id: chronicle name: Google Chronicle version: 1.0.0 description: "Google Chronicle (Backstory API) — SIEM threat context: list IOCs seen in the enterprise, list alerts, list assets, and get IOC details for an artifact. Authenticates with a Google service account (RS256 JWT bearer flow). Runs on a remote engine. Requires the Python 'PyJWT' and 'cryptography' libraries on the engine host (pip install pyjwt cryptography)." changelog: "1.0.0 — Initial release: list IOCs, list alerts, list assets, get IOC details." category: siem # Per-instance configuration. The scripts build a signed RS256 assertion from the # service account's private_key/client_email and exchange it for an access token # (scope chronicle-backstory). base_url is the regional Chronicle API host. config_schema: properties: service_account_json: type: string description: "Full Chronicle service account key JSON (must contain client_email and private_key)" x-soar-sensitive: true base_url: type: string description: "Chronicle API base URL (region-specific)" default: "https://backstory.googleapis.com" required: - service_account_json commands: - id: list_iocs name: chronicle-list-iocs description: "List IOCs (indicators of compromise) observed in the enterprise since a start time." risk: read inputs_schema: properties: start_time: { type: string, description: "RFC3339 start time (e.g. 2024-01-01T00:00:00Z)" } page_size: { type: number, description: "Max IOCs (default 100)" } required: [start_time] outputs_schema: { properties: {} } - id: list_alerts name: chronicle-list-alerts description: "List alerts in a time window." risk: read inputs_schema: properties: start_time: { type: string, description: "RFC3339 start time" } end_time: { type: string, description: "RFC3339 end time" } page_size: { type: number, description: "Max alerts (default 100)" } required: [start_time, end_time] outputs_schema: { properties: {} } - id: list_assets name: chronicle-list-assets description: "List assets that accessed an artifact (domain, IP, or hash) in a time window." risk: read inputs_schema: properties: artifact_type: { type: string, description: "domain_name, destination_ip_address, or hash_sha256" } artifact_value: { type: string, description: "The artifact value" } start_time: { type: string, description: "RFC3339 start time" } end_time: { type: string, description: "RFC3339 end time" } required: [artifact_type, artifact_value, start_time, end_time] outputs_schema: { properties: {} } - id: ioc_details name: chronicle-ioc-details description: "Get IOC details for an artifact (domain, IP, or hash)." risk: read inputs_schema: properties: artifact_type: { type: string, description: "domain_name, destination_ip_address, or hash_sha256" } artifact_value: { type: string, description: "The artifact value" } required: [artifact_type, artifact_value] outputs_schema: { properties: {} } - id: test_connection name: chronicle-test-connection description: "Verify the service-account token exchange (used by the Test button)." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} }