SOC Interfaces
This document lists the interface contracts available in the SOC Solutions Bundle. For general information about what interfaces are and how to use them, see Working with InterfacesWorking with Interfaces. For complete data model field definitions, see Turbine Schema Reference (Classic SOC)Turbine Schema Reference (Classic SOC).
SOC Solutions Bundle Interfaces
The SOC Solutions Bundle includes 20 interfaces for Security Operations Center workflows. Use these interfaces for alert triage, observable enrichment, email processing, and remediation actions.
Alert to None v1.0.2
Purpose: Processes an alert object without producing output. Use this interface for alert ingestion workflows where you process alerts without transforming them.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
alert | object | Yes | Alert object |
alert.alert_categories | array of strings | No | Alert categories |
alert.alert_created_timestamp | string | No | When the alert was created |
alert.alert_description | string | No | Alert description |
alert.alert_end_timestamp | string | No | Alert end time |
alert.alert_impacted_hostnames | array of strings | No | Affected hostnames |
alert.alert_impacted_ip_addresses | array of strings | No | Affected IP addresses |
alert.alert_impacted_usernames | array of strings | No | Affected usernames |
alert.alert_ingested_timestamp | string | No | When alert was ingested |
alert.alert_mitre_attack_tactic_technique | array of objects | No | MITRE ATT&CK mappings |
alert.alert_mitre_attack_tactic_technique.tactics | array | No | Tactic information |
alert.alert_mitre_attack_tactic_technique.technique | object | No | Technique details with name, uid |
alert.alert_mitre_attack_tactic_technique.technique.name | string | No | Technique name |
alert.alert_mitre_attack_tactic_technique.technique.uid | string | No | Technique UID |
alert.alert_mitre_attack_tactic_technique.version | string | No | ATT&CK version |
alert.alert_organization | string | No | Organization identifier |
alert.alert_originating_files | array of objects | No | Files associated with alert |
alert.alert_originating_files.content | object | No | File content (base64 or turbine_attachment) |
alert.alert_originating_files.file_hashes | array | No | Hash information |
alert.alert_originating_files.observables | array | No | Observable data |
alert.alert_permalink | string | No | Link to alert details |
alert.alert_provider | string | No | Alert source provider |
alert.alert_risk_score | integer | No | Risk score |
alert.alert_rules | array | No | Rules that triggered the alert |
alert.alert_severity | string | No | Alert severity level |
alert.alert_start_timestamp | string | No | Alert start time |
alert.alert_title | string | No | Alert title |
alert.alert_uid | string | No | Unique alert identifier |
alert.observables | array | No | Observable entities |
alert.raw_alert | object | No | Raw alert data |
Output schema: Empty object (no output)
Use cases:
- Alert ingestion pipelines
- Alert logging and archival
- Alert forwarding without transformation
Array of Alerts to None v1.0.2
Purpose: Processes an array of alerts without producing output. Use this interface for bulk alert processing.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
alerts | array of alert objects | Yes | Array of alert objects to process |
Output schema: Empty object (no output)
Use cases:
- Bulk alert ingestion
- Alert batch processing
- Alert archival workflows
Array of Simple Observable to None v1.0.2
Purpose: Processes an array of simple observable objects without producing output.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
observables | array of objects | Yes | Array of simple observable objects |
observables[].observable_type | string | Yes | Type of observable |
observables[].observable_value | string | Yes | Observable value |
Output schema: Empty object (no output)
Use cases:
- Bulk observable ingestion
- Observable logging
- Observable forwarding
Simple Observable to None v1.0.2
Purpose: Processes a simple observable without producing output.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
observable | object | No | Observable object |
observable.observable_type | string | No | Type of observable |
observable.observable_value | string | No | Observable value |
Output schema: Empty object (no output)
Use cases:
- Observable logging
- Observable ingestion
- Observable forwarding
Phishing Email Report to None v1.0.2
Purpose: Processes phishing email report objects without producing output.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
phishing_email_report | object | No | Phishing email report data |
Output schema: Empty object (no output)
Use cases:
- Phishing report ingestion
- Phishing report logging
- Phishing report archival
Alert Triage Ingestion to Array of Alert v1.0.2
Purpose: Converts triage ingestion data into an array of standardized alert objects.
Input schema: Triage ingestion format (specific structure)
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
alerts | array of alert objects | No | Array of standardized alert objects that match the Alert schema |
Use cases:
- Bulk alert ingestion
- Alert normalization from multiple sources
- Alert triage workflows
Simple Observable to Enrichment v1.0.2
Purpose: Converts a simple observable into an enrichment object that includes threat intelligence data.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
observable | object | Yes | Observable object |
observable.observable_metadata | object | No | Additional metadata |
observable.observable_type | string | Yes | Type of observable (such as "ip", "domain", or "hash") |
observable.observable_value | string | Yes | The observable value |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
enrichment | object | No | Enrichment object |
enrichment.enrichment_context | string | No | Context information |
enrichment.enrichment_permalink | string | No | Link to enrichment details |
enrichment.enrichment_provider | string | No | Enrichment data provider name |
enrichment.enrichment_raw_data | string | No | Raw enrichment data |
enrichment.enrichment_timestamp | string | No | When enrichment was retrieved |
enrichment.enrichment_type | string | No | Type of enrichment (such as "location" or "reputation") |
enrichment.enrichment_verdict | string | No | Reputation verdict |
Use cases:
- Threat intelligence enrichment
- Observable reputation checking
- Security context gathering
Simple Observable to Observable v1.0.2
Purpose: Converts a simple observable into a full observable object with enrichment capabilities.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
observable | object | No | Observable object |
observable.observable_type | string | No | Type of observable |
observable.observable_value | string | No | Observable value |
observable.observable_metadata | object | No | Additional metadata |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
observable | object | No | Full observable object with enrichment fields |
Use cases:
- Observable normalization
- Observable enrichment preparation
- Data structure standardization
Text to Array of Observables v1.0.2
Purpose: Extracts observables from text content and returns them as an array.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
text_value | string | Yes | Text content to parse for observables |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
observables | array of objects | No | Array of extracted observables |
observables[].observable_type | string | No | Type of extracted observable |
observables[].observable_value | string | No | The extracted value |
Use cases:
- Email body parsing
- Log file analysis
- Text extraction from documents
- IOC extraction from reports
Object to Alert v1.0.2
Purpose: Converts a generic object into a standardized alert object.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
object | object | No | Generic object with alert-related fields |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
alert | object | No | Standardized alert object matching Alert schema |
Use cases:
- Alert normalization from various sources
- Custom alert format conversion
- Alert standardization
Error to Enrichment v1.0.2
Purpose: Converts error information into an enrichment object for error tracking and analysis.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
error | object | No | Error information |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
enrichment | object | No | Enrichment object containing error context |
Use cases:
- Error tracking
- Error enrichment
- Error analysis workflows
Email to Email v1.0.2
Purpose: Converts email objects while preserving the email structure. Used for email processing workflows.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
object | Yes | Email object | |
email.email_bcc_addresses | array of strings | No | BCC recipients |
email.email_body | string | No | Email body content |
email.email_cc_addresses | array of strings | No | CC recipients |
email.email_delivery_timestamp | string | No | Delivery timestamp |
email.email_from_address | string | No | Sender address |
email.email_headers | array of objects | No | Email headers |
email.email_headers[].header_key | string | No | Header name |
email.email_headers[].header_value | string | No | Header value |
email.email_html_body | string | No | HTML body content |
email.email_message_id | string | No | Message ID |
email.email_mime_parts | array of objects | No | MIME parts |
email.email_mime_parts[].content | object | No | Content (base64 or turbine_attachment) |
email.email_mime_parts[].file_name | string | No | File name |
email.email_mime_parts[].is_attachment | boolean | No | Whether it is an attachment |
email.email_mime_parts[].mime_type | string | No | MIME type |
email.email_organization | string | No | Organization identifier |
email.email_origination_timestamp | string | No | Origination time |
email.email_reply_to_addresses | array of strings | No | Reply-to addresses |
email.email_subject | string | No | Email subject |
email.email_text_body | string | No | Plain text body |
email.email_to_addresses | array of strings | No | TO recipients |
email.observables | array | No | Observable entities extracted from email |
email.raw_email | string | No | Raw email content |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
object | No | Transformed email object with same structure |
Use cases:
- Email processing workflows
- Email transformation
- Email forwarding
- Email analysis
Turbine Attachment to Email v1.0.2
Purpose: Converts a Turbine attachment object into an email object format.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
turbine_attachment | object | No | Turbine attachment object |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
object | No | Email object structure |
Use cases:
- Attachment to email conversion
- Email reconstruction from attachments
- Email processing workflows
File to File v1.0.2
Purpose: Converts file objects while preserving file structure.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
file | object | No | File object with file metadata and content |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
file | object | No | Transformed file object |
Use cases:
- File processing workflows
- File transformation
- File forwarding
Header to Header v1.0.2
Purpose: Converts header objects (email or HTTP headers).
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
header | object | No | Header object |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
header | object | No | Transformed header object |
Use cases:
- Header processing
- Header transformation
- Header analysis
MIME Part to MIME Part v1.0.2
Purpose: Converts MIME part objects while preserving structure.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
mime_part | object | No | MIME part object |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
mime_part | object | No | Transformed MIME part object |
Use cases:
- MIME part processing
- Email attachment handling
- Content extraction
Phishing Triage Email Ingestion to Array of Phishing Email Report v1.0.2
Purpose: Converts phishing triage email ingestion data into an array of phishing email reports.
Input schema: Phishing triage ingestion format
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
phishing_email_reports | array of objects | No | Array of phishing email report objects |
Use cases:
- Bulk phishing email processing
- Phishing triage workflows
- Phishing report generation
Block/Unblock Observable Remediation Action
Purpose: Performs block or unblock actions on observables (such as IPs and domains) in security systems.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
observable | string | Yes | The observable value to block or unblock |
observable_type | string | Yes | Type of observable (such as "ip" or "domain") |
action | string | Yes | Action to perform ("block" or "unblock") |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
block_message | string | No | Response message from the remediation action |
Use cases:
- IP address blocking/unblocking
- Domain blocking
- Threat containment workflows
- Security control automation
Enable/Disable User Account Remediation Action
Purpose: Enables or disables user accounts in identity management systems.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
user_account | string | Yes | The user account identifier to enable or disable |
action | string | Yes | Action to perform ("enable" or "disable") |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
response_message | string | No | Response message from the account action |
Use cases:
- Account remediation
- Incident response
- Access control automation
- User account management
Isolate/Rejoin Hosts Remediation Action
Purpose: Isolates or rejoins hosts in network security systems.
Input schema:
Field | Type | Required | Description |
|---|---|---|---|
host | string | Yes | Host identifier to isolate or rejoin |
action | string | Yes | Action to perform ("isolate" or "rejoin") |
Output schema:
Field | Type | Required | Description |
|---|---|---|---|
response_message | string | No | Response message from the remediation action |
Use cases:
- Host isolation during incidents
- Network containment
- Incident response automation
- Security control workflows