Teamt5 Threatsonar Edr
The TeamT5 Threatsonar EDR connector facilitates seamless integration with TeamT5's endpoint detection and response system, enabling automated threat analysis and incident response.
TeamT5 Threatsonar EDR is a cutting-edge endpoint detection and response platform that provides comprehensive visibility into endpoint activities and potential threats. By integrating with Swimlane Turbine, users can automate the retrieval of endpoint data, manage isolation states, and access detailed incident and malware information. This connector empowers security teams to streamline their incident response workflows, enhance threat hunting capabilities, and maintain robust endpoint security posture without manual intervention. The actionable intelligence and automated response capabilities provided by this integration are crucial for maintaining a proactive defense against evolving cyber threats.
Prerequisites
To effectively utilize the TeamT5 Threatsonar EDR connector with Swimlane Turbine, ensure you have the following prerequisites:
- API Key Authentication with the following parameters:
- URL: The base endpoint URL for the TeamT5 Threatsonar EDR API.
- API Key: A valid API key provided by TeamT5 to authenticate requests.
Capabilities
This Connector provides the following capabilities:
- Data Retrieval Count
- Data Retrieval Deisolate
- Data Retrieval Endpoints List
- Data Retrieval Isolate
- Data Retrieval Show
- Endpoint Events Connections
- Endpoint Events Show
- Hunter Processes Connections
- Hunter Processes Endpoints
- Hunter Processes Show
- IncidentReport Index
- IncidentReport Show
- MalwareInfo Show
- Network Ips Endpoints
- Network Ips Processes ... and so on
Configurations
API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
X-Auth-Token | API key | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Data Retrieval Count
Retrieve a count of endpoints, categorized by client and department, from TeamT5 Threatsonar EDR.
Endpoint
- URL: /api/v2/endpoints/count
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
online | boolean | Optional | Online. |
Input Example
{"json_body":{"online":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
clients | array | Output field: clients |
clients.id | number | Unique identifier |
clients.name | string | Name of the resource |
clients.departments | array | Output field: clients.departments |
clients.departments.id | number | Unique identifier |
clients.departments.name | string | Name of the resource |
clients.departments.count | number | Count value |
clients.count | number | Count value |
count | number | Count value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"clients":[{}],"count":159}}
Data Retrieval Deisolate
Deisolate a specific endpoint in TeamT5 Threatsonar EDR using the provided endpoint ID.
Endpoint
- URL: /api/v2/endpoints/{{endpoint_id}}/deisolate
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.endpoint_id | string | Required | Endpoint ID |
Input Example
{"path_parameters":{"endpoint_id":"abc123"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
message | string | Response message |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"message":"success"}}
Data Retrieval Endpoints List
Retrieve a list of endpoint records from TeamT5 Threatsonar Edr using specified parameters.
Endpoint
- URL: /api/v2/endpoints
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ip_address | string | Optional | IP Address. |
parameters.computer_name | string | Optional | Computer Name. |
parameters.scan_start | string | Optional | scan start is in YYYY-MM-dd hh:mm:ss format. |
parameters.scan_end | string | Optional | scan end is in YYYY-MM-dd hh:mm:ss format. |
parameters.entries_per_query | number | Optional | Entries Per Query. |
parameters.append_event | string | Optional | Append Event. |
parameters.above_level | number | Optional | Above Level. |
parameters.agent_status | string | Optional | Agent Status |
Input Example
{"parameters":{"ip_address":"192.168.1.2","computer_name":"windows","scan_start":"2019-01-00 03:00:00","scan_end":"2019-01-01 03:00:00","entries_per_query":10,"append_event":"true","above_level":10,"agent_status":"true"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"id":1,"computer_name":"Qoo-Qmmmmm","computer_manufacturer":"Acer","username":"SYSTEM","timezone":"+08:00","number_of_cores":4,"cpu_name":"Qoo-PC","os_name":"Microsoft Windows 10 \u5bb6\u7528\u7248(x64-based PC)","installed_at":"2020-11-16T10:58:40.000Z","ram_size":8072,"connect_ip":"192.168.1.1","local_ip":"192.168.110.22","start_scan_counter":1,"loader_version":"2103p9","engine_version":"2109p1"}]}
Data Retrieval Isolate
Isolates an endpoint in TeamT5 Threatsonar EDR using the provided endpoint ID to contain potential threats.
Endpoint
- URL: /api/v2/endpoints/{{endpoint_id}}/isolate
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.endpoint_id | string | Required | Endpoint ID. |
Input Example
{"path_parameters":{"endpoint_id":"abc123"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
message | string | Response message |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"message":"success"}}
Data Retrieval Show
Query the execution status of ThreatSonar agents on specified hosts using the endpoint ID.
Endpoint
- URL: /api/v2/endpoints/{{endpoint_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.endpoint_id | string | Required | The ID of the data retrieval endpoint. |
scan_start | string | Optional | Scan start time in UTC. Must set along with scan_end. |
scan_end | string | Optional | Scan end time in UTC. Must set along with scan_start. |
append_mac | string | Optional | Append MAC address. Optional. |
append_event | string | Optional | Append event. Optional. |
above_level | number | Optional | Above level. Optional. |
agent_status | string | Optional | Agent status. Optional. |
Input Example
{"path_parameters":{"endpoint_id":"string"},"scan_start":"string","scan_end":"string","append_mac":"string","append_event":"string","above_level":123,"agent_status":"active"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"reason":"OK","json_body":[{"id":1,"computer_name":"Qoo-Qmmmmm","computer_manufacturer":"Acer","username":"SYSTEM","timezone":"+08:00","number_of_cores":4,"cpu_name":"Qoo-PC","os_name":"Microsoft Windows 10 \u5bb6\u7528\u7248(x64-based PC)","installed_at":"2020-11-16T10:58:40.000Z","ram_size":8072,"connect_ip":"192.168.1.1","local_ip":"192.168.110.22","start_scan_counter":1,"loader_version":"2103p9","engine_version":"2109p1"}]}
Endpoint Events Connections
Retrieve connection details for a specific endpoint event in TeamT5 Threatsonar EDR using the provided event ID.
Endpoint
- URL: /api/v2/endpoint/events/{{event_id}}/connections
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.event_id | string | Required | Parameters for the Endpoint Events Connections action |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
Input Example
{"path_parameters":{"event_id":"abc123@21"},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"id":101,"address":"8.8.8.8"}]}
Endpoint Events Show
Retrieve detailed information for a specific endpoint event in TeamT5 Threatsonar Edr using the provided event ID.
Endpoint
- URL: /api/v2/endpoint/events/{{event_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.event_id | string | Required | Event ID. |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
Input Example
{"path_parameters":{"event_id":"abc123"},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
threat_level | number | Output field: threat_level |
ntfs_changetime | string | Time value |
ntfs_createtime | string | Time value |
file_create_time | string | Time value |
process_createtime | object | Time value |
file_createtime | string | Time value |
ntfs_last_writetime | string | Time value |
sha256 | string | Output field: sha256 |
file_path | string | Output field: file_path |
file_last_writetime | string | Time value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"threat_level":1,"ntfs_changetime":"2022-01-07 16:44:36","ntfs_createtime":"2022-01-07 16:44:36","file_create_time":"2022-01-07T16:44:36.000Z","process_createtime":null,"file_createtime":"2022-01-07 16:44:36","ntfs_last_writetime":"2022-01-07 16:44:36","sha256":"359C5D85022C772DB5E05306595D3FF31C8CEFBF30506F716BD239C15AE04E82","file_path":"c:\\programdata\\microsoft\\windows defender\\definitionupdates\\{965fec8b-1372-429e-...",...
Hunter Processes Connections
Retrieve network connection details for a specific process in TeamT5 Threatsonar Edr using the provided process ID.
Endpoint
- URL: /api/v2/hunter/processes/{{id}}/connections
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | ID. |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Optional | HTTP headers for the request |
Input Example
{"path_parameters":{"id":123},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"id":1,"address":"192.168.1.14"},{"id":2,"address":"192.168.1.87"},{"id":3,"address":"192.168.1.24"}]}
Hunter Processes Endpoints
Retrieves detailed information on a process by its ID, including network IP connections, path parameters, and headers in TeamT5 Threatsonar Edr.
Endpoint
- URL: /api/v2/hunter/processes/{{id}}/endpoints
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | ID. |
parameters.connect_to | string | Optional | IP address to connect. |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
Input Example
{"parameters":{"connect_to":"192.168.1.137"},"path_parameters":{"id":123},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"id":1,"department":"Dept-1","computer_name":"Srv-1","ip_address":"192.168.1.137","threat_level":3,"last_scanned_at":"2019-03-23T11:09:43.000Z"},{"id":2,"department":"Dept-2","computer_name":"TSrv-2","ip_address":"192.168.1.23","threat_level":3,"last_scanned_at":"2019-12-07T16:39:47.000Z"}]}
Hunter Processes Show
Retrieve detailed information on a process by its ID from TeamT5 Threatsonar Edr, including network IP connections. Requires path parameter 'id'.
Endpoint
- URL: /api/v2/hunter/processes/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | ID. |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
Input Example
{"path_parameters":{"id":123},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"name":"mstsc.exe"}}
IncidentReport Index
Retrieve a list of incident reports accessible by the current user in TeamT5 ThreatSonar EDR.
Endpoint
- URL: /api/v2/incident_reports/
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
start_at | string | Optional | Start time for incident report query. |
end_at | string | Optional | End time for incident report query. |
trigger_types | array | Optional | List of trigger types for incident reports. |
levels | array | Optional | List of levels for incident reports. |
page | number | Optional | Page number for pagination. |
page_size | number | Optional | Number of items per page. |
Input Example
{"start_at":"string","end_at":"string","trigger_types":["string"],"levels":["string"],"page":123,"page_size":123}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | array | Response data |
data.id | number | Response data |
data.uuid | string | Response data |
data.status | string | Response data |
data.level | number | Response data |
data.department_id | number | Response data |
data.client | string | Response data |
data.os | string | Response data |
data.os_family | string | Response data |
data.engine_version | string | Response data |
data.connect_ip | string | Response data |
data.exchange_token | object | Response data |
data.intermediate_token | object | Response data |
data.afterthoughts_error_detail | object | Response data |
data.local_time_utc_offset | number | Response data |
data.source | string | Response data |
data.service_request_id | string | Response data |
data.scanned_at | string | Response data |
data.created_at | string | Response data |
data.updated_at | string | Response data |
data.local_ip | string | Response data |
data.version | string | Response data |
data.server_apply_whitelist | number | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":[{},{}],"page":1,"page_size":2,"count":2}}
IncidentReport Show
Retrieve detailed information for a specific incident report identified by an ID in TeamT5 Threatsonar EDR.
Endpoint
- URL: /api/v2/incident_reports/
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.id | number | Required | The ID of the incident report. |
Input Example
{"parameters":{"id":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
max_level | number | Output field: max_level |
metadata | array | Response data |
metadata.file_name | string | Response data |
metadata.file | string | Response data |
records | array | Output field: records |
records.attributes | array | Output field: records.attributes |
records.display_name | string | Name of the resource |
records.id | number | Unique identifier |
records.level | number | Output field: records.level |
records.meta_id | object | Unique identifier |
records.rec_data | object | Response data |
records.rec_data.file_path | string | Response data |
records.rec_hash | string | Output field: records.rec_hash |
records.rec_src | string | Output field: records.rec_src |
records.rec_type | string | Type of the resource |
records.rule_id | object | Unique identifier |
records.tactics | object | Output field: records.tactics |
records.techniques | object | Output field: records.techniques |
relations | array | Output field: relations |
relations.from | number | Output field: relations.from |
relations.to | number | Output field: relations.to |
relations.verb | string | Output field: relations.verb |
summary | array | Output field: summary |
Output Example
{"status_code":200,"reason":"OK","json_body":{"max_level":5,"metadata":[],"records":[{},{},{}],"relations":[{},{}],"summary":["Volume Shadow Copies have been deleted using svchost.exe to prevent Windows from creating file backups prior to deploying ransomware. Deletion of Volume Shadow Copies may also affect System Restore functions. Adversaries may disable or delete system recovery features to augment the effects of <em>Data Destruction</em> and <em>Data Encrypted for Impact</em> techniques."],...
MalwareInfo Show
Retrieve STIX-compatible malware information from TeamT5 Threatsonar EDR using a unique identifier.
Endpoint
- URL: api/v2/malware_infos/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the MalwareInfo Show action |
Input Example
{"path_parameters":{"id":"1-1234"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.id | string | Unique identifier |
meta.report_id | string | Unique identifier |
indicator | object | Output field: indicator |
indicator.indicator_types | array | Type of the resource |
indicator.pattern_type | string | Type of the resource |
indicator.pattern | array | Output field: indicator.pattern |
indicator.valid_from | string | Unique identifier |
attack-pattern | object | Output field: attack-pattern |
attack-pattern.name | string | Name of the resource |
attack-pattern.description | string | Output field: attack-pattern.description |
attack-pattern.kill_chain_phases | array | Output field: attack-pattern.kill_chain_phases |
attack-pattern.kill_chain_phases.kill_chain_name | string | Name of the resource |
attack-pattern.kill_chain_phases.phase_name | string | Name of the resource |
attack-pattern.last_mitre_tag_id | string | Unique identifier |
attack-pattern.mitre_tag_ids | array | Unique identifier |
malware | object | Output field: malware |
malware.name | string | Name of the resource |
malware.malware_type | array | Type of the resource |
malware.is_family | boolean | Output field: malware.is_family |
malware.description | string | Output field: malware.description |
malware-analysis | object | Output field: malware-analysis |
malware-analysis.submitted | string | Output field: malware-analysis.submitted |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"meta":{"id":"1-1234","report_id":"1"},"indicator":{"indicator_types":[],"pattern_type":"stix","pattern":[],"valid_from":"2022-07-07 10:57:26"},"attack-pattern":{"name":"Web Service","description":"Adversaries may use an existing, legitimate external Web service as a means for ...","kill_chain_phases":[],"last_mitre_tag_id":"T1102","mitre_tag_ids":[]},"malware":{"name":"APT_T5_02855","malware_type":[],"is_family":true,"descripti...
Network Ips Endpoints
Queries endpoints connected to a specified IP in TeamT5 Threatsonar Edr using the provided 'ip_id'.
Endpoint
- URL: /api/v2/network/ips/{{ip_id}}/endpoints
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip_id | string | Required | Parameters for the Network Ips Endpoints action |
parameters.process_id | number | Optional | Parameters for the Network Ips Endpoints action |
Input Example
{"parameters":{"process_id":123},"path_parameters":{"ip_id":"192.168.1.137"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"id":1,"vmp_hid":"00000000-0000-0000-0000-000000000000","computer_name":"SRV-1","computer_manufacturer":"Dell","username":"User-1","timezone":" 08:00","number_of_cores":4,"cpu_name":"BFEBFBFF000306D4","os_name":"Microsoft Windows 7 \u5c08\u696d\u7248 (x64-based PC)","installed_at":"2015-12-22T13:37:23.000Z","department_id":1,"ram_size":8112,"connect_ip":"192.168.1.1","local_ip":"192.168.1.113","start_scan_counter":248}]}
Network Ips Processes
Query endpoint event connections for processes associated with a specified IP in TeamT5 Threatsonar Edr, using the 'ip_id' path parameter.
Endpoint
- URL: /api/v2/network/ips/{{ip_id}}/processes
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip_id | string | Required | Parameters for the Network Ips Processes action |
headers | object | Optional | HTTP headers for the request |
headers.Content-Type | string | Optional | HTTP headers for the request |
Input Example
{"path_parameters":{"ip_id":"192.168.1.137"},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"name":"mstsc.exe"},{"id":548,"name":"lsass.exe"},{"id":13634,"name":"httpd.exe"}]}
Network Ips Show
Retrieve detailed information for a specific IP by its ID in TeamT5 Threatsonar Edr, including path parameters and headers.
Endpoint
- URL: /api/v2/network/ips/{{ip_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip_id | string | Required | IP ID. |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
Input Example
{"path_parameters":{"ip_id":"192.168.1.137"},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
address | string | Output field: address |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"address":"8.8.8.8"}}
Report Detail
Retrieve a detailed scan report from TeamT5 Threatsonar Edr using a unique scan_result_id.
Endpoint
- URL: /api/v2/scan_results/{{scan_result_id}}/report_detail
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.scan_result_id | number | Required | Scan Result ID. |
Input Example
{"path_parameters":{"scan_result_id":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
os_name | string | Name of the resource |
threats | array | Output field: threats |
threats.total_match_rule_lists | array | Output field: threats.total_match_rule_lists |
threats.malicious_level | string | Output field: threats.malicious_level |
threats.malicious_attribute_tag | array | Output field: threats.malicious_attribute_tag |
threats.related_paths | object | Output field: threats.related_paths |
network | array | Output field: network |
network.local_port | string | Output field: network.local_port |
network.process_name | string | Name of the resource |
network.remote_ip | string | Output field: network.remote_ip |
network.remote_port | string | Output field: network.remote_port |
network.state | string | Output field: network.state |
event_log | array | Output field: event_log |
event_log.eventid | number | Unique identifier |
event_log.malicious_level | number | Output field: event_log.malicious_level |
event_log.malicious_attribute_tag | array | Output field: event_log.malicious_attribute_tag |
event_log.malicious_attribute_tag.file_name | string | Name of the resource |
event_log.malicious_attribute_tag.file | string | Output field: event_log.malicious_attribute_tag.file |
event_log.process_commandline | object | Output field: event_log.process_commandline |
total_visiblememory_size | string | Output field: total_visiblememory_size |
free_physicalmemory_size | string | Output field: free_physicalmemory_size |
software_list | array | Output field: software_list |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"os_name":"Microsoft Windows 10 \u5c08\u696d\u7248(x64-based PC)","threats":[{}],"network":[{}],"event_log":[{}],"total_visiblememory_size":"6143 MB","free_physicalmemory_size":"3298 MB","software_list":["ESET Security(15.1.12.0)","Microsoft Edge(100.0.1185.44)","Microsoft Edge Update(1.3.157.61)"]}}
Report Import Report Bundle
Upload a report bundle to TeamT5 Threatsonar EDR for comprehensive threat analysis, requiring form data.
Endpoint
- URL: /api/v2/scan_results/import_report_bundle
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
form_data | object | Required | Response data |
form_data.report | object | Required | File to be uploaded. |
form_data.report.file | string | Required | Response data |
form_data.report.file_name | string | Required | Response data |
Input Example
{"form_data":{"report":{"file":"string","file_name":"Example Name"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
url | string | URL endpoint for the request |
report_id | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"url":"https://cloud.threatsonar.org:80/scan_results?report_viewer[id]=1","report_id":1}}
Report Show
Retrieves a base64-encoded PDF report of scan results from TeamT5 Threatsonar EDR using the provided scan_result_id.
Endpoint
- URL: /api/v2/scan_results/{{scan_result_id}}/report
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.scan_result_id | number | Required | Scan Result ID. |
headers | object | Required | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
Input Example
{"path_parameters":{"scan_result_id":123},"headers":{"Content-Type":"application/octet binary"}}
Output
Parameter | Type | Description |
|---|---|---|
file | object | Attachments |
file.file | string | Output field: file.file |
file.file_name | string | Name of the resource |
Output Example
{"file":{"file":"string","file_name":"Example Name"}}
ThreatTracer Count Events
Counts the number of events captured by TeamT5 Threatsonar EDR within a specified time range, requiring start_on, end_on, and client_id parameters.
Endpoint
- URL: /api/v2/threat_tracer/events/meta
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.start_on | string | Required | Start of date range |
parameters.end_on | string | Required | End of date range. The date range must be within 6 months |
parameters.client_id | number | Required | The client id. Can be obtained from List Clients API |
Input Example
{"parameters":{"tracer_id":"example_id"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
meta | object | Output field: meta |
meta.total_hits_count | number | Count value |
meta.total_pages | number | Output field: meta.total_pages |
Output Example
{"status_code":200,"reason":"OK","json_body":{"meta":{"total_hits_count":3345678,"total_pages":35}}}
ThreatTracer List Clients
Retrieve a list of clients from TeamT5 Threatsonar EDR for monitoring and management purposes.
Endpoint
- URL: /api/v2/clients
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
clients | array | Output field: clients |
clients.id | number | Unique identifier |
clients.name | string | Name of the resource |
Output Example
{"status_code":200,"reason":"OK","json_body":{"clients":[{}]}}
ThreatTracer List Events
Retrieve a list of events from TeamT5 Threatsonar EDR within a specified time range, requiring start_on, end_on, and client_id parameters.
Endpoint
- URL: /api/v2/threat_tracer/events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.start_on | string | Required | Start of date range |
parameters.end_on | string | Required | End of date range. The date range must be within 6 months |
parameters.client_id | number | Required | The client id. Can be obtained from List Clients API |
parameters.limit | number | Optional | The maximum amount of events |
parameters.offset | number | Optional | The amount events to skip |
Input Example
{"parameters":{"tracer_id":"example_id"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
events | array | Output field: events |
events.id | number | Unique identifier |
events.ruleset_type | string | Type of the resource |
events.ruleset_id | string | Unique identifier |
events.ruleset_name | string | Name of the resource |
events.hunter_event_id | number | Unique identifier |
events.client_name | string | Name of the resource |
events.department_name | string | Name of the resource |
events.endpoint_name | string | Name of the resource |
events.local_ip | string | Output field: events.local_ip |
events.os_name | string | Name of the resource |
events.first_seen_at | string | Output field: events.first_seen_at |
events.level | number | Output field: events.level |
events.normalized_file_path | string | Output field: events.normalized_file_path |
events.sha256_hash | string | Output field: events.sha256_hash |
events.is_ignored | boolean | Output field: events.is_ignored |
events.created_at | string | Output field: events.created_at |
Output Example
{"status_code":200,"reason":"OK","json_body":{"events":[{}]}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |