Skip to main content

CybleEvents v2

This Integration is part of the CybleEventsV2 Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.2.0 and later.

Cyble Events for Vision Users. Must have Vision API access to use the threat intelligence. This integration was integrated and tested with version 2.0 of cybleeventsv2

Configure CybleEventsV2 on Cortex XSOAR#

  1. Navigate to Settings > Integrations > Servers & Services. Search for CybleEventsV2. Click Add instance to create and configure a new integration instance.

    ParameterDescriptionRequired
    URLServer URL (e.g., https://example.net\)True
    Access TokenAccess TokenTrue
    Collections to FetchSelect collections of incidents to be fetched from the dropdown menuFalse
    Severities to FetchSelect severities of incident to be fetched from the dropdown menuFalse
    Trust any certificate (not secure)False
    Use system proxy settingsFalse
    Incident Fetch LimitMaximum incidents to be fetched every time. Upper limit is 50 incidentsFalse
    Hide Card DetailsSelect to hide CVV and Expiry date of cardFalse
    Update Incident to Remote SystemSelect to update changes in any incident to VisionFalse
  2. To ensure that fetch incidents works:

    • Select the Fetches incidents radio button.
    • Under Incident type, select Cyble Vision Alert V2.
  3. Click Test to validate the URLs, token, and connection.

Commands#

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

cyble-vision-subscribed-services#


Get list of Subscribed services

Base Command#

cyble-vision-subscribed-services

Input#

There are no input arguments for this command.

Context Output#

PathTypeDescription
CybleEvents.SubscribedServicesStringA list of subscribed services from Cyble vision

cyble-vision-fetch-iocs#


Fetch the indicators in the given timeline.

Base Command#

cyble-vision-fetch-iocs

Input#

Argument NameDescriptionRequired
ioc_typeReturns records according to their type (Domain, FileHash-MD5, FileHash-SHA1, FileHash-SHA256, IPv4, IPv6, URL, Email, Wallet-Address). Default is Domain.Optional
iocReturns records for the specified indicator value.Optional
fromReturns records that starts from the given page number (the value of the form parameter) in the results list. Default is 1.Optional
limitNumber of records to return (max 100). Using a smaller limit will get faster responses. Default is 1.Optional
sort_bySorting based on the column(last_seen,first_seen,ioc_type). Possible values are: last_seen, first_seen, ioc_type. Default is last_seen.Optional
orderSorting order for ioc either Ascending or Descending based on sort by. Default is desc.Optional
tagsReturns records for the specified tags.Optional
start_dateTimeline start date in the format "YYYY-MM-DD". Should be used with start_date as timeline range.Optional
end_dateTimeline end date in the format "YYYY-MM-DD". Should be used with end_date as timeline range.Optional

Context Output#

PathTypeDescription
CybleEvents.IoCs.DataStringReturns indicator with risk score, confident rating, first seen and last seen

cyble-vision-fetch-alerts#


Fetch alerts based on the given parameters. The alerts would have multiple events grouped into one, based on a specific service type. This way the user will see, in some cases, more events than the limit provides.

Base Command#

cyble-vision-fetch-alerts

Input#

Argument NameDescriptionRequired
limitNumber of records to return (max 50). Using a smaller limit will get faster responses. Default is 5.Optional
start_dateTimeline start date in the format "%Y-%m-%dT%H:%M:%S%z" (iso-8601).Required
end_dateTimeline end date in the format "%Y-%m-%dT%H:%M:%S%z" (iso-8601).Required
order_bySorting order for alert fetch either Ascending or Descending. Possible values are: asc, desc. Default is asc.Optional
fromReturns records for the timeline starting from the given indice. Default is 0.Optional

Context Output#

PathTypeDescription
CybleEvents.Events.nameStringReturn Event name
CybleEvents.Events.alert_group_idStringReturn alert group id
CybleEvents.Events.event_idStringReturn event id
CybleEvents.Events.keywordUnknownReturn keywords

cyble-vision-fetch-alert-groups#


Fetch incident event group

Base Command#

cyble-vision-fetch-alert-groups

Input#

Argument NameDescriptionRequired
order_bySorting order for alert fetch either Ascending or Descending. Possible values are: asc, desc. Default is asc.Optional
limitNumber of records to return (max 50). Using a smaller limit will get faster responses. Default is 5.Optional
start_dateTimeline start date in the format "%Y-%m-%dT%H:%M:%S%z" (iso-8601).Required
end_dateTimeline end date in the format "%Y-%m-%dT%H:%M:%S%z" (iso-8601).Required
from`Returns records that starts from the given page number (the value of the form parameter) in the results list. Default is 0.Required

Context Output#

PathTypeDescription
CybleEvents.AlertGroupStringFetch all the alert groups