create Investigation
- Start an investigation for an existing detection by ID and source.
Get Investigation by ID
- Fetch a single investigation by ID, including results once complete.
Get Message Token Count
- Count the tokens a request would consume without running the agent.
List Detections
- List detections, optionally filtered and paginated by various criteria.
List Investigations
- List investigations, optionally filtered and paginated by various criteria.
Send Message to Soc0
- Send messages to the Soc0 security agent. Set stream - true for a streamed response.
Configurations
Port0 API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
x-api-key | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create Custom Investigation
Start an investigation for a detection outside Port0 Soc0 by supplying its metadata inline.
Endpoint
- URL: api/v1/investigations/custom
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
detection_id | string | Optional | Unique identifier |
source | string | Optional | Parameter for Create Custom Investigation |
metadata | object | Optional | Response data |
metadata.title | string | Optional | Response data |
metadata.severity | string | Optional | Response data |
metadata.host | string | Optional | Response data |
metadata.raw_event | object | Optional | Response data |
metadata.raw_event.pid | number | Optional | Response data |
metadata.raw_event.command | string | Optional | Response data |
Input Example
{"json_body":{"detection_id":"custom-det-001","source":"my-siem","metadata":{"title":"Suspicious process execution","severity":"high","host":"workstation-01","raw_event":{"pid":1234,"command":"powershell.exe"}}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
investigation_id | string | Unique identifier |
status | string | Status value |
url | string | URL endpoint for the request |
already_exists | boolean | Output field: already_exists |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"investigation_id":"INV-a1b2c3d4...","status":"pending","url":"https://app.soc0.ai/investigations/INV-a1b2c3d4...","already_exists":false}}
Create Investigation
Start an investigation for an existing detection by ID and source in Port0 Soc0 using the provided JSON body.
Endpoint
- URL: api/v1/investigations
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
detection_id | string | Optional | Unique identifier |
source | string | Optional | Parameter for Create Investigation |
Input Example
{"json_body":{"detection_id":"det_abc123","source":"port0"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
investigation_id | string | Unique identifier |
status | string | Status value |
url | string | URL endpoint for the request |
already_exists | boolean | Output field: already_exists |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"investigation_id":"INV-a1b2c3d4...","status":"pending","url":"https://app.soc0.ai/investigations/INV-a1b2c3d4...","already_exists":false}}
Get Investigation by ID
Fetch a single investigation by ID in Port0 Soc0, including results once complete. Requires the 'id' as a path parameter.
Endpoint
- URL: api/v1/investigations/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The ID of the investigation. |
Input Example
{"path_parameters":{"id":"INV-a1b2c3d4"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
investigation_id | string | Unique identifier |
detection_id | string | Unique identifier |
detection_source | string | Output field: detection_source |
status | string | Status value |
url | string | URL endpoint for the request |
created_at | string | Output field: created_at |
content | string | Response content |
result_severity | string | Result of the operation |
result_resolution | string | Result of the operation |
result_notes | string | Result of the operation |
result_suggestions | array | Result of the operation |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"investigation_id":"INV-a1b2c3d4...","detection_id":"det_abc123","detection_source":"port0","status":"complete","url":"https://app.soc0.ai/investigations/INV-a1b2c3d4...","created_at":"2026-03-11T14:30:00Z","content":"## Investigation Summary\n...","result_severity":"high","result_resolution":"true_positive","result_notes":"Confirmed malicious activity...","result_suggestions":["Isolate host","Reset credentials"]}}
Get Message Token Count
Count the tokens a request would consume in Port0 Soc0 without running the agent. Requires 'messages' in JSON body.
Endpoint
- URL: api/v1/messages/count_tokens
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
messages | array | Optional | Response message |
messages.role | string | Optional | Response message |
messages.content | string | Optional | Response content |
Input Example
{"json_body":{"messages":[{"role":"user","content":"Analyze this security alert ..."}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
tokens | number | Output field: tokens |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"tokens":24}}
List agent tools
List available agent tools and their JSON input schema in Port0 Soc0, requiring the tools:read scope.
Endpoint
- URL: api/v1/tools
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
tools | array | Output field: tools |
tools.name | string | Name of the resource |
tools.description | string | Output field: tools.description |
tools.input_schema | object | Input data for the action |
tools.input_schema.type | string | Input data for the action |
tools.input_schema.properties | object | Input data for the action |
tools.input_schema.properties.status | object | Input data for the action |
tools.input_schema.properties.status.type | string | Input data for the action |
tools.input_schema.properties.limit | object | Input data for the action |
tools.input_schema.properties.limit.type | string | Input data for the action |
total | number | Output field: total |
Output Example
{"status_code":200,"reason":"OK","json_body":{"tools":[{}],"total":1}}
List Detections
List detections in Port0 Soc0 with optional filtering and pagination by various criteria.
Endpoint
- URL: api/v1/detections
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.id | string | Optional | Filter by a single detection ID. |
parameters.severity | string | Optional | Filter by severity. |
parameters.status | string | Optional | Filter by detection status (e.g. new, open). |
parameters.category | string | Optional | Filter by category. |
parameters.host | string | Optional | Filter by affected host. |
parameters.assignee | string | Optional | Filter by assignee. |
parameters.soc0_status | string | Optional | Filter by the Soc0 investigation status. |
parameters.date_from | string | Optional | Lower bound (ISO 8601) on detection time. |
parameters.date_to | string | Optional | Upper bound (ISO 8601) on detection time. |
parameters.sort_by | string | Optional | Field to sort by. |
parameters.sort_order | string | Optional | Sort direction. |
parameters.page | number | Optional | Page number (1-indexed). |
parameters.page_size | number | Optional | Items per page. |
Input Example
{"parameters":{"id":"det_a1b2c3...","severity":"medium","status":"new","category":"new category","host":"example.com","assignee":"[email protected]","soc0_status":"open","date_from":"1966-07-01T04:23:48.671Z","date_to":"1966-07-01T04:23:48.671Z","sort_by":"created_at","sort_order":"desc","page":1,"page_size":10}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
total | number | Output field: total |
page | number | Output field: page |
page_size | number | Output field: page_size |
items | array | Output field: items |
items.id | string | Unique identifier |
items.title | string | Output field: items.title |
items.severity | string | Output field: items.severity |
items.status | string | Status value |
items.category | string | Output field: items.category |
items.source | string | Output field: items.source |
items.host | string | Output field: items.host |
items.risk_score | number | Score value |
items.soc0_status | string | Status value |
items.soc0_resolution_type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"total":343,"page":1,"page_size":20,"items":[{}]}}
List Investigations
List investigations in Port0 Soc0 with optional filtering and pagination by various criteria.
Endpoint
- URL: api/v1/investigations
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | Page number (1-indexed). |
parameters.page_size | number | Optional | Items per page. |
Input Example
{"parameters":{"page":1,"page_size":20}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
investigations | array | Output field: investigations |
investigations.investigation_id | string | Unique identifier |
investigations.detection_id | string | Unique identifier |
investigations.detection_title | string | Output field: investigations.detection_title |
investigations.detection_source | string | Output field: investigations.detection_source |
investigations.status | string | Status value |
investigations.result_severity | string | Result of the operation |
investigations.url | string | URL endpoint for the request |
investigations.created_at | string | Output field: investigations.created_at |
page | number | Output field: page |
page_size | number | Output field: page_size |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"investigations":[{}],"page":1,"page_size":20,"total":1}}
Run an agent tool
Execute a specified agent tool by name in Port0 Soc0 using JSON input. Ensure tools:write scope is available to avoid a 403 error.
Endpoint
- URL: api/v1/tools/{{name}}/call
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.name | string | Required | Parameters for the Run an agent tool action |
input | object | Optional | Input data for the action |
input.status | string | Optional | Input data for the action |
input.limit | number | Optional | Input data for the action |
Input Example
{"json_body":{"input":{"status":"open","limit":5}},"path_parameters":{"name":"get_cases"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
tool | string | Output field: tool |
result | object | Result of the operation |
result.count | number | Result of the operation |
result.cases | array | Result of the operation |
result.cases.id | string | Unique identifier |
result.cases.name | string | Name of the resource |
is_error | boolean | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"tool":"get_cases","result":{"count":1,"cases":[]},"is_error":false}}
Send Message to Soc0
Send messages to the Soc0 security agent with an option for a streamed response. Requires 'messages' in JSON body.
Endpoint
- URL: api/v1/messages
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
messages | array | Optional | Response message |
messages.role | string | Optional | Response message |
messages.content | string | Optional | Response content |
Input Example
{"json_body":{"messages":[{"role":"user","content":"Analyze this security alert ..."}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
text | string | Output field: text |
finish_reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"req_a1b2c3...","text":"Based on the security alert provided...","finish_reason":"complete"}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |