feat(cisco-umbrella-enforcement): new Cisco Umbrella Enforcement integration

Umbrella Enforcement API, 4 commands: add domain (DNS-layer block),
list enforced domains, delete domain. Customer-key auth, stdlib-only.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Guillaume BOURGEOIS
2026-07-11 23:13:24 +02:00
parent 8ee19ffe85
commit fb82de7f93
5 changed files with 290 additions and 0 deletions
@@ -0,0 +1,62 @@
id: cisco_umbrella_enforcement
name: Cisco Umbrella Enforcement
version: 1.0.0
description: "Cisco Umbrella Enforcement API — DNS-layer containment: push malicious domains to the enforcement block list, list enforced domains, and remove them. Customer-key authentication; stdlib-only, no extra Python dependencies."
changelog: "1.0.0 — Initial release: add domain event (block), list domains, delete domain."
category: network
# Per-instance configuration. The customer key is appended as the 'customerKey'
# query parameter on every request.
config_schema:
properties:
api_url:
type: string
description: "Enforcement API base URL"
default: "https://s-platform.api.opendns.com"
api_key:
type: string
description: "Umbrella Enforcement customer key"
x-soar-sensitive: true
required:
- api_key
commands:
- id: add_domain
name: umbrella-add-domain
description: "Submit a security event that adds a domain to the Umbrella enforcement block list."
inputs_schema:
properties:
domain: { type: string, description: "Domain to block (e.g. malicious.example.com)" }
url: { type: string, description: "Destination URL (defaults to http://<domain>/)" }
device_id: { type: string, description: "Reporting device id (defaults to a fixed Riposte device id)" }
device_version: { type: string, description: "Reporting device version (default 1.0)" }
provider_name: { type: string, description: "Provider name (default 'Riposte SOAR')" }
required: [domain]
outputs_schema: { properties: {} }
- id: list_domains
name: umbrella-list-domains
description: "List the domains currently in the enforcement block list."
risk: read
inputs_schema:
properties:
page: { type: number, description: "Page number (default 1)" }
limit: { type: number, description: "Domains per page (default 200)" }
required: []
outputs_schema: { properties: {} }
- id: delete_domain
name: umbrella-delete-domain
description: "Remove a domain from the enforcement block list by its numeric id."
inputs_schema:
properties:
domain_id: { type: string, description: "Numeric id of the domain to remove (from umbrella-list-domains)" }
required: [domain_id]
outputs_schema: { properties: {} }
- id: test_connection
name: umbrella-test-connection
description: "Verify connectivity and the customer key (used by the Test button)."
risk: read
inputs_schema:
properties: {}
required: []
outputs_schema: { properties: {} }