feat(cisco-umbrella-enforcement): new Cisco Umbrella Enforcement integration
Umbrella Enforcement API, 4 commands: add domain (DNS-layer block), list enforced domains, delete domain. Customer-key auth, stdlib-only. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,62 @@
|
||||
id: cisco_umbrella_enforcement
|
||||
name: Cisco Umbrella Enforcement
|
||||
version: 1.0.0
|
||||
description: "Cisco Umbrella Enforcement API — DNS-layer containment: push malicious domains to the enforcement block list, list enforced domains, and remove them. Customer-key authentication; stdlib-only, no extra Python dependencies."
|
||||
changelog: "1.0.0 — Initial release: add domain event (block), list domains, delete domain."
|
||||
category: network
|
||||
|
||||
# Per-instance configuration. The customer key is appended as the 'customerKey'
|
||||
# query parameter on every request.
|
||||
config_schema:
|
||||
properties:
|
||||
api_url:
|
||||
type: string
|
||||
description: "Enforcement API base URL"
|
||||
default: "https://s-platform.api.opendns.com"
|
||||
api_key:
|
||||
type: string
|
||||
description: "Umbrella Enforcement customer key"
|
||||
x-soar-sensitive: true
|
||||
required:
|
||||
- api_key
|
||||
|
||||
commands:
|
||||
- id: add_domain
|
||||
name: umbrella-add-domain
|
||||
description: "Submit a security event that adds a domain to the Umbrella enforcement block list."
|
||||
inputs_schema:
|
||||
properties:
|
||||
domain: { type: string, description: "Domain to block (e.g. malicious.example.com)" }
|
||||
url: { type: string, description: "Destination URL (defaults to http://<domain>/)" }
|
||||
device_id: { type: string, description: "Reporting device id (defaults to a fixed Riposte device id)" }
|
||||
device_version: { type: string, description: "Reporting device version (default 1.0)" }
|
||||
provider_name: { type: string, description: "Provider name (default 'Riposte SOAR')" }
|
||||
required: [domain]
|
||||
outputs_schema: { properties: {} }
|
||||
- id: list_domains
|
||||
name: umbrella-list-domains
|
||||
description: "List the domains currently in the enforcement block list."
|
||||
risk: read
|
||||
inputs_schema:
|
||||
properties:
|
||||
page: { type: number, description: "Page number (default 1)" }
|
||||
limit: { type: number, description: "Domains per page (default 200)" }
|
||||
required: []
|
||||
outputs_schema: { properties: {} }
|
||||
- id: delete_domain
|
||||
name: umbrella-delete-domain
|
||||
description: "Remove a domain from the enforcement block list by its numeric id."
|
||||
inputs_schema:
|
||||
properties:
|
||||
domain_id: { type: string, description: "Numeric id of the domain to remove (from umbrella-list-domains)" }
|
||||
required: [domain_id]
|
||||
outputs_schema: { properties: {} }
|
||||
|
||||
- id: test_connection
|
||||
name: umbrella-test-connection
|
||||
description: "Verify connectivity and the customer key (used by the Test button)."
|
||||
risk: read
|
||||
inputs_schema:
|
||||
properties: {}
|
||||
required: []
|
||||
outputs_schema: { properties: {} }
|
||||
Reference in New Issue
Block a user