SecureWorks Taegis Magic
SecureWorks Taegis Magic is a security operations platform that streamlines threat detection, investigation, and response through automation and orchestration.
SecureWorks Taegis Magic is a cloud-native security operations and threat detection platform that empowers organizations to investigate, respond to, and manage security incidents. This connector enables Swimlane Turbine users to automate key security operations tasks in Taegis Magic, including searching and managing alerts, investigations, and evidence, as well as orchestrating playbook actions and running advanced queries. By integrating SecureWorks Taegis Magic with Swimlane Turbine, security teams can streamline incident response, accelerate investigations, and enhance collaborationβall without writing code. This integration helps reduce manual effort, improve response times, and ensure consistent, auditable security workflows.
Limitations
- This connector wraps the official taegis-magic CLI (taegis binary). It does not call Taegis GraphQL from connector Python.
- Interactive taegis auth login / device-code login is not supported.
Supported Versions
- This connector uses latest version.
Additional Documents
- Documentation Taegis Magic CLI
- Related GraphQL connector: secureworks_taegis (both can coexist)
Configuration
Prerequisites
To use the SecureWorks Taegis Magic connector, ensure you have the following prerequisites:
- OAuth2 client credentials authentication for the taegis-magic CLI, requiring:
- URL: The base endpoint for accessing the SecureWorks Taegis Magic API.
- Client ID: The unique identifier for your application or integration.
- Client Secret: The secret key associated with your client ID for secure authentication.
- Region: The geographic region where your Taegis Magic instance is hosted.
Authentication Methods
- URL: Taegis API base URL (for example https://api.delta.taegis.secureworks.com/).
- Client ID: Taegis OAuth client ID (mapped to CLIENT_ID for the CLI).
- Client Secret: Taegis OAuth client secret (mapped to CLIENT_SECRET for the CLI).
- Region: Default Taegis region for CLI --region.
- Tenant (optional): Default tenant context for CLI --tenant.
- Use Universal Auth (optional): Enables universal authentication for the CLI/SDK when true.
- Command Timeout (seconds) (optional): Hard kill timeout for hung CLI commands (default 300).
- Default Search Limit (optional): Default --limit for alert/investigation search (default 500).
- HTTP(s) Proxy (optional): Proxy URL applied as HTTPS_PROXY / HTTP_PROXY.
- Verify SSL Certificates (optional): Documented for parity; CLI/SDK may not honor this flag.
Setup instructions
- In SecureWorks Taegis, create or select an OAuth2 client application for your tenant.
- Copy the Client ID and Client Secret.
- Set URL to the regional Taegis API host for your environment, for example:
- https://api.ctpx.secureworks.com/ (US1)
- https://api.delta.taegis.secureworks.com/ (US2)
- https://api.echo.taegis.secureworks.com/ (EU)
- Set Region to match that environment (for example delta).
- Optionally set Tenant if your playbooks need a default --tenant context.
- Optionally configure proxy, timeout, and default search limit as needed.
If authentication fails, verify Client ID / Client Secret, region, API URL, and network egress to the Taegis regional API host.
Capabilities
This Connector provides the following capabilities:
- Add Investigation Comment
- Append Evidence
- Create Investigation
- Execute Playbook Action
- Run Raw Command
- Search Alerts
- Search Events
- Search Investigations
- Show Staged Evidence
- Stage Investigation Evidence
Add Investigation Comment
- Add a comment to an existing investigation (taegis investigations comment add).
Append Evidence
- Append previously staged evidence to an existing investigation (taegis investigations evidence append).
Create Investigation
- Create a Taegis investigation from a title and key findings (markdown string or Turbine attachment) (taegis investigations create).
Execute Playbook Action
- Execute a Taegis orchestration playbook action (taegis orchestration execute_playbook_action).
Run Raw Command
- Run an allowlisted passthrough CLI command for Dell CLI fidelity (taegis <argv...>).
Search Alerts
- Search SecureWorks Taegis alerts with CQL (taegis alerts search).
Search Events
- Search SecureWorks Taegis events with CQL (taegis events search).
Search Investigations
- Search SecureWorks Taegis investigations with CQL (taegis investigations search).
Show Staged Evidence
- Display staged investigation evidence from the local evidence database (taegis investigations evidence show).
Stage Investigation Evidence
- Stage alerts, events, or search queries for investigation workflows using JSON or a Turbine file attachment (taegis investigations evidence stage).
Configurations
Secureworks Taegis Magic Client Credentials
Authenticates the taegis-magic CLI using OAuth2 client credentials (CLIENT_ID / CLIENT_SECRET). Does not use interactive device-code login.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | Taegis API base URL for the target environment (e.g. https://api.delta.taegis.secureworks.com/). | string | Required |
client_id | Taegis OAuth client ID. Mapped to env CLIENT_ID for the CLI. | string | Required |
client_secret | Taegis OAuth client secret. Mapped to env CLIENT_SECRET for the CLI. | string | Required |
region | Default Taegis region for CLI --region (e.g. charlie, delta, echo). | string | Required |
tenant | Optional default tenant context for CLI --tenant. | string | Optional |
use_universal_auth | When true, enables universal authentication for the CLI/SDK. | boolean | Optional |
command_timeout_seconds | Hard kill timeout for hung CLI commands. | number | Optional |
default_limit | Default --limit for alert/investigation search when not provided on the action. | number | Optional |
http_proxy | Proxy URL applied as HTTPS_PROXY / HTTP_PROXY for the CLI process. | string | Optional |
verify_ssl | Verify SSL certificates (documented for parity; CLI/SDK may not honor this flag). | boolean | Optional |
Actions
Add Investigation Comment
Add a comment to an investigation in SecureWorks Taegis Magic by specifying the investigation ID and comment text.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
investigation_id | string | Required | Unique identifier |
comment | string | Required | Comment body passed to --cell. |
region | string | Optional | Parameter for Add Investigation Comment |
tenant | string | Optional | Parameter for Add Investigation Comment |
debug | boolean | Optional | Parameter for Add Investigation Comment |
Input Example
{"investigation_id":"string","comment":"string","region":"string","tenant":"string","debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Append Evidence
Add staged evidence to an existing investigation in SecureWorks Taegis Magic using the specified investigation ID.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
investigation_id | string | Required | Unique identifier |
use_new | boolean | Optional | Pass --use-new when true. |
region | string | Optional | Parameter for Append Evidence |
tenant | string | Optional | Parameter for Append Evidence |
debug | boolean | Optional | Parameter for Append Evidence |
Input Example
{"investigation_id":"string","use_new":true,"region":"string","tenant":"string","debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Create Investigation
Initiate a new investigation in SecureWorks Taegis by specifying a title and including key findings as either a markdown string or file attachment.
Input
Argument Name | Type | Required | Description | ||||
|---|---|---|---|---|---|---|---|
title | string | Required | Parameter for Create Investigation | ||||
key_findings | string | Optional | Markdown string. Use this or key_findings_file. | ||||
key_findings_file | object | Optional | Turbine attachment (markdown). Same pattern as VirusTotal Analyse File input. | ||||
key_findings_file.file | string | Optional | Parameter for Create Investigation | ||||
key_findings_file.file_name | string | Optional | Name of the resource | ||||
priority | string | Optional | Parameter for Create Investigation | ||||
type | string | Optional | Type of the resource | ||||
status | string | Optional | Status value | ||||
assignee_id | string | Optional | @me | @partner | @tenant | id | |
dry_run | boolean | Optional | Parameter for Create Investigation | ||||
region | string | Optional | Parameter for Create Investigation | ||||
tenant | string | Optional | Parameter for Create Investigation | ||||
debug | boolean | Optional | Parameter for Create Investigation |
Input Example
{"title":"Suspicious AWS Account Enumeration"}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Execute Playbook Action
Execute a SecureWorks Taegis orchestration playbook action by specifying the playbook action ID and target resource ID, with optional investigation ID and additional parameters.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
playbook_action_id | string | Required | Unique identifier |
target_resource_id | string | Required | Unique identifier |
investigation_id | string | Optional | Unique identifier |
additional_inputs | string | Optional | Object or JSON string passed to --additional-inputs. |
reason | string | Optional | Response reason phrase |
region | string | Optional | Parameter for Execute Playbook Action |
tenant | string | Optional | Parameter for Execute Playbook Action |
debug | boolean | Optional | Parameter for Execute Playbook Action |
Input Example
{"playbook_action_id":"string","target_resource_id":"string","investigation_id":"string","additional_inputs":"string","region":"string","tenant":"string","debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Run Raw Command
Execute allowlisted passthrough Dell CLI commands in SecureWorks Taegis Magic using specified arguments, excluding authentication and non-allowlisted subcommands.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
argv | array | Required | Array of strings after taegis, e.g. ["alerts", "history", "--id", "alert://..."]. |
region | string | Optional | If set and --region is not already in argv, append --region. |
tenant | string | Optional | If set and --tenant is not already in argv, append --tenant. |
debug | boolean | Optional | Parameter for Run Raw Command |
Input Example
{"argv":["alerts","history","--id","alert://example"]}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Search Alerts
Search for SecureWorks Taegis alerts using CQL, with options for limit, region, tenant, track, and GraphQL output. Requires specifying the cell.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
cell | string | Required | CQL query string passed to --cell. |
limit | number | Optional | Max results (--limit). Defaults to asset default_limit (500). |
region | string | Optional | Parameter for Search Alerts |
tenant | string | Optional | Parameter for Search Alerts |
track | boolean | Optional | When true, pass --track. Connector creates an ephemeral DB inside the container for this action only. |
graphql_output | string | Optional | Optional --graphql-output value. |
save_as_file | boolean | Optional | When true, also return results as a Turbine output attachment (file). |
debug | boolean | Optional | Parameter for Search Alerts |
Input Example
{"cell":"FROM alert WHERE status = 'OPEN' EARLIEST=-1d | head 50"}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
file | object | Optional JSON results attachment when save_as_file is true. |
file.file | string | Output field: file.file |
file.file_name | string | Name of the resource |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string","file":{"file":"string","file_name":"Example Name"}}
Search Events
Search for events in SecureWorks Taegis using CQL by specifying the cell parameter to filter and retrieve relevant event data.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
cell | string | Required | CQL query string passed to --cell. |
region | string | Optional | Parameter for Search Events |
tenant | string | Optional | Parameter for Search Events |
track | boolean | Optional | Parameter for Search Events |
save | boolean | Optional | Pass --save when true. |
save_as_file | boolean | Optional | When true, also return results as a Turbine output attachment (file). |
debug | boolean | Optional | Parameter for Search Events |
Input Example
{"cell":"string","region":"string","tenant":"string","track":true,"save":true,"save_as_file":true,"debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
file | object | Optional JSON results attachment when save_as_file is true. |
file.file | string | Output field: file.file |
file.file_name | string | Name of the resource |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string","file":{"file":"string","file_name":"Example Name"}}
Search Investigations
Search SecureWorks Taegis investigations using CQL, with optional parameters for limit, region, and tenant to refine your results.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
cell | string | Required | CQL WHERE-style filter used by the CLI. |
limit | number | Optional | Parameter for Search Investigations |
region | string | Optional | Parameter for Search Investigations |
tenant | string | Optional | Parameter for Search Investigations |
debug | boolean | Optional | Parameter for Search Investigations |
Input Example
{"cell":"string","limit":123,"region":"string","tenant":"string","debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Show Staged Evidence
Display staged investigation evidence from the local database in SecureWorks Taegis Magic, equivalent to the CLI command: taegis investigations evidence show.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
investigation_id | string | Optional | Unique identifier |
region | string | Optional | Parameter for Show Staged Evidence |
tenant | string | Optional | Parameter for Show Staged Evidence |
debug | boolean | Optional | Parameter for Show Staged Evidence |
Input Example
{"investigation_id":"string","region":"string","tenant":"string","debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Stage Investigation Evidence
Stage alerts, events, or search queries as investigation evidence in SecureWorks Taegis Magic using the specified evidence type and file attachments.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
evidence_type | string | Required | Evidence kind to stage. |
evidence_json | string | Optional | Array/object to stage (playbook JSON). Use this or files attachment. |
files | object | Optional | Turbine attachment containing JSON evidence (VirusTotal-style files input). |
files.file | string | Optional | Parameter for Stage Investigation Evidence |
files.file_name | string | Optional | Name of the resource |
investigation_id | string | Optional | Defaults to NEW when omitted. |
region | string | Optional | Parameter for Stage Investigation Evidence |
tenant | string | Optional | Parameter for Stage Investigation Evidence |
debug | boolean | Optional | Parameter for Stage Investigation Evidence |
Input Example
{"evidence_type":"string","evidence_json":"string","files":{"file":"string","file_name":"Example Name"},"investigation_id":"string","region":"string","tenant":"string","debug":true}
Output
Parameter | Type | Description |
|---|---|---|
exit_code | number | Output field: exit_code |
stdout_raw | string | Output field: stdout_raw |
stderr_raw | string | Output field: stderr_raw |
data | string | Response data |
command | array | Output field: command |
region | string | Output field: region |
tenant | string | Output field: tenant |
error_message | string | Response message |
Output Example
{"exit_code":123,"stdout_raw":"string","stderr_raw":"string","data":"string","command":[],"region":"string","tenant":"string","error_message":"string"}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |