Vmware Carbon Black Cloud
The VMWare Carbon Black Cloud connector enables seamless integration with Swimlane Turbine, providing automated actions such as device searches, alert management, and sensor device updates within the security infrastructure.
VMWare Carbon Black Cloud is a comprehensive endpoint security platform that provides organizations with advanced threat detection and response capabilities. This connector enables Swimlane Turbine users to automate critical security operations such as device quarantine, alert management, and vulnerability searches. By integrating with VMWare Carbon Black Cloud, users can streamline their security workflows, rapidly respond to threats, and enhance their overall security posture without the need for manual intervention.
Prerequisites
To effectively utilize the VMWare Carbon Black Cloud connector for Turbine, ensure you have the following prerequisites:
- HTTP Basic Authentication with the following parameters:
- URL: Endpoint URL for the VMWare Carbon Black Cloud API.
- API ID: Unique identifier for API access.
- API Secret: Secret key associated with the API ID for authentication.
Capabilities
The Swimlane VMWare Carbon Black Cloud connector has the following capabilities:
- Bypass Device
- Delete Sensor Device
- Dismiss Alerts
- Get Alert by ID
- Get Alerts
- Get Device by ID
- Quarantine or Unquarantine Device
- Search Devices
- Search Specific Device Vulnerabilities
- Set Background Scan for device
- Uninstall Sensor Device
- Update Alert
- Update Device Policy
Using the Schema
Following are the definitions for each field, default values, whether it is required, searchable and/or tokenized. You can also see accepted values and routes supported per each field.
Possible Alert TypesIcons indicate the alert types a field is valid for.
- CB_ANALYTICS - These fields are part of a CB Analytics alert type
- CONTAINER_RUNTIME - These fields are part of a Container Runtime alert type
- WATCHLIST - These fields are part of a Watchlist alert type
- DEVICE_CONTROL - These fields are part of a Device Control alert type
- HOST_BASED_FIREWALL - These fields are part of a Host Based Firewall alert type
- INTRUSION_DETECTION_SYSTEM - These fields are part of a Intrusion Detection System alert type
- FACET - These fields can be used for returning most prevalent values.
Note: For fields where the Alert Types Supported column contains no entries, this means this field is available only to MDR customers.
Platform API
Platform APIs are available to all Carbon Black Cloud customers: Platform API Documentation - https://developer.carbonblack.com/reference/carbon-black-cloud/platform-apis
Authentication
The X-Auth-Token authentication method uses the API Id and Secret directly in the call to the Carbon Black Cloud APIs. For more information - https://developer.carbonblack.com/reference/carbon-black-cloud/authentication
This is a valid cURL request - some values need to be replaced with yours.
curl https://defense.conferdeploy.net/appservices/v6/orgs/ABCD1234/devices/_search \
-X POST \
-H 'X-AUTH-TOKEN: <API_SECRET>/<API_ID>' \
-H 'Content-Type: application/json' \
-d '{"criteria": {"id": [ "1234567" ]}}'This is the same request with the variables named. Follow the information on how to create them.
$ curl {cbc-hostname}/{API Service Category}/{API path} \
-X POST \
-H 'X-Auth-Token: {API Secret}/{API ID}' \
-H 'Content-Type: application/json' \
-d '{{request body}}'Create an API Key
This is like adding a user to a system and setting their access level, except you are granting access to your application or script instead of a user.
- To create an API Key, go to Settings > API Access > API Keys tab in the Carbon Black Cloud console.
- Select Add API Key from the far right.
- Give the API Key a unique name, and select the appropriate access level provided in the table above. If you select Custom, you will need to choose the Access Level you created in the prior section. β’ Choose a name to clearly distinguish the API from your organizationβs other API Keys. Example: Event_Forwarder_Test_Key
β’ Access Level types of API, LIVE_RESPONSE and SIEM are deprecated. See the Migration Guides for details of how to move to new APIs.
- Hit save, and you will be provided with your API Key Credentials: β’ API Secret Key β’ API ID
- If your API Key already exists, you can view your credentials by opening the Actions dropdown and selecting API Credentials. This will reveal your API Secret Key and API ID. β’ If your system becomes compromised, you can generate a new secret key here (this is like changing the password for your application or script).
Notes
- Set Background Scan for device Action: Not supported on devices of OS type Linux
- Update alerts Action: Bulk Update Alerts Workflow - This is an async operation that updates all alerts that match the search criteria of the request.
- First call this route to start the update job.
- The response contains a request_id. Use this in the job details route to check the progress of the operation.
- When the job is complete, all alerts matching the criteria will have the updates applied.
- Use the Alert Search request to view updated records.
- Search Devices Action has the criteria - please refer to: https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/devices-api/#search-devices
- Search Specific Device Vulnerabilities action has the criteria - please refer to: https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/vulnerability-assessment/#search-specific-device-vulnerabilities
- Get alerts Action:
- For criteria and exclusions objects data in request body - please refer to: https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alert-search-fields
- For more information on Get alerts api - please refer to: https://developer.carbonblack.com/reference/carbon-black-cloud/platform/latest/alerts-api/#find-alerts
API Documentation
Additional Documentation
Configurations
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Username | string | Required |
password | Password | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Bypass Device
Sets a bypass flag on a device in VMWare Carbon Black Cloud using the device ID and specified action type.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/device_actions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Bypass Device action |
action_type | string | Optional | Type of the resource |
device_id | array | Optional | Unique identifier |
options | object | Optional | Parameter for Bypass Device |
options.toggle | string | Optional | Parameter for Bypass Device |
Input Example
{"json_body":{"action_type":"BYPASS","device_id":["12131","12132"],"options":{"toggle":"OFF"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":204,"response_headers":{},"reason":"OK","json_body":{}}
Delete Sensor Device
Removes a sensor device from VMWare Carbon Black Cloud by using the device's ID and an action type.
Endpoint
- URL: /sensor_update_service/v3/orgs/{{org_key}}/jobs/{{job_id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Delete Sensor Device action |
path_parameters.job_id | string | Required | Parameters for the Delete Sensor Device action |
action_type | string | Optional | Type of the resource |
device_id | array | Optional | Unique identifier |
Input Example
{"json_body":{"action_type":"DELETE_SENSOR","device_id":["12131","12132"]},"path_parameters":{"org_key":"ABCD1234","job_id":"abcd1234"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Dismiss Alerts
Mark future alerts linked to a threat_id as DISMISSED in VMWare Carbon Black Cloud, utilizing org_key and alert_id.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/alerts/{{alert_id}}/workflow
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Dismiss Alerts action |
path_parameters.alert_id | string | Required | Parameters for the Dismiss Alerts action |
state | string | Optional | Parameter for Dismiss Alerts |
comment | string | Optional | Parameter for Dismiss Alerts |
remediation_state | string | Optional | Parameter for Dismiss Alerts |
Input Example
{"json_body":{"state":"DISMISSED","comment":"This is an example","remediation_state":"NOTHING"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
state | string | Output field: state |
remediation | string | Output field: remediation |
last_update_time | string | Time value |
comment | string | Output field: comment |
changed_by | string | Output field: changed_by |
Output Example
{"status_code":200,"response_headers":{},"reason":"string","json_body":{"state":"DISMISSED","remediation":"NOTHING","last_update_time":"2020-09-14T15:02:04.620Z","comment":"This is an example","changed_by":"A569S6YYRE"}}
Get Alert by ID
Retrieve detailed information for a specific alert in VMWare Carbon Black Cloud using the provided alert ID and organization key.
Endpoint
- URL: /api/alerts/v7/orgs/{{org_key}}/alerts/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Get Alert by ID action |
path_parameters.id | string | Required | Parameters for the Get Alert by ID action |
Input Example
{"path_parameters":{"org_key":"string","id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
org_key | string | Output field: org_key |
alert_url | string | URL endpoint for the request |
id | string | Unique identifier |
type | string | Type of the resource |
backend_timestamp | string | Output field: backend_timestamp |
user_update_timestamp | object | Output field: user_update_timestamp |
backend_update_timestamp | string | Output field: backend_update_timestamp |
detection_timestamp | string | Output field: detection_timestamp |
first_event_timestamp | string | Output field: first_event_timestamp |
last_event_timestamp | string | Output field: last_event_timestamp |
severity | number | Output field: severity |
reason_code | string | Response reason phrase |
threat_id | string | Unique identifier |
primary_event_id | string | Unique identifier |
policy_applied | string | Output field: policy_applied |
run_state | string | Output field: run_state |
sensor_action | string | Output field: sensor_action |
workflow | object | Output field: workflow |
workflow.change_timestamp | string | Output field: workflow.change_timestamp |
workflow.changed_by_type | string | Type of the resource |
workflow.changed_by | string | Output field: workflow.changed_by |
workflow.closure_reason | string | Response reason phrase |
workflow.status | string | Status value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"org_key":"ABCD1234","alert_url":"https://defense.conferdeploy.net/alerts?s[c][query_string]=id:52fa009d-e2d1-4118...","id":"12ab345cd6-e2d1-4118-8a8d-04f521ae66aa","type":"WATCHLIST","backend_timestamp":"2023-04-14T21:30:40.570Z","user_update_timestamp":null,"backend_update_timestamp":"2023-04-14T21:30:40.570Z","detection_timestamp":"2023-04-14T21:27:14.719Z","first_event_timestamp":"2023-04-14T21:21:42.193Z","last_event_timest...
Get Alerts
Retrieve alerts from VMWare Carbon Black Cloud using specified query, criteria, and exclusions. Requires an 'org_key' path parameter.
Endpoint
- URL: /api/alerts/v7/orgs/{{org_key}}/alerts/_search
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Get Alerts action |
query | string | Optional | A lucene-formatted query using the Alert Search Fields |
time_range | object | Optional | A Time Range Filter on backend_timestamp. Defaults to "range" with value "-2w" |
time_range.start | string | Optional | Parameter for Get Alerts |
time_range.end | string | Optional | Parameter for Get Alerts |
time_range.range | string | Optional | Parameter for Get Alerts |
criteria | object | Optional | Parameter for Get Alerts |
criteria.minimum_severity | number | Optional | Parameter for Get Alerts |
criteria.device_os | array | Optional | Parameter for Get Alerts |
exclusions | object | Optional | Parameter for Get Alerts |
exclusions.type | array | Optional | Type of the resource |
exclusions.device_os_version | array | Optional | Parameter for Get Alerts |
start | number | Optional | Parameter for Get Alerts |
rows | number | Optional | Parameter for Get Alerts |
sort | array | Optional | Parameter for Get Alerts |
sort.field | string | Optional | Parameter for Get Alerts |
sort.order | string | Optional | Parameter for Get Alerts |
Input Example
{"json_body":{"time_range":{"range":"-2w"},"criteria":{"minimum_severity":2,"device_os":["WINDOWS"]},"exclusions":{"type":["WATCHLIST"],"device_os_version":["Windows 10 x64 SP: 1"]},"start":1,"rows":1,"sort":[{"field":"severity","order":"DESC"}]},"path_parameters":{"org_key":"7DESJ9GN"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
results | array | Result of the operation |
results.org_key | string | Result of the operation |
results.alert_url | string | URL endpoint for the request |
results.id | string | Unique identifier |
results.type | string | Type of the resource |
results.backend_timestamp | string | Result of the operation |
results.user_update_timestamp | object | Result of the operation |
results.backend_update_timestamp | string | Result of the operation |
results.detection_timestamp | string | Result of the operation |
results.first_event_timestamp | string | Result of the operation |
results.last_event_timestamp | string | Result of the operation |
results.severity | number | Result of the operation |
results.reason | string | Response reason phrase |
results.reason_code | string | Response reason phrase |
results.threat_id | string | Unique identifier |
results.primary_event_id | string | Unique identifier |
results.policy_applied | string | Result of the operation |
results.run_state | string | Result of the operation |
results.sensor_action | string | Result of the operation |
results.workflow | object | Result of the operation |
results.workflow.change_timestamp | string | Result of the operation |
results.workflow.changed_by_type | string | Type of the resource |
results.workflow.changed_by | string | Result of the operation |
Output Example
{"results":[{"org_key":"7DESJ9GN","alert_url":"defense.conferdeploy.net/alerts?s[c][query_string]=id:b9fc1f28-33c8-4ebe-a241-a8...","id":"b9fc1f28-33c8-4ebe-a241-a83e7f98a5b0","type":"WATCHLIST","backend_timestamp":"2024-03-18T10:12:56.474Z","user_update_timestamp":null,"backend_update_timestamp":"2024-03-18T10:12:56.474Z","detection_timestamp":"2024-03-18T10:11:32.528Z","first_event_timestamp":"2024-03-18T10:05:11.608Z","last_event_timestamp":"2024-03-18T10:05:11.608Z","severity":7,"reason":"Pr...
Get Device by ID
Retrieve details for a specific device from VMWare Carbon Black Cloud using the provided organization key and device ID.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/devices/{{device_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Get Device by ID action |
path_parameters.device_id | string | Required | Parameters for the Get Device by ID action |
Input Example
{"path_parameters":{"org_key":"string","device_id":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
activation_code | object | Output field: activation_code |
activation_code_expiry_time | string | Time value |
ad_group_id | number | Unique identifier |
appliance_name | object | Name of the resource |
appliance_uuid | object | Unique identifier |
auto_scaling_group_name | object | Name of the resource |
av_ave_version | string | Output field: av_ave_version |
av_engine | string | Output field: av_engine |
av_last_scan_time | object | Time value |
av_master | boolean | Output field: av_master |
av_pack_version | string | Output field: av_pack_version |
av_product_version | string | Output field: av_product_version |
av_status | array | Status value |
av_update_servers | object | Output field: av_update_servers |
av_vdf_version | string | Output field: av_vdf_version |
base_device | object | Output field: base_device |
cloud_provider_account_id | object | Unique identifier |
cloud_provider_resource_id | object | Unique identifier |
cloud_provider_tags | object | Unique identifier |
cluster_name | object | Name of the resource |
current_sensor_policy_name | string | Name of the resource |
datacenter_name | object | Response data |
deployment_type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"activation_code":null,"activation_code_expiry_time":"2022-07-11T06:53:06.190Z","ad_group_id":0,"appliance_name":null,"appliance_uuid":null,"auto_scaling_group_name":null,"av_ave_version":"8.3.64.172","av_engine":"4.15.1.560-ave.8.3.64.172:avpack.8.5.2.64:vdf.8.19.20.4:vdfdate.20220711","av_last_scan_time":null,"av_master":false,"av_pack_version":"8.5.2.64","av_product_version":"4.15.1.560","av_status":["AV_ACTIVE","ONDEMAND_SCA...
Quarantine or Unquarantine Device
Isolate or reconnect a device in VMWare Carbon Black Cloud by specifying 'org_key' and 'action_type'.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/device_actions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Organisation Key |
action_type | string | Optional | Action to perform on selected devices. |
device_id | array | Optional | List of devices to perform action on. Either device_id or search is required. |
search | object | Optional | A device search. Device actions will be performed on the result set of this search. |
search.criteria | object | Optional | Parameter for Quarantine or Unquarantine Device |
search.exclusions | object | Optional | Parameter for Quarantine or Unquarantine Device |
search.query | string | Optional | Parameter for Quarantine or Unquarantine Device |
options | object | Optional | Parameter for Quarantine or Unquarantine Device |
options.toggle | string | Optional | Determines whether to enable or disable the action. |
options.auto_assign | boolean | Optional | When true, Devices will be automatically assigned to the policy configured with their associated Asset Group or use the default policy if no Asset Group is associated. Auto assignment will remove any existing manual override. |
options.sensor_version | object | Optional | Devices will be updated to the specified sensor version based on the device's sensor_kit_type. |
options.policy_id | number | Optional | Devices will have a manual override to this policy ID. |
Input Example
{"json_body":{"action_type":"BACKGROUND_SCAN","device_id":["7533319"],"search":{"criteria":{},"exclusions":{},"query":"test query"},"options":{"toggle":"ON","auto_assign":true,"sensor_version":{"RHEL":"2.4.0.3"},"policy_id":123432}},"path_parameters":{"org_key":"7DESJ9G234234N"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{"Date":"Thu, 01 Aug 2024 04:33:23 GMT","Connection":"keep-alive","Cache-Control":"no-cache, no-store, max-age=0, must-revalidate","Expires":"0","Pragma":"no-cache","Set-Cookie":"JSESSIONID=903F464982690571EC30EE48716A77C8; Path=/appservices; Secure; HttpOnly","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY","X-Xss-Protection":"1; mode=block"},"reason":"No Content","response_text":""}
Search Devices
Locate devices within a specified organization in VMWare Carbon Black Cloud using the provided org_key.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/devices/_search
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Search Devices action |
criteria | object | Optional | Criteria is an object that represents values that must be in the results. |
criteria.ad_distinguished_name | array | Optional | Name of the resource |
criteria.ad_domain | array | Optional | Parameter for Search Devices |
criteria.ad_group_id | array | Optional | Unique identifier |
criteria.ad_org_unit | array | Optional | Parameter for Search Devices |
criteria.auto_scaling_group_name | array | Optional | Name of the resource |
criteria.base_device | boolean | Optional | Parameter for Search Devices |
criteria.cloud_provider_account_id | string | Optional | Unique identifier |
criteria.cloud_provider_managed_identity | array | Optional | Unique identifier |
criteria.cloud_provider_network | array | Optional | Unique identifier |
criteria.cloud_provider_resource_group | array | Optional | Unique identifier |
criteria.cloud_provider_resource_id | array | Optional | Unique identifier |
criteria.cloud_provider_scale_group | array | Optional | Unique identifier |
criteria.cloud_provider_tags | array | Optional | Unique identifier |
criteria.cluster_name | array | Optional | Name of the resource |
criteria.compliance_status | array | Optional | Status value |
criteria.datacenter_name | array | Optional | Response data |
criteria.deployment_type | array | Optional | Type of the resource |
criteria.esx_host_name | array | Optional | Name of the resource |
criteria.golden_device_id | array | Optional | Unique identifier |
criteria.golden_device_status | array | Optional | Status value |
criteria.asset_group_id | array | Optional | Unique identifier |
criteria.asset_group_name | array | Optional | Name of the resource |
criteria.host_based_firewall_status | array | Optional | Status value |
Input Example
{"path_parameters":{"org_key":"string"},"criteria":{"ad_distinguished_name":["string"],"ad_domain":["string"],"ad_group_id":["string"],"ad_org_unit":["string"],"auto_scaling_group_name":["string"],"base_device":true,"cloud_provider_account_id":"string","cloud_provider_managed_identity":["string"],"cloud_provider_network":["string"],"cloud_provider_resource_group":["string"],"cloud_provider_resource_id":["string"],"cloud_provider_scale_group":["string"],"cloud_provider_tags":["string"],"cluster_name":["string"],"compliance_status":["string"],"datacenter_name":["string"],"deployment_type":["string"],"esx_host_name":["string"],"golden_device_id":["string"],"golden_device_status":["string"],"asset_group_id":["string"],"asset_group_name":["string"],"host_based_firewall_status":["string"],"id":["string"],"infrastructure_provider":["string"],"last_contact_time":{"end":"string","range":"string","start":"string"},"os":["string"],"os_version":["string"],"policy_id":["string"],"sensor_gateway_url":["string"],"sensor_version":["string"],"signature_status":["string"],"status":["string"],"sub_deployment_type":["string"],"subnet":["string"],"target_priority":["string"],"vcenter_host_url":["string"],"vcenter_name":["string"],"vcenter_uuid":["string"],"virtual_private_cloud_id":["string"],"virtualization_provider":["string"],"vm_uuid":["string"]},"exclusions":{"sensor_version":["string"]},"query":"string","sort":[{"field":"string","order":"string"}],"rows":"string","start":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
num_found | number | Output field: num_found |
results | array | Result of the operation |
results.activation_code | object | Result of the operation |
results.activation_code_expiry_time | string | Result of the operation |
results.ad_domain | object | Result of the operation |
results.ad_group_id | number | Unique identifier |
results.ad_org_unit | object | Result of the operation |
results.appliance_name | object | Name of the resource |
results.appliance_uuid | object | Unique identifier |
results.auto_scaling_group_name | object | Name of the resource |
results.av_ave_version | string | Result of the operation |
results.av_engine | string | Result of the operation |
results.av_last_scan_time | object | Result of the operation |
results.av_master | boolean | Result of the operation |
results.av_pack_version | string | Result of the operation |
results.av_product_version | string | Result of the operation |
results.av_status | array | Status value |
results.av_update_servers | object | Result of the operation |
results.av_vdf_version | string | Result of the operation |
results.base_device | object | Result of the operation |
results.cloud_provider_account_id | object | Unique identifier |
results.cloud_provider_resource_id | object | Unique identifier |
results.cloud_provider_tags | array | Unique identifier |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"num_found":1,"results":[{}]}}
Search Specific Device Vulnerabilities
Retrieve vulnerability information for a specific device in VMWare Carbon Black Cloud using the organization key and device ID.
Endpoint
- URL: /vulnerability/assessment/api/v1/orgs/{{org_key}}/devices/{{device_id}}/vulnerabilities/_search
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Filter down to a single organization. |
path_parameters.device_id | string | Required | Parameters for the Search Specific Device Vulnerabilities action |
parameters.dataForExport | boolean | Optional | Whether to send detailed data for export. If not set to true, vuln_info will be null. |
query | string | Optional | Query to search vulnerability list. |
rows | number | Optional | For pagination, how many results to return per page. Maximum value is 1000. |
start | number | Optional | For pagination, where to start retrieving results from. |
criteria | object | Optional | Criteria is an object that represents values that must be in the results. |
sort | array | Optional | Sort is a collection of sort parameters that specify a field and order to sort the results. Only one sort can be specified at this time. |
sort.field | string | Optional | Parameter for Search Specific Device Vulnerabilities |
sort.order | string | Optional | Parameter for Search Specific Device Vulnerabilities |
Input Example
{"parameters":{"dataForExport":false},"json_body":{"query":"Python","rows":20,"start":0,"criteria":{},"sort":[{"field":"risk_meter_score","order":"DESC"}]},"path_parameters":{"org_key":"7DESJ9GN","device_id":"7773485"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
num_found | number | Output field: num_found |
results | array | Result of the operation |
results.os_product_id | string | Unique identifier |
results.category | string | Result of the operation |
results.os_info | object | Result of the operation |
results.os_info.os_type | string | Type of the resource |
results.os_info.os_name | string | Name of the resource |
results.os_info.os_version | string | Result of the operation |
results.os_info.os_arch | string | Result of the operation |
results.product_info | object | Result of the operation |
results.product_info.vendor | string | Result of the operation |
results.product_info.product | string | Result of the operation |
results.product_info.version | string | Result of the operation |
results.product_info.release | string | Result of the operation |
results.product_info.arch | string | Result of the operation |
results.vuln_info | object | Result of the operation |
results.vuln_info.cve_id | string | Unique identifier |
results.vuln_info.cve_description | string | Result of the operation |
results.vuln_info.risk_meter_score | number | Result of the operation |
results.vuln_info.severity | string | Result of the operation |
results.vuln_info.fixed_by | string | Result of the operation |
results.vuln_info.solution | object | Result of the operation |
results.vuln_info.created_at | string | Result of the operation |
Output Example
{"num_found":123,"results":[{"os_product_id":"string","category":"string","os_info":{},"product_info":{},"vuln_info":{},"device_count":123,"affected_assets":{},"rule_id":{},"dismissed":true,"dismiss_reason":{},"notes":{},"dismissed_on":{},"dismissed_by":{},"deployment_type":{}}]}
Set Background Scan for Device
Configures background scan settings on a device in VMWare Carbon Black Cloud using the device ID and specified action type.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/device_actions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Set Background Scan for Device action |
action_type | string | Optional | Type of the resource |
device_id | array | Optional | Unique identifier |
options | object | Optional | Parameter for Set Background Scan for Device |
options.toggle | string | Optional | Parameter for Set Background Scan for Device |
Input Example
{"json_body":{"action_type":"BACKGROUND_SCAN","device_id":["12312","12320"],"options":{"toggle":"ON"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":204,"response_headers":{},"reason":"Successful device action creation","json_body":{}}
Uninstall Sensor Device
Initiates the uninstallation of a sensor on a device by using the device ID and organization key in VMWare Carbon Black Cloud.
Endpoint
- URL: /appservices/v6/orgs/{{org_key}}/device_actions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Uninstall Sensor Device action |
action_type | string | Optional | Type of the resource |
device_id | array | Optional | Unique identifier |
Input Example
{"json_body":{"action_type":"UNINSTALL_SENSOR","device_id":["12131","12132"]},"path_parameters":{"org_key":"7DESJ9GN"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":204,"response_headers":{"Date":"Mon, 18 Mar 2024 10:38:47 GMT","Connection":"keep-alive","Cache-Control":"no-cache, no-store, max-age=0, must-revalidate","Expires":"0","Pragma":"no-cache","Set-Cookie":"JSESSIONID=A54F220267AAEFA2F8A7F2B702152306; Path=/appservices; Secure; HttpOnly","X-Content-Type-Options":"nosniff","X-Frame-Options":"DENY","X-Xss-Protection":"1; mode=block"},"reason":"No Content","response_text":""}
Update Alert
Performs an asynchronous update of alerts in VMWare Carbon Black Cloud using the 'org_key' path parameter.
Endpoint
- URL: /api/alerts/v7/orgs/{{org_key}}/alerts/workflow
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Update Alert action |
query | string | Optional | Parameter for Update Alert |
time_range | object | Optional | Parameter for Update Alert |
time_range.start | string | Optional | Parameter for Update Alert |
time_range.end | string | Optional | Parameter for Update Alert |
time_range.range | string | Optional | Parameter for Update Alert |
criteria | string | Optional | Parameter for Update Alert |
exclusions | string | Optional | Parameter for Update Alert |
determination | string | Optional | Parameter for Update Alert |
closure_reason | string | Optional | Response reason phrase |
status | string | Optional | Status value |
note | string | Optional | Parameter for Update Alert |
Input Example
{"json_body":{"query":"<string>","time_range":{"start":"<string>","end":"<string>","range":"<string>"},"criteria":"<object>","exclusions":"<object>","determination":"<string>","closure_reason":"<string>","status":"<string>","note":"<string>"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
request_id | string | Unique identifier |
Output Example
{"status_code":204,"response_headers":{},"reason":"OK","json_body":{"request_id":"5372752"}}
Update Device Policy
Updates an existing device policy in VMWare Carbon Black Cloud using the provided organization key and policy ID.
Endpoint
- URL: /policyservice/v1/orgs/{{org_key}}/policies/{{policy_id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.org_key | string | Required | Parameters for the Update Device Policy action |
path_parameters.policy_id | string | Required | Parameters for the Update Device Policy action |
id | number | Optional | Unique identifier |
name | string | Optional | Name of the resource |
org_key | string | Optional | Parameter for Update Device Policy |
priority_level | string | Optional | Parameter for Update Device Policy |
position | number | Optional | Parameter for Update Device Policy |
is_system | boolean | Optional | Parameter for Update Device Policy |
description | string | Optional | Parameter for Update Device Policy |
auto_deregister_inactive_vdi_interval_ms | number | Optional | Parameter for Update Device Policy |
auto_delete_known_bad_hashes_delay | object | Optional | Parameter for Update Device Policy |
av_settings | object | Optional | Parameter for Update Device Policy |
av_settings.avira_protection_cloud | object | Optional | Parameter for Update Device Policy |
av_settings.avira_protection_cloud.enabled | boolean | Optional | Parameter for Update Device Policy |
av_settings.avira_protection_cloud.max_exe_delay | number | Optional | Parameter for Update Device Policy |
av_settings.avira_protection_cloud.max_file_size | number | Optional | Parameter for Update Device Policy |
av_settings.avira_protection_cloud.risk_level | number | Optional | Parameter for Update Device Policy |
av_settings.on_access_scan | object | Optional | Parameter for Update Device Policy |
av_settings.on_access_scan.enabled | boolean | Optional | Parameter for Update Device Policy |
av_settings.on_access_scan.mode | string | Optional | Parameter for Update Device Policy |
av_settings.on_demand_scan | object | Optional | Parameter for Update Device Policy |
av_settings.on_demand_scan.enabled | boolean | Optional | Parameter for Update Device Policy |
av_settings.on_demand_scan.profile | string | Optional | Parameter for Update Device Policy |
av_settings.on_demand_scan.schedule | object | Optional | Parameter for Update Device Policy |
av_settings.on_demand_scan.schedule.days | object | Optional | Parameter for Update Device Policy |
Input Example
{"json_body":{"id":4920125,"name":"Standard","org_key":"ABCD1234","priority_level":"MEDIUM","position":-1,"is_system":true,"description":"Prevents known malware and reduces false positives. Used as the default policy for all new sensors, unless sensor group criteria is met.","auto_deregister_inactive_vdi_interval_ms":0,"auto_delete_known_bad_hashes_delay":null,"av_settings":{"avira_protection_cloud":{"enabled":false,"max_exe_delay":45,"max_file_size":4,"risk_level":4},"on_access_scan":{"enabled":true,"mode":"NORMAL"},"on_demand_scan":{"enabled":true,"profile":"NORMAL","schedule":{"days":null,"start_hour":0,"range_hours":0,"recovery_scan_if_missed":true},"scan_usb":"AUTOSCAN","scan_cd_dvd":"AUTOSCAN"},"signature_update":{"enabled":true,"schedule":{"full_interval_hours":0,"initial_random_delay_hours":4,"interval_hours":4}},"update_servers":{"servers_override":[],"servers_for_onsite_devices":[{"server":"http://updates2.cdc.carbonblack.io/update2","preferred":false}],"servers_for_offsite_devices":["http://updates2.cdc.carbonblack.io/update2"]}},"rules":[{"id":1,"required":false,"action":"TERMINATE","application":{"type":"REPUTATION","value":"KNOWN_MALWARE"},"operation":"RUN"},{"id":2,"required":false,"action":"TERMINATE","application":{"type":"REPUTATION","value":"COMPANY_BLACK_LIST"},"operation":"RUN"}],"directory_action_rules":[],"sensor_settings":[{"name":"ALLOW_UNINSTALL","value":"true"}],"managed_detection_response_permissions":{"policy_modification":true,"quarantine":true},"version":null,"message":null,"rule_configs":[]},"path_parameters":{"org_key":"ABCD1234","policy_id":"4920125"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | number | Unique identifier |
name | string | Name of the resource |
org_key | string | Output field: org_key |
priority_level | string | Output field: priority_level |
position | number | Output field: position |
is_system | boolean | Output field: is_system |
description | string | Output field: description |
auto_deregister_inactive_vdi_interval_ms | number | Output field: auto_deregister_inactive_vdi_interval_ms |
auto_delete_known_bad_hashes_delay | object | Output field: auto_delete_known_bad_hashes_delay |
av_settings | object | Output field: av_settings |
av_settings.avira_protection_cloud | object | Output field: av_settings.avira_protection_cloud |
av_settings.avira_protection_cloud.enabled | boolean | Output field: av_settings.avira_protection_cloud.enabled |
av_settings.avira_protection_cloud.max_exe_delay | number | Output field: av_settings.avira_protection_cloud.max_exe_delay |
av_settings.avira_protection_cloud.max_file_size | number | Output field: av_settings.avira_protection_cloud.max_file_size |
av_settings.avira_protection_cloud.risk_level | number | Output field: av_settings.avira_protection_cloud.risk_level |
av_settings.on_access_scan | object | Output field: av_settings.on_access_scan |
av_settings.on_access_scan.enabled | boolean | Output field: av_settings.on_access_scan.enabled |
av_settings.on_access_scan.mode | string | Output field: av_settings.on_access_scan.mode |
av_settings.on_demand_scan | object | Output field: av_settings.on_demand_scan |
av_settings.on_demand_scan.enabled | boolean | Output field: av_settings.on_demand_scan.enabled |
av_settings.on_demand_scan.profile | string | Output field: av_settings.on_demand_scan.profile |
av_settings.on_demand_scan.schedule | object | Output field: av_settings.on_demand_scan.schedule |
av_settings.on_demand_scan.schedule.days | object | Output field: av_settings.on_demand_scan.schedule.days |
Output Example
{"status_code":204,"response_headers":{},"reason":"OK","json_body":{"id":4920125,"name":"Standard","org_key":"ABCD1234","priority_level":"MEDIUM","position":-1,"is_system":true,"description":"Prevents known malware and reduces false positives. Used as the default policy f...","auto_deregister_inactive_vdi_interval_ms":0,"auto_delete_known_bad_hashes_delay":null,"av_settings":{"avira_protection_cloud":{},"on_access_scan":{},"on_demand_scan":{},"signature_update":{},"update_servers":{}},"rules":[{...
Response Headers
Header | Description | Example |
|---|---|---|
Cache-Control | Directives for caching mechanisms | no-cache, no-store, max-age=0, must-revalidate |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Fri, 07 Jun 2024 08:36:38 GMT |
Expires | The date/time after which the response is considered stale | 0 |
Pragma | HTTP response header: Pragma | no-cache |
Requestid | HTTP response header: Requestid | 77fcfadb1471584ad917f590f10d040a |
Set-Cookie | HTTP response header: Set-Cookie | JSESSIONID=A54F220267AAEFA2F8A7F2B702152306; Path=/appservices; Secure; HttpOnly |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding, Origin, Access-Control-Request-Method, Access-Control-Request-Headers |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | DENY |
X-Xss-Protection | HTTP response header: X-Xss-Protection | 0 |