Skip to main content

Darktrace AI Analyst

This Integration is part of the Darktrace Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.6.0 and later.

Darktrace is a Cyber AI platform for threat detection and response across cloud, email, industrial, and the network. This integration was integrated and tested with version 6.0.0 of Darktrace

Configure Darktrace in Cortex#

ParameterDescriptionRequired
urlServer URL (e.g. https://example.net\)True
isFetchFetch incidentsFalse
insecureTrust any certificate (not secure)False
proxyUse system proxy settingsFalse
public_api_tokenPublic API TokenTrue
private_api_tokenPrivate API TokenTrue
min_scoreMinimum ScoreTrue
max_alertsMaximum Model Breaches per FetchFalse
first_fetchFirst fetch timeFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

darktrace-get-ai-analyst-incident-event#


Returns all AI Analyst incident events

Base Command#

darktrace-get-ai-analyst-incident-event

Input#

Argument NameDescriptionRequired
eventIdUnique identified of an AI Analyst incident eventRequired

Context Output#

PathTypeDescription
Darktrace.AIAnalyst.eventIdUnknownAIAnalyst unique identifier
Darktrace.AIAnalyst.titleStringAIAnalyst event title
Darktrace.AIAnalyst.mitreTacticsUnknownAIAnalyst mitre tactics seen on event
Darktrace.AIAnalyst.scoreUnknowngroup score for ai analyst incident
Darktrace.AIAnalyst.categoryStringgroup category for ai analyst incident
Darktrace.AIAnalyst.summaryStringAIAnalyst event summary
Darktrace.AIAnalyst.groupIdUnknownunique identifier for event Id
Darktrace.AIAnalyst.devicesUnknownAssociated devices with incident event
Darktrace.AIAnalyst.modelBreachesUnknownAssociated model breaches with event Id

darktrace-get-comments-for-ai-analyst-incident-event#


Returns all Darktrace Comments for a given Incident Event

Base Command#

darktrace-get-comments-for-ai-analyst-incident-event

Input#

Argument NameDescriptionRequired
eventIdUnique identified of an AI Analyst incident eventRequired

Context Output#

PathTypeDescription
Darktrace.AIAnalyst.incidet_idNumberIncident event unique identifier
Darktrace.AIAnalyst.messageStringPosted message
Darktrace.AIAnalyst.eventIdStringUnique event identifier
Darktrace.AIAnalyst.timeStringMessage post timestamp
Darktrace.AIAnalyst.usernameStringDarktrace username of posting user

darktrace-post-comment-to-ai-analyst-incident-event#


Post comment to an AI Analyst Incident Event.

Base Command#

darktrace-post-comment-to-ai-analyst-incident-event

Input#

Argument NameDescriptionRequired
eventIdUnique identified of an AI Analyst incident eventRequired
commentEnter a message to commentRequired

Context Output#

PathTypeDescription
Darktrace.AIAnalyst.commentedStringWhether the incident is commented in Darktrace
Darktrace.AIAnalyst.responseStringPost command response
Darktrace.AIAnalyst.eventIdStringUnique event identifier
Darktrace.AIAnalyst.messageStringMessage to be commented

darktrace-acknowledge-ai-analyst-incident-event#


Acknowledges an AI Analyst Incident Event

Base Command#

darktrace-acknowledge-ai-analyst-incident-event

Input#

Argument NameDescriptionRequired
eventIdUnique identified of an AI Analyst incident eventRequired

Context Output#

PathTypeDescription
Darktrace.AIAnalyst.acknowledgedStringWhether the incident is acknowledge in Darktrace
Darktrace.AIAnalyst.responseStringPost response comment
Darktrace.AIAnalyst.eventIdStringincident event unique identifier

darktrace-unacknowledge-ai-analyst-incident-event#


Unacknowledges an AI Analyst Incident Event

Base Command#

darktrace-unacknowledge-ai-analyst-incident-event

Input#

Argument NameDescriptionRequired
eventIdUnique identified of an AI Analyst incident eventRequired

Context Output#

PathTypeDescription
Darktrace.AIAnalyst.unacknowledgedStringWhether the incident is acknowledge in Darktrace
Darktrace.AIAnalyst.responseStringPost response comment
Darktrace.AIAnalyst.eventIdStringincident event unique identifier

darktrace-get-ai-analyst-incident-group-from-eventId#


Pulls all linked events for a given event. Over time, events can become merged with one another. This happens when two sets of disparate activity are suddenly linked by shared factors.

Base Command#

darktrace-get-ai-analyst-incident-group-from-eventId

Input#

Argument NameDescriptionRequired
eventIdUnique identified of an AI Analyst incident eventRequired

Context Output#

PathTypeDescription
Darktrace.AIAnalyst.groupIdStringInvestigation Group Unique Identifier
Darktrace.AIAnalyst.incidentEventsUnknownAssociated events
Darktrace.AIAnalyst.mitreTacticsUnknownAssociated Mitre Tactics seen on incident
Darktrace.AIAnalyst.groupScoreNumberGroup score
Darktrace.AIAnalyst.groupCategoryStringGroup category