id: rapid7_insightidr name: Rapid7 InsightIDR version: 1.0.0 description: "Rapid7 InsightIDR (REST API) — investigation ingestion and full lifecycle (list/get/search/create/update/assign/set-status/bulk-close), investigation alerts and Rapid7 product alerts, custom threat indicators (add/replace), log management and LEQL log/log-set queries with downloads, and user directory search." changelog: "1.0.0 — Initial release: investigation ingestion (list_investigations) with an exhaustive OCSF mapper, 18 commands across investigations, alerts, custom threats, logs/LEQL search and users. API v1/v2 selectable per instance and per command." category: siem # Per-instance configuration. The Insight platform region selects the API host # (https://.api.insight.rapid7.com). Authentication is an Organization # API key sent in the X-Api-Key header. config_schema: properties: region: type: string description: "Insight platform region: us, eu, ca, au or ap" default: us api_key: type: string description: "InsightIDR Organization API key (Read/Write)" x-soar-sensitive: true is_v2: type: string description: "Use API v2 by default for investigation commands (true/false). Can be overridden per command with api_version. Defaults to true (v2)." default: "true" is_multi_customer: type: string description: "Set to true if the API key has multi-customer access (adds the multi-customer query parameter on v2 calls)." default: "false" required: - region - api_key auth: - id: apikey type: api_key in: header name: X-Api-Key value_template: "{{secret}}" secret_field: api_key commands: # ── Ingestion ─────────────────────────────────────────────────────────────── - id: list_investigations name: rapid7-insight-idr-list-investigations description: "List investigations, sorted by created_time descending. Used for ingestion: results path = data. Investigations aggregate the applicable alert data and are tied to alerts and detection rules." risk: read inputs_schema: properties: api_version: { type: string, description: "API version to use: V1, V2 or Default (uses the instance default)" } statuses: { type: string, description: "Comma-separated statuses to include (open, investigating, closed)" } start_time: { type: string, description: "Only investigations created after this ISO-8601 timestamp (e.g. 2018-07-01T00:00:00Z). Incremental fetch watermark; V2 only." } end_time: { type: string, description: "Only investigations created before this ISO-8601 timestamp. V2 only." } time_range: { type: string, description: "Relative time range string (e.g. 1 week, 1 day) instead of start_time/end_time" } sources: { type: string, description: "Comma-separated sources to include (User, Alert). V2 only." } priorities: { type: string, description: "Comma-separated priorities to include (Unspecified, Low, Medium, High, Critical). V2 only." } assignee_email: { type: string, description: "Only investigations assigned to this user email" } tags: { type: string, description: "Comma-separated tags; only investigations having all of them are returned. V2 only." } sort_field: { type: string, description: "Field to sort by (Created time, Priority, RRN Last Created Alert, Last Detection Alert). V2 only." } sort_direction: { type: string, description: "Sort direction (ASC, DESC). V2 only." } index: { type: string, description: "0-based page index" } page_size: { type: string, description: "Page size (1-1000)" } limit: { type: number, description: "Maximum number of records to retrieve (default 50)" } required: [] outputs_schema: { properties: {} } ingest: results_path: data dedup_key: rrn incremental_field: start_time - id: get_investigation name: rapid7-insight-idr-get-investigation description: "Get a single investigation by ID or Rapid7 Resource Name (RRN). With api_version=V2 the ID must be in RRN format." risk: read inputs_schema: properties: api_version: { type: string, description: "API version to use: V1, V2 or Default" } investigation_id: { type: string, description: "Investigation ID or RRN" } required: [investigation_id] outputs_schema: { properties: {} } - id: search_investigation name: rapid7-insight-idr-search-investigation description: "Search investigations matching the given search/sort criteria (v2)." risk: read inputs_schema: properties: start_time: { type: string, description: "ISO-8601 lower bound on created_time (default 28 days ago)" } end_time: { type: string, description: "ISO-8601 upper bound on created_time (default now)" } actor_asset_hostname: { type: string, description: "Comma-separated values; CONTAINS match on actor_asset_hostname" } actor_user_name: { type: string, description: "Comma-separated values; CONTAINS match on actor_user_name" } alert_mitre_t_codes: { type: string, description: "Comma-separated values; EQUALS match on alert_mitre_t_codes" } alert_rule_rrn: { type: string, description: "Comma-separated values; EQUALS match on alert_rule_rrn" } assignee_id: { type: string, description: "Comma-separated values; EQUALS match on assignee_id" } organization_id: { type: string, description: "Comma-separated values; EQUALS match on organization_id" } priority: { type: string, description: "Comma-separated values; EQUALS match on priority (UNSPECIFIED, LOW, MEDIUM, HIGH, CRITICAL)" } rrn: { type: string, description: "Comma-separated values; EQUALS match on rrn" } source: { type: string, description: "Comma-separated values; EQUALS match on source (USER, ALERT)" } status: { type: string, description: "Comma-separated values; EQUALS match on status (OPEN, CLOSED, INVESTIGATING, WAITING)" } title: { type: string, description: "Comma-separated values; CONTAINS match on title" } sort: { type: string, description: "Comma-separated fields to sort by (Created time, Priority, RRN, Alert created time, Alert detection created time)" } sort_direction: { type: string, description: "Sort direction (asc, desc)" } index: { type: string, description: "0-based page index" } page_size: { type: string, description: "Page size (1-1000)" } limit: { type: number, description: "Maximum number of records to retrieve (default 50)" } required: [] outputs_schema: { properties: {} } - id: create_investigation name: rapid7-insight-idr-create-investigation description: "Create a new investigation manually (v2)." risk: safe_write inputs_schema: properties: title: { type: string, description: "Name of the investigation" } status: { type: string, description: "Open, Investigating or Closed (default Open)" } priority: { type: string, description: "Unspecified, Low, Medium, High or Critical (default Unspecified)" } disposition: { type: string, description: "Undecided, Benign, Malicious or Not Applicable (default Undecided)" } user_email_address: { type: string, description: "Email of the user to assign the investigation to" } required: [title] outputs_schema: { properties: {} } - id: update_investigation name: rapid7-insight-idr-update-investigation description: "Update fields of an investigation by ID or RRN (v2)." risk: safe_write inputs_schema: properties: investigation_id: { type: string, description: "Investigation ID or RRN to update" } title: { type: string, description: "Name of the investigation" } status: { type: string, description: "Open, Investigating or Closed" } priority: { type: string, description: "Unspecified, Low, Medium, High or Critical" } disposition: { type: string, description: "Undecided, Benign, Malicious or Not Applicable" } user_email_address: { type: string, description: "Email of the user to assign the investigation to" } threat_command_free_text: { type: string, description: "Additional text when closing an associated Threat Command alert (status=Closed)" } threat_command_close_reason: { type: string, description: "Threat Command close reason (status=Closed)" } required: [investigation_id] outputs_schema: { properties: {} } - id: assign_user name: rapid7-insight-idr-assign-user description: "Assign a user (by email) to one or more investigations. With api_version=V2 the IDs must be in RRN format." risk: safe_write inputs_schema: properties: api_version: { type: string, description: "API version to use: V1, V2 or Default" } investigation_id: { type: string, description: "Comma-separated investigation IDs or RRNs" } user_email_address: { type: string, description: "Email of the user to assign" } required: [investigation_id, user_email_address] outputs_schema: { properties: {} } - id: set_status name: rapid7-insight-idr-set-status description: "Set the status of one or more investigations. Closing requires a disposition (v2). With api_version=V2 the IDs must be in RRN format." risk: safe_write inputs_schema: properties: api_version: { type: string, description: "API version to use: V1, V2 or Default" } investigation_id: { type: string, description: "Comma-separated investigation IDs or RRNs" } status: { type: string, description: "open, closed, investigating or waiting" } disposition: { type: string, description: "benign, malicious or not_applicable (status=closed, V2 only)" } threat_command_close_reason: { type: string, description: "Threat Command close reason (status=closed, V2 only)" } threat_command_free_text: { type: string, description: "Additional text for a Threat Command alert (status=closed, V2 only)" } required: [investigation_id, status] outputs_schema: { properties: {} } - id: close_investigations name: rapid7-insight-idr-close-investigations description: "Bulk-close all investigations matching the request parameters within a time window (v2)." risk: safe_write inputs_schema: properties: source: { type: string, description: "Investigation source to close: ALERT, MANUAL or HUNT. ALERT requires alert_type or detection_rule_rrn." } start_time: { type: string, description: "ISO-8601 lower bound on createTime (e.g. 2018-07-01T00:00:00Z)" } end_time: { type: string, description: "ISO-8601 upper bound on createTime (e.g. 2018-07-28T23:59:00Z)" } alert_type: { type: string, description: "Alert category to close. Required when source=ALERT." } disposition: { type: string, description: "Disposition to set: Undecided, Benign, Malicious or Not Applicable (default Not Applicable)" } detection_rule_rrn: { type: string, description: "Detection rule RRN; only investigations linked to it are closed. Requires alert_type 'Attacker Behavior Detected'." } max_investigations_to_close: { type: string, description: "Maximum number of investigations to close (no maximum if omitted)" } required: [source, start_time, end_time] outputs_schema: { properties: {} } - id: list_investigation_alerts name: rapid7-insight-idr-list-investigation-alerts description: "List all alerts associated with an investigation, sorted by alert created time descending (v2)." risk: read inputs_schema: properties: investigation_id: { type: string, description: "Investigation ID or RRN (V2 RRN format)" } all_results: { type: string, description: "Return all results, overriding the limit (true/false, default false)" } limit: { type: number, description: "Maximum number of records to retrieve (default 50)" } required: [investigation_id] outputs_schema: { properties: {} } - id: list_investigation_product_alerts name: rapid7-insight-idr-list-investigation-product-alerts description: "List all Rapid7 product alerts (from other Rapid7 products) associated with an investigation (v2)." risk: read inputs_schema: properties: investigation_id: { type: string, description: "Investigation ID or RRN (V2 RRN format)" } all_results: { type: string, description: "Return all results, overriding the limit (true/false, default false)" } limit: { type: number, description: "Maximum number of records to retrieve (default 50)" } required: [investigation_id] outputs_schema: { properties: {} } - id: add_threat_indicators name: rapid7-insight-idr-add-threat-indicators description: "Add indicators (IPs, hashes, domains, URLs) to one or more custom threats by key." risk: safe_write inputs_schema: properties: key: { type: string, description: "Comma-separated threat keys to add indicators to" } ip_addresses: { type: string, description: "Comma-separated IP address indicators" } hashes: { type: string, description: "Comma-separated hash indicators" } domain_names: { type: string, description: "Comma-separated domain indicators" } url: { type: string, description: "Comma-separated URL indicators" } required: [key] outputs_schema: { properties: {} } - id: replace_threat_indicators name: rapid7-insight-idr-replace-threat-indicators description: "Replace all indicators of one or more custom threats: deletes existing indicators and adds the supplied ones." risk: safe_write inputs_schema: properties: key: { type: string, description: "Comma-separated threat keys to replace indicators for" } ip_addresses: { type: string, description: "Comma-separated IP address indicators" } hashes: { type: string, description: "Comma-separated hash indicators" } domain_names: { type: string, description: "Comma-separated domain indicators" } url: { type: string, description: "Comma-separated URL indicators" } required: [key] outputs_schema: { properties: {} } - id: list_logs name: rapid7-insight-idr-list-logs description: "List all logs available to the account." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} } - id: list_log_sets name: rapid7-insight-idr-list-log-sets description: "List all log sets configured for the InsightIDR instance." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} } - id: query_log name: rapid7-insight-idr-query-log description: "Run a LEQL query against a single log, following pagination links to gather all events." risk: read inputs_schema: properties: log_id: { type: string, description: "Log key to query" } query: { type: string, description: "Valid LEQL query (no calculations)" } time_range: { type: string, description: "Relative time range (e.g. 1 week, 1 day). When set, start_time/end_time are not needed." } start_time: { type: string, description: "Lower bound as a UNIX timestamp in milliseconds" } end_time: { type: string, description: "Upper bound as a UNIX timestamp in milliseconds" } logs_per_page: { type: string, description: "Maximum log entries per page (default 50)" } sequence_number: { type: string, description: "Earliest sequence number of a log entry to start from" } required: [log_id, query] outputs_schema: { properties: {} } - id: query_log_set name: rapid7-insight-idr-query-log-set description: "Run a LEQL query against a log set, following pagination links to gather all events." risk: read inputs_schema: properties: log_set_id: { type: string, description: "Log set ID to query" } query: { type: string, description: "Valid LEQL query (no calculations)" } time_range: { type: string, description: "Relative time range (e.g. 1 week, 1 day). When set, start_time/end_time are not needed." } start_time: { type: string, description: "Lower bound as a UNIX timestamp in milliseconds" } end_time: { type: string, description: "Upper bound as a UNIX timestamp in milliseconds" } logs_per_page: { type: string, description: "Maximum log entries per page (default 50)" } sequence_number: { type: string, description: "Earliest sequence number of a log entry to start from" } required: [log_set_id, query] outputs_schema: { properties: {} } - id: download_logs name: rapid7-insight-idr-download-logs description: "Download raw log events for up to 10 logs over a time window, optionally filtered by a LEQL query. Returns the events as text." risk: read inputs_schema: properties: log_ids: { type: string, description: "Comma-separated log IDs to download (up to 10)" } time_range: { type: string, description: "Relative time range (e.g. Last 4 Days). Defaults to Last 3 days when no bounds are given." } start_time: { type: string, description: "Lower bound as a UNIX timestamp in milliseconds" } end_time: { type: string, description: "Upper bound as a UNIX timestamp in milliseconds" } query: { type: string, description: "LEQL query to match desired events (no calculations)" } limit: { type: string, description: "Maximum number of events to download (cannot exceed 20 million)" } required: [log_ids] outputs_schema: { properties: {} } - id: list_users name: rapid7-insight-idr-list-users description: "List users matching the search/sort criteria, or retrieve a single user by RRN." risk: read inputs_schema: properties: rrn: { type: string, description: "RRN of a single user to retrieve. When set, the other filters are ignored." } first_name: { type: string, description: "Comma-separated values to match on first_name (requires search_operator)" } last_name: { type: string, description: "Comma-separated values to match on last_name (requires search_operator)" } name: { type: string, description: "Comma-separated values to match on name (requires search_operator)" } search_operator: { type: string, description: "Filter operator when first_name/last_name/name are used: contains or equals" } sort: { type: string, description: "Comma-separated fields to sort by (first_name, last_name, name)" } sort_direction: { type: string, description: "Sort direction (asc, desc)" } index: { type: string, description: "0-based page index" } page_size: { type: string, description: "Page size (1-1000)" } limit: { type: number, description: "Maximum number of records to retrieve (default 50)" } required: [] outputs_schema: { properties: {} } # ── Connectivity test ───────────────────────────────────────────────────── - id: test_connection name: rapid7-insight-idr-test-connection description: "Verify connectivity and credentials (used by the Test button)." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} } ingestion: command: list_investigations mapper: list_investigations default_incident_type: "Rapid7 InsightIDR Investigation"