id: cisco_umbrella_enforcement name: Cisco Umbrella Enforcement version: 1.0.0 description: "Cisco Umbrella Enforcement API — DNS-layer containment: push malicious domains to the enforcement block list, list enforced domains, and remove them. Customer-key authentication; stdlib-only, no extra Python dependencies." changelog: "1.0.0 — Initial release: add domain event (block), list domains, delete domain." category: network # Per-instance configuration. The customer key is appended as the 'customerKey' # query parameter on every request. config_schema: properties: api_url: type: string description: "Enforcement API base URL" default: "https://s-platform.api.opendns.com" api_key: type: string description: "Umbrella Enforcement customer key" x-soar-sensitive: true required: - api_key commands: - id: add_domain name: umbrella-add-domain description: "Submit a security event that adds a domain to the Umbrella enforcement block list." inputs_schema: properties: domain: { type: string, description: "Domain to block (e.g. malicious.example.com)" } url: { type: string, description: "Destination URL (defaults to http:///)" } device_id: { type: string, description: "Reporting device id (defaults to a fixed Riposte device id)" } device_version: { type: string, description: "Reporting device version (default 1.0)" } provider_name: { type: string, description: "Provider name (default 'Riposte SOAR')" } required: [domain] outputs_schema: { properties: {} } - id: list_domains name: umbrella-list-domains description: "List the domains currently in the enforcement block list." risk: read inputs_schema: properties: page: { type: number, description: "Page number (default 1)" } limit: { type: number, description: "Domains per page (default 200)" } required: [] outputs_schema: { properties: {} } - id: delete_domain name: umbrella-delete-domain description: "Remove a domain from the enforcement block list by its numeric id." inputs_schema: properties: domain_id: { type: string, description: "Numeric id of the domain to remove (from umbrella-list-domains)" } required: [domain_id] outputs_schema: { properties: {} } - id: test_connection name: umbrella-test-connection description: "Verify connectivity and the customer key (used by the Test button)." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} }