Sekoia Defend (XDR)
The Sekoia Defend (XDR) connector enables automated interactions with the Sekoia Defend platform, facilitating advanced threat detection and response through Swimlane Turbine.
Sekoia Defend (XDR) is a cutting-edge security platform that specializes in event search and asset management, providing a comprehensive view of an organization's security posture. This connector enables Swimlane Turbine users to automate the integration of Sekoia Defend's capabilities into their security workflows. By leveraging this connector, users can initiate event search jobs, retrieve detailed asset and community information, and manage alert workflows, enhancing their threat detection and response strategies.
Sekoia Defend (XDR) connector is an extended Detection and Response platform that automates your SOC. It manages alerts produced by SIC engines.
Prerequisites
Before integrating Sekoia Defend (XDR) with Swimlane Turbine, ensure you have the following prerequisites:
- HTTP Bearer Token Authentication with the following parameters:
- URL: Endpoint URL for Sekoia Defend (XDR) API
- The API key: A valid API key for authenticating requests to Sekoia Defend (XDR)
Capabilities
This connector provides the following capabilities:
- Create an Event Search Job
- Get a Community
- Get a Cyber Kill Chain Stage
- Get an Asset by UUID
- Get an Event Search Job
- Get the Events Found by an Event Search Job
- Get the Fields of the Events
- Get the Timeline of an Alert by its UUID
- List Alerts
- Search Assets
- Trigger an Action on the Alert Workflow
- Triggers a Status Update on a List of Alerts
API Documentation Link
Additional Notes
- If you are using the Get a Cyber Kill Chain Stage action, then please provide the following mentioned permissions and follow this Action related API Documentation Link.
- βView alertsβ (9ea2b8a3-593f-4bab-92f5-d0af9b563f6f)
- If you are using the Trigger an Action on the Alert Workflow action, then please provide the following mentioned permissions and follow this Action related API Documentation Link.
- βUpdate alert statusβ (9f3df1b1-4db7-44bd-b615-af5873ad7f8a)
- If you are using the Get the Timeline of an Alert by its UUID action, then please provide the following mentioned permissions and follow this Action related API Documentation Link.
- βView alertsβ (9ea2b8a3-593f-4bab-92f5-d0af9b563f6f)
- The action_uuid (also referred to as status_uuid in this table) represents a unique identifier (UUID) for different alert statuses. Available Action UUIDs for Status Updates.
Action | Description | action_uuid |
|---|---|---|
Pending | This alert needs to be addressed. | 2efc4930-1442-4abb-acf2-58ba219a4fd0 |
Acknowledge | Alert will be evaluated (true or false positive?). | 8f206505-af6d-433e-93f4-775d46dc7d0f |
Ongoing | Alert might be a true positive, action must be taken. | 1f2f88d5-ff5b-48bf-bbbc-00c2fff82d9f |
Reject | It is a false positive or will not be addressed. | 4f68da89-38e0-4703-a6ab-652f02bdf24e |
Close | It was a true positive, and the alert has been addressed. | 1738b1c1-767d-489e-bada-19176621a007 |
Configurations
Sekoia Defend (XDR) HTTP Bearer Authentication
Authenticates using bearer token such as a JWT, etc.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The API key. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create an Event Search Job
Initiates a search job for events within Sekoia Defend (XDR) based on specified UTC time boundaries.
Endpoint
- URL: /v1/sic/conf/events/search/jobs
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
term | string | Optional | Event search term |
term_lang | string | Optional | Optional language of the event search term. If undefined and term is not a valid dork search, falls back to es-query-string search mode. |
ο»Ώ | |||
filters | array | Optional | List of filters to apply |
filters.field | string | Optional | Field to filter |
filters.value | object | Optional | Value that the field should have |
filters.operator | string | Optional | Filter operator. Supported values: '=', 'startswith', 'endswith', 'contains', 'exists', '>', '>=', '<', '<='. |
ο»Ώ | |||
filters.excluded | boolean | Optional | Should matches be excluded? |
filters.disabled | boolean | Optional | Is this filter disabled? |
earliest_time | string | Optional | Earliest time of the time range of the search |
latest_time | string | Optional | Latest time of the time range of the search |
results_ttl | number | Optional | The job time to leave (allowed range is 10-86400), default is 1800. |
ο»Ώ | |||
view_uuid | string | Optional | The identifier of the view to be used for searching events |
visible | boolean | Optional | Define if the job should be retrievable |
only_eternal | boolean | Optional | Only search inside eternal events |
community_uuids | array | Optional | List of community UUIDs |
max_last_events | number | Optional | Maximum number of listed events |
date_field | string | Optional | Optional name of the field used for the event's date boundaries. '@timestamp' is used by default. |
ο»Ώ | |||
storage | string | Optional | Kind of storage to search. Supported values: 'hot', 'archives'. Default is 'hot'. |
ο»Ώ |
Input Example
{"json_body":{"term":"term","term_lang":"dork","filters":[{"field":"field","value":null,"operator":"=","excluded":true,"disabled":true}],"earliest_time":"earliest time","latest_time":"latest time","results_ttl":10,"view_uuid":"view uuid","visible":true,"only_eternal":true,"community_uuids":["community uuids"],"max_last_events":0,"date_field":"@timestamp","storage":"hot"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
uuid | string | Unique identifier |
status | number | Status value |
total | number | Output field: total |
retrieved | number | Output field: retrieved |
term | string | Output field: term |
term_lang | string | Output field: term_lang |
filters | array | Output field: filters |
filters.field | string | Output field: filters.field |
filters.value | object | Value for the parameter |
filters.operator | string | Output field: filters.operator |
filters.excluded | boolean | Output field: filters.excluded |
filters.disabled | boolean | Output field: filters.disabled |
created_by | string | Output field: created_by |
created_by_type | string | Type of the resource |
created_at | string | Output field: created_at |
started_at | string | Output field: started_at |
canceled_by | string | Output field: canceled_by |
canceled_by_type | string | Type of the resource |
canceled_at | string | Output field: canceled_at |
ended_at | string | Output field: ended_at |
earliest_time | string | Time value |
latest_time | string | Time value |
results_ttl | number | Result of the operation |
Output Example
{"status_code":200,"reason":"OK","json_body":{"uuid":"ae0e6607-8c52-4243-a7a1-b3e8a10d3852","status":0,"total":0,"retrieved":0,"term":"term","term_lang":"term lang","filters":[{}],"created_by":"created by","created_by_type":"created by type","created_at":"2025-05-08T06:46:55.856Z","started_at":"2025-05-08T06:46:55.856Z","canceled_by":"canceled by","canceled_by_type":"canceled by type","canceled_at":"2025-05-08T06:46:55.856Z","ended_at":"2025-05-08T06:46:55.856Z"}}
Get a Community
Retrieve detailed information about a specific community in Sekoia Defend (XDR) using the community UUID.
Endpoint
- URL: /v1/communities/{{community_uuid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.community_uuid | string | Required | The Unique Identifier of the community. |
Input Example
{"path_parameters":{"community_uuid":"7ea88310-b725-4de6-9035-0f6739dfcf8a"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
licenses | array | Output field: licenses |
licenses.uuid | string | Unique identifier |
licenses.license_type | string | Type of the resource |
licenses.plan | object | Output field: licenses.plan |
licenses.plan.uuid | string | Unique identifier |
licenses.plan.title | string | Output field: licenses.plan.title |
licenses.plan.required_properties | array | Output field: licenses.plan.required_properties |
licenses.plan.optional_properties | array | Output field: licenses.plan.optional_properties |
licenses.plan.limits | array | Output field: licenses.plan.limits |
licenses.plan.module | object | Output field: licenses.plan.module |
licenses.plan.module.uuid | string | Unique identifier |
licenses.plan.module.name | string | Name of the resource |
licenses.plan.module.description | string | Output field: licenses.plan.module.description |
licenses.properties | string | Output field: licenses.properties |
licenses.limits | string | Output field: licenses.limits |
licenses.start | string | Output field: licenses.start |
licenses.end | string | Output field: licenses.end |
licenses.duration | number | Output field: licenses.duration |
licenses.transaction_id | string | Unique identifier |
licenses.management_community_uuid | string | Unique identifier |
licenses.beneficiary_community_uuid | string | Unique identifier |
licenses.created_at | string | Output field: licenses.created_at |
licenses.created_by | string | Output field: licenses.created_by |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"licenses":[{}],"limits":"limits"}}
Get a Cyber Kill Chain Stage
Retrieve a specific Cyber Kill Chain stage definition from Sekoia Defend (XDR) using the provided UUID.
Endpoint
- URL: /v1/sic/kill-chains/{{uuid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.uuid | string | Required | Unique identifier of the kill chain step. |
Input Example
{"path_parameters":{"uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
order_id | number | Unique identifier |
uuid | string | Unique identifier |
short_id | string | Unique identifier |
name | string | Name of the resource |
description | string | Output field: description |
stix_name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"order_id":0,"uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","short_id":"string","name":"string","description":"string","stix_name":"string"}}
Get an Asset by UUID
Retrieve detailed information for a specific asset in Sekoia Defend (XDR) using the unique UUID provided.
Endpoint
- URL: /v2/asset-management/assets/{{uuid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.uuid | string | Required | Asset's UUID. |
parameters.with_telemetry | boolean | Optional | Enrich returned assets with their telemetry statistics. |
cookies | object | Optional | Parameter for Get an Asset by UUID |
cookies.access_token_cookie | string | Optional | Access token cookie. |
Input Example
{"parameters":{"with_telemetry":false},"path_parameters":{"uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
uuid | string | Unique identifier |
entity_uuid | string | Unique identifier |
community_uuid | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
category | string | Output field: category |
criticality | number | Output field: criticality |
created_at | string | Output field: created_at |
created_by | string | Output field: created_by |
created_by_type | string | Type of the resource |
updated_at | string | Output field: updated_at |
first_seen | string | Output field: first_seen |
last_seen | string | Output field: last_seen |
nb_events | number | Output field: nb_events |
nb_alerts | number | Output field: nb_alerts |
nb_atoms | number | Output field: nb_atoms |
atoms | object | Output field: atoms |
props | object | Output field: props |
tags | array | Output field: tags |
revoked | boolean | Output field: revoked |
revoked_at | string | Output field: revoked_at |
revoked_by | string | Output field: revoked_by |
reviewed | boolean | Output field: reviewed |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 18 Mar 2025 20:37:23 GMT"},"reason":"OK","json_body":{"uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","entity_uuid":"ccd0bbaa-1979-4620-9054-a91c61d70e41","community_uuid":"e391588b-4c35-45eb-a5af-211fba0cde08","name":"string","type":"string","category":"string","criticality":0,"created_at":"2019-08-24T14:15:22Z","created_by":"ee824cad-d7a6-4f48-87dc-e8461a9201c4","created_by_type":"string"...
Get an Event Search Job
Retrieve details for a specific event search job in Sekoia Defend (XDR) by using the event_search_job_uuid.
Endpoint
- URL: /v1/sic/conf/events/search/jobs/{{event_search_job_uuid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.event_search_job_uuid | string | Required | UUID of the event search job. The UUID is a 36-character string consisting of hexadecimal digits and hyphens. |
ο»Ώ |
Input Example
{"path_parameters":{"event_search_job_uuid":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
uuid | string | Unique identifier |
status | number | Status value |
total | number | Output field: total |
retrieved | number | Output field: retrieved |
term | string | Output field: term |
term_lang | string | Output field: term_lang |
filters | array | Output field: filters |
filters.field | string | Output field: filters.field |
filters.value | object | Value for the parameter |
filters.operator | string | Output field: filters.operator |
filters.excluded | boolean | Output field: filters.excluded |
filters.disabled | boolean | Output field: filters.disabled |
created_by | string | Output field: created_by |
created_by_type | string | Type of the resource |
created_at | string | Output field: created_at |
started_at | string | Output field: started_at |
canceled_by | string | Output field: canceled_by |
canceled_by_type | string | Type of the resource |
canceled_at | string | Output field: canceled_at |
ended_at | string | Output field: ended_at |
earliest_time | string | Time value |
latest_time | string | Time value |
results_ttl | number | Result of the operation |
Output Example
{"status_code":200,"reason":"OK","json_body":{"uuid":"d036c419-f1bc-4a42-9848-d411ab49ebb3","status":0,"total":0,"retrieved":0,"term":"term","term_lang":"term lang","filters":[{}],"created_by":"created by","created_by_type":"created by type","created_at":"2025-05-08T06:50:11.883Z","started_at":"2025-05-08T06:50:11.883Z","canceled_by":"canceled by","canceled_by_type":"canceled by type","canceled_at":"2025-05-08T06:50:11.883Z","ended_at":"2025-05-08T06:50:11.883Z"}}
Get the Events Found by an Event Search Job
Retrieves events matched by a specific event search job using its UUID in Sekoia Defend (XDR), requiring path parameter 'event_search_job_uuid'.
Endpoint
- URL: /v1/sic/conf/events/search/jobs/{{event_search_job_uuid}}/events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.limit | integer | Optional | Limit a number of items (allowed range is 1-1000), default is 100. |
parameters.offset | integer | Optional | A number of items to skip, default is 0. |
parameters.latest_time | string | Optional | The latest (exclusive) time bounds for the requested event in UTC time (in seconds). |
parameters.earliest_time | string | Optional | The earliest (inclusive) time bounds for the requested event in UTC time (in seconds). |
path_parameters.event_search_job_uuid | string | Required | UUID of the event search job. The UUID is a 36-character string consisting of hexadecimal digits and hyphens. |
ο»Ώ |
Input Example
{"parameters":{"limit":100,"offset":0,"latest_time":"2023-10-01T00:00:00Z","earliest_time":"2023-09-01T00:00:00Z"},"path_parameters":{"event_search_job_uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
items | array | Output field: items |
total | number | Output field: total |
paging_token | string | Output field: paging_token |
Output Example
{"status_code":200,"reason":"OK","json_body":{"items":[{}],"total":0,"paging_token":"paging token"}}
Get the Fields of the Events
Retrieve event field details from Sekoia Defend (XDR) using a specific event search job UUID; an HTTP 410 error indicates an expired job.
Endpoint
- URL: /v1/sic/conf/events/search/jobs/{{event_search_job_uuid}}/fields
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.limit | number | Optional | Limit a number of items (allowed range is 1-1000), default is 100. |
parameters.offset | number | Optional | A number of items to skip, default is 0. |
path_parameters.event_search_job_uuid | string | Required | UUID of the event search job. The UUID is a 36-character string consisting of hexadecimal digits and hyphens. |
ο»Ώ |
Input Example
{"parameters":{"limit":100,"offset":0},"path_parameters":{"event_search_job_uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
items | array | Output field: items |
items.name | string | Name of the resource |
items.display_name | string | Name of the resource |
items.description | string | Output field: items.description |
items.value_type | string | Type of the resource |
items.most_common_values | array | Value for the parameter |
items.most_common_values.name | string | Name of the resource |
items.most_common_values.value | number | Value for the parameter |
total | number | Output field: total |
retrieved | number | Output field: retrieved |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"items":[{}],"total":0,"retrieved":0}}
Get the Timeline of an Alert by its UUID
Retrieve a detailed timeline of a specific alert in Sekoia Defend (XDR) by using the alert's unique identifier (UUID).
Endpoint
- URL: /v1/sic/alerts/{{alert_uuid}}/timeline
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.alert_uuid | string | Required | The Alert's UUID. |
parameters.type | string | Optional | Type of timeline (supported values are '24h', '14d'). |
parameters.frame-length | number | Optional | Size in observed-data of the requested frame. |
Input Example
{"parameters":{"type":"24h","frame-length":2}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
timeline | array | Output field: timeline |
timeline.start | string | Output field: timeline.start |
timeline.end | string | Output field: timeline.end |
timeline.value | number | Value for the parameter |
frame | object | Output field: frame |
frame.start | string | Output field: frame.start |
frame.end | string | Output field: frame.end |
Output Example
{"status_code":200,"response_headers":{"Content-Type":"application/json","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","x-sekoia-traceid":"c4e688b3ce225feb3c160449ddba33aa","Strict-Transport-Security":"max-age=63072000; includeSubdomains; preload","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Content-Encoding":"gzip","Content-Length":"263","Expires":"Tue, 18 Mar 2025 09:58:05 GMT","Cache-Control":"max-age=0, no-cache, no-store","Pragma":"no-cache","Date":"Tue, 1...
List Alerts
Retrieve a paginated list of alerts from Sekoia Defend (XDR), with optional filters for targeting specific incidents.
Endpoint
- URL: /v1/sic/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.match[community_uuid] | string | Optional | Match alerts by their community UUIDs. |
parameters.match[entity_name] | string | Optional | Match alerts by their entity names (separated by commas). |
parameters.match[entity_uuid] | string | Optional | Match alerts by their entity UUIDs (separated by commas). |
parameters.match[status_uuid] | string | Optional | Match alerts by their status UUIDs (separated by commas). |
parameters.match[status_name] | string | Optional | Match alerts by their status name (separated by commas). |
parameters.match[type_category] | string | Optional | Match alerts by their type categories (separated by commas). |
parameters.match[type_value] | string | Optional | Match alerts by their type values (separated by commas). |
parameters.match[source] | string | Optional | Match alerts by their sources (separated by commas). |
parameters.match[target] | string | Optional | Match alerts by their targets (separated by commas). |
parameters.match[node] | string | Optional | Match alerts either by their sources or their targets (separated by commas). |
parameters.match[stix_object] | string | Optional | Match alerts that contains requested STIX objects IDs. |
parameters.match[rule_uuid] | string | Optional | Match alerts by their rule UUIDs (separated by commas). |
parameters.match[rule_name] | string | Optional | Match alerts by their rule names (separated by commas). |
parameters.match[short_id] | string | Optional | Match alerts by their short_id (separated by commas). |
parameters.match[uuid] | string | Optional | Match alerts by their UUID (separated by commas). |
parameters.match[title] | string | Optional | Match alerts by their title (separated by commas). |
parameters.match[asset_uuid] | string | Optional | Match alerts for specific assets (separated by commas). |
parameters.match[urgency_display] | string | Optional | Match alerts for specific urgency display (separated by commas). |
parameters.date[created_at] | string | Optional | Filter alerts by their creation dates. |
parameters.date[updated_at] | string | Optional | Filter alerts by their update dates. |
parameters.range[urgency] | string | Optional | Filter alerts by their urgencies. |
parameters.range[similar] | string | Optional | Filter alerts by their number of similar occurrences. |
parameters.visible | boolean | Optional | Filter alerts according their visibility. |
parameters.similar_to | string | Optional | Filter alerts similar to the provided alert short ID. |
parameters.nomatch[asset_uuid] | string | Optional | Exclude alerts for specific assets (separated by commas). |
Input Example
{"parameters":{"match[community_uuid]":"e391588b-4c35-45eb-a5af-211fba0cde08","match[entity_name]":"Entity Names","match[entity_uuid]":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","match[status_uuid]":"e392588b-4c35-45eb-a5af-211fba0cde09","match[status_name]":"Status Name","match[type_category]":"Type Categories","match[type_value]":"Type Values","match[source]":"Sources","match[target]":"Targets","match[node]":"String","match[stix_object]":"STIX objects IDs","match[rule_uuid]":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","match[rule_name]":"Rule Names","match[short_id]":"Short ID","match[uuid]":"085be615-a8ad-4c34-8e9c-c7612fbf6c8f","match[title]":"Title","match[asset_uuid]":"497f6eca-6276-4993-bfeb-53cbbbba6f08","match[urgency_display]":"Urgency Display","date[created_at]":"null","date[updated_at]":"null","range[urgency]":"null","range[similar]":"null","visible":true,"similar_to":"null","nomatch[asset_uuid]":"497f6eca-6276-4993-bfeb-53cbbbba6f08","nomatch[entity_uuid]":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","nomatch[rule_uuid]":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","nomatch[rule_name]":"Rule Names","nomatch[source]":"Sources","nomatch[target]":"Targets","nomatch[status_uuid]":"e392588b-4c35-45eb-a5af-211fba0cde09","nomatch[stix_object]":"STIX objects IDs","nomatch[type_value]":"Type Values","nomatch[urgency_display]":"Urgency Display","limit":20,"offset":0,"stix":false,"sort":"created_at","direction":"asc","with_count":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
items | array | Output field: items |
items.uuid | string | Unique identifier |
items.title | string | Output field: items.title |
items.created_at | number | Output field: items.created_at |
items.created_by | string | Output field: items.created_by |
items.created_by_type | string | Type of the resource |
items.updated_at | number | Output field: items.updated_at |
items.updated_by | string | Output field: items.updated_by |
items.updated_by_type | string | Type of the resource |
items.community_uuid | string | Unique identifier |
items.short_id | string | Unique identifier |
items.entity | object | Output field: items.entity |
items.entity.uuid | string | Unique identifier |
items.entity.name | string | Name of the resource |
items.urgency | object | Output field: items.urgency |
items.urgency.current_value | number | Value for the parameter |
items.urgency.value | number | Value for the parameter |
items.urgency.severity | number | Output field: items.urgency.severity |
items.urgency.criticity | number | Output field: items.urgency.criticity |
items.urgency.display | string | Output field: items.urgency.display |
items.alert_type | object | Type of the resource |
items.alert_type.value | string | Type of the resource |
items.alert_type.category | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Mon, 11 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{"items":[{}],"total":0,"has_more":true}}
Search Assets
Retrieve a paginated, sortable, and filterable list of assets from Sekoia Defend (XDR).
Endpoint
- URL: /v2/asset-management/assets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.limit | number | Optional | Limit a number of items (allowed range is 1-100), default is 20. |
parameters.offset | number | Optional | A number of items to skip, default is 0. Values must be greater than or equal to 0. |
parameters.search | string | Optional | Search assets by name. |
parameters.also_search_in_detection_properties | boolean | Optional | Search by attached detection property too. |
parameters.also_search_in_tags | boolean | Optional | Search by asset tags too. |
parameters.uuids | string | Optional | Filter by comma-separated list of asset UUIDs. |
parameters.community_uuids | string | Optional | Filter by comma-separated list of community UUIDs. |
parameters.type | string | Optional | Filter by comma-separated list of asset types. |
parameters.category | string | Optional | Filter by comma-separated list of asset categories. |
parameters.source | string | Optional | Filter by comma-separated list of asset sources. |
parameters.tags | string | Optional | Filter by comma-separated list of tags. |
parameters.reviewed | boolean | Optional | Filter reviewed assets only. |
parameters.criticality | number | Optional | Filter assets with higher criticality. |
parameters.sort | string | Optional | Sort criterion. |
parameters.direction | string | Optional | Sort order. |
parameters.with_telemetry | boolean | Optional | Enrich returned assets with their telemetry statistics. |
parameters.incorporate_atoms | boolean | Optional | Enrich returned assets with their detection properties. |
parameters.include_revoked | boolean | Optional | Include revoked assets in the search results. |
parameters.rule_uuid | string | Optional | Filter by comma-separated list of asset discovery rules UUIDs. |
parameters.rule_version | string | Optional | Filter by comma-separated list of asset discovery rules versions. |
parameters.format | string | Optional | Format return assets using legacy Assets API v1.0 format. |
cookies | object | Optional | Parameter for Search Assets |
cookies.access_token_cookie | string | Optional | Access token cookie. |
Input Example
{"parameters":{"limit":20,"offset":0,"search":"","also_search_in_detection_properties":false,"also_search_in_tags":false,"uuids":"","community_uuids":"","type":"","category":"","source":"","tags":"","reviewed":true,"criticality":1,"sort":"name","direction":"desc","with_telemetry":false,"incorporate_atoms":false,"include_revoked":false,"rule_uuid":"32fa9e3e-fc95-4447-9cd6-8b81210a70f6","rule_version":"","format":""},"cookies":{"access_token_cookie":""}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
total | number | Output field: total |
items | array | Output field: items |
items.uuid | string | Unique identifier |
items.entity_uuid | string | Unique identifier |
items.community_uuid | string | Unique identifier |
items.name | string | Name of the resource |
items.type | string | Type of the resource |
items.category | string | Output field: items.category |
items.criticality | number | Output field: items.criticality |
items.created_at | string | Output field: items.created_at |
items.created_by | string | Output field: items.created_by |
items.created_by_type | string | Type of the resource |
items.updated_at | string | Output field: items.updated_at |
items.first_seen | string | Output field: items.first_seen |
items.last_seen | string | Output field: items.last_seen |
items.nb_events | number | Output field: items.nb_events |
items.nb_alerts | number | Output field: items.nb_alerts |
items.nb_atoms | number | Output field: items.nb_atoms |
items.atoms | object | Output field: items.atoms |
items.props | object | Output field: items.props |
items.tags | array | Output field: items.tags |
items.revoked | boolean | Output field: items.revoked |
items.revoked_at | string | Output field: items.revoked_at |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Tue, 18 Mar 2025 20:37:23 GMT"},"reason":"OK","json_body":{"total":0,"items":[{}]}}
Trigger an Action on the Alert Workflow
Executes a specified action on an alert in Sekoia Defend (XDR) using the alert's UUID to update its workflow status.
Endpoint
- URL: /v1/sic/alerts/{{uuid}}/workflow
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.uuid | string | Required | The Alert's UUID. |
action_uuid | string | Optional | UUID of the action to trigger, or the status to set. For more details see Readme. |
comment | string | Optional | A comment to describe why the alert status has changed. |
Input Example
{"path_parameters":{"uuid":"9f3df1b1-4db7-44bd-b615-af5873ad7f8a"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
actions | array | Output field: actions |
actions.id | string | Unique identifier |
actions.name | string | Name of the resource |
actions.description | string | Output field: actions.description |
Output Example
{"status_code":200,"response_headers":{"Content-Type":"application/json","Content-Length":"3","Access-Control-Allow-Origin":"*","x-sekoia-traceid":"75a030b6ae2104d007ef0aab26e974ef","Strict-Transport-Security":"max-age=63072000; includeSubdomains; preload","X-Frame-Options":"SAMEORIGIN","X-Content-Type-Options":"nosniff","Expires":"Tue, 18 Mar 2025 10:25:39 GMT","Cache-Control":"max-age=0, no-cache, no-store","Pragma":"no-cache","Date":"Tue, 18 Mar 2025 10:25:39 GMT","Connection":"keep-alive"},"...
Triggers a Status Update on a List of Alerts
Updates the status of selected Sekoia Defend (XDR) alerts using specific alert and action identifiers.
Endpoint
- URL: /v1/sic/alerts/bulk/workflow
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.match[uuid] | string | Required | Match alerts by their identifier (UUID or Short ID; separated by commas). |
parameters.action_uuid | string | Required | UUID of the action to trigger, or the status to set. |
parameters.comment | string | Optional | A comment to describe why the alert status has changed. |
Input Example
{"parameters":{"match[uuid]":"9f3df1b1-4db7-44bd-b615-af5873ad7f8a","action_uuid":"095be615-a8ad-4c33-8e9c-c7612fbf6c9f","comment":"Comment"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":204,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Mon, 11 Dec 2023 20:37:23 GMT"},"reason":"OK","json_body":{}}
Response Headers
Header | Description | Example |
|---|---|---|
Access-Control-Allow-Origin | HTTP response header: Access-Control-Allow-Origin | * |
Cache-Control | Directives for caching mechanisms | max-age=0, no-cache, no-store |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
content-length | The length of the response body in bytes | 140 |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Tue, 18 Mar 2025 20:37:23 GMT |
Expires | The date/time after which the response is considered stale | Tue, 18 Mar 2025 10:25:39 GMT |
Pragma | HTTP response header: Pragma | no-cache |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=63072000; includeSubdomains; preload |
Vary | HTTP response header: Vary | Accept-Encoding |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | SAMEORIGIN |
x-sekoia-traceid | HTTP response header: x-sekoia-traceid | c4e688b3ce225feb3c160449ddba33aa |