fb82de7f93
Umbrella Enforcement API, 4 commands: add domain (DNS-layer block), list enforced domains, delete domain. Customer-key auth, stdlib-only. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
63 lines
2.6 KiB
YAML
63 lines
2.6 KiB
YAML
id: cisco_umbrella_enforcement
|
|
name: Cisco Umbrella Enforcement
|
|
version: 1.0.0
|
|
description: "Cisco Umbrella Enforcement API — DNS-layer containment: push malicious domains to the enforcement block list, list enforced domains, and remove them. Customer-key authentication; stdlib-only, no extra Python dependencies."
|
|
changelog: "1.0.0 — Initial release: add domain event (block), list domains, delete domain."
|
|
category: network
|
|
|
|
# Per-instance configuration. The customer key is appended as the 'customerKey'
|
|
# query parameter on every request.
|
|
config_schema:
|
|
properties:
|
|
api_url:
|
|
type: string
|
|
description: "Enforcement API base URL"
|
|
default: "https://s-platform.api.opendns.com"
|
|
api_key:
|
|
type: string
|
|
description: "Umbrella Enforcement customer key"
|
|
x-soar-sensitive: true
|
|
required:
|
|
- api_key
|
|
|
|
commands:
|
|
- id: add_domain
|
|
name: umbrella-add-domain
|
|
description: "Submit a security event that adds a domain to the Umbrella enforcement block list."
|
|
inputs_schema:
|
|
properties:
|
|
domain: { type: string, description: "Domain to block (e.g. malicious.example.com)" }
|
|
url: { type: string, description: "Destination URL (defaults to http://<domain>/)" }
|
|
device_id: { type: string, description: "Reporting device id (defaults to a fixed Riposte device id)" }
|
|
device_version: { type: string, description: "Reporting device version (default 1.0)" }
|
|
provider_name: { type: string, description: "Provider name (default 'Riposte SOAR')" }
|
|
required: [domain]
|
|
outputs_schema: { properties: {} }
|
|
- id: list_domains
|
|
name: umbrella-list-domains
|
|
description: "List the domains currently in the enforcement block list."
|
|
risk: read
|
|
inputs_schema:
|
|
properties:
|
|
page: { type: number, description: "Page number (default 1)" }
|
|
limit: { type: number, description: "Domains per page (default 200)" }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_domain
|
|
name: umbrella-delete-domain
|
|
description: "Remove a domain from the enforcement block list by its numeric id."
|
|
inputs_schema:
|
|
properties:
|
|
domain_id: { type: string, description: "Numeric id of the domain to remove (from umbrella-list-domains)" }
|
|
required: [domain_id]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: test_connection
|
|
name: umbrella-test-connection
|
|
description: "Verify connectivity and the customer key (used by the Test button)."
|
|
risk: read
|
|
inputs_schema:
|
|
properties: {}
|
|
required: []
|
|
outputs_schema: { properties: {} }
|